Privacy policy

A. General Information

This Privacy Policy describes how the website operator processes personal data, and whether and to whom this data is disclosed.

This Privacy Policy describes both the rights of data subjects and the measures taken by the operator to protect the privacy of customers and users.

According to Article 4(1) of the GDPR, personal data refers to any information relating to an identified or identifiable natural person. This includes, for example, information such as first and last name, address, phone number, email address, as well as the IP address. This includes data that the user knowingly provides, such as in the context of contact requests, as well as system data—such as browser type and version, operating system used, referrer URL, and the time of the server request—which is automatically collected and stored by the website provider when the user’s browser transmits this information.

Under the GDPR, “processing” occurs whenever—with or without the aid of automated means—operations such as collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, distribution, or any other form of disclosure; or the comparison or linking, restriction, erasure, or destruction of data take place.

The responsible party is the owner of the company that operates this website. For this website, that is:

Altano International GmbH
Weddern 16c
D-48249 Dülmen

Phone: +49 2594 9190 500
Email: kontakt@altano-gruppe.de

An external data protection officer has been appointed to address data protection issues and, consequently, to safeguard the privacy of website users. This person is:

Sebastian Wulf, J.D.

wulf-services

Melsterhag 20

59457 Werl

info@wulf-services.de

Phone: 02922/911-7623

 

B. Legal Basis

The legal bases for processing are, first,

  • the user's consent to the processing (Art. 6(1)(a) of the GDPR),
  • the necessity to fulfill a contract (Art. 6(1), sentence 1(b) of the GDPR) and
  • the protection of legitimate interests (Art. 6(1)(f) of the GDPR).
 
 

C. User Rights

The user's rights are governed by Chapter 3 of the GDPR. These include, in particular:

  • the right to obtain information about the source, recipients, and purpose of the stored personal data, 
  • the right to request the correction, restriction, or deletion of the data,
  • the right to file a complaint with the competent supervisory authority,
  • the right to request the restriction of the processing of personal data, as well as
  • the right to revoke consent once it has been given.
 
 

D. Regulatory Authority

The competent supervisory authority is the State Data Protection Commissioner of the state in which the operator of this website has its registered office. For the operator of this website, this is:

The State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia

P.O. Box 20 04 44

40102 Düsseldorf

Switchboard: +49 (0)211 / 38424 – 0

poststelle@ldi.nrw.de

 

E. Duration of Storage

The length of time personal data is stored depends on the purpose for which the data is stored:

– Data that is technically necessary for the operation of the website is deleted as soon as the aforementioned personal data is no longer required to display the website. The collection of data for the purpose of providing the website and the storage of this data in log files is strictly necessary for the operation of the website. Consequently, users have no right to object to this aspect. Further storage may occur in individual cases if required by law.

– Data transmitted for the purpose of fulfilling a contract will be deleted as soon as it is no longer necessary for the purpose of its processing. However, additional statutory retention requirements may apply, such as those under commercial or tax law pursuant to the German Commercial Code (HGB) or the German Fiscal Code (AO). If such retention requirements exist, the data will be deleted upon expiration of these retention periods.

– Data transmitted as part of an order process is deleted as soon as it is no longer needed to fulfill the purpose of the processing. In addition, statutory retention requirements may apply to this data, such as commercial or tax-related retention requirements under the German Commercial Code (HGB) or the German Fiscal Code (AO). If such retention requirements exist, the data will be deleted upon expiration of these retention periods.

 

F.1. Contact Form

If you send us inquiries via the contact form, your details from the inquiry form, including the contact details you provide there, will be stored by us for the purpose of processing the inquiry and in the event of follow-up questions. We will not pass on this data without your consent.

This data is processed on the basis of Art. 6 para. 1 lit. b GDPR if your request is related to the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective processing of the inquiries addressed to us (Art. 6 para. 1 lit. f GDPR) or on your consent (Art. 6 para. 1 lit. a GDPR) if this has been requested; consent can be revoked at any time.

We will retain the data you provide on the contact form until you request its deletion, revoke your consent for its storage, or the purpose for its storage no longer pertains (e.g. after fulfilling your request). Mandatory statutory provisions - in particular retention periods - remain unaffected.

If you contact us by e-mail, telephone or fax, we will store and process your inquiry, including all personal data (name, inquiry), for the purpose of processing your request. We will not pass on this data without your consent.

This data is processed on the basis of Art. 6 para. 1 lit. b GDPR if your request is related to the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective processing of the inquiries addressed to us (Art. 6 para. 1 lit. f GDPR) or on your consent (Art. 6 para. 1 lit. a GDPR) if this has been requested; consent can be revoked at any time.

The data you send to us via contact requests will remain with us until you ask us to delete it, revoke your consent to storage or the purpose for data storage no longer applies (e.g. after your request has been processed). Mandatory statutory provisions - in particular statutory retention periods - remain unaffected.

 

F.2. Career Portal

We use the Rexx Systems career portal, which is linked on our website, for applications to job postings and for managing our talent pool.

The processing of applicants’ personal data through the portal is based on the users’ consent in accordance with Article 6(1)(a) of the GDPR. Users may withdraw this consent at any time, which will result in the deletion of the stored personal data.

When registering on our career portal, users can choose to submit their information solely in response to a specific job posting, or they can consent to being added to our applicant pool at the same time.

Stored data will be deleted no later than six months after the job posting process is completed. If the user has consented to being added to the applicant pool, the data will be deleted no later than two years after it was stored or upon the user’s informal request.

 

G. Cookies

When using the website, cookies—small files—are stored on the user’s device by the user’s browser. Some features of the website cannot be provided without the use of technically necessary cookies. Other cookies enable various types of analysis. For example, some cookies can recognize the browser used when the user revisits the website and transmit various pieces of information to the website operator. Cookies are used to facilitate and improve the user experience on the website. Among other things, cookies help make the website more user-friendly and effective by tracking how the website is used and identifying preferred settings (e.g., country and language settings). If third parties process information via cookies, they collect this information directly through the browser. Cookies do not cause any damage to the device. They cannot execute programs and do not contain viruses. Various types of cookies are used on the website; their types and functions are explained below:

  1. Temporary cookies

The website uses so-called temporary cookies, or session cookies, which are automatically deleted as soon as the browser is closed. These types of cookies make it possible to record a so-called session ID. This allows various requests from the browser to be assigned to a single session and enables the user’s device to be recognized during subsequent visits to the website.

  1. persistent cookies

So-called "persistent cookies" are also used. Persistent cookies are cookies that are stored in the user's browser for an extended period of time and can transmit information. The storage period varies depending on the cookie. Persistent cookies can be deleted manually through the browser settings.

  1. Third-Party Cookies

In addition, analytical cookies are used to track anonymized user behavior on the website.

In addition, advertising cookies are used to track user behavior for advertising and targeted marketing purposes.

Social media cookies make it possible to connect to the user's social networks and share content from the website within the user's social networks.

You can set your browser so that you are informed about the setting of cookies and only allow cookies in individual cases, exclude the acceptance of cookies for certain cases or in general and activate the automatic deletion of cookies when closing the browser. If cookies are deactivated, the functionality of this website may be restricted.

