We have drawn up this privacy policy to explain to you what personal data we, as the controller, and the processors commissioned by us (e.g. providers) process and will process in the future, and what legal options you have. The terms used are to be understood as gender-neutral.

The privacy policy also applies to all personal data processed by us within the company and to all personal data processed by companies commissioned by us (processors). By personal data, we mean information within the meaning of Art. 4 No. 1 GDPR, such as a person's name, email address and postal address. The processing of personal data ensures that we can offer and invoice our services and products, whether online or offline. The scope of this privacy policy covers:

  • all online presences (websites, online shops) operated by the controller

  • social media sites and email communication

  • mobile apps for smartphones and other devices

Definitions

We use the following terms in this privacy policy, among others:

Personal data: Personal data is any information relating to an identified or identifiable natural person (hereinafter referred to as "data subject"). A natural person is considered identifiable if they can be identified directly or indirectly, in particular by association with an identifier such as a name, an identification number, location data, an online identifier or one or more special characteristics that express the physical, physiological, genetic, psychological, economic, cultural or social identity of that natural person.


Data subject: A data subject is any identified or identifiable natural person whose personal data is processed by the controller.


Processing: Processing is any operation or set of operations which is performed on personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, distribution or otherwise making available, alignment or combination, restriction, erasure or destruction.


Restriction of processing: Restriction of processing is the marking of stored personal data with the aim of limiting their processing in the future.


Profiling: Profiling is any form of automated processing of personal data consisting of the use of such personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.


Pseudonymisation: Pseudonymisation is the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data is not attributed to an identified or identifiable natural person.


Controller or processor: The controller or processor is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. Where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.


Processor: A processor is a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.


Recipient: A recipient is a natural or legal person, public authority, agency or another body to which personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.


Third party: A third party is a natural or legal person, public authority, agency or other body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data.


Consent: Consent is any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.
 

  • Our websites use cookies. Cookies are text files that are stored on a computer system via an internet browser.
    Numerous websites and servers use cookies. Many cookies contain a so-called cookie ID. A cookie ID is a unique identifier for the cookie. It consists of a string of characters that can be used to assign websites and servers to the specific web browser in which the cookie was stored. This enables the websites and servers visited to distinguish the individual browser of the person concerned from other web browsers that contain other cookies. A specific Internet browser can be recognised and identified via the unique cookie ID.
    By using cookies, we can provide users of this website with more user-friendly services that would not be possible without the use of cookies.
    Cookies enable us to optimise the information and offers on our website for the benefit of the user. As already mentioned, cookies enable us to recognise users of our website. The purpose of this recognition is to make it easier for users to use our website. For example, users of a website that uses cookies do not have to re-enter their access data each time they visit the website, as this is done by the website and the cookie stored on the user's computer system. Another example is the cookie used for a shopping basket in an online shop. The online shop uses a cookie to remember the items that a customer has placed in their virtual shopping basket.
    The data subject can prevent the setting of cookies by our website at any time by means of a corresponding setting in the Internet browser used and thus permanently object to the setting of cookies. Furthermore, cookies that have already been set can be deleted at any time via an Internet browser or other software programmes. This is possible in all common Internet browsers. If the data subject deactivates the setting of cookies in the Internet browser used, not all functions of our website may be fully usable.

  • Our website collects a range of general data and information each time a data subject or an automated system accesses the website. This general data and information is stored in the server log files. The following may be recorded:

    • the browser types and versions used,
    • the operating system used by the accessing system,
    • the website from which an accessing system reaches our website (so-called referrer),
    • the sub-websites accessed via an accessing system on our website,
    • the date and time of access to the website,
    • an Internet Protocol address (IP address),
    • the Internet service provider of the accessing system, and
    • other similar data and information that serves to avert danger in the event of attacks on our information technology systems.

    When using this general data and information, we do not draw any conclusions about the data subject. Rather, this information is required in order to:

    • deliver the content of our website correctly,
    • optimise the content of our website and the advertising for it,
    • ensure the long-term functionality of our information technology systems and the technology of our website, and
    • provide law enforcement authorities with the information necessary for prosecution in the event of a cyber attack.


    We therefore evaluate this anonymously collected data and information statistically and with the aim of increasing data protection and data security in our company in order to ultimately ensure an optimal level of protection for the personal data we process. The anonymous data in the server log files is stored separately from all personal data provided by a data subject.

  • If you have any questions about data protection or the processing of personal data, you will find the contact details of the controller in accordance with Art. 4 (7) of the EU General Data Protection Regulation (GDPR) below:


    UnternehmerTUM GmbH
    Lichtenbergstr. 6
    85748 Garching 


    Authorised representatives:
    •    Prof. Dr Helmut Schönenberger (CEO)
    •    Stefan Drüssler
    •    Claudia Frey
    •    Christian Mohr
    •    Thomas Zeller


    Email: datenschutz@unternehmertum.de
    Legal notice: www.unternehmertum.de/impressum
     

  • Below you will find the contact details of the data protection officer:


    Alexander Stolberg-Stolberg
    SVF Lawyers
    Oberanger 30
    80331 Munich
    E-Mail: stolberg@unternehmertum.de
    Telephone: +49 89 21025120


    It is our general policy to store personal data only for as long as is absolutely necessary for the provision of our services and products. This means that we delete personal data as soon as the reason for data processing no longer exists. In some cases, we are legally obliged to store certain data even after the original purpose has ceased to exist, for example for accounting purposes.
    If you wish to have your data deleted or revoke your consent to data processing, the data will be deleted as soon as possible and insofar as there is no obligation to store it.
    We will inform you about the specific duration of the respective data processing below, provided we have further information on this.

