Privacy Policy
We appreciate your interest in our company. Data protection and data security are a top priority for us. Below, we would like to provide you with comprehensive information about how we process personal data within our company and on our website.
We are
Sunnic Lighthouse GmbH
Kirchenpauerstraße 26
20457 Hamburg
T: +49 40 756 64 49 - 444
F: +49 40 756 64 49 - 699
Email: info@sunnic.de
Management: Christoph Koeppen, Arved von Harpe
We have appointed an external data protection officer. This person can be reached at the address listed above with the note “personal – confidential for the data protection officer,” as well as at datenschutz@sunnic.de.
Provided that certain conditions are met, you have the right to
- access to your data, to have inaccurate data corrected,
- to have your data deleted if there is no longer a reason to retain it,
- to restrict processing,
- to data portability, to object to processing based on our legitimate interest (Article 6(1), first sentence, letter f of the GDPR),
- to withdraw consent that has been given, with effect for the future, and
- to file a complaint against us with the competent supervisory authority.
Of course, these rights are subject to conditions set forth in the relevant laws, in particular the General Data Protection Regulation (GDPR).
If we transfer your data to countries outside the European Union (third countries), we need additional safeguards, which are governed by Articles 44 et seq. of the GDPR. These include, in particular,
- adequacy decisions, in which the European Commission has determined that a country or sector has an adequate level of data protection (Article 45 of the GDPR),
- Standard contractual clauses, through which data recipients in third countries contractually commit to maintaining an adequate level of data protection (Article 46 of the GDPR),
- Binding internal data protection rules that have been reviewed by EU supervisory authorities and through which data recipients in third countries commit to maintaining an adequate level of data protection (Article 47 of the GDPR),
- Declarations of consent, through which you agree on a case-by-case basis to the transfer of your data to a third country (Article 49(1)(a) of the GDPR). Any risk notices can be found in the glossary.
We have the following additional information:
- When we process your data, we do not engage in automated decision-making, and in particular, we do not engage in profiling.
- We are legally obligated to process your data only if we expressly indicate this in the following privacy policy.
Establishing Contact
First, we collect your data to establish initial contact. In this process, it is possible that we will contact you first, or vice versa. In any case, we process all data that you voluntarily provide to us. This often includes your contact information (name, email address, mailing address, phone number) as well as communication data (e.g., a summary of the conversation, conversation notes, form entries). On this basis, we will submit an offer to you and store the corresponding data. The purpose of this processing is to initiate or establish a contract. The legal basis for this is Article 6(1), first sentence, letter b of the GDPR.
Credit
Check In some cases, we will transmit your contact information to Creditreform Hamburg von der Decken KG and, on that basis, also retrieve and store information regarding your creditworthiness from them. The purpose is to assess your creditworthiness. We will also transmit data regarding your payment history, which includes both positive data (settlement of claims) and negative data (payment defaults). In the case of negative data, however, this will only occur if it does not conflict with the interests of the data subjects. The legal basis for the aforementioned processing operations is Article 6(1), first sentence, subparagraph (f) of the GDPR. The legitimate interest required for this arises from the fact that credit checks are necessary for services such as those owed under this contract in order to minimize any risks to the controller associated with providing services in advance. Please note that Creditreform Hamburg von der Decken KG uses the aforementioned data, among other things, to calculate a probability value regarding a specific future behavior of the customers in question (score). The data controller may request such a score from Creditreform Hamburg von der Decken KG in order to use it for its own credit checks.
Video Conferences
In some cases, you may communicate with us via video conference. In doing so, we process the resulting video and audio data as well as any transcripts that may be created. The purpose of this processing is either to negotiate a contract with you or, at a later stage, to fulfill it. The legal basis is Article 6(1), first sentence, letter b of the GDPR.
Recordings are made only if we suggest it and you consent. To fulfill a legal obligation (Article 7(1) of the GDPR), we first store the information indicating whether you have given your consent. The legal basis for this is Article 6(1), first sentence, subparagraph (c) of the GDPR. We then record the conversation and store the resulting video and audio data to document the conversation. The legal basis for this is Article 6(1), first sentence, subparagraph (a) of the GDPR. The prohibition under Article 9(1) of the GDPR does not preclude this, as the exception under Article 9(2)(a) of the GDPR applies.
Performance of a Contract
If a contract is actually concluded between us, we will communicate with you, make payments, etc., and in doing so process communication and billing data (e.g., for the delivery of services and responding to inquiries) in order to fulfill the contract. The purpose of this processing is to execute the contract. The legal basis for this is Article 6(1), first sentence, subparagraph (b) of the GDPR.
Notification of Changes to Data Processing
If we ever change the way we process your data (e.g., by using new tools), we will inform you of the changes, e.g., via email. As a rule, we will send you updated privacy information. The purpose of this processing is to comply with a legal obligation (Articles 12–14 of the GDPR). The legal basis for this is Article 6(1), first sentence, letter c of the GDPR.
Data Processing When Exercising Rights
If you exercise your rights under the GDPR or other legal provisions, we process your data to review these claims and, if necessary, fulfill them. The purpose of this processing is to comply with a legal obligation. The legal basis for this is Article 6(1), first sentence, subparagraph (c) of the GDPR in conjunction with the respective statutory provision from which your right or claim arises.
Data Retention/Retention Period
We retain your data both during and after the end of the contract. Here we inform you how long the data will be stored:
- We retain booking documents for eight years. This period begins on December 31 of the calendar year in which the respective document was created. We are legally obligated to do so (Section 147 of the German Fiscal Code (AO), Section 257 of the German Commercial Code (HGB)), and the legal basis is Article 6(1), first sentence, letter c of the GDPR in conjunction with the respective statutory provision from which your right or claim arises.
- We retain other internal records (e.g., annual financial statements) for ten years. This period begins on December 31 of the calendar year in which the respective document was created. We are legally obligated to do so (Section 147 of the German Fiscal Code (AO), Section 257 of the German Commercial Code (HGB)), and the legal basis is Article 6(1), first sentence, letter c of the GDPR in conjunction with the respective statutory provision from which your right or claim arises.
- We retain business correspondence (e.g., customer letters) and other tax-related documents for six years. This period begins on December 31 of the calendar year in which the respective document was created. We are legally obligated to do so (Section 147 of the German Fiscal Code (AO), Section 257 of the German Commercial Code (HGB)), and the legal basis is Article 6(1), first sentence, letter c of the GDPR in conjunction with the respective statutory provision from which your right or claim arises.
