Privacy Policy
Preamble
With the following Privacy Policy, we would like to inform you about the types of personal data (hereinafter also referred to as “data”) we process, the purposes for which we process it, and the scope of such processing. This Privacy Policy applies to all processing of personal data carried out by us, both in connection with the provision of our services and, in particular, on our websites, in mobile applications, and on external online platforms, such as our social media profiles (hereinafter collectively referred to as the “online offerings”).
The terms used are not gender-specific.
As of March 14, 2025
Table of Contents
- Preamble
- Person in Charge
- Contact the Data Protection Officer
- Overview of Processing Steps
- Relevant Legal Bases
- Safety Measures
- Transfer of Personal Data
- International Data Transfers
- General Information on Data Storage and Deletion
- Rights of Data Subjects
- Provision of the Online Service and Web Hosting
- Use of Cookies
- Blogs and Publishing Platforms
- Contact and Inquiry Management
- Web Analytics, Monitoring, and Optimization
- Social Media Presence
- Plug-ins, embedded features, and content
- Application Process
- Changes and Updates
- Definitions of Terms
Person in Charge
roeren GmbH
Ludwig-Erhard-Str. 13a
D-84034 Landshut
Germany
Authorized Representatives: Prof. Dr.-Ing. Sven Roeren
Email address: info@roeren.eu
Phone: +49 871 966448-07
Legal Notice: https://www.roeren.eu/impressum
Contact the Data Protection Officer
HBSN GmbH
28 Schloßbergstraße
D-38315 Hornburg
Phone: +49 5334 9488467
E-mail: datenschutz@hbsn-gruppe.de
Overview of Processing Steps
The following overview summarizes the types of data processed and the purposes of such processing, and identifies the data subjects.
Types of Data Processed
- Inventory data.
- Contact Information.
- Table of Contents.
- Usage data.
- Meta data, communication data, and procedural data.
- Applicant information.
- Log data.
Categories of Data Subjects
- Communication partners.
- Users.
- Applicants.
Purposes of Processing
- Communication.
- Safety measures.
- Reach measurement.
- Tracking.
- Target Audience Identification.
- Organizational and Administrative Procedures.
- Application Process.
- Firewall.
- Feedback.
- Marketing.
- Profiles containing user-specific information.
- Provision of our online services and user-friendliness.
- Information Technology Infrastructure.
- Public Relations.
Relevant Legal Bases
We process personal data exclusively in accordance with the GDPR, the BDSG, the DDG, and the TDDDG.
Relevant legal bases under the GDPR: Below is an overview of the legal bases under the GDPR on which we process personal data. Please note that, in addition to the provisions of the GDPR, national data protection regulations may apply in your country of residence or our country of residence or registered office. Should more specific legal bases apply in individual cases, we will inform you of these in the Privacy Policy.
- Consent (Art. 6(1), first sentence, subparagraph (a) of the GDPR) — The data subject has given consent to the processing of personal data concerning him or her for a specific purpose or for several specific purposes.
- Performance of a Contract and Precontractual Inquiries (Art. 6(1), first sentence, subparagraph (b) of the GDPR) — Processing is necessary for the performance of a contract to which the data subject is a party or for the implementation of precontractual measures taken at the data subject’s request.
- Legitimate Interests (Art. 6(1), first sentence, subparagraph (f) of the GDPR) – Processing is necessary to safeguard the legitimate interests of the controller or a third party, provided that the interests, fundamental rights, and fundamental freedoms of the data subject that require the protection of personal data do not override those interests.
- The recruitment process as a pre-contractual or contractual relationship (Art. 6(1), first sentence, lit. b) of the GDPR) – To the extent that, as part of the application process, special categories of personal data within the meaning of Article 9(1) of the GDPR (e.g., health data, such as severe disability status or ethnic origin) are requested from applicants, so that the controller or the data subject can exercise the rights arising from labor law and the law on social security and social protection and fulfill their respective obligations in this regard, such processing is carried out in accordance with Article 9(2)(b) GDPR; in the case of protecting the vital interests of applicants or other individuals pursuant to Article 9(2)(c) of the GDPR; or for the purposes of preventive healthcare or occupational medicine, for assessing an employee’s fitness for work, for medical diagnosis, care or treatment in the health or social sector, or for the administration of systems and services in the health or social sector pursuant to Article 9(2)(h) of the GDPR. In the event that special categories of data are provided on the basis of voluntary consent, their processing is based on Article 9(2)(a) of the GDPR.
National Data Protection Regulations in Germany: In addition to the data protection regulations of the GDPR, national data protection regulations apply in Germany. These include, in particular, the Act on the Protection Against the Misuse of Personal Data in Data Processing (Federal Data Protection Act—BDSG). The BDSG contains, in particular, special provisions regarding the right of access, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, and the transfer of data, as well as automated decision-making in individual cases, including profiling. Furthermore, state data protection laws of the individual federal states may apply.
Safety Measures
We implement technical and organizational measures appropriate to the circumstances and the purposes of the processing, as well as the varying likelihoods and severity of threats to the rights and freedoms of natural persons, in accordance with legal requirements and taking into account the state of the art, the costs of implementation, and the nature, scope, circumstances, and purposes of the processing, as well as the varying likelihoods and severity of threats to the rights and freedoms of natural persons, to ensure a level of protection appropriate to the risk.