  • The controller collects and processes applicants' personal data for the purpose of handling the application process. This involves processing personal data that the applicant has provided to UnternehmerTUM (CV, references, questionnaires, interviews, previous activities) or career-related information that the controller has obtained from publicly available sources (e.g. professional social media networks, application websites, etc.).
    This also includes information that is publicly available and contains job-related data, such as a profile on professional social media networks.
    Processing may also be carried out electronically. This is particularly the case if an applicant submits the relevant application documents to the controller electronically, for example by email.
    If the controller concludes an employment contract with an applicant, the data transmitted will be stored for the purpose of processing the employment relationship in compliance with the statutory provisions. If the controller does not conclude an employment contract with the applicant, the application documents will be automatically deleted six months after notification of the rejection decision, provided that no other legitimate interests of the controller prevent deletion.
    Other legitimate interests in this sense include, for example, the burden of proof in proceedings under the General Equal Treatment Act (AGG).
     

    Talent pool

    The talent pool is used to match your applicant profile with relevant future positions. If there is a match, we will contact you again.
    If you expressly wish to be included in our talent pool by confirming "storage in the talent pool" in an email after rejection, we will store your data until revoked, but for a maximum of 12 months. You will be informed one month before expiry and can thus extend the storage of your data in the talent pool for a further 12 months. After expiry of the term, your data will be deleted automatically and without separate notification.
    The legal basis for the processing of your application documents is Art. 6 (1) (b) and Art. 88 (1) GDPR in conjunction with § 26 (1) (1) BDSG.
     

    Personio

    The data you enter in the application form is first transferred to our servers. The data is then transferred via an interface (API) to our personnel software Personio from Personio SE & Co. KG, Seidlstraße 3, 80335 Munich (hereinafter referred to as "Personio" - https://www.personio.de/impressum/).
    Personio's privacy policy can be found here: https://www.personio.de/datenschutzerklaerung/.
    Personio uses Amazon Web Services Europe (AWS) as its hosting provider. According to Personio, AWS data centres are certified to DIN ISO/IEC 27001 and DIN ISO/IEC 27018, among other standards, and guarantee the highest level of data protection security. In addition, all customer data is stored on servers within the European Union. According to its own statement, Personio takes additional technical and organisational measures to ensure the security of processing. Further information is available here.

    We have concluded a data processing agreement with Personio. The legal basis for data processing is Art. 6 (1) (b) GDPR.

  • In order to offer our services and contractual performance, we also process data from our customers, business partners and other third parties. This data always includes personal data. Customer data refers to all information that is processed on the basis of a contractual or pre-contractual cooperation in order to be able to provide the services offered. Customer data is therefore all the information we collect and process about our customers.
    There are many reasons why we collect and process customer data. The most important one is that we simply need various data to provide our services. Sometimes your email address is sufficient, but if you purchase a product or service, we also need data such as your name, address, bank details or contract details. We also use the data for marketing and sales optimisation so that we can improve our overall service to our customers. Another important point is our customer service, which is always very important to us. We want you to be able to contact us at any time with questions about our offers, and for this we need at least your email address.
    At this point, we can only provide a general overview of the data that is stored. This always depends on the services you purchase from us. In some cases, you only provide us with your email address so that we can contact you or answer your questions, for example. In other cases, you purchase a product or service from us, and we require significantly more information, such as your contact details, payment details, and contract details.


    Here is a list of possible data that we receive from you and process:

    • Name
    • Contact address
    • Email address
    • Telephone number
    • Date of birth
    • Payment details (invoices, bank details, payment history, etc.)
    • Contract details (term, content)
    • Usage data (websites visited, access data, etc.)
    • Metadata (IP address, device information)


    As soon as we no longer need the customer data to fulfil our contractual obligations and our purposes, and the data is also not required for possible warranty and liability obligations, we delete the corresponding customer data. This is the case, for example, when a business contract ends. After that, the limitation period is usually 3 years, although longer periods are possible in individual cases. We also comply with the statutory retention obligations. Your customer data will certainly not be passed on to third parties unless you have given your explicit consent.
     

  • A contact form is a web form that you can fill out on our website to get in touch with us easily. This usually involves sending us personal data such as your name, email address and message. This information helps us to process your enquiries in a targeted manner and to get in touch with you.
    We provide a contact form so that you can communicate with us quickly and easily. Whether you have questions about our services, feedback or other concerns, you can contact us directly using the contact form. We use the data you enter exclusively to process your request and to contact you. If further steps result from the contact, such as a quotation or a contractual relationship, we will also use the data for this purpose.
    The specific data processed depends on the information you provide in the contact form. As a rule, this includes:

    • Name
    • Email address
    • Telephone number (optional)
    • Content of the message
    • Date and time of transmission
    • IP address and technical metadata (for security and traceability)


    This information helps us to better classify and respond to your enquiry.
    We only store data from the contact form for as long as is necessary to process your request. If a business relationship is established, the corresponding storage periods apply as for customer data. In special cases (e.g. legal disputes), longer storage periods may apply.
     

  • When you register or sign up for events or individual programmes with us, personal data may be processed if you enter personal data or if data such as your IP address is collected during processing. You can read more about what we mean by the rather cumbersome term "personal data" below.
    Please only enter data that we require for registration and for which you have the consent of a third party if you are registering on behalf of a third party. If possible, use a secure password that you do not use anywhere else and an email address that you check regularly.
    Below, we provide information about the exact nature of data processing, because we want you to feel comfortable with us!
    When you register, we collect certain data from you and enable you to easily log in online later and use your account with us. An account with us has the advantage that you do not have to re-enter everything each time. This saves time and effort and ultimately prevents errors in the provision of our services.
    In short, we process personal data to enable the creation and use of an account with us. All data that you provided during registration, enter when logging in, or enter when managing your data in your account.


