White medical pills.

Pri­va­cy poli­cy

Over­view

1. over­ar­ching pri­va­cy poli­cy

Infor­ma­ti­on on the EU Gene­ral Data Pro­tec­tion Regu­la­ti­on

Data pro­tec­tion infor­ma­ti­on in accordance with the EU Gene­ral Data Pro­tec­tion Regu­la­ti­on - Sta­tus: Sep­tem­ber 2025

Gene­ral infor­ma­ti­on

We take the pro­tec­tion of your per­so­nal data very serious­ly. Your pri­va­cy is an important con­cern for us.

The fol­lo­wing pro­vi­si­ons are inten­ded to inform you about the pro­ces­sing of per­so­nal data in accordance with the requi­re­ments of the Gene­ral Data Pro­tec­tionRegu­la­ti­on (GDPR). In par­ti­cu­lar, taking into account the infor­ma­ti­on obli­ga­ti­ons under Art. 12 to 14 GDPR, as well as to inform you about the rights of data sub­jects under the GDPR in accordance with Art. 15 to 22 and Art. 34 GDPR.

Plea­se note that due to the ECJ ruling C-394/23, the afo­re­men­tio­ned legi­ti­ma­te inte­rests include not only tho­se for who­se imple­men­ta­ti­on pro­ces­sing is alre­a­dy taking place, but also tho­se that are plan­ned in the fore­seeable future in order to com­ply with a pri­or trans­pa­ren­cy obli­ga­ti­on. We assu­me that you do not want to con­stant­ly take note of an amen­ded pri­va­cy poli­cy.

Infor­ma­ti­on on the con­trol­ler

Respon­si­ble for the pro­ces­sing of your per­so­nal data is

secur­Ph­arm e.V.
Ham­bur­ger Allee 26-28
60486 Frank­furt am Main

Tele­pho­ne: +49 69 979 919 12
E-mail: info@securPharm.de

Infor­ma­ti­on about us as the respon­si­ble body and our cont­act details can be found in the
IMPRINT.

Cont­act details of the data pro­tec­tion offi­cer

We have appoin­ted a data pro­tec­tion offi­cer for our com­pa­ny. You can reach him at datenschutz@securpharm.de or by post (see imprint)

Gene­ral infor­ma­ti­on

We pro­cess your per­so­nal data in accordance with the appli­ca­ble sta­tu­to­ry data pro­tec­tion requi­re­ments for the pur­po­ses lis­ted below for each group of data sub­jects:

  • Gene­ral pri­va­cy poli­cy
  • Pri­va­cy poli­cy for web­site users
  • Pri­va­cy poli­cy for cus­to­mers (incl. inte­res­ted par­ties) and other data sub­jects
  • Pri­va­cy poli­cy for employees
  • Pri­va­cy poli­cy for appli­cants
  • Pri­va­cy poli­cy for the public aut­ho­ri­ty por­tal

Use of ser­vice pro­vi­ders

Some of the afo­re­men­tio­ned pro­ces­ses or ser­vices are car­ri­ed out by careful­ly sel­ec­ted and com­mis­sio­ned ser­vice pro­vi­ders. We trans­mit or recei­ve per­so­nal data from the­se ser­vice pro­vi­ders sole­ly on the basis of a pro­ces­sing con­tract. If the regis­tered office of a ser­vice pro­vi­der is loca­ted out­side the Euro­pean Uni­on or the Euro­pean Eco­no­mic Area, a third coun­try trans­fer takes place. With the­se ser­vice pro­vi­ders, data pro­tec­tion agree­ments cor­re­spon­ding to the legal requi­re­ments are con­trac­tual­ly defi­ned to estab­lish an appro­pria­te level of data pro­tec­tion and cor­re­spon­ding gua­ran­tees are agreed.

Infor­ma­ti­on on your rights

You have the right

  • to request con­fir­ma­ti­on from us as to whe­ther per­so­nal data con­cer­ning you is being pro­ces­sed by us; if this is the case, you have a right to infor­ma­ti­on about this per­so­nal data and to the infor­ma­ti­on lis­ted in detail in Art. 15 GDPR.
  • to demand the publi­ca­ti­on of the data con­cer­ning you in the rest­ric­tions of Art. 20 GDPR in a com­mon elec­tro­nic, machi­ne-rea­da­ble data for­mat. This also includes the trans­fer (whe­re pos­si­ble) to ano­ther con­trol­ler named direct­ly by you.
  • to demand that we rec­ti­fy your data if it is incor­rect, inac­cu­ra­te and/or incom­ple­te. Rec­ti­fi­ca­ti­on also includes com­ple­ti­on by means of decla­ra­ti­ons or noti­fi­ca­ti­on.
  • to demand that we dele­te per­so­nal data con­cer­ning you imme­dia­te­ly if one of the reasons lis­ted in Art. 17 GDPR appli­es. Unfort­u­na­te­ly, we are not per­mit­ted to era­se data that is sub­ject to a sta­tu­to­ry reten­ti­on peri­od. If you no lon­ger wish us to cont­act you by news­let­ter or other means, we will store your cont­act details on a black­list.
  • to revo­ke any con­sent you have given with effect for the future wit­hout any dis­ad­van­ta­ges for you.
  • to demand that we rest­rict pro­ces­sing if one of the con­di­ti­ons lis­ted in Art. 18 GDPR appli­es
  • to object, on grounds rela­ting to your par­ti­cu­lar situa­ti­on, at any time to the pro­ces­sing of per­so­nal data con­cer­ning you.
    We will then no lon­ger pro­cess the per­so­nal data unless we can demons­tra­te com­pel­ling legi­ti­ma­te grounds which over­ri­de your inte­rests, rights and free­doms or the pro­ces­sing ser­ves the estab­lish­ment, exer­cise or defen­se of legal claims(Art. 21 GDPR).
  • wit­hout pre­ju­di­ce to any other admi­nis­tra­ti­ve or judi­cial reme­dy, and if you con­sider that the pro­ces­sing of per­so­nal data rela­ting to you inf­rin­ges the GDPR, to lodge a com­plaint with
    • our data pro­tec­tion offi­cer: datenschutz@securpharm.de or by post (see legal noti­ce)
    • a super­vi­so­ry aut­ho­ri­ty in the Mem­ber Sta­te of your habi­tu­al resi­dence, place of work or place of the alle­ged inf­rin­ge­ment.

Dele­ti­on of your data

Unless other­wi­se sti­pu­la­ted in the more detail­ed pri­va­cy poli­ci­es, we will era­se your per­so­nal data once the con­trac­tu­al rela­ti­onship with you has ended, you have exer­cis­ed your right to era­su­re, all mutu­al claims have been satis­fied and the­re are no other sta­tu­to­ry reten­ti­on obli­ga­ti­ons or legal jus­ti­fi­ca­ti­ons for sto­rage. Com­mer­cial law reten­ti­on peri­ods for finan­ci­al­ly rele­vant data are gene­ral­ly up to 10 years. In addi­ti­on, we may retain data for as long as is neces­sa­ry to pro­tect us from claims that could be asser­ted against us. The­se peri­ods can be up to 30 years.