These measures include, in particular, ensuring the confidentiality, integrity, and availability of data by controlling physical and electronic access to the data, as well as access to, input of, and disclosure of the data, ensuring its availability, and maintaining its separation. Furthermore, we have established procedures that ensure the exercise of data subjects’ rights, the deletion of data, and responses to data breaches. Furthermore, we take the protection of personal data into account from the very beginning of the development and selection of hardware, software, and procedures, in accordance with the principle of data protection through technical design and privacy-friendly default settings.
Securing Online Connections Using TLS/SSL Encryption Technology (HTTPS): To protect user data transmitted via our online services from unauthorized access, we rely on TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the Internet. These technologies encrypt the information transmitted between the website or app and the user’s browser (or between two servers), thereby protecting the data from unauthorized access. TLS, as the more advanced and secure version of SSL, ensures that all data transmissions meet the highest security standards. When a website is secured by an SSL/TLS certificate, this is indicated by the presence of “HTTPS” in the URL. This serves as an indicator to users that their data is being transmitted securely and in an encrypted form.
Transfer of Personal Data
As part of our processing of personal data, it may happen that such data is transferred to or disclosed to other agencies, companies, legally independent organizational units, or individuals. Recipients of this data may include, for example, service providers contracted to perform IT tasks or providers of services and content integrated into a website. In such cases, we comply with legal requirements and, in particular, enter into appropriate contracts or agreements with the recipients of your data to ensure the protection of your data.
International Data Transfers
Data Processing in Third Countries: If we transfer data to a third country (i.e., outside the European Union (EU) or the European Economic Area (EEA)), or if this occurs in connection with the use of third-party services or the disclosure or transfer of data to other individuals, entities, or companies (which can be identified by the provider’s mailing address or if the privacy policy explicitly refers to data transfers to third countries), this is always done in accordance with legal requirements.
For data transfers to the United States, we primarily rely on the Data Privacy Framework (DPF), which was recognized as a secure legal framework by an adequacy decision of the European Commission dated July 10, 2023. In addition, we have entered into standard contractual clauses with the respective providers that comply with the European Commission’s requirements and establish contractual obligations to protect your data.
This two-tiered safeguard ensures comprehensive protection of your data: The DPF serves as the primary layer of protection, while the Standard Contractual Clauses provide additional security. Should any changes arise within the scope of the DPF, the Standard Contractual Clauses will serve as a reliable fallback option. This ensures that your data remains adequately protected at all times, even in the event of any political or legal changes.
For each service provider, we will let you know whether they are DPF-certified and whether standard contractual clauses are in place. For more information on the DPF and a list of certified companies, visit the U.S. Department of Commerce website at https://www.dataprivacyframework.gov/ (in English).
Data transfers to other third countries are subject to appropriate security measures, in particular standard contractual clauses, explicit consent, or transfers required by law. Information on transfers to third countries and applicable adequacy decisions can be found on the European Commission’s website: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en?prefLang=de.
General Information on Data Storage and Deletion
We delete the personal data we process in accordance with legal requirements as soon as the underlying consents are revoked or there is no longer a legal basis for processing. This applies to cases in which the original purpose of processing no longer applies or the data is no longer needed. Exceptions to this rule apply when legal obligations or specific interests require the data to be retained or archived for a longer period.
In particular, data that must be retained for commercial or tax law purposes, or whose storage is necessary for the enforcement of legal claims or the protection of the rights of other natural or legal persons, must be archived accordingly.
Our privacy notices contain additional information regarding the retention and deletion of data that applies specifically to certain processing operations.
If there are multiple specifications regarding the retention period or deletion deadlines for a given date, the longest period shall always apply.
If a time limit does not expressly begin on a specific date and is at least one year in duration, it automatically begins at the end of the calendar year in which the event triggering the time limit occurred. In the case of ongoing contractual relationships under which data is stored, the event triggering the period is the date on which the termination or other termination of the legal relationship takes effect.
We process data that is no longer retained for its originally intended purpose—but rather due to legal requirements or other reasons—exclusively for the purposes that justify its retention.
Additional information on processing procedures, methods, and services:
- Data Retention and Deletion: The following general time limits apply to data retention and archiving under German law:
- 10 years – Retention period for books and records, annual financial statements, inventories, management reports, opening balance sheets, as well as the work instructions and other organizational documents necessary for their understanding (Section 147(1)(1) in conjunction with (3) of the German Fiscal Code (AO), § 14b(1) of the Value-Added Tax Act (UStG), § 257(1)(1) in conjunction with (4) of the Commercial Code (HGB)).
- 8 years—accounting documents, such as invoices and expense receipts (Section 147(1)(4) and (4a) in conjunction with (3), first sentence, of the German Fiscal Code (AO), and Section 257(1)(4) in conjunction with (4) of the German Commercial Code (HGB)).
- 6 years — Other business records: received business or commercial correspondence, copies of sent business or commercial correspondence, and other documents to the extent they are relevant for tax purposes, e.g., hourly pay slips, payroll sheets, cost calculation documents, price tags, as well as payroll records, provided they are not already accounting entries, and cash register receipts (Section 147(1)(2), 3, 5 in conjunction with para. 3 of the German Fiscal Code (AO), § 257(1)(2) and (3) in conjunction with para. 4 of the German Commercial Code (HGB)).