    During registration, we process the following types of data:

    • First name
    • Surname
    • Email address
    • Company name
    • Street + house number
    • Town
    • Postcode
    • Country


    When you register, we process the data you enter during registration, such as your user name and password, and data collected in the background, such as device information and IP addresses.
    When you use your account, we process data that you enter during account use and that is created in the course of using our services.
    We store the data entered at least for as long as the account linked to the data exists and is used by us, as long as contractual obligations between us exist and, if the contract ends, until the respective claims arising from it have become time-barred. In addition, we store your data for as long as and to the extent that we are subject to legal obligations to store it. After that, we retain booking documents related to the contract (invoices, contract documents, account statements, etc.) and other relevant business documents for the legally prescribed period (usually several years).
    Have you registered, entered data and would like to revoke the processing? No problem. The rights under the General Data Protection Regulation also apply during and after registration, login or account creation with us. Contact the data protection officer listed above to exercise your rights. If you already have an account with us, you can easily view and manage your data and texts in your account.
     

  • For the provision, management and processing of tickets as well as for the execution of our events, we use the ticketing and event platform of ECENT GmbH, Zentnerstraße 1, 80798 Munich, Germany, which provides us with the event management software ERADIANT for this purpose.

    ECENT GmbH processes the data on our behalf within the framework of a data processing agreement pursuant to Art. 28 GDPR. 

    Privacy policy: https://ecent.eu/datenschutz.
     

  • We use software on our website to evaluate the behaviour of website visitors, known as web analytics or web analysis for short. This involves collecting data that is stored, managed and processed by the respective analytics tool provider (also known as a tracking tool). The data is used to create analyses of user behaviour on our website and made available to us as the website operator. In addition, most tools offer various testing options. This allows us to test which offers or content are most popular with our visitors. To do this, we show you two different offers for a limited period of time. After the test (known as an A/B test), we know which product or content our website visitors find more interesting. For such testing procedures, as well as for other analytics procedures, user profiles can also be created and the data stored in cookies.
    We have a clear goal in mind with our website: we want to provide the best web offering on the market for our industry. To achieve this goal, we want to offer the best and most interesting products and services on the one hand, and ensure that you feel completely at home on our website on the other. With the help of web analysis tools, we can take a closer look at the behaviour of our website visitors and then improve our website for you and us accordingly.


    Exactly which data is stored depends, of course, on the analysis tools used. However, as a rule, the following information is stored: what content you view on our website, which buttons or links you click on, when you visit a page, which browser you use, which device (PC, tablet, smartphone, etc.) you use to visit the website, and which computer system you use. If you have agreed that location data may also be collected, this data may also be processed by the web analysis tool provider.


    Your IP address is also stored. According to the GDPR, IP addresses are personal data. However, your IP address is usually stored in pseudonymised form. For the purposes of testing, web analysis and web optimisation, no direct data such as your name, age, address or email address is stored. All such data, if collected, is stored in pseudonymised form. This means that you cannot be identified as an individual.
    How long the respective data is stored always depends on the provider. Some cookies only store data for a few minutes or until you leave the website, while others can store data for several years. We only process personal data for as long as is absolutely necessary for the provision of our services and products. If it is required by law, for example in the case of accounting, this storage period may also be exceeded.
    You also have the right and the option to revoke your consent to the use of cookies or third-party providers at any time, either via our cookie management tool or via other opt-out functions.

  • We use the Google Analytics 4 (GA4) analysis tracking tool from the American company Google Inc. on our website. For the European region, Google Ireland Limited (Gordon House, Barrow Street Dublin 4, Ireland) is responsible for all Google services. Google Analytics collects data about your actions on our website. By combining various technologies such as cookies, device IDs and login information, you as a user can be identified across different devices.


    Google Analytics is a tracking tool used to analyse traffic on our website. These measurements and analyses are based on a pseudonymous user identification number. GA4 uses an event-based model that collects detailed information about user interactions such as page views, clicks, scrolling and conversion events, and relies on machine-learning-based modelling to extrapolate missing data for forecasts.
    In order for Google Analytics to function properly, a tracking code is embedded in the code of our website. As soon as you leave our website, this data is sent to the Google Analytics servers and stored there. Google processes the data and we receive reports on your user behaviour, including audience, advertising, acquisition, behaviour, conversion and real-time reports.


    Google Analytics 4 also offers an event-based data model, advanced analytics features (segmentation, comparative analysis), predictive modelling and cross-platform analysis (websites and apps), provided you have consented to data processing.
    Google Analytics uses a tracking code to create a random, unique ID that is linked to your browser cookie, allowing recognition as a new or returning user. A property ID must be inserted into the tracking code so the data is stored in the corresponding property.


    According to Google, IP addresses are not logged or stored in Google Analytics 4. Google uses IP address data only to derive location data and deletes it immediately afterwards; all IP addresses collected from users in the EU are deleted before the data is stored in a data centre or on a server.


    Google has servers located around the world (see datacenters.google). The retention period for data depends on the properties used. Google Analytics offers four options for controlling the storage period: 2 months, 14 months (default), 26 months, or deletion only when done manually. There is also the option of resetting the retention period each time you revisit the site within the chosen period.


    Under EU data protection law, you have the right to obtain information about your data, to update it, to delete it or to restrict its use. You can prevent Google Analytics 4 from using your data via the browser add-on at https://tools.google.com/dlpage/gaoptout?hl=de.


    Google uses standard contractual clauses (Art. 46 (2) and (3) GDPR) and the EU-US Data Privacy Framework to ensure your data complies with European data protection standards even when transferred to and stored in the USA. See here.
     

