STATICS Privacy Policy
1. General Information
1.1 Purpose of this Privacy Policy
We would like to inform you about how we handle your personal data and what rights you have under the European General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG). Responsibility for the data processing lies with the organization STATICS Holding GmbH (hereinafter referred to as "we" or "us").
1.2 Controller and Data Protection Officer
1.3 Controller
The controller responsible for the processing of your personal data is:
STATICS Holding GmbH
Maximilian Lang, Melanie Groß & Kirsten Wilhelm
Stephansplatz 3 – Alte Oberpostdirektion
20354 Hamburg, Germany
Phone: +49 40 604297717
E-mail: info@statics-group.de
1.4 Contact Details of the Data Protection Officer
You can reach our Data Protection Officer at the following contact details:
Iqanta GmbH
Sven Weschler
Boschstrasse 23a
22761 Hamburg, Germany
E-mail: kontakt@iqanta.com
Phone: +49 40 357 014 60
1.5 Legal Bases for the Processing of Personal Data
"Personal data" means any information relating to an identified or identifiable person. We process such data in accordance with the applicable data protection laws, in particular the GDPR and the BDSG. We may only process personal data where a legal basis permits us to do so.
We process personal data only with your consent, in order to conclude a contract with you or to respond to your inquiry in connection with a potential business relationship, to fulfil legal obligations, or to protect our legitimate interests, provided this does not override your interests or fundamental rights and freedoms that require the protection of personal data.
2. Information on Individual Processing Activities
2.1 Processing for the Operation of the APP
We process your personal data to the extent necessary for the technical and functional operation of the APP / web application. This includes in particular:
Providing the APP functions and your user account
Ensuring the stability and security of the systems
Error analysis and improvement of performance and usability
The following categories of personal data may in particular be processed for the operation of the APP:
Master data (e.g. name, user ID)
Contact data (e.g. e-mail address)
Usage data (e.g. functions used, times of use)
Technical log and device data (e.g. IP address, device/browser information, log files)
The legal basis for this processing is generally Art. 6(1)(b) GDPR (performance of the usage agreement or implementation of pre-contractual measures), insofar as the data is required to provide the APP and its functions.
Insofar as the processing additionally serves to ensure IT security, error analysis, and optimization of the APP, it is carried out on the basis of our legitimate interest under Art. 6(1)(f) GDPR in a secure, stable, and user-friendly operation of the APP.
The data is generally collected
directly from you as part of registration and use of the APP, and
automatically through the device you use or through the technical infrastructure we operate (e.g. server log files).
We store the personal data only for as long as this is necessary for the operation of the APP and the fulfilment of the stated purposes, or as required by statutory retention obligations. Technical log data and log files are generally deleted or anonymized after an appropriate period, unless they are still required for error analysis, ensuring IT security, or for the assertion, exercise, or defence of legal claims.
2.2 STATICS Mind APP / Web Application
We process your personal data insofar as this is necessary to fulfil the following purposes:
Operation of the STATICS Mind APP / web application
Measurement and training of mental health
For this purpose, personal data relating to your use of the APP or web application is collected and evaluated.
The following categories of personal data may in particular be processed as part of the use of the STATICS Mind APP / web application:
Contact data
Usage data
Meta and communication data
Master data
Image data
Location data
Information on occupation and hobbies
Health data (special categories of personal data within the meaning of Art. 9 GDPR)
The legal basis for this processing is your consent pursuant to Art. 6(1)(a), Art. 7 GDPR.
Insofar as health data within the meaning of Art. 9(1) GDPR (special categories of personal data) is processed, this is done on the basis of your explicit consent pursuant to Art. 9(2)(a) GDPR. Special security measures apply, in particular a detailed authorization concept, a limited group of authorized persons, general technical and organizational measures, encryption, multi-factor authentication, and pseudonymization.
The personal data is collected from the following sources:
directly from you as the data subject
through technically necessary, automatic transmission as part of the use of the APP / web application
The personal data is deleted
as soon as the respective processing purpose has been fulfilled, or
when you withdraw your consent,
provided no statutory retention periods apply.
A decision based solely on automated processing – including profiling – that produces legal effects concerning you or similarly significantly affects you does not currently take place in connection with the use of the STATICS Mind APP / web application.
2.3 Evaluation of Health Questionnaires
We process your personal data insofar as this is necessary to fulfil the following purposes:
Measurement and training of mental health
Implementation of workplace health prevention measures
For this purpose, health data is evaluated in order to derive individual recommendations and measures as part of counselling and health prevention offerings.
The following categories of personal data may in particular be processed as part of the evaluation of health questionnaires:
Contact data
Name
Health data (special categories of personal data within the meaning of Art. 9 GDPR)
The legal basis for this processing is your consent pursuant to Art. 6(1)(a), Art. 7 GDPR.
Insofar as health data within the meaning of Art. 9(1) GDPR is processed, this is done on the basis of your explicit consent pursuant to Art. 9(2)(a) GDPR. Special security measures apply, in particular a detailed authorization concept, a limited group of authorized persons, general technical and organizational measures, encryption, multi-factor authentication, and pseudonymization.
Providing your data as part of the evaluation of health questionnaires is voluntary. You may withdraw your consent at any time with effect for the future, without any disadvantages resulting from this. However, without consent, participation in the relevant evaluations and the counselling and prevention offerings based on them is not possible.
The personal data is collected in particular from the following sources:
from you via an online form
through voluntary self-disclosure
through technically determined measurements that are transmitted into the system
The personal data is deleted as soon as the respective processing purpose has been fulfilled, or when you withdraw your consent, provided no statutory retention periods apply.
A decision based solely on automated processing – including profiling – that produces legal effects concerning you or similarly significantly affects you does not take place as part of the evaluation of health questionnaires.
2.4 Health Day for Employees
We process your personal data insofar as this is necessary to fulfil the following purposes:
Appointment scheduling
Measurement and training of mental health
Implementation of workplace health prevention measures
For this purpose, medical history questionnaires are completed and measurements (e.g. foot and spinal measurements) are carried out as part of the Health Day. Depending on the evaluation of the medical history and measurement results, health promotion recommendations are given. Anonymized data may also be used to analyze and improve the work environment.
The following categories of personal data may in particular be processed as part of the Health Day:
Contact data
Name
Company name
Health data (special categories of personal data within the meaning of Art. 9 GDPR)
The legal basis for this processing is your consent pursuant to Art. 6(1)(a), Art. 7 GDPR.
Insofar as health data within the meaning of Art. 9(1) GDPR is processed, this is done on the basis of your explicit consent pursuant to Art. 9(2)(a) GDPR. Special security measures apply, in particular a detailed authorization concept, a limited group of authorized persons, general technical and organizational measures, encryption, multi-factor authentication, and pseudonymization.
Providing your data as part of the Health Day is voluntary. You may withdraw your consent at any time with effect for the future, without this resulting in any employment-related disadvantages. However, without consent, participation in the Health Day and the performance of the associated measurements, evaluations, and recommendations is not possible.
The personal data is collected in particular from the following sources:
from you as part of registration and participation (medical history questionnaires, other information)
through online tools or procedures used
through technically determined measurements that are transmitted into the system
The personal data is deleted as soon as the respective processing purpose has been fulfilled, or when you withdraw your consent, provided no statutory retention periods apply.
