Privacy Policy – Home
Privacy policy World of Retail Services GmbH
Preface
We, World of Retail Services GmbH (hereinafter: “the company”, “we” or “us”) take the protection of your personal data seriously and would like to inform you here about data protection in our company.
Definitions: EU General Data Protection Regulation (Regulation (EU) 2016/679; hereinafter: “GDPR”).
Person affected by data processing hereinafter also referred to as “customer”, “user”, “you”, or “data subject”.
With this statement (hereinafter: “Data Protection Notice“), we inform you about the way in which your personal data is processed by us.
Our data protection notices have a modular structure. They consist of a general part for any processing of personal data and processing situations that come into play each time a website is called up (A. General) and a special part, the content of which relates in each case only to the processing situation specified there with the designation of the respective offer or product, in particular the visit to websites as detailed here (B. Visit to websites).
In order to find the parts that are relevant for you, please refer to the following overview for the subdivision of the data protection information:
Content
Preface
A. General
(1) Definitions
(2) Name and address of the data controller
(3) Name and address of the data protection officer
(4) Legal basis for data processing
(5) Data erasure and storage period
(6) Data security
(7) Cooperation with Processors
(8) Conditions for the transfer of personal data to third countries
(9) No automated decision-making (including profiling)
(10) Obligation to provide personal data
(11) Legal obligation to transfer certain data
(12) Your rights
(13) Changes to the data protection notice
B. Visiting the web pages
(1) Explanation of the function
(2) Personal data processed
1. log data
2. Hosting
3. Content delivery network and attack protection (Cloudflare)
(3) Contact form data, e-mail communication
(4) Duration of data processing
(5) Transfer of personal data to third parties; justification basis
(6) Use of cookies, plug-ins and other services on our website
a) Cookies, consent management
b) CRM system and visitor analytics HubSpot
c) YouTube with extended data protection
d) Google Maps
e) Google Fonts (local hosting)
f) Google reCAPTCHA
g) Vimeo
h) Wordfence security module
(8) Analysis tools and advertising
Google Tag Manager
Google Analytics 4
Google Ads conversion tracking
C. Social media
D. Audio and video conferencing
E. Applications
F. Inclusion in the database as a partner company
A. General
(1) Definitions
Following the model of Art. 4 GDPR, this data protection notice is based on the following definitions:
- “Personal data” (Art. 4 No. 1 GDPR) means any information relating to an identified or identifiable natural person (“data subject”). An individual is identifiable if he or she can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, an online identifier, location data or by means of information relating to his or her physical, physiological, genetic, mental, economic, cultural or social identity characteristics. The identifiability can also be given by means of a linkage of such information or other additional knowledge. The origin, form or embodiment of the information is irrelevant (photographs, video or sound recordings may also contain personal data).
- “Processing” (Art. 4 No. 2 GDPR) means any operation which involves the handling of personal data, whether or not by automated (i.e. technology-based) means. This includes, in particular, the collection (i.e. acquisition), recording, organization, arrangement, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment, combination, restriction, erasure or destruction of personal data, as well as the change of a purpose or intended purpose on which a data processing was originally based.
- “Controller” (Art. 4 No. 7 GDPR) means the natural or legal person, public authority, agency or other body which alone or jointly with others determines the purposes and means of the processing of personal data.
- “Third party” (Art. 4 No. 10 GDPR) means any natural or legal person, public authority, agency or other body other than the data subject, the controller, the processor and the persons who, under the direct responsibility of the controller or processor, are authorized to process the personal data; this also includes other group-affiliated legal entities.
- “Processor” (Art. 4 No. 8 GDPR) means a natural or legal person, authority, institution or other body that processes personal data on behalf of the controller, in particular in accordance with the controller’s instructions (e.g. IT service provider). In particular, a processor is not a third party in the sense of data protection law.
- “Consent” (Art. 4 No. 11 GDPR) of the data subject means any freely given specific, informed and unambiguous indication of his or her wishes in the form of a statement or other unambiguous affirmative act by which the data subject signifies his or her agreement to the processing of personal data relating to him or her.
(2) Name and address of the controller
The controller of your personal data within the meaning of Article 4 No. 7 GDPR is us:
World of Retail Services GmbH
Kasseler Landstraße 5
37213 Witzenhausen
Tel.: 0551 2887280
E-mail: [email protected]
For further information about our company, please refer to the imprint details on our website: https://retail-services.net/legal-notice/
(3) Name and address of the data protection officer
Our data protection officer is available to answer any questions you may have and to act as your contact person on the subject of data protection in our company. His contact details are:
Dr. Machunsky Datenschutz & Compliance GmbH
Jan N. Machunsky
Mittelbergring 61
37085 Göttingen
Phone: 0551-79097161
[email protected]
https://www.machunsky-datenschutz.de
(4) Legal basis for data processing
In principle, any processing of personal data is prohibited by law and only permitted if the data processing falls under one of the following justifications:
- Art. 6 (1) (1) (a) GDPR (“consent”): If the data subject has voluntarily, in an informed manner and unambiguously indicated by a statement or other unambiguous confirmatory act that he or she consents to the processing of personal data relating to him or her for one or more specific purposes;
- Art. 6 (1) (1) (b) GDPR: If the processing is necessary for the performance of a contract to which the data subject is a party or for the performance of pre-contractual measures taken at the data subject’s request;
- Art. 6 (1) (1) (c) GDPR: If processing is necessary for compliance with a legal obligation to which the controller is subject (e.g., a legal obligation to preserve records);
- Art. 6 (1) (1) (d) GDPR: If the processing is necessary to protect vital interests of the data subject or another natural person;
- Art. 6 (1) (1) (e) GDPR: If the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller; or
- Art. 6 (1) (1) (f) GDPR (“Legitimate Interests”): If the processing is necessary to protect legitimate (in particular legal or economic) interests of the controller or a third party, unless the conflicting interests or rights of the data subject override (in particular if the data subject is a minor).
For the processing operations carried out by us, we indicate below the applicable legal basis in each case. A processing operation may also be based on several legal bases.
(5) Data erasure and storage period
For the processing operations carried out by us, we indicate below in each case how long the data will be stored by us and when it will be deleted or blocked. As far as
no explicit storage period is specified below, your personal data will be deleted or blocked as soon as the purpose or legal basis for the storage no longer applies. In principle, your data will only be stored on our servers in Germany, subject to any forwarding that may take place in accordance with the regulations in A (7) and A.(8).