- 3 years—Data necessary to address potential warranty and damage claims or similar contractual claims and rights, as well as to process related inquiries, based on past business experience and standard industry practices, are stored for the duration of the standard statutory limitation period of three years (Sections 195, 199 of the German Civil Code (BGB)).
Rights of Data Subjects
Rights of Data Subjects Under the GDPR: As a data subject, you have various rights under the GDPR, which arise in particular from Articles 15 through 21 of the GDPR:
- Right to Object: You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data carried out pursuant to Article 6(1)(e) or (f) of the GDPR; this also applies to profiling based on these provisions. If your personal data is processed for the purpose of direct marketing, you have the right to object at any time to the processing of your personal data for such marketing purposes; this also applies to profiling to the extent that it is related to such direct marketing.
- Right to Withdraw Consent: You have the right to withdraw your consent at any time.
- Right of Access: You have the right to request confirmation as to whether your personal data is being processed, as well as access to that data, additional information, and a copy of the data in accordance with legal requirements.
- Right to Rectification: In accordance with legal requirements, you have the right to request that data concerning you be completed or that inaccurate data concerning you be corrected.
- Right to erasure and restriction of processing: In accordance with legal requirements, you have the right to request that data concerning you be erased without delay or, alternatively, to request a restriction on the processing of such data in accordance with legal requirements.
- Right to Data Portability: You have the right to receive the personal data concerning you that you have provided to us in a structured, commonly used, and machine-readable format, in accordance with legal requirements, or to request that it be transferred to another data controller.
- Complaint to a Supervisory Authority: In accordance with legal requirements and without prejudice to any other administrative or judicial remedy, you also have the right to file a complaint with a data protection supervisory authority—in particular, a supervisory authority in the Member State where you habitually reside— the supervisory authority of your place of work or the location of the alleged infringement, if you believe that the processing of your personal data violates the GDPR.
Provision of the Online Service and Web Hosting
We process users’ data in order to provide them with our online services. For this purpose, we process the user’s IP address, which is necessary to deliver the content and features of our online services to the user’s browser or device.
- Types of Data Processed: Usage data (e.g., page views and time spent on the site, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and features); Meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, individuals involved). Log data (e.g., log files regarding logins, data retrieval, or access times).
- Data subjects: Users (e.g., website visitors, users of online services).
- Purposes of processing: Provision of our online services and user-friendliness; information technology infrastructure (operation and provision of information systems and technical devices (computers, servers, etc.)); security measures. Firewall.
- Retention and Deletion: Deletion in accordance with the information provided in the section “General Information on Data Retention and Deletion.”
- Legal basis: Legitimate interests (Art. 6(1), first sentence, subparagraph (f) of the GDPR).
Additional information on processing procedures, methods, and services:
- Provision of Online Services on Leased Storage Space: To provide our online services, we use storage space, computing capacity, and software that we lease or otherwise obtain from a server provider (also known as a “web host”); Legal basis: Legitimate interests (Art. 6(1), first sentence, lit. f) of the GDPR).
- Collection of Access Data and Log Files: Access to our online service is logged in the form of so-called “server log files.” Server log files may include the address and name of the web pages and files accessed, the date and time of the request, the amount of data transferred, a notification of a successful request, the browser type and version, the user’s operating system, the referrer URL (the previously visited page), and, as a rule, IP addresses and the requesting provider. The server log files may be used, on the one hand, for security purposes—for example, to prevent server overload (particularly in the event of malicious attacks, so-called DDoS attacks)—and, on the other hand, to ensure server capacity and stability; Legal basis: Legitimate interests (Art. 6(1)(f) GDPR). Data deletion: Log file information is stored for a maximum of 30 days and is then deleted or anonymized. Data that must be retained for evidentiary purposes is exempt from deletion until the respective incident has been fully resolved.
- Wordfence: Firewall , security, and intrusion detection features to detect and prevent unauthorized access attempts as well as technical vulnerabilities that could enable such access. For these purposes, cookies and similar storage methods necessary for this purpose may be used, and security logs may be created during the check and, in particular, in the event of unauthorized access. In this context, users’ IP addresses, a user identification number, and their activities—including the time of access—are processed and stored, compared with the data provided by the provider of the firewall and security functions, and transmitted to that provider; Service Provider: Defiant, Inc., 800 5th Ave Ste 4100, Seattle, WA 98104, USA; Legal basis: Legitimate interests (Art. 6(1)(f) GDPR); Website: https://www.wordfence.com; Privacy Policy: https://www.wordfence.com/privacy-policy/; Basis for transfers to third countries: Standard Contractual Clauses (https://www.wordfence.com/standard-contractual-clauses/), Standard Contractual Clauses (https://www.wordfence.com/standard-contractual-clauses/). Further information: https://www.wordfence.com/help/general-data-protection-regulation/.
- SPIEGLHOF media GmbH: Website hosting; Service provider: SPIEGLHOF media GmbH
Luitpoldstraße 4
D-84034 Landshut; Website: https://www.spieglhof-media.de. Privacy Policy: https://www.spieglhof-media.de/hilfe/datenschutz/.