- When you exercise your rights under the GDPR, communication data is generated (correspondence via email, mail, etc.). We retain this data for three years. This period begins on December 31 of the calendar year in which we responded to your request. In doing so, we are pursuing our own legitimate interests. This is because, in the event of a dispute, we want to be able to prove that we have handled your claims correctly. The legal basis is Article 6(1), first sentence, letter f of the GDPR. The three-year period is based on the statute of limitations for claims for damages (Sections 195, 199(1) of the German Civil Code (BGB)) and, supplementarily, on the statute of limitations provisions under administrative offense law (Section 31(2)(1) of the German Administrative Offenses Act (OWiG) in conjunction with Article 83 of the GDPR).
- If you assert other rights not covered by the GDPR, communication data will also be generated, which we retain for three years. This period begins on December 31 of the calendar year in which we responded to your request. In doing so, we are pursuing our own legitimate interests. This is because, in the event of a dispute, we want to be able to prove that we handled your claims correctly. The legal basis is Article 6(1), first sentence, subparagraph (f) of the GDPR. The three-year period is based on the statute of limitations for claims for damages (Sections 195, 199(1) of the German Civil Code (BGB)).
- If you consent to data processing, we
will store the information that you have given your consent for three years. This period begins as soon as you withdraw your consent or the associated purpose ceases to exist, whichever occurs first. In doing so, we are pursuing our own legitimate interests. This is because, in the event of a dispute, we want to be able to prove that we have handled your claims correctly. The legal basis is Article 6(1), first sentence, letter f of the GDPR. The three-year period is governed by the statute of limitations provisions for claims for damages (Sections 195, 199(1) of the German Civil Code (BGB)) and, supplementarily, on the statute of limitations provisions under administrative offense law (Section 31(2)(1) of the German Administrative Offenses Act (OWiG) in conjunction with Article 83 of the GDPR).
- We store the data we process based on your consent until you revoke your consent. The purpose is set forth in the respective consent form, and the legal basis for this is Article 6(1), first sentence, letter a of the GDPR.
Deletion of Data
As soon as the aforementioned retention periods end, we will delete your data. In doing so, we fulfill a legal obligation (Article 5(1)(a), (e) of the GDPR). The legal basis is Article 6(1), first sentence, subparagraph (c) of the GDPR.
Recipients
The following recipients and other external parties process your data:
Recipients within the European Union: Within the European Union, your data is processed by companies (recipients) in the following categories:
- Backup tool providers
- Software hosting companies,
- Providers of video conferencing systems,
- law firms, tax firms, and auditing firms
- Project management tools,
- Providers of whistleblower platforms,
- Providers of accounting solutions
- Providers of Microsoft productivity tools
- Providers of translation tools
- ENERPARC AG
- Creditreform Hamburg von der Decken KG
Recipients outside the European Union: Outside the European Union, your data is processed by the following specific companies (recipients):
- Microsoft: Various applications from Microsoft Corporation (U.S.) are used; Microsoft has been appointed as a processor in accordance with Article 28 of the GDPR, namely: Microsoft 365 Cloud, Microsoft Teams (project management tool), Microsoft Teams (video conferencing tool), Microsoft Bookings, Microsoft Forms, and SharePoint. A transfer of data to a third country (in this case, the U.S.), which cannot be ruled out, is justified under Article 45 of the GDPR.
- New Relic: The website monitoring tool “New Relic” from New Relic, Inc. (USA) is used; New Relic, Inc. has been appointed as a processor in accordance with Article 28 of the GDPR. A transfer of data to a third country (in this case, the U.S.), which cannot be ruled out, is justified under Article 45 of the GDPR.
- Lacework: We use the IT security tool “Lacework” from Lacework, Inc. (U.S.). A transfer of data to a third country (in this case, the U.S.), which cannot be ruled out, is justified under Article 46 of the GDPR.
- ShareFile: The IT tool “ShareFile” from Citrix Systems Inc. (U.S.) is used; this company has been appointed as a processor in accordance with Article 28 of the GDPR. A data transfer to a third country (in this case, the U.S.), which cannot be ruled out, is justified under Article 46 of the GDPR.
- Monday.com: The collaboration tool “Monday.com” from Monday.com Ltd. (Israel) is used. A data transfer to a third country (in this case, Israel), which cannot be ruled out, is justified under Article 45 of the GDPR.
- Atlassian: The project management tool provided by Atlassian Pty Ltd (Australia) is used; this company has been appointed as a processor in accordance with Article 28 of the GDPR. A data transfer to a third country (in this case, Australia), which cannot be ruled out, is justified under Article 46 of the GDPR.
- Autodesk: The “Autodesk” project management tool from Autodesk, Inc. (USA) is used; Autodesk, Inc. has been appointed as a processor in accordance with Article 28 of the GDPR. A transfer of data to a third country (in this case, the U.S.), which cannot be ruled out, is justified under Article 46 of the GDPR for employee data and under Article 45 of the GDPR for all other data.
Establishing Contact
First, we collect your data to establish initial contact. In this process, it is possible that we will contact you first. It is also possible that you will contact us first. In any case, we process all data that we have either researched in advance and/or that you voluntarily provide to us. This often includes your contact information (name, email address, mailing address, phone number) as well as communication data (e.g., a summary of the conversation, conversation notes, form entries). Based on this information, we review your inquiry and store the relevant data. The purpose of this processing is to initiate or establish a contract. The legal basis for this is Article 6(1), first sentence, letter b of the GDPR.
Video Conferences
In some cases, you may communicate with us via video conference. In doing so, we process the resulting video and audio data as well as any transcripts that may be created. The purpose of this processing is either to negotiate a contract with you or, at a later stage, to fulfill it. The legal basis is Article 6(1), first sentence, subparagraph (b) of the GDPR.
Recordings are made only if we propose this and you consent. To fulfill a legal obligation (Article 7(1) of the GDPR), we first store the information indicating whether you have given your consent. The legal basis for this is Article 6(1), first sentence, subparagraph (c) of the GDPR. We then record the conversation and store the resulting video and audio data to document the conversation. The legal basis for this is Article 6(1), first sentence, subparagraph (a) of the GDPR. The prohibition under Article 9(1) of the GDPR does not preclude this, as the exception under Article 9(2)(a) of the GDPR applies.
Performance of a Contract
If a contract is actually concluded between us, we will communicate with you, make payments, etc., and in doing so process communication and billing data (e.g., for the delivery of services and responding to inquiries) in order to fulfill the contract. The purpose of this processing is to execute the contract. The legal basis for this is Article 6(1), first sentence, subparagraph (b) of the GDPR.