A decision based solely on automated processing – including profiling – that produces legal effects concerning you or similarly significantly affects you does not take place as part of the Health Day for employees.
2.5 Processing as Part of the "STATICS LEAD" Behavioral and Potential Analysis
We conduct the "STATICS LEAD" behavioral analysis in order to identify individual behavioral patterns, potential, and preferences in the work context and – where corresponding consent has been given – to link these with existing results from STATICS Mind.
The processing of your personal data as part of STATICS LEAD is carried out in particular for the following purposes:
Conducting the "STATICS LEAD" behavioral and potential analysis to identify individual behavioral patterns.
Linking the STATICS LEAD results with existing STATICS Mind results to create a combined profile.
Creating and providing an individual results report for coaching, development, or feedback discussions.
Planning and implementing measures for professional development and to promote job satisfaction and performance.
The following categories of personal data may in particular be processed as part of STATICS LEAD:
Master data
Contact data
Responses from the behavioral and potential analysis
Derived profile information
Where applicable, linked STATICS Mind results (including health/stress data with explicit consent).
Participation in STATICS LEAD is generally voluntary. The legal basis for the processing of the data mentioned above is your consent pursuant to Art. 6(1)(a), Art. 7 GDPR. Insofar as, as part of the linking with STATICS Mind, health data or other special categories of personal data within the meaning of Art. 9(1) GDPR are also incorporated into the combined profile, this processing is based on your explicit consent pursuant to Art. 9(2)(a) GDPR.
The data originates in particular from:
your responses in the STATICS LEAD analysis (online questionnaires/tools).
results already available from STATICS Mind (only insofar as you have expressly permitted the linking).
Access to the results and reports is granted – within the framework of a strict authorization concept – exclusively to those persons for whom this is necessary to achieve the purposes mentioned above, e.g.:
internal or external coaches/consultants,
where applicable, direct managers, insofar as this has been expressly named as part of the consent process and accepted by you.
Data is not disclosed to uninvolved third parties.
Participation in the behavioral and potential analysis and the linking with STATICS Mind results is voluntary. You may withdraw your consent at any time with effect for the future. A withdrawal has no effect on your existing employment relationship but may mean that certain development or coaching formats cannot be carried out, or can only be carried out to a limited extent.
The personal data processed as part of STATICS LEAD is stored only for as long as necessary for conducting the analysis, creating and using the results report, and supporting coaching, development, or feedback processes, or as required by statutory retention obligations. It is subsequently deleted or, where possible and permissible, anonymized.
As part of STATICS LEAD, your responses are evaluated algorithmically and combined into behavioral and potential profiles (profiling within the meaning of Art. 4 No. 4 GDPR). However, no decision-making based solely on automated processing within the meaning of Art. 22 GDPR takes place that produces legal effects concerning you or similarly significantly affects you. The results serve exclusively as a basis for personal discussions (coaching, feedback, development) and are always interpreted in dialogue with you.
2.6 Anonymized Evaluation of Health Data
We process your personal data insofar as this is necessary to plan, implement, and evaluate workplace health prevention measures. This is based in particular on:
the results of the evaluation of the health questionnaires answered by you, and
where applicable, the results of physical measurements and gait analyses (e.g. posture, foot, or movement analyses).
On this basis, individual recommendations as well as – in anonymized or aggregated form – preventive measures in the workplace environment are derived.
The following categories of personal data may in particular be processed as part of these prevention measures:
Contact data
Name
Information from the answered health questionnaires
Results of physical measurements and gait analyses (e.g. posture, foot, movement, and load data)
Health data (special categories of personal data within the meaning of Art. 9 GDPR)
The legal basis for this processing is your consent pursuant to Art. 6(1)(a), Art. 7 GDPR.
Insofar as health data within the meaning of Art. 9(1) GDPR is processed, this is done on the basis of your explicit consent pursuant to Art. 9(2)(a) GDPR.
The processed data originates in particular from:
your responses to the provided health questionnaires (online form/questionnaire)
results of physical measurements and gait analyses carried out as part of the prevention offerings and transmitted into the system
where applicable, further voluntary information provided in the course of counselling
Participation in the health questionnaires, physical measurements, gait analyses, and the prevention measures based on them is voluntary. You may withdraw your consent at any time with effect for the future, without any disadvantages resulting from this. However, without consent, participation in the relevant prevention offerings or an individual evaluation based on them is not possible.
The personal data is deleted as soon as the respective processing purpose has been fulfilled (completion of the prevention measure), or when you withdraw your consent, provided no statutory retention obligations apply. Any anonymized or aggregated data from which no personal reference can be established may additionally be used for statistical evaluations and for further development of the prevention offerings.
2.7 Processing for Workplace Health Prevention Measures
We process your personal data insofar as this is necessary to plan, implement, and evaluate workplace health prevention measures. This is based in particular on the results of the evaluation of the health questionnaires answered by you. On this basis, individual recommendations as well as – in anonymized or aggregated form – preventive measures in the workplace environment are derived.
The following categories of personal data may in particular be processed as part of these prevention measures:
Contact data
Name
Information from the answered health questionnaires
Health data (special categories of personal data within the meaning of Art. 9 GDPR)
The legal basis for this processing is your consent pursuant to Art. 6(1)(a), Art. 7 GDPR.
Insofar as health data within the meaning of Art. 9(1) GDPR is processed, this is done on the basis of your explicit consent pursuant to Art. 9(2)(a) GDPR.
The processed data originates in particular from:
your responses to the provided health questionnaires (online form/questionnaire)
where applicable, further voluntary information provided in the course of counselling
Participation in the health questionnaires and the prevention measures based on them is voluntary. You may withdraw your consent at any time with effect for the future, without any disadvantages resulting from this. However, without consent, participation in the relevant prevention offerings or an individual evaluation based on them is not possible.
The personal data is deleted as soon as the respective processing purpose has been fulfilled (completion of the prevention measure), or when you withdraw your consent, provided no statutory retention obligations apply. Any anonymized or aggregated data from which no personal reference can be established may additionally be used for statistical evaluations and for further development of the prevention offerings.
2.8 Processing for Appointment Scheduling (Measurements and Personal Consultations)
For the scheduling of appointments for measurements and personal consultations, we process personal data insofar as this is necessary for the planning, implementation, and administration of the respective appointments.
The data is processed in particular for the following purposes:
Booking and management of appointments
Assigning appointments to individuals
Communication before and after the appointment (e.g. appointment confirmations, reminders, organizational information)
The following categories of personal data may in particular be processed as part of appointment scheduling:
Master data (e.g. name, company affiliation where applicable)
Contact data (e.g. e-mail address, phone number where applicable)
Appointment data (e.g. date, time, duration, reason for the appointment)
Technical usage data as part of the online booking (e.g. IP address, time of booking)
The legal basis for processing your data as part of appointment scheduling is generally Art. 6(1)(b) GDPR (performance of a contract or implementation of pre-contractual measures), insofar as the data is required for the preparation and implementation of the respective appointment.