However, storage may take place beyond the specified time in the event of a (threatened) legal dispute with you or other legal proceedings, or if storage is required by legal regulations to which we are subject as the responsible party (e.g. § 257 HGB, § 147 AO). If the storage period prescribed by the legal regulations expires, the personal data will be blocked or deleted unless further storage by us is necessary and there is a legal basis for this.
(6) Data security
We use appropriate technical and organizational security measures to protect your data against accidental or intentional manipulation, partial or complete loss, destruction or against unauthorized access by third parties (e.g. TLS encryption for our website), taking into account the state of the art, implementation costs and the nature, scope, context and purpose of the processing, as well as the existing risks of a data breach (including its probability and impact) for the data subject. Our security measures are continuously improved in line with technological developments.
We will be happy to provide you with more detailed information on request.
(7) Cooperation with processors
As with any larger company, we use external domestic and foreign service providers to process our business transactions (e.g. for IT, logistics, telecommunications, sales and marketing). They will only act on our instructions and have been contractually obligated to comply with the data protection provisions in accordance with Art. 28 GDPR.
Our group of companies includes World of Retail Services Inc., 10 Mall Road, Suite 301, Burlington, MA 01803, USA. If your enquiry concerns services in the United States or Canada, or is submitted via our English-language pages with an evident US connection, we forward the enquiry, including the contact and project details you provided, to our US subsidiary for handling. The US subsidiary processes this data as an independent controller in order to respond to your enquiry and to prepare the contract you have requested (Art. 6(1)(1)(b) GDPR). The forwarding is limited to the specific enquiry and the data required for it. We base the transfer to the USA on Art. 49(1)(b) GDPR, because it is necessary for the implementation of pre-contractual measures taken at your request, and – where the contract is to be concluded with the company you represent – on Art. 49(1)(c) GDPR; it is not based on an adequacy decision or on Standard Contractual Clauses. Please note: in the absence of an adequacy decision and appropriate safeguards for this transfer, there is a risk that US authorities may access the data under US law without you having remedies comparable to those available in the EU. If you do not wish your enquiry to be forwarded to the USA, please tell us so in your enquiry or at any time afterwards; your enquiry will then be handled exclusively by World of Retail Services GmbH. You may also exercise your rights under A.(12) towards us with regard to the forwarded data; we will pass your request on to our subsidiary.
(8) Conditions for the transfer of personal data to third countries
In the course of our business relationships, your personal data may be passed on or disclosed to third party companies. These may also be located outside the European Economic Area (EEA), i.e. in third countries. Such processing is carried out exclusively for the fulfillment of contractual and business obligations and to maintain your business relationship with us. We will inform you about the respective details of the transfer below at the relevant points.
Some third countries are certified by the European Commission through so-called adequacy decisions to have data protection comparable to the EEA standard (a list of these countries as well as a copy of the adequacy decisions can be found here: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en). However, in other third countries to which personal data may be transferred, there may not be a consistently high level of data protection due to a lack of legal provisions. If this is the case, we ensure that data protection is adequately guaranteed. This is possible through binding company regulations, standard contractual clauses of the European Commission for the protection of personal data, certificates or recognized codes of conduct. Please contact our Data Protection Officer (see under A.(3)) if you would like more information on this.
For the United States of America, the European Commission adopted an adequacy decision on the EU-U.S. Data Privacy Framework (“DPF”) on 10 July 2023 (Implementing Decision (EU) 2023/1795). We base transfers to US companies certified under the DPF on Art. 45(1) GDPR. This applies in particular to Google LLC, HubSpot, Inc., Microsoft Corporation and Cloudflare, Inc. You can verify each provider’s certification at https://www.dataprivacyframework.gov/list. In addition, and in case the adequacy decision ceases to apply or a provider is not (or no longer) certified, we have concluded the European Commission’s Standard Contractual Clauses (Art. 46(2)(c) GDPR) with these providers. For transfers to our own US subsidiary, see A.(7).
(9) No automated decision-making (including profiling)
We do not intend to use any personal data collected from you for any automated decision making process (including profiling).
(10) Obligation to provide personal data
Within the scope of our business relationship, you must provide the personal data that is required for the establishment and performance of the respective business relationship and the fulfillment of the associated contractual obligations or which we are legally obliged to collect. Without this data, we will generally not be able to enter into the business relationship with you and fulfill the obligations arising therefrom.
(11) Legal obligation to transfer certain data
We may be subject to a specific legal or statutory obligation to provide lawfully processed personal data to third parties, in particular public bodies (Art. 6 (1) (1) (c) GDPR).
(12) Your rights
- You can assert your rights as a data subject regarding your processed personal data to us at any time using the contact details provided at the beginning of A.(2). As a data subject, you have the right
- to request information about your data processed by us in accordance with Art. 15 GDPR. In particular, you can request information about the processing purposes, the category of data, the categories of recipients to whom your data has been or will be disclosed, the planned storage period, the existence of a right to rectification, erasure, restriction of processing or objection, the existence of a right of complaint, the origin of your data if it has not been collected by us, as well as the existence of automated decision-making, including profiling, and, if applicable, meaningful information about its details;
- in accordance with Art. 16 GDPR, to demand the correction of incorrect or the completion of your data stored by us without delay;
- pursuant to Art. 17 GDPR, to request the deletion of your data stored by us, unless the processing is necessary for the exercise of the right to freedom of expression and information, for compliance with a legal obligation, for reasons of public interest or for the assertion, exercise or defense of legal claims;
- pursuant to Art. 18 GDPR, to request the restriction of the processing of your data, insofar as the accuracy of the data is disputed by you or the processing is unlawful;
- pursuant to Art. 20 GDPR, to receive your data that you have provided to us in a structured, common and machine-readable format or to request the transfer to another controller (“data portability”);
- object to the processing in accordance with Art. 21 GDPR, provided that the processing is based on Art. 6 (1) (1) (e) or (f) GDPR. This is particularly the case if the processing is not necessary for the performance of a contract with you. Unless it is an objection to direct marketing, when exercising such an objection, we ask you to explain the reasons why we should not process your data as we have done. In the event of your justified objection, we will examine the factual situation and will either stop or adapt the data processing or show you our compelling legitimate grounds on the basis of which we continue the processing;
- in accordance with Art. 7(3) of the GDPR, revoke your consent given once (also before the GDPR applies, i.e. before 25.5.2018) – i.e. your voluntary will, made understandable in an informed manner and unambiguously by a statement or other unambiguous confirming act, that you agree to the processing of the personal data concerned for one or more specific purposes – at any time vis-à-vis us, if you have given such consent. This has the consequence that we may no longer continue the data processing based on this consent for the future and
- to complain to a data protection supervisory authority about the processing of your personal data in our company in accordance with Art. 77 GDPR, such as the data protection supervisory authority responsible for us:
The Hessian Commissioner for Data Protection and Freedom of Information (Der Hessische Beauftragte für Datenschutz und Informationsfreiheit, HBDI)
Gustav-Stresemann-Ring 1
65189 Wiesbaden, Germany
P.O. Box 3163, 65021 Wiesbaden, Germany
Phone: +49 611 1408-0
E-mail: [email protected]
Website: https://datenschutz.hessen.de
The competent authority is determined by the registered office of our company in Witzenhausen (Hesse). Irrespective of this, you may also contact the supervisory authority of your habitual residence, place of work or the place of the alleged infringement (Art. 77(1) GDPR).
