Data privacy

Protecting your personal data is particularly important to us. For this reason, too, we comply with the relevant legal regulations. This privacy policy is intended to inform you what type of data is collected for what purpose and to what extent this data is made available to third parties.

The data protection information is divided into five parts:

A. General Data protection information

B. Privacy information for user of this website

C. Data protection information for customers

D. Rights of data subjects

E. Data protection information for contenders

A. General data protection information

Name und Anschrift des für die Verarbeitung Verantwortlichen

itelio GmbH
vertreten durch die Geschäftsführer: Dipl.-Inf. (FH) Peter Kurz, Tobias Kurz, Ingemar Mayr

Franz-Larcher-Straße 4
D – 83088 Kiefersfelden

Telefon: +49 (0)8033 / 6978–0
Telefax: +49 (0)8033 / 6978–91
E-Mail: info@itelio.com
Internet: www.itelio.com

Betrieblicher Datenschutzbeauftragter

Sollten Sie noch Fragen zum Datenschutz oder zur Verarbeitung Ihrer durch uns verarbeiteten personenbezogenen Daten haben, so erreichen Sie unseren betrieblichen Datenschutzbeauftragten per E-Mail unter: datenschutz@itelio.com oder unter der o.g. Anschrift mit der Kennzeichnung „Datenschutzbeauftragter“.

B. Data protection information when using our website.

Processing of personal data

The processing of personal data is carried out in accordance with Article 5 GDPR.
Personal data is processed on our websites

  • insofar as this is technically necessary,
  • serves to analyze, optimize or economically operate our websites,
  • this is necessary to process the contract, or
  • to provide you as a customer with product-specific information.

Data security

We use technical and organizational security measures to protect your data managed by us against accidental or intentional manipulation, loss, destruction or access by unauthorized persons. Our security measures are constantly being improved in line with technological developments.
Data transfers are carried out using the SSL (Secure Socket Layer) procedure.

Safety notice
By taking all technical and organizational options, we make every effort to store your personal data in such a way that it is not accessible to third parties. When communicating by e-mail, we cannot guarantee complete data security, so we recommend that you send confidential information by post.

Use of service providers

We use service providers (so-called contract processors) to provide services and to process your data. The service providers process the data exclusively on our instructions and are obliged to comply with the applicable data protection regulations. All contract processors have been carefully selected and will only have access to your data to the extent and for the period required to provide the services.

External service providers are carefully selected by us and contractually bound by means of an order processing agreement in accordance with Article 28 GDPR.

Processing of data in countries outside the European Economic Area EEA

Some service providers we use are based in the USA or other countries outside the European Economic Area. Companies in these countries are subject to data protection laws that generally do not protect personal data to the same extent as is the case in Member States of the European Union. Through contractual arrangements or other recognized instruments, we ensure that your personal data is adequately protected.

Processing of personal data

When you visit our websites, you transfer data to a web server via your Internet browser (for technical reasons). The following data is recorded during an ongoing connection for communication between your Internet browser and our web servers:

  • browser type/version,
  • operating system used,
  • referrer URL (the previously visited page) and
  • the time of the server request.

We need this data for reasons of technical security and for statistical evaluations and cannot usually be assigned to specific persons. This data is not combined with other data sources. This data will be deleted after 14 days at the latest.

Cookies

Various services on our websites use so-called “cookies.” These are small text files that are stored on your computer and allow an analysis of your use of the website. They are used to make our website more user-friendly, effective and secure overall — for example when it comes to speeding up navigation on our platform.

Cookies also enable us to measure, for example, the frequency of page views and general navigation. Cookies are small text files that are stored on your computer system. Please note that some of these cookies are transferred from our server to your computer system, which are usually so-called “session cookies.” “Session cookies” are characterized by the fact that they are automatically deleted from your hard drive at the end of the browser session. Other cookies remain on your computer system and enable us to recognize your computer system the next time you visit (so-called persistent cookies). Of course, you can reject cookies at any time, provided that your browser allows this.

cookies: Approval options

Of course, you can also use our website without using cookies. To do this, you can generally deactivate the use of cookies at any time via the settings of your Internet browser or have cookies displayed and then decide on a case-by-case basis whether to accept cookies. However, please note that in this case you may not be able to use all functions of our websites to their full extent.