  • We have implemented IP address anonymisation from Google Analytics on this website. This function was developed by Google so that this website can comply with the applicable data protection regulations and recommendations of local data protection authorities if they prohibit the storage of the full IP address. The anonymisation or masking of the IP address takes place as soon as the IP addresses arrive in the Google Analytics data collection network and before the data is stored or processed. 

    More information: support.google.com.

  • We use Google Maps from Google Inc. on our website. For Europe, Google Ireland Limited is responsible for all Google services. Google Maps allows us to show you locations more effectively, tailoring our service to your needs; when you use it, data is transferred to and stored on Google's servers.


    In order for Google Maps to offer its service in full, the company collects and stores data from you, including the search terms you enter, your IP address, your latitude and longitude coordinates and, if you use the route planner, the start address entered. Google sets at least one cookie (name: NID) in your browser, primarily to optimise its own services and provide personalised advertising.


    Google's servers are located in data centres around the world, mostly in America (see https://datacenters.google/). Google anonymises information in server logs after 9 or 18 months by deleting part of the IP address and cookie information, and with the automatic deletion feature introduced in 2019, location and activity data is stored for either 3 or 18 months, depending on your choice, and then deleted. You can manage or delete cookies in your browser settings at any time.
     

  • Like many other websites, we use the services of the newsletter company MailChimp, operated by Intuit Inc., 2700 Coast Ave, Mountain View, California 94043, USA.

     MailChimp is a cloud-based (SaaS) newsletter management service that lets us run individual campaigns, regular campaigns, autoresponders, A/B tests, RSS campaigns and follow-up campaigns.


    When you subscribe to our newsletter via our website, you confirm your membership in a MailChimp email list by email. MailChimp stores the date of registration and your IP address, as well as your email address, name, physical address and demographic information such as language or location.


    MailChimp also shares some data with third-party advertising partners to better understand customer interests, and uses web beacons in HTML emails to determine whether an email has been received, opened and whether links have been clicked.
    If you access a MailChimp website via a link in our newsletter, MailChimp may set its own cookies on its website; see MailChimp's Cookie Statement at https://mailchimp.com/legal/cookies/.


    Data generally remains stored on MailChimp's servers until you request deletion. You can withdraw your consent to receive our newsletter at any time via the unsubscribe link at the bottom of each email; once you unsubscribe, your data will be deleted from MailChimp.


    MailChimp uses standard contractual clauses (Art. 46 GDPR) and participates in the EU-US Data Privacy Framework. See mailchimp.com/legal/data-processing-addendum, mailchimp.com/legal/cookies/ and www.intuit.com/privacy/statement/

    We have concluded a Data Processing Agreement with MailChimp under Art. 28 GDPR: mailchimp.com/de/legal/data-processing-addendum/.
     

  • In addition to our website, we are also active on various social media platforms. User data may be processed so that we can specifically target users who are interested in us via social networks. Elements of a social media platform may also be embedded directly into our website.

    The data stored and processed through your use of a social media channel is primarily used to perform web analytics and develop more accurate, personalised marketing and advertising strategies. In most cases, cookies are set in your browser for this purpose.

    We generally assume that we remain responsible for data protection, even when using the services of a social media platform. However, the European Court of Justice has ruled that in certain cases the operator of the social media platform may be jointly responsible with us within the meaning of Art. 26 GDPR. If this is the case, we point this out separately.

    Please note that when using social media platforms or our built-in elements, your data may also be processed outside the EU, as many social media channels are American companies. Exactly which data is stored and processed depends on the respective provider, but usually includes telephone numbers, email addresses, contact-form data, user data (button clicks, likes, follows), visit timestamps, device information and your IP address, mostly stored in cookies.

    We only process personal data for as long as is absolutely necessary for the provision of our services and products, except where legally required storage periods (e.g. accounting) apply. You have the right and option to revoke your consent to the use of cookies or third-party providers such as embedded social media elements at any time, via our cookie management tool or other opt-out functions.
     

    Facebook

    We use selected Facebook tools on our website. Facebook is a social media network owned by Meta Platforms Inc. or, for the European region, Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.
    If data is collected and forwarded via our embedded Facebook elements or via our Facebook page (fan page), both we and Facebook Ireland Ltd. are responsible for this, as set out in a publicly available agreement at www.facebook.com/legal/controller_addendum

    Facebook is solely responsible for further processing of this data and for the data security of Facebook products.
    Facebook Business Tools used on our site may include:

    • Facebook pixels
    • Social plug-ins (such as the "Like" or "Share" button)
    • Facebook Login
    • Account Kit
    • APIs (application programming interfaces)
    • SDKs
    • Platform integrations
    • Plugins
    • Codes
    • Specifications
    • Documentation
    • Technologies and services


    Facebook refers to data about your behaviour on our website as "event data", used for measurement, analysis and "campaign reports". Depending on the tools used, customer data such as name, address, telephone number and IP address may be sent to Facebook, undergoing a hashing process before transmission. Event data can be linked to contact details to enable personalised advertising; after this matching process, Facebook deletes the contact details again.
    Facebook generally stores data until it is no longer needed for its own services; customer data is deleted within 48 hours after it has been matched with the user's own data. You have the right to access, correct, transfer and delete your data; complete deletion only occurs if you delete your Facebook account entirely.

    Facebook and Meta Platforms are active participants in the EU-US Data Privacy Framework and also use standard contractual clauses (Art. 46 (2) and (3) GDPR). 

    Data processing terms: https://www.facebook.com/legal/terms/dataprocessing
    Privacy policy: https://www.facebook.com/privacy/policy/
    General cookie information: https://www.facebook.com/policies/cookies.

