Privacy Statement of SIEGENIA-AUBI KG

This privacy statement is valid for the Internet presence of SIEGENIA-AUBI KG. We take the protection of your personal data very seriously. We would therefore like to provide you with information regarding the data protection in our company.

SIEGENIA-AUBI KG takes the protection of your personal data very seriously. We would like you to know when we store which data and how we use them. As a private-law company, we are subject to the provisions of the European General Data Protection Regulation (GDPR) or the German Federal Data Protection Act (BDSG) and the German Telemedia Act (TMG). We have taken both technical and organisation measures that ensure that the regulations concerning data protection are observed both by us and by external service providers.

We wish to point out that the data transmission in the Internet (e.g. with the communication via e-mail) can exhibit security gaps. Complete protection of data against access by third parties is not possible.

We only collect and use your personal data within the scope of the regulations of the Data Protection Act of the Federal Republic of Germany. Hereafter, we will inform you about the manner, extent and purposes of the collection and usage of personal data. You can retrieve this information from our website at any time.

 

1. General Information

By the use of our website, you give your consent to the collection, processing and usage of data in according with the following description. Our website can be visited without registration, on principle.

Whenever you visit our website or retrieve a file, our web server or the page provider will collect and save log information about these procedures for statistical purposes and will store these as „server log files“ (e.g. data and time of access, URL the referring website, retrieved file, volume of sent data, browser type and version, operating system and your IP address ). These data are evaluated anonymously for statistical purposes and finally deleted    .  These are not personal data. Personal data, especially name, address, telephone number or e-mail address are collected on a voluntary basis. There will be no transfer to third parties. An assignment of these data to a specific person or linking these data with other data is not possible for us. SIEGENIA, however reserves the right to check the server log files subsequently if concrete -reference points should indicate unlawful usage.

2. Name and address of the person who is responsible for the processing

The responsible person in terms of the General Data Protection Regulation, other data protection laws that are valid in the member states of the European Union and other regulations with data protection character is SIEGENIA-AUBI KG. You will find the contact data listed in the disclaimer.

3. Name and address of the data protection officer

The data protection officer who is responsible for the processing:

VIA Consult GmbH & Co. KG
Dr. Hanni Koch
Kurfürst-Heinrich-Strasse 10
57462 Olpe
Tel.: +49 2761 83668-0
E-Mail: siegenia.datenschutz@via-consult.de

Any person affected can contact our data protection officer directly at any time to ask questions or make comments with regard to data protection.

4. Personal data

4.1 Personal data in the contact form

On our page, we offer you the possibility to contact us via e-mail and/or via a contact form. Your personal data entered into the contact form (mandatory fields: surname, first name, e-mail-address, selection of company type as well as the relevant product group; optional entries are: company, address, telephone) and your message will only be forwarded to us, saved in our internal customer database and processed by the responsible person for the intended purpose of the processing of your contact enquiry. You can find the information on the customer database and the service provider used for this purpose in Point 9 of the privacy statement.

Moreover, via the source of supply search, you have the opportunity to contact our registered partner companies through our platform via a contact form. For this, you must enter your name, the reference, your e-mail address and your requests.

Your data will only be sent to the corresponding partner company for the purpose of processing your contact enquiry. In addition, you will receive a copy of your enquiry to the e-mail address you have entered. Furthermore, your data will be stored in our internal database so we may contact our partner companies for the evaluation of successful transactions and therefore measure the effectiveness of our platform. Alternatively, you can also contact our partner companies via your e-mail program using the specified e-mail address.

If you desire, we will delete these data after the termination of the written correspondence. There will be no transfer to third parties outside the group. There will be no matching of the data collected in this way with data that have possibly been collected by other components of our page.

Personal data comprise information which can be used to find out personal or factual circumstances about you (e.g. name, address, telephone number, date of birth or e-mail address). Information, with which we are unable to establish a relationship to your person (or only with an disproportionate amount of effort), e.g. due to the anonymization of the information, is not personal data.

Personal data, especially name, address, telephone number or e-mail address are collected only on a voluntary basis. We only collect personal data in compliance with the currently valid data protection regulations.