Defi­ni­ti­ons

  1. Per­so­nal data - any infor­ma­ti­on rela­ting to an iden­ti­fied or iden­ti­fia­ble natu­ral per­son; an iden­ti­fia­ble natu­ral per­son is one who can be iden­ti­fied, direct­ly or indi­rect­ly, in par­ti­cu­lar by refe­rence to an iden­ti­fier such as a name, an iden­ti­fi­ca­ti­on num­ber, loca­ti­on data, an online iden­ti­fier or to one or more fac­tors spe­ci­fic to the phy­si­cal, phy­sio­lo­gi­cal, gene­tic, men­tal, eco­no­mic, cul­tu­ral or social iden­ti­ty of that natu­ral per­son. Examp­les are cont­act data, com­mu­ni­ca­ti­on data, bil­ling data.
  2. Con­trol­ler - the natu­ral or legal per­son, public aut­ho­ri­ty, agen­cy or other body which, alo­ne or joint­ly with others, deter­mi­nes the pur­po­ses and means of the pro­ces­sing of per­so­nal data; whe­re the pur­po­ses and means of such pro­ces­sing are deter­mi­ned by Uni­on or Mem­ber Sta­te law, the con­trol­ler or the spe­ci­fic cri­te­ria for its nomi­na­ti­on may be pro­vi­ded for by Uni­on or Mem­ber Sta­te law.
  3. Pro­ces­sor - a natu­ral or legal per­son, public aut­ho­ri­ty, agen­cy or other body which pro­ces­ses per­so­nal data on behalf of the con­trol­ler.
  4. Reci­pi­ent - a natu­ral or legal per­son, public aut­ho­ri­ty, agen­cy or ano­ther body, to which the per­so­nal data are dis­c­lo­sed, whe­ther a third par­ty or not.
  5. Employees - employees, inclu­ding tem­po­ra­ry workers in rela­ti­on to the hirer, per­sons employ­ed for their voca­tio­nal trai­ning, par­ti­ci­pan­ts in bene­fits for par­ti­ci­pa­ti­on in working life as well as in cla­ri­fi­ca­ti­ons of pro­fes­sio­nal apti­tu­de or work tri­als (reha­bi­li­tants), per­sons employ­ed in reco­gni­zed work­shops for dis­ab­led per­sons, vol­un­teers who per­form a ser­vice in accordance with the Youth Vol­un­teer Ser­vice Act or the Fede­ral Vol­un­teer Ser­vice Act, per­sons who are to be regard­ed as employee-like per­sons due to their eco­no­mic inde­pen­dence. The­se also include per­sons working from home and tho­se trea­ted as such, civil ser­vants of the Fede­ral Govern­ment, jud­ges of the Fede­ral Govern­ment, sol­diers and per­sons per­forming civi­li­an ser­vice. As well as appli­cants for employ­ment and per­sons who­se employ­ment has ended.
  6. Third par­ty - a natu­ral or legal per­son, public aut­ho­ri­ty, agen­cy or body other than the data sub­ject, con­trol­ler, pro­ces­sor and per­sons who, under the direct aut­ho­ri­ty of the con­trol­ler or pro­ces­sor, are aut­ho­ri­zed to pro­cess per­so­nal data.
  7. Pro­fil­ing - any form of auto­ma­ted pro­ces­sing of per­so­nal data con­sis­ting of the use of per­so­nal data to eva­lua­te cer­tain per­so­nal aspects rela­ting to a natu­ral per­son.
    In par­ti­cu­lar, to ana­ly­ze or pre­dict aspects rela­ting to the work per­for­mance, eco­no­mic situa­ti­on, health, per­so­nal pre­fe­ren­ces, inte­rests, relia­bi­li­ty, beha­vi­or, loca­ti­on or relo­ca­ti­on of that natu­ral per­son.
  8. Rest­ric­tion of pro­ces­sing - the mar­king of stored per­so­nal data with the aim of rest­ric­ting its future pro­ces­sing.

Chan­ges to the pri­va­cy poli­cy

We reser­ve the right to chan­ge our pri­va­cy poli­cy if neces­sa­ry and to publish it here. Plea­se check this page regu­lar­ly. The updated state­ment will enter into force upon publi­ca­ti­on, sub­ject to the appli­ca­ble legal pro­vi­si­ons. If we have alre­a­dy coll­ec­ted data about you that is affec­ted by the chan­ge and/or is sub­ject to a legal obli­ga­ti­on to pro­vi­de infor­ma­ti­on, we will also inform you of any signi­fi­cant chan­ges to our pri­va­cy poli­cy.

2. pri­va­cy poli­cy for web­site users

Scope of appli­ca­ti­on

This data pro­tec­tion decla­ra­ti­on appli­es to all pages of our online net­work that link to this decla­ra­ti­on. The gene­ral infor­ma­ti­on can be found on our main data pro­tec­tion page.

Pur­po­se of data coll­ec­tion

The pur­po­ses of data coll­ec­tion are

  • Pro­vi­si­on and opti­miza­ti­on of the web­site
    • to ensu­re the secu­ri­ty and func­tion­a­li­ty of the web­site
    • error detec­tion and ana­ly­sis, in par­ti­cu­lar the use of foren­sic pro­ce­du­res to ana­ly­ze mal­func­tions (“bug hun­ting”) to detect, pre­vent and pro­se­cu­te secu­ri­ty inci­dents and (attempt­ed) cri­mi­nal offen­ses or misu­se
  • User-ori­en­ted design and ser­vice
    • the indi­vi­du­al adapt­a­ti­on of our cus­to­miza­ti­on to your needs in terms of form, con­tent and func­tion
    • the offer and imple­men­ta­ti­on of cont­act estab­lish­ment and qua­li­fi­ca­ti­on
    • the pro­ces­sing of inco­ming inqui­ries via the com­mu­ni­ca­ti­on chan­nels pro­vi­ded or other cus­to­mer sup­port (see also pri­va­cy poli­cy for cus­to­mers)
  • Con­tract ful­fill­ment and busi­ness pro­ces­sing
    • the pro­ces­sing of orders and pay­ments

Gene­ral infor­ma­ti­on on data pro­ces­sing

We coll­ect and use the per­so­nal data of our users only to the ext­ent neces­sa­ry to pro­vi­de a func­tion­al web­site and our con­tent and ser­vices or to the ext­ent that you as a user pro­vi­de us with this data vol­un­t­a­ri­ly. The coll­ec­tion and use of per­so­nal data by you as a user takes place regu­lar­ly only with your con­sent or for the estab­lish­ment and exe­cu­ti­on of a legal tran­sac­tion. An excep­ti­on appli­es in cases whe­re pri­or con­sent can­not be obtai­ned for fac­tu­al reasons or is dis­pro­por­tio­na­te and the pro­ces­sing of the data is per­mit­ted by ano­ther legal pro­vi­si­on.

Legal bases for the pro­ces­sing of your data

  • Inso­far as we obtain the con­sent of the data sub­ject for the pro­ces­sing of per­so­nal data, Art.
    per­son con­cer­ned, Art. 6 para. 1 lit. a EU Gene­ral Data Pro­tec­tion Regu­la­ti­on
    (GDPR) ser­ves as the legal basis.
  • When pro­ces­sing per­so­nal data that is neces­sa­ry for the per­for­mance of a con­tract to which the data sub­ject is a par­ty, Art. 6 para. 1 lit. b GDPR ser­ves as the legal basis. This also appli­es to pro­ces­sing ope­ra­ti­ons that are neces­sa­ry for the per­for­mance of pre-con­trac­tu­al mea­su­res.
  • If the pro­ces­sing is neces­sa­ry to safe­guard a legi­ti­ma­te inte­rest of our com­pa­ny or a third par­ty and if the inte­rests, fun­da­men­tal rights and free­doms of the data sub­ject do not out­weigh the first-men­tio­ned inte­rest, Art. 6 para. 1 lit. f GDPR ser­ves as the legal basis for the pro­ces­sing.

Legi­ti­ma­te inte­rests can be in par­ti­cu­lar

  • Respon­ding to inqui­ries;
  • the imple­men­ta­ti­on of direct mar­ke­ting mea­su­res;
  • the pro­vi­si­on of ser­vices and/or infor­ma­ti­on inten­ded for you
  • the pro­ces­sing and trans­fer of per­so­nal data for inter­nal or admi­nis­tra­ti­ve pur­po­ses
  • the ope­ra­ti­on and admi­nis­tra­ti­on of our web­site
  • the tech­ni­cal sup­port of users;
  • the pre­ven­ti­on and detec­tion of fraud and cri­mi­nal offen­ses;
  • pro­tec­tion against pay­ment defaults when obtai­ning cre­dit infor­ma­ti­on for requests for deli­veries and ser­vices; and/or
  • ensu­ring net­work and data secu­ri­ty, inso­far as the­se inte­rests are con­sis­tent with the appli­ca­ble law and with the rights and free­dom of the user;
  • achie­ving effi­ci­en­cy gains by bund­ling ser­vices in indi­vi­du­al Group com­pa­nies (in par­ti­cu­lar mar­ke­ting, IT, pro­cu­re­ment)

Cate­go­ries of reci­pi­ents

  • Ser­vice pro­vi­ders for web­site opti­miza­ti­on, ser­vice com­pa­nies for infor­ma­ti­on and com­mu­ni­ca­ti­on tech­no­lo­gy, com­pa­nies for soft­ware and device main­ten­an­ce, some of which are descri­bed in more detail below
  • Social net­works and com­mu­ni­ties
  • Inter­nal reci­pi­ents accor­ding to the “need to know” prin­ci­ple

Usa­ge data/server log files

Each time our web­site is acces­sed, our sys­tems auto­ma­ti­cal­ly coll­ect data and infor­ma­ti­on from the com­pu­ter sys­tem of the acces­sing com­pu­ter.

The fol­lo­wing types of data are coll­ec­ted: Brow­ser type, ver­si­on used, user’s ope­ra­ting sys­tem, host name, inter­net ser­vice pro­vi­der, user’s IP address, date and time of access, web­sites from which the user’s sys­tem has acces­sed our web­site or to which the user has acces­sed from our web­site.