(13) Changes to data protection information
Version: September 2026. Main changes compared with the November 2022 version: inclusion of HubSpot, Google Ads conversion tracking, Cloudflare, Wordfence, Vimeo and Microsoft 365; update of the legal bases for third-country transfers (EU-U.S. Data Privacy Framework); correction of the competent supervisory authority; additions regarding online job applications.
B. Visiting the websites
(1) Explanation of function
Our website serves to provide information about our company, our areas of activity and to enable you to contact us. When you visit our web pages, personal data may be processed.
(2) Processed personal data
During the informative use of the web pages, the following categories of personal data are collected, stored and processed by us:
1. Protocol data
When you visit our web pages, a so-called log data record (so-called server log files) is stored temporarily and anonymously on our web server. This consists of:
- the page from which the page was requested (so-called referrer URL)
- the name and URL of the requested page
- the date and time of the request
- the description of the type, language and version of the web browser used
- the IP address of the requesting computer, which is shortened so that a personal reference can no longer be established
- the amount of data transferred
- the operating system
- the message whether the call was successful (access status/http status code) the GMT time zone difference.
The processing of the log data serves statistical purposes and the improvement of the quality of our website, in particular the stability and security of the connection (legal basis is Art. 6 (1) (1) (f) GDPR). These files are deleted within 4 days.
2. Hosting
Our website is hosted by netcup GmbH.
netcup GmbH
Daimlerstraße 25
76185 Karlsruhe
A data processing agreement pursuant to Art. 28 GDPR is in place with netcup GmbH. The servers are located in Germany.
3. Content delivery network and attack protection (Cloudflare)
The traffic of our website is routed through the network of Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA (contracting entity for the EEA: Cloudflare Germany GmbH, Rosental 7, 80331 Munich, Germany; hereinafter “Cloudflare”). Cloudflare provides DNS resolution, delivery of static content via a content delivery network, and protection against attacks (web application firewall, mitigation of DDoS attacks and automated access).
For technical reasons, Cloudflare processes the connection data of every page request: IP address, requested URL, time, browser and operating system identifier (user agent), referrer, and security-related characteristics of the request. To detect automated access, Cloudflare may set technically necessary cookies (in particular “__cf_bm”, retention 30 minutes, and “cf_clearance”); these serve solely the security and functionality of the website and are not used for marketing purposes.
The legal basis is Art. 6(1)(1)(f) GDPR; our legitimate interest lies in the secure, stable and fast provision of our website. The storage of and access to the cookies mentioned is governed by Section 25(2) No. 2 TDDDG (strictly necessary). Cloudflare acts as a processor (Art. 28 GDPR). As Cloudflare operates a global network, processing may also take place in the USA; Cloudflare, Inc. is certified under the EU-U.S. Data Privacy Framework (see A.(8)); in addition, the European Commission’s Standard Contractual Clauses apply. Cloudflare retains connection logs only for a short period for security analysis. Further information: https://www.cloudflare.com/privacypolicy/ and https://www.cloudflare.com/cloudflare-customer-dpa/.
(3) Contact form data, e-mail communication
We provide forms on our website (contact, project/quotation request, partner company enquiry, job application). For job applications, see Section E separately. When you use a form, we process the data you enter (e.g. salutation, first and last name, company, position, e-mail address, telephone number, country, your message or project details), as well as the time of submission, your IP address and the language version from which you submitted the form.
Purpose and legal basis. The processing serves to respond to your enquiry and to prepare a contract (Art. 6(1)(1)(b) GDPR). Where your enquiry has no pre-contractual connection, the legal basis is our legitimate interest in responding to enquiries (Art. 6(1)(1)(f) GDPR). Mandatory fields are marked as such; without this information we cannot process the enquiry.
Technical processing and recipients. The forms are operated with the “Elementor” form module (Elementor Ltd., Tel Aviv, Israel) on our own web server; the entries are first stored in the database of our website (servers in Germany, see B.(2)). No data is transmitted to the manufacturer of the module. In addition, each enquiry is forwarded by e-mail to the responsible mailbox of our company, and a confirmation of receipt is sent to the e-mail address you provided. For sending e-mails we use Microsoft 365 (Microsoft Graph) of Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland, with which a data processing agreement pursuant to Art. 28 GDPR is in place. The mailboxes are operated in Microsoft data centres. Insofar as data reaches the USA (Microsoft Corporation), the EU-U.S. Data Privacy Framework and the Standard Contractual Clauses apply (see A.(8)); information: https://privacy.microsoft.com/en-us/privacystatement.
To protect the forms against automated input we use Google reCAPTCHA (see B.(6) f). The content of contact and enquiry forms (not: application forms) is additionally transferred server-side to our CRM system HubSpot (first name, last name, e-mail address, telephone number, company, message, and a record of the declaration you made in the consent field of the form); this serves the handling and follow-up of your enquiry, takes place irrespective of your cookie settings and is based on Art. 6(1)(1)(b) or (f) GDPR (see B.(6) b) aa)). If you have consented to “Marketing” in the cookie banner, your HubSpot visitor identifier (cookie “hubspotutk”) is additionally assigned to the contact record so that previous page views can be linked to the enquiry (see B.(6) b) bb)), and information on whether you reached us via a Google ad is attached to the enquiry (hidden form field “attribution”, see B.(8) Google Ads conversion tracking). Enquiries with a US connection are forwarded to our US subsidiary (see A.(7)).
E-mail communication. If you contact us by e-mail, we process your e-mail address, the metadata of the message and its content in order to handle your enquiry (Art. 6(1)(1)(b) or (f) GDPR). Unencrypted e-mails may be viewed by third parties in transit; for confidential content we recommend postal mail or prior arrangement.