Use of Cookies
The term “cookies” refers to functions that store and retrieve information on users’ devices. Cookies may also be used for various purposes, such as ensuring the functionality, security, and convenience of online services, as well as analyzing visitor traffic. We use cookies in accordance with legal requirements. To this end, we obtain users’ consent in advance when necessary. If consent is not required, we rely on our legitimate interests. This applies when the storage and retrieval of information is essential to provide explicitly requested content and features. This includes, for example, saving settings and ensuring the functionality and security of our online services. Consent may be revoked at any time. We provide clear information about the scope of our use and which cookies are used.
Notes on the Legal Basis for Data Protection: Whether we process personal data using cookies depends on consent. If consent has been given, it serves as the legal basis. Without consent, we rely on our legitimate interests, which are explained above in this section and in the context of the respective services and procedures.
Storage Duration: With regard to storage duration, the following types of cookies are distinguished:
- Temporary cookies (also known as session cookies): Temporary cookies are deleted at the latest after a user leaves a website and closes their device (e.g., browser or mobile app).
- Persistent cookies: Persistent cookies remain stored even after the device is turned off. This allows, for example, the user’s login status to be saved and preferred content to be displayed immediately when the user visits a website again. Similarly, user data collected via cookies may be used for audience measurement. Unless we provide users with explicit information regarding the type and storage duration of cookies (e.g., when obtaining consent), they should assume that these cookies are persistent and may be stored for up to two years.
General Information on Withdrawal of Consent and Objection (Opt-out): Users may withdraw the consent they have provided at any time and may also object to the processing of their data in accordance with legal requirements, including through their browser’s privacy settings.
- Types of data processed: Meta data, communication data, and procedural data (e.g., IP addresses, timestamps, identification numbers, individuals involved). Usage data (e.g., page views and time spent on the site, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and features).
- Data subjects: Users (e.g., website visitors, users of online services).
- Purposes of processing: To provide our online services and ensure user-friendliness.
- Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR). Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR).
Additional information on processing procedures, methods, and services:
- Processing of Cookie Data Based on Consent: We use a consent management solution to obtain users’ consent to the use of cookies or to the procedures and providers specified within the consent management solution. This procedure serves to obtain, log, manage, and revoke consents, particularly with regard to the use of cookies and similar technologies that are used to store, read, and process information on users’ devices. As part of this process, users’ consent is obtained for the use of cookies and the associated processing of information, including the specific processing activities and providers mentioned in the consent management process. Users also have the option to manage and revoke their consents. The consent declarations are stored to avoid repeated requests and to maintain proof of consent in accordance with legal requirements. Storage takes place on the server and/or in a cookie (known as an “opt-in cookie”) or via comparable technologies to enable the consent to be assigned to a specific user or their device. Unless specific information regarding the providers of consent management services is available, the following general guidelines apply: Consent is stored for up to two years. A pseudonymous user identifier is created and stored along with the time of consent, details regarding the scope of consent (e.g., relevant categories of cookies and/or service providers), and information about the browser, the system, and the end device used; Legal basis: Consent (Art. 6(1), sentence 1, letter a) of the GDPR).
- Moove GDPR Cookie Compliance: Consent Management : Procedures for obtaining, logging, managing, and revoking consent, particularly for the use of cookies and similar technologies to store, read, and process information on users’ end devices, as well as the processing of such information; Service Provider: Execution on servers and/or computers under the provider’s own responsibility under data protection law; Legal Bases: Legitimate Interests (Art. 6(1), sentence 1, lit. f) GDPR). Website: https://wordpress.org/plugins/gdpr-cookie-compliance/.
Blogs and Publishing Platforms
We use blogs or similar means of online communication and publication (hereinafter “publication medium”). Readers’ data is processed for the purposes of the publication medium only to the extent necessary for its presentation and for communication between authors and readers, or for security reasons. For further information, please refer to the details regarding the processing of visitors to our publication medium as set forth in this Privacy Policy.
- Types of data processed: Master data (e.g., full name, home address, contact information, customer number, etc.); contact information (e.g., mailing and email addresses or phone numbers); Content data (e.g., text or image-based messages and posts, as well as related information such as details regarding authorship or the time of creation); Usage data (e.g., page views and time spent on the site, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and features). Meta, communication, and process data (e.g., IP addresses, timestamps, identification numbers, individuals involved).
- Data subjects: Users (e.g., website visitors, users of online services).
- Purposes of processing: Feedback (e.g. collecting feedback via online form). Provision of our online services and user-friendliness.
- Retention and Deletion: Deletion in accordance with the information provided in the section “General Information on Data Retention and Deletion.”
- Legal basis: Legitimate interests (Art. 6(1), first sentence, subparagraph (f) of the GDPR).
Contact and Inquiry Management
When you contact us (e.g., by mail, contact form, email, phone, or social media), as well as in the context of existing user and business relationships, we process the information provided by the individuals making the inquiry to the extent necessary to respond to their inquiries and take any requested actions.
- Types of data processed: Master data (e.g., full name, home address, contact information, customer number, etc.); contact information (e.g., mailing and email addresses or phone numbers); Content data (e.g., text or image-based messages and posts, as well as related information such as details regarding authorship or the time of creation); Usage data (e.g., page views and time spent on the site, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and features). Meta, communication, and process data (e.g., IP addresses, timestamps, identification numbers, individuals involved).