Instructions for deleting cookies in the most common browsers can be found here:

Social networks

We use various plug-ins from social networks on our websites.

facebook is operated by Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA (“Facebook”). An overview of Facebook plugins and their appearance can be found here:
https://developers.facebook.com/docs/plugins

instagram is operated by Instagram LLC., 1601 Willow Road, Menlo Park, CA 94025, USA (“Instagram”). An overview of the Instagram buttons and their appearance can be found here:
https://instagram.tumblr.com/post/36222022872/introducing-instagram-badges

linkedin is operated by LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland (“LinkedIn”).

XING is operated by Xing SE, Dammtorstraße 30, 20354 Hamburg, Germany (“Xing”). An overview of the Xing buttons and their appearance can be found here:
https://dev.xing.com/plugins/share_button

X (Twitter) is operated by X Inc., 1355 Market St, Suite 900, San Francisco, CA 94103, USA (“Twitter”). An overview of the Twitter buttons and their appearance can be found here:
https://about.twitter.com/de/company/brand-resources.html

Cookies also enable us to measure, for example, the frequency of page views and general navigation. Cookies are small text files that are stored on your computer system. Please note that some of these cookies are transferred from our server to your computer system, which are usually so-called “session cookies.” “Session cookies” are characterized by the fact that they are automatically deleted from your hard drive at the end of the browser session. Other cookies remain on your computer system and enable us to recognize your computer system the next time you visit (so-called persistent cookies). Of course, you can reject cookies at any time, provided that your browser allows this.

cookies: Approval options

These social plugins are operated exclusively by the respective providers. The social plugins on our website are identified by the respective button belonging to the provider or service. If you visit one of our websites that contains such a social plugin, your browser connects to the servers of the respective service. This in turn transmits the content of the plugin to your browser and integrates it into the displayed page. When you visit our website, the respective information is therefore transmitted to the respective service.

If, while visiting our website, you are also logged in to one of the respective services via your personal user account at the same time, this service can associate the visit to the website with your account. Users can post or share links to websites on social networks using social plugins. Through interactions, such as leaving a comment or clicking on the respective button, the respective information is transferred directly to the respective services and stored there.

If you do not want and do not want to prevent such data transfer, log out of your social networks or user accounts before you visit our websites. We have no influence on data collection and transfer through social plugins. The purpose and scope of the data collection by the respective provider or service and the further use and processing of your data can be found in the respective data protection notices directly from the providers' websites. Please find out there what rights you have and how you can achieve a satisfactory data protection setting.

Data protection information on social plugins currently used on our websites:

Bing Ads

Our website uses Bing Ads technologies to collect and store data from which user profiles are created using pseudonyms. This is a service of

Microsoft Corporation
One Microsoft Way
Redmond, WA 98052-6399
USA

This service allows us to track the activity of users on our website when they have reached our website via Bing Ads ads. If you reach our website via such an ad, a cookie is set on your computer. A Bing UET tag is integrated on our website. This is a code that, in conjunction with the cookie, stores some non-personal data about the use of the website. This includes the time spent on the website, which areas of the website were accessed and which ad brought users to the website. Information about your identity is not collected.

The information collected is transferred to Microsoft servers in the USA and stored there for a maximum of 180 days in principle. Data transfer to the USA is based on the EU-US Data Privacy Framework. You can prevent the collection of data generated by the cookie and related to your use of the website and the processing of this data by deactivating the setting of cookies. This may restrict the functionality of the website. In addition, Microsoft may be able to track your usage behavior across several of your electronic devices through so-called cross-device tracking and may therefore be able to display personalized advertising on or in Microsoft websites and apps.

You can see this behavior at
https://choice.microsoft.com/de-de/opt-out
Deactivate. For more information about Bing's analytics services, visit the Bing Ads website (
https://help.bingads.microsoft.com/#apex/3/de/53056/2
). For more information about data protection at Microsoft and Bing, please see Microsoft's privacy policy (
https://privacy.microsoft.com/de-de/privacystatement
).

Facebook Custom Audience

Facebook users should note that Facebook's Website Custom Audience communication tool is used on this website. For this purpose, so-called Facebook pixels are integrated on our websites, which mark you as a visitor to our website in anonymized form, i.e. without identifying you as a person.