The legal basis for the tem­po­ra­ry sto­rage of the data and the log files is Art. 6 para. 1 lit. f GDPR with the abo­ve-men­tio­ned legi­ti­ma­te inte­rests.

The tem­po­ra­ry sto­rage of the IP address by the sys­tem is neces­sa­ry to enable the web­site to be deli­ver­ed to the user’s com­pu­ter. For this pur­po­se, the user’s IP address must remain stored for the dura­ti­on of the ses­si­on.

The data is stored in log files to ensu­re the func­tion­a­li­ty of the web­site.
In addi­ti­on, we use the data to opti­mi­ze the web­site and to ensu­re the secu­ri­ty of our infor­ma­ti­on tech­no­lo­gy sys­tems. The data is not ana­ly­zed for mar­ke­ting pur­po­ses in this con­text. Our legi­ti­ma­te inte­rest in data pro­ces­sing also lies in the­se pur­po­ses. The data is dele­ted as soon as it is no lon­ger requi­red to achie­ve the pur­po­se for which it was coll­ec­ted. In the case of the coll­ec­tion of data for the pro­vi­si­on of the web­site, this is the case when the respec­ti­ve ses­si­on has ended. We also reser­ve the right to check the files if the­re is a jus­ti­fied sus­pi­ci­on of unlawful use or a spe­ci­fic attack on the pages based on con­cre­te evi­dence. In this case, our legi­ti­ma­te inte­rest is pro­ces­sing for the pur­po­se of inves­ti­ga­ting and pro­se­cu­ting such attacks and unlawful use.

Use of coo­kies

We use coo­kies. Coo­kies are data that can be stored in the Inter­net brow­ser or by the Inter­net brow­ser on the user’s com­pu­ter sys­tem and retrie­ved again when visi­ting a web­site. Coo­kies may con­tain a cha­rac­te­ristic string of cha­rac­ters that enables the brow­ser to be uni­que­ly iden­ti­fied when the web­site or an inte­gra­ted ser­vice is cal­led up again. We use coo­kies to enable the ope­ra­ti­on of our web­site (tech­ni­cal­ly neces­sa­ry coo­kies), to make our web­site more user-fri­end­ly (func­tion­al coo­kies) and for mar­ke­ting and adver­ti­sing pur­po­ses (adver­ti­sing coo­kies).

Tech­ni­cal coo­kies: Some ele­ments of our web­site requi­re that the acces­sing brow­ser can be iden­ti­fied even after a page chan­ge. The pur­po­se of their use is to enable the web­site to func­tion at all. Examp­les of tech­ni­cal­ly neces­sa­ry coo­kies are the pro­vi­si­on of a shop­ping cart or log­ging in as a regis­tered user. The pro­ces­sing is the­r­e­fo­re car­ri­ed out on the basis of Art. 6 para. 1 lit. b or f GDPR.

Func­tion­al coo­kies: The­re may be func­tions that are not abso­lut­e­ly tech­ni­cal­ly neces­sa­ry for the ope­ra­ti­on of our web­site, but which con­sider­a­b­ly sim­pli­fy its use, such as the adop­ti­on of lan­guage set­tings or font sizes, the remem­be­ring of search terms, etc.. The pro­ces­sing is also car­ri­ed out on the basis of Art. 6 para. 1 lit. b or f GDPR.

Adver­ti­sing coo­kies: We also use coo­kies on some of our web­sites that enable us to ana­ly­ze the sur­fing beha­vi­or of users. In this way, for exam­p­le: search terms ente­red in search engi­nes, fre­quen­cy of page views, use of web­site func­tions, and infor­ma­ti­on about the ope­ra­ting sys­tem and brow­ser, etc. are trans­mit­ted. The user data coll­ec­ted in this way is pseud­ony­mi­zed by tech­ni­cal pre­cau­ti­ons. It is the­r­e­fo­re no lon­ger pos­si­ble to assign the data to the acces­sing user. The data is not stored tog­e­ther with other per­so­nal data of the user. The legal basis for the pro­ces­sing of per­so­nal data using coo­kies for ana­ly­sis pur­po­ses is Art. 6 para. 1 lit. a GDPR if the user has given con­sent to this - e.g. by sel­ec­ting it in a coo­kie opt-in ban­ner - other­wi­se Art. 6 para. 1 lit. f GDPR in con­junc­tion with EC 47. If third-par­ty ser­vices are inte­gra­ted, pro­ces­sing by them is gover­ned by their respec­ti­ve data pro­tec­tion pro­vi­si­ons, which are men­tio­ned and/or lin­ked below.

Note on coo­kies and track­ing in con­nec­tion with pro­ces­sing

Inso­far as we use coo­kies, com­pa­ra­ble tech­no­lo­gies or track­ing pro­ce­du­res, they are used for the pur­po­ses sta­ted in each case, such as for the ana­ly­sis of user beha­vi­or, the opti­miza­ti­on of our offer, the imple­men­ta­ti­on of adver­ti­sing cam­paigns, A/B tests or con­ver­si­on opti­miza­ti­ons as well as the crea­ti­on of tar­get groups (loo­ka­li­ke audi­en­ces) using third-par­ty data. The legal basis for this is regu­lar­ly your con­sent pur­su­ant to Art. 6 para. 1 lit. a GDPR, alter­na­tively the legi­ti­ma­te inte­rest pur­su­ant to Art. 6 para. 1 lit. f GDPR for the opti­miza­ti­on of our web­site, ana­ly­sis and for mar­ke­ting and sales pur­po­ses (in con­junc­tion with EG47 GDPR). Inso­far as the use ser­ves to ensu­re func­tion­a­li­ty, error ana­ly­sis or the detec­tion and pro­se­cu­ti­on of cri­mi­nal offen­ses, the pro­ces­sing is based on our legi­ti­ma­te inte­rest pur­su­ant to Art. 6 para. 1 lit. f GDPR.

Com­pli­anz coo­kie con­sent

The Com­pli­anz GDPR/CCPA Coo­kie Con­sent ser­vice is used on our web­site. We use the con­sent ser­vice to obtain appro­pria­te con­sent.
When you visit our web­site, the cons­ents or refu­sals are stored with a time stamp and IP address. We store your brow­ser data in the pro­cess.

The legal basis for the pro­ces­sing of your per­so­nal data is Art. 6 para. 1 lit. c GDPR (pro­ces­sing is neces­sa­ry for com­pli­ance with a legal obli­ga­ti­on).
Fur­ther infor­ma­ti­on on Complianz’s pri­va­cy poli­cy. You can find it at:
https://complianz.io/privacy-statement.

Con­tent from exter­nal pro­vi­ders

We use acti­ve Java­Script con­tent and fonts on our web­site, which may also ori­gi­na­te from exter­nal pro­vi­ders such as Goog­le. By acces­sing our web­site, the­se pro­vi­ders may recei­ve infor­ma­ti­on about your visit to our web­site, for exam­p­le by trans­mit­ting your IP address. You can pre­vent this trans­mis­si­on by instal­ling a Java­Script blo­cker such as the brow­ser plug­in ‘NoScript’ or by deac­ti­vat­ing Java­Script in your brow­ser.
Howe­ver, this can lead to func­tion­al rest­ric­tions.

Some of our web­sites incor­po­ra­te third-par­ty con­tent, such as vide­os from You­Tube, maps from Goog­le Maps, images, texts and mul­ti­me­dia files, RSS feeds or other ser­vices from other web­sites. This always requi­res your IP address to be trans­mit­ted to the pro­vi­ders of this con­tent. We can­not make any state­ment about the use of your data by the­se pro­vi­ders and also have no influence on fur­ther pro­ces­sing. In par­ti­cu­lar, we have no con­trol over whe­ther the data is used for other pur­po­ses, such as pro­fil­ing. Plea­se refer to the rele­vant data pro­tec­tion noti­ces of the respec­ti­ve third-par­ty pro­vi­ders. You can pro­tect yours­elf against fur­ther track­ing by track­ing pixels from the­se pro­vi­ders by deac­ti­vat­ing the accep­tance of third-par­ty coo­kies in your brow­ser set­tings. The legal basis for the trans­fer of per­so­nal data when inte­gra­ting third-par­ty pro­vi­ders is Art. 6 para. 1 lit. a GDPR if the user has given their con­sent - e.g. by sel­ec­ting this in a coo­kie opt-in ban­ner - other­wi­se Art. 6 para. 1 lit. f GDPR in con­junc­tion with EC 47.