- Affected individuals: Communication partners.
- Purposes of processing: Communication; organizational and administrative procedures; feedback (e.g. collecting feedback via online form). Provision of our online services and user-friendliness.
- Retention and Deletion: Deletion in accordance with the information provided in the section “General Information on Data Retention and Deletion.”
- Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR). Contract performance and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR).
Additional information on processing procedures, methods, and services:
- Contact Form: When you contact us via our contact form, by email, or through other communication channels, we process the personal data you provide to us in order to respond to and handle your inquiry. This generally includes information such as your name, contact information, and, if applicable, any additional information provided to us that is necessary for proper processing. We use this data exclusively for the stated purpose of establishing contact and communication; Legal Bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR), Legitimate interests (Art. 6(1)(f) GDPR).
Web Analytics, Monitoring, and Optimization
Web analysis (also referred to as “reach measurement”) is used to evaluate the flow of visitors to our online offering and may include behavior, interests or demographic information about visitors, such as age or gender, as pseudonymous values. With the help of reach analysis, we can, for example, recognize at what time our online offer or its functions or content are most frequently used, or invite visitors to reuse them. It also enables us to understand which areas require optimization.
In addition to web analytics, we can also use testing methods to, for example, test and optimize different versions of our online offering or its components.
Unless otherwise specified below, profiles—that is, data aggregated for a specific usage session—may be created for these purposes, and information may be stored in a browser or on a device and then retrieved. The information collected includes, in particular, websites visited and the elements used there, as well as technical information such as the browser used, the computer system used, and details regarding usage times. If users have consented to the collection of their location data by us or by the providers of the services we use, the processing of location data is also possible.
In addition, users’ IP addresses are stored. However, we use an IP masking process (i.e., pseudonymization by truncating the IP address) to protect users. In general, no personally identifiable user data (such as email addresses or names) is stored in the context of web analytics, A/B testing, and optimization; instead, pseudonyms are used. This means that neither we nor the providers of the software we use know the actual identity of the users; we only know the information stored in their profiles for the purpose of the respective processes.
Notes on Legal Bases: If we ask users for their consent to the use of third-party providers, the legal basis for data processing is consent. Otherwise, user data is processed based on our legitimate interests (i.e., our interest in providing efficient, cost-effective, and user-friendly services). In this context, we would also like to direct your attention to the information regarding the use of cookies in this Privacy Policy.
- Types of Data Processed: Usage data (e.g., page views and time spent on the site, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and features). Meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, individuals involved).
- Data subjects: Users (e.g., website visitors, users of online services).
- Purposes of processing: Audience measurement (e.g., traffic statistics, identification of returning visitors). Profiles containing user-related information (creation of user profiles).
- Storage and deletion: Deletion in accordance with the information in the section “General information on data storage and deletion”. Storage of cookies for up to 2 years (Unless otherwise stated, cookies and similar storage methods may be stored on users’ devices for a period of two years).
- Security measures: IP masking (pseudonymization of the IP address).
- Legal basis: Consent (Art. 6(1), first sentence, subparagraph (a) of the GDPR). Legitimate interests (Art. 6(1), first sentence, subparagraph (f) of the GDPR).
Additional information on processing procedures, methods, and services:
- Matomo: Matomo is software used for web analytics and audience measurement. When Matomo is used, cookies are generated and stored on the user’s device. The user data collected through the use of Matomo is processed solely by us and is not shared with third parties. The cookies are stored for a maximum period of 13 months: https://matomo.org/faq/general/faq_146/; Legal basis: Consent (Art. 6(1)(a) GDPR). Data deletion: The cookies are stored for a maximum of 13 months.
- Google Analytics 4: We use the web analytics service Google Analytics 4 (GA4), provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”), on our website.
Purpose of processing: Google Analytics enables us to analyze how our website is used in order to improve our offerings and marketing activities. In particular, page views, time spent on the site, interactions, and technical information about the device used are processed.
Legal Basis: Processing is carried out exclusively on the basis of your consent in accordance with Article 6(1)(a) of the GDPR. Consent is obtained through our consent management tool and may be withdrawn at any time with future effect.
Type of Data Processed: When using Google Analytics, the following data in particular is processed:
- IP address (abbreviated/anonymized)
- Device and Browser Information
- Usage behavior (e.g., page views, clicks)
- Approximate location data (region)
- Technical Information on Display
We ensure that no personally identifiable information, such as names or email addresses, is transmitted to Google.
IP anonymization: Google truncates the IP address within the European Union or the European Economic Area before any further processing takes place.
Transfers to Third Countries: It cannot be ruled out that data may also be transferred to Google servers in the United States. For such cases, Google has entered into so-called Standard Contractual Clauses (SCCs) in accordance with Article 46 of the GDPR. Please note that the level of data protection in the United States may not be comparable to that in the EU, and access by government authorities cannot be ruled out.
Retention Period: The data we send that is linked to cookies is automatically deleted after 2 months.
Withdrawal of Consent: You can withdraw your consent at any time through the settings on our cookie banner.
Additional Information: For more information about Google’s privacy practices, please visit: https://policies.google.com/privacy
Social Media Presence
We maintain online presences on social media platforms and, in this context, process user data in order to communicate with users active on those platforms or to provide information about us.
