Privacy Notice
Contents
1. Introduction and selected terminology
2. Controller and Data Protection Officer
3. Compact overview
4. Legal bases for the processing of personal data
5. Your rights under the General Data Protection Regulation
6. External hosting
7. Automatic server log files
8. Use of cookies
9. Zoho CRM system
10. Data processing in connection with communication and contact
11. Information for applicants
12. Direct marketing
13. Audio and video conferences with MS Teams
14. Jira ticket system
15. Analytics tools
16. PeakAvenue social media presences
17. Supplementary privacy information for our business partners
18. Last updated
1. Introduction and selected terminology
This Privacy Notice informs visitors and users of our website about online data processing operations in which personal data is processed. It also provides information on our processing operations that do not primarily take place online.
GDPR stands for the European General Data Protection Regulation.
BDSG stands for the German Federal Data Protection Act in its current version.
Personal data means any individual information that allows conclusions to be drawn about a natural person (definition: Art. 4(1) GDPR). This includes, for example, names, email addresses, telephone numbers, but also data such as IP addresses or customer numbers.
The processing of personal data includes any operation, such as collecting, storing, transmitting, archiving or deleting personal data (definition: Art. 4(2) GDPR).
The data subject within the meaning of data protection law is any natural person whose personal data is processed.
Further definitions can be found in the General Data Protection Regulation, primarily in Art. 4 GDPR (definitions).
2. Controller and Data Protection Officer
Controller
APIS Informationstechnologien GmbH
a PeakAvenue company
Gewerbepark A 13
D-93086 Woerth/Donau
Phone: +49-(0)9482-94 15-0
Fax: +49-(0)9482-94 15-25
Joint controllership
APIS Informationstechnologien GmbH is part of the PeakAvenue group of companies. Systems and synergies are used within the group of companies. The companies of the PeakAvenue Group have entered into an agreement on the processing of personal data under joint controllership (Art. 26 GDPR). Information on the corporate group is available at https://www.peakavenue.de.
Data Protection Officer of the PeakAvenue group of companies
DSB External Data Protection Officer Stuttgart
Fabian Henkel
Certified Data Protection Officer
Certified Information Security Officer
Email: info@externer-datenschutzbeauftragter-stuttgart.de
3. Compact overview
The following content provides a brief overview of the processing of personal data. More detailed information can be found in the respective sections set out in detail below.
Security on our website
Our website uses a TLS certificate to encrypt data transmission processes. This applies, for example, when you send us a message via a form. However, as a precaution, we point out that one hundred percent security in electronic data processing is not possible and that a residual risk always remains.
Data that you transmit to us
On this website, we process data that you enter yourself, for example in a form. In this case, the purpose of the processing follows from the type of form and from this Privacy Notice. If, for example, you send us a message by email or contact us in another way, we process your data in accordance with the purpose of the contact.
Automatic server log files
Our server also automatically records all access and therefore IP addresses (log files). This serves to defend against attacks, analyse access figures and ensure smooth operation.
Use of cookies
Cookies help us provide various services. More detailed information can be found in this Privacy Notice.
Analytics and tracking tools
In addition to pure server log files, which also provide us with information on page views, we use analytics tools. These tools give us detailed insights into the content visited on our site, the user flow and, for example, the country from which access took place. In order for such services to function, cookies must be set on the website visitor's device or scripts must be executed.
Plugins and content delivery networks
We sometimes use plugins and content delivery networks; well-known examples of such services include the video service YouTube or the map service Google Maps. If such services are integrated via a website, access data is transmitted to the services. As a rule, this includes your IP address and other metadata, such as the time and date of access. As a rule, the services are provided by setting cookies.
Newsletter / direct marketing
a) Direct marketing to existing customers based on legitimate interests
We reserve the right to send newsletters to our customers on the basis of Section 7(3) UWG in conjunction with Art. 6(1)(f) GDPR. You may of course object to receiving direct marketing information at any time.
b) Direct marketing based on your consent
If you give us your consent, we will send you newsletters until you withdraw your consent. You may withdraw your consent from us at any time with effect for the future.
Other data recipients
Disclosure within the group of companies
Within the PeakAvenue Group, we process data on shared systems and for shared purposes. This is done on the basis of joint controllership within the framework of legitimate interests.
Contracting of Data Processors
We have contract suppliers that act as Data processors - including within the PeakAvenue group of companies - in accordance with Art. 28 GDPR. Examples are IT service providers, web hosting providers, email hosting providers or SaaS providers. These suppliers process personal data for us on the basis of our instructions following Art. 28 GDPR.
Use of specialist third-party services
Where necessary, for example for contract performance, we disclose your data to banks, shipping service providers, our tax advisor or lawyers.
Legal obligations
We are subject to legal obligations on the basis of which we must transmit data to authorities. For example, under commercial or tax law, we transmit certain data to tax authorities in this context.
Investigation of criminal offences
If necessary for the investigation of a criminal offence, we disclose data to law enforcement authorities.