4.2. Personal Data in the Service Form

We are providing you with the option of contacting us by e-mail and/or via a contact form at out website for service enquiry purposes. Your personal data entered on the form (required fields: e-mail address, job/business; optional inputs: company, contact name, telephone number, subject) and your description are forwarded to us for the intended purpose of processing your enquiry, saved in our internal customer database and processed by the relevant party. You can find the information on the customer database and the service provider used for this purpose in Point 9 of the privacy statement. Your data will only be sent to the corresponding partner company for the purpose of processing your contact enquiry. In addition, you will receive a copy of your enquiry at the e-mail address you have entered. Furthermore, your data will be stored in our internal database so we may contact our partner companies for the evaluation of successful transactions and therefore measure the effectiveness of our platform. Alternatively, you can also contact our partner companies via your e-mail program using the specified e-mail address. If you desire, we will delete these data after the termination of the written correspondence. There will be no transfer to third parties outside the group. A matching of the data collected in this way with data that may be collected via other component parts of our website will likewise not be made.
 

4.3 Processing of personal data as part of the application process

We collect and process personal data of applicants for the purpose of processing the application procedure. If this should result in an employment relationship, the application data will continue to be used for this purpose, taking the legal guidelines into consideration. It should be noted that the data you have provided will not be stored anonymously, but will be made available to the responsible person(s) in Human Resources and the competent authorities in the company responsible for the position in the scope of the application procedure. By reason of additional consent, the application you have submitted can be stored and taken into consideration for other vacant positions in the company.

Insofar as you have applied for a position in one of our group companies, your data will be communicated to that company for this purpose. Insofar as you have applied for a position outside Germany, your data will be communicated for this purpose, also to the relevant country if necessary.

5. Subscription for the newsletter

We offer you the possibility to subscribe to our newsletter on our page. In this newsletter we will inform you about our offers at regular intervals. To be able to receive our newsletter, we need a valid e-mail address as well as the country and language so that we can dispatch the newsletter in the right language. Moreover, you have the opportunity to enter your surname and first name for the personal address in the newsletter. We will check the e-mail address you have entered to ensure that you are actually the owner of the e-mail address you have stated or are authorised to receive the newsletter. We will send you a confirmation mail for this purpose (double opt-In).

When you subscribe to our newsletter, we store your IP address   and the date and time of your subscription. This serves as a safeguard, on our part, in the event that a third party misuses your e-mail address and subscribes to our newsletter without your knowledge. We will not collect any further data. The data collected in this way are used solely for the subscription to our newsletter. There will be no transfer to third parties. There will be no matching of the data collected in this way with data that have possibly been collected by other components of our page. You can opt out of the subscription for this newsletter at any time. You can find details about this in the confirmation mail and in every individual newsletter or get in touch with us via the following contact data: marketing@siegenia.com.

Scnem

We use Scnem from SC-Networks GmbH, Würmstraße 4, 82319 Starnberg, Germany, to send our newsletter. This enables us to contact subscribers directly. In addition, we analyse your usage patterns to optimise what we offer.

Also, according to our service provider, the following personal data is collected by the provider with the aid of cookies and other tracking methods: information about your terminal equipment (IP address, device information, operating system, browser ID, information about the application you use to read your e-mails and other information about hardware and internet connection). Furthermore, usage data is collected, like date and time when you launched the e-mail / campaign and browser activities (e.g. which e-mails / websites were opened). The service provider requires this data to guarantee the security and reliability of the systems, to ensure compliance with the terms of use and to prevent misuse. This constitutes a legitimate interest of the service provider (pursuant to GDPR Article 6(1)(f)) and is necessary for performance of the contract (pursuant to GDPR Article 6(1)(b)). Furthermore, the service provider analyses performance data, such as e-mail delivery statistics and other communication data. This information is used to generate usage and performance statistics for the services.

Further Information about objection and deletion options with respect to the service provider can be found at: https://www.sc-networks.de/datenschutz/

6. Use of the "X-Cell Academy Maker" e-learning system for online and classroom training sessions

We use the "Academy Maker" e-learning tool from X-CELL AG, Kaistraße 2, 40221 Düsseldorf, to provide you with online and also classroom training sessions.

A registration in the system is required to reserve and book the training. For the purposes of this registration we process the following personal data from you: first name, last name, e-mail address and password. The processing is carried out on the basis of your consent in accordance with Art. 6 para. 1 lit. a of the GDPR. You can cancel your consent at any time. Should you cancel, your data and your user account are deleted immediately. Your registration data is stored until your consent is cancelled.