Insofar as processing operations additionally take place for the technical provision, security, and optimization of the online booking system, we base these on our legitimate interest in an efficient, user-friendly, and secure organization of appointments pursuant to Art. 6(1)(f) GDPR.
Providing the mandatory fields requested as part of appointment scheduling is necessary in order to book and carry out an appointment. Without this information, an appointment cannot be scheduled via the online booking system. Where offered, appointments may alternatively also be arranged via other contact channels (e.g. phone, e-mail).
We store the personal data collected as part of appointment scheduling only for as long as necessary for the planning, implementation, and documentation of the respective appointment, or as required by statutory retention obligations. The data is subsequently deleted or, where possible and permissible, anonymized.
2.9 Newsletter
To register for the newsletter, the data requested during the registration process is required. Newsletter registration is logged. After registration, you will receive a message to the e-mail address provided, asking you to confirm your registration ("double opt-in"). This is necessary to prevent third parties from registering with your e-mail address.
You may withdraw your consent to receive the newsletter at any time and thereby unsubscribe from the newsletter.
We store the registration data for as long as it is needed to send the newsletter. We store the logging of the registration and the sending address for as long as there is an interest in proving the originally given consent, which is generally the limitation period for civil law claims, i.e. a maximum of three years.
The legal basis for sending the newsletter is your consent pursuant to Art. 6(1) sentence 1(a) in conjunction with Art. 7 GDPR in conjunction with Sec. 7(2) No. 3 of the German Act Against Unfair Competition (UWG). The legal basis for logging the registration is our legitimate interest in demonstrating that the newsletter was sent with your consent.
You may cancel your registration at any time, free of charge. A message in text form to the contact details listed under Section 1.3 (e.g. e-mail, fax, letter) is sufficient for this purpose. Of course, you will also find an unsubscribe link in every newsletter.
3. Information on External Specialist Service Providers
3.1 Statics inside (Data Collection and Analysis)
We use the service Statics inside provided by STATICS INSIDE GMBH, Stephansplatz 3, 20354 Hamburg, a company of the Statics Group, to carry out data collection and evaluations for our Mental Health Guidance Tool. Statics inside collects and analyzes the data arising from the use of the tool in order to provide evaluations and metrics for us and – insofar as contractually agreed – for our customers.
The following in particular is processed as part of Statics inside:
usage and interaction data collected by the Mental Health Guidance Tool (e.g. content accessed, clicks, inputs)
results and status data (e.g. scores, evaluation metrics)
basic technical data (e.g. pseudonymous identifiers, timestamps, general device/browser information)
where applicable, customer-related data in pseudonymized or aggregated form
The legal basis for the processing – including any health data processed – is, depending on the specific arrangement, in particular your (explicit) consent pursuant to Art. 6(1)(a), Art. 7, and Art. 9(2)(a) GDPR, the fulfilment of contractual obligations pursuant to Art. 6(1)(b) GDPR, insofar as the evaluations are part of the agreed services, and our legitimate interest pursuant to Art. 6(1)(f) GDPR in the analysis, further development, and secure, economical operation of the Mental Health Guidance Tool as well as in providing meaningful metrics.
Statics inside acts as a processor within the meaning of Art. 28 GDPR for all relevant processing activities. A data processing agreement obliges Statics inside, among other things, to process personal data confidentially and securely, to process it exclusively on our instructions, and to implement appropriate technical and organizational measures.
The data processed as part of Statics inside is stored only for as long as necessary for the described analysis, documentation, and evidentiary purposes and is subject to statutory retention obligations; it is subsequently deleted or, where possible, further anonymized.
3.2 S'TATICS Hamburg GmbH (Measurements and Gait Analyses)
For the performance of measurements and gait analyses, we use S'TATICS Hamburg GmbH, Stephansplatz 3 – Alte Oberpostdirektion, 20354 Hamburg, a company of the Statics Group. The corresponding measurements and analyses in connection with our services are carried out at this location.
The following in particular is processed as part of the measurements and gait analyses:
Master and contact data (e.g. name, contact details, customer number where applicable)
Appointment and contract data (e.g. booked service, time of measurement)
Measurement and analysis data from measurements and gait analyses (e.g. pressure and force measurements, movement profiles, gait patterns, measurement protocols, video/image recordings where applicable)
Health-related information, insofar as necessary for the assessment (e.g. complaints, limitations, medical history information)
The legal basis for the processing – including the processing of health data – is, depending on the specific arrangement, in particular your (explicit) consent pursuant to Art. 6(1)(a), Art. 7, and Art. 9(2)(a) GDPR, the fulfilment of contractual obligations pursuant to Art. 6(1)(b) GDPR, insofar as the measurements and gait analyses are part of the agreed services, and our legitimate interest pursuant to Art. 6(1)(f) GDPR in quality assurance, further development, and the secure, professional provision of our services.
S'TATICS Hamburg GmbH acts as a processor within the meaning of Art. 28 GDPR for all relevant processing activities. A data processing agreement obliges S'TATICS Hamburg GmbH, among other things, to process personal data confidentially and securely, to process it exclusively on our instructions, and to implement appropriate technical and organizational measures.
The data processed as part of the measurements and gait analyses is stored only for as long as necessary for the described analysis, documentation, and evidentiary purposes and is subject to statutory retention obligations; it is subsequently deleted or, where possible, further anonymized.
3.3 StepChange Consulting GmbH (Online Consultations and Coaching)
For the provision of personal consultations and coaching in online format, we use StepChange Consulting GmbH, Friedingstraße 37, 40625 Düsseldorf, a company of the Statics Group. StepChange Consulting provides individual consultation and coaching services for us – and, insofar as contractually agreed, also for our customers – via online communication.
The following in particular is processed as part of online consultations and coaching:
Master and contact data (e.g. name, contact details, customer number where applicable)
Appointment and contract data (e.g. booked services, participation status, session duration)
Substantive information from the consultation and coaching discussions (e.g. goals, questions, professional situation, personal preferences, stress factors where applicable)
Documentation and progress data (e.g. notes, protocols, interim results, agreed measures)
Technical metadata of the online sessions (e.g. timestamps, communication channels used, in general form)
Insofar as, as part of the consultations and coaching, information with a particular personal reference (e.g. relating to health, psychological stress, or similar sensitive topics) is also provided, this may be classified as special categories of personal data within the meaning of Art. 9 GDPR.
The legal basis for the processing – including any special categories of personal data processed – is, depending on the specific arrangement, in particular your (explicit) consent pursuant to Art. 6(1)(a), Art. 7, and where applicable Art. 9(2)(a) GDPR, the fulfilment of contractual obligations pursuant to Art. 6(1)(b) GDPR, insofar as the consultation and coaching services are part of the agreed services, and our legitimate interest pursuant to Art. 6(1)(f) GDPR in quality assurance, further development, and the secure, professional provision of our services.
StepChange Consulting GmbH acts as a processor within the meaning of Art. 28 GDPR for all relevant processing activities. A data processing agreement obliges StepChange Consulting, among other things, to process personal data confidentially and securely, to process it exclusively on our instructions, and to implement appropriate technical and organizational measures.
The data processed as part of the online consultations and coaching is stored only for as long as necessary for the described consultation, documentation, and evidentiary purposes and is subject to statutory retention obligations; it is subsequently deleted or, where possible, further anonymized.