You can find out which cookies and services are used on this website in this privacy policy.

Our website uses Complianz’s consent technology to obtain your consent to the storage of certain cookies on your device or to the use of certain technologies, and to document this in compliance with data protection regulations. The provider of this technology is Complianz B.V., Kalmarweg 14-5, 9723 JG Groningen, Netherlands (hereinafter “Complianz”).

Complianz is hosted on our servers, so no connection is established to the servers of the provider of Complianz. Complianz stores a cookie in your browser in order to be able to assign the consents you have given or revoke them. The data collected in this way is stored until you ask us to delete it, delete the Complianz cookie yourself or the purpose for storing the data no longer applies. Mandatory statutory retention obligations remain unaffected.

 

H. Tracking and Analytics Tools

H.1. Google Analytics

This website uses features of the web analytics service Google Analytics. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Google Analytics uses technologies that enable the recognition of the user for the purpose of analyzing user behavior (e.g. cookies or device fingerprinting). The information collected by Google about the use of this website is generally transmitted to a Google server in the USA and stored there.

The use of this service is based on your consent in accordance with Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG. Consent can be revoked at any time.

Data transfers to the United States are based on the European Commission's Standard Contractual Clauses. For details, please visit:https://privacy.google.com/businesses/controllerterms/mccs/.

The company is certified under the “EU-U.S. Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the United States designed to ensure compliance with European data protection standards when data is processed in the United States. Every company certified under the DPF commits to complying with these data protection standards. For more information, please visit the provider’s website at the following link:https://www.dataprivacyframework.gov/participant/5780.

  • IP anonymization

The IP anonymization feature is enabled on this website. This means that Google truncates the user’s IP address within member states of the European Union or in other signatory states to the Agreement on the European Economic Area before transmitting it to the United States. Only in exceptional cases is the full IP address transmitted to a Google server in the United States and truncated there. On behalf of the operator of this website, Google will use this information to evaluate the use of the website, to compile reports on website activity, and to provide the website operator with other services related to website and Internet usage. The IP address transmitted by the browser as part of Google Analytics is not merged with other Google data.

  • Browser plugin

The user can prevent cookies from being stored by adjusting the settings in their browser software; however, please note that in this case, it may not be possible to use all features of this website to their full extent. In addition, users can prevent Google from collecting the data generated by the cookie and related to their use of the website (including their IP address), as well as from processing this data, by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=de.

For more information on how Google Analytics handles user data, please see Google's Privacy Policy:https://support.google.com/analytics/answer/6004245?hl=de.

  • Objection to Data Collection

Users can prevent Google Analytics from collecting data by clicking the following link. An opt-out cookie will be set to prevent data collection during future visits to this website: Disable Google Analytics.

For more information on how Google Analytics handles user data, please see Google's Privacy Policy: https://support.google.com/analytics/answer/6004245?hl=de.

H.2. Microsoft Clarity

We use the Microsoft Clarity analytics service on our website (operated by Microsoft Corporation, One Microsoft Way, Redmond, WA 98052, USA; EU representative: Microsoft Ireland Operations Limited, Dublin).

  • Purpose of Processing

Clarity helps us understand how visitors navigate our website (e.g., which buttons they click, how far they scroll, and what content interests them). To do this, Clarity creates heat maps and records individual sessions. This helps us make our website more user-friendly and efficient.

  • Type of Data Collected

The following information, among other things, is collected:

  • Clicks, mouse movements, and scrolling.
  • The end device's IP address.
  • Screen size and device type.
  • Browser information and operating system.
  • Geographic location (country only).
  • Preferred language.

Clarity uses cookies for this purpose (including _clck and _clsk).

Note: Personal information entered in form fields is obscured through technical "masking" and is not recorded.

  • Legal Basis

Data processing is carried out exclusively on the basis of your explicit consent in accordance with Article 6(1)(a) of the GDPR. Data collection does not begin until you have given your consent via our cookie banner.

  • Data Transfer to the United States

The data is processed on Microsoft servers, including those in the United States. Microsoft is certified under the EU-U.S. Data Privacy Framework.

  • Retention Period and Withdrawal

Microsoft typically deletes session recordings after 30 days; individual flagged or randomly selected recordings are stored for up to 9 months. You can withdraw your consent at any time, effective for the future, through the cookie settings on our website. For more information, please see Microsoft’s Privacy Statement: https://privacy.microsoft.com/de-de/privacystatement.

H.3. Google Tag Manager

We use the Google Tag Manager. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Google Tag Manager is a tool that enables us to integrate tracking or statistical tools and other technologies on our website. The Google Tag Manager itself does not create any user profiles, does not store any cookies and does not carry out any independent analyses. It is only used to manage and display the tools integrated via it. However, Google Tag Manager records your IP address, which may also be transmitted to Google's parent company in the United States.

The Google Tag Manager is used on the basis of Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in the fast and uncomplicated integration and management of various tools on its website. If a corresponding consent has been requested, the processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG, insofar as the consent includes the storage of cookies or access to information in the user's terminal device (e.g. device fingerprinting) within the meaning of the TDDDG. Consent can be revoked at any time.

The company is certified under the “EU-U.S. Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the United States designed to ensure compliance with European data protection standards when data is processed in the United States. Every company certified under the DPF commits to complying with these data protection standards. For more information, please visit the provider’s website at the following link:https://www.dataprivacyframework.gov/participant/5780.

H.4. Matomo

  • Type of Data Collected

On our career portal (the “Rexx Systems” website), data is collected and stored for marketing and optimization purposes using the web analytics software Matomo (www.matomo.org). Usage profiles are created from this data under a pseudonym; cookies are used for this purpose. Cookies are small text files that are stored locally in the cache of the site visitor’s web browser. The cookies enable the recognition of the web browser. The data collected using Matomo technology (including your anonymized IP address) is transmitted to the “Rexx Systems” server and stored for usage analysis purposes, which serves to optimize the website. The information generated by the cookie in the pseudonymous user profile is not used to personally identify the website visitor and is not combined with personal data about the person behind the pseudonym. You can prevent the use of cookies—and thus participation in tracking—by adjusting your browser settings accordingly; however, in this case, you may not be able to fully utilize all features of this website.

  • Legal Basis

 The legal basis for the processing of users' personal data is Article 6(1)(a) of the GDPR.

  • Purpose of Processing

Processing users’ personal data allows us to analyze their browsing behavior. By evaluating the data collected, we are able to compile information about the use of the website’s individual components. This helps us to continuously improve the website and its user-friendliness. Data is collected and stored only with express consent in accordance with Article 6(1)(a) of the GDPR.

  • Storage duration

The storage period varies depending on the type of cookies used. Temporary cookies (also known as session cookies) are deleted at the latest after a user leaves an online service and closes it on their device (e.g., browser or mobile application). Persistent cookies remain stored even after you leave the website or application, etc., until you delete them or they are automatically deleted after a specified period, which varies depending on the cookie and can be as long as several years.