General information on retention periods for personal data
We process the data for as long as this is necessary for the respective purpose. Where required, we process your personal data for the duration of our business relationship, which also includes the initiation and performance of a contract. In addition, we are obliged to comply with statutory retention obligations. If the data processing is based on your consent, we delete your data after you withdraw your consent.
Transfer of personal data to a third country
We try to have all service providers and services provided by providers within the European Union wherever possible. A transfer to a third country may be considered if you have given us your consent and/or we have concluded a data processing agreement pursuant to Art. 28 GDPR, taking into account appropriate safeguards. In individual cases, we may use plugins or tools that are hosted in third countries but that we use on the basis of our legitimate interests. Where applicable, we will point this out in such cases.
Obligation to provide personal data
You are free to decide whether to provide personal data on our website for specific purposes. For the execution of legal transactions, the provision of personal data is contractually required.
4. Legal bases for the processing of personal data
The legal bases for the processing of personal data are exceptions that permit the processing of personal data. The main legal bases are set out in particular in Art. 6 GDPR. The legal bases on which we process personal data are described in the individual processing operations in this Privacy Notice.
Consent given (Art. 6(1)(a) GDPR)
Consent is one of these legal bases and requires that the consenting person gives it in an informed manner and on a voluntary basis. Consent based on Art. 6(1)(a) GDPR can generally be withdrawn at any time without giving reasons.
Contract-related data processing (Art. 6(1)(b) GDPR)
The processing of personal data for the initiation or performance of contracts is also a legal basis and is defined in Art. 6(1)(b) GDPR.
Legal obligation (Art. 6(1)(c) GDPR)
The exception of data processing due to a legal obligation is found in Art. 6(1)(c) GDPR; for example, we are obliged to comply with certain retention periods under commercial and tax law.
Legitimate interests (Art. 6(1)(f) GDPR)
The processing of personal data on the basis of a balancing of interests under Art. 6(1)(f) GDPR permits processing after careful balancing of financial or legal interests against the legitimate interests of the data subject.
5. Your rights under the General Data Protection Regulation
Every natural person has certain rights, which are defined in particular in Articles 15 to 21 and 77 GDPR. In principle, you have the following rights, which you may assert against us.
Right to withdraw consent given under Art. 7 GDPR
You may withdraw consent given to us at any time without giving reasons with effect for the future.
Right of access under Art. 15 GDPR (restrictions under Section 34 BDSG possible)
You have the right at any time to request information about the data processed about you and the purposes of the processing.
Right to rectification under Art. 16 GDPR
If you find that we process incorrect or incomplete data about you, you have the right to rectification.
Right to erasure under Art. 17 GDPR (restrictions under Section 35 BDSG possible)
You have the right at any time to request the erasure of your personal data that we process about you. If complete erasure is not possible, for example because we must comply with statutory retention obligations or can assert legitimate interests for another reason, we will restrict your data until these reasons cease to apply.
Right to restriction of processing under Art. 18 GDPR
You have the right to request the restriction of the processing of your personal data. You may contact us at any time at the address stated in the legal notice. The right to restriction of processing exists in the following cases:
If you dispute the accuracy of your personal data stored by us, we usually need time to verify this. For the duration of the review, you have the right to request restriction of the processing of your personal data.
If the processing of your personal data was/is unlawful, you may request restriction of data processing instead of erasure.
If we no longer need your personal data but you need it to exercise, defend or assert legal claims, you have the right to request restriction of the processing of your personal data instead of erasure.
If you have objected pursuant to Art. 21(1) GDPR, a balancing of your interests and our interests must be carried out. As long as it has not yet been determined whose interests prevail, you have the right to request restriction of the processing of your personal data.
If you have restricted the processing of your personal data, this data may - apart from its storage - only be processed with your consent or for the establishment, exercise or defence of legal claims, for the protection of the rights of another natural or legal person, or for reasons of important public interest of the European Union or of a Member State.
Right to data portability under Art. 20 GDPR
You have the right to have data that we process automatically on the basis of your consent or in fulfilment of a contract handed over to you or to a third party in a commonly used, machine-readable format. If you request direct transfer of the data to another controller, this will only be done where technically feasible.
Right to object to certain processing operations and direct marketing under Art. 21 GDPR
If data processing is carried out on the basis of Art. 6(1)(e) or (f) GDPR, you have the right at any time, on grounds relating to your particular situation, to object to the processing of your personal data; this also applies to profiling based on these provisions. The respective legal basis on which processing is based can be found in this Privacy Notice. If you object, we will no longer process your affected personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims (objection under Art. 21(1) GDPR).
If your personal data is processed for the purpose of direct marketing, you have the right at any time to object to the processing of personal data concerning you for the purpose of such marketing; this also applies to profiling insofar as it is related to such direct marketing. If you object, your personal data will subsequently no longer be used for direct marketing purposes (objection under Art. 21(2) GDPR).
