Any collection, processing and use (hereinafter "use") of data is solely for the purpose of providing our services. Our services have been designed to use as little personal information as possible. For that matter, "personal data" is understood as all individual details about a person or factual circumstances of an identifiable natural person (so-called "affected person"). The following statements on data protection describe what types of data are collected when accessing our website, what happens with these data and how you may object to data usage.
Responsible within the meaning of the EU General Data Protection Regulation (GDPR) and the new Federal Data Protection Act (BDSG) is:
Address: Christoph-Rapparini-Bogen 25,
80639 Munich, Germany
The data protection officer is:
Kemal Webersohn of WS Datenschutz GmbH
If you have questions about data protection, you can contact WS Datenschutz GmbH at the following email address: firstname.lastname@example.org
WS Datenschutz GmbH
We have taken technical and organizational measures to ensure that the requirements of the EU General Data Protection Regulation (GDPR) are met by us, as well as, by external service providers working for us.
If we work with other companies to provide our services, such as email and server providers, this will only be done after an extensive selection process. In this selection process, each individual service provider is carefully selected for its suitability in terms of technical and organizational data protection skills. This selection procedure will be documented in writing and an agreement on the order processing of data (data processing agreement) will only be concluded if the third party complies with the requirements of Art. 28 GDPR.
Your information will be stored on specially protected servers. Access to it is only possible for a few specially authorized persons. Our website is SSL/TLS encrypted, as can be seen by the https:// at the start of our URL.
We process personal data only if necessary. As soon as the purpose of the data processing is fulfilled, erasure of the data is carried out according to the standards of the erasure concept, unless legal or contractual regulations oppose this.
When visiting our website, AWS web servers temporarily store every access in a log file. The following data may be collected and stored by AWS until automated erasure:
We do not access or analyze this data, which is stored on AWS servers.
We use the services of AWS for hosting purposes. The data processing is carried out by: Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, Luxembourg 1855, Luxembourg (a subsidiary of Amazon.com Inc., 410 Terry Avenue North, Seattle WA 98109, USA).
AWS hosting services are used to provide the following services: Infrastructure and platform services, computing capacity, storage space and database services, e-mail dispatch, security services and technical maintenance services, which we use for the purpose of operating this online offer.
You can find more information on the data protection of the service provider here: https://aws.amazon.com/de/privacy/
The legal basis for the temporary storage of the data and log files is Art. 6 para. 1 s. 1 lit. f) GDPR. Our legitimate interest is to make our website accessible for you.
The processing of this data serves: the purpose of enabling the use of the website (connection establishment), system security, the technical administration of the network infrastructure, as well as to optimize the website. The IP address is evaluated only in case of attacks on our network infrastructure or the network infrastructure of our internet provider.
As soon as the purpose of the data processing is fulfilled, erasure of the data is carried out. This happens as soon as you close our website. Our hosting service, Amazon Web Services (AWS), might use data for statistical purposes. Any personal data will be anonymized for this. Our hosting service will delete this data after a period of 6 months.
The data processing is necessary in order to present the website and to ensure the website’s operation. Therefore, objecting is impossible.
The legal basis for the processing of data by cookies, which do not only serve the functionality of our website, is Art. 6 para. 1 s. 1 lit. a) GDPR.
The legal basis for the processing of data for cookies, which serve only the functionality of this website, is Art. 6 para. 1 s. 1 lit. f) GDPR.
Our legitimate interests are to provide you with a working website connection and to ensure a comfortable use of this website. Also, we need to process your personal data to solve occurring safety and security issues, as well as to ensure system stability.
The data processing takes place to make a statistical evaluation of our website possible.
This website uses the following types of cookies. The extend and function of each are being explained below:
a) Transient cookies are automatically deleted when you close the browser. This is especially true for session cookies which store your session ID, with which various requests from your browser can be assigned to your session. This will allow your computer to be recognized when you return to our website. Session cookies are deleted when you log out or close the browser.
b) Persistent cookies are automatically deleted after a specified period, which may differ depending on the cookie.