Notification of Changes to Data Processing
If we ever change the way we process your data (e.g., by using new tools), we will inform you of the changes, e.g., via email. As a rule, we will send you updated privacy information. The purpose of this processing is to comply with a legal obligation (Articles 12–14 of the GDPR). The legal basis for this is Article 6(1), first sentence, letter c of the GDPR.
Data Processing When Exercising Rights
If you exercise your rights under the GDPR or other legal provisions, we process your data to review these claims and, if applicable, to fulfill them. The purpose of this processing is to comply with a legal obligation. The legal basis for this is Article 6(1), first sentence, letter c of the GDPR in conjunction with the respective statutory provision from which your right or claim arises.
Data Retention/Retention Period
We retain your data both during and after the end of the contract. Here we inform you how long the data will be stored:
- We retain booking documents for eight years. This period begins on December 31 of the calendar year in which the respective document was created. We are legally obligated to do so (Section 147 of the German Fiscal Code (AO), Section 257 of the German Commercial Code (HGB)), and the legal basis is Article 6(1), first sentence, letter c of the GDPR in conjunction with the respective statutory provision from which your right or claim arises.
- We retain other internal records (e.g., annual financial statements) for ten years. This period begins on December 31 of the calendar year in which the respective document was created. We are legally obligated to do so (Section 147 of the German Fiscal Code (AO), Section 257 of the German Commercial Code (HGB)), and the legal basis is Article 6(1), first sentence, letter c of the GDPR in conjunction with the respective statutory provision from which your right or claim arises.
- We retain business correspondence (e.g., letters to customers) and other tax-related documents for six years. This period begins on December 31 of the calendar year in which the respective document was created. We are legally obligated to do so (Section 147 of the German Fiscal Code (AO), Section 257 of the German Commercial Code (HGB)), and the legal basis is Article 6(1), first sentence, letter c of the GDPR in conjunction with the respective statutory provision from which your right or claim arises.
- When you exercise your rights under the GDPR, communication data is generated (correspondence via email, mail, etc.). We retain this data for three years. This period begins on December 31 of the calendar year in which we responded to your request. In doing so, we are pursuing our own legitimate interests. This is because, in the event of a dispute, we want to be able to prove that we have handled your claims correctly. The legal basis is Article 6(1), first sentence, letter f of the GDPR. The three-year period is based on the statute of limitations for claims for damages (Sections 195, 199(1) of the German Civil Code (BGB)) and, supplementarily, on the statute of limitations provisions under administrative offense law (Section 31(2)(1) of the German Administrative Offenses Act (OWiG) in conjunction with Article 83 of the GDPR).
- If you assert other rights not covered by the GDPR, communication data will also be generated, which we retain for three years. This period begins on December 31 of the calendar year in which we responded to your request. In doing so, we are pursuing our own legitimate interests. This is because, in the event of a dispute, we want to be able to prove that we handled your claims correctly. The legal basis is Article 6(1), first sentence, subparagraph (f) of the GDPR. The three-year period is based on the statute of limitations for claims for damages (Sections 195, 199(1) of the German Civil Code (BGB)).
- If you consent to data processing, we
will store the information that you have given your consent for three years. This period begins as soon as you withdraw your consent or the associated purpose ceases to exist, whichever occurs first. In doing so, we are pursuing our own legitimate interests. This is because, in the event of a dispute, we want to be able to prove that we have handled your claims correctly. The legal basis is Article 6(1), first sentence, letter f of the GDPR. The three-year period is governed by the statute of limitations provisions for claims for damages (Sections 195, 199(1) of the German Civil Code (BGB)) and, supplementarily, on the statute of limitations provisions under administrative offense law (Section 31(2)(1) of the German Administrative Offenses Act (OWiG) in conjunction with Article 83 of the GDPR).
- We store the data we process based on your consent until you revoke your consent. The purpose is set forth in the respective consent form, and the legal basis for this is Article 6(1), first sentence, subparagraph (a) of the GDPR.
Deletion of Data
As soon as the aforementioned retention periods end, we will delete your data. In doing so, we fulfill a legal obligation (Article 5(1)(a), (e) of the GDPR). The legal basis is Article 6(1), first sentence, (c) of the GDPR.
Recipients
The following recipients and other external parties process your data:
Recipients within the European Union: Within the European Union, your data is processed by companies (recipients) in the following categories:
- Backup tool providers
- Software hosting companies,
- Providers of video conferencing systems,
- law firms, tax firms, and auditing firms
- Project management tools,
- Providers of whistleblower platforms,
- Providers of accounting solutions
- Providers of Microsoft productivity tools
- Providers of translation tools
- ENERPARC AG
Recipients outside the European Union: Outside the European Union, your data is processed by the following specific companies (recipients):
- Microsoft: Various applications from Microsoft Corporation (U.S.) are used; Microsoft has been appointed as a processor in accordance with Article 28 of the GDPR, namely: Microsoft 365 Cloud, Microsoft Teams (project management tool), Microsoft Teams (video conferencing tool), Microsoft Bookings, Microsoft Forms, and SharePoint. A transfer of data to a third country (in this case, the U.S.), which cannot be ruled out, is justified under Article 45 of the GDPR.
- New Relic: The website monitoring tool “New Relic” from New Relic, Inc. (USA) is used; New Relic, Inc. has been appointed as a processor in accordance with Article 28 of the GDPR. A transfer of data to a third country (in this case, the U.S.), which cannot be ruled out, is justified under Article 45 of the GDPR.
- Lacework: We use the IT security tool “Lacework” from Lacework, Inc. (U.S.). A transfer of data to a third country (in this case, the U.S.), which cannot be ruled out, is justified under Article 46 of the GDPR.
- ShareFile: The IT tool “ShareFile” from Citrix Systems Inc. (U.S.) is used; this company has been appointed as a processor in accordance with Article 28 of the GDPR. A data transfer to a third country (in this case, the U.S.), which cannot be ruled out, is justified under Article 46 of the GDPR.
- Monday.com: The collaboration tool “Monday.com” from Monday.com Ltd. (Israel) is used. A data transfer to a third country (in this case, Israel), which cannot be ruled out, is justified under Article 45 of the GDPR.
- Atlassian: The project management tool provided by Atlassian Pty Ltd (Australia) is used; this company has been appointed as a processor in accordance with Article 28 of the GDPR. A data transfer to a third country (in this case, Australia), which cannot be ruled out, is justified under Article 46 of the GDPR.
- Autodesk: The “Autodesk” project management tool from Autodesk, Inc. (USA) is used; Autodesk, Inc. has been appointed as a data processor in accordance with Article 28 of the GDPR. A transfer of data to a third country (in this case, the U.S.), which cannot be ruled out, is justified under Article 46 of the GDPR for employee data and under Article 45 of the GDPR for all other data.