Right to lodge a complaint with a supervisory authority under Art. 77 GDPR in conjunction with Section 19 BDSG
In the event of infringements of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work or the place of the alleged infringement. The right to lodge a complaint exists without prejudice to any other administrative or judicial remedies.
6. External hosting
This website is hosted externally. The personal data collected on this website is stored on the server(s) of the hoster(s). This may include, in particular, IP addresses, contact requests, meta and communication data, contract data, contact details, names, website access data and other data generated via a website.
External hosting is carried out for the purpose of contract performance vis-a-vis our potential and existing customers (Art. 6(1)(b) GDPR) and in the interest of a secure, fast and efficient provision of our online offering by a professional provider (Art. 6(1)(f) GDPR).
Our hoster will process your data only to the extent necessary to fulfil their performance obligations and will follow our instructions with regard to this data.
We use the following hoster:
Flying Circus Internet Operations GmbH
Leipziger Str. 70/71
06108 Halle (Saale)
Processing on behalf of the controller
We have concluded a data processing agreement (DPA) for the use of the hosting provider. The GDPR requirements stated in Art. 28 GDPR are applied.
7. Automatic server log files
Our web server automatically logs all access and therefore also the IP addresses of visitors. This serves to defend against attacks, analyse access figures and ensure smooth operation. We have a legitimate interest in this (Art. 6(1)(f) GDPR).
In addition to the IP address, the server log generally records further metadata relating to the session. This data is listed below.
Date and time of access
Information on the browser type and browser version used
Information on the operating system used
Device (client)
Referrer URL (the page from which you arrived at our site)
Hyperlinks accessed
We process this data only for the purposes stated above. We delete server log files after no more than two weeks.
8. Use of cookies
Our website uses cookies to provide services and ensure full functionality. Cookies - small text files that are automatically stored in your browser or device - can have various functions and contain a characteristic string that enables unique identification of the browser when the website is accessed again.
Cookies are stored on your end device and transmitted from it to our website. As a user, you generally have full control over the use of cookies. You can specify in your browser settings whether and which cookies you generally allow. We recommend setting your browser so that you are informed when a website wants to set cookies on your device. This gives you control over which cookies you want to allow. If you do not allow cookies, however, the functionality of websites may be restricted.
Cookies are generally divided into non-persistent and persistent cookies. A further distinction is made between first-party cookies (which come directly from our web server) and third-party cookies (which are set via third-party providers).
Cookie types by duration
Session cookies
Session cookies are deleted at the latest when you leave our website and close your browser.
Persistent cookies
These cookies remain stored even after you leave our website and close your browser. Persistent cookies can have different lifetimes, ranging from one day to several years. These cookies can fulfil various functions; for example, your login details may be stored so that you are automatically logged in when you revisit our website. Other persistent cookies are used for analytics, tracking and marketing purposes.
Cookie types by origin
We use both first-party cookies and third-party cookies. First-party cookies are cookies that come directly from us. Third-party cookies are cookies that are placed via a third-party provider. We use various third-party cookies for analytics, tracking and marketing purposes.
Cookie types by function
Technically required or necessary cookies
These cookies enable the operation of our website; without technically necessary cookies, our site would not be usable or would only be usable to a very limited extent. Such cookies are used, for example, when you log in to our site or place a product in the shopping cart. Some necessary cookies also serve security purposes.
Analytics or statistics cookies
Analytics cookies collect information about the behaviour of website visitors, provide information about the length of stay and which information was accessed. Information is also collected about the website from which visitors arrive, how many visitors the websites have and how long the user stays on the websites. The purpose of these cookies is to optimise our website on the basis of the collected information.
Tracking and marketing cookies
Tracking or marketing cookies (also remarketing and retargeting cookies) enable analysis of browsing behaviour; they store which content was visited or which products the user searched for (tracking in this sense means following). On the basis of these cookies, a user can also be identified across websites with the aim of displaying advertisements tailored to the user's interests.
Other cookies and third-party services
This includes, in particular, services through which we integrate third-party content into our website. These services use cookies; in particular, the IP addresses of our visitors are also transmitted to the service providers. In some cases, further personal data may also be processed by these third-party providers, as stated in their respective privacy policies.
Legal bases
We use technically necessary cookies in the interest of a functional and stable website (Art. 6(1)(f) GDPR in conjunction with Section 25(2) of the German TDDDG); we use other cookies only with your consent (Art. 6(1)(a) GDPR in conjunction with Section 25(1) of the German TDDDG).
The individual legal bases for the use of various tools that use cookies can be found in the respective sections of our Privacy Notice.
9. Zoho CRM system
Personal data that you provide to us in the context of contact requests, business relationships, registrations, form enquiries, product enquiries, test accounts, contract initiation or other interactions is processed and maintained by us with the help of a customer relationship management system (CRM).