Please note that user data may be processed outside the European Union in this context. This may pose risks to users, as it could, for example, make it more difficult to enforce their rights.
Furthermore, user data within social networks is generally processed for market research and advertising purposes. For example, user profiles can be created based on users’ behavior and the resulting interests. These profiles may in turn be used, for example, to display advertisements both within and outside the networks that are presumed to match users’ interests. For this reason, cookies are typically stored on users’ computers to record their usage behavior and interests. In addition, data may also be stored in these usage profiles regardless of the devices used by users (particularly if they are members of the respective platforms and are logged in there).
For a detailed description of the specific ways in which your data is processed and your options for opting out, please refer to the privacy policies and information provided by the operators of the respective networks.
We would also like to point out that requests for information and the exercise of data subject rights are most effectively handled by the service providers themselves. Only the service providers have access to user data and can take appropriate action and provide information directly. If you still need assistance, however, you can contact us.
- Types of data processed: Contact information (e.g., mailing and email addresses or phone numbers); content data (e.g., text or image-based messages and posts, as well as related information such as details regarding authorship or the time of creation). Usage data (e.g., page views and time spent on the site, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and features).
- Data subjects: Users (e.g., website visitors, users of online services).
- Purposes of processing: Communication; feedback (e.g. collecting feedback via online form). Public relations.
- Retention and Deletion: Deletion in accordance with the information provided in the section “General Information on Data Retention and Deletion.”
- Legal basis: Legitimate interests (Art. 6(1), first sentence, subparagraph (f) of the GDPR).
Additional information on processing procedures, methods, and services:
- LinkedIn: Social Network – Together with LinkedIn Ireland Unlimited Company, we are responsible for the collection (but not the further processing) of visitor data used to generate “Page Insights” (statistics) for our LinkedIn profiles. This data includes information about the types of content users view or interact with, as well as the actions they take. In addition, details about the devices used are collected, such as IP addresses, operating system, browser type, language settings, and cookie data, as well as information from user profiles, such as job title, country, industry, hierarchical level, company size, and employment status. Privacy information regarding LinkedIn’s processing of user data can be found in LinkedIn’s Privacy Policy: https://www.linkedin.com/legal/privacy-policy.
We have entered into a specific agreement with LinkedIn Ireland (“Page Insights Joint Controller Addendum,” https://legal.linkedin.com/pages-joint-controller-addendum), which specifically outlines the security measures LinkedIn must observe and in which LinkedIn has agreed to honor the rights of data subjects (i.e., users can, for example, submit requests for access or deletion directly to LinkedIn). Users’ rights (in particular the right to access, erasure, objection, and complaint to the competent supervisory authority) are not restricted by the agreements with LinkedIn. Joint responsibility is limited to the collection and transfer of data to LinkedIn Ireland Unlimited Company, a company based in the EU. Further processing of the data is the sole responsibility of LinkedIn Ireland Unlimited Company, particularly with regard to the transfer of data to the parent company, LinkedIn Corporation, in the United States; Service provider: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland; Legal basis: Legitimate interests (Art. 6(1)(f) GDPR); Website: https://www.linkedin.com; Privacy Policy: https://www.linkedin.com/legal/privacy-policy; Basis for transfers to third countries: Data Privacy Framework (DPF), Standard Contractual Clauses (https://legal.linkedin.com/dpa), Data Privacy Framework (DPF), Standard Contractual Clauses (https://legal.linkedin.com/dpa). Option to object (opt-out): https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out. - YouTube: Social network and video platform; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal basis: Legitimate interests (Art. 6(1), first sentence, lit. f) of the GDPR); Privacy Policy: https://policies.google.com/privacy; Basis for transfers to third countries: Data Privacy Framework (DPF), Data Privacy Framework (DPF). Option to object (opt-out): https://myadcenter.google.com/personalizationoff.
- Xing: Social network; Service provider: New Work SE, Am Strandkai 1, 20457 Hamburg, Germany; Legal basis: Legitimate interests (Art. 6(1)(f) GDPR); Website: https://www.xing.com/. Privacy Policy: https://privacy.xing.com/de/datenschutzerklaerung.
Plug-ins, embedded features, and content
We incorporate functional and content elements into our online offering that are sourced from the servers of their respective providers (hereinafter referred to as “third-party providers”). These may include, for example, graphics, videos, or city maps (hereinafter collectively referred to as “content”).
This integration always requires that the third-party providers of this content process users’ IP addresses, since they would not be able to send the content to users’ browsers without them. The IP address is therefore necessary for displaying this content or these features. We strive to use only content whose respective providers use the IP address solely for the purpose of delivering the content. Third-party providers may also use so-called pixel tags (invisible graphics, also known as “web beacons”) for statistical or marketing purposes. These “pixel tags” allow information—such as visitor traffic on the pages of this website—to be analyzed. This pseudonymous information may also be stored in cookies on the user’s device and may include, among other things, technical information about the browser and operating system, referring websites, the time of the visit, and other details regarding the use of our online service; it may also be linked to such information from other sources.