Once successfully registered, you can book online and/or classroom training sessions. In the course of this, we process the following additional data: invoice recipient, billing address, meals preference and optionally a remark. This processing is carried out in accordance with Art. 6 para. 1 lit. b of the GDPR (contractual performance) and also Art. 6 para. 1 lit. c of the GDPR (legal obligations).

When participating in an online training session, the following training data is also processed: type of course selected, time when conducted, number of attempts and the result of the training (passed failed). This information is needed for issuing participant certificates. The training data (including training results) is stored for the duration of the particular qualification process to provide proof of training courses passed and qualifications obtained. On completion of the qualification process or when it is known that this is not being pursued, the data is deleted as quickly as possible, provided that there is not any legal obligation to preserve records or a prolonged storage is not required.

Further information about data protection at X-Cell can be accessed at the following link: https://www.x-cell.com/deutsch/utility/datenschutz. 

7. Salesforce 

We use the service provider Salesforce Inc. in our company. Salesforce Tower, 415 Mission Street, 3rd Floor, San Francisco, CA 94105, United States. This is a software company that provides cloud-computing solutions for companies. 

You can find the privacy statement of our service provider here:

https://www.salesforce.com/de/company/privacy/full_privacy/.

The legal foundations on which our processing is based are Art. 6 Section 1 lit. a (Consent), Art. 6 Section 1 lit. b (Contract Fulfillment) and Art. 6 Section 1 lit. f (Justified Interest).

It cannot be excluded that personal data that is stored in Salesforce will be processed outside the European Economic Community.

CRM system

We use Salesforce for the management of our customer relationships. Personal data are stored to be able to carry out service, sales and marketing activities for our customers. The personal data we process are your first name and surname as well as business or private customer data.

Chatbot

We also use Salesforce as service provider for our Live Chatbot on our website. This Chatbot is available to our customers to contact SIEGENIA 24 hours a day. Personal data are stored to be able to provide you with the best possible help. The personal data we process are your first name and surname as well as your e-mail address or your telephone number. You also have the opportunity to upload a file via the Chat window. This file will also be stored. The data will be stored as a case in Salesforce. The responses will also be stored and analysed in order to train the Chatbot.
 

8. Use of cookies 

Our website uses cookies. They are small text files that enable the storage of specific user-related information on the end device of the user while he is using the website. Cookies enable the determination of the frequency of use and number of users visiting the pages, the analysis of the behavior of page usage, but also to make our offer more customer-friendly. Cookies remain stored beyond the end of a browser session and can be reactivated if you visit the page again.

The data sets do not contain any personal information. There will be no merging with any personal data you have provided.

Cookies save you from having to enter data multiple times, facilitate the transmission of specific contents and are needed for the registration in the closed area. You can refuse to accept cookies in your browser if you wish to prevent the use of cookies. You can find out how this works in the instructions of your browser manufacturer. We would like to point out that the deactivation of cookies could lead to a restriction in the range of functions of our offer.

8.1 Usercentrics 

We use the consent management service Usercentrics from Usercentrics GmbH, Sendlinger Str. 7, 80331 Munich, Germany (Usercentrics). This makes it possible to obtain and manage the consent of website users for data processing. The processing is required to meet a legal obligation (Art. 7 para. 1 GDPR), which we are subject to (Art. 6 para. 1 p. 1 lit. c GDPR). Usercentrics will receive your personal data and process it for us. The Usercentrics Consent Management Platform collects devise information, browser information, opt-in and opt-out data, date and time of the visit, requests for URLs and page path of the website as well as cookie preferences. This data is deleted as soon as it is no longer needed for record-keeping purposes and there are no legal obligations to retain it. The consent data (consent and revocation of consent) is stored for three years. Data is processed in the European Union.

Further information about objection and deletion options with respect to Usercentrics can be found at the following link: https://usercentrics.com/de/datenschutzerklaerung/

9. Photos

"The publication of photos in the Internet always requires the consent of the person photographed. Exceptions to this are cases defined in § 23 Section 1 i.V.m. Section 2 KunstUrhG no consent when it comes to

  • Images from the area of contemporary history,
  • Images in which persons only appear as accessories besides a landscape or other location,
  • Images of meetings, parades and similar occurrences in which the displayed persons have taken part, or
  • Images that have not been commissioned as long as the distribution or exhibition serves a highly artistic purpose."