The provider is Zoho Europe, operated by Zoho Corporation B.V., Beneluxlaan 4B, 3527 HT Utrecht, Netherlands. The privacy notice is available at https://www.zoho.com/privacy.html.
Data processing is generally carried out at server locations within the European Union. Where necessary for the provision of the technical service, individual processing activities may also be carried out by affiliated companies or subcontractors of Zoho.
If personal data is processed outside the European Union or the European Economic Area, this is done exclusively in compliance with the requirements of Art. 44 et seq. GDPR. Where required, appropriate safeguards, in particular EU Standard Contractual Clauses, are used.
A data processing agreement pursuant to Art. 28 GDPR has been concluded with Zoho. This ensures that personal data is processed exclusively in accordance with our instructions and in compliance with data protection requirements.
We use Zoho CRM in particular for:
Managing existing and potential customers
Processing contact requests
Managing customer and prospect relationships
Carrying out pre-contractual measures
Communicating with customers and prospects
Sales management
Documenting communication processes
Optimising customer-related business processes
Within our corporate structure, personal data may be processed centrally within the group of companies where this is necessary to process your request or to carry out internal business processes.
Processing is carried out on the basis of Art. 6(1)(b) GDPR where your request is aimed at concluding a contract or carrying out pre-contractual measures.
Otherwise, processing is carried out on the basis of our legitimate interest pursuant to Art. 6(1)(f) GDPR in efficient management of customer relationships, optimised communication and the organisation of internal business processes.
The data is deleted as soon as the purpose of the processing no longer applies and no statutory retention obligations prevent deletion.
10. Data processing in connection with communication and contact
Message via contact form (integrated via Zoho CRM)
You have the option of sending us messages via a contact form.
In this context, we process the data that you enter in the input form. Mandatory fields are marked accordingly. Processing is carried out to handle your request and, where applicable, to carry out pre-contractual measures.
The legal basis is Art. 6(1)(b) GDPR if your request relates to specific products, services or the conclusion of a contract.
Otherwise, processing is carried out on the basis of our legitimate interest pursuant to Art. 6(1)(f) GDPR in efficient handling of contact requests.
Requests submitted via the contact form are stored directly in the Zoho CRM system. The data is deleted as soon as the purpose of the processing no longer applies and no statutory retention obligations prevent deletion.
Communication by email
If you write to us by email, we process your data in accordance with the content and purpose of the message. As a rule, processing is carried out on the basis of pre-contractual measures or in the context of performing a contractual relationship on the basis of Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR. We have a legitimate interest in responding to your request quickly and efficiently.
If the message relates to a product or service, we generally process your data on the basis of our legitimate interests pursuant to Art. 6(1)(b) GDPR.
Please note that we store all incoming emails in accordance with the principles of proper accounting for a period of ten years, beginning on the first day of the year following receipt of the message. If you ask us to delete the data, we will restrict your data from then on for handling purposes and store it only for the purpose of complying with retention periods in our legitimate interest.
Communication by telephone or fax
If you contact us by telephone or fax, we process your data either to initiate and perform contractual relationships (where the content relates to a product or service) and/or in our legitimate interest, analogous to contact by email.
We do not record call content, but we may take notes to process your request. We store these until the purpose of the data processing has been achieved.
11. Information for applicants
Privacy provisions for the application procedure
If you apply to us, whether for an advertised position or speculatively, we process your data to carry out the selection process.
Applications via Workwise
Applications may be submitted via the Workwise recruiting platform. The provider of the platform is Workwise GmbH, Karlsruhe. Workwise processes applicants' personal data as an independent controller for the operation of the platform and the provision of the application function. Further information on data protection at the service provider Workwise GmbH can be found in the privacy policy.
When an application is transmitted to our company, the data is passed on to us and is then processed by us independently as part of the application procedure.
Recruiting via onlyfy
For the implementation of our application procedure, we use the recruiting software onlyfy within the PeakAvenue group of companies, an applicant management system of New Work SE, Am Strandkai 1, 20457 Hamburg, Germany. The software is used for structured management of applications, communication with applicants and organisation of the selection process.
Where personal data is processed within the onlyfy platform as part of our application process, this processing is carried out by New Work SE as a joint controller pursuant to Art. 26 GDPR.
The processing includes, in particular, the storage and management of incoming applications, organisation of the application process, communication with applicants and documentation of application decisions.
Independently of this, New Work SE also processes personal data in some cases as an independent controller, where this is necessary for the technical operation of the platform, ensuring system security or for certain platform functions.
Further information on independent data processing by New Work SE can be found in New Work SE's privacy notice at https://privacy.xing.com/de/datenschutzerklaerung.
Scope of processing
In principle, during an application procedure we process only the data that you have provided to us yourself. Additional sources will only be used after informing and consulting with you, for example if we may contact a former employer.
The legal basis for carrying out an application procedure is Section 26 BDSG in conjunction with Art. 6(1)(b) GDPR (initiation of an employment contract). If you give us your consent to store your data for a longer period, this is done on the legal basis of Art. 6(1)(a) GDPR.