     

    Instagram

    We have integrated Instagram features into our website. Instagram is a social media platform owned by Instagram LLC, 1601 Willow Rd, Menlo Park CA 94025, USA, and has been a subsidiary of Meta Platforms Inc. since 2012. 

    Instagram uses the same systems and technologies as Facebook, so your data is processed across Facebook companies.


    When you visit a page on our website with an embedded Instagram feature, your browser automatically connects to Instagram's servers and data is sent, stored and processed, regardless of whether you have an Instagram account. Customer data (name, address, phone number, IP address) is hashed before transmission; "event data" about your user behaviour may also be combined with contact data.


    If you have an Instagram account or have visited instagram.com, a cookie will typically already be set; after 90 days at the latest (following reconciliation), this data is deleted or anonymised. Instagram shares information with Facebook companies, external partners and connected users worldwide, mostly on servers in the United States.


    You have the right to access, transfer, correct and delete your data via the Instagram settings; complete deletion requires permanently deleting your Instagram account. Instagram and Meta Platforms participate in the EU-US Data Privacy Framework and use standard contractual clauses (Art. 46 (2) and (3) GDPR). 

    Privacy policy: https://privacycenter.instagram.com/policy/.

    LinkedIn

    We use social plug-ins from the social media network LinkedIn, LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA. For the European Economic Area and Switzerland, LinkedIn Ireland Unlimited Company, Wilton Place, Dublin, is responsible for data processing.


    LinkedIn does not store personal data simply by integrating the social plug-ins ("passive impressions"); however, if you click on a plug-in, e.g. to share our content, the platform stores personal data as "active impressions", regardless of whether you have a LinkedIn account. Your browser establishes a direct connection to LinkedIn's servers, allowing the company to log your IP address, login data, device information and provider information; location may also be determined with your consent.


    LinkedIn retains your personal data for as long as it deems necessary, but deletes it (generally within 30 days) when you delete your account, subject to legally required retention. You have the right to access and delete your personal data via your LinkedIn account settings.


    LinkedIn is an active participant in the EU-US Data Privacy Framework and uses standard contractual clauses (Art. 46 (2) and (3) GDPR). 

    More information: https://de.linkedin.com/legal/l/dpa, https://www.linkedin.com/legal/l/eu-sccs

    and privacy policy at https://www.linkedin.com/legal/privacy-policy.
     

  • We also use the Make automation platform. 

    The service provider is the American company Celonis Inc., One World Trade Centre, 87th Floor, New York, NY, 10007, USA.


    Make and Celonis process your data in the USA, among other places. 

    Celonis is an active participant in the EU-US Data Privacy Framework (commission.europa.eu/document). 

    More information: www.make.com/en/privacy-notice.
     

  • We use the integration service provider n8n.io, a service provided by n8n GmbH, Borsigstr. 27, 10115 Berlin ("n8n"). 

    We use n8n to link various services and applications and to create automated processes. n8n processes data that you enter via our website, such as your name, email address or other information you provide to us.


    Data processing by n8n takes place on our own servers or on the servers of third-party providers with whom we collaborate. We have concluded a contract for order processing (AVV) for the use of this service, ensuring the provider processes personal data only in accordance with our instructions and in compliance with the GDPR. 

    More information: n8n.io.
     

  • We use Salesforce, a customer relationship management (CRM) service, on our website. The service provider is the American company Salesforce, Inc., One Market Street, Suite 300, San Francisco, CA 94105, USA.


    Salesforce processes your data in the USA, among other places, and is an active participant in the EU-US Data Privacy Framework (commission.europa.eu/document), in addition to using standard contractual clauses (Art. 46 (2) and (3) GDPR, see eur-lex.europa.eu/).


    Data Processing Addendum: https://www.salesforce.com/content/dam/web/en_us/www/documents/legal/Agreements/data-processing-addendum.pdf

    Privacy policy: 

    www.salesforce.com/de/company/privacy/

    We have concluded a Data Processing Agreement with Salesforce under Art. 28 GDPR.
     

  • We also use the cloud services of Salesforce Service Cloud. The service provider is the American company Salesforce Inc., Salesforce Tower, 415 Mission Street, San Francisco, CA 94105, USA.


    Salesforce processes your data in the USA, among other places, and is an active participant in the EU-US Data Privacy Framework, in addition to using standard contractual clauses (Art. 46 (2) and (3) GDPR). 

    Data Processing Addendum: https://www.salesforce.com/content/dam/web/en_us/www/documents/legal/Agreements/data-processing-addendum.pdf

    Privacy policy: https://www.salesforce.com/de/company/privacy/.
     

  • We use Typeform, a survey software, for individual registration and application processes. The service provider is the Spanish company Typeform, 163 Carrer de Bac de Roda, Barcelona, Spain. 

    Privacy policy: https://admin.typeform.com/to/dwk6gt.

  • We also use the services of Tally, Tally BV, August Van Lokerenstraat 71, 9050 Ghent, Belgium, to create and provide surveys and forms (e.g. for speaker placement).


    Tally processes the data entered via the surveys and forms exclusively on our behalf and acts as a processor within the meaning of Art. 28 GDPR. The data is stored on servers within the European Union and is encrypted both during transmission and at rest. Tally does not use cookies for tracking and does not share personal data with third parties.


    Further information: https://tally.so/help/privacy-policy and https://tally.so/help/gdpr.
     

  • We also use the productivity tool Notion. The service provider is the American company Notion Labs Inc., 2300 Harrison Street, San Francisco, CA 94110, USA.


    Notion processes your data in the USA, among other places, and is an active participant in the EU-US Data Privacy Framework, in addition to using standard contractual clauses (Art. 46 (2) and (3) GDPR). 