Retention period. We delete form entries in the database of our website no later than six months after receipt. In addition, an access-protected backup copy of these entries (not: application data) is kept on our server; it is accessible only to our administrators, serves solely to restore data in the event of technical errors and is deleted automatically after 90 days in each case. Enquiries forwarded by e-mail and the related correspondence are deleted once the enquiry has been finally dealt with and no business relationship is established, at the latest after twelve months. If a contract is concluded, the statutory commercial and tax retention periods apply (Section 257 HGB, Section 147 AO: six, eight or ten years). Your right to object under Art. 21 GDPR to processing based on Art. 6(1)(1)(f) GDPR remains unaffected.
(4) Duration of data processing
Your data will only be processed for as long as is necessary to achieve the above-mentioned processing purposes; the legal bases stated in the context of the processing purposes apply accordingly. With regard to the cookies used, their providers and retention periods, please refer to B.(6) a) and our Cookie Policy, which is based on a technical review of our website and is updated whenever the cookies used change. You can view, change or withdraw your consents at any time via the “Cookie Settings” link in the footer of every page.
Third parties used by us will store your data on their system for as long as is necessary in connection with the provision of services for us in accordance with the respective order.
(5) Transfer of personal data to third parties; basis for justification
The following categories of recipients, which are usually order processors (see A.(7)), may receive access to your personal data:
- Service providers for the operation of our website and the processing of data stored or transmitted by the systems (e.g. for data center services, payment processing, IT security). The legal basis for the transfer is then Art. 6 (1) (1) (b) or (f) GDPR, insofar as they are not order processors;
- Government agencies/authorities, insofar as this is necessary on the one hand to fulfill our services and on the other hand to fulfill a legal obligation. The legal basis for the transfer is then Art. 6 (1) (1) (c) GDPR;
- Persons employed to carry out our business operations (e.g. auditors, banks, insurance companies, legal advisors, supervisory authorities, parties involved in company acquisitions or the establishment of joint ventures). The legal basis for the disclosure is then Art. 6 (1) (1) (b) or (f) GDPR. For the guarantees of an adequate level of data protection in the event of a transfer of data to third countries, see A.(8).
In addition, we will only share your personal data with third parties if you have given your express consent to do so in accordance with Art. 6 (1) (1) (a) GDPR.
(6) Use of cookies, plugins and other services on our website
a) Cookies, consent management
We use cookies on our websites. Cookies are small text files that are assigned to the browser you are using on your hard drive by means of a characteristic character string and stored and through which certain information flows to the body that sets the cookie. Cookies cannot execute programs or transfer viruses to your computer and therefore cannot cause any damage. They serve to make the Internet offer as a whole more user-friendly and effective, i.e. more pleasant for you.
Cookies can contain data that make it possible to recognize the device used. In some cases, however, cookies only contain information on certain settings that cannot be related to a specific person. However, cookies cannot directly identify a user.
A distinction is made between session cookies, which are deleted as soon as you close your browser, and permanent cookies, which are stored beyond the individual session. With regard to their function, a distinction is made between cookies:
- Strictly necessary cookies: these are required to provide the website, to store your language choice and your cookie decision and to protect the website against attacks; they are set without consent (Section 25(2) No. 2 TDDDG) and contain no advertising identifiers;
- Statistics cookies: these make it possible to distinguish users and sessions pseudonymously and to evaluate the use of our website (Google Analytics 4, see B.(8)); retention up to two years;
- Marketing cookies: these serve to attribute enquiries to a previously clicked Google ad, to recognise returning visitors for our CRM system and to play embedded videos (Google Ads, HubSpot, Vimeo, YouTube; see B.(6) b), c), g) and B.(8)); retention up to two years.
Any use of cookies that is not absolutely technically necessary constitutes data processing that is only permitted with your explicit and active consent pursuant to Art. 6 (1) (1) (a) GDPR. This applies to all cookies in the “Statistics” and “Marketing” categories. In addition, we will only share your personal data processed through cookies with third parties if you have given your express consent to do so pursuant to Art. 6 (1) (1) (a) GDPR.
Consent management (cookie banner). When you first visit our website, a consent banner is displayed. Non-essential cookies and services (categories “Statistics” and “Marketing”) are only loaded once you have actively selected the respective category. For this we use the “Complianz” software (Really Simple Plugins B.V., Groningen, Netherlands), which runs on our own server. Your selection is stored in cookies with the prefix “cmplz_” on your device (retention 365 days) so that the banner does not reappear on every visit and your decision can be implemented technically. This data is not transmitted to the software provider. The legal basis is Art. 6(1)(1)(c) GDPR in conjunction with our obligation to demonstrate consent under Art. 7(1) GDPR and Section 25(2) No. 2 TDDDG. You can withdraw or change your consent at any time with effect for the future via “Cookie Settings” in the footer. Details of all cookies used are set out in our Cookie Policy (see B.(4)).
Strictly necessary cookies (Section 25(2) No. 2 TDDDG, Art. 6(1)(1)(f) GDPR) are used for language selection (multilingual module “WPML”, OnTheGoSystems Ltd., Cyprus; cookie “wp-wpml_current_language”, retained until the end of the session; no transmission to the provider), for consent management (see above), – only where automated access is detected – for attack protection (Cloudflare, see B.(2) 3.) and for securing the login area of our website (Wordfence, see B.(6) h); the latter affects only logged-in editors, not visitors.
b) CRM system and visitor analytics HubSpot
We use HubSpot, a software for customer relationship management (CRM) and marketing. The provider is HubSpot, Inc., 2 Canal Park, Cambridge, MA 02141, USA; the contracting entity for customers in the EEA is HubSpot Ireland Limited, 1 Sir John Rogerson’s Quay, Dublin 2, Ireland (together “HubSpot”). Our HubSpot account is hosted in the US data centre region; the data described below is therefore stored on servers in the USA.
aa) CRM database. In HubSpot we manage the contact details of customers, prospects, partner companies and other business contacts (name, company, position, e-mail address, telephone number, correspondence, quotation and project history). The purpose is the initiation, performance and maintenance of business relationships. Enquiries you submit via the contact and enquiry forms on our website are created server-side as a contact record in HubSpot for this purpose (see B.(3)); this takes place irrespective of your cookie settings. The legal basis is Art. 6(1)(1)(b) GDPR insofar as the preparation or performance of a contract is concerned, and otherwise Art. 6(1)(1)(f) GDPR (legitimate interest in structured customer management and communication). For the inclusion of partner companies, see Section F.
bb) Website tracking and form capture. Only if you have activated the “Marketing” category in the cookie banner is the HubSpot tracking code loaded on our website. It sets cookies on your device (in particular “__hstc” and “hubspotutk”, each retained for six months; “__hssc”, 30 minutes; “__hssrc”, until the end of the session) and transmits to HubSpot your IP address, the pages visited, time and duration of visits, referrer URL, and device and browser information. Via the “Collected Forms” function, when you submit a contact or enquiry form, the form entries including your e-mail address are also transmitted to HubSpot together with your visitor identifier (cookie “hubspotutk”); this allows previous page views to be linked to the contact record created in accordance with B.(3). The purpose is the follow-up and handling of enquiries and the evaluation of which content on our website is relevant to prospects. The HubSpot code is disabled on our career and application pages; applicant data is not transferred to HubSpot (see Section E).