Special Notes Regarding Responsibilities:
To the extent that we maintain corporate pages on social media platforms or networks, please note that
- to the extent that we analyze your use of our corporate page, we and the respective provider are jointly responsible under data protection law in accordance with Article 26 of the GDPR.
- In all other cases, we have engaged the providers as processors in accordance with Article 28 of the GDPR.
Use of the Website
You have the option to use our website for informational purposes only. This means that you simply visit the site without clicking on anything or entering any information. Even in this case, we process the following data from you so that the website can be displayed in your browser at all:
- IP address,
- Date and time of the request,
- Time zone difference from Greenwich Mean Time (GMT),
- Content of the request (specific page),
- Access status/HTTP status code,
- Amount of data transferred,
- the page from which the request originated,
- Browser,
- operating system and its user interface,
- language and version of the browser software.
The legal basis for this is Article 6(1), first sentence, subparagraph (f) of the GDPR, whereby our legitimate interest arises from this purpose.
Web Hosting
We use an external web hosting provider to make our website accessible. To this end, the web host processes all data already mentioned in the previous section (Display of the Website). The legal basis for this is Article 6(1), first sentence, (f) of the GDPR, whereby our legitimate interest arises from this purpose.
Cookie Consent
We give you the option to consent to the use of cookies and use a cookie consent tool for this purpose. In doing so, we process all data already mentioned in the previous section (Website Display), as well as information regarding whether, to what extent, and when you have given your consent. The purpose of this processing is to fulfill a legal obligation (Article 7(1) of the GDPR). The legal basis is Article 6(1), first sentence, letter c of the GDPR.
Recruiting
: You have the option to apply for a position with us through the recruiting section of our website or via other contact channels. We collect this data to determine whether we can proceed with the application process. The legal basis is Article 6(1), first sentence, subparagraph (b) of the GDPR. In all other respects, our privacy policy for employees applies.
Analysis of User Behavior
We use cookies to analyze how you arrive at our website and what exactly you do there. Cookies are text files stored on your computer that enable us to perform this analysis (reports on your activities and interactions on the website, e.g., sequence of interactions, duration of visit).
We use this data and these analyses to improve our website and the user experience and to tailor them specifically to you and other data subjects. Further details can be found in the information about the tools (see below).
The purpose of this processing is to optimize our website. The legal basis is Article 6(1), first sentence, letter a of the GDPR.
Social Media/Networks
We are active on social media and networks. If you access our company pages on social media/networks from our website, certain data about you will be processed. This also applies, of course, if you access these pages through other means rather than via our website.
We would like to make it clear from the outset that we have no control over what data is processed, how it is processed, or how long it is stored. There is always the possibility that the providers of these platforms may store your data and use it for advertising purposes, market research, and/or to tailor their services to your needs. Further details can be found below in the information about the providers.
The following data is processed in this context:
- cookie- or pixel-based data regarding your interactions with our company websites,
- your email address,
- your name,
- your contact information
The purpose of this processing is to present our company. The legal basis is Article 6(1), first sentence, letter a of the GDPR.
Video Playback
Our website displays videos that are embedded via plugins from video and streaming portals. Each time you access a subpage or page containing a video clip, a direct connection is established to a server of the video portal. Further details can be found in the information provided by the respective providers.
The following data is processed in this context:
- cookie-based data regarding your interactions with the video subpages,
- information about which video you clicked on
The purpose of this processing is to display videos and optimize our website. The legal basis is Article 6(1)(a) of the GDPR.
Data Processing When Exercising Rights
If you exercise your rights under the GDPR or other legal provisions, we process your data to review these claims and, if necessary, fulfill them. The purpose of this processing is to comply with a legal obligation. The legal basis for this is Article 6(1), first sentence, (c) of the GDPR in conjunction with the respective statutory provision from which your right or claim arises.
Data Retention/Retention Period
We retain your data both during and after the end of the contract. Here we inform you how long the data will be stored:
- If you exercise your rights under the GDPR, communication data (correspondence via email, mail, etc.) is generated. We retain this data for three years. This period begins on December 31 of the calendar year in which we responded to your request. In doing so, we are pursuing our own legitimate interests. This is because, in the event of a dispute, we want to be able to prove that we have handled your claims correctly. The legal basis is Article 6(1), first sentence, letter f of the GDPR. The three-year period is based on the statute of limitations for claims for damages (Sections 195, 199(1) of the German Civil Code (BGB)) and, supplementarily, on the statute of limitations provisions under administrative offense law (Section 31(2)(1) of the German Administrative Offenses Act (OWiG) in conjunction with Article 83 of the GDPR).
- If you assert other rights not covered by the GDPR, communication data will also be generated, which we retain for three years. This period begins on December 31 of the calendar year in which we responded to your request. In doing so, we are pursuing our own legitimate interests. This is because, in the event of a dispute, we want to be able to prove that we handled your claims correctly. The legal basis is Article 6(1), first sentence, subparagraph (f) of the GDPR. The three-year period is based on the statute of limitations for claims for damages (Sections 195, 199(1) of the German Civil Code (BGB)).
- If you consent to data processing, we
will store the information that you have given your consent for three years. This period begins as soon as you withdraw your consent or the associated purpose ceases to exist, whichever occurs first. In doing so, we are pursuing our own legitimate interests. This is because, in the event of a dispute, we want to be able to prove that we have handled your claims correctly. The legal basis is Article 6(1), first sentence, letter f of the GDPR. The three-year period is governed by the statute of limitations provisions for claims for damages (Sections 195, 199(1) of the German Civil Code (BGB)) and, supplementarily, on the statute of limitations provisions under administrative offense law (Section 31(2)(1) of the German Administrative Offenses Act (OWiG) in conjunction with Article 83 of the GDPR).
- We store the data we process based on your consent until you revoke your consent. The purpose is set forth in the respective consent form, and the legal basis for this is Article 6(1), first sentence, subparagraph (a) of the GDPR.
Deletion of Data
As soon as the aforementioned retention periods expire, we will delete your data. In doing so, we fulfill a legal obligation (Article 5(1)(a), (e) of the GDPR). The legal basis is Article 6(1), first sentence, subparagraph (c) of the GDPR.