3.4 Use of JobMatch ("STATICS LEAD" Behavioral and Potential Analysis)
For the implementation and evaluation of the "STATICS LEAD" behavioral and potential analysis, we use the online diagnostic tool JobMatch provided by JobMatch Deutschland GmbH, Telleringstr. 30, 40597 Düsseldorf, Germany.
JobMatch provides the online questionnaires and evaluation functions. Via JobMatch, in particular the data used as part of STATICS LEAD is processed, e.g.:
Identification/master data (e.g. name or participant ID, organization/role where applicable)
Contact data (e.g. e-mail address for invitations/assignment)
Responses in the STATICS LEAD questionnaires
Profile and scale values calculated from these
A substantive description of the STATICS LEAD behavioral and potential analysis and the data processed there is provided in a separate section of this privacy policy.
The use of JobMatch to carry out STATICS LEAD is based on the same legal basis as the analysis itself, generally your consent pursuant to Art. 6(1)(a), Art. 7 GDPR.
Insofar as, as part of STATICS LEAD, special categories of personal data (e.g. health or stress data as part of a linking with STATICS Mind) are processed, this is done only on the basis of your explicit consent pursuant to Art. 9(2)(a) GDPR.
JobMatch Deutschland GmbH acts as a processor within the meaning of Art. 28 GDPR for us in this regard. Processing is carried out exclusively on our instructions on the basis of a data processing agreement with appropriate technical and organizational measures to protect your data.
Further information on the processing of data by JobMatch Deutschland GmbH can be found in the provider's privacy notices at https://www.jobmatchtalent.de/datenschutzerklaerung/
3.5 Use of Idiag AG (Medical Measurement and Analysis Systems)
For certain health-related measurements and evaluations (e.g. spinal and posture analyses, other medical measurements), we use systems and services provided by Idiag AG, Staffelstrasse 12, CH-8045 Zurich, Switzerland.
The involvement of Idiag AG serves in particular the following purposes:
Performance and evaluation of medical-technical measurements (e.g. spinal/posture analyses)
Provision and operation of the measurement and analysis systems used for this purpose
Support in preparing reports and evaluations on workplace prevention and health measures
In connection with the use of the Idiag systems, the following categories of personal data may in particular be affected, depending on the offering used:
Master data (e.g. name, identification or participant ID)
Contact data (e.g. e-mail address, where necessary for assignment/invitation)
Measurement and health data (e.g. measured values relating to posture, spine, movement patterns)
Where applicable, further information on health and physical condition as part of the respective offering
The underlying processing operations (measurements, evaluations, and prevention measures based on them) are carried out on the legal bases described in this privacy policy, in particular:
your consent pursuant to Art. 6(1)(a), Art. 7 GDPR,
insofar as health data within the meaning of Art. 9(1) GDPR is processed, your explicit consent pursuant to Art. 9(2)(a) GDPR.
The involvement of Idiag AG as a technical service provider is based on the same legal basis as the underlying primary processing in each case.
Idiag AG acts for us as a service provider/processor within the meaning of Art. 28 GDPR. A data processing agreement has been concluded with Idiag AG, which governs, among other things,
the processing of personal data exclusively on our instructions,
appropriate technical and organizational measures to protect the data, and
confidentiality and data security.
The data is transferred to Switzerland. An adequacy decision by the European Commission exists for Switzerland, confirming that a level of data protection comparable to the EU is guaranteed there. The transfer of personal data to Switzerland is therefore permissible under Chapter V GDPR.
The personal data processed by Idiag AG as part of the measurements and evaluations is stored only for as long as necessary for the implementation of the respective measure, the preparation of the evaluation, and the fulfilment of statutory obligations. It is subsequently deleted or, where possible and permissible, anonymized.
Further information on the processing of data by Idiag AG can be found in the privacy notices on the provider's website at https://www.idiag.ch.
3.6 Use of molibso Entwicklungs- und Vertriebs GmbH (Measurement Systems and Analyses)
For certain measurements and evaluations related to movement, posture, and health analyses, we use systems and services provided by molibso Entwicklungs- und Vertriebs GmbH, Karl-Benz-Straße 1, 40764 Langenfeld (Rhineland), Germany.
The involvement of molibso Entwicklungs- und Vertriebs GmbH serves in particular the following purposes:
Performance and evaluation of biomechanical measurements (e.g. foot, gait, or posture analyses)
Provision and technical operation of the measurement and analysis systems used for this purpose
Support in preparing reports and evaluations as part of workplace health and prevention measures
In connection with the use of the molibso systems, the following categories of personal data may in particular be affected, depending on the offering used:
Master data (e.g. name, identification or participant ID)
Contact data (e.g. e-mail address, where necessary for assignment/invitation)
Measurement and movement data (e.g. gait pattern, pressure distribution, posture data)
Health data (special categories of personal data within the meaning of Art. 9 GDPR), insofar as health-related conclusions are drawn from the measurements
Processing takes place only to the extent necessary for the performance of the respective measurements and evaluations.
The underlying processing operations (measurements, evaluations, and prevention measures based on them) are carried out on the legal bases described in this privacy policy, in particular:
your consent pursuant to Art. 6(1)(a), Art. 7 GDPR,
insofar as health data within the meaning of Art. 9(1) GDPR is processed, your explicit consent pursuant to Art. 9(2)(a) GDPR.
The involvement of molibso Entwicklungs- und Vertriebs GmbH as a technical service provider is based on the same legal basis as the underlying primary processing in each case.
molibso Entwicklungs- und Vertriebs GmbH acts for us as a processor within the meaning of Art. 28 GDPR. A data processing agreement has been concluded with the company, which governs, among other things,
the processing of personal data exclusively on our instructions,
appropriate technical and organizational measures to protect the data, and
confidentiality and data security.
Further information on the processing of data by molibso Entwicklungs- und Vertriebs GmbH can be found in the privacy notices on the provider's website at https://molibso.com/.
The personal data processed by molibso Entwicklungs- und Vertriebs GmbH as part of the measurements and evaluations is stored only for as long as necessary for the implementation of the respective measure, the preparation of the evaluation, and the fulfilment of statutory obligations. It is subsequently deleted or, where possible and permissible, anonymized.
4. Information on External IT Service Providers and Online Tools
4.1 Use of Hetzner for Hosting and Server Services
For the hosting of our platform and the provision of the technical IT infrastructure, we use services provided by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany.
Personal data is processed on servers within the European Union. Hetzner provides us in particular with server, storage, and data center services that we require for the operation of our systems and applications (provision of the platform/APP, stability, performance, IT security).
The following data may, among other things, be processed as part of the hosting:
content and usage data processed via our platform/APP (e.g. inputs, access times, functions used)
technical connection and log data (e.g. IP address, time of access, pages/resources accessed, browser/device information, log files)
The legal bases are Art. 6(1)(b) GDPR (insofar as the operation of the platform/APP is necessary for contract performance) and Art. 6(1)(f) GDPR (legitimate interest in a secure, stable, and efficient operation of our IT systems and online offerings).
Hetzner acts as a processor pursuant to Art. 28 GDPR. A data processing agreement governs in particular the processing exclusively on our instructions, appropriate technical and organizational measures, and confidentiality and data security.