The legal basis for tracking and form capture is exclusively your consent, Art. 6(1)(1)(a) GDPR and Section 25(1) TDDDG. You can withdraw your consent at any time via “Cookie Settings” in the footer; no further data will be collected from the time of withdrawal. The lawfulness of processing carried out until then remains unaffected.
Recipients, third country, retention. HubSpot processes the data as a processor on the basis of an agreement pursuant to Art. 28 GDPR (https://legal.hubspot.com/dpa). We base the transfer to the USA on the adequacy decision on the EU-U.S. Data Privacy Framework, under which HubSpot, Inc. is certified, and additionally on the European Commission’s Standard Contractual Clauses (see A.(8)). We retain contact records for the duration of the business relationship and beyond that for as long as statutory retention obligations exist (Section 257 HGB, Section 147 AO); records of prospects with whom no business relationship is established are deleted no later than 24 months after the last contact. Tracking data on page views is linked to the contact record in HubSpot and deleted with it. You may object at any time to processing based on Art. 6(1)(1)(f) GDPR pursuant to Art. 21 GDPR. Further information: https://legal.hubspot.com/privacy-policy and https://knowledge.hubspot.com/privacy-and-consent/what-cookies-does-hubspot-set-in-a-visitor-s-browser.
c) YouTube with enhanced data protection
This website embeds videos of YouTube. The operator of the pages is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
We use YouTube in the extended data protection mode. According to YouTube, this mode means that YouTube does not store any information about visitors to this website before they watch the video. However, the transfer of data to YouTube partners is not necessarily excluded by the extended data protection mode. Thus, YouTube – regardless of whether you watch a video – establishes a connection to the Google DoubleClick network.
As soon as you start a YouTube video on this website, a connection to YouTube’s servers is established. This tells the YouTube server which of our pages you have visited. If you are logged into your YouTube account, you enable YouTube to assign your surfing behavior directly to your personal profile. You can prevent this by logging out of your YouTube account.
Furthermore, YouTube can save various cookies on your end device after starting a video or use comparable recognition technologies (e.g. device fingerprinting). In this way, YouTube can obtain information about visitors to this website. This information is used, among other things, to collect video statistics, improve the user experience, and prevent fraud attempts.
If necessary, further data processing operations may be triggered after the start of a YouTube video, over which we have no control.
YouTube videos are only loaded on our website once you have activated the “Marketing” category in the cookie banner; until then, only a placeholder without any connection to Google is displayed. The legal basis is therefore exclusively your consent pursuant to Art. 6(1)(1)(a) GDPR and Section 25(1) TDDDG. You can withdraw your consent at any time via “Cookie Settings” in the footer. We base the transfer to Google LLC in the USA on the adequacy decision on the EU-U.S. Data Privacy Framework and additionally on the European Commission’s Standard Contractual Clauses (see A.(8)).
For more information about data protection at YouTube, please see their privacy policy at: https://policies.google.com/privacy?hl=de.
d) Google Maps
This site uses the map service Google Maps. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
To use the functions of Google Maps, it is necessary to store your IP address. This information is usually transferred to a Google server in the USA and stored there. The provider of this site has no influence on this data transmission.
The use of Google Maps is in the interest of an appealing presentation of our online offers and an easy location of the places indicated by us on the website. This represents a legitimate interest within the meaning of Art. 6 (1) (1) (f) GDPR. Insofar as a corresponding consent has been requested, the processing is carried out exclusively on the basis of Art. 6 (1) (1) (a) GDPR; the consent can be revoked at any time.
We base the transfer to Google LLC in the USA on the adequacy decision on the EU-U.S. Data Privacy Framework and additionally on the European Commission’s Standard Contractual Clauses (see A.(8)).
More information on the handling of user data can be found in Google’s privacy policy: https://policies.google.com/privacy?hl=de.
e) Google Fonts (local hosting)
This site uses so-called Google Fonts, which are provided by Google, for the uniform display of fonts. The Google Fonts are installed locally. A connection to Google servers does not take place.
You can find more information about Google Fonts at https://developers.google.com/fonts/faq and in Google’s privacy policy: https://policies.google.com/privacy?hl=de.
f) Google reCAPTCHA
We use “Google reCAPTCHA” (hereinafter “reCAPTCHA”) on this website. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
The purpose of reCAPTCHA is to verify whether data entry on this website (e.g. in a contact form) is made by a human or by an automated program. For this purpose, reCAPTCHA analyzes the behavior of the website visitor based on various characteristics. This analysis begins automatically as soon as the website visitor enters the website. For the analysis, reCAPTCHA evaluates various information (e.g. IP address, time spent by the website visitor on the website or mouse movements made by the user). The data collected during the analysis is forwarded to Google.
The reCAPTCHA analyses run entirely in the background. Website visitors are not notified that an analysis is taking place.
The storage and analysis of the data is based on Art. 6 (1) (1) (f) GDPR. The website operator has a legitimate interest in protecting its web offers from abusive automated spying and from SPAM. If a corresponding consent has been requested, the processing is carried out exclusively on the basis of Art. 6 (1) (1) (a) GDPR and Section 25(1) TDDDG, insofar as the consent includes the storage of cookies or access to information in the user’s terminal device (e.g. device fingerprinting) as defined by the TDDDG. The consent can be revoked at any time.
For more information on Google reCAPTCHA, please refer to the Google Privacy Policy and the Google Terms of Use at the following links: https://policies.google.com/privacy?hl=de and https://policies.google.com/terms?hl=de.
On individual pages we embed videos from the Vimeo platform. The provider is Vimeo.com, Inc., 330 West 34th Street, 5th Floor, New York, NY 10001, USA (“Vimeo”). The embedding is implemented via the “Slider Revolution” presentation module (ThemePunch OHG, Germany), which runs on our server and does not itself transmit any data to the module manufacturer.