If you are a Facebook user, Facebook can thereby associate your visit to our pages with your user account. Facebook can also subsequently recognize whether a Facebook ad had an effect, i.e. led to a purchase being concluded, for example. The Facebook pixel is also used to enable us to display advertisements to a defined audience on Facebook. For this purpose, we only receive statistical data from Facebook without reference to a specific person. This is done for the purposes of advertising and market research and designing our website in line with needs. Tracking using the pixel is carried out in a way that does not enable us to identify you as a person and only marks users as visitors to our website in an anonymized form for us. Facebook uses cookies for this purpose. Facebook stores and uses the data collected using the pixel. This is also happening, at least in part, outside the territorial scope of EU data protection legislation.

Objection option: If you would like to object to the use of Facebook Website Custom Audiences, you can do so at https://www.facebook.com/ads/website_custom_audiences do. To do this, you must be logged in to Facebook.

Data transmission to the USA is based on the EU-US Data Privacy Framework. For more information about the purpose and scope of data collection and the further processing and use of data by Facebook as well as your settings options to protect your privacy, please refer to Facebook's privacy policy, which is available at https://www.facebook.com/privacy/explanation can be found.

Google Ads

Google Ads will set a cookie on your computer (“conversion cookie”) if you have reached our website via a Google ad. These cookies expire after 30 days and are not used for personal identification. If you visit certain pages of ours and the cookie has not yet expired, we and Google can recognize that someone clicked on the ad and was thus redirected to our site. Each Google Ads customer receives a different cookie. Cookies can therefore not be tracked via the websites of Google Ads customers. The information collected using the conversion cookie is used to generate conversion statistics for Google Ads customers who have opted for conversion tracking.

Google Ads customers learn the total number of users who clicked on their ad and were redirected to a page with a conversion tracking tag. However, they do not receive any information that personally identifies users. Data transmission to the USA is based on the EU-US Data Privacy Framework.

If you do not want to participate in the tracking process, you can refuse the necessary setting of a cookie — for example via a browser setting that generally deactivates the automatic setting of cookies. You can also deactivate conversion tracking cookies by setting your browser to block cookies from the “googleadservices.com” domain.

Google's privacy policy on conversion tracking can be found at:
https://services.google.com/sitestats/de.html

You can also prevent Google Ads from collecting data by clicking on the following link. An opt-out cookie is set which prevents the future collection of your data when you visit this website:To draw the attention of potential users and customers to our online offerings, we use the “Google Ads” online advertising program and, as part of Google Ads, conversion tracking, an analysis service provided by

Google Inc. (Google)
1600 Amphitheatre Parkway
Mountain View
CA 94043
USA

Deactivate Google Ads

Google Analytics

This website uses Google Analytics, a web analysis service provided by

Google Inc. (“Google”)
1600 Amphitheatre Parkway
Mountain View
CA 94043
USA

Google Analytics uses “cookies.” The information generated by the cookie about your use of this website is usually transferred to a Google server in the USA and stored there for 14 months. Data transmission to the USA is based on the EU-US Data Privacy Framework. However, if IP anonymization is activated on this website, Google will abbreviate your IP address beforehand within member states of the European Union or in other states party to the Agreement on the European Economic Area.

Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and abbreviated there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, to compile reports on website activity and to provide other services related to website activity and Internet usage to the website operator. The IP address transmitted by your browser as part of Google Analytics is not combined with other data from Google. You can prevent cookies from being saved by setting your browser software accordingly; however, we would like to point out that in this case you may not be able to use all functions of this website in full.

Please note that on this website Google Analytics includes the code “gat. _anonymizeIp ();” was extended to ensure anonymized collection of IP addresses (so-called IP masking). You can also prevent Google from collecting the data generated by the cookie and related to your use of the website (including your IP address) and from processing this data by Google by using the link available at the following link Browser plugin download and install:
https://tools.google.com/dlpage/gaoptout?hl=de

You can also prevent Google Analytics from collecting data by clicking on the following link. An opt-out cookie is set which prevents the future collection of your data when you visit this website:

Deactivate Google Analytics

Google Tag Manager

Google Tag Manager is used on this website. Google Tag Manager is a solution from

Google Inc. (“Google”)
1600 Amphitheatre Parkway
Mountain View
CA 94043
USA

which allows companies to manage website tags via an interface. Google Tag Manager is a cookie-less domain that does not collect any personal data. Google Tag Manager triggers other tags, which in turn may collect data. We hereby point this out separately.