    More information: https://www.notion.so/Data-Processing-Addendum-361b540101274b1fa7e16b90402b0d99 

    and privacy policy: https://www.notion.so/Privacy-Policy-3468d120cf614d4c9014c09f6adc9091.


    Notion AI: Feature overview, including Custom Agents (as of December 2025)
    This section provides a concise overview of the key features of Notion AI, including the newer Custom Agents, intended for data protection officers and taking into account current technical and organisational aspects.

    Overview: what is Notion AI?
    Notion AI is an integrated, AI-based assistant that operates directly within the Notion workspace, aiming to automate work processes, make information easier to find and streamline routine tasks without requiring users to switch tools. Notion AI uses only the data to which the respective user has access and respects all permissions within the workspace.

    Core features of Notion AI
    Chat: a built-in assistant enabling interaction with advanced language models (such as Claude, GPT-5 or Gemini 3 Pro) for general knowledge questions, strategy discussions or task planning; conversations can be converted into Notion pages.

    Search (including Enterprise Search): AI-powered search across the entire workspace, connected apps (e.g. Slack, Google Drive) and, if desired, the web, restrictable or expandable to specific sources; Enterprise Search is particularly suited to process-, project- and fact-based queries and can incorporate external data sources.

    Analysis: AI-powered evaluation of pages, Slack threads, PDFs, images and database content, recognising patterns and extracting relevant information for summaries or deeper insights.

    Notes & meeting transcription: real-time meeting transcription, identification of key points and action items, and automatic creation of structured, searchable notes that can generate follow-up emails, to-do lists or project updates.

    Content generation and editing: assistance with writing, rewriting, summarising and translating texts, plus automatic task extraction from meeting notes into to-do lists.

    Research Mode: consolidates, analyses and processes information from multiple internal and external sources into comprehensive reports for market analyses, competitive comparisons or strategic evaluations.

    Integration with third-party applications: Notion AI can be connected to external tools (e.g. Slack, Google Drive, SharePoint, MS Teams, Salesforce — some in beta) to incorporate information from these systems into search and analysis.

    Notion Agents (personal agents)
    Notion 3.0 introduced "Agents" — a personal, AI-powered assistant that can perform tasks independently within the scope of the user's individual access permissions. An agent can execute complex, multi-step tasks (e.g. create project plans, assign tasks, update databases), perform actions at scale (e.g. updating hundreds of pages at once), use the same permissions and access as the respective user, be customised via an "Agent Instructions" page, and remains visible and controllable only by that user.

    Notion Custom Agents
    Custom Agents are an advanced version of the agent feature, currently in the rollout/alpha phase, offering:
     

    • Automation based on a schedule or trigger — Custom Agents can be scheduled or triggered by specific events (e.g. a new Slack message, a database update) and perform tasks autonomously, even outside business hours.
    • Workflow optimisation — automating recurring tasks such as tool status checks, incident management, or the collection and distribution of status reports.
    • Cross-team usage — Custom Agents can be shared within the workspace and used collaboratively by multiple teams, e.g. for IT incident management or automated notifications.
    • Slack integration — Custom Agents can be connected to Slack to process requests directly from Slack (e.g. "Is Tool X currently available?") and post results in the corresponding Slack thread.
    • Database and API integration — accessing Notion databases, retrieving status information from external APIs, and transparently logging all actions and status changes.


    Example: a Custom Agent regularly checks the availability of enterprise applications, reads status pages, updates the internal database, and automatically notifies the IT team in case of outages, including full logging of all operations.


    Data protection and access rights (brief overview)
    Data processing: Notion AI processes data exclusively within the scope of the user's permissions and can only access content visible to the user. There is no way to specifically exclude individual pages from AI processing, but access can be effectively controlled through Teamspace and page permissions.

    Data transfer and storage: Standard Contractual Clauses (SCCs) are in place for the use of Notion AI to comply with GDPR requirements regarding data transfers to third countries (e.g. the USA). Data is protected through technical and organisational measures, and subcontractors are not permitted to use the data for their own purposes or for AI training.

    Data deletion: personal data is stored only for as long as necessary for the respective purpose and is subsequently deleted or blocked in accordance with legal requirements.

    Audit and compliance: additional features such as audit logs, Data Loss Prevention (DLP), SIEM integration and content verification are available to enterprise customers.


    Summary
    Notion AI offers a wide range of features for text generation, analysis, search, meeting transcription and automation. The new agents — particularly the Custom Agents — enable extensive workflow automation, whereby all actions are performed within the scope of individual user permissions and in compliance with data protection requirements. Management and control are handled through existing Notion permission and compliance mechanisms.
     

  • We use the application programming interface (API) of the US company OpenAI for our website. The service provider is OpenAI OpCo, LLC, 3180 18th Street, San Francisco, CA, USA.


    We use OpenAI services on our website to provide you with a better and more interactive user experience, for example enabling you to interact directly with our website and ask questions. We also use OpenAI products to develop our own solutions and applications for our company.


    The data stored always depends on your input and the specific AI tool used, and may include chat content, question types, device/browser/OS information, IP address, audio recordings and image inputs. Generally, unless you enter personal data, only your IP address is processed and stored; all other data entered is anonymised and stored in encrypted form.


    Data entered generally remains stored at OpenAI because the tools use it for training; however, there is a function that lets us deactivate chat history so data is not used for training, in which case it is stored for only 30 days. If you decide to enter personal data such as your email address or name, this may be stored permanently, but only with your prior consent.