Recipients
Recipients within the European Union: Within the European Union, your data is processed by companies (recipients) in the following categories:
- Hosting providers
- Providers of cookie consent tools
- Social networks
- Law, tax, and auditing firms
- Project management tools,
- Providers of whistleblower platforms,
- Providers of accounting solutions
- Providers of Microsoft productivity tools
- Providers of translation tools
Recipients outside the European Union: Outside the European Union, your data is processed by the following specific companies (recipients):
- Google: Various applications from Google Ireland Ltd. (Ireland – EU) are used; this company has been appointed as a processor pursuant to Article 28 of the GDPR. A transfer of data to a third country (in this case, to Google LLC in the U.S.), which cannot be ruled out, is justified under Article 45 of the GDPR. The following Google tools are used:
- We use Google Analytics. Google generally processes IP addresses only within the European Union or the signatory states of the Agreement on the European Economic Area. Only in exceptional cases is the full IP address transmitted to a server operated by the provider in the United States and truncated there. To the best of our knowledge, the transmitted IP address is not combined with other data. We also use Google Analytics for cross-device analysis of visitor traffic, which is carried out via
a user ID.- We use Google Remarketing and Google Ads. Here’s how it works: When you interact with us online—for example, by visiting our website—you may be identified as a suitable recipient of advertisements (so-called “ads”) through the use of cookies (so-called ad server cookies). These cookies also allow us to measure and evaluate the success of an advertising campaign. If you subsequently visit Google sites (YouTube, the Google search engine, etc.), you will be recognized based on these cookies, and our “ads” will be displayed to you (so-called “remarketing”). This occurs when your browser automatically establishes a direct connection to Google’s server. The “ads” are then delivered via Google ad servers. The ad server cookies used in this process are generally valid for 30 days and are not used for personal identification. Typically, the following analytics data is stored: a unique cookie ID, the number of ad impressions per placement (frequency), the last impression (relevant for post-view conversions), and opt-out information (indicating that you do not wish to receive further ads).
- You can restrict or prevent tracking, for example, (a) by adjusting the settings in your browser software (in particular, blocking third-party cookies prevents you from receiving advertisements) or (b) by disabling cookies for conversion tracking by configuring your browser to block cookies from the provider’s domain. However, this setting will be reset if you clear the cookies in your browser.
- The purpose of this processing is to present our company, analyze user behavior regarding interaction with our website, and communicate with you via social media, including for advertising purposes
where applicable.- We use Google Tag Manager. Here’s how it works: This tool allows us to integrate various codes and services into our website in a structured and simplified manner. The tool implements so-called “tags” or triggers the integrated tags. When a tag is triggered, Google may also process personal data under certain
circumstances. - We use DoubleClick. Here’s how it works: DoubleClick uses cookies to show you relevant ads, improve campaign performance reports, or prevent you from seeing the same ads multiple times. Using a cookie ID, Google tracks which ads were displayed in which browser to avoid duplicate ads. In addition, the use of cookie IDs enables the tracking of so-called conversions related to ad requests. This is the case, for example, if you see a DoubleClick ad and later visit our company’s website using the same browser and make a purchase there. Through the marketing tools we use, your browser automatically establishes a direct connection to Google’s server. Through the integration of DoubleClick, Google receives the information that you have accessed the relevant part of our website or clicked on one of our ads. If you are registered with a Google service, Google can associate the visit with your respective account. Even if you are not registered or logged in, it is possible that Google will collect and store your IP address.
- Google Maps: We use Google Maps. Please note the following: Google Maps is a map display tool. The specific data transmitted depends, among other things, on whether users are logged into a Google account while using this website. - X (formerly Twitter): The social network “X” operated by Twitter International Company (Ireland – EU) is used. Further details on how this provider processes data are described here: twitter.com/de/privacy. A transfer of data to a third country (in this case, the U.S.), which cannot be ruled out, is justified under Article 46 of the GDPR. The data controller uses this social network as follows: to operate a company page. The terms used here are explained in the glossary at the end of this statement.
- LinkedIn: The social network “LinkedIn” operated by LinkedIn Ireland Unlimited Company (Ireland – EU) is used. A transfer of data to a third country (in this case, the U.S.)—which cannot be ruled out—is justified in accordance with Article 46 of the GDPR. The data controller uses this social network as follows: to operate a company page. The terms used here are explained in the glossary at the end of this statement.
Initial Contact During the Application Process
During the application process, we receive and review your application materials. This involves the collection of all data you provide about yourself. If we remain interested, this is followed by a job interview, during which data (contact information, typically name, phone number, and email address) is collected, stored, and used to schedule the interview. If we remain interested, we will extend an offer of employment to you, in which case your contact information (typically name, phone number, and email address) and the information from the employment contract (typically job description, vacation time, and salary) will be processed. At any of the aforementioned processing stages, it is also possible that your application may be rejected. The purpose of the aforementioned processing operations is to conduct the application process. The legal basis is Article 6(1), first sentence, letter b of the GDPR.
Active Recruiting
Prior to the application process, we research information about potential employees from publicly available sources. We will contact you. In doing so, we process the data necessary to establish contact (e.g., name, address, email address) as well as job-specific data regarding your qualifications (e.g., degrees, certificates, etc.). The purpose of the aforementioned processing operations is to initiate the application process. The legal basis is Article 6(1), first sentence, letter b of the GDPR.
Request for Certificates and Documentation
We request specific certificates and qualifications that are essential for the performance of the job. In doing so, we process the data contained in the certificates and other relevant documents. The purpose of the aforementioned processing operations is to initiate the application process and, subsequently, to carry out the employment relationship. The legal basis is Article 6(1), first sentence, letter b of the GDPR.
Conducting a Trial Work Day
You will participate in a trial work day, and we will record our observations, which we will subsequently use to make a decision regarding your application. In doing so, we process the data necessary to contact you (e.g., name, address, email address) as well as any notes taken during the trial workday. The purpose of the aforementioned processing activities is to initiate the application process. The legal basis is Article 6(1), first sentence, letter b of the GDPR.
Video Conferences
In some cases, you may communicate with us via video conference. In doing so, we process the resulting video and audio data as well as any transcripts that may be created. The purpose of this processing is either to negotiate a contract with you or, at a later stage, to fulfill it. The legal basis is Article 6(1), first sentence, subparagraph (b) of the GDPR.
Recordings are made only if we propose this and you consent. To fulfill a legal obligation (Article 7(1) of the GDPR), we first store the information indicating whether you have given your consent. The legal basis for this is Article 6(1), first sentence, subparagraph (c) of the GDPR. We then record the conversation and store the resulting video and audio data to document the conversation. The legal basis for this is Article 6(1), first sentence, subparagraph (a) of the GDPR. The prohibition under Article 9(1) of the GDPR does not preclude this, as the exception under Article 9(2)(a) of the GDPR applies.