Google Tag Manager does not access this data. If a deactivation has been made by the user at domain or cookie level, this will remain valid for all tracking tags that are implemented with Google Tag Manager.

Jotform

To provide forms on our websites, we use a service from

Jotform Ltd.
25 Cabot Square
E14 4QZ Londra
United Kingdom

Jotform allows us to create online forms to collect registrations, applications, and general inquiries on our websites. The entries you make are processed on Jotform's servers. Jotform only stores the data on servers in Europe (Germany).
Jotform is used to perform our tasks (Art. 6 para. 1 lit. e DSGVO) or on the basis of our legitimate interest in optimal digital processing of your request (Art. 6 para. 1 lit. f GDPR). In connection with a contractual relationship, we process on the basis of Art. 6 para. 1 lit. b GDPR.

You can find more information about Jotforms privacy here: www.jotform.com/gdpr-compliance/dpa/.

Matomo

We collect certain information so that we can offer you the best possible experience on our websites. To do this, we use the company's Matomo web analytics platform

InnoCraft Ltd
7 Waterloo Quay PO625
6140 Wellington
New Zealand

When you visit our site, we save: your anonymized IP address, the website from which you visited us, the parts of our websites that you visit, the date and duration of your visit, information from the device you used during your visit (device type, operating system, screen resolution, language, country in which you are located and web browser type) and more. We process this usage data in the Matomo Web Analytics Platform for statistical purposes to improve our site and to identify and prevent misuse.

Opt-out from web analysis

You can unsubscribe from tracking through our Matomo web analytics at any time.

You have the option to prevent actions you have taken here from being analyzed and linked. This will protect your privacy but will also prevent the owner from learning from your actions and improving usability for you and other users.

Microsoft

To create a user account for authentication in our online portals, we use the “Microsoft Azure Active Directory B2C” service on the basis of Article 6 paragraph 1 letter f GDPR from

Microsoft Ireland Operations Ltd.
One Microsoft Place
South County Business Park
Leopardstown
Dublin 18
Ireland

First and last name and email address are transferred to create a user account. The password chosen by the user himself is saved there.

Die Datenübertragung in die USA basiert auf dem EU-US Data Privacy Framework.

Mollie

On our website in our web shop, we offer payment via an external payment service provider

Mollie B.V.
Keizersgracht 126
1015 CW Amsterdam
netherlands

on. Mollie processes the following payment methods: Mastercard, Visa, American Express, SEPA and PayPal. If you select the payment method, the payment details you enter will be sent to both Mollie and the payment provider you have chosen. Your data is transmitted to Mollie on the basis of Article 6 (1) (b) GDPR (processing to fulfill a contract). Payment transactions are subject to the terms and conditions and data protection notices of the respective payment service providers, which are also available within the respective websites or transaction applications. We also refer to these for further information and to assert revocation, information and other data subject rights. Details on payment via payment service provider Mollie can be found at the following link: https://www.mollie.com/de/privacy.

Salesforce / Pardot

We only store personal data from website visitors who have voluntarily or on their own initiative registered on our websites in order to receive information about products and services, subscribe to newsletters or download documents. Some forms and web pages are linked to Pardot. Pardot is marketing automation software from

salesforce.com Germany GmbH
Erika-Mann-Strasse 31-37
80636 Munich
germany

Voluntarily provided personal data is first stored in Pardot and then processed with the Salesforce CRM system for the purpose of contacting and/or sending information.

We use Pardot as a marketing analysis service, which enables us to maintain, measure, expand our website and marketing communication and optimize website content. Data is processed in Salesforce/Pardot on our behalf through the use of cookies.

Here you can find out how Salesforce processes your data when you visit websites: https://help.salesforce.com/articleView?id=pardot_basics_cookies.htm&type=5.

