Privacy Policy
Introduction
We, coneva GmbH, Paul-Heyse-Str. 2–4, 80336 Munich, as the operator of the online offering, are the controller responsible for the processing of the personal data of the users of the online offering. You will find our contact details in the legal notice of the online offering, and the contact persons for questions regarding the processing of personal data are named directly in this privacy policy. We take the protection of your privacy and your personal data very seriously. We collect, store, and use your personal data only in accordance with the content of this privacy policy and the applicable data protection regulations, in particular the European General Data Protection Regulation (GDPR) and national data protection laws. We place great importance on justifying the trust you place in us, especially in this regard. We therefore protect your personal data in particular against access by unauthorized persons. With this privacy policy we aim to inform you about the extent and the purpose for which personal data is processed in connection with the use of the online offering.
Personal Data
Personal data refers to information relating to an identified or identifiable natural person. This includes all information relating to your identity, such as your name, email address, or postal address. Information that cannot be associated with your identity (such as statistical data, e.g., the number of users of the online offering) does not qualify as personal data. You can generally use our online offering without disclosing your identity and without providing personal data. In that case, we only collect general information regarding your visit to our online offering. For some services offered, however, personal data will be collected from you. These data are generally processed only for the purposes of using this online offering, in particular to provide the information requested. When collecting personal data, only those data that are strictly necessary are required as mandatory fields. Additional information may be possible but is voluntary. We will always indicate whether information is mandatory or voluntary. Details are provided in the corresponding section of this privacy policy. No automated decision-making based on your personal data takes place in connection with the use of our online offering.
Processing of Personal Information
Your information is stored on specially protected servers within the European Union. These servers are protected through technical and organizational measures against loss, destruction, access, alteration, or dissemination of your data by unauthorized persons. Access to your data is only possible for a limited number of authorized persons. These persons are responsible for the technical, commercial, or editorial management of the servers. Despite regular checks, complete protection against all risks cannot be guaranteed. Your personal data is transmitted in encrypted form over the internet. We use SSL encryption (Secure Socket Layer) for data transmission.
Disclosure of Personal Data to Third Parties
We use your personal information exclusively to provide the services you request. Where we use external service providers in the course of providing services, their access to the data is limited exclusively to the purpose of service provision. Through technical and organizational measures, we ensure compliance with data protection requirements and also oblige our external service providers to do so. Beyond this, we do not disclose data to third parties without your explicit consent, particularly not for advertising purposes. Disclosure of your personal data occurs only if you have given consent or if we are authorized or obligated to do so pursuant to legal provisions and/or administrative or judicial orders. This may include disclosure for purposes of criminal prosecution, hazard prevention, or enforcement of intellectual property rights.
Legal Bases for Data Processing
Where we obtain consent from you for the processing of personal data, Art. 6(1)(a) GDPR serves as the legal basis. Where we process your personal data because this is necessary for the performance of a contract or a quasi-contractual relationship with you, Art. 6(1)(b) GDPR is the legal basis. Where we process your personal data in order to comply with a legal obligation, Art. 6(1)(c) GDPR is the legal basis. Furthermore, Art. 6(1)(f) GDPR may serve as the legal basis where processing is necessary for the purposes of a legitimate interest pursued by our company or by a third party and where your interests, fundamental rights, and freedoms do not require the protection of your personal data. Within this privacy policy, we always indicate the legal basis on which the processing of your personal data is based.
Data Deletion and Storage Duration
We delete or block your personal data as soon as the purpose of storage no longer applies. Storage may take place beyond this if required by legal regulations to which we are subject, such as statutory retention and documentation obligations. In such cases, we delete or block your personal data once the relevant retention periods have expired.
General Provisions on Use of the Online Offering
Information About Your End Device
Each time you access our online offering, we collect the following information about your end device, regardless of registration: the IP address of your device, your browser request, and the time of the request. We also collect the status and the amount of data transmitted in the context of this request. We collect product and version information regarding the browser used and the operating system of the end device. We also collect information regarding the website from which access to the online offering occurred. The IP address of your end device is stored only for the duration of your use of the online offering and deleted or anonymized thereafter. The remaining data is stored for a limited period. We use these data to operate the online offering, in particular to detect and eliminate errors, to determine usage levels, and to make adjustments or improvements. For technically necessary cases, these purposes also constitute our legitimate interest pursuant to Art. 6(1)(f) GDPR. For all other cases, your consent — if granted — is the legal basis pursuant to Art. 6(1)(a) GDPR.