Performance of the Employment Relationship
During the active employment relationship, all access and/or communication data related to the fulfillment of the employment contract (e.g., emails) are processed. The purpose of the aforementioned processing operations is the performance of the employment relationship. The legal basis is Article 6(1), first sentence, subparagraph (b) of the GDPR.
Collection of Driver’s License Data
Only if we provide you with a company car to fulfill your obligations under your employment contract will we collect your driver’s license data in advance through an external provider, with whom you can have your driver’s license digitally recorded. In this process, all driver’s license data is processed. The purpose is to fulfill our traffic safety obligations and our obligations to insurers, specifically to ensure that you are authorized to drive a company car. The legal basis is Article 6(1), first sentence, subparagraph (f) of the GDPR, whereby the legitimate interest arises from the aforementioned purposes.
Employee Benefits (Based on Legitimate Interest)
(1) In certain select cases, we offer you the opportunity to take advantage of so-called employee benefits. (2) We transfer the contact information required to grant these benefits to external third-party providers (typically your name, address, and the fact that you are employed by us). The purpose is to grant benefits; this serves to retain employees and enhance our attractiveness as an employer. The legal basis is Article 6(1), first sentence, letter f of the GDPR, whereby the legitimate interest arises from the aforementioned purpose. Whether benefits are granted—and, if so, which ones—is subject to an agreement under labor law, which may still need to be concluded separately from this privacy notice. The mere mention of this possibility does not give rise to any entitlement on your part.
Issuance of Keys (including Logging)
In some cases, you will receive keys and/or access cards for entry to company premises, and the issuance of these items is logged. In doing so, we process the following data: name, status of the issuance of the aforementioned items. The purpose of the aforementioned processing operations is to fulfill a data protection obligation, namely that of implementing adequate organizational security measures. The legal basis is Article 6(1), first sentence, letter c of the GDPR in conjunction with Article 32 of the GDPR.
Issuance of Access Credentials (including logging)
In some cases, you will receive access credentials for company software and hardware; both these access credentials and their assignment to you are recorded and stored. The assignment itself is also logged. In doing so, we process the following data: name, access credentials, and the status of the assignment of the access credentials. The purpose of the aforementioned processing operations is to fulfill a data protection obligation, namely the obligation to implement adequate organizational security measures. The legal basis is Article 6(1), first sentence, letter c of the GDPR in conjunction with Article 32 of the GDPR.
Issuance of Company Equipment (including Logging)
In some cases, you will receive company hardware, and the issuance of this equipment is logged. In doing so, we process the following data: name, status of the hardware issuance. The purpose of the aforementioned processing operations is the internal organization of the services owed under the employment contract. The legal basis is Article 6(1), first sentence, subparagraph (f) of the GDPR, whereby the legitimate interest arises from the aforementioned purpose.
Mental Health Coaching
(1) In certain selected cases, we offer you the opportunity to participate in mental health coaching. (2) If you decide to do so, we will obtain the necessary consent. For this purpose, we process your name, the date and time, and the status of your consent. The purpose is to comply with a legal obligation. The legal basis is Article 6(1), first sentence, subparagraph (c) of the GDPR in conjunction with Article 7(1) of the GDPR. (3) We do not process any data regarding participation in the coaching sessions and/or their content ourselves; rather, we only receive an invoice. The legal basis is Article 6(1), first sentence, letter a of the GDPR.
Changes to Data Processing
If we make changes to our data processing—in particular, if we engage new recipients—we will notify you of the change via email by sending you the updated privacy policy. The purpose is to fulfill the transparency obligations under the GDPR (Articles 12 through 14 of the GDPR). The legal basis is Article 6(1), first sentence, letter c of the GDPR.
Exercising Rights
If you exercise your rights under the GDPR or other legal provisions, we will process the data to review these claims and, if necessary, fulfill them. The purpose is to comply with a legal obligation. The legal basis is Article 6(1), first sentence, subparagraph (c) of the GDPR in conjunction with the provision from which the legal obligation arises.
Labor Disputes
In the event of a labor law dispute between you and us, the data will be processed to issue relevant statements and, if necessary, to seek external legal counsel. The following data is processed in this context: name, contact information, and all matters related to the labor law dispute. The processing serves the purpose of obtaining external labor law advice and support, as well as exercising our own rights. The legal basis is Article 6(1), first sentence, subparagraph (f) of the GDPR, whereby the legitimate interest arises from the aforementioned purposes. To the extent that data is processed externally, this does not constitute commissioned processing (see DSK Brief 13), but rather a data transfer, which in turn is justified by Article 6(1), first sentence, letter f of the GDPR. This therefore constitutes a case of other outsourcing.
Receipt and Processing of Whistleblower Reports
We offer you the opportunity to contact us as a so-called whistleblower. Incoming whistleblower reports from employees are acknowledged and processed. Personal data is processed only to the extent that the report is not submitted anonymously. The data processed in such cases includes the following: name(s), content of the report. The purpose of the processing is to fulfill a legal obligation under Sections 12 et seq. of the HinSchG. The legal basis is Article 6(1), first sentence, subparagraph (c) of the GDPR.
Production of Media Recordings
(1) In certain selected cases, we allow you to have media recordings (photos, video, audio) made. (2) If you decide to do so, we will obtain the necessary consent. For this purpose, we process the name, time, and status of the consent. The purpose is to fulfill a legal obligation. The legal basis is Article 6(1), first sentence, subparagraph (c) of the GDPR in conjunction with Article 7(1) of the GDPR. (3) Media recordings will be made of you and, to the extent permitted by your consent, may also be published in certain cases to be determined by us. In doing so, we process image, video, and audio data. The purpose is to present our company to the public. The legal basis is Article 6(1), first sentence, subparagraph (a) of the GDPR. This is not precluded by the prohibition under Article 9(1) of the GDPR, as the exception under Article 9(2)(a) of the GDPR applies here.
Fulfilment of Additional Legal Obligations
In the context of the employment relationship, data is processed to fulfil additional legal obligations not yet mentioned here. These include the following scenarios:
- Processing of all data regarding participation in training courses and instruction, including, in particular, first aid training (Section 14 of Book VII of the Social Code [SGB VII] in conjunction with DGUV Regulation 1), Conducting data protection training for employees (Article 32 of the GDPR), training for EuP (Section 14 of SGB VII in conjunction with DGUV Regulation 3), Driver safety training (Section 3 of the Occupational Safety Regulation (ArbSichV)), fire extinguisher training (Section 14 of Book VII of the Social Code (SGB VII) in conjunction with DGUV Regulation 1), and IT training (BSI Critical Infrastructure Regulation, Article 32 of the GDPR). The following data is processed in this context: name, work contact information, communication data, status, and, if applicable, the date and time of participation (day, time).