    The legal basis for personal data processing by OpenAI products is your consent (Art. 6 (1) (a) GDPR); in addition, we have a legitimate interest (Art. 6 (1) (f) GDPR) in optimising our service. OpenAI processes data in the USA, among other places, using standard contractual clauses (Art. 46 (2) and (3) GDPR) based on Commission Implementing Decision (EU) 2021/914. 

    Privacy policy: https://openai.com/policies/privacy-policy.
     

  • We also use videos from Vimeo on our website. The video portal is operated by Vimeo LLC, 555 West 18th Street, New York, New York 10011, USA.


    When you visit a page with an embedded Vimeo video, your browser connects to Vimeo's servers and data is transferred, collected, stored and processed, regardless of whether you have a Vimeo account. This includes your IP address, browser type, operating system, basic device information and web activities such as session duration, bounce rate and button clicks. If you are logged in as a registered Vimeo member, more data can typically be collected and linked directly to your account.


    Vimeo's data may be stored and processed on servers in the USA and is retained until the company no longer has an economic reason for storing it, after which it is deleted or anonymised. You can manage cookies in your browser settings at any time.
    Vimeo is an active participant... Vimeo uses standard contractual clauses (Art. 46 (2) and (3) GDPR) as the basis for data transfers to third countries. 

    More information: https://vimeo.com/privacy#international_data_transfers_and_certain_user_rights
    cookie policy at https://vimeo.com/cookie_policy, and privacy policy at https://vimeo.com/privacy

  • We have embedded YouTube videos on our website. YouTube has been a subsidiary of Google since 2006 and is operated by YouTube, LLC, 901 Cherry Ave., San Bruno, CA 94066, USA. Google Ireland Limited is responsible for all data processing in the European Union.


    When you visit a page with an embedded YouTube video, your browser automatically connects to the YouTube or Google servers, and various data is transferred depending on your settings. YouTube sets at least one cookie storing your IP address and our URL; if logged into a YouTube account, interactions may be assigned to your profile, including session duration, bounce rate, approximate location, browser type, screen resolution and internet service provider.


    If you are not logged into a Google or YouTube account, Google stores data with a unique identifier linked to your device, browser or app, for example to retain your preferred language setting.


    Data received and processed from you is stored on Google's servers, most of which are located in America (see https://datacenters.google/). 

    Google stores collected data for varying lengths of time; with the automatic deletion feature introduced in 2019, location and activity data is stored for either 3 or 18 months, depending on your choice, and then deleted. You can manage or delete cookies in your browser settings at any time.
     

  • We use software programmes that enable us to hold video conferences, online meetings, webinars, display sharing and/or streaming, allowing us to communicate quickly and easily with customers, business partners, clients and employees via the internet. We pay attention to the applicable legal framework when selecting a service provider.
    Third-party providers can process data as soon as you interact with the software, using your data and metadata to make the tool more secure, improve the service, and in some cases for their own marketing purposes.


    Exactly which data is stored depends on the solutions used, but most providers store your name, address, contact details, email address, telephone number and IP address, plus device and usage information, and any data shared within the video conference (photos, videos, texts).


    We only process personal data for as long as is absolutely necessary for the provision of our services and products. You always have the right to access, correct and delete your personal data; contact details for the responsible party can be found in the specific privacy policy of the tool used or on the provider's website. You can manage cookies used by providers in your browser at any time.
     

    Google Meet

    We use Google Meet from Google Inc. on our website. For the European region, Google Ireland Limited is responsible for all Google services.
    Google processes your data in the USA, among other places, and is an active participant in the EU-US Data Privacy Framework, in addition to using standard contractual clauses (Art. 46 (2) and (3) GDPR). 

    We have concluded a Data Processing Agreement with Google under Art. 28 GDPR: https://workspace.google.com/terms/dpa_terms.html

    Privacy policy: https://policies.google.com/privacy.
     

    Microsoft Teams

    We use Microsoft Teams, a service for online meetings and video conferencing, on our website. The service provider is the American company Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA.


    Microsoft processes your data in the USA, among other places, and is an active participant in the EU-US Data Privacy Framework, in addition to using standard contractual clauses (Art. 46 (2) and (3) GDPR). 

    More information: https://learn.microsoft.com/en-us/compliance/regulatory/offering-eu-model-clauses 

    and privacy policy at https://privacy.microsoft.com/de-de/privacystatement.
     

    Slack

    We use Slack, a streaming and communication platform. The service provider is the American company Slack Technologies Limited, with its Irish headquarters at One Park Place, Upper Hatch Street, Dublin 2, Ireland.


    Slack processes data in the USA, among other places, using standard contractual clauses approved by the EU Commission (Art. 46 (2) and (3) GDPR). 

    Privacy policy: https://slack.com/intl/de-at/legal. 

    We have concluded a Data Processing Agreement with Slack under Art. 28 GDPR: https://slack.com/intl/de-de/terms-of-service/data-processing.
     

    Zoom

    We use the Zoom video conferencing tool from the American software company Zoom Video Communications, headquartered at 55 Almaden Boulevard, 6th Floor, San Jose, CA 95113, USA.


    When you use Zoom, both data you consciously provide (name, telephone number, email address, uploaded content such as files or chat logs) and data automatically transmitted (technical data such as your IP address, MAC address, device IDs, device type, operating system, client, camera/microphone/speaker type, approximate location, and metadata such as meeting duration and chat status) are collected and stored.


    Zoom states that it does not use advertising cookies or tracking technologies for its services (only on its own marketing websites) and does not sell personal data or use it for advertising purposes. Zoom stores collected data for as long as necessary to provide its services, generally on American servers, though data may be sent to different data centres worldwide.


    You always have the right to have your personal data deleted; instructions are available at https://support.zoom.us/hc/en-us/articles/201363243-How-Do-I-Delete-Terminate-My-Account

    Zoom is an active participant in the EU-US Data Privacy Framework and uses standard contractual clauses (Art. 46 (2) and (3) GDPR). 