Use of Cookies
For our online services, we use cookies—as is the case on many websites. Cookies are small text files that are stored on your computer and save certain settings and data for exchange with our online services via your browser. A cookie generally contains the name of the domain from which the cookie file was sent, as well as information about the age of the cookie and an alphanumeric identifier. Cookies enable us to recognize your device and make any preset configurations immediately available. Cookies help us improve the online services and offer you a better and more tailored service. This also constitutes our legitimate interest in data processing pursuant to Art. 6 para. 1 lit. f) GDPR. For cookies that exceed the technically necessary scope, we request your consent via our cookie banner. If you do not provide such consent, we will naturally not set any cookies. In the event you grant consent, this also serves as the legal basis for our processing pursuant to Art. 6 para. 1 lit. a) GDPR.
The cookies we use are so-called session cookies, which are automatically deleted after the end of the browser session. In addition, cookies with a longer storage period are used so that your preset configurations and preferences can also be taken into account during your next visit to our online services. Most browsers are configured to automatically accept cookies. However, you can disable the storage of cookies or configure your browser to notify you whenever cookies are being sent. It is also possible to manually delete already stored cookies via your browser settings. Please note that you may only be able to use our online services in a limited manner—or not at all—if you decline the storage of cookies or delete necessary cookies.
Use of Technically Necessary Cookies
Some cookies are technically necessary to enable your use of our online services. With these cookies we collect and store the following data:
– Language settings
– Search settings
– Information for user identification or authentication
– Data required for the smooth playback of audio or video content
Cookies enable us to recognize your computer and make any preset configurations immediately available. Cookies help us improve the online services and offer you a better and more user-friendly service. The use of cookies is also required to simplify your use of our online services. Some functions can only be provided through the use of cookies. This applies to search functions, language settings, and similar features. From this follows our legitimate interest constituting the legal basis for processing data with the help of cookies pursuant to Art. 6 para. 1 lit. f) GDPR.
Use of Analytics Cookies (“Google Analytics”)
We also use cookies on our website that enable an analysis of your user behavior, so-called analytics cookies. With these cookies, we collect and store the following data:
– Frequency of page views
– Search terms
– Use of website features
– Dwell time
The data collected using these cookies is pseudonymized so that the data can no longer be associated with a specific user unless you explicitly and actively consent. We use analytics cookies to improve and optimize the quality of our online services and their content, as well as to review and enhance the reach and visibility of our online services. Analytics cookies are used only with your consent. The legal basis for processing is Art. 6 para. 1 lit. a) GDPR.
To analyze user behavior for the purposes described above, we use the Google Analytics software, which in turn uses cookies as explained. We use Google Analytics for statistical evaluations. Google Analytics is a web analytics service provided by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94034, USA (“Google”). Google Analytics uses so-called “cookies,” text files that are stored on your computer and enable an analysis of your use of the website. The information generated by the cookies about your use of this website is usually transferred to a Google server in the USA and stored there.
If IP anonymization is activated on this website, your IP address will, however, be shortened by Google within the member states of the European Union or in other contracting states of the Agreement on the European Economic Area before transmission. Only in exceptional cases will the full IP address be transferred to a Google server in the USA and shortened there. On behalf of the operator of this website, Google will use this information to analyze your use of the website, to compile reports on website activity, and to provide further services related to website and internet use to the website operator. The IP address transmitted by your browser within the framework of Google Analytics will not be merged with other Google data.
You can prevent the storage of cookies through an appropriate browser setting; however, we would like to point out that in this case you may not be able to use all functions of this website to their full extent. Furthermore, you can prevent the collection of data generated by the cookie relating to your use of the website (including your IP address) by Google as well as the processing of this data by Google by refusing to allow the respective cookies via the cookie banner. Further information can be found at http://tools.google.com/dlpage/gaoptout?hl=de or http://www.google.com/intl/de/analytics/privacyoverview.html (general information on Google Analytics and data protection).
We note that Google Analytics on our website has been extended with the code “anonymizeIp();” to ensure anonymized collection of IP addresses by deleting the last octet.
Use of Advertising Cookies (“Salesforce Pardot Services”)
We store personal data of website visitors solely and exclusively if they voluntarily register on our websites to receive information about products and services, to subscribe to our newsletter, or to download documents. If you have given your consent, you may also receive promotional, interest-based emails. Some forms on the website are linked to Pardot. Pardot is a marketing automation software provided by Salesforce.com EMEA Limited (Salesforce), Village 9, Floor 26, Salesforce Tower, 110 Bishopsgate, London, UK, EC2N 4AY.
Voluntarily provided personal data is initially stored in Pardot and then processed in the Salesforce CRM system for the purpose of contacting you and/or sending information. Salesforce does not store IP addresses but uses the individual identifiers “unique visitor ID” and “unique identifier.” Personal identification is not possible. At https://help.salesforce.com/articleView?id=pardot_basics_cookies.htm&type=5 you can learn how Salesforce processes your data when visiting websites.