  1. Cookies are stored on the user’s computer and transmitted from there to the “Rexx Systems” website. Therefore, you have full control over the use of cookies. By changing the settings in your web browser, you can disable or restrict the transmission of cookies. Cookies that have already been stored can be deleted at any time. This can also be done automatically. If cookies are disabled for our website, you may no longer be able to use all of the website’s features to their full extent. For more information on the privacy settings of the Matomo software, please visit the following link: https://matomo.org/docs/privacy/
 

I. Plugins and Tools

I.1. Google Maps

The website uses the Google Maps mapping service via an API. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

To use the features of Google Maps, it is necessary to store the user's IP address. This information is typically transmitted to a Google server in the United States and stored there. The provider of this site has no control over this data transfer.

We use Google Maps to ensure that our online offerings are presented in an appealing way and that the locations listed on the website are easy to find. This constitutes a legitimate interest within the meaning of Article 6(1)(f) of the GDPR.

More information about how user data is handled can be found in Google's Privacy Policy: https://www.google.de/intl/de/policies/privacy/.

I.2. Instagram

This website incorporates features from the Instagram service. These features are provided by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.

When the social media element is active, a direct connection is established between your device and the Instagram server. Instagram thereby receives information about your visit to this website.

If you are logged into your Instagram account, you can link the content of this website to your Instagram profile by clicking on the Instagram button. This allows Instagram to associate your visit to this website with your user account. We would like to point out that, as the provider of the pages, we have no knowledge of the content of the transmitted data or its use by Instagram.

The use of this service is based on your consent in accordance with Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG. Consent can be revoked at any time.

To the extent that personal data is collected on our website using the tool described here and forwarded to Facebook or Instagram, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbor, Dublin 2, Ireland, are jointly responsible for this data processing (Art. 26 GDPR). This joint responsibility is limited exclusively to the collection of the data and its transmission to Facebook or Instagram. Any processing by Facebook or Instagram following the transmission is not part of the joint responsibility. The obligations we share have been set forth in a joint processing agreement. You can find the text of the agreement at:

 https://www.facebook.com/legal/controller_addendum. Under this agreement, we are responsible for providing privacy notices when using the Facebook or Instagram tools and for ensuring that the tools are implemented on our website in compliance with data protection laws. Facebook is responsible for the data security of its Facebook and Instagram products. You may exercise your data subject rights (e.g., requests for information) regarding the data processed by Facebook or Instagram directly with Facebook. If you exercise your data subject rights with us, we are obligated to forward these requests to Facebook.

Data transfers to the United States are based on the European Commission's Standard Contractual Clauses. For details, see:https://www.facebook.com/legal/EU_data_transfer_addendum,https://privacycenter.instagram.com/policy/, andhttps://de-de.facebook.com/help/566994660333381.

For more information on this, please see Instagram's Privacy Policy: 

https://privacycenter.instagram.com/policy/.

The company is certified under the “EU-U.S. Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the United States designed to ensure compliance with European data protection standards when data is processed in the United States. Every company certified under the DPF commits to complying with these data protection standards. For more information on this, please visit the provider’s website at the following link:https://www.dataprivacyframework.gov/participant/4452.

I.3. Facebook

For our Facebook page, we use the technical platform and services provided by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.

Please note that you use the Facebook page and its features at your own risk. This applies in particular to interactive features (such as commenting, sharing, and rating). Meta processes personal data related to your account, your IP address, and the devices you use; cookies are used to collect data. These are small files that are stored on your devices. Meta describes in general terms what information it collects and how it is used in itsPrivacy Policy. There you will also find information on how to contact Meta, your options for objecting to data processing, and settings for managing advertisements.

Meta may use this information to provide us, as the operators of the Facebook pages, with statistical information—such as gender and age distribution—regarding the use of the Facebook page. In addition, Meta may show you further information or advertisements based on your preferences. For more information on this, please visitMeta’s Help Center.

The data collected about you in this context is processed by Meta Platforms Ireland Ltd and may be transferred to countries outside the European Union.

When you visit one of our social media pages (e.g., Facebook), you trigger the processing of your personal data during that visit. In this case, we are jointly responsible with the operator of the respective social network for the data processing operations within the meaning of Article 26 of the GDPR, provided that we actually make a joint decision with the social network operator regarding data processing and that we also have an influence on the data processing. To the extent possible, we have entered into joint controller agreements with the social media platform operators in accordance with Article 26 of the GDPR, specifically the Page Controller Addendum from Meta Ireland Ltd.Yourrights (right of access under Article 15 of the GDPR, right to rectification under Article 16 of the GDPR, right to erasure pursuant to Art. 17 GDPR, right to restriction of processing pursuant to Art. 18 GDPR, right to data portability pursuant to Art. 20 GDPR, and right to lodge a complaint pursuant to Art. 77 GDPR) can generally be exercised both with us and with the operator of the respective social network (e.g., Facebook).

Please note that, despite our joint responsibility under Article 26 of the GDPR with social media platform operators, we do not have full control over how individual social media platforms process data. The corporate policies of the respective provider have a significant influence on our options. In the event that data subjects exercise their rights, we would only be able to forward these requests to the social media platform operator.

Meta does not clearly and definitively specify how it uses data from visits to Facebook pages for its own purposes, to what extent activities on the Facebook page are attributed to individual users, how long Meta stores this data, or whether data from a visit to the Facebook page is shared with third parties; we are not aware of this information.

When you access a Facebook page, the IP address assigned to your device is transmitted to Meta. According to Meta, this IP address is anonymized (for “German” IP addresses) and deleted after 90 days. Meta also stores information about its users’ devices (for example, as part of the “login notification” feature); in some cases, this may allow Meta to associate IP addresses with individual users.

If you, as a user, are currently logged into Facebook, there is a cookie on your device containing your Facebook ID. This allows Meta to track that you have visited this page and how you used it. This also applies to all other Facebook pages. Through Facebook buttons embedded in websites, Meta can track your visits to these websites and associate them with your Facebook profile. Based on this data, content or advertising can be tailored specifically to you.

If you wish to avoid this, you should log out of Facebook or disable the “Stay Logged In” feature, delete the cookies stored on your device, and close and restart your browser. This will delete Facebook information that can be used to directly identify you. This allows you to use our Facebook page without revealing your Facebook ID. If you access interactive features on the page (Like, Comment, Share, Messages, etc.), a Facebook login screen will appear. Once you log in, Facebook will once again recognize you as a specific user. Alternatively, you can use a different browser than usual when visiting our Facebook page.

For information on how to manage or delete the information we have about you, please visit theMeta Privacy Center.

As the provider of this information service, we do not collect or process any other data resulting from your use of our service. 

I.4. YouTube

This website embeds videos from YouTube. The website is operated by Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.

When you visit one of our websites on which YouTube is integrated, a connection to the YouTube servers is established. This tells the YouTube server which of our pages you have visited.

Furthermore, YouTube may store various cookies on your device or use comparable technologies to recognize you (e.g. device fingerprinting). In this way, YouTube can obtain information about visitors to this website. This information is used, among other things, to record video statistics, improve user-friendliness and prevent fraud attempts. Furthermore, the data collected is processed in the Google advertising network.

If you are logged into your YouTube account, you enable YouTube to assign your surfing behavior directly to your personal profile. You can prevent this by logging out of your YouTube account.