You have the possibility to revoke your consent to the data processing by means of cookies, which do not only serve the functionality of the website. In addition, we do not set cookies until you have agreed to set cookies when you visit the site. In this way, you can prevent data processing via cookies on our website. You can also delete the cookies in your browser's security settings at any time. Please note that you may not be able to use all the features of this website. The setting of cookies can also be prevented at any time by appropriate settings in your internet browser.
Via our website it is possible to contact us via email. This will require different data to answer the request, which will be automatically saved for processing.
Your data will not be passed on to third parties, unless you have given your consent.
The legal basis depends on Art. 6 para. 1 s. 1 lit. b) GDPR.
The processing of personal data from the input form is used solely handling the contact request.
The data will be deleted as soon as we answer your request. There might occur rare cases when legal or contractual retention periods interfere with the erasure of your personal data. In this case your data will be deleted after these periods.
The user has the right to withdraw their consent to the processing of personal data at any time. If the user contacts us, they can object to storage of their personal data at any time. Insuch cases, the conversation cannot be continued. All personal data that has been stored in the course of the contact will be deleted.
We offer the opportunity to apply for jobs by email (email@example.com). For this purpose, personal data is processed and stored for further processing during the respective application process.
Data processing will be based on Art. 88 GDPR and § 26 BDSG (2018).
We process your data exclusively for the purpose of carrying out the application process.
In case of successful application and employment, the personal data is stored in accordance with the legal requirements. In case of unsuccessful application, the data will be deleted in accordance with the rules of the local erasure concept. In doing so the provisions of the AGG (German Employment Law), especially the existing evidence pursuant to § 22 AGG, are taken into account.
This does not apply if we are obliged to any legal erasure periods or if you have given consent to store your data for further communication with us (e.g. we have another suitable job in the future). If you have given consent the legal basis for further storage of your data is Art. 6 para. 1 s. 1 lit. c) or lit. a) GDPR.
You can contact us at any time and object to further processing of your data. All personal data of the application process will be deleted in this case.
For the continuous improvement of our website we use the following tracking and analytics tools. Below you can find information on which personal data is processed in each case and how you can reach the respective service providers:
Our website uses Amazon CloudFront. This is a Java Script code from the Amazon Web Services company that will be reloaded on the page when you open it. It is a Content Delivery Network (CDN). A CDN is a service that helps deliver content from our website, especially large media files, such as graphics or scripts, using regionally distributed and Internet-connected servers. Data processing is carried out by: Amazon Web Services, Inc., P.O. Box 81226, Seattle, WA 98108, USA (Amazon CloudFront – Content Delivery Network (CDN)
The legal basis for this data processing is your given consent, Art. 6 para. 1 s. 1 lit. a) GDPR.
Processing your data receives the security and functionality of the CDN.
The data will be deleted as soon as they are no longer needed for our recording purposes.
You always have the option to object your given consent. To prevent this Java based processing of your data you can install a java blocker (e.g. http://www.noscript.net or http://www.ghostery.com).
Our website uses Google Analytics. This is a service for analyzing access to websites of Google Inc. ("Google") and allows us to improve our website. Data processing for the European Economic Area and for Switzerland is carried out by:Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Cookies enable us to analyze your use of our website. The information collected by a cookie are:
The legal basis is your given consent, Art. 6 para 1 s. 1 lit. a) GDPR.
By processing the data, we can analyze how our website is used, so we can improve it for our users.
The data will be deleted 50 months after your last website visit.
You can prevent the installation of cookies by Google Analytics in your browser settings. In this case, however, it may happen that you cannot fully use all features of our website. Also, trough browsers extensions e.g. http://tools.google.com/dlpage/gaoptout?hl=de Google Analytics can be disabled and controlled.