Notes on Legal Bases: When we ask users for their consent to the use of third-party providers, the legal basis for data processing is their consent. Otherwise, user data is processed based on our legitimate interests (i.e., our interest in providing efficient, cost-effective, and user-friendly services). In this context, we would also like to draw your attention to the information regarding the use of cookies in this Privacy Policy.
- Types of Data Processed: Usage data (e.g., page views and time spent on the site, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and features). Meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, individuals involved).
- Data subjects: Users (e.g., website visitors, users of online services).
- Purposes of processing: Provision of our online services and user-friendliness; reach measurement (e.g. access statistics, recognition of returning visitors); tracking (e.g. interest/behavioral profiling, use of cookies); target group formation. Marketing.
- Storage and deletion: Deletion in accordance with the information in the section “General information on data storage and deletion”. Storage of cookies for up to 2 years (Unless otherwise stated, cookies and similar storage methods may be stored on users’ devices for a period of two years).
- Legal basis: Consent (Art. 6(1), first sentence, subparagraph (a) of the GDPR). Legitimate interests (Art. 6(1), first sentence, subparagraph (f) of the GDPR).
Additional information on processing procedures, methods, and services:
- Google Fonts (hosted on our own server): Provision of font files to ensure a user-friendly display of our online content; Service provider: Google Fonts are hosted on our server; no data is transmitted to Google; Legal basis: Legitimate interests (Art. 6(1)(f) of the GDPR).
- Font Awesome (hosted on our own server): Display of fonts and icons; Service provider: The Font Awesome icons are hosted on our server; no data is transmitted to the Font Awesome provider; Legal basis: Legitimate interests (Art. 6(1)(f) of the GDPR).
- YouTube videos: Video content ; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal basis: Consent (Art. 6(1), first sentence, lit. a) GDPR); Website: https://www.youtube.com; Privacy Policy: https://policies.google.com/privacy; Basis for transfers to third countries: Data Privacy Framework (DPF), Data Privacy Framework (DPF). Opt-out option: Opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=de, Settings for displaying ads: https://myadcenter.google.com/personalizationoff.
- Google Hosted Libraries: Google Hosted Libraries is a globally available content delivery network (CDN) for the most popular open-source JavaScript libraries. These libraries are used to provide web libraries that optimize website loading times, reduce bandwidth usage, and improve performance by utilizing shared, public resources; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal basis: Legitimate interests (Art. 6(1)(f) GDPR); Website: https://developers.google.com/speed/libraries/. Privacy Policy: https://policies.google.com/privacy.
Application Process
The application process requires applicants to provide us with the data necessary for their assessment and selection. The information required can be found in the job description or, in the case of online forms, in the details provided there.
Generally, the required information includes personal details such as your name, address, and contact information, as well as proof of the qualifications necessary for the position. Upon request, we are also happy to provide additional details regarding what information is needed.
If available, applicants are welcome to submit their applications via our online form, which is encrypted using state-of-the-art technology. Alternatively, you may also send your application to us by email. However, we would like to point out that emails are generally not encrypted when sent over the Internet. Although emails are usually encrypted during transmission, this encryption does not apply to the servers from which they are sent and received. Therefore, we cannot assume any responsibility for the security of your application while it is being transmitted between you and our server.
For the purposes of searching for candidates, submitting applications, and selecting candidates, we may use applicant tracking and recruitment software, as well as third-party platforms and services, in compliance with legal requirements.
Applicants are welcome to contact us to find out how to submit their application or to send it to us by mail.
Processing of Special Categories of Data: To the extent that, as part of the application process, special categories of personal data (Art. 9(1) GDPR, e.g., health data, such as severe disability status or ethnic origin) are requested from applicants or provided by them, such data is processed so that the controller or the data subject may exercise the rights and fulfill the obligations arising under labor law and the law on social security and social protection, in the case of the protection of the vital interests of applicants or other individuals, or for the purposes of preventive healthcare or occupational medicine, for the assessment of an employee’s fitness for work, for medical diagnosis, for care or treatment in the health or social sector, or for the administration of systems and services in the health or social sector.
Deletion of Data: The data provided by applicants may be further processed by us for the purposes of the employment relationship in the event of a successful application. Otherwise, if the application for a job opening is unsuccessful, the applicants’ data will be deleted. Applicants’ data will also be deleted if an application is withdrawn, which applicants are entitled to do at any time. Subject to a valid revocation by the applicant, the data will be deleted no later than six months after the application is submitted, so that we can answer any follow-up questions regarding the application and fulfill our obligations to provide evidence under the regulations on equal treatment of applicants. Invoices for any travel expense reimbursements are archived in accordance with tax regulations.
Inclusion in a Candidate Pool: Inclusion in a candidate pool, if offered, is based on consent. Candidates are informed that their consent to be included in the talent pool is voluntary, has no impact on the current application process, and that they may withdraw their consent at any time with future effect.
- Types of data processed: Master data (e.g., full name, home address, contact information, customer number, etc.); contact information (e.g., mailing and email addresses or phone numbers); Content data (e.g., text or image-based messages and posts, as well as related information such as details regarding authorship or the time of creation). Applicant data (e.g., personal details, mailing and contact addresses, documents submitted with the application, and the information contained therein, such as cover letters, resumes, certificates, and other information regarding a specific position or voluntarily provided by applicants about themselves or their qualifications).
- Individuals affected: Job applicants.