Visual Website Optimizer

On our websites, we use the Visual Website Optimizer web analysis tool from

Wingify Software Pvt Ltd
1104, 11th Floor, KLJ Tower B-5
Netaji Subhash Place, Pitampura
Delhi-110034
India

We use this web analysis tool for so-called A/B and multivariate tests and only serves to improve the usability and design of our websites. We carry out analyses to evaluate your use of the websites and to compile reports on website activity. Visual Website Optimizer analyses, for example, how long a user spent on different versions of our websites and which areas of the respective version were clicked on. These purposes pursued by us represent a legitimate interest based on Art. 6 para. 1 lit. f DSGVO.

Visual Website Optimizer uses cookies. The information generated by cookies about your use of our websites is transferred to a provider's server and stored there. Since we have activated IP anonymization, your IP address will be abbreviated by Visual Website Optimizer within a member state of the European Union or in other states party to the Agreement on the European Economic Area. You can deactivate Visual Website Optimizer tracking at any time and thus prevent Visual Website Optimizer from collecting data generated by cookies and related to your use of the website — including your IP address — and from processing this data. You can find information about this in the guide at https://vwo.com/opt-out.

Wistia

On our websites, based on Article 6 paragraph 1 letter f GDPR, we use the software Wistia (https://wistia.com/) from

Wistia Inc.
17 Tudor Street
Cambridge, MA 02139
USA

The software is used to embed videos into our website and to promote and measure the interaction behavior of website visitors with the videos. Wistia collects the following categories of personal data on our behalf:

  • anonymisierte IP-Adresse inkl. Provider;
  • Zugriffszeit auf angesehene Videos;
  • Details zu deren angesehen Videoabschnitten;
  • URL der Videos;
  • Art des Endgerätes (stationär, mobil), Betriebssystem und verwendeter Browser.

No cookies are used for this purpose.

All information about the transfer and use of data by Wistia can be found here: https://wistia.com/privacy.

Zapier

To integrate various databases and tools to automate our workflows, we use Zapier, a service provided by

Zapier Inc.
548 Market St #62411
San Francisco
California 94104
USA

Customer data, with the exception of payment data, may be transmitted. You can find more information about Zapier's privacy policy at https://zapier.com/privacy/.

Amendment to our privacy policy

We reserve the right to change our security and data protection measures at any time, insofar as this is necessary due to technical developments or legal changes. In these cases, we will also adapt our privacy policy accordingly. Please therefore note the latest version of this privacy policy.

C. Customer privacy information.

If you conclude a contract with us or in the case of pre-contractual measures, we process your data to conclude and execute the contract. Your data is processed on the basis of Art. 6 (1) (b) GDPR (contract fulfilment) and Art. 6 (1) (c) GDPR (compliance with legal storage requirements, § 257 HGB, § 147 AO). We process your data as long as the contract exists and there may still be claims arising from the contract, which is usually three years after the conclusion of the contract in the case of a purchase contract and three years after the termination of a service contract, in each case beginning on 31.12. of a year. In addition, we store accounting documents for a period of 10 years and commercial and business letters for a period of 6 years to fulfill our legal storage obligations. The storage period always begins at the end of the calendar year of receipt/dispatch of the commercial and business letter or the creation of the accounting document.

The data will not be passed on to third parties, with the exception of contract processors in accordance with Article 28 GDPR, with whom there is a contract for order processing. There is no transfer of data to a third country. Automated decision-making also does not take place.

D. Data subject rights for users of this website and customers.

If you have any questions regarding data protection, please contact our data protection officer, whom you can contact by e-mail at datenschutz@itelio.com or can also be reached by post at our address marked “Data Protection Officer”.

In addition, you are also entitled to legal data subject rights, which we list below. In these cases, too, please contact our data protection officer.