The video is only loaded once you have activated the “Marketing” category in the cookie banner. When loaded, a connection to Vimeo’s servers is established; Vimeo receives your IP address, the address of the page visited, browser and device information, and may set cookies (in particular “vuid”, retained for up to two years) to control playback and compile usage statistics. If you are logged in to Vimeo, Vimeo can attribute the visit to your account. The legal basis is exclusively your consent, Art. 6(1)(1)(a) GDPR and Section 25(1) TDDDG; withdrawal at any time via “Cookie Settings” in the footer.
Vimeo processes the data in the USA. Vimeo.com, Inc. is certified under the EU-U.S. Data Privacy Framework (Art. 45 GDPR, see A.(8)); in addition, the European Commission’s Standard Contractual Clauses (Art. 46(2)(c) GDPR), which form part of Vimeo’s terms, apply. We have no influence on the retention period at Vimeo. Further information: https://vimeo.com/privacy and https://vimeo.com/cookie_policy.
h) Wordfence security module
To protect our website against attacks we use the “Wordfence” security module. The provider is Defiant, Inc., 800 5th Avenue, Suite 4100, Seattle, WA 98104, USA (“Defiant”). Wordfence provides an application-level firewall, scans the files of our website for malware, limits failed login attempts and blocks access that is identified as an attack.
For this purpose, in the event of security-relevant incidents (in particular blocked requests, detected attack patterns and login attempts), Wordfence processes on our server the IP address, time, requested URL, browser identifier and referrer of the request concerned and – in the case of login attempts – the user name used; logging of all page views (“Live Traffic”) is disabled. This data is stored in the database of our website and deleted automatically after 30 days; blocks of IP addresses are lifted after the configured blocking period expires. To identify known attackers, Wordfence transmits IP addresses from which attacks or repeated failed login attempts originate to Defiant’s servers and retrieves block lists from there (“Threat Defense Feed”); data of ordinary visitors is not transmitted to Defiant.
The legal basis is Art. 6(1)(1)(f) GDPR; our legitimate interest lies in the integrity, availability and security of our website and the data stored in it (cf. Recital 49 GDPR). Wordfence does not set cookies for visitors; a session cookie (“wfwaf-authcookie”) is set only for logged-in editors (Section 25(2) No. 2 TDDDG). Insofar as IP addresses are transmitted to Defiant in the USA, this is done on the basis of the European Commission’s Standard Contractual Clauses, which form part of the Wordfence terms. Further information: https://www.wordfence.com/privacy-policy/ and https://www.wordfence.com/help/general-data-protection-regulation/.
Google Tag Manager
We use the Google Tag Manager. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
The Google Tag Manager is a tool that allows us to integrate tracking or statistical tools and other technologies on our website. The Google Tag Manager itself does not create user profiles, does not store cookies and does not perform any independent analyses. It only serves to manage and play out the tools integrated via it. However, the Google Tag Manager records your IP address, which may also be transferred to Google’s parent company in the United States.
The use of the Google Tag Manager is based on Art. 6 (1) (1) (f) GDPR. The website operator has a legitimate interest in a quick and uncomplicated integration and management of various tools on his website. Insofar as a corresponding consent has been requested, the processing is carried out exclusively on the basis of Art. 6 (1) (1) (a) GDPR; the consent can be revoked at any time.
We configure Google Tag Manager so that tags in the “Statistics” and “Marketing” categories are only triggered after your consent in the cookie banner (Consent Mode). Insofar as the IP address is transmitted to Google LLC in the USA, we base this on the adequacy decision on the EU-U.S. Data Privacy Framework and additionally on the European Commission’s Standard Contractual Clauses (see A.(8)).
Google Analytics 4
This website uses functions of the web analytics service Google Analytics. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
Google Analytics enables the website operator to analyze the behavior of website visitors. In doing so, the website operator receives various usage data, such as page views, dwell time, operating systems used and the origin of the user. This data may be summarized by Google in a profile that is assigned to the respective user or their end device.
Google Analytics uses technologies that enable the recognition of the user for the purpose of analyzing user behavior (e.g. cookies or device fingerprinting). The information collected by Google about the use of this website is usually transferred to a Google server in the USA and stored there.
Google Analytics is only loaded once you have activated the “Statistics” category in the cookie banner. The legal basis is exclusively your consent pursuant to Art. 6(1)(1)(a) GDPR and Section 25(1) TDDDG; the purpose is the analysis of user behaviour in order to improve our website and our advertising. You can withdraw your consent at any time with effect for the future via “Cookie Settings” in the footer. We base the transfer to Google LLC in the USA on the adequacy decision on the EU-U.S. Data Privacy Framework and additionally on the European Commission’s Standard Contractual Clauses (see A.(8); https://business.safety.google/adsprocessorterms/).
IP addresses and retention in Google Analytics 4
We use Google Analytics in the “Google Analytics 4” version. In this version, according to Google, IP addresses are used only for coarse location determination (region) and are not logged or stored; Google Analytics 4 uses cookies with the prefix “_ga” (retention up to two years). The “Google Signals” feature (cross-device linking and interest categories of signed-in Google users) is disabled in our account. You can stop the collection at any time via “Cookie Settings” in the footer.
Order processing
We have concluded an order processing agreement with Google and fully implement the strict requirements of the German data protection authorities when using Google Analytics.
Storage period
Data stored by Google at user and event level that is linked to cookies or user identifiers is deleted automatically after the retention period configured by us (event data: two months; user-level data: 14 months); aggregated reports contain no personal references. Details: https://support.google.com/analytics/answer/7667196?hl=de
Google Ads conversion tracking
We place advertisements via Google Ads and use Google Ads conversion tracking. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”); the parent company is Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
Purpose. With conversion tracking we measure whether users who reached our website via a Google ad subsequently perform an action relevant to us (in particular submitting an enquiry form or clicking a telephone number or e-mail address). We receive from Google only aggregated statistics (number of conversions per ad and campaign) and cannot identify individual users through them. The evaluation serves to monitor and optimise the performance of our ads.