Use of hCaptcha

We use the hCaptcha ser­vice of Intui­ti­on Machi­nes, Inc, 350 Ala­ba­ma Street, San Fran­cis­co,
CA 94110, USA (“hCaptcha”). hCaptcha is used to check whe­ther the data input on
our web­sites (e.g. in a cont­act form) is made by a natu­ral per­son or by auto­ma­ted pro­grams (bots). For this pur­po­se, hCaptcha ana­ly­zes the beha­vi­or of the web­site visi­tor based on various cha­rac­te­ristics. This ana­ly­sis beg­ins auto­ma­ti­cal­ly as soon as the visi­tor acces­ses the web­site.

As part of the ana­ly­sis, hCaptcha eva­lua­tes various infor­ma­ti­on (e.g. IP address, time spent on the web­site by the visi­tor, mou­se move­ments or other tech­ni­cal infor­ma­ti­on). The data coll­ec­ted during the ana­ly­sis is trans­mit­ted to hCaptcha and pro­ces­sed the­re. The pro­ces­sing is car­ri­ed out on the basis of Art. 6 para. 1 lit. f GDPR: The web­site ope­ra­tor has a legi­ti­ma­te inte­rest in pro­tec­ting its offers from abu­si­ve auto­ma­ted spy­ing and spam.

If a cor­re­spon­ding con­sent has been reques­ted (e.g. via a con­sent ban­ner), the pro­ces­sing is car­ri­ed out exclu­si­ve­ly on the basis of Art. 6 para. 1 lit. a GDPR; the con­sent can be revo­ked at any time.

Fur­ther infor­ma­ti­on about hCaptcha and the pri­va­cy poli­cy of Intui­ti­on Machi­nes, Inc.
can be found at: https://www.hcaptcha.com/privacy

Goog­le reCAPTCHA

In order to ensu­re data secu­ri­ty when sub­mit­ting forms and to pro­tect us from SPAM, we use the reCAPTCHA ser­vice of Goog­le Inc, 1600 Amphi­theat­re Park­way, Moun­tain View, CA 94043, USA (“Goog­le”). This is pri­ma­ri­ly used to distin­gu­ish whe­ther the input is made by a natu­ral per­son or abu­si­ve­ly by machi­ne and auto­ma­ted pro­ces­sing. After ente­ring and pres­sing the cor­re­spon­ding con­firm but­ton, your IP address and any other data requi­red for the reCAPTCHA ser­vice will be sent to Goog­le. The legal basis for the pro­ces­sing of your IP address and the use of reCAPTCHA is Art. 6 para. 1 lit. a GDPR. You can with­draw your con­sent at any time with effect for the future.

For the excep­tio­nal cases in which per­so­nal data is trans­fer­red to the USA, the EU-U.S. Data Pri­va­cy Frame­work appli­es, accor­ding to which Goog­le is cer­ti­fied. Fur­ther­mo­re, devia­ting data pro­tec­tion regu­la­ti­ons of Goog­le Inc. app­ly. Fur­ther infor­ma­ti­on on the data pro­tec­tion gui­de­lines of Goog­le Inc. can be found at http://www.google.de/intl/de/privacy
or https://www.google.com/intl/de/policies/privacy/.

E-mail cont­act

You can cont­act us via the e-mail address pro­vi­ded. In this case, the user’s per­so­nal data trans­mit­ted with the e-mail will be stored. The data will not be pas­sed on to third par­ties in this con­text. The data is used exclu­si­ve­ly for pro­ces­sing the con­ver­sa­ti­on.

The legal basis for the pro­ces­sing is:

  • For the receipt of the data on the basis of the sen­ding of the cont­act form as con­sent pur­su­ant to Art. 6 para. 1 lit. a in con­junc­tion with. Art. 5 (expec­ta­ble pro­ces­sing) GDPR or alter­na­tively on the basis of the legi­ti­ma­te inte­rest of ans­we­ring your cont­act request
    in accordance with Art. 6 para. 1 lit. f GDPR.
  • For the pro­ces­sing of data trans­mit­ted in the cour­se of sen­ding an e-mail, Art. 6 para. 1 lit. f GDPR with the abo­ve-men­tio­ned legi­ti­ma­te inte­rests.
  • If the e-mail cont­act is aimed at the con­clu­si­on of a con­tract, the addi­tio­nal legal basis for the pro­ces­sing is Art. 6 para. 1 lit. b GDPR.

The data will be dele­ted as soon as it is no lon­ger requi­red to achie­ve the pur­po­se for which it was coll­ec­ted. For per­so­nal data sent by email, this is the case when the respec­ti­ve con­ver­sa­ti­on with the user has ended and the­re is no reason for fur­ther sto­rage. The con­ver­sa­ti­on has ended when it can be infer­red from the cir­cum­s­tances that the mat­ter in ques­ti­on has been con­clu­si­ve­ly cla­ri­fied. The­re may be reten­ti­on peri­ods under com­mer­cial and tax law.

The user has the opti­on of with­dra­wing their con­sent to the pro­ces­sing of per­so­nal data at any time. If the user cont­acts us by e-mail, they can object to the sto­rage of their per­so­nal data at any time. In such a case, the con­ver­sa­ti­on can­not be con­tin­ued.

Data coll­ec­tion during regis­tra­ti­on and regis­tered use

Some of our web­sites requi­re or offer regis­tra­ti­on. The data coll­ec­ted is used for the pur­po­se of using the respec­ti­ve web­sites and ser­vices, unless other­wi­se descri­bed and expli­cit­ly con­sen­ted to during regis­tra­ti­on. The data coll­ec­ted results from the input mask during regis­tra­ti­on, the pro­ces­sing is based on Art. 6 para. 1 lit. b GDPR. All other data that you can enter at a later date to com­ple­te your pro­fi­le is optio­nal and vol­un­t­a­ry and is based on the legal basis of Art. 6 para. 1 lit. a GDPR. After regis­tra­ti­on, we may inform you about rele­vant cir­cum­s­tances rela­ted to our offer for which you have regis­tered by means of the e-mail address you have pro­vi­ded.

Data trans­mis­si­on via the inter­net

Data trans­mis­si­on via the Inter­net is gene­ral­ly asso­cia­ted with cer­tain risks. Data is not spe­ci­al­ly encrypt­ed, in par­ti­cu­lar mes­sa­ges from the cont­act form on our web­site and mes­sa­ges in the ser­vice chat are trans­mit­ted unen­crypt­ed. Plea­se bear this in mind when trans­mit­ting data. If you wish to com­mu­ni­ca­te with us by encrypt­ed e-mail, this is pos­si­ble via SMIME encryp­ti­on. Plea­se inform us of your request for encryp­ti­on, as we regu­lar­ly send unen­crypt­ed e-mails due to the curr­ent­ly low mar­ket pene­tra­ti­on of e-mail encryp­ti­on methods.

Data trans­fer

If you pro­vi­de us with per­so­nal data, it will only be pas­sed on to third par­ties if this is neces­sa­ry to pro­cess the con­trac­tu­al rela­ti­onship or if ano­ther legal reason legi­ti­mi­zes this trans­fer. Howe­ver, we pro­vi­de cer­tain ser­vices with the assis­tance of ser­vice pro­vi­ders. We have careful­ly sel­ec­ted the­se ser­vice pro­vi­ders and taken appro­pria­te mea­su­res to pro­tect your per­so­nal data.

Sto­rage peri­ods

The per­so­nal data of the data sub­ject will be dele­ted or blo­cked as soon as the pur­po­se of sto­rage no lon­ger appli­es. Data may also be stored if this has been pro­vi­ded for by the Euro­pean or natio­nal legis­la­tor in EU regu­la­ti­ons, laws or other pro­vi­si­ons to which the con­trol­ler is sub­ject. The data will also be blo­cked or dele­ted if a sto­rage peri­od pre­scri­bed by the afo­re­men­tio­ned stan­dards expi­res, unless the­re is a need for fur­ther sto­rage of the data for the con­clu­si­on or ful­fill­ment of a con­tract.

3. pri­va­cy poli­cy for cus­to­mers (incl. inte­res­ted par­ties) and other data sub­jects

Infor­ma­ti­on on data pro­ces­sing

As a cus­to­mer and as an inte­res­ted par­ty or other data sub­ject, we pro­cess your per­so­nal data pri­ma­ri­ly to estab­lish and ful­fill a con­trac­tu­al rela­ti­onship con­cluded with you or on the basis of our legi­ti­ma­te inte­rest. Your data will be coll­ec­ted, stored and, if neces­sa­ry, pas­sed on by us to the ext­ent neces­sa­ry to pro­vi­de the con­trac­tual­ly agreed ser­vice, to pro­vi­de infor­ma­ti­on, to car­ry out direct mar­ke­ting acti­vi­ties or other acti­vi­ties of our busi­ness ope­ra­ti­ons. Fail­ure to pro­vi­de this data may mean that the con­tract can­not be con­cluded. In addi­ti­on, we only pro­cess your data if you have con­sen­ted to the pro­ces­sing or ano­ther legal per­mis­si­on exists.