(Source of the citation: State Officer for Data Protection and Freedom of Information North Rhine Westphalia)

Note: If you should be displayed as a person on a photo, which we have published in the scope of documentation on our website according to listed point 3 (see above), but you do not agree to the publication of this photo, please contact us or send an e-mail to marketing@siegenia.com.

10. Use of Google and other technologies

10.1 Google Analytics

This website uses Google Analytics, a web analysis service of Google Inc. („Google“). Google Analytics uses so-called „Cookies“, Text files, which are stored on your computer and enable the analysis of your usage of the website. The information about your use of this website, created by the cookie, is usually transferred to a Google server in the USA where it is stored.

In case of the activation of the IP anonymization on this website, your IP address will be shortened beforehand, however, within the member state of the European Union or in other contracting states to the agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. On behalf of the provider of this website, Google will use this information to evaluate your use of the website, to compile reports about the website activities and to provide further services associated with website and Internet usage for the website providers.

The IP address transmitted from your browser in the scope of Google Analytics will not be merged with other data by Google. You can opt out of the storage of cookies by making a corresponding setting in your browser software; However, we wish to point out that you will not be able to use all functions of this website in this case. Moreover, you can prevent the recording of the data created by the cookie and related to your use of the website (incl. your IP address) to Google, as well as the processing of these data by Google, by downloading and installing the browser plugin, available from the following link (http://tools.google.com/dlpage/gaoptout?hl=en).

You can prevent the collection by Google Analytics by clicking on the following link. An Opt-Out cookie will be set, which prevents the future collection of your data when you visit this website:

Google Analytics deactivate

Our website uses Google Consent Mode, a consent mode for websites and apps that is provided by the web analytics service from Google LLC. The data controller for users in the EU/EEA is Google Ireland Limited, Google Building Gordon House, 4 Borrow St, Dublin, D04 E5W5, Ireland.
As you can see from our privacy policy, we use Google Analytics and Google Tag Manager, which allows us to track activity on our website. We use this information to understand user behaviour on the website. We will only track your activity if you have consented to this via the cookie banner in accordance with GDPR Article 6(1)(a). If consent has not been given to personalised tracking, Consent Mode by Google uses pings to perform anonymised analysis without the use of cookies. We process this data in accordance with the legal basis of legitimate interest pursuant to GDPR Article 6(1)(f).
The following data is processed:

  • Operational information: timestamp, user agent, referrer URL
  • Aggregated information: indicates whether the current page or a previous page in the user's navigation history on the website contains ad click information in the URL (e.g. GCLID/DCLID), Boolean information regarding consent status, a random number generated on each page load and information about the consent management platform used by the website owner (e.g. developer ID)

For more information about Consent Mode, please see: https://support.google.com/analytics/answer/9976101

You will find more detailed information on the terms and conditions of use and data protection under http://www.google.com/analytics/terms/de.html or under https://www.google.de/intl/de/policies/. We wish to point out that, on this website, Google Analytics has been extended by the code „anonymizeIp“ in order to ensure anonymized collection of IP addresses (so-called IP masking).

10.2 Google Tag Manager 

We use the Google Tag Manager service from Google. Google Tag Manager is an assistance service and processes personal data itself only for technically requisite purposes. Google Tag Manager loads other components that may in turn collect data under certain circumstances. It does not access this data itself. 

10.3 Google Translate 

The automatic translation function in the sidebar of this website is carried out by Google Translate, a third-party provider over which we have no influence. The computer generated translations agree at times only approximately with the original contents of this website. 

The translations generated should not be regarded as accurate and may occasionally contain incorrect or even offensive terms. We do not guarantee the accuracy, reliability or up-to-dateness of any information translated by this system and do not accept any liability for damages that may arise from it. Furthermore, some applications, files or elements, including graphics, photos or PDFs, may not be translatable. 

Google captures, stores and processes information in order to improve the services it provides to users. This includes, for example, the language that you speak, but it covers your personal surfing or online behaviour. 

Further information about Google Translate can be found at the following sites: https://translate.google.com/ sowie http://translate.google.com/manager/website/?hl=de und http://www.google.com/policies/privacy/ 

10.4 Google Ads

Google Ads is an online advertising tool provided by Google Ireland Limited (‘Google’), Gordon House, Barrow Street, Dublin 4, Ireland. 