We use Pardot as a marketing analytics service that enables us to maintain, measure, expand, and optimize our web offering and marketing communications. To protect users and partners, fraud and security risks may also be identified and, if necessary, mitigated. Data is processed in Salesforce on our behalf through the use of cookies. Pardot cookies are only used if you have given your consent in our cookie banner. You may additionally disable the storage of cookies in your browser settings. If you do not allow advertising cookies, this may restrict functionality and user-friendliness of the web services.
Use of Retargeting and Remarketing
Retargeting or remarketing refers to technologies that allow users who have previously visited a particular website to be shown relevant advertising even after they leave that website. For this purpose, it is necessary to recognize internet users beyond the boundaries of our own website, which is achieved through cookies set by the respective service providers; in addition, past usage behavior is taken into account.
For example, if a user views certain products, these or similar products may later be displayed as advertisements on other websites. This constitutes personalized advertising tailored to the needs of individual users. For such personalized advertising, it is not necessary to identify the user beyond recognition. The data used for retargeting or remarketing is therefore not combined with other data by us.
We use such technologies to display online advertisements. For this purpose, we rely on third-party providers. We use services from Google, Facebook, and LinkedIn, among others, which enable the automated display of products that may be of interest to the internet user. This function is implemented through cookies. Further information can be found in the Google privacy policy under https://policies.google.com/privacy?hl=de, in the Facebook privacy policy under https://www.facebook.com/business/help/651294705016616, or in the LinkedIn privacy policy under https://www.linkedin.com/legal/privacy-policy#choices-oblig.
We set cookies only after your consent in the cookie banner. The legal basis is Art. 6 para. 1 lit. a) GDPR. You can also prevent the installation of cookies for Google Remarketing and Google AdWords Conversion Tracking by adjusting your browser settings via http://www.google.com/policies/privacy/ads/ and changing the respective settings. Analogous functions are offered by Facebook under https://www.facebook.com/settings?tab=ads and LinkedIn under https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
Use of Google Maps
In our online services, we use the Google Maps map service via an interface. This is a service provided by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94034, USA (“Google”). To use the functions of Google Maps, it is necessary to store your IP address. This information is usually transferred to and stored on a Google server in the USA. The provider of this website has no influence on this data transfer.
We use Google Maps to make it easier for you to locate the places referenced in our online services. This constitutes a legitimate interest pursuant to Art. 6 para. 1 lit. f) GDPR, which also forms the legal basis for the use of Google Maps. Further information on the handling of user data can be found in Google’s privacy policy at https://www.google.de/intl/de/policies/privacy/.
Use of YouTube
Videos are embedded in our online services for which we use a plugin of the YouTube service operated by Google (“YouTube”). The provider of the service is YouTube LLC, 901 Cherry Ave., San Bruno, CA 94066, USA. When you visit a page within our online services on which a video is embedded, a connection to YouTube’s servers is established. The YouTube server is informed which pages of our online services you have visited.
If you are logged into your YouTube account, you enable YouTube to directly associate your browsing behavior with your personal profile. You can prevent this by logging out of your YouTube account. Further information on the handling of user data can be found in Google’s privacy policy at https://www.google.de/intl/de/policies/privacy/, which also applies to YouTube.
We use YouTube to show you videos and thus provide you with more insight into our company and services. This also constitutes a legitimate interest pursuant to Art. 6 para. 1 lit. f) GDPR.
Use of Google Web Fonts
This website uses so-called web fonts provided by Google for the uniform display of fonts. When you access a page, your browser downloads the required web fonts into your browser cache to display texts and fonts correctly. To do this, the browser you use must connect to Google’s servers. This provides Google with the information that our website has been accessed via your IP address.
The use of Google Web Fonts is in the interest of a uniform and visually appealing presentation of our online services. This constitutes a legitimate interest pursuant to Art. 6 para. 1 lit. f) GDPR.
Communication With Us
You can contact us in various ways, including via the contact form on our website. In addition, we are happy to inform you regularly by e-mail through our newsletter.
Contact Form
If you wish to use the contact form in our online services, we will collect the personal data you enter in the contact form, particularly your name and email address. We also store the IP address as well as the date and time of the request. We process the data transmitted via the contact form solely for the purpose of responding to your inquiry or request. You may decide which information you choose to provide via the contact form.
The legal basis for processing your data is your consent pursuant to Art. 6 para. 1 lit. a) GDPR. After we have processed your inquiry, the data will initially be stored in case of follow-up questions. You may request deletion of the data at any time; otherwise, deletion will occur after full resolution of the matter. Statutory retention obligations remain unaffected.