The use of YouTube is in the interest of an appealing presentation of our online offers. This constitutes a legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR. If a corresponding consent has been requested, the processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG, insofar as the consent includes the storage of cookies or access to information in the user's terminal device (e.g. device fingerprinting) within the meaning of the TDDDG. Consent can be revoked at any time.

For more information on how user data is handled, please see YouTube's Privacy Policy at:https://policies.google.com/privacy?hl=de.

The company is certified under the “EU-U.S. Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the United States designed to ensure compliance with European data protection standards when data is processed in the United States. Every company certified under the DPF commits to complying with these data protection standards. For more information, please visit the provider’s website at the following link:https://www.dataprivacyframework.gov/participant/5780.

 

J. Disclosure of Data to Third Parties

As part of our business operations, we collaborate with various external entities. In some cases, this requires us to transfer personal data to these external entities.

Except as required by law, we disclose users’ personal data to third parties only if:

  1. a) Express consent has been given in accordance with Article 6(1)(a) of the GDPR.
  2. b) This is permitted by law and is necessary, pursuant to Article 6(1)(a) of the GDPR, to fulfill a contractual relationship with users or to take steps prior to entering into a contract.
  3. c) Pursuant to Article 6(1)(c) of the GDPR, there is a legal obligation to disclose data to government authorities, such as tax authorities, social security agencies, health insurance providers, regulatory agencies, and law enforcement agencies.
  4. d) The disclosure pursuant to Article 6(1)(f) of the GDPR is necessary to safeguard legitimate business interests, as well as to assert, exercise, or defend legal claims, and there is no reason to believe that the user has an overriding legitimate interest in preventing the disclosure of the data         
  5. e) If, in accordance with Article 28 of the GDPR, external service providers (so-called “processors”) are used for processing, and they have been obligated to handle the data with due care.

Service providers are engaged in the following areas:

  • IT
  • Logistics
  • Telecommunications
  • Sales
  • Marketing

When data is transferred to external entities in third countries—that is, outside the EU or the EEA—we ensure that these entities handle users’ personal data with the same level of care as is required within the EU or the EEA.

Personal data is transferred to third countries only if the European Commission has confirmed that they provide an adequate level of protection, or if the proper handling of personal data is ensured through contractual agreements or other appropriate safeguards.

 

J.1. Hosting

We host the content of our website with the following provider:

IONOS

The provider is IONOS SE, Elgendorfer Str. 57, 56410 Montabaur (hereinafter “IONOS”). When you visit our website, IONOS collects various log files, including your IP addresses. For details, please refer to IONOS’s Privacy Policy:

https://www.ionos.de/terms-gtc/terms-privacy.

The use of IONOS is based on Art. 6 para. 1 lit. f GDPR. We have a legitimate interest in displaying our website as reliably as possible. If a corresponding consent has been requested, the processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG, insofar as the consent includes the storage of cookies or access to information in the user's terminal device (e.g. device fingerprinting) within the meaning of the TDDDG. Consent can be revoked at any time.

This site uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content, such as orders or inquiries that you send to us as the site operator. You can recognize an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in your browser line.

If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.

J.2. Data Transfer to Creditreform

Creditworthiness is checked when contracts are concluded and, in certain cases where there is a legitimate interest, also for existing customers. To this end, we collaborate with Creditreform Boniversum GmbH, Hellersbergstraße 11, 41460 Neuss, from which we obtain the necessary data. On behalf of Creditreform Boniversum, the following information is provided in advance in accordance with Art. 14 of the EU GDPR: 

Creditreform Boniversum GmbH is a consumer credit reporting agency. It maintains a database that stores credit information on individuals. Based on this information, Creditreform Boniversum provides credit reports to its clients. Clients include, for example, banks, leasing companies, insurance companies, telecommunications companies, debt collection agencies, mail-order, wholesale, and retail firms, as well as other companies that supply goods or provide services. In accordance with legal provisions, some of the data contained in the credit report database is also used to supply other corporate databases, including for use in address-based marketing. The Creditreform Boniversum database stores, in particular, information regarding the name, address, date of birth, email address (if applicable), payment history, and ownership interests of individuals. The purpose of processing the stored data is to provide credit reports on the creditworthiness of the person in question. The legal basis for the processing is Article 6(1)(f) of the EU GDPR. According to this provision, information regarding this data may only be disclosed if a customer credibly demonstrates a legitimate interest in obtaining this information. If data is transferred to countries outside the EU, this is done on the basis of the so-called “Standard Contractual Clauses,” which are available at the following link: 

http://eur-lex.europa.eu/legal-content/DE/TXT/PDF/?uri=CELEX:32001D0497&from=DE 

The data is stored for as long as access to it is necessary to fulfill the purpose of storage. Access to the data is generally necessary for an initial storage period of three years. After this period expires, a review is conducted to determine whether continued storage is necessary; if not, the data is deleted to the exact day. If a matter is resolved, the data is deleted to the exact day three years after resolution. Entries in the debtor registry are deleted to the exact day in accordance with § 882e ZPO three years after the date of the entry order. 

Legitimate interests within the meaning of Article 6(1)(f) of the EU GDPR may include: credit decisions, business development, equity interests, claims, credit checks, insurance contracts, and information on debt enforcement. 

The user has the right to request information from Creditreform Boniversum GmbH regarding the data stored there about him or her. If any of the stored data is incorrect, the user has the right to have it corrected or deleted. If it cannot be immediately determined whether the data is incorrect or correct, the user has the right to have the data in question blocked until the matter is clarified. If the data is incomplete, the user may request that it be completed. 

If consent has been given for the processing of data stored by Creditreform Boniversum, you have the right to revoke that consent at any time. 

Withdrawal of consent does not affect the lawfulness of the processing of data that took place on the basis of consent prior to such withdrawal. 

If you have any objections, requests, or complaints regarding data protection, you may contact the Data Protection Officer at Creditreform Boniversum at any time. The Data Protection Officer will ensure that all data protection issues are addressed promptly and confidentially. Your right to file a complaint with the relevant state data protection commissioner remains unaffected. 

The data stored by Creditreform Boniversum comes from publicly available sources, debt collection agencies, and their clients. To assess creditworthiness, Creditreform Boniversum calculates a score based on this data. The score incorporates data on age and gender, address information, and, in some cases, payment history. These data points are factored into the score calculation with varying weightings. Creditreform Boniversum’s clients use the scores as a tool to help them make their own credit decisions. 

Right to Object: 

The processing of stored data is carried out for compelling legitimate reasons related to creditor and credit protection, which generally outweigh the interests, rights, and freedoms of the user, or serves to assert, exercise, or defend legal claims. The user may object to the processing of their data only if there are reasons arising from a specific situation that must be substantiated. If such specific reasons are demonstrably present, the data will no longer be processed. 

The controller within the meaning of Article 4(7) of the EU GDPR is Creditreform Boniversum GmbH, Hellersbergstr. 11, 41460 Neuss. The contact is the Consumer Service, Tel.: 02131 36845560, Fax: 02131 36845570, Email: selbstauskunft@boniversum.de. 