Server log data and other technical logs are stored only for as long as necessary for operation, error analysis, and IT security, or as required by statutory retention obligations; they are subsequently deleted or anonymized.
4.2 K&W Media Consulting GmbH (Development and Operation of Online Offerings)
For the development, technical support, and operation of our online offerings (including web applications, platforms, apps, and related evaluations), we use the services of K&W Media Consulting GmbH, Willy-Brandt-Straße 51, 20457 Hamburg, Germany.
K&W supports us in particular with the development and further development of the STATICS online offerings, technical operation, maintenance, and error resolution, ensuring functionality, performance, and IT security, as well as the technical implementation and evaluation of online offerings, questionnaires, and measurements.
Depending on the offering, the following data may, among other things, be affected:
Master and contact data (e.g. name, user ID, e-mail address)
Usage, meta, and technical data (e.g. log data, pages/functions accessed, IP address, device/browser information)
Content data (e.g. inputs in applications),
as part of corresponding offerings, also health data, insofar as this is collected via our online offerings and used in the processing described in this privacy policy.
The processing of personal data as part of the involvement of K&W Media Consulting GmbH is based – depending on the purpose – in particular on Art. 6(1)(b) GDPR (performance of the usage/contractual relationship) and Art. 6(1)(f) GDPR (legitimate interest in a secure, high-performing, and user-friendly operation of our online offerings). Insofar as K&W also processes health data as part of the offerings described by us, this is done on the basis of your explicit consent given for this purpose pursuant to Art. 9(2)(a) GDPR.
K&W Media Consulting GmbH acts as a processor pursuant to Art. 28 GDPR. A data processing agreement governs in particular the processing exclusively on our instructions, appropriate technical and organizational measures, and confidentiality and data security.
The personal data processed by K&W as part of development, operational, and evaluation activities is stored only for as long as necessary for the stated purposes, or as required by statutory retention obligations; it is subsequently deleted or, where possible and permissible, anonymized.
Further information on the processing of data by K&W Media Consulting GmbH can be found in the privacy notices on the provider's website (available e.g. at https://www.kuwmc.com/).
4.3 Use of the Appointment Scheduling Tool "meetergo"
For the online scheduling of appointments (e.g. for measurements and personal consultations), we use the service "meetergo" provided by meetergo GmbH, Hauptstraße 44, 40789 Monheim am Rhein, Germany, as an external service provider. This tool allows appointments to be booked, managed, and coordinated online.
As part of the use of the appointment scheduling tool, the personal data required for booking an appointment is collected via the interface provided by meetergo and processed on the provider's systems. This may in particular include the following data:
Master data (e.g. name, company affiliation where applicable)
Contact data (e.g. e-mail address, phone number where applicable)
Appointment data (e.g. date, time, duration, reason for the appointment)
Technical usage data (e.g. IP address, times of booking, log data)
The use of the appointment scheduling tool serves to fulfil and prepare contractual relationships (Art. 6(1)(b) GDPR) as well as on the basis of our legitimate interest in an efficient, user-friendly, and secure organization of appointments (Art. 6(1)(f) GDPR).
meetergo acts as a processor within the meaning of Art. 28 GDPR for us in this regard. A data processing agreement has been concluded with meetergo GmbH, which governs in particular appropriate technical and organizational measures to protect your personal data as well as adherence to instructions and confidentiality.
Further information on the processing of data by meetergo can be found in the privacy notices of meetergo GmbH: https://meetergo.com/datenschutz
4.4 Use of HubSpot as a CRM and Communication Platform
For the management of contacts, communication, and certain online interactions (e.g. contact forms, landing pages, campaign evaluations), we use the services of HubSpot, Inc. The provider is HubSpot, Inc., 25 First Street, 2nd Floor, Cambridge, MA 02141, United States of America (USA).
HubSpot is used in particular for:
Management of contact and communication data (CRM)
Processing of inquiries (e.g. via contact forms)
Sending and evaluating informational and marketing measures (insofar as consent has been given)
Evaluating the use of certain online offerings to optimize content and communication
The following data may, among other things, be processed:
Master and contact data
Communication and prospect data
Usage and metadata
The legal bases are, depending on the purpose, in particular Art. 6(1)(b) GDPR (initiation/performance of a contract), Art. 6(1)(a) GDPR (consent, e.g. for the newsletter), and Art. 6(1)(f) GDPR (legitimate interest in efficient CRM, communication, and optimization of our online offerings).
HubSpot acts as a processor pursuant to Art. 28 GDPR for us. A corresponding data processing agreement governs in particular the processing exclusively on our instructions, as well as appropriate technical and organizational measures to protect your data.
HubSpot, Inc. is headquartered in the United States of America (USA). A transfer of personal data to the USA therefore takes place. This is carried out on the basis of an adequacy decision of the EU Commission (EU-U.S. Data Privacy Framework) and supplementary contractual guarantees, where necessary.
Further information on the processing of data by HubSpot can be found in HubSpot's privacy notices at: https://legal.hubspot.com/privacy-policy
4.5 Use of SurveyMonkey Europe UC (Online Surveys)
For conducting and evaluating online surveys (e.g. health questionnaires, evaluation and feedback surveys), we use the service SurveyMonkey Europe UC, 70 Sir John Rogerson's Quay, Dublin 2, D02 R296, Ireland.
The processing is carried out in particular for conducting the surveys, evaluating the results, and planning and optimizing health, prevention, and improvement measures.
Depending on the specific survey, the following data may in particular be processed as part of the use of SurveyMonkey:
Master data (e.g. name, organization/department where applicable)
Contact data (e.g. e-mail address for invitation/assignment)
Survey data (responses, free-text answers)
Where applicable, health data (special categories pursuant to Art. 9 GDPR), insofar as this is the subject of the survey
Usage and metadata (e.g. time of participation, technical log data)
Participation in the surveys is voluntary. The legal basis is generally your consent pursuant to Art. 6(1)(a), Art. 7 GDPR; insofar as health data is processed, this is done on the basis of your explicit consent pursuant to Art. 9(2)(a) GDPR.
SurveyMonkey Europe UC acts as a processor pursuant to Art. 28 GDPR on the basis of a corresponding data processing agreement. SurveyMonkey operates data centers in the EU and the USA, among other places. For certain processing operations, a transfer to SurveyMonkey Inc. in the USA may take place. SurveyMonkey Inc. is certified under the EU-U.S. Data Privacy Framework (DPF); on the basis of the EU Commission's adequacy decision, an adequate level of data protection is recognized.
Privacy notices: https://www.surveymonkey.com/mp/legal/privacy/
You may withdraw your consent to the processing of your survey data at any time with effect for the future. The personal data collected as part of online surveys is stored only for as long as necessary for evaluation and implementation of measures, or as required by statutory retention obligations; the data is subsequently deleted or, where possible, anonymized. Anonymized evaluations may continue to be used for statistical and reporting purposes.
4.6 Use of Matomo Cloud
We use the web analytics service Matomo Cloud to statistically evaluate the use of our online offerings and to technically and substantively improve our content. The provider of this service is InnoCraft Ltd, 7 Waterloo Quay, PO Box 625, 6140 Wellington, New Zealand.