How it works. If you click on an ad placed by Google, a click identifier (“GCLID”) is appended to your redirection to our website. If you have activated the “Marketing” category in the cookie banner, the Google Ads tag and the “Conversion Linker” are loaded via Google Tag Manager. For this purpose, the Conversion Linker stores a cookie on our own domain (“_gcl_au”, retention 90 days). In addition, we ourselves store – likewise only after your consent to “Marketing” – the click identifier in the cookie “wrs_gclid” (retention 90 days) and the origin of your visit (search engine, ad or direct access) in the cookie “wrs_src” (retention 30 days); these two cookies are read exclusively by us. When you reach a target page or submit a form, the Google Ads tag transmits to Google the information that a conversion has taken place, together with the click identifier, the URL of the page, your IP address, browser and device information and the time. In addition, when you submit a contact or enquiry form, we copy the click identifier into a form field that is not visible to you (“attribution”) and store it together with your enquiry so that we can trace internally which ad led to the enquiry. Without consent to “Marketing”, no cookies are set, no data is transmitted to Google and no click identifier is stored.
Legal basis. Exclusively your consent, Art. 6(1)(1)(a) GDPR and Section 25(1) TDDDG. You can withdraw your consent at any time with effect for the future via “Cookie Settings” in the footer. You can also disable personalised advertising by Google at https://adssettings.google.com.
Recipients, third country, retention. For conversion tracking, we and Google are each independent controllers within the meaning of the “Google Ads Controller-Controller Data Protection Terms” (https://business.safety.google/adscontrollerterms/). We base the transfer to Google LLC in the USA on the adequacy decision on the EU-U.S. Data Privacy Framework and additionally on the European Commission’s Standard Contractual Clauses (see A.(8)). The cookies mentioned expire on your device after 90 days at the latest. We delete the click identifier stored with your enquiry together with the enquiry data (see B.(3)). We have no influence on the retention period at Google; information is available at https://policies.google.com/technologies/ads and https://policies.google.com/privacy.
C. Social media
We operate our own pages on various social networks to enable an exchange with interested users or customers and to inform them about our activities and events. We do not process any user data in social networks ourselves and can only evaluate and use the data anonymized by e.g. Facebook. This may result in data transfers of user data to countries outside the European Union. Furthermore, the collected user data is processed for marketing purposes, for example, to define target groups and then display targeted advertising material to them on the respective social media platform. To make this possible, cookies are often used by the social network/the respective provider.
of the social network, which include the online behavior, interests, etc. of the user. Usage profiles on the respective platforms may also contain data that is stored independently of the end device. The legal basis for this type of data processing is our legitimate interest in a functional and stable communication with users via the respective online presence (Art. 6(1)(1)(f) GDPR). Insofar as the platform operators provide us with statistics on the use of our pages (“Page Insights”), we are joint controllers with the respective operator within the meaning of Art. 26 GDPR; the relevant arrangements are available for Facebook and Instagram at https://www.facebook.com/legal/terms/page_controller_addendum and for LinkedIn at https://legal.linkedin.com/pages-joint-controller-addendum. If applicable, the providers of social media ask you for consent to the respective data processing. In this case, the legal basis for the data processing would be precisely this consent.
As a data subject, you can assert various rights against the data controllers (see A.(12)). However, please note that the most sensible way to exercise these data subject rights is generally to assert them directly against the platform provider. As a rule, only the platform providers have direct access to the processed data and are the only ones who can take appropriate measures. Of course, we are at your disposal if you have any further questions in this regard.
In order to provide you with as much relevant information as possible regarding data processing on social networks, we also refer you to the data protection notices or privacy statements of the individual platform providers:
Facebook: https://www.facebook.com/about/privacy
Xing: https://privacy.xing.com/de/datenschutzerklaerung
Linked-In: https://www.linkedin.com/legal/privacy-policy
Twitter: https://twitter.com/de/privacy
Instagram: https://de-de.facebook.com/help/instagram/519522125107875
D. Audio and video conferencing
Data Processing
We use online conferencing tools, among others, to communicate with our customers. The specific tools we use are listed below. When you communicate with us via video or audio conferencing over the Internet, your personal data is collected and processed by us and the provider of the respective conferencing tool.
In doing so, the conferencing tools collect all data that you provide/enter to use the tools (email address and/or your phone number). Furthermore, the conference tools process the duration of the conference, start and end (time) of participation in the conference, number of participants and other “context information” related to the communication process (metadata).
Furthermore, the provider of the tool processes all technical data required to handle the online communication. This includes in particular IP addresses, MAC addresses, device IDs, device type, operating system type and version, client version, camera type, microphone or speaker, and the type of connection.
If content is exchanged, uploaded or otherwise made available within the tool, this is also stored on the servers of the tool providers. Such content includes, but is not limited to, cloud recordings, chat/instant messages, voicemails uploaded photos and videos, files, whiteboards, and other information shared while using the Service.
Please note that we do not have full control over the data processing operations of the tools used. Our options are largely based on the company policy of the respective provider. For further information on data processing by the conference tools, please refer to the privacy statements of the respective tools used, which we have listed below this text.
Purpose and legal basis The conference tools are used to communicate with prospective or existing contractual partners or to offer certain services to our customers (Art. 6 (1) (1) (b) GDPR). Furthermore, the use of the tools serves the general simplification and acceleration of communication with us or our company (legitimate interest within the meaning of Art. 6 (1) (1) (f) GDPR). If consent has been requested, the tools in question are used on the basis of this consent; consent can be revoked at any time with effect for the future.
Storage period
The data collected directly by us via the video and conference tools will be deleted from our systems as soon as you request us to delete it, revoke your consent to store it, or the purpose for storing the data no longer applies. Stored cookies remain on your terminal device until you delete them. Mandatory legal retention periods remain unaffected.
We have no influence on the storage period of your data, which is stored by the operators of the conference tools for their own purposes. For details, please contact the operators of the conference tools directly.
Conference tools used
We use the following conference tools:
Zoom
We use Zoom. The provider of this service is Zoom Communications Inc, San Jose, 55 Almaden Boulevard, 6th Floor, San Jose, CA 95113, USA. For details on data processing, please refer to Zoom’s privacy policy: https://zoom.us/de-de/privacy.html.
Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://zoom.us/de-de/privacy.html.
Conclusion of a contract for order processing
We have concluded an order processing contract with the provider of Zoom and fully implement the strict requirements of the German data protection authorities when using Zoom.
Microsoft Teams
We use Microsoft Teams. The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. For details on data processing, please refer to the Microsoft Teams privacy policy: https://privacy.microsoft.com/de-de/privacystatement.
Order Processing
We have entered into a contract on order processing (AVV) for the use of the above service. This is a contract required by data protection law and ensures that it only processes the personal data of our website visitors in accordance with our instructions and in compliance with the GDPR.