The Data Protection Officer can be reached at the following contact information: Creditreform Boniversum GmbH, Data Protection Officer, Hellersbergstr. 11, 41460 Neuss, Email: datenschutz@boniversum.de. 

A. General Information

This privacy policy describes how personal data is processed by the operator of this website, and whether and to whom this data is disclosed.

This privacy policy also describes the rights of data subjects as well as the measures taken by the operator to protect the privacy of customers and users.

Personal data, as defined in Article 4(1) of the GDPR, means any information relating to an identified or identifiable natural person. This includes, for example, information such as first and last name, address, telephone number, and email address, as well as the IP address. It includes data knowingly provided by users themselves—for example, in the context of contact inquiries—as well as system data such as browser type and version, operating system used, referrer URL, and time of the server request, which are automatically collected and stored by the website provider when transmitted by the user’s browser.

Under the GDPR, “processing” means any operation performed, with or without the aid of automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.

The controller is the owner of the company that operates this website. For this website, the controller is:

Altano International GmbH
Weddern 16c
D-48249 Dülmen

Phone: +49 2594 9190 500
Email: kontakt@altano-gruppe.de

An external Data Protection Officer has been appointed to handle data protection matters and, consequently, to protect the privacy of the website’s users. The Data Protection Officer is:

Sebastian Wulf, J.D.

wulf-services

Melsterhag 20

D-59457 Werl

info@wulf-services.de

Phone: +492922/911-7623

 

B. Legal Bases

The legal bases for processing are:

  • the user’s consent to the processing (Art. 6 (1), sentence 1 (a) of the GDPR),
  • the necessity of processing for the performance of a contract (Art. 6(1), first sentence, (b) of the GDPR), and
  • the protection of legitimate interests (Art. 6(1), sentence 1(f) of the GDPR).
 
 

C. User Rights

The user's rights are governed by Chapter 3 of the GDPR. These include, in particular:

  • the right to obtain information about the origin, recipients, and purpose of the stored personal data,
  • the right to request the correction, restriction, or erasure of the data,
  • the right to file a complaint with the competent supervisory authority,
  • the right to request restriction of the processing of personal data, and
  • the right to withdraw consent once it has been given.
 
 

D. Supervisory Authority

The competent supervisory authority is the State Data Protection Commissioner of the federal state in which the operator of this website has its registered office. For the operator of this website, this is:

The State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen)

P.O. Box 20 04 44

D-40102 Düsseldorf

Switchboard: +49 (0)211 / 38424 – 0

poststelle@ldi.nrw.de

 

E. Retention Period

The retention period for personal data depends on the purpose for which the data is stored:

– Data that is technically necessary for the operation of the website is deleted as soon as the personal data in question is no longer needed to display the website. The collection of data for the purpose of providing the website and the storage of data in log files is strictly necessary for the operation of the website. Consequently, the user has no right to object in this regard. In individual cases, data may be stored for a longer period if required by law.

– Data transmitted for the purpose of performing a contract is deleted as soon as it is no longer required for the purpose for which it was processed. However, statutory retention requirements may also apply, such as those under commercial or tax law pursuant to the German Commercial Code (HGB) or the German Fiscal Code (AO). Where such retention requirements exist, the data is deleted at the end of these retention periods.

– Data transmitted during the ordering process is deleted as soon as it is no longer needed to fulfill the purpose of processing. Statutory retention requirements may also apply to this data, such as those under commercial or tax law pursuant to the German Commercial Code (HGB) or the German Fiscal Code (AO). Where such retention requirements exist, the data is deleted at the end of these retention periods.

 

F.1. Contact Form

If you send us inquiries via the contact form, the information you provide in the inquiry form—including the contact details you enter there—will be stored by us for the purpose of processing the inquiry and in case of follow-up questions. We do not share this data without your consent.

This data is processed pursuant to Article 6(1)(b) of the GDPR if your inquiry relates to the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, processing is based on our legitimate interest in the effective handling of inquiries addressed to us (Art. 6 (1) (f) GDPR) or on your consent (Art. 6 (1) (a) GDPR) where this has been requested; consent may be withdrawn at any time.

The data you enter in the contact form will remain with us until you ask us to delete it, withdraw your consent to its storage, or the purpose for storing the data no longer applies (e.g., after your inquiry has been processed). Mandatory statutory provisions—in particular retention periods—remain unaffected.

If you contact us by email, telephone, or fax, your inquiry—including all resulting personal data (name, inquiry)—will be stored and processed by us for the purpose of handling your request. We do not share this data without your consent.

This data is processed pursuant to Article 6(1)(b) of the GDPR if your inquiry relates to the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, processing is based on our legitimate interest in the effective handling of inquiries addressed to us (Art. 6 (1) (f) GDPR) or on your consent (Art. 6 (1) (a) GDPR) where this has been requested; consent may be withdrawn at any time.

The data you send us through contact inquiries will remain with us until you ask us to delete it, withdraw your consent to its storage, or the purpose for storing the data no longer applies (e.g., after your request has been processed). Mandatory statutory provisions—in particular statutory retention periods—remain unaffected.

F.2. Career Portal

To process applications for job postings and manage our talent pool, we use the career portal provided by Rexx Systems, which is linked on our website.

Applicants’ personal data is processed within the portal based on the users’ consent pursuant to Article 6(1)(a) of the GDPR. Users may withdraw this consent at any time, which will result in the deletion of the stored personal data.

When registering on our career portal, users can choose to submit their information only as an application for a specific job opening, or to also consent to being included in our applicant pool.

Stored data is deleted no later than six months after the recruitment process is completed. If the user has consented to being included in the applicant pool, the data is deleted no later than two years after it is stored or upon an informal request by the user.

 

G. Cookies

This website uses cookies, which are small files stored by the user’s browser on their device. Some features of the website cannot be provided without the use of technically necessary cookies. Other cookies enable various types of analysis. For example, some cookies can recognize the browser used when the website is visited again and transmit various information to the site operator. Cookies are used to make the website easier and more enjoyable to use. Among other things, cookies help make our online offering more user-friendly and effective by tracking how the website is used and identifying preferred settings (e.g., country and language settings). When third parties process information via cookies, they collect it directly through the browser. Cookies do not cause any damage to the device. They cannot run programs and do not contain viruses. Various types of cookies are used on this website; their types and functions are explained below:

  1. Temporary cookies

This website uses so-called temporary cookies, or session cookies, which are automatically deleted as soon as the browser is closed. This type of cookie makes it possible to store a so-called session ID. As a result, various browser requests can be assigned to a single session, and the user’s device can be recognized on subsequent visits to the website.

  1. Persistent cookies

So-called permanent cookies are also used. Permanent cookies are cookies that are stored in the user’s browser for an extended period and can transmit information. The storage period varies depending on the cookie. Permanent cookies can be deleted manually through the browser settings.

  1. Third-party cookies

In addition, analytical cookies are used to track anonymized user behavior on the website.

In addition, advertising cookies are used to track user behavior for advertising and targeted marketing purposes.

Social media cookies make it possible to connect to the user's social networks and to share website content within the user's networks.