You have the right to:

  • gemäß Art. 15 DS-GVO Auskunft über Ihre von uns verarbeiteten personenbezogenen Daten zu verlangen. Insbesondere können Sie Auskunft über die Verarbeitungszwecke, die Kategorie der personenbezogenen Daten, die Kategorien von Empfängern, gegenüber denen Ihre Daten offengelegt wurden oder werden, die geplante Speicherdauer, das Bestehen eines Rechts auf Berichtigung, Löschung, Einschränkung der Verarbeitung oder Widerspruch, das Bestehen eines Beschwerderechts, die Herkunft ihrer Daten, sofern diese nicht bei uns erhoben wurden, sowie über das Bestehen einer automatisierten Entscheidungsfindung einschließlich Profiling und ggf. aussagekräftigen Informationen zu deren Einzelheiten verlangen;
  • gemäß Art. 16 DS-GVO unverzüglich die Berichtigung unrichtiger oder Vervollständigung Ihrer bei uns gespeicherten personenbezogenen Daten zu verlangen;
  • gemäß Art. 17 DS-GVO die Löschung Ihrer bei uns gespeicherten personenbezogenen Daten zu verlangen, soweit nicht die Verarbeitung zur Ausübung des Rechts auf freie Meinungsäußerung und Information, zur Erfüllung einer rechtlichen Verpflichtung, aus Gründen des öffentlichen Interesses oder zur Geltendmachung, Ausübung oder Verteidigung von Rechtsansprüchen erforderlich ist;
  • gemäß Art. 18 DS-GVO die Einschränkung der Verarbeitung Ihrer personenbezogenen Daten zu verlangen, soweit die Richtigkeit der Daten von Ihnen bestritten wird, die Verarbeitung unrechtmäßig ist, Sie aber deren Löschung ablehnen und wir die Daten nicht mehr benötigen, Sie jedoch diese zur Geltendmachung, Ausübung oder Verteidigung von Rechtsansprüchen benötigen oder Sie gemäß Art. 21 DS-GVO Widerspruch gegen die Verarbeitung eingelegt haben;
  • gemäß Art. 20 DS-GVO Ihre personenbezogenen Daten, die Sie uns bereitgestellt haben, in einem strukturierten, gängigen und maschinenlesebaren Format zu erhalten oder die Übermittlung an einen anderen Verantwortlichen zu verlangen;
  • gemäß Art. 7 Abs. 3 DS-GVO Ihre einmal erteilte Einwilligung jederzeit gegenüber uns zu widerrufen. Dies hat zur Folge, dass wir die Datenverarbeitung, die auf dieser Einwilligung beruhte, für die Zukunft nicht mehr fortführen dürfen;
  • gemäß Art. 21 DS-GVO Widerspruch gegen die Verarbeitung Ihrer personenbezogenen Daten einzulegen, soweit dafür Gründe vorliegen, die sich aus Ihrer besonderen Situation ergeben oder sich der Widerspruch gegen Direktwerbung richtet. Im letzteren Fall haben Sie ein generelles Widerspruchsrecht, das ohne Angabe einer besonderen Situation von uns umgesetzt wird. Sie haben die Möglichkeit, den Widerspruch telefonisch, per E-Mail, per Telefax oder an unsere zu Beginn dieser Datenschutzerklärung aufgeführte Adresse formlos mitzuteilen und

In accordance with Article 77 GDPR, you also have the right to lodge a complaint with a supervisory authority. As a rule, you can contact the supervisory authority of your usual place of residence or place of work or our headquarters; an overview of the supervisory authorities can be found here (https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html); the supervisory authority responsible for us is usually

Bavarian State Office for Data Protection Supervision
Promenade 27 (castle)
91522 Ansbach
Telephone: 0981/53-1300
Fax: 0981/53-5300
email: poststelle@lda.bayern.de
Home page: http://www.lda.bayern.de

E. Data protection information for applicants.

The information provided to us as part of your application will of course be kept confidential and, in compliance with data protection regulations, exclusively for

  • Durchführung des Bewerbungsprozesses sowie
  • ggf. zur Vorbereitung und Begründung eines Beschäftigungsverhältnisses verarbeitet.

Your data is processed on the basis of Section 26 BDSG (data processing for employment purposes) on the basis of Article 6 (1) (f) GDPR (legitimate interest). If there is no employment relationship, the data will be deleted after 6 months at the latest. We have a legitimate interest in being able to defend ourselves against liability claims under the General Equal Treatment Act (AGG) and therefore store the application documents for this period of time even after your application has been rejected.

Within our company, only the people involved in the application and selection process have access to your data. Your data will not be passed on to third parties. Automated decision-making does not take place.

Status: April 2024