    Privacy policy: https://explore.zoom.us/de/privacy/

    We have concluded a Data Processing Agreement with Zoom under Art. 28 GDPR: https://sdpc.a4l.org/agreements/2023-02-27_2547_1974_signed_agreement_file.pdf.
     

  • In individual cases, we use the DocuSign transaction management platform. The service provider is the American company DocuSign, Inc., 221 Main Street Suite 1000, San Francisco, CA 94105, USA.

    DocuSign processes your data in the USA, among other places, using standard contractual clauses (Art. 46 (2) and (3) GDPR). 

    More information: https://www.docusign.com/legal/terms-and-conditions/schedule-docusign-gen-negotiate/attachment-data-protection/ 

    and privacy policy at https://www.docusign.com/privacy/

    We have concluded a Data Processing Agreement with DocuSign under Art. 28 GDPR: https://www.docusign.com/legal/terms-and-conditions/schedule-docusign-signature/attachment-data-protection/.
     

  • We also use Google Docs, an online document editor, for our business. The service provider is the American company Google Inc.; for the European region, Google Ireland Limited is responsible for all Google services.


    Google processes your data in the USA, among other places, and is an active participant in the EU-US Data Privacy Framework, in addition to using standard contractual clauses (Art. 46 (2) and (3) GDPR). 

    Privacy policy: https://policies.google.com/privacy.
     

  • We also use Google Workspace productivity and collaboration tools for our business. The service provider is the American company Google Inc.; for the European region, Google Ireland Limited is responsible for all Google services.


    Google processes your data in the USA, among other places, and is an active participant in the EU-US Data Privacy Framework, in addition to using standard contractual clauses (Art. 46 (2) and (3) GDPR). 

    Privacy policy: https://policies.google.com/privacy.
     

  • The controller processes and stores the personal data of the data subject only for the period necessary to achieve the purpose of storage or as provided for by the European directive and regulation legislator or another legislator in laws or regulations to which the controller is subject.


    If the storage purpose no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, the personal data will be routinely blocked or deleted in accordance with the statutory provisions.
     

  • In the following, we provide you with transparent information about the legal principles and regulations, i.e. the legal basis of the General Data Protection Regulation, which enable us to process personal data. 

    With regard to EU law, we refer to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (https://eur-lex.europa.eu/legal-content/DE/ALL/?uri=celex%3A32016R0679).


    We only process your data if at least one of the following conditions applies:

    • Consent (Art. 6 (1) (a) GDPR): You have given us your consent to process data for a specific purpose, for example the storage of your data entered in a contact form.
    • Contract (Art. 6 (1) (b) GDPR): We process your data in order to fulfil a contract or pre-contractual obligations with you.
    • Legal obligation (Art. 6 (1) (c) GDPR): We process your data if we are subject to a legal obligation, e.g. the obligation to retain invoices for accounting purposes.
    •  Legitimate interests (Art. 6 (1) (f) GDPR): In the case of legitimate interests that do not restrict your fundamental rights, we reserve the right to process personal data, e.g. to operate our website securely and economically.


    Other conditions, such as the performance of tasks carried out in the public interest and the exercise of official authority, as well as the protection of vital interests, do not generally apply to us. If such a legal basis should nevertheless be relevant, it will be indicated accordingly.
     

  • If we process data in a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)) or if processing takes place in connection with the use of third-party services or the disclosure or transfer of data to other persons, bodies or companies, this will only be done in accordance with the legal requirements.


    Subject to express consent or contractually or legally required transfer, we only process or have the data processed in third countries with a recognised level of data protection, contractual obligations through so-called standard protection clauses of the EU Commission, in the presence of certifications or binding internal data protection regulations (Art. 44 to 49 GDPR). 

    More information: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection_de.
     

  • We use HTTPS (Hypertext Transfer Protocol Secure) to transmit data securely over the internet. This means that the entire transfer of all data from your browser to our web server is secure.


    By using TLS (Transport Layer Security), an encryption protocol for secure data transmission on the internet, we can ensure the protection of confidential data, complying with data protection through technology design (Art. 25 (1) GDPR).
     

  • In accordance with Articles 13 and 14 of the GDPR, we hereby inform you of the following rights to which you are entitled in order to ensure fair and transparent data processing. You have the right to:

    • request information about the categories of data processed, the purposes of processing, any recipients of the data, and the planned storage period (Art. 15 GDPR);
    • request the rectification or completion of inaccurate or incomplete data (Art. 16 GDPR);
    • withdraw your consent at any time with effect for the future (Art. 7 (3) GDPR);
    • object to data processing that is to be carried out on the basis of a legitimate interest for reasons arising from your particular situation (Art. 21 (1) GDPR);
    • request the erasure of data in certain cases within the scope of Art. 17 GDPR — in particular if the data is no longer necessary for the intended purpose or is being processed unlawfully, or if you have revoked your consent or lodged an objection as above;
    • request the restriction of data under certain conditions, insofar as erasure is not possible or the obligation to erase is disputed (Art. 18 GDPR);
    • data portability, i.e. you can receive the data you have provided to us in a commonly used machine-readable format such as CSV and, if necessary, transfer it to others (Art. 20 GDPR);
    • lodge a complaint with the competent supervisory authority regarding data processing.
       
  • The supervisory authority responsible for the controller is:


    Bavarian State Office for Data Protection Supervision
    Promenade 18
    91522 Ansbach
    Germany
    Telephone: +49 (0) 981 180093-0
    Fax: +49 (0) 981 180093-800


    E-Mail: poststelle@lda.bayern.de