You can configure your browser so that you are notified when cookies are set and can choose to allow cookies only on a case-by-case basis, block cookies in certain cases or in general, and enable the automatic deletion of cookies when you close your browser. If cookies are disabled, the functionality of this website may be limited.

You can find out which cookies and services are used on this website in this privacy policy.

Our website uses Complianz’s consent technology to obtain your consent to the storage of certain cookies on your device or to the use of certain technologies, and to document this in compliance with data protection laws. The provider of this technology is Complianz B.V., Kalmarweg 14-5, 9723 JG Groningen, the Netherlands (hereinafter “Complianz”).

Complianz is hosted on our servers, so no connection is established to the Complianz provider’s servers. Complianz stores a cookie in your browser to track the consents you have given or withdrawn. The data collected in this way is stored until you ask us to delete it, delete the Complianz cookie yourself, or the purpose for storing the data no longer applies. Mandatory statutory retention requirements remain unaffected.

 

H. Tracking and Analytics Tools

H.1. Google Analytics

This website uses features of the web analytics service Google Analytics. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Google Analytics uses technologies that make it possible to identify the user for the purpose of analyzing user behavior (e.g., cookies or device fingerprinting). The information collected by Google regarding the use of this website is typically transmitted to a Google server in the United States and stored there. This service is used based on your consent pursuant to Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG. You may withdraw your consent at any time.

Data transfers to the United States are based on the European Commission's Standard Contractual Clauses. Details can be found here: https://privacy.google.com/businesses/controllerterms/mccs/.

The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the United States intended to ensure compliance with European data protection standards for data processing in the United States. Every company certified under the DPF commits to complying with these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780.

  • IP anonymization

The IP anonymization feature is enabled on this website. As a result, Google truncates the user’s IP address within member states of the European Union or in other contracting states of the Agreement on the European Economic Area before transmitting it to the United States. Only in exceptional cases is the full IP address transmitted to a Google server in the United States and truncated there. On behalf of the operator of this website, Google will use this information to evaluate the use of the website, to compile reports on website activity, and to provide the website operator with additional services related to website and internet usage. The IP address transmitted by the browser as part of Google Analytics is not combined with other Google data.

  • Browser plugin

Users can prevent cookies from being stored by adjusting their browser settings accordingly; however, please note that in this case, they may not be able to use all features of this website to their full extent. In addition, users can prevent Google from collecting the data generated by the cookie and related to their use of the website (including the IP address), as well as from processing this data, by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=de.

For more information on how Google Analytics handles user data, see Google’s privacy policy: https://support.google.com/analytics/answer/6004245?hl=de.

  • Objection to Data Collection

Users can prevent Google Analytics from collecting data by clicking on the following link. An opt-out cookie will be set to prevent data collection on future visits to this website: Disable Google Analytics.

H.2. Microsoft Clarity

We use the analytics service Microsoft Clarity on our website (operated by Microsoft Corporation, One Microsoft Way, Redmond, WA 98052, USA; EU representative: Microsoft Ireland Operations Limited, Dublin).

  • Purpose of Processing

Clarity helps us understand how visitors navigate our website (e.g., which buttons they click, how far they scroll, and what content interests them). To this end, Clarity generates heat maps and recordings of individual sessions. This helps us make our website more user-friendly and efficient.

  • Type of data collected

The information collected includes, among other things:

  • Clicks, mouse movements, and scrolling activity.
  • The device's IP address.
  • Screen size and device type.
  • Browser information and operating system.
  • Geographical location (country only).
  • Preferred language.

Clarity sets cookies for this purpose (including _clck and _clsk).

Note: Personal information entered in form fields is rendered unrecognizable through technical “masking” and is not collected.

  • Legal basis

Data processing is carried out exclusively on the basis of your explicit consent pursuant to Article 6(1)(a) of the GDPR. Data collection does not begin until you have given your consent via our cookie banner.

  • Data Transfer to the United States

The data is processed on Microsoft servers, including those in the United States. Microsoft is certified under the EU-U.S. Data Privacy Framework.

  • Retention Period and Withdrawal

Microsoft generally deletes session recordings after 30 days; individual flagged or randomly sampled recordings are retained for up to 9 months. You can withdraw your consent at any time, effective for the future, through the cookie settings on our website. For more information, see the Microsoft Privacy Statement: https://privacy.microsoft.com/en-us/privacystatement.

H.3. Google Tag Manager

We use Google Tag Manager. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Google Tag Manager is a tool that allows us to integrate tracking and analytics tools and other technologies into our website. Google Tag Manager itself does not create user profiles, does not store cookies, and does not perform any independent analyses. It is used solely to manage and deploy the tools integrated through it. However, Google Tag Manager does collect your IP address, which may also be transferred to Google’s parent company in the United States.

Google Tag Manager is used pursuant to Art. 6 (1) (f) of the GDPR. The website operator has a legitimate interest in the quick and straightforward integration and management of various tools on its website. If appropriate consent has been requested, processing is carried out exclusively on the basis of Article 6(1)(a) of the GDPR and § 25(1) of the TDDDG, insofar as the consent includes the storage of cookies or access to information on the user’s device (e.g., device fingerprinting) within the meaning of the TDDDG. Consent may be withdrawn at any time.

The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the United States intended to ensure compliance with European data protection standards for data processing in the United States. Every company certified under the DPF commits to complying with these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780.

H.4. Matomo

  • Type of data collected

On our career portal (the “Rexx Systems” website), data is collected and stored for marketing and optimization purposes using the web analytics software Matomo (www.matomo.org). Pseudonymized usage profiles are created from this data, for which cookies are used. Cookies are small text files that are stored locally in the cache of the site visitor’s web browser. The cookies enable the web browser to be recognized. The data collected using Matomo technology (including your anonymized IP address) is transmitted to the “Rexx Systems” server and stored for usage analysis purposes, which helps optimize the website. The information generated by the cookie in the pseudonymized user profile is not used to personally identify the website visitor and is not combined with personal data about the holder of the pseudonym. You can prevent the use of cookies—and thus participation in tracking—by adjusting your browser settings accordingly; however, in this case, you may not be able to use all features of this website to their full extent.

  • Legal basis

The legal basis for processing users' personal data is Article 6(1)(a) of the GDPR.

  • Purpose of Processing

Processing users’ personal data enables us to analyze our users’ browsing behavior. By evaluating the data obtained, we are able to compile information on the use of the individual components of the website. This helps us continuously improve the website and its user-friendliness. Data is collected and stored only with explicit consent pursuant to Article 6(1)(a) of the GDPR.

  • Retention period

The storage period varies depending on the type of cookie used. Temporary cookies (also known as session cookies) are deleted at the latest after a user has left an online service and closed it on their device (e.g., browser or mobile app). Permanent cookies remain stored even after you leave the website or app, etc., until you delete them or they are deleted automatically after a predefined period, which varies depending on the cookie and may be several years.