Pur­po­ses of data pro­ces­sing

We pro­cess your per­so­nal data to achie­ve the fol­lo­wing pur­po­ses in con­nec­tion with the initia­ti­on and exe­cu­ti­on of a con­trac­tu­al rela­ti­onship or other acti­vi­ties in the inte­rests of our orga­niza­ti­on:

  • con­tract pro­ces­sing, inclu­ding cus­to­mer ser­vice
  • com­mu­ni­ca­ti­on about pro­ducts, ser­vices and pro­jects and to respond to inqui­ries
  • adver­ti­sing to exis­ting cus­to­mers, use as a sel­ec­tion cri­ter­ion for direct mar­ke­ting in order to be able to offer you a cus­to­mi­zed ser­vice
  • the manage­ment of our busi­ness rela­ti­onships
  • qua­li­ty manage­ment
  • the impro­ve­ment and deve­lo­p­ment of intel­li­gent and inno­va­ti­ve ser­vices
  • Cus­to­mer ana­ly­sis for mar­ket and opi­ni­on rese­arch
  • the orga­niza­ti­on of events and trade fair appearan­ces
  • report­ing on our orga­niza­ti­on and events held and atten­ded by us as well as trade fair appearances/visits in elec­tro­nic and non-elec­tro­nic media
  • Com­pli­ance with legal or con­trac­tu­al requi­re­ments
  • the sett­le­ment of legal dis­pu­tes, enforce­ment of con­tracts and the asser­ti­on, defen­se and exer­cise of legal claims, detec­tion and pro­se­cu­ti­on of frau­du­lent and other unlawful acts

In addi­ti­on, we only pro­cess your data with your express con­sent.

Types of data that we pro­cess

The fol­lo­wing per­so­nal data is pro­ces­sed

  • Cont­act data: e.g. name, address, tele­pho­ne num­ber;
  • Identification/payment data: e.g. account num­ber, VAT ID no.
  • Image data: Pho­to and video recor­dings
  • Other data: Other infor­ma­ti­on requi­red in the con­text of the busi­ness rela­ti­onship, pro­vi­ded vol­un­t­a­ri­ly or available from public sources

Cate­go­ries of reci­pi­ents

The per­so­nal data will be trans­mit­ted to super­vi­so­ry aut­ho­ri­ties, legal ser­vice providers/auditors as requi­red. If we are sub­ject to a legal obli­ga­ti­on to do so, we will dis­c­lo­se your data to the com­pe­tent aut­ho­ri­ty upon request.

In some cases, we use exter­nal ser­vice pro­vi­ders to pro­cess your data. If the­se ser­vice pro­vi­ders are not based in the Euro­pean Eco­no­mic Area, we ensu­re that the data trans­fer is per­mis­si­ble under data pro­tec­tion law by means of data pro­tec­tion agree­ments that com­ply with the legal requi­re­ments and, if neces­sa­ry, other mea­su­res to ensu­re an appro­pria­te level of data pro­tec­tion.

The­se ser­vice pro­vi­ders have been careful­ly sel­ec­ted by us, com­mis­sio­ned in wri­ting and are bound by our ins­truc­tions. Our ser­vice pro­vi­ders are sub­ject to ran­dom checks by us. The ser­vice pro­vi­ders will not pass this data on to third par­ties, but will dele­te it after the con­tract has been ful­fil­led and the sta­tu­to­ry sto­rage peri­ods have expi­red, unless you have con­sen­ted to fur­ther sto­rage.

The­se are e.g:

  • Bank, pay­ment ser­vice pro­vi­ders
  • IT ser­vice pro­vi­ders
  • Mar­ke­ting ser­vice pro­vi­ders
  • Fur­ther education/training providers/company con­sul­tants
  • etc.

Legal bases of the pro­ces­sing

The legal bases for the pro­ces­sing of your data are in par­ti­cu­lar

  1. Art. 6 para. 1 lit. a) on the basis of your con­sent. This can also be given ver­bal­ly or through an unam­bi­guous act of con­sent.
  2. Art. 6 para. 1 lit. b) for the estab­lish­ment, per­for­mance and ter­mi­na­ti­on of a con­trac­tu­al rela­ti­onship
  3. Art. 6 para. 1 lit. c) for the ful­fill­ment of a legal obli­ga­ti­on
  4. Art. 6 para. 1 lit. f) for the pro­tec­tion of a legi­ti­ma­te inte­rest

Legi­ti­ma­te inte­rests

Our legi­ti­ma­te inte­rests lie in achie­ving the abo­ve-men­tio­ned pur­po­ses and also, for exam­p­le, in

  • Incre­asing effi­ci­en­cy and effec­ti­ve­ness poten­ti­al, also in coope­ra­ti­on with part­ners and, if appli­ca­ble, affi­lia­ted com­pa­nies,
  • ensu­ring com­pli­ance with safe­ty regu­la­ti­ons, requi­re­ments, indus­try stan­dards and con­trac­tu­al obli­ga­ti­ons
  • the asser­ti­on, exer­cise or defen­se of legal claims,
  • avo­i­ding dama­ge and/or lia­bi­li­ty of the com­pa­ny through appro­pria­te mea­su­res,
  • the imple­men­ta­ti­on of infor­ma­ti­on and com­mu­ni­ca­ti­on mea­su­res, inclu­ding of an adver­ti­sing natu­re and
  • the report­ing of com­pa­ny infor­ma­ti­on.

Cus­to­mer ana­ly­sis

In the con­text of cus­to­mer ana­ly­sis - this also includes cus­to­mer satis­fac­tion sur­veys car­ri­ed out by us - your data is pro­ces­sed eit­her in anony­mous form or, if com­ple­te anony­miza­ti­on is not pos­si­ble or does not make sen­se for fac­tu­al reasons, in pseud­ony­mi­zed form. In the case of sur­veys after trai­ning cour­ses, par­ti­ci­pan­ts can vol­un­t­a­ri­ly pro­vi­de anony­mous feed­back or sta­te their name, for exam­p­le if they wish to recei­ve per­so­nal feed­back from us. In this case, the infor­ma­ti­on can be assi­gned to a spe­ci­fic per­son. Howe­ver, the over­all eva­lua­ti­on of the sur­vey results is car­ri­ed out exclu­si­ve­ly in the form of an anony­mi­zed sum­ma­ry, so that it is no lon­ger pos­si­ble to draw con­clu­si­ons about indi­vi­du­al per­sons in the con­text of the pre­sen­ta­ti­on of results.

Some of the afo­re­men­tio­ned pro­ces­ses or ser­vices are car­ri­ed out by careful­ly sel­ec­ted and com­mis­sio­ned ser­vice pro­vi­ders. Per­so­nal data is trans­mit­ted or pro­ces­sed by them exclu­si­ve­ly on the basis of a pro­ces­sing con­tract. If the regis­tered office of a ser­vice pro­vi­der is loca­ted out­side the Euro­pean Uni­on or the Euro­pean Eco­no­mic Area, a so-cal­led third coun­try trans­fer takes place. In the­se cases, data pro­tec­tion agree­ments are con­cluded in accordance with the legal requi­re­ments and sui­ta­ble gua­ran­tees are agreed to ensu­re an appro­pria­te level of data pro­tec­tion.

Data coll­ec­ted by third par­ties

Data may be made available to us by third par­ties, e.g. by trade fair orga­ni­zers or as part of recom­men­da­ti­ons. In this case, this is usual­ly cont­act data in con­nec­tion with data on spe­ci­fic pro­duct or ser­vice requi­re­ments or inte­rests.

Sto­rage peri­od

Once the respec­ti­ve pur­po­se no lon­ger appli­es, your data will be dele­ted in com­pli­ance with sta­tu­to­ry reten­ti­on peri­ods. We dele­te your busi­ness cont­act data after ter­mi­na­ti­on of the busi­ness rela­ti­onship. We store image data per­ma­nent­ly.

4. pri­va­cy poli­cy for employees

Infor­ma­ti­on on data pro­ces­sing

We would like to inform our employees about how we hand­le their per­so­nal data in the con­text of the employ­ment rela­ti­onship.

Pur­po­se of data coll­ec­tion

During the peri­od of your employ­ment, your per­so­nal data will main­ly be pro­ces­sed for the per­for­mance and/or ter­mi­na­ti­on of the con­trac­tu­al rela­ti­onship, inclu­ding the tasks asso­cia­ted with the respec­ti­ve acti­vi­ty. Other pur­po­ses may include pro­ces­sing for the pur­po­ses of com­ply­ing with legal regu­la­ti­ons (inclu­ding third-par­ty claims for infor­ma­ti­on) or mea­su­res for cor­po­ra­te deve­lo­p­ment or com­mu­ni­ca­ti­on.