Google Ads allows us to display adverts in the Google search engine or on third-party websites when users enter certain search terms on Google (keyword targeting). Furthermore, the user data held by Google (e.g. location data and interests) can be used to display targeted adverts (target group targeting). As the website administrator, we can perform a quantitative evaluation of this data by analysing, for example, which search terms resulted in our adverts being displayed and how many of these adverts generated clicks. 

The use of this service is subject to your consent pursuant to GDPR Article 6(1)(a) and Section 25(1) of the German Telecommunications Digital Services Data Protection Act (TDDDG). You can revoke consent at any time. 

Data transfer to the USA is based on the standard contractual clauses of the EU Commission. You can find details here: https://policies.google.com/privacy/frameworks und https://privacy.google.com/businesses/controllerterms/mccs/ 

10.5 Google Ads Remarketing 

This website used the functions of Google Ads Remarketing. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland. 

With Google Ads Remarketing we are able to arrange for people who interact with our online offer particular target groups in order to then have interest based advertising displayed to them in the Google ads network (remarketing or retargeting). 

In addition, the advertising target groups created with Google Ads Remarketing can be linked with the functions of Google across devices. In this way, interest based, personalised advertising messages that were matched for you, subject to your earlier use and surfing behaviour, on a terminal device (e.g. mobile phone) can be displayed on another of your terminal devices (e.g. tablet or PC). 

If you have a Google account, you can object to the personalised advertising at the following link: https://www.google.com/settings/ads/onweb/ 

The use of this service is subject to your consent pursuant to GDPR Article 6(1)(a) and Section 25(1) of the German Telecommunications Digital Services Data Protection Act (TDDDG). You can revoke consent at any time. 

Further information and the data protection regulations can be found in Google's data protection declaration at: https://policies.google.com/technologies/ads?hl=de 

10.6 Amazon Web Services 

The provider is Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, 1855 Luxembourg (hereinafter AWS). 

When you visit our website, your personal data is processed on AWS servers. Personal data may also be transmitted to the AWS parent company in the United States. Data transmission to the US is governed by the EU's standard contractual clauses. Details can be found here: https://aws.amazon.com/de/blogs/security/aws-gdpr-data-processing-addendum/. 

For more information, please see the AWS privacy policy: https://aws.amazon.com/privacy/?nc1=h_ls. 

The use of AWS is governed by GDPR Article 6(1)(f). We have a legitimate interest in ensuring that our website is displayed as reliably as possible. If the appropriate consent has been requested, the processing of this data is strictly in accordance with GDPR Article 6(1)(a) and TDDDG Section 25(1), provided that the consent granted includes the storage of cookies or access to information in the user's end device (e.g. device fingerprinting) as per the TDDDG. You can revoke consent at any time. 

The company is certified according to the ‘EU-US Data Privacy Framework’ (DPF). The DPF is an agreement between the European Union and the United States, which is designed to ensure compliance with European data protection standards when processing data in the United States. Every company certified according to the DPF undertakes to comply with these data protection standards. You can receive further information about this from the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt0000000TOWQAA4&status=Active 

10.7 Microsoft 

We use the technologies of Microsoft Ireland Operations Ltd., One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland ("Microsoft") shown below. The data processing is carried out on the basis of an agreement between the parties jointly responsible in accordance with Art. 26 GDPR. The information automatically collected by the Microsoft technologies via your use of our website is, as a rule, transferred to a server of the Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA, and stored there. The European Commission does not have an adequacy decision for the USA. Our cooperation with it is based on standard data protection clauses of the European Commission. Further information about the data processing by Microsoft can be found in Microsoft's data privacy statements. 

10.8 Microsoft Advertising 

For advertising purposes in the Bing, Yahoo and MSN search results and also on the websites of third parties, the so-called Microsoft Advertising Remarketing Cookie is set when visiting our website, which automatically enables interest based advertising by collecting and processing data (IP address, time of visit, device and browser information and information about your use of our website) and by means of a pseudonymous cookie ID and on the basis of the pages you visit. 

10.9 LinkedIn Insight Tag

We use LinkedIn Insight Tag for marketing purposes. LinkedIn sets cookies in the user's browser. In addition, LinkedIn also collects data such as the URL, referrer URL, device properties, browser properties and IP address. 