Cookies are stored on the user’s computer and transmitted from it to the “Rexx Systems” website. You therefore have full control over the use of cookies. By changing the settings in your web browser, you can disable or restrict the transmission of cookies. Cookies that have already been stored can be deleted at any time. This can also be done automatically. If cookies are disabled for our website, you may no longer be able to use all of the website’s features to their full extent. Further information on the privacy settings of the Matomo software can be found at the following link: https://matomo.org/docs/privacy/

 

I. Plugins and Tools

I.1. Google Maps

This website uses the Google Maps service via an API. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

To use the features of Google Maps, the user’s IP address must be stored. This information is typically transmitted to a Google server in the United States and stored there. The provider of this website has no control over this data transfer.

Google Maps is used to present our online offerings in an appealing way and to make it easy to find the locations listed on the website. This constitutes a legitimate interest within the meaning of Article 6(1)(f) of the GDPR.

More information on the handling of user data can be found in Google’s privacy policy: https://www.google.de/intl/de/policies/privacy/.

I.2. Instagram

This website incorporates features from the Instagram service. These features are provided by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.

When the social media feature is active, a direct connection is established between your device and the Instagram server. As a result, Instagram receives information about your visit to this website.

If you are logged into your Instagram account, you can link the content of this website to your Instagram profile by clicking the Instagram button. This allows Instagram to associate your visit to this website with your user account. Please note that, as the provider of these pages, we have no knowledge of the content of the data transmitted or of how Instagram uses it.

This service is provided based on your consent pursuant to Article 6(1)(a) of the GDPR and § 25(1) of the TDDDG. You may withdraw your consent at any time.

To the extent that personal data is collected on our website using the tool described here and transmitted to Facebook or Instagram, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbor, Dublin 2, Ireland, are jointly responsible for this data processing (Art. 26 GDPR). Joint responsibility is limited exclusively to the collection of the data and its transmission to Facebook or Instagram. Processing by Facebook or Instagram after the data has been transmitted is not part of the joint responsibility. The obligations incumbent upon us jointly have been set forth in a joint processing agreement. The text of the agreement can be found at:

https://www.facebook.com/legal/controller_addendum. Under this agreement, we are responsible for providing data protection information when using the Facebook or Instagram tool and for ensuring that the tool is implemented on our website in compliance with privacy regulations. Facebook is responsible for the data security of Facebook and Instagram products. You can exercise your data subject rights (e.g., requests for information) regarding the data processed by Facebook or Instagram directly with Facebook. If you exercise your data subject rights with us, we are obligated to forward them to Facebook.

Data transfers to the United States are based on the European Commission's Standard Contractual Clauses. Details can be found here: https://www.facebook.com/legal/EU_data_transfer_addendum, https://privacycenter.instagram.com/policy/, and https://de-de.facebook.com/help/566994660333381.

Further information can be found in Instagram's privacy policy:

https://privacycenter.instagram.com/policy/.

The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the United States intended to ensure compliance with European data protection standards for data processing in the United States. Every company certified under the DPF commits to complying with these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/4452.

I.3. Facebook

For our Facebook presence, we use the technical platform and services provided by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.

Please note that you use the Facebook page and its features at your own risk. This applies in particular to interactive features (e.g., commenting, sharing, rating). Meta processes personal data related to your account, your IP address, and the devices you use; cookies are used to collect data. These are small files that are stored on your devices. Meta describes in general terms what information it receives and how it is used in its privacy policy. There you will also find information on how to contact Meta, on your options to object, and on the settings available for advertisements.

Meta may use this information to provide us, as the operator of the Facebook pages, with statistical data about the use of the Facebook page, such as gender and age distribution. In addition, Meta may show you additional information or advertisements based on your preferences. For more information, please visit the Meta Help Center.

The data collected about you in this context is processed by Meta Platforms Ireland Ltd and may be transferred to countries outside the European Union.

If you visit one of our social media pages (e.g., Facebook), such a visit triggers the processing of your personal data. In this case, we are jointly responsible with the operator of the respective social network for the data processing operations within the meaning of Article 26 of the GDPR, provided that we actually make a joint decision with the operator of the social network regarding the data processing and also exercise influence over the data processing. Where possible, we have entered into joint controller agreements pursuant to Article 26 of the GDPR with the operators of the social networks, in particular Meta Ireland Ltd’s Page Controller Addendum. In principle, you may exercise your rights (right of access pursuant to Article 15 of the GDPR, right to rectification pursuant to Article 16 of the GDPR, right to erasure pursuant to Article 17 of the GDPR, right to restriction of processing pursuant to Article 18 of the GDPR, right to data portability pursuant to Article 20 of the GDPR, and right to lodge a complaint pursuant to Article 77 of the GDPR) both against us and against the operator of the respective social network (e.g., Facebook).

Please note that, despite sharing responsibility with social network operators under Article 26 of the GDPR, we do not have full control over how individual social networks process data. The corporate policy of the respective provider significantly limits our options. If data subject rights are exercised, we may only be able to forward these requests to the social network operator.

Meta does not state conclusively and clearly—and we do not know—how Meta uses data from visits to Facebook pages for its own purposes, to what extent activities on the Facebook page are attributed to individual users, how long Meta stores this data, and whether data from a visit to the Facebook page is shared with third parties.

When a Facebook page is accessed, the IP address assigned to your device is transmitted to Meta. According to Meta, this IP address is anonymized (for “German” IP addresses) and deleted after 90 days. Meta also stores information about its users’ devices (for example, as part of the “login notification” feature); this may enable Meta to associate IP addresses with individual users.

If you are currently logged into Facebook as a user, there is a cookie containing your Facebook ID on your device. This allows Meta to track that you have visited this page and how you have used it. This also applies to all other Facebook pages. Facebook buttons integrated into websites allow Meta to record your visits to these websites and associate them with your Facebook profile. Based on this data, content or advertising can be tailored to you.

If you wish to avoid this, you should log out of Facebook or disable the “stay logged in” feature, delete the cookies on your device, and close and restart your browser. This will delete any Facebook information that can directly identify you. This allows you to use our Facebook page without revealing your Facebook ID. If you access interactive features on the page (Like, Comment, Share, Messages, etc.), a Facebook login screen will appear. After logging in, Facebook will once again recognize you as a specific user. Alternatively, you can use a different browser than usual to visit our Facebook page.

Information on how you can manage or delete existing information about yourself can be found in the Meta Privacy Center.

Beyond that, we, as the provider of this information service, do not collect or process any data resulting from your use of our service.

I.4. YouTube

This website embeds videos from YouTube. The operator of the website is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.

When you visit one of our web pages that has YouTube embedded, a connection to YouTube’s servers is established. In the process, the YouTube server is informed which of our pages you have visited.

Furthermore, YouTube may store various cookies on your device or use similar recognition technologies (e.g., device fingerprinting). In this way, YouTube can obtain information about visitors to this website. This information is used, among other things, to collect video statistics, improve the user experience, and prevent fraud. The collected data is also processed within Google’s advertising network.

If you are logged into your YouTube account, you allow YouTube to associate your browsing activity directly with your personal profile. You can prevent this by logging out of your YouTube account.

YouTube is used to ensure an appealing presentation of our online offerings. This constitutes a legitimate interest within the meaning of Article 6(1)(f) of the GDPR. If appropriate consent has been requested, processing is carried out exclusively on the basis of Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG, insofar as the consent includes the storage of cookies or access to information on the user’s device (e.g., device fingerprinting) within the meaning of the TDDDG. Consent may be withdrawn at any time.