- Purposes of processing: Hiring process (establishment and any subsequent implementation of, as well as possible future termination of, the employment relationship).
- Retention and Deletion: Deletion in accordance with the information provided in the section “General Information on Data Retention and Deletion.”
- Legal Basis: The application process as a pre-contractual or contractual relationship (Art. 6(1), first sentence, subparagraph (b) of the GDPR).
Changes and Updates
We ask that you review the content of our Privacy Policy on a regular basis. We will update the Privacy Policy as soon as changes to our data processing practices make it necessary. We will notify you as soon as the changes require action on your part (e.g., consent) or any other individual notification.
Although roeren GmbH regularly checks the website to ensure that all information provided is up to date, it cannot be generally ruled out that changes may occur between individual checks. This applies, among other things, to links and contact information.
Definitions of Terms
This section provides an overview of the terms used in this Privacy Policy. To the extent that these terms are defined by law, their legal definitions apply. The explanations below, however, are intended primarily to aid understanding.
- Inventory data: Inventory data includes essential information necessary for the identification and management of contractual partners, user accounts, profiles and similar assignments. This data may include personal and demographic information such as names, contact information (addresses, telephone numbers, e-mail addresses), dates of birth and specific identifiers (user IDs). Inventory data forms the basis for any formal interaction between people and services, facilities or systems by enabling clear assignment and communication.
- Firewall: A firewall is a security system that protects a computer network or an individual computer from unwanted network access.
- Content data: Content data includes information generated in the course of creating, editing and publishing content of all kinds. This category of data can include text, images, videos, audio files and other multimedia content published on various platforms and media. Content data is not limited to the actual content, but also includes metadata that provides information about the content itself, such as tags, descriptions, author information and publication dates
- Contact details: Contact data is essential information that enables communication with individuals or organizations. It includes telephone numbers, postal addresses and email addresses, as well as communication tools such as social media handles and instant messaging identifiers.
- Meta, communication and procedural data: Meta, communication and procedural data are categories that contain information about the way in which data is processed, transmitted and managed. Meta data, also known as data about data, includes information that describes the context, origin and structure of other data. It can include information on file size, creation date, the author of a document and change histories. Communication data records the exchange of information between users via various channels, such as e-mail traffic, call logs, messages in social networks and chat histories, including the persons involved, time stamps and transmission paths. Procedural data describes the processes and procedures within systems or organizations, including workflow documentation, logs of transactions and activities, and audit logs used to track and review operations.
- Usage data: Usage data refers to information that captures how users interact with digital products, services or platforms. This data includes a wide range of information that shows how users use applications, which functions they prefer, how long they stay on certain pages and which paths they navigate through an application. Usage data can also include frequency of use, timestamps of activities, IP addresses, device information and location data. It is particularly valuable for analysing user behaviour, optimizing user experiences, personalizing content and improving products or services. In addition, usage data plays a crucial role in identifying trends, preferences and potential problem areas within digital offerings
- Personal data: “Personal data” means any information relating to an identified or identifiable natural person (hereinafter referred to as “data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. a cookie) or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
- Profiles with user-related information: The processing of “profiles with user-related information”, or “profiles” for short, includes any type of automated processing of personal data that consists of using this personal data to analyze, evaluate or predict certain personal aspects relating to a natural person (depending on the type of profiling, this may include various information relating to demographics, behavior and interests, such as interaction with websites and their content, etc.) (e.g. interests in certain content or products, click behavior on a website or location). Cookies and web beacons are often used for profiling purposes.
- Log data: Log data is information about events or activities that have been logged on a system or network. This data typically contains information such as timestamps, IP addresses, user actions, error messages and other details about the use or operation of a system. Log data is often used to analyze system problems, for security monitoring or to create performance reports.
- Reach measurement: Reach measurement (also known as web analytics) is used to evaluate the flow of visitors to an online offering and can include the behavior or interests of visitors in certain information, such as website content. With the help of reach analysis, operators of online offers can, for example, recognize at what time users visit their websites and what content they are interested in. This allows them to better adapt the content of their websites to the needs of their visitors, for example. For the purposes of reach analysis, pseudonymous cookies and web beacons are often used to recognize returning visitors and thus obtain more precise analyses of the use of an online offer.
- Tracking: The term “tracking” is used when the behavior of users can be traced across several online offers. As a rule, behavioral and interest information is stored in cookies or on the servers of the providers of the tracking technologies with regard to the online offers used (so-called profiling). This information can then be used, for example, to display advertisements to users that are likely to correspond to their interests.
- Controller: The “controller” is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
- Processing: “Processing” means any operation or set of operations which is performed on personal data, whether or not by automated means. The term is broad and covers practically every handling of data, be it collection, analysis, storage, transmission or deletion.
- Target group formation: Target group formation (custom audiences) is the term used when target groups are determined for advertising purposes, e.g. the display of advertisements. For example, based on a user’s interest in certain products or topics on the Internet, it can be concluded that this user is interested in advertisements for similar products or the online store in which they viewed the products. In turn, “lookalike audiences” (or similar target groups) are when the content deemed suitable is displayed to users whose profiles or interests presumably correspond to the users for whom the profiles were created. Cookies and web beacons are generally used for the purpose of creating custom audiences and lookalike audiences.