We use Matomo Cloud for web analytics. The data is stored on AWS Europe servers in Germany, with backups in Ireland. The provider (processor pursuant to Art. 28 GDPR) is InnoCraft Ltd, New Zealand.
Purposes of the processing:
Reach measurement and statistical evaluation of the use of our websites/online offerings
Optimization of structure, content, and usability
Ensuring technical functionality and stability
In particular, the following is processed:
(shortened/anonymized) IP address
Date and time of access
Pages/files accessed, dwell time, referrer URL
Device and browser information
Where applicable, a pseudonymous identifier for returning visitors
The data is not used for advertising purposes by third parties.
Insofar as Matomo is used without cookies requiring consent (e.g. with IP anonymization, without cross-device tracking), the processing is based on our legitimate interest pursuant to Art. 6(1)(f) GDPR in a privacy-friendly, statistical evaluation and needs-based design of our offerings.
Insofar as we obtain consent for Matomo (e.g. for cookies or extended tracking functions), the legal basis is your consent pursuant to Art. 6(1)(a), Art. 7 GDPR.
InnoCraft Ltd is based in New Zealand. An adequacy decision by the EU Commission exists for New Zealand; the transfer of personal data there is therefore permissible under Chapter V GDPR.
Personal or pseudonymous raw data is stored only for as long as necessary for the stated purposes and is subsequently deleted or anonymized. Anonymized statistics may continue to be used for evaluations for a longer period.
Insofar as the processing is based on our legitimate interest pursuant to Art. 6(1)(f) GDPR, you may object to the processing, provided there are grounds arising from your particular situation.
Insofar as the processing is based on consent, you may withdraw it at any time with effect for the future, e.g. via the settings in the consent/cookie banner or the opt-out functions we provide.
Further information on the processing of data by Matomo Cloud can be found in the privacy notices at: https://matomo.org/matomo-cloud-privacy-policy/
4.7 Use of Microsoft Teams (Online Meetings and Consultations)
For conducting online meetings, personal discussions, and consultation appointments, we use the service Microsoft Teams. The provider is: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland.
We use Microsoft Teams for video, audio, and online consultation discussions. Depending on the conversation and settings, the following data may in particular be processed:
Master and contact data (e.g. name, display name, e-mail address, organization/company where applicable)
Meeting and metadata (e.g. date, time, duration, participants)
Content data (e.g. spoken contributions, chat messages, shared files/screen content)
Technical data (e.g. IP address, device and browser information)
As part of personal consultations, depending on the reason for the discussion, you may also share health data or other sensitive information; this is processed exclusively for the purpose of the consultation.
The legal basis is, depending on the context, Art. 6(1)(b) GDPR (initiation/performance of a contract) or Art. 6(1)(f) GDPR (legitimate interest in efficient, secure online communication). Insofar as special categories of personal data (e.g. health data) are affected, processing is carried out on the basis of your explicit consent pursuant to Art. 9(2)(a) GDPR.
Microsoft acts as a processor pursuant to Art. 28 GDPR for us in this regard. Processing is carried out predominantly on servers within the EU; a transfer of personal data to Microsoft in the USA or other third countries cannot be ruled out in individual cases (e.g. support). In these cases, the transfer is based on appropriate safeguards pursuant to Art. 44 et seq. GDPR (in particular Standard Contractual Clauses, additional protective measures, participation in the EU-U.S. Data Privacy Framework).
Participation in discussions via Microsoft Teams is generally voluntary; where possible, alternative communication channels (e.g. phone) are available. Discussions are generally not recorded.
Log and metadata are stored only for as long as necessary for implementation, documentation, billing, and statutory retention obligations; they are subsequently deleted or, where possible, anonymized.
Further information: https://privacy.microsoft.com/en-us/privacystatement
4.8 Use of Vimeo (Video Embedding)
Videos from the service Vimeo may be embedded on our websites. The provider is Vimeo, Inc., 555 West 18th Street, New York, New York 10011, USA.
When accessing an area in which a Vimeo video is embedded, a connection is established to Vimeo's servers. In this context, the following categories of personal data may in particular be processed:
IP address
page/URL accessed
device and browser information
usage data (e.g. starting/stopping a video, viewing duration)
If the data subject is logged into Vimeo, Vimeo may be able to assign the access to the respective Vimeo user account.
The legal basis for the integration and data processing is generally your consent pursuant to Art. 6(1)(a) GDPR, which we obtain via the consent/cookie banner. You may withdraw your consent at any time with effect for the future.
Vimeo may transfer personal data to the USA. The transfer takes place in accordance with the data protection mechanisms used by Vimeo (e.g. an adequacy decision or appropriate safeguards pursuant to Art. 45 et seq. GDPR), as described in Vimeo's privacy notices.
Further information on the processing of data by Vimeo can be found in the provider's privacy notices at: https://vimeo.com/privacy
4.9 Use of CCM19 Cloud (Consent Management)
We use the consent management tool CCM19 provided by Papoo Software & Media GmbH, Auguststr. 4, 53229 Bonn, Germany, on our platform to manage consent to the use of cookies and similar technologies.
CCM19 is used to
obtain and document consent for setting cookies and running scripts that require consent (e.g. analytics, marketing, and third-party services),
store your settings (e.g. "accept", "decline", category selection), and
implement the corresponding technical control (blocking/enabling services depending on your selection).
The following in particular is processed via CCM19:
your selection in the consent banner (consent status per category)
a pseudonymous identifier (e.g. consent ID)
the time and scope of the consent given or changed
basic technical data on the browser/device (e.g. truncated IP address, browser type, date/time of visit)
The legal basis for the use of CCM19 and the storage of your consent decision is our legitimate interest pursuant to Art. 6(1)(f) GDPR in a data-protection-compliant operation of our online offerings and in demonstrating consent given or refused.
The processing of the services released via CCM19 (e.g. analytics/marketing tools) is additionally based on your consent pursuant to Art. 6(1)(a), Art. 7 GDPR.
Consent data is stored only for as long as necessary to demonstrate your consent decision and for any statutory documentation obligations; it is subsequently deleted or, where possible, anonymized.
Further information on the processing of data by CCM19 can be found in the provider's privacy notices at: https://www.ccm19.de/datenschutzerklaerung.html
4.10 YouTube Videos and YouTube Images
We use the service YouTube provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("YouTube") on our platform to provide and play videos and preview images.
YouTube is used to
embed video content directly on our platform,
display preview images (thumbnails) for embedded videos, and
enable the playback of videos (e.g. start, pause, volume, full screen).
The integration of YouTube content generally only takes place after you have given your consent to the use of YouTube (or the corresponding category, e.g. "External media" or "Third-party services") via our consent management tool CCM19. In particular, the following is processed via YouTube:
IP address and basic technical information about the browser/device
page/URL accessed and date/time of the visit
information on the use of the embedded video (e.g. start, stop, playback duration)
where applicable, information from your Google/YouTube account, if you are logged in
In connection with embedded YouTube videos, Google advertising services (Google AdSense/YouTube Partner Program) may also be used, through which advertisements are displayed before, during, or alongside the videos. In this context, in particular cookie identifiers or advertising IDs, information on pages accessed, and interactions with advertisements (e.g. views, clicks, skipping of ads) may be processed.