Further information on the handling of user data can be found in YouTube’s privacy policy at: https://policies.google.com/privacy?hl=de.

The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the United States intended to ensure compliance with European data protection standards for data processing in the United States. Every company certified under the DPF commits to complying with these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780.

  1. Disclosure of Data to Third Parties

In the course of our business activities, we work with various external parties. In some cases, this also requires the transfer of personal data to these external parties.

Except for disclosures required by law, we only share users’ personal data with third parties if:

  1. a) explicit consent has been given pursuant to Article 6(1)(a) of the GDPR;
  2. b) this is legally permissible and necessary pursuant to Article 6(1)(a) of the GDPR for the performance of a contractual relationship with users or for the implementation of pre-contractual measures;
  3. c) there is a legal obligation under Article 6(1)(c) of the GDPR to transfer the data to public authorities, such as tax authorities, social insurance agencies, health insurance funds, supervisory authorities, and law enforcement agencies;
  4. d) the disclosure is necessary pursuant to Article 6(1)(f) of the GDPR to protect legitimate business interests or to establish, exercise, or defend legal claims, and there is no reason to believe that the user has an overriding legitimate interest in the data not being disclosed;
  5. e) External service providers (so-called processors) who are required to handle the data with care are used for processing in accordance with Article 28 of the GDPR.

Service providers are used in the following areas:

  • IT
  • Logistics
  • Telecommunications
  • Sales
  • Marketing

When data is transferred to external parties in third countries—that is, outside the EU or the EEA—we ensure that these parties handle users’ personal data with the same care as within the EU or the EEA.

Personal data is transferred to third countries only if the European Commission has confirmed that they provide an adequate level of protection, or if the careful handling of personal data is ensured by contractual agreements or other appropriate safeguards.

 

J.1. Hosting

We host the content of our website with the following provider:

IONOS

The provider is IONOS SE, Elgendorfer Str. 57, D-56410 Montabaur, Germany (hereinafter "IONOS"). When you visit our website, IONOS records various log files, including your IP addresses. For details, please refer to the IONOS privacy policy:

https://www.ionos.de/terms-gtc/terms-privacy.

IONOS is used pursuant to Art. 6 (1) (f) GDPR. We have a legitimate interest in ensuring that our website is displayed as reliably as possible. If appropriate consent has been requested, processing is carried out exclusively on the basis of Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG, insofar as the consent includes the storage of cookies or access to information on the user’s device (e.g., device fingerprinting) within the meaning of the TDDDG. Consent may be withdrawn at any time.

For security reasons and to protect the transmission of confidential information, such as orders or inquiries that you send to us as the site operator, this site uses SSL or TLS encryption. You can tell that a connection is encrypted because the address bar in your browser changes from “http://” to “https://” and because a lock icon appears in your browser’s address bar.

When SSL or TLS encryption is enabled, the data you send to us cannot be read by third parties.

J.2. Data Transfer to Creditreform

When contracts are concluded—and, in certain cases where there is a legitimate interest, also for existing customers—a credit check is performed. For this purpose, we work with Creditreform Boniversum GmbH, Hellersbergstraße 11, D-41460 Neuss, Germany, from which we obtain the necessary data. On behalf of Creditreform Boniversum, the following information is provided in advance pursuant to Article 14 of the EU GDPR:

Creditreform Boniversum GmbH is a consumer credit reporting agency. It operates a database that stores creditworthiness information about private individuals. Based on this information, Creditreform Boniversum provides credit reports to its customers. Customers include, for example, credit institutions, leasing companies, insurance companies, telecommunications companies, debt management companies, mail-order, wholesale, and retail companies, and other companies that supply goods or provide services. Within the framework of statutory provisions, some of the data held in the credit reporting database is also used to supply other corporate databases, including for address trading purposes. The Creditreform Boniversum database stores, in particular, information on the name, address, date of birth, email address (where applicable), payment history, and shareholdings of individuals. The purpose of processing the stored data is to provide information on the creditworthiness of the person in question. The legal basis for processing is Article 6(1)(f) of the EU GDPR. Accordingly, information about this data may only be provided if a customer credibly demonstrates a legitimate interest in knowing this information. Where data is transferred to countries outside the EU, this is done on the basis of the so-called “Standard Contractual Clauses,” which can be accessed via the following link:

http://eur-lex.europa.eu/legal-content/DE/TXT/PDF/?uri=CELEX:32001D0497&from=DE

The data is stored for as long as it is necessary to fulfill the purpose of storage. As a general rule, access to the data is necessary for an initial storage period of three years. After this period, a review is conducted to determine whether further storage is still necessary; otherwise, the data is deleted on the specified date. If a matter has been resolved, the data is deleted on the specified date three years after resolution. Entries in the debtors’ register are deleted on the specified date three years after the date of the registration order, in accordance with § 882e of the German Code of Civil Procedure (ZPO).

Legitimate interests within the meaning of Article 6(1)(f) of the EU GDPR may include: credit decisions, establishing business relationships, shareholdings, accounts receivable, credit checks, insurance contracts, and enforcement information.

The user has the right to obtain information from Creditreform Boniversum GmbH regarding the data stored there about them. If the stored data is incorrect, the user has the right to have it corrected or deleted. If it cannot be determined immediately whether the data is incorrect or correct, the user has the right to have the data in question blocked until the matter is clarified. If the data is incomplete, the user may request that it be completed.

If consent has been given for the processing of data stored by Creditreform Boniversum, you have the right to withdraw that consent at any time.

The withdrawal of consent does not affect the lawfulness of the processing carried out on the basis of consent prior to its withdrawal.

In the event of objections, requests, or complaints regarding data protection, you may contact the Data Protection Officer at Creditreform Boniversum at any time. The Data Protection Officer will provide prompt and confidential assistance with all data protection matters. The right to file a complaint with the competent state data protection commissioner remains unaffected.

The data stored by Creditreform Boniversum comes from publicly available sources, debt collection agencies, and their customers. To assess creditworthiness, Creditreform Boniversum calculates a score based on this data. The score takes into account information on age and gender, address information, and, in some cases, payment history. These factors are weighted differently in the calculation of the score. Creditreform Boniversum’s customers use the scores as a tool to help them make their own credit decisions.

 

Right to object:

The stored data is processed for compelling legitimate reasons related to creditor and credit protection, which generally take precedence over the interests, rights, and freedoms of the user, or for the establishment, exercise, or defense of legal claims. The user may object to the processing of their data only on grounds arising from their particular situation, which must be substantiated. If such particular grounds are demonstrably present, the data will no longer be processed.

The controller within the meaning of Article 4(7) of the EU GDPR is Creditreform Boniversum GmbH, Hellersbergstr. 11, D-41460 Neuss, Germany. The contact is Consumer Service, Tel.: +492131 36845560, Fax: +492131 36845570, Email: selbstauskunft@boniversum.de.

The Data Protection Officer can be contacted at: Creditreform Boniversum GmbH, Data Protection Officer, Hellersbergstr. 11, D-41460 Neuss, Germany, Email: datenschutz@boniversum.de.