- Processing of all data when ordering hardware or software that must be provided for occupational safety reasons, e.g., computer glasses (Section 3 of the Occupational Safety Act (ArbSchG)). The following data is processed in this context: name, work-related contact information, communication data, proof of the necessity of the hardware or software, date of order, date of delivery, date of commissioning, and costs.
- Processing of all data in connection with maintaining a first-aid logbook, in particular the retention of completed first-aid logbook pages (Section 14 of Book VII of the Social Code [SGB VII] in conjunction with DGUV Regulation 1, Section 24(6)). The following data is processed in this context: name, workplace contact information, communication data, data on all first-aid incidents, in particular the type of incident, time, measures taken, and the identities of the assisting and affected employees/individuals.
- Processing of all data generated in connection with occupational medical examinations (§ 3 ArbSchG). The following data is processed in this context: name, workplace contact information, communication data, time of the appointment, and status regarding attendance at the appointment.
- Processing of all data collected in connection with occupational eye examinations (Section 3 of the Occupational Safety and Health Act (ArbSchG)). The following data is processed in this context: name, workplace contact information, communication data, appointment time, and status regarding attendance at the appointment.
- Other training courses for which training obligations currently exist or may exist in the future. The following data is processed in this context: name, work-related contact information, communication data.
All processing steps serve to fulfill the legal obligations specified in the respective parenthetical notes. The legal basis is Article 6(1), first sentence, letter c of the GDPR in conjunction with the provisions specified in the respective parenthetical note.
Fulfillment of Additional Obligations
Under the Employment Contract: Within the employment relationship, data is processed for the purpose of carrying out the employment relationship. This includes, in particular but not exclusively, the following scenarios:
- The filing of planning documents and documentation related to substation suppliers is recorded, stored, and further utilized. The following data is processed in this context: name, company contact information, communication data, status and time of entry, and the identity of the employee making the entry.
- Documentation regarding the filing of planning documents and documentation related to substation installers is collected, stored, and further used. The following data is processed in this context: name, company contact information, communication data, status and date/time of entry, and the identity of the employee making the entry.
- Absences due to parental leave, illness, vacation, special leave, educational leave, and unpaid leave are recorded, stored, and further processed. The following data is processed in this context: name, work contact information, communication data, time period, reason, and supporting documentation for the reason for the absence.
- In the case of procurements/purchases, including orders for work clothing that concern you, the following data is collected, stored, and used: name, work contact information, communication data, clothing size, assignment of work clothing, and condition of the work clothing.
- Internal communication takes place regarding the management of work clothing. The following data is processed in this context: name, work contact information, communication data, clothing size, assignment of work clothing, and condition of the work clothing.
- In certain cases, electronic signatures are obtained. The following data is processed in this context: name, work contact information, communication data, signature image, time of signature, and content of the signed document.
- Hotel reservations are made and documented on your behalf. The following data is processed in this context: name, company contact information, communication data, business trip status, business trip dates, business trip expenses.
- The reimbursement of other travel expenses for business trips is recorded, stored, and used. The following data is processed in this context: name, company contact information, communication data, status of the business trip, duration of the business trip, and costs of the business trip.
All processing steps serve the purposes of internal communication and the fulfillment of obligations under employment contracts. The legal basis is Article 6(1), first sentence, letter b of the GDPR.
Video Recordings on the Premises of the Solar Parks
Our solar parks are under video surveillance, and the video surveillance data (image data, recording period, recording location) is processed to protect our right of access to our premises, our property, and our possessions, as well as to fulfill legal obligations (Article 32 of the GDPR: access control, Section 8a of the BSI Act: special security measures). Furthermore, still images are recorded several times a day to measure and statistically evaluate any environmental impacts (e.g., hail, snowfall). To the extent that the processing serves to protect our right to control our premises, our property, and our possessions, the legal basis is Article 6(1), first sentence, subparagraph (f) of the GDPR, whereby the legitimate interest arises from the aforementioned purposes. To the extent that the processing serves to fulfill legal obligations, the legal basis is Article 6(1), first sentence, letter c of the GDPR. To the extent that the processing serves to measure and evaluate any environmental impacts, the legal basis is Article 6(1), first sentence, (f) of the GDPR, whereby the legitimate interest arises from the aforementioned purpose.
Data Retention/Retention Period
We retain your data both during and after the end of the contract. Here we inform you how long the data will be stored:
- We retain booking documents for eight years. This period begins on December 31 of the calendar year in which the respective document was created. We are legally obligated to do so (Section 147 of the German Fiscal Code (AO), Section 257 of the German Commercial Code (HGB)), and the legal basis is Article 6(1), first sentence, letter c of the GDPR in conjunction with the respective statutory provision from which your right or claim arises.
- Other internal records (e.g., annual financial statements), business communication data (e.g., customer letters), and other tax-related documents must be retained for 6 years, beginning on December 31 of the calendar year in which the respective document was created. The processing serves to fulfill a legal obligation and is based on Article 6(1), first sentence, letter c of the GDPR in conjunction with § 147 of the German Fiscal Code (AO) and § 257 of the German Commercial Code (HGB).
- Data from working time records must be retained for 2 years, beginning on December 31 of the calendar year in which the respective document was created. The processing serves to fulfill a legal obligation and is based on Article 6(1), first sentence, letter c of the GDPR in conjunction with § 16 of the Working Hours Act (ArbZG) and § 17 of the Minimum Wage Act (MiLoG).
- Data from the payroll records must be retained for 6 years, beginning on December 31 of the calendar year in which the last recorded payroll payment was made. The processing serves to fulfill a legal obligation and is based on Article 6(1), first sentence, letter c of the GDPR in conjunction with § 41 of the Income Tax Act (EStG).
- Data regarding health insurance status and sick leave are retained for 5 years. The processing serves to fulfill a legal obligation and is based on Article 6(1), first sentence, letter c of the GDPR in conjunction with § 198 of the SGB V and § 165 of the SGB VII.
- Data generated when you assert data protection claims is retained for three years, beginning on December 31 of the calendar year in which we responded to your claim. The processing serves to protect the interest in defending against claims and is based on Article 6(1), first sentence, letter f of the GDPR, whereby the legitimate interest arises from the aforementioned purpose. The duration of the legitimate interest is determined by the statute of limitations provisions for claims for damages (Sections 195, 199(1) of the German Civil Code (BGB)) and, supplementarily, from the statute of limitations provisions under administrative offense law (Section 31(2)(1) of the German Administrative Offenses Act (OWiG) in conjunction with Article 83 of the GDPR).