Comments
You have the option to comment on our posts within our online services. To do so, you must provide your name, whereby you may also use a pseudonym. You must also provide your email address. Providing your email address is required so we can contact you in case of complaints about your comments and request a statement from you; we also store the IP address. Without providing this information, you cannot submit comments. However, only the name or pseudonym you selected will be displayed when publishing the comment. The legal basis for processing your data is your consent pursuant to Art. 6 para. 1 lit. a) GDPR.
Social Media
In our online services, you will find links to the social networks Facebook, the career networks Xing and LinkedIn, as well as the short message service Twitter. You can recognize the links by the respective provider’s logo. By clicking on these links, the corresponding social media pages are opened, to which this Privacy Policy does not apply. Please refer to the respective providers’ privacy policies for details on the applicable provisions; you can find them at:
Facebook: http://www.facebook.com/policy.php
Xing: https://privacy.xing.com/de/datenschutzerklaerung
LinkedIn: https://www.linkedin.com/legal/privacy-policy?_l=de_DE
Twitter: https://twitter.com/privacy?lang=de
Before accessing the respective links, no personal information is transmitted to the respective providers. Your access of the linked page itself constitutes the basis for data processing by the respective providers.
Inquiries by Email, Letter, or Telephone
If you contact us by email, letter, or telephone, your inquiry, including any personal data resulting from it (name, inquiry), will be stored and processed by us for the purpose of handling your request. We will not share this data without your consent.
The processing of this data is based on Art. 6 para. 1 lit. b GDPR if your inquiry is related to the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, processing is based on your consent (Art. 6 para. 1 lit. a GDPR) and/or on our legitimate interests (Art. 6 para. 1 lit. f GDPR), as we have a legitimate interest in the effective processing of inquiries directed to us.
The data you transmit to us in connection with an inquiry remains with us until you request deletion, withdraw your consent to storage, or the purpose of the data processing no longer applies (e.g., after your request has been fully processed). Mandatory statutory provisions—particularly statutory retention requirements—remain unaffected.
Your Rights and Contact
We place great importance on explaining the processing of your personal data to you in a transparent manner and informing you about your rights. If you would like more detailed information or wish to exercise your rights, you may contact us at any time so that we can address your concern.
Rights of Data Subjects
With regard to the processing of your personal data, you have extensive rights. First, you have a comprehensive right of access and may, where applicable, request the rectification and/or deletion or blocking of your personal data. You may also request the restriction of processing and have a right to object. With respect to the personal data you have provided to us, you further have the right to data portability.
If you wish to exercise any of your rights and/or obtain more detailed information, please contact our customer service. Alternatively, you may also contact our Data Protection Officer.
Withdrawal of Consent and Objection
Any consent you have given may be withdrawn at any time with effect for the future. The withdrawal of consent does not affect the lawfulness of processing carried out on the basis of the consent prior to its withdrawal. The appropriate contact persons for this are likewise our customer service and our Data Protection Officer.
If the processing of your personal data is not based on consent but on another legal basis, you may object to such data processing. Your objection will lead to a review and, if necessary, termination of the data processing. You will be informed about the result of the review and—if processing is to continue—receive further information from us on why the data processing is permissible.
Data Protection Officer and Contact
We have appointed a Data Protection Officer who supports us in matters of data protection law and whom you may also contact directly. If you have questions regarding the collection, processing, or use of your personal data that are not answered by this Privacy Policy, or if you require the correction or deletion of your data or wish to withdraw consent granted, please contact: Möller, Georg georg.moeller@sk-consulting.com oder Vogt, Carsten carsten.vogt@centrotec.de.
Complaints
If you believe that the processing of your personal data by us is not in accordance with this Privacy Policy or the applicable data protection regulations, you may lodge a complaint with our Data Protection Officer. The Data Protection Officer will review the matter and inform you of the outcome. Furthermore, you also have the right to lodge a complaint with a supervisory authority.
Further Information and Amendments
Links to Other Websites
Our online services may contain links to other websites. These links are generally marked as such. We have no influence on whether the applicable data protection regulations are adhered to on the linked websites. We therefore recommend that you also review the respective privacy policies on other websites.
Amendments to this Privacy Policy
The date indicated below shows the status of this Privacy Policy. We reserve the right to amend this Privacy Policy at any time with effect for the future. Amendments may occur in particular in the event of technical adjustments to the online services or changes to data protection regulations. The current version of the Privacy Policy is always accessible directly through the online services. We recommend that you regularly inform yourself about amendments to this Privacy Policy.
Status of this Privacy Policy: August 2021
Version 2.0