Types of data that we pro­cess

We pro­cess the fol­lo­wing per­so­nal data as part of your employ­ment rela­ti­onship:

  • Appli­cant data: Name Date of birth, CV, cer­ti­fi­ca­tes, cer­ti­fi­ca­te of enroll­ment for stu­dents, work per­mit if appli­ca­ble, driver’s licen­se for the ent­ry pro­cess;
  • Pri­va­te cont­act details: address, tele­pho­ne num­ber, e-mail;
  • busi­ness cont­act data: e.g. tele­pho­ne num­bers, e-mail, place of work, job title;
  • Image data: Pho­to for iden­ti­fi­ca­ti­on and pho­to­graphs taken as part of com­pa­ny events;
  • Identification/payment data: ID card data or work per­mit for iden­ti­fi­ca­ti­on and deter­mi­na­ti­on of the legi­ti­ma­cy of employ­ment, place of birth, marital sta­tus, in the case of paren­tal sta­tus, pro­of by birth certificate(s) of the child(ren), tax iden­ti­fi­ca­ti­on num­ber, health insu­rance mem­ber­ship, social secu­ri­ty num­ber (copy of social secu­ri­ty card or let­ter from pen­si­on insu­rance pro­vi­der), inco­me tax class, allo­wan­ces, deno­mi­na­tio­nal affi­lia­ti­on for church tax, account num­ber, any wage gar­nish­ments (for the pur­po­se of pay­roll accoun­ting and ful­fill­ment of social secu­ri­ty, tax ando­ther legal obli­ga­ti­ons);
  • Health data: Peri­ods of absence/incapacity for work, e.g. in the con­text of pay­roll accoun­ting, for sett­le­ment with health insu­rance com­pa­nies or employ­ers’ lia­bi­li­ty insu­rance asso­cia­ti­ons or in the con­text of legal obli­ga­ti­ons as an employ­er such as com­pa­ny inte­gra­ti­on manage­ment or the ful­fill­ment of duties in the pro­tec­tion of sever­ely dis­ab­led per­sons or in the con­text of com­pa­ny self-moni­to­ring such as occu­pa­tio­nal health and safe­ty or com­pa­ny medi­cal exami­na­ti­ons;
  • Time recor­ding, access and usa­ge data: Vaca­ti­on times, working time accounts, if appli­ca­ble
    shift sche­du­les, clo­sing times or access logs, time logs rela­ting to the acti­vi­ties car­ri­ed out, inclu­ding elec­tro­nic logs rela­ting to the use of our IT infra­struc­tu­re, etc;
  • Data in the con­text of per­son­nel scree­ning: if within the scope of the infor­ma­ti­on manage­ment sys­tem: e.g. poli­ce cle­arance cer­ti­fi­ca­te;
  • Data on sui­ta­bi­li­ty and performance/behavioral con­trol: trai­ning and fur­ther trai­ning infor­ma­ti­on, data for the pur­po­se of mea­su­ring tar­get achie­ve­ment, e.g. for varia­ble remu­ne­ra­ti­on com­pon­ents, data on inci­dents rele­vant to employ­ment law; data on vio­la­ti­ons of road traf­fic regu­la­ti­ons (“par­king tickets”);
  • other data in per­son­nel admi­nis­tra­ti­on: secon­da­ry employ­ment, data in the con­text of com­pa­ny health care and com­pa­ny health manage­ment, occu­pa­tio­nal health and safe­ty, copy of sever­ely dis­ab­led person’s pass if appli­ca­ble, copy of dri­ving licen­se if appli­ca­ble, BAV, capi­tal-forming bene­fits, RMV Deutsch­land­ti­cket, inter­net cost reim­bur­se­ment.

Cate­go­ries of reci­pi­ents

We send your per­so­nal data to the fol­lo­wing reci­pi­ents, e.g. to com­ply with legal obli­ga­ti­ons or obli­ga­ti­ons ari­sing from the employ­ment rela­ti­onship:

  • inter­nal depart­ments accor­ding to the “need-to-know prin­ci­ple”,
  • Bank ser­vice pro­vi­ders, finan­cial ser­vice pro­vi­ders, ser­vice pro­vi­ders for the cal­cu­la­ti­on of pen­si­on pro­vi­si­ons, if appli­ca­ble,
  • Ser­vice pro­vi­ders for pay­roll accoun­ting - tax con­sul­tants, audi­tors, ser­vice pro­vi­ders for infor­ma­ti­on and com­mu­ni­ca­ti­on tech­no­lo­gy, soft­ware and equip­ment main­ten­an­ce com­pa­nies,
  • Health, social, pen­si­on and acci­dent insu­rance pro­vi­ders as well as other insu­rance com­pa­nies and pro­vi­ders of capi­tal-forming bene­fits,
  • Aut­ho­ri­ties such as tax aut­ho­ri­ties, social secu­ri­ty funds, employ­ment agen­ci­es, safe­ty, health, road traf­fic and rela­ted fine aut­ho­ri­ties, cus­toms aut­ho­ri­ties and
    moni­to­ring bodies for unde­clared work and mini­mum wage; other aut­ho­ri­ties,
  • com­pa­ny medi­cal ser­vice,
  • Third-par­ty deb­tors in the event of wage gar­nish­ment, insol­ven­cy admi­nis­tra­tor in the event of per­so­nal insol­ven­cy
  • Busi­ness part­ners and cus­to­mers (busi­ness cont­act details)

Legal basis for pro­ces­sing

When pro­ces­sing your per­so­nal data, we natu­ral­ly com­ply with appli­ca­ble law. Pro­ces­sing the­r­e­fo­re only takes place on a legal basis. The fol­lo­wing legal bases come into con­side­ra­ti­on in par­ti­cu­lar in the employ­ment rela­ti­onship:

  • Art. 6 para. 1 lit. a) on the basis of your con­sent, wher­eby none is gene­ral­ly requi­red for the con­clu­si­on of a con­tract or the con­ti­nua­tion of an exis­ting con­tract: this appli­es in par­ti­cu­lar to such data that is neither legal­ly nor fac­tual­ly neces­sa­ry for the per­for­mance of the employ­ment rela­ti­onship and has been vol­un­t­a­ri­ly pro­vi­ded to us by you or in respect of which you have con­sen­ted to pro­ces­sing.
  • Art. 6 para. 1 lit.b) i.V.m. § Sec­tion 26 BDSG for the estab­lish­ment, exe­cu­ti­on and ter­mi­na­ti­on of a con­trac­tu­al rela­ti­onship: all data that estab­lish the employ­ment rela­ti­onship such as cur­ri­cu­lum vitae and pro­of of qua­li­fi­ca­ti­ons, employee mas­ter data requi­red for the exe­cu­ti­on of the con­tract, from other insu­ran­ces, on sta­tus in the con­text of disa­bi­li­ty and pregnan­cy pro­tec­tion, to pro­ve the pro­vi­si­on of the con­trac­tual­ly owed ser­vice (e.g. time sheets, vaca­ti­on plan­ning) and, if appli­ca­ble, in accordance with Sec­tion 26 BDSG, data in con­nec­tion with inter­nal inves­ti­ga­ti­ons to cla­ri­fy a con­cre­te sus­pi­ci­on of cri­mi­nal offen­ses or serious brea­ches of duty.
  • Art. 6 para. 1 lit.c) to ful­fill a legal obli­ga­ti­on: infor­ma­ti­on on tax cir­cum­s­tances, health and social insu­rance, other records on legal­ly requi­red trai­ning and ins­truc­tion, pos­si­bly data within the frame­work of the Infec­tion Pro­tec­tion Act (if appli­ca­ble).
  • Art. 6 para. 1 lit. f) to safe­guard a legi­ti­ma­te inte­rest: all other data such as log files, inter­nal coor­di­na­ti­on data and plan­ning, inter­nal cor­re­spon­dence and in the con­text of inter­nal IT sys­tems. Some pro­ces­sing ope­ra­ti­ons are regu­la­ted by a (com­pa­ny agree­ment) BV. In accordance with Art. 88 GDPR, coll­ec­ti­ve agree­ments (works agree­ments) may give rise to a pre­sump­ti­on of over­ri­ding legi­ti­ma­te inte­rest with regard to the pro­ces­sing regu­la­ted in the works agree­ments.