Retention periods for applicant data
We delete applicant data no later than six months after completion of the application procedure (when a candidate has been selected and all applicants have been informed of the outcome). In principle, the purpose of the data processing no longer exists once the selection process has ended; however, we have a legitimate interest (Art. 6(1)(f) GDPR) in being able to defend ourselves against any claims by rejected applicants. If you believe that your interests in immediate deletion outweigh ours, you may ask us to do so. We will then review your request and provide you with feedback.
After expiry of the above period, your data will be deleted unless we have to defend ourselves, for example in ongoing proceedings such as a claim under the General Equal Treatment Act. In this case, we delete your data after completion of the proceedings, unless statutory retention periods apply.
If we are permitted to store your data for a longer period on the basis of your consent, we will delete your data if you ask us to do so and withdraw your consent. Where applicable, we may also delete your data before you withdraw your consent if it becomes apparent that no position will be available.
Inclusion in our applicant pool
If we cannot offer you a position at the current time, we may ask for your consent to continue storing your data. This serves the purpose of offering you a suitable position at a later date. The legal basis for processing your data in our applicant pool is your consent (Art. 6(1)(a) GDPR). You may of course withdraw your consent at any time with effect for the future. If you do not withdraw your consent yourself within a period of two years, we will delete your data from our applicant pool at the latest at that time.
12. Direct marketing
Direct marketing to existing customers based on legitimate interests
We reserve the right to use data collected in connection with a purchase contract or service contract, where applicable, for direct advertising by email or post pursuant to Section 7(3) UWG, provided that the customer has not objected to such use. Direct advertising includes only offers for similar products or services to those already purchased from us by the user.
We have a legitimate economic interest (Art. 6(1)(f) GDPR) in informing our customers about new products and improving our services. You may of course object to receiving direct marketing at any time. Please send your objection to the controller named above. Each newsletter also contains information on how you can exercise your right to object.
Direct marketing based on your consent (newsletter)
You have the option of giving us your consent to receive direct marketing content. If you give your consent (Art. 6(1)(a) GDPR), for example to receive our email newsletter, we process your data for the specific purpose of direct marketing measures by email.
As we are obliged to verify the accuracy of the email address you provide when registering for the newsletter and want to ensure its correctness, we use procedures that enable verification of ownership of the email address. As a rule, this verification is carried out using the double opt-in procedure: after registration, you receive an email containing a link that you must click to confirm. If the double opt-in procedure is temporarily unavailable for technical reasons, we will send you an email to which you can reply without text in order to confirm your identity.
You may withdraw your consent at any time with effect for the future. A 'unsubscribe' link is included in each newsletter for this purpose. Alternatively, you can send us an email with the subject 'Unsubscribe from newsletter'. We process your data until you withdraw your consent. Statutory retention periods remain unaffected.
After you unsubscribe from the newsletter mailing list, your email address may be stored by us or by the newsletter service provider in a blacklist in order to prevent future mailings. The data in the blacklist is used only for this purpose and is not combined with other data. This serves both your interest and our interest in complying with statutory requirements when sending newsletters (legitimate interest within the meaning of Art. 6(1)(f) GDPR). Storage in the blacklist is not limited in time. You may object to the storage if your interests outweigh our legitimate interest.
Use of the mailing service provider 'Mailingwork'
The newsletter is sent using 'Mailingwork', a newsletter platform of Mailingwork GmbH, Schoenherrstrasse 8, 09113 Chemnitz, Germany. https://mailingwork.de/. We have concluded a data processing agreement with Mailingwork.
With the following information, we would like to inform you about the contents of our newsletter, the registration, dispatch and statistical evaluation procedures, and your rights of objection. To receive our newsletter, we ask you to consent to the described procedure by ticking the relevant box during registration. Without your consent, we are unfortunately unable to send you a newsletter for data protection reasons.
Statistical collection and analyses
'Mailingwork' is a service with which, among other things, the sending of newsletters can be organised and analysed. The data you enter for the purpose of receiving the newsletter is stored on the servers of Mailingwork GmbH.
The sending of the newsletter and the related performance measurement are carried out on the basis of the recipients' consent pursuant to Art. 6(1)(a), Art. 7 GDPR in conjunction with Section 7(2) No. 3 UWG or, where consent is not required, on the basis of our legitimate interests in direct marketing pursuant to Art. 6(1)(f) GDPR in conjunction with Section 7(3) UWG.
13. Audio and video conferences with MS Teams
We use Microsoft Teams for communication. The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. Details on data processing can be found in the Microsoft Teams privacy statement: https://privacy.microsoft.com/de-de/privacystatement.
Microsoft Teams processes all data that you provide/use to use the tools (email address and/or your telephone number). The conference tools also process the duration of the conference, the start and end (time) of participation in the conference, the number of participants and other 'context information' in connection with the communication process (metadata).