YouTube/Google may use cookies and similar technologies to recognize and analyze usage and advertising behavior. This processing is carried out under Google's own responsibility and may also involve the transfer of data to Google LLC's servers in the USA or other third countries without an adequate level of data protection.
The legal basis for the use of YouTube and the associated advertising services (e.g. Google AdSense/YouTube advertising) is your consent pursuant to Art. 6(1)(a) GDPR in conjunction with Art. 7 GDPR; any data transfers to third countries are additionally based on your explicit consent pursuant to Art. 49(1)(a) GDPR. Without your consent, YouTube content and the associated marketing services are technically blocked via CCM19 and not loaded.
YouTube-related data is only processed by us insofar as this is necessary for the integration and display of the content; the storage period for the cookies set and data processed by YouTube/Google is governed by Google's specifications.
You may withdraw your consent at any time with effect for the future via the CCM19 consent banner, or adjust your selection there (e.g. deactivating the corresponding category).
Further information on the processing of data by YouTube/Google can be found in Google's privacy notices at: https://policies.google.com/privacy
4.11 Google Photos
We use the service Google Photos provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google") on our platform to provide and display image content (e.g. photos, albums, galleries).
The integration of Google Photos content generally only takes place after you have given your consent to the use of Google Photos (or the corresponding category, e.g. "External media" or "Third-party services") via our consent management tool CCM19.
In particular, the following is processed via Google Photos:
IP address and basic technical information about the browser/device
page/URL accessed and date/time of the visit
information on the display and use of the embedded images/albums (e.g. loading processes, interactions)
where applicable, information from your Google account, if you are logged in and this allows an assignment
Google may use cookies and similar technologies to recognize and analyze usage behavior. This processing is carried out under Google's own responsibility and may also involve the transfer of data to Google LLC's servers in the USA or other third countries without an adequate level of data protection.
The legal basis for the use of Google Photos is your consent pursuant to Art. 6(1)(a) GDPR in conjunction with Art. 7 GDPR; any data transfers to third countries are additionally based on your explicit consent pursuant to Art. 49(1)(a) GDPR. Without your consent, Google Photos content is technically blocked via CCM19 and not loaded.
Google Photos-related data is only processed by us insofar as this is necessary for the integration and display of the content; the storage period for the cookies set and data processed by Google is governed by Google's specifications.
You may withdraw your consent at any time with effect for the future via the CCM19 consent banner, or adjust your selection there (e.g. deactivating the corresponding category).
4.12 Google Fonts
We use the service Google Fonts provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google") on our platform for the uniform display of fonts.
The integration of Google Fonts content generally only takes place after you have given your consent to the use of Google Fonts (or the corresponding category, e.g. "External media", "Design", or "Third-party services") via our consent management tool CCM19.
In particular, the following is processed via Google Fonts:
IP address and basic technical information about the browser/device
page/URL accessed and date/time of the visit
the font(s) requested and, where applicable, technical display parameters
Google may use cookies and similar technologies to provide and optimize the fonts. This processing is carried out under Google's own responsibility and may also involve the transfer of data to Google LLC's servers in the USA or other third countries without an adequate level of data protection.
The legal basis for the use of Google Fonts is your consent pursuant to Art. 6(1)(a) GDPR in conjunction with Art. 7 GDPR; any data transfers to third countries are additionally based on your explicit consent pursuant to Art. 49(1)(a) GDPR. Without your consent, fonts provided via Google are technically blocked via CCM19 and not loaded.
Google Fonts-related data is only processed by us insofar as this is necessary for the integration and display of the fonts; the storage period for the cookies set and data processed by Google is governed by Google's specifications.
You may withdraw your consent at any time with effect for the future via the CCM19 consent banner, or adjust your selection there (e.g. deactivating the corresponding category).
4.13 Amazon Web Services (AWS)
For the technical operation and delivery of certain content on our platform, we use infrastructure services provided by Amazon Web Services (AWS). The provider is Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg, and, where applicable, affiliated companies of Amazon Web Services, Inc., 410 Terry Ave North, Seattle, WA 98109, USA ("AWS"). AWS is used on individual subpages in order to provide an embedded service there and to ensure its secure, high-performance delivery.
In particular, the following is processed as part of the use of AWS:
IP address and basic technical information about the browser/device
page/URL accessed and date/time of the visit
amount of data transferred and server log data (e.g. access and error messages)
where applicable, referrer URL (previously visited page)
The processing is carried out exclusively for the purpose of providing the requested content, ensuring the stability and security of operations (e.g. protection against overload/attacks), and enabling reliable delivery of the embedded service on the relevant subpages.
The legal basis for the use of AWS is our legitimate interest pursuant to Art. 6(1)(f) GDPR in a secure, efficient, and professionally operated online offering. Insofar as the embedded service delivered via AWS itself is only loaded following your consent (e.g. via CCM19), the associated use of AWS is additionally based on your consent pursuant to Art. 6(1)(a) GDPR, Art. 7 GDPR.
A data processing agreement pursuant to Art. 28 GDPR has been concluded with AWS. It cannot be ruled out that, in the course of the provision of services, access to data from third countries (in particular the USA) may occur. In these cases, the data transfer is based on appropriate safeguards pursuant to Art. 46 GDPR (e.g. EU Standard Contractual Clauses) and supplementary technical and organizational measures. Data is stored only for as long as necessary for the stated purposes; it is subsequently deleted or, where possible, anonymized.
Further information on the processing of data by AWS can be found in AWS's privacy notices at: https://aws.amazon.com/privacy/
5. Your Rights as a Data Subject
Under applicable law, you have various rights regarding your personal data. If you wish to exercise these rights, please send your request by e-mail or post, clearly identifying yourself, to the address given in Section 1.3.
Below you will find an overview of your rights.
5.1 Right to Confirmation and Access
You have the right to receive a clear overview of the processing of your personal data.
In detail:
You have the right, at any time, to obtain confirmation from us as to whether personal data concerning you is being processed. If this is the case, you have the right to obtain free access from us to the personal data stored about you, together with a copy of this data. You also have the right to the following information:
the purposes of the processing;
the categories of personal data processed;
the recipients or categories of recipients to whom the personal data has been or will be disclosed, in particular recipients in third countries or international organizations;
where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period;
the existence of a right to rectification or erasure of the personal data concerning you, or restriction of processing by the controller, or a right to object to such processing;
the existence of a right to lodge a complaint with a supervisory authority;
where the personal data is not collected from you, all available information about its source;
the existence of automated decision-making, including profiling, pursuant to Art. 22(1) and (4) GDPR and – at least in these cases – meaningful information about the logic involved, as well as the significance and envisaged consequences of such processing for you.
Where personal data is transferred to a third country or to an international organization, you have the right to be informed of the appropriate safeguards pursuant to Art. 46 GDPR relating to the transfer.
5.2 Right to Rectification
You have the right to request that we rectify and, where applicable, complete personal data concerning you.
In detail:
You have the right to request that we rectify, without undue delay, any inaccurate personal data concerning you. Taking into account the purposes of the processing, you have the right to have incomplete personal data completed, including by means of providing a supplementary statement.