Google Tag Manager is a solution that allows us to manage web site tags through one interface (including Google Analytics and other Google marketing services on our website). The tag manager itself (which implements the tags) does not process users' personal data. Regarding the processing of users' personal data, reference is made to the details of the Google services. Google Tag Manager usage policies can be viewed here: https://www.google.com/intl/de/tagmanager/use-policy.html
In order to be able to provide our services, we use the support of service providers from third party countries (non-EU countries). In order to ensure the protection of your personal data in this case, we conclude processing contracts with each - carefully selected - service provider. All of our processors provide sufficient guarantees to implement appropriate technical and organizational measures. Our third country data processors are either located in a country with an adequate level of data protection (Art. 45 GDPR) or provide appropriate safeguards (Art 46 GDPR).
Adequate level of protection: The provider comes from a country whose level of data protection has been recognized by the EU Commission. For more information, see: https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu/adequacy-protection-personal-data-non-eu-countries_en
EU standard contract clauses: Our provider has submitted to the EU standard contractual
clauses to ensure secure data transfer. For more information, see: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?uri=CELEX%3A32021D0914&locale=en
Binding Corporate Rules: Article 47 of the GDPR provides the possibility of ensuring data protection when transferring data to a third country via Binding Corporate Rules. These are examined and approved by the data security authorities within the framework of the consistency mechanism pursuant to Art. 63 GDPR.
Consent: In addition, a data transfer to a third country without an adequate level of protection will only take place if you have given us your consent in accordance with Art. 49 sec. 1 lit. a) GDPR for this purpose.
You have the following rights with respect to the personal data concerning you:
If you have given your consent to the processing of your data, you can withdraw it at any time. This will affect the admissibility of processing your personal data by us for the time after you have withdrawn your consent. To withdraw your consent, contact us personally or in written form.
You have the right to obtain from us confirmation as to whether or not personal data concerning you are being processed, and, where that is the case, access to your personal data and the following information:
In the case of such a request, you must provide enough information about your identity to prove that the request concerns your own personal data.
You have the right to obtain from us without undue delay the rectification and completion of inaccurate personal data concerning yourself.
You may also request the erasure of your personal data if any of the following applies to you:
Where we made the personal data public and are obliged to erase the personal data pursuant to Art. 17 para. 1 GDPR, we, taking account of available technology and the cost of implementation, shall take reasonable steps, including technical measures, to inform controllers which are processing the personal data that you have requested the erasure by such controllers of any links to, or copy or replication of, those personal data.
These rights shall not apply to the extent that processing is necessary:
You shall have the right to obtain from us restriction of processing where one of the following applies:
Where processing has been restricted under the aforementioned conditions, such personal data shall, except for storage, only be processed with your consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the Union or of a Member State.
If the limitation of the processing is restricted, you will be informed by us before the restriction is lifted.
If you have asserted to us your right to rectification, erasure or restriction of data processing, we will inform all recipients of your personal data to correct, delete or restrict the processing of data, unless this proves impossible or involves disproportionate effort.
You also have the right to know which recipients have received your personal data.
You have the right to receive your personal data, which you provided to us, in a structured, commonly used and machine-readable format. Also, you have the right to transmit those data to another controller, where
In exercising your right to data portability, you have the right to obtain that personal data transmitted directly from us to another controller, as far as technically feasible. The right to data portability does not apply to processing of personal data necessary for the performance of a task carried out in the public interest or in the exercise of official authority that has been delegated to us.
Where we based the processing of your personal data on a legitimate interest (Art. 6 para. 1 s. 1 lit. f) GDPR), you may object to the processing. The same applies if the data processing is based on Art. 6 para. 1 s. 1 lit. e).
In this case, we ask you to explain the reasons why we should not process your personal data. Based on this we will terminate or adapt the data processing or show you our legitimate reasons why we continue the data processing.
Without prejudice to any other administrative or judicial remedy, you shall have the right to complain to a supervisory authority, in particular in the Member State of your residence, place of work or place of alleged infringement, if you believe that the processing of the personal data concerning you is against the infringes of the GDPR.
The supervisory authority to which the complaint has been submitted shall inform you of the status and results of the complaint, including the possibility of a judicial remedy according to Article 78 GDPR.
To exercise these rights, please contact our data protection officer: Kemal Webersohn from Webersohn & Scholtz GmbH
firstname.lastname@example.org or by mail:
WS Datenschutz GmbH