In addition, the provider of the tool processes all technical data required to handle online communication. This includes, in particular, IP addresses, MAC addresses, device IDs, device type, operating system type and version, client version, camera type, microphone or speaker and the type of connection.
If content is exchanged, uploaded or otherwise provided within the tool, this is also stored on the servers of the tool providers. Such content includes, in particular, cloud recordings, chat/instant messages, voicemails, uploaded photos and videos, files, whiteboards and other information shared during use of the service.
Please note that we do not have full influence over the data processing operations of the tools used. Our options depend largely on the corporate policy of the respective provider. Further information on data processing by the conference tools can be found in the privacy policies of the respective tools used, which we have listed below this text.
Purpose and legal bases
We use Microsoft Teams to communicate with prospective or existing contractual partners or to offer certain services to our customers (Art. 6(1)(b) GDPR). In addition, the use of the tools serves the general simplification and acceleration of communication with us or our company (legitimate interest within the meaning of Art. 6(1)(f) GDPR). Where consent has been requested, the respective tools are used on the basis of that consent; consent can be withdrawn at any time with effect for the future.
Retention period
The data collected directly by us via the video and conference tools is deleted from our systems as soon as you ask us to delete it, withdraw your consent to storage or the purpose for storing the data no longer applies. Stored cookies remain on your end device until you delete them. Mandatory statutory retention periods remain unaffected.
We have no influence over the retention period of your data that is stored by the operators of the conference tools for their own purposes. For details, please contact the operators of the conference tools directly.
Processing on behalf of the controller
We have concluded a data processing agreement (DPA) for the use of the above-mentioned service. This is a contract required under data protection law which ensures that the provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.
14. Jira ticket system
We use the project management tool Jira for our support requests. The provider is Atlassian, Inc., 1098 Harrison Street, San Francisco, California 94103, USA (privacy notice: https://www.atlassian.com/legal/privacy-policy).
Jira serves as a tool for our customers to open tickets. In this context, the personal data and content entered in the ticket are processed. Each ticket is assigned timestamps and a status, which is updated as processing progresses.
The personal data processed in tickets is stored until the purpose of the processing has been achieved and we must fulfil our documentation obligations within the customer relationship.
The legal basis for processing is Art. 6(1)(b) GDPR; the ticket system is used within the scope of contractual services. We also have a legitimate interest within the meaning of Art. 6(1)(f) GDPR in using an established provider that regularly demonstrates its compliance obligations. We have concluded a Data Processing Agreement with Atlassian based on the EU Standard Contractual Clauses. The data centres used are located in the European Union.
15. Analytics tools
Anonymous usage analysis using Matomo
This website uses the open-source web analytics software Matomo. Unlike many other analytics products, the software is operated by the controllers themselves on servers within the Federal Republic of Germany.
Our Matomo installation respects 'Do Not Track' HTTP headers ('DNT') from web browsers. DNT is intended to notify website operators in advance if no usage analysis is desired. You can configure the use of DNT yourself in most current web browsers, or it may already be preset.
If DNT is active, your visit is not included in usage data collection from the outset. The box below may already show whether DNT is active in your browser.
If DNT is not active, Matomo records your visit without the use of cookies and in anonymised form. Anonymisation means that, when data is collected, the last two IP blocks are set to 0 before storage, so that the usage data no longer allows conclusions to be drawn about the person. These data are also automatically deleted after no more than 12 months.
The basis for this data processing is Art. 6(1)(f) GDPR, as we have a legitimate interest in analysing the reach and type of use of our website.
You can also deactivate this anonymised collection of usage data. If DNT has not already prevented data collection, a selection field will appear in the box below through which you can communicate your decision to the website. To document this decision, an opt-out cookie is stored in your browser in this case. If you delete your cookies, the Matomo opt-out cookie will also be deleted. The opt-out must then be activated again when you revisit this website.
16. PeakAvenue social media presences
Data processing by social networks
We maintain publicly accessible profiles on social networks. The individual social networks we use are listed below.
Social networks such as Facebook, X etc. can generally analyse your user behaviour comprehensively when you visit their website or a website with integrated social media content (e.g. like buttons or advertising banners). Visiting our social media presences triggers numerous data protection-relevant processing operations. In detail:
If you are logged into your social media account and visit our social media presence, the operator of the social media portal can assign this visit to your user account. Your personal data may also be collected in certain circumstances if you are not logged in or do not have an account with the respective social media portal. In this case, data collection may take place, for example, via cookies stored on your end device or by recording your IP address.
Using the data collected in this way, the operators of the social media portals can create user profiles in which your preferences and interests are stored. This allows interest-based advertising to be displayed to you within and outside the respective social media presence. If you have an account with the respective social network, interest-based advertising can be displayed on all devices on which you are or were logged in.
Please also note that we cannot trace all processing operations on the social media portals. Depending on the provider, further processing operations may therefore be carried out by the operators of the social media portals. Details can be found in the terms of use and privacy policies of the respective social media portals.