5.3 Right to Erasure ("Right to be Forgotten")
In a number of cases, we are obliged to erase personal data concerning you.
In detail:
Pursuant to Art. 17(1) GDPR, you have the right to request that we erase personal data concerning you without undue delay, and we are obliged to erase personal data without undue delay where one of the following grounds applies:
The personal data is no longer necessary for the purposes for which it was collected or otherwise processed.
You withdraw your consent on which the processing was based pursuant to Art. 6(1) sentence 1(a) GDPR or Art. 9(2)(a) GDPR, and there is no other legal basis for the processing.
You object to the processing pursuant to Art. 21(1) GDPR and there are no overriding legitimate grounds for the processing, or you object to the processing pursuant to Art. 21(2) GDPR.
The personal data has been processed unlawfully.
Erasure of the personal data is necessary for compliance with a legal obligation under Union or Member State law to which we are subject.
The personal data has been collected in relation to the offer of information society services referred to in Art. 8(1) GDPR.
Where we have made the personal data public and are obliged pursuant to Art. 17(1) GDPR to erase it, we shall, taking into account available technology and the cost of implementation, take reasonable steps, including technical measures, to inform controllers processing the personal data that you have requested the erasure of any links to, or copies or replications of, that personal data.
5.4 Right to Restriction of Processing
In a number of cases, you are entitled to request that we restrict the processing of your personal data.
In detail:
You have the right to request that we restrict processing where one of the following conditions applies:
the accuracy of the personal data is contested by you, for a period enabling us to verify the accuracy of the personal data,
the processing is unlawful and you oppose the erasure of the personal data and request the restriction of its use instead;
we no longer need the personal data for the purposes of the processing, but you need it for the establishment, exercise, or defence of legal claims, or
you have objected to processing pursuant to Art. 21(1) GDPR, pending verification as to whether our legitimate grounds override yours.
5.5 Right to Data Portability
You have the right to receive personal data concerning you in a machine-readable format, to transmit it yourself, or to have us transmit it.
In detail:
You have the right to receive the personal data concerning you that you have provided to us in a structured, commonly used, and machine-readable format, and you have the right to transmit that data to another controller without hindrance from us, provided that
the processing is based on consent pursuant to Art. 6(1) sentence 1(a) GDPR or Art. 9(2)(a) GDPR, or on a contract pursuant to Art. 6(1)(b) GDPR, and
the processing is carried out by automated means.
When exercising your right to data portability pursuant to paragraph 1, you have the right to have the personal data transmitted directly from us to another controller, where technically feasible.
5.6 Right to Object
You have the right to object to lawful processing of your personal data by us where this arises from your particular situation, unless our interests in the processing do not prevail.
In detail:
You have the right to object, on grounds relating to your particular situation, at any time, to processing of personal data concerning you which is based on Art. 6(1) sentence 1(e) or (f) GDPR; this also applies to profiling based on these provisions. We will no longer process the personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or the processing serves the establishment, exercise, or defence of legal claims.
Where we process personal data for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for such marketing; this also applies to profiling insofar as it is related to such direct marketing.
You have the right, on grounds relating to your particular situation, to object to processing of personal data concerning you carried out for scientific or historical research purposes, or for statistical purposes pursuant to Art. 89(1) GDPR, unless the processing is necessary for the performance of a task carried out for reasons of public interest.
5.7 Automated Decision-Making, Including Profiling
You have the right not to be subject to a decision based solely on automated processing – including profiling – which produces legal effects concerning you or similarly significantly affects you.
Automated decision-making based on the personal data collected does not take place.
5.8 Right to Withdraw Consent under Data Protection Law
You have the right to withdraw consent to the processing of personal data at any time.
5.9 Right to Lodge a Complaint with a Supervisory Authority
You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or the place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the GDPR.
6. Data Security
We make every effort, within the scope of applicable data protection laws and technical possibilities, to ensure the security of your data.
Your personal data is transmitted to us in encrypted form. This applies to all forms we offer. We use the SSL (Secure Socket Layer) encoding system, but we point out that data transmission over the internet (e.g. when communicating by e-mail) may have security vulnerabilities. Complete protection of data against access by third parties is not possible.
To secure your data, we maintain technical and organizational security measures in accordance with Art. 32 GDPR, which we continuously adapt to the state of the art.
We furthermore do not guarantee that our offering will be available at all times; disruptions, interruptions, or outages cannot be ruled out. The servers we use are regularly and carefully backed up.
7. Disclosure of Data to Third Parties; No Data Transfer to Non-EU Countries
As a general rule, we use your personal data only within our company.
If and to the extent we engage third parties in the course of fulfilling contracts (e.g. logistics service providers), they receive personal data only to the extent that the disclosure is necessary for the respective service.
Where we outsource certain parts of the data processing ("processing on our behalf"), we contractually obligate the processors to use personal data only in accordance with the requirements of data protection law and to ensure the protection of the rights of the data subject.
A transfer of data to bodies or persons outside the EU, other than in the cases mentioned in Sections 3 and 4 of this policy, does not take place and is not planned.
8. Data Protection Officer
If you have any questions or concerns regarding data protection, please contact our Data Protection Officer:
Iqanta GmbH, Sven Weschler
kontakt@iqanta.com
9. Changes to this Privacy Policy
If new services or providers are used to operate this website, we reserve the right to amend this privacy policy in order to comply with legal requirements. The amended privacy policy will then apply to your next visit to this website.
10. Processing When You Exercise Your Rights
If you wish to exercise your rights pursuant to Articles 15 to 22 GDPR, we will process the personal data you provide to us in order to implement these rights and to be able to provide evidence of having done so. We will process the data stored for the purposes of providing information and preparation exclusively for this purpose and for data protection control purposes, and will otherwise restrict processing pursuant to Article 18 GDPR.
This processing is based on the legal basis of Article 6(1)(c) GDPR in conjunction with Articles 15 to 22 GDPR and Sec. 34(2) of the German Federal Data Protection Act (BDSG).
11. Your Rights as a Data Subject
The General Data Protection Regulation (GDPR) guarantees every data subject certain rights with regard to their personal data. These include, in particular:
The right to access: You have the right to obtain confirmation from us as to whether personal data is being processed, as well as access to that data and further information and copies of it.
The right to rectification: You have the right to request the immediate rectification of inaccurate personal data.
The right to erasure ("right to be forgotten"): You have the right to request the immediate erasure of your personal data.
The right to restriction of processing: You have the right to request the restriction of the processing of your personal data.
The right to data portability: You have the right to receive the personal data concerning you that you have provided to us in a structured, commonly used, and machine-readable format.
The right to object: You have the right, on grounds relating to your particular situation, to object at any time to processing of personal data concerning you carried out on the basis of Art. 6(1)(e) or (f) GDPR. Where we process personal data for direct marketing purposes, you may object to such processing at any time pursuant to Art. 21(2) and (3) GDPR.
You also have the right to lodge a complaint with a supervisory authority if you consider that the processing of your personal data infringes the GDPR. The supervisory authority responsible for us is the Hamburg Commissioner for Data Protection and Freedom of Information (Hamburgische Beauftragte für Datenschutz und Informationsfreiheit).