Legi­ti­ma­te inte­rests

If we pro­cess your data within the scope of our legi­ti­ma­te inte­rest, this lies, for exam­p­le, in

  1. the imple­men­ta­ti­on of elec­tro­nic access con­trols,
  2. the opti­miza­ti­on of per­son­nel plan­ning,
  3. ensu­ring com­pli­ance with safe­ty regu­la­ti­ons, requi­re­ments, indus­try stan­dards and con­trac­tu­al obli­ga­ti­ons
  4. the asser­ti­on, exer­cise or defen­se of legal claims, inclu­ding data for the docu­men­ta­ti­on of ser­vice flows
  5. the avo­id­ance of dama­ge and/or lia­bi­li­ty of the com­pa­ny through appro­pria­te mea­su­res
  6. the imple­men­ta­ti­on of inter­nal infor­ma­ti­on and com­mu­ni­ca­ti­on mea­su­res.
  7. report­ing on com­pa­ny infor­ma­ti­on.

You have the right to object to the pro­ces­sing of per­so­nal data within the scope of a legi­ti­ma­te inte­rest on grounds rela­ting to your par­ti­cu­lar situa­ti­on. We will then no lon­ger pro­cess your data unless we can demons­tra­te com­pel­ling legi­ti­ma­te grounds on our part that out­weigh your rights and free­doms, or the pro­ces­sing ser­ves to assert, exer­cise or defend legal claims.

We do not use the per­so­nal data pro­vi­ded by you to make auto­ma­ted decis­i­ons con­cer­ning you.

Data coll­ec­ted by third par­ties

We coll­ect data for pay­roll accoun­ting via the ELSTAM pro­ce­du­re, which is pro­vi­ded to us by the tax aut­ho­ri­ties for cor­rect accoun­ting. This appli­es in par­ti­cu­lar to the pay­roll accoun­ting data lis­ted below.

From 2021, due to the intro­duc­tion of the elec­tro­nic cer­ti­fi­ca­te of inca­pa­ci­ty for work, we are obli­ged to retrie­ve the sick lea­ve data (i.e. start and dura­ti­on of inca­pa­ci­ty for work, as well as the time of ter­mi­na­ti­on of con­tin­ued pay­ment of remu­ne­ra­ti­on in the event of ill­ness) from your health insu­rance com­pa­ny on the basis of a sick note from you.

Note: The gene­ral infor­ma­ti­on can be found on our main data pro­tec­tion page.

Sto­rage peri­od

Once the respec­ti­ve pur­po­se has been achie­ved, your data will be dele­ted in com­pli­ance with the sta­tu­to­ry reten­ti­on peri­ods, gene­ral­ly 6 or 10 years, and 30 years or lon­ger for various data cate­go­ries such as occu­pa­tio­nal pen­si­on pro­vi­si­on.

5. pri­va­cy poli­cy for appli­cants

Infor­ma­ti­on on data pro­ces­sing

When you app­ly for a posi­ti­on in our com­pa­ny, we pro­cess and store your per­so­nal data. We take your pri­va­cy very serious­ly and would the­r­e­fo­re like to take this oppor­tu­ni­ty to inform you about how we hand­le your appli­cant data.

Pur­po­se of data coll­ec­tion

Befo­re you join our com­pa­ny or during the appli­ca­ti­on pro­cess, we pro­cess your per­so­nal data exclu­si­ve­ly for the pur­po­se of estab­li­shing a con­trac­tu­al rela­ti­onship to the ext­ent neces­sa­ry.

Types of data that we pro­cess

The fol­lo­wing types of per­so­nal data are regu­lar­ly pro­ces­sed:

  • Appli­cant data: Name, date of birth, CV, cer­ti­fi­ca­tes, nationality/work per­mit, etc. for the sel­ec­tion, recruit­ment pro­cess, ent­ry and exit manage­ment,
  • pri­va­te cont­act data: Address, tele­pho­ne num­ber, e-mail (for the pur­po­se of cont­ac­ting you)
  • Data in the con­text of per­son­nel scree­ning: e.g. poli­ce cle­arance cer­ti­fi­ca­te, back­ground check (ZUP)
  • If appli­ca­ble, data sub­ject to pro­fes­sio­nal sec­re­cy: e.g. data on health sui­ta­bi­li­ty and any rest­ric­tions
  • Other data in per­son­nel admi­nis­tra­ti­on: seve­re disa­bi­li­ty (if rele­vant), dri­ving licen­se hol­der

We do not requi­re any infor­ma­ti­on from you that is not usable under the Gene­ral Equal Tre­at­ment Act (AGG) (race, eth­nic ori­gin, gen­der, pregnan­cy, infor­ma­ti­on on phy­si­cal or men­tal ill­ness, mem­ber­ship of a trade uni­on, reli­gi­on or belief, disa­bi­li­ty, age, sexu­al iden­ti­ty or sex life), unless rele­vant to the adver­ti­sed posi­ti­on.

We ask that you do not send us such data. The same appli­es to con­tent that is likely to inf­rin­ge the rights of third par­ties (e.g. copy­rights, ancil­la­ry copy­rights or other intellec­tu­al pro­per­ty rights, per­so­nal rights, press law or gene­ral rights of third par­ties).

Legal bases of the pro­ces­sing

  • for the estab­lish­ment, exe­cu­ti­on and ter­mi­na­ti­on of a con­trac­tu­al rela­ti­onship pur­su­ant to Art. 6 para. 1 lit. b GDPR i.V.m. § Sec­tion 26 BDSG (ver­si­on from 25.5.2018),
  • to ful­fill a legal obli­ga­ti­on pur­su­ant to Art. 6 para. 1 lit. c GDPR,
  • in the case of pro­ces­sing to safe­guard a legi­ti­ma­te inte­rest pur­su­ant to Art. 6 para. 1
    lit. f
    GDPR,
  • as well as on the basis of your con­sent by vol­un­t­a­ri­ly pro­vi­ding data that is not abso­lut­e­ly neces­sa­ry for the pur­po­se, such as hob­bies in your CV.
    Howe­ver, such con­sent is gene­ral­ly not requi­red for the con­clu­si­on of a con­tract or the con­ti­nua­tion of an exis­ting con­tract. The legal basis is Art. 6 para. 1 lit. a GDPR.

Legi­ti­ma­te inte­rests

Our legi­ti­ma­te inte­rests lie, for exam­p­le, in

  • the opti­miza­ti­on of appli­ca­ti­on pro­ces­ses,
  • achie­ving effi­ci­en­cy gains by bund­ling ser­vices in indi­vi­du­al Group com­pa­nies (in par­ti­cu­lar HR, IT)
  • ensu­ring com­pli­ance with safe­ty regu­la­ti­ons, requi­re­ments, indus­try stan­dards and con­trac­tu­al obli­ga­ti­ons,
  • the asser­ti­on, exer­cise or defen­se of legal claims,
  • the avo­id­ance of dama­ge and/or lia­bi­li­ty of the com­pa­ny through appro­pria­te mea­su­res.

Cate­go­ries of reci­pi­ents

  1. Inter­nal reci­pi­ents accor­ding to the “need to know” prin­ci­ple, gene­ral­ly on the basis of neces­si­ty for the per­for­mance of the employ­ment rela­ti­onship and on the basis of an over­ri­ding legi­ti­ma­te inte­rest;
  2. Ser­vice pro­vi­ders who sup­port us pro­fes­sio­nal­ly or tech­ni­cal­ly in the appli­ca­ti­on pro­cess.

Dele­ti­on peri­ods

Your data will be dele­ted once the respec­ti­ve pur­po­se has been achie­ved. Howe­ver, data will be stored for as long as is neces­sa­ry for the defen­se of legal claims. The reten­ti­on peri­od is gene­ral­ly 6 months. If your pro­fi­le has been trans­mit­ted to us by a per­son­nel ser­vice pro­vi­der and the­re are com­mis­si­on claims from this ser­vice pro­vi­der, the sto­rage peri­od may be up to their ful­fill­ment or the sta­tu­te of limi­ta­ti­ons. If pro­ces­sing rele­vant to accoun­ting has been car­ri­ed out, such as the reim­bur­se­ment of tra­vel expen­ses, the data requi­red for this will be dele­ted in com­pli­ance with the sta­tu­to­ry reten­ti­on peri­ods, usual­ly 6 or 10 years. If the appli­ca­ti­on was suc­cessful and we con­clude a con­tract with you, we will trans­fer the data coll­ec­ted during the appli­ca­ti­on pro­cess to our per­son­nel file.

6. pri­va­cy poli­cy for the public aut­ho­ri­ties por­tal

Thank you for your inte­rest in the public aut­ho­ri­ties por­tal. Com­pli­ance with data pro­tec­tion regu­la­ti­ons is of par­ti­cu­lar importance to us. The aim of this pri­va­cy poli­cy is to inform you as a user of the public aut­ho­ri­ties por­tal about the type, scope and pur­po­se of the pro­ces­sing of per­so­nal data and your exis­ting rights, inso­far as you are a data sub­ject within the mea­ning of Art. 4 No. 1 of the Gene­ral Data Pro­tec­tion Regu­la­ti­on.