Legal basis
Our social media presences are intended to ensure the broadest possible presence on the internet. This constitutes a legitimate interest within the meaning of Art. 6(1)(f) GDPR. The analysis processes initiated by the social networks may be based on different legal bases that must be specified by the operators of the social networks (e.g. consent within the meaning of Art. 6(1)(a) GDPR).
Controller and exercise of rights
When you visit one of our social media presences (e.g. Facebook), we are jointly responsible with the operator of the social media platform for the data processing operations triggered by this visit. You may generally assert your rights (access, rectification, erasure, restriction of processing, data portability and complaint) both against us and against the operator of the respective social media portal (e.g. against Facebook).
Please note that, despite joint controllership with the social media portal operators, we do not have full influence over the data processing operations of the social media portals. Our options depend largely on the corporate policy of the respective provider.
Retention period
The data collected directly by us via the social media presence is deleted from our systems as soon as you ask us to delete it, withdraw your consent to storage or the purpose for storing the data no longer applies. Stored cookies remain on your end device until you delete them. Mandatory statutory provisions - in particular retention periods - remain unaffected.
We have no influence over the retention period of your data that is stored by the operators of the social networks for their own purposes. For details, please contact the operators of the social networks directly (e.g. in their privacy policy, see below).
Your rights
You have the right at any time to obtain information free of charge about the origin, recipients and purpose of your stored personal data. You also have the right to object, the right to data portability and the right to lodge a complaint with the competent supervisory authority. You may also request the rectification, blocking, erasure and, under certain circumstances, restriction of the processing of your personal data.
Social networks in detail
We have a profile on Facebook. The provider of this service is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland (hereinafter Meta). According to Meta, the data collected is also transferred to the USA and other third countries.
We have concluded an agreement on joint processing (Controller Addendum) with Meta. This agreement specifies which data processing operations we or Meta are responsible for when you visit our Facebook Page. You can view this agreement at the following link: https://www.facebook.com/legal/terms/page_controller_addendum.
You can adjust your advertising settings independently in your user account. Click the following link and log in: https://www.facebook.com/settings?tab=ads.
Data transfer to the USA is based on the Standard Contractual Clauses of the EU Commission. Details can be found here: https://www.facebook.com/legal/EU_data_transfer_addendum and https://de-de.facebook.com/help/566994660333381.
Details can be found in Facebook's privacy policy: https://www.facebook.com/about/privacy/.
We have a profile on Instagram. The provider of this service is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.
Data transfer to the USA is based on the Standard Contractual Clauses of the EU Commission. Details can be found here: https://www.facebook.com/legal/EU_data_transfer_addendum and https://de-de.facebook.com/help/566994660333381.
Details on how they handle your personal data can be found in Instagram's privacy policy: https://privacycenter.instagram.com/policy/.
We have a profile on XING. The provider is New Work SE, Am Strandkai 1, 20457 Hamburg, Germany. Details on how they handle your personal data can be found in XING's privacy policy: https://privacy.xing.com/de/datenschutzerklaerung.
We have a profile on LinkedIn. The provider is LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland. LinkedIn uses advertising cookies.
If you wish to disable LinkedIn advertising cookies, please use the following link: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
Data transfer to the USA is based on the Standard Contractual Clauses of the EU Commission. Details can be found here: https://www.linkedin.com/legal/l/dpa and https://www.linkedin.com/legal/l/eu-sccs.
Details on how they handle your personal data can be found in LinkedIn's privacy policy: https://www.linkedin.com/legal/privacy-policy.
YouTube
We have a profile on YouTube. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Details on how they handle your personal data can be found in YouTube's privacy policy: https://policies.google.com/privacy?hl=de.
17. Supplementary privacy information for our business partners
Data categories and purposes of processing
We process personal data of our service providers and partners that we receive directly in the context of our business relationship. If we have received data from you, we generally process it only for the purposes for which we received or collected it.
As a rule, we process the following categories of data about you
Last name, first name
Address and/or company address
Telecommunications data
Email address
Company
Professional function and/or position
Bank details / other payment information
Data on the history of the business relationship
During the business initiation phase and during the business relationship, in particular through personal, telephone or written contacts initiated by you or by one of our employees, further personal data is created, e.g. information on contact channel, date, reason and result; (electronic) copies of correspondence and information on participation in direct marketing measures.
We also process personal data that we have lawfully obtained from publicly accessible sources (e.g. commercial and association registers, press, media, internet) and are permitted to process.
Data processing for other purposes will only be considered if the legal requirements necessary in this respect pursuant to Art. 6(4) GDPR are met. In that case, we will of course comply with any information obligations pursuant to Art. 13(3) GDPR and Art. 14(4) GDPR.
Legal bases on which we process your data
Based on your consent (Art. 6(1)(a) GDPR)
We process personal data for one or more specific purposes if you have given us consent to do so. If personal data is processed on the basis of consent given by you, you have the right to withdraw the consent from us at any time with effect for the future.