E. Applications
Handling of applicant data
We offer you the opportunity to apply to us (e.g. by e-mail, post or via online application form). In the following, we inform you about the scope, purpose and use of your personal data collected during the application process. We assure you that the collection, processing and use of your data will be carried out in accordance with applicable data protection law and all other statutory provisions and that your data will be treated in strict confidence.
Scope and purpose of data collection
When you send us an application, we process your associated personal data We process personal data that we receive as part of your application.
At the time of your contact as well as in the context of an application procedure, the following data in particular come into consideration, provided that you send them to us:
- Personal details (name, address and other contact details, date and place of birth, nationality),
- Bank details (for the purpose of travel expense reimbursement)
- Legitimation data (e.g. ID card data)
- Health data* (e.g. information on disability/difficulty and, if applicable, cancellation for health reasons),
- Qualification documents (e.g. certificates, evaluations and other proof of training)
- Information on your personal background
- Information about your school career
- Information about your academic career
- Information about your professional career
- Photographs
If you are sending your application by e-mail:
- E-mail address
- Mail server
- IP address of the server
If you send your application via our online form or portal:
- IP address
*Particularly sensitive data in the sense of Art. 9 (1) GDPR.
We collect this data insofar as it is necessary for the decision on the establishment of an employment relationship. The legal basis for this is § 26 BDSG-neu under German law (initiation of an employment relationship), Art. 6 (1) (1) (b) GDPR (general contract initiation) and – if you have given your consent – Art. 6 (1) (1) (a) GDPR. The consent can be revoked at any time. Your personal data will only be passed on within our company to persons involved in processing your application.
If the application is successful, the data you submitted will be stored in our data processing systems on the basis of Section 26 BDSG-neu and Art. 6 (1) (1) (b) GDPR for the purpose of implementing the employment relationship.
Recipients of your data
Data that you provide to us will be transmitted to the management as well as to the management staff in the respective responsible departments. For the settlement of travel expenses, if necessary, your data will be transmitted to the accounting department as well as our tax advisor.
However, we may use service providers for our organizational processes, the operation of our websites or for e-mail communication, for example. We also use external service providers such as tax consultants and company doctors. Here it may happen that a service provider obtains knowledge of personal data. We select our service providers carefully – particularly with regard to data protection and data security – and take all measures required under data protection law for permissible data processing.
We only transfer your personal data to third parties if this is permitted by law or if you have given your consent.
Application via the online form
If you apply via the application form on our career pages, your details and the uploaded documents (cover letter, CV, certificates; permitted formats and sizes are indicated in the form) are first stored on our web server in Germany: the form entries in the database of our website, the attachments in a directory protected against public access. Immediately after submission, the application is forwarded by e-mail to our applications mailbox ([email protected]) and a confirmation of receipt is sent to you; e-mails are sent via Microsoft 365 (see B.(3)). Only the persons involved in the recruitment process have access to the applications mailbox.
On our career and application pages, the marketing and analytics services described in B.(6) b) and B.(8) (in particular HubSpot and Google Ads conversion tracking) are disabled. Applicant data is not transferred to our CRM system, is not used for advertising purposes and is not linked to data from website tracking. Google reCAPTCHA is used to protect the form against automated input (B.(6) f). The legal basis for processing via the form is Art. 6(1)(1)(b) GDPR in conjunction with Art. 88(1) GDPR and Section 26(1) BDSG.
The form entries and attachments temporarily stored on the web server are deleted no later than 30 days after forwarding to the applications mailbox; the retention period stated below applies to the application documents themselves.
Third country transfer
For e-mail and document storage we use Microsoft 365 of Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland, as a processor (Art. 28 GDPR). The data is stored in Microsoft data centres. Insofar as access by Microsoft Corporation, One Microsoft Way, Redmond, WA 98052, USA, takes place, we base the transfer on the adequacy decision on the EU-U.S. Data Privacy Framework, under which Microsoft Corporation is certified, and additionally on the European Commission’s Standard Contractual Clauses, which form part of the Microsoft Data Protection Addendum (https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA). Information on data protection at Microsoft: https://privacy.microsoft.com/en-us/privacystatement.
Applications for positions with our US subsidiary World of Retail Services Inc., 10 Mall Road, Suite 301, Burlington, MA 01803, USA, are forwarded there only with your express consent (Art. 6(1)(1)(a), Art. 49(1)(a) GDPR), about which we inform you separately; otherwise applicant data remains with World of Retail Services GmbH.
Retention period of data
If we are unable to make you a job offer, if you reject a job offer, or if you withdraw your application, we reserve the right to retain the data you have submitted for up to 6 months from the end of the application process (rejection or withdrawal of the application) on the basis of our legitimate interests (Art. 6 (1) (1) (f) GDPR). Subsequently, the data will be deleted and the physical application documents destroyed. This storage serves in particular as evidence in the event of a legal dispute. If it is apparent that the data will be required after the 6-month period has expired (e.g. due to an impending or pending legal dispute), the data will not be deleted until the purpose for continued storage no longer applies.
Longer storage may also take place if you have given the corresponding consent (Art. 6 (1) (1) (a) GDPR) or if legal storage obligations prevent deletion.
Inclusion in the applicant pool
If we do not make you a job offer, it may be possible to include you in our applicant pool. If you are accepted, all documents and information from your application will be transferred to the applicant pool so that we can contact you in the event of suitable vacancies.
Inclusion in the applicant pool takes place exclusively on the basis of your express consent (Art. 6 (1) (1) (a) GDPR). The provision of consent is voluntary and is not related to the current application process. The data subject may revoke his/her consent at any time. In this case, the data from the applicant pool will be irrevocably deleted, unless there are legal reasons for retention.
The data from the applicant pool will be irrevocably deleted no later than two years after consent has been given.
Proceedings under the General Equal Treatment Act (AGG)
The retention of up to six months after completion of the application process mentioned above serves in particular to defend against any claims under the German General Equal Treatment Act (Section 15(4) AGG, Section 61b ArbGG). The data we collect is not used to discriminate on any of the grounds listed in Section 1 AGG.
F. Inclusion in the database as a partner company
Since we are constantly looking for partner companies in the field of shopfitting, which handle orders for us on site, we have an interest in contacting companies before concrete orders and to store them, provided their consent in our contact database.
In this case, the name and contact details of the company as well as the surname, first name, e-mail address, telephone number and position in the company of the personal contact persons are stored in our CRM system. This is done on the basis of your consent, Art. 6 (1) (1) (a) GDPR.
The data will be deleted as soon as deletion is requested.
Version: September 2026