- Data generated when you assert other claims will be retained for three years, beginning on December 31 of the calendar year in which we responded to such claims. The processing serves to safeguard the interest in defending against claims and is based on Article 6(1), first sentence, subparagraph (f) of the GDPR, whereby the legitimate interest arises from the aforementioned purpose. The duration of the legitimate interest is determined by the statute of limitations for claims for damages (Sections 195, 199(1) of the German Civil Code (BGB)).
- Data processed on the basis of consent must be retained until the consent is revoked or until the purpose associated with the processing no longer applies, whichever occurs first. Retention serves the purpose associated with the consent and is based on Article 6(1), first sentence, letter a of the GDPR.
- Data proving that consent was given must be retained for 3 years, beginning on the date consent is revoked or the purpose ceases to exist, whichever occurs first. The processing serves to safeguard the interest in defending against claims and is based on Article 6(1), first sentence, letter f of the GDPR, whereby the legitimate interest arises from the aforementioned purpose. The duration of the legitimate interest is determined by the statute of limitations provisions under administrative offense law (Section 31(2)(1) of the German Administrative Offenses Act (OWiG) in conjunction with Article 83 of the GDPR).
- Data from a job application is retained for 6 months, beginning on the date the rejection notice is received. The processing serves to safeguard the interest in defending against claims under the AGG and is based on Article 6(1), first sentence, (f) of the GDPR, whereby the legitimate interest arises from the aforementioned purpose. The duration of the legitimate interest is determined by the time limits set forth in Section 15(4) of the Unfair Competition Act (UWG), plus the period after which the receipt of a complaint can no longer be expected.
- Video recordings on the solar park premises are generally retained for only 48 hours. The legal basis is Article 6(1), first sentence, (f) of the GDPR, whereby the legitimate interest arises from the aforementioned purposes (protection of our right of access to our premises, our property, and our possessions). If these purposes are compromised (e.g., trespassing, theft, property damage), we retain the data for as long as necessary to pursue our rights (e.g., claims for damages), but we will delete it no later than upon final clarification of the facts.
- We retain still images derived from the video recordings and created for the purpose of measuring and evaluating any environmental impacts for a maximum of 5 years, with the period beginning on December 31 of the calendar year in which the recordings were made. The legal basis is Article 6(1), first sentence, subparagraph (f) of the GDPR, whereby the legitimate interest arises from the aforementioned purpose.
Deletion of Data
The data is deleted upon expiration of the retention periods. The erasure serves to fulfill a legal obligation and is based on Article 6(1), first sentence, letter c of the GDPR in conjunction with Article 5(1), letters a and e of the GDPR.
Recipients
The following recipients and other external parties process your data:
Recipients within the European Union: Within the European Union, your data is processed by companies (recipients) in the following categories:
- Backup tool providers
- Software hosting companies,
- Providers of video conferencing systems and remote work tools,
- law firms, tax firms, and auditing firms,
- Providers of password management systems,
- project management tools,
- providers of whistleblower platforms,
- providers of compliance and training solutions,
- providers of (payroll) accounting solutions,
- Providers of Microsoft productivity tools,
- Providers of translation tools,
- Providers of work equipment (e.g., work clothing),
- Providers of HR systems,
- Providers of employee benefits,
- Providers of security and surveillance services.
- Social media providers (for recruiting purposes)
- ENERPARC AG
Recipients outside the European Union: Outside the European Union, your data is processed by the following specific companies (recipients):
- Microsoft: Various applications from Microsoft Corporation (U.S.) are used; Microsoft has been appointed as a processor in accordance with Article 28 of the GDPR, namely: Microsoft 365 Cloud, Microsoft Teams (project management tool), Microsoft Teams (video conferencing tool), Microsoft Bookings, Microsoft Forms, and SharePoint. A transfer of data to a third country (in this case, the U.S.), which cannot be ruled out, is justified under Article 45 of the GDPR.
- New Relic: The website monitoring tool “New Relic” from New Relic, Inc. (USA) is used; New Relic, Inc. has been appointed as a processor in accordance with Article 28 of the GDPR. A transfer of data to a third country (in this case, the U.S.), which cannot be ruled out, is justified under Article 45 of the GDPR.
- Lacework: We use the IT security tool “Lacework” from Lacework, Inc. (U.S.). A transfer of data to a third country (in this case, the U.S.), which cannot be ruled out, is justified under Article 46 of the GDPR.
- ShareFile: The IT tool “ShareFile” from Citrix Systems Inc. (U.S.) is used; this company has been appointed as a processor in accordance with Article 28 of the GDPR. A data transfer to a third country (in this case, the U.S.)—which cannot be ruled out—is justified under Article 46 of the GDPR.
- Monday.com: The collaboration tool “Monday.com” from Monday.com Ltd. (Israel) is used. A data transfer to a third country (in this case, Israel), which cannot be ruled out, is justified under Article 45 of the GDPR.
- Atlassian: The project management tool provided by Atlassian Pty Ltd (Australia) is used; this company has been appointed as a processor in accordance with Article 28 of the GDPR. A data transfer to a third country (in this case, Australia), which cannot be ruled out, is justified under Article 46 of the GDPR.
- Autodesk: The “Autodesk” project management tool from Autodesk, Inc. (USA) is used; Autodesk, Inc. has been appointed as a processor in accordance with Article 28 of the GDPR. A transfer of data to a third country (in this case, the U.S.)—which cannot be ruled out—is justified under Article 46 of the GDPR for employee data and under Article 45 of the GDPR for all other data.
- Adobe: In connection with the use and creation of documents, software solutions from Adobe Systems Software Ireland Limited (Ireland—EU) are used; this company has been appointed as a processor in accordance with Article 28 of the GDPR. A transfer of data to a third country (in this case, to Adobe Inc., USA), which cannot be ruled out, is justified for employee data in accordance with Article 46 of the GDPR and for all other data in accordance with Article 45 of the GDPR.
- LinkedIn (social network): The “LinkedIn” social network operated by LinkedIn Ireland Unlimited Company (Ireland – EU) is used. However, it cannot be ruled out that data may be transferred to or integrated with the parent company, LinkedIn Corporation (USA). A data transfer to a third country (in this case, the USA), which cannot be ruled out, is justified under Article 46 of the GDPR. The following tools are used: LinkedIn (Company Page), LinkedIn (Recruiting)
- Dropbox: We use the “Dropbox” cloud service provided by Dropbox, Inc. (U.S.), which has been appointed as a processor in accordance with Article 28 of the GDPR. A data transfer to a third country (in this case, the U.S.), which cannot be ruled out, is justified under Article 45 of the GDPR.
As of: July 1, 2025