Data processing for the performance of contracts (Art. 6(1)(b) GDPR)
We process personal data for the performance of contracts. Performance of contracts includes, for example, the conclusion, execution and reversal of a contract. In addition, we process personal data that is necessary to carry out pre-contractual measures, such as initiating a contract, and that are carried out at your request.
Data processing due to a legal obligation (Art. 6(1)(c) GDPR)
Like every company, we must comply with retention obligations and other documentation obligations; this may also concern documents containing personal information. Where we process data for these purposes, processing is carried out due to a legal obligation.
Data processing based on a balancing of interests (Art. 6(1)(f) GDPR)
If we process data based on a balancing of interests, you as the data subject have the right to object to the processing of personal data, taking into account the requirements of Art. 21 GDPR. To the extent permitted by the specific purpose, we process your data in pseudonymised or anonymised form.
Other recipients of your data
Disclosure within the PeakAvenue group of companies
Within the PeakAvenue Group, we process data on shared systems and for shared purposes. This is done on the basis of joint controllership within the framework of legitimate interests.
Disclosure to processors within the scope of Art. 28 GDPR
Processors used by us (Art. 28 GDPR), in particular in the area of IT services and, for example, printing services, process your data for us on the basis of instructions. If we engage service providers to fulfil our tasks, we always comply with data protection provisions; in particular, disclosure takes place only after conclusion of data processing agreements. We will gladly inform you which processors we use.
For the performance of a contractual relationship
If this is necessary for the performance of the contract with you, we disclose your data, for example, to our bank for payment processing or to shipping service providers such as Deutsche Post, DHL, UPS, GSL, DPD or other providers relevant to the occasion.
Disclosure due to a legal obligation
Where there is a statutory or official obligation, we disclose your data to public bodies or institutions (authorities, for example in the context of criminal prosecution).
Other bodies, where you have given us your consent
Where explicit consent exists, we also disclose your data to other bodies. However, this is done within the limits of verifiable consent given by you.
Information on retention periods for personal data
Principle of purpose limitation and compliance with statutory retention periods
We process the data for as long as this is necessary for the respective purpose. Where required, we process your personal data for the duration of our business relationship, which also includes the initiation and performance of a contract.
In addition, like every company, we are obliged to comply with statutory retention periods, for example periods under commercial and tax law. Where statutory retention obligations exist, the relevant personal data is stored for the duration of the retention obligation. The storage period is also based on statutory limitation periods, which, for example under Sections 195 et seq. of the German Civil Code (BGB), are generally three years, but in certain cases may be up to thirty years. After the retention obligation has expired, it is checked whether there is a further need for processing. If there is no further need, the data is deleted.
As a rule, such retention periods in the context of legal transactions (pursuant to Section 147 AO / Section 257 HGB / Section 14b UStG) are eight years, beginning with the year following the legal transaction.
Specific example
If you provide us with your contact details, for example by email, telephone or by handing over your business card, we store this data on the basis of Art. 6(1)(b) GDPR based on pre-contractual measures and in the legitimate interest (Art. 6(1)(f) GDPR) of smooth and targeted communication. If no legal transaction is concluded, we delete your data if you ask us to do so or if no further contact takes place within a period of three years. If you enter into a legal transaction with us (Art. 6(1)(b) GDPR), we store your data until the expiry of the commercial and tax law requirements for ten years. After this period, we check whether we can delete the data and, where applicable, proceed with deletion.
Emails and business letters
We archive all of our email correspondence for ten years. If you write to us by email, your data and the entire email content are stored accordingly for eight years. Most emails qualify as business letters; in addition, emails may contain information relevant under tax law. In our view, the effort required to check each individual email in this respect is not proportionate to the benefit and the legitimate interests of the sender. You may of course request deletion from us at any time; we will then carry out an individual case review and inform you of the result. Depending on the content of the correspondence, this may lead to deletion or restriction of processing.
Withdrawal of your consent
If we process your data on the basis of your consent (Art. 6(1)(a) GDPR), we delete it after you withdraw your consent, unless legitimate interests prevent complete deletion. For example, we generally retain declarations of consent for up to three years after receipt of your withdrawal in our legitimate interest (Art. 6(1)(f) GDPR). We retain the consent only with processing restricted in order to defend ourselves in the event of a dispute.
Statutory or contractual obligation to provide personal data
The provision of personal data is regularly necessary for the initiation, conclusion, execution and reversal of a contract. If you do not provide the required personal data, we will not be able to conclude and perform a contract with you.
Transfer to a third country
Your personal data is generally processed by us in data centres in the Federal Republic of Germany or the European Union. A transfer to a third country will only be considered if you have given us your consent or if we have concluded a data processing agreement pursuant to Art. 28 GDPR, taking into account appropriate safeguards or other suitable safeguards.
18. Last updated
Last updated on 20 May 2026.