This pri­va­cy poli­cy appli­es to the public aut­ho­ri­ty por­tal (available at
https://www.securpharm.de/datenschutzerklaerung-behoerdenportal/) and pro­vi­des you with an
over­view of the type, scope and pur­po­se of the coll­ec­tion, use and pro­ces­sing of per­so­nal data by secur­Ph­arm e.V. Fur­ther­mo­re, we inform you in this pri­va­cy poli­cy about the rights to which you are entit­led vis-à-vis secur­Ph­arm e.V. with regard to your per­so­nal data. Under no cir­cum­s­tances will your per­so­nal data be pas­sed on to third par­ties, unless other­wi­se sta­ted below

Respon­si­ble body

For the public aut­ho­ri­ty por­tal and the ran­ge of ser­vices

secur­Ph­arm e.V.
Ham­bur­ger Allee 26-28
60486 Frank­furt am Main

Pho­ne: +49 69 979 919 12
E-mail: info@securPharm.de

Respon­si­ble within the mea­ning of the GDPR.

Infor­ma­ti­on about us as the respon­si­ble body and our cont­act details can be found in the
IMPRINT.

Cont­act details of the data pro­tec­tion offi­cer

We have appoin­ted a data pro­tec­tion offi­cer for our com­pa­ny. You can reach him at datenschutz@securpharm.de or by post (see imprint)

Gene­ral infor­ma­ti­on

The public aut­ho­ri­ty por­tal is desi­gned to coll­ect as litt­le data as pos­si­ble from you.
We always ensu­re that your per­so­nal data is only pro­ces­sed in accordance with a legal basis or with your con­sent. We com­ply with the pro­vi­si­ons of the Gene­ral Data Pro­tec­tion Regu­la­ti­on (GDPR) and the appli­ca­ble natio­nal regu­la­ti­ons, such as the Fede­ral Data Pro­tec­tion Act, the Tele­com­mu­ni­ca­ti­ons Digi­tal Ser­vices Data Pro­tec­tion Act or other more spe­ci­fic data pro­tec­tion laws.

Pur­po­se and legal basis for the pro­ces­sing of per­so­nal data

We pro­cess your per­so­nal data for the fol­lo­wing pur­po­ses:

  1. For the tech­ni­cal rea­liza­ti­on of the aut­ho­ri­ty por­tal and to be able to pro­vi­de you with our infor­ma­ti­on (e.g. IP address, coo­kies, brow­ser infor­ma­ti­on)
  2. To cont­act you and pro­cess your request (e.g. first and last name, orga­niza­ti­on)
  3. To pro­vi­de our ticket sys­tem with which you can send us inqui­ries about tech­ni­cal faults (e.g. email address)

We pro­cess per­so­nal data that is requi­red for the estab­lish­ment, imple­men­ta­ti­on or pro­ces­sing of our ran­ge of ser­vices (con­tract pro­ces­sing) on the legal basis of Art. 6 para. 1 lit. b GDPR. Inso­far as we obtain your con­sent for the pro­ces­sing of your per­so­nal data, the con­sent pur­su­ant to Art. 6 para. 1 lit. a GDPR forms the legal basis for data pro­ces­sing. Data pro­ces­sing is also per­mit­ted if we pro­cess your data to pro­tect our legi­ti­ma­te inte­rests and your inte­rests or fun­da­men­tal rights and free­doms with regard to the pro­ces­sing of per­so­nal data do not pre­vail. (Art. 6 para. 1 lit. f GDPR) If we use exter­nal ser­vice pro­vi­ders as part of com­mis­sio­ned data pro­ces­sing, the pro­ces­sing is car­ri­ed out in accordance with Art. 28 GDPR.

Coll­ec­tion of per­so­nal data when using the public aut­ho­ri­ty por­tal

When you use the public aut­ho­ri­ty por­tal, we coll­ect the data that is tech­ni­cal­ly neces­sa­ry for us to ensu­re the sta­bi­li­ty and secu­ri­ty of the appli­ca­ti­on:

  • IP address
  • Date and time of access
  • Date and time of the report query
  • Time zone dif­fe­rence to Green­wich Mean Time (GMT)
  • Access status/HTTP sta­tus code
  • Type of access (user inter­face or API inter­face)

Coo­kies

Coo­kies are small text files that are stored on your data car­ri­er and save cer­tain set­tings and data for exch­an­ge with our sys­tem via your brow­ser. A coo­kie usual­ly con­ta­ins the name of the domain from which the coo­kie data was sent, as well as infor­ma­ti­on about the age of the coo­kie and an alpha­nu­me­ric iden­ti­fier. Only tech­ni­cal­ly neces­sa­ry coo­kies are set when the aut­ho­ri­ty por­tal is acces­sed.

Regis­tra­ti­on pro­cess

In order to be able to use our public aut­ho­ri­ty por­tal, we coll­ect per­so­nal data when you app­ly for access to the public aut­ho­ri­ty por­tal. The fol­lo­wing data cate­go­ries are requi­red for the appli­ca­ti­on: The fol­lo­wing data is coll­ec­ted in the role of cont­act per­son:

  • Name of the con­trac­tu­al part­ner (minis­try / aut­ho­ri­ty)
  • Address of the con­trac­tu­al part­ner
  • Salu­ta­ti­on, first name and sur­na­me
  • Offi­ci­al e-mail address
  • Work tele­pho­ne num­ber
  • Offi­ci­al address

The fol­lo­wing data is coll­ec­ted in the role of the user cont­act per­son:

  • Name of the con­trac­tu­al part­ner (minis­try / aut­ho­ri­ty)
  • Fede­ral sta­te of the con­trac­tu­al part­ner
  • Salu­ta­ti­on, first name and sur­na­me
  • Offi­ci­al e-mail address
  • Name of the aut­ho­ri­ty (for which the cont­act per­son may report aut­ho­ri­ty users)
  • Address of the aut­ho­ri­ty

The fol­lo­wing data is coll­ec­ted in the role of the aut­ho­ri­ty user:

  • Name of the aut­ho­ri­ty
  • Sta­te of the aut­ho­ri­ty
  • Salu­ta­ti­on, first name and sur­na­me
  • Offi­ci­al e-mail address
  • Address (whe­re the user can recei­ve let­ters by post)

We pro­cess the per­so­nal data to pro­vi­de the public aut­ho­ri­ty por­tal and hand­le busi­ness inter­ac­tions. The pro­ces­sing of the afo­re­men­tio­ned per­so­nal data for the pur­po­ses sta­ted here takes place on the legal basis of Art. 6 para. 1 lit. b GDPR.

We may also pro­cess the data you pro­vi­de in order to inform you about fur­ther func­tion­a­li­ties of the public aut­ho­ri­ty por­tal, remin­ders about access aut­ho­riza­ti­ons or to send you e-mails with tech­ni­cal infor­ma­ti­on or satis­fac­tion sur­veys. For the lat­ter, we do not need to obtain sepa­ra­te con­sent from you in accordance with Sec­tion 7 (3) UWG.

Manage­ment of cus­to­mer mas­ter data

We use the cus­to­mer rela­ti­onship manage­ment sys­tem Bigin to mana­ge cus­to­mer mas­ter data for the pur­po­se of busi­ness pro­ces­sing. This is ope­ra­ted by Zoho Cor­po­ra­ti­on GmbH, Trin­kau­stra­ße 7, 40213 Düs­sel­dorf, Ger­ma­ny.

Bigin is used on the basis of Art. 6 para. 1 lit. f GDPR. Our legi­ti­ma­te inte­rest lies in the most effi­ci­ent cus­to­mer manage­ment and cus­to­mer com­mu­ni­ca­ti­on pos­si­ble.
With regard to the sto­rage peri­od, we dele­te per­so­nal data as soon as its sto­rage is no lon­ger neces­sa­ry for the ful­fill­ment of the ori­gi­nal pur­po­se and the­re are no lon­ger any legal reten­ti­on peri­ods. We have con­cluded an order pro­ces­sing con­tract with Zoho. Data trans­fer to third count­ries out­side the Euro­pean Uni­on is based on the stan­dard con­trac­tu­al clau­ses of the EU Com­mis­si­on. Details
c

Find a contact

Do you have any questions or need help? Don't worry, we are here to help you. Simply use our contact form and we will forward your request to the right contact person, who will get back to you as quickly as possible. Your stress is our concern – let us help you.

contact us