LinkedIn anonymises this data within seven days. After a period of 90 days, the provider deletes the data. We as the site operator do not receive any personal data. We only receive summarised reports about the demographics of our target group and the performance of our displayed ads. In so doing, we receive information about criteria, like business, job description, company size, career level and location of the site visitor. 

The processing of this is governed by GDPR Article 6(1)(a). We obtain your consent via the cookie banner. You can revoke your consent at any time by changing the cookie settings. 

10.10 Facebook Pixel 

This website uses the visitor activity tracker Pixel from Facebook/Meta to measure conversions. The provider of this service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. 

Using this tool enables us to track the behaviour of site visitors after they have been redirected to the provider's website by clicking on an advert. This allows us to evaluate the effectiveness of the adverts for statistical and market research purposes and to optimise advertising measures in the future. The data collected is stored under a pseudonym for us as the operator of this website; we cannot use it to draw any conclusions about the identity of the user. The data is stored and processed by Facebook, however, which means that it is possible to link it to the respective user profile and Facebook can use the data for its own advertising purposes, in accordance with the Facebook data usage policy (https://en-gb.facebook.com/privacy/policy/). As a result, Facebook can enable the switching from ads on sites of Facebook and also outside of Facebook. As the website administrator, we have no influence over how this data is used. 

We process the data within the European Union. However, it is not possible to exclude the possibility that Meta may also process the data outside the European Union/European Economic Area. The use of this service is subject to your consent pursuant to GDPR Article 6(1)(a) and Section 25(1) of the German Telecommunications Digital Services Data Protection Act (TDDDG). You can revoke consent at any time. The cookie is stored for one year. 

Insofar as personal data is collected on our website using the tool described here and is transmitted to Facebook, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland are jointly responsible for this data processing (GDPR Article 26). This joint responsibility is limited solely to the collection of data and the transmission of this data to Facebook. Any processing by Facebook that takes place after the data has been transmitted is not covered by this joint responsibility. The obligations to which we are jointly subject have been defined in a joint processing agreement. The wording of the agreement can be found at: https://www.facebook.com/legal/controller_addendum. Under this agreement, we are responsible for providing data protection information when using the Facebook tool and for implementing the tool on our website in a manner that is secure under data protection law. Facebook is responsible for the data security of Facebook products. You can assert your rights as a data subject (e.g. requests for information) regarding the data processed by Facebook by contacting Facebook directly. If you assert your data subject rights with us, we are obliged to forward them to Facebook. 

Data transmission to the US is governed by the standard contractual clauses of the European Commission. For details, see: https://www.facebook.com/legal/EU_data_transfer_addendum and https://de-de.facebook.com/help/566994660333381. You can find more information about protecting your privacy in Facebook's privacy information: https://en-gb.facebook.com/privacy/policy/. You can also disable the ‘Custom Audiences’ remarketing function in the ad settings section at https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen. You must be logged in to Facebook to do that. If you do not have a Facebook account, you can disable usage-based advertising from Facebook on the European Interactive Digital Advertising Alliance website: https://www.youronlinechoices.com/uk/your-ad-choices/. 

The company is certified according to the ‘EU-US Data Privacy Framework’ (DPF). The DPF is an agreement between the European Union and the United States, which is designed to ensure compliance with European data protection standards when processing data in the United States. Every company certified according to the DPF undertakes to comply with these data protection standards. You can receive further information about this from the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt0000000GnywAAC&status=Active

11. Unity Analytics

We use the analytical service, Unity Analytics, for digital product presentation in the SIEGENIA world. The service provider is the American company Unity Technologies, 30 3rd Street, San Francisco, CA 94103, USA.

We use analytical services to enable statistical usage measurements and the formation of user categories. Data for the evaluation of user habits are collected via the analytical services we employ.

The analysis is performed with justified interest according to Art. 6 Section 1 Letter f) GDPR. Our justified interest is obtained from the economical usability of the findings resulting from the statistics and user categories. We do not merge this information with other personal data. We do not know your identity and will not take any steps to determine this.

The data collected by Unity Analytics will be transmitted in anonymised form and have the objective to statistically determine the user intensity, the number of usages and users of the SIEGENIA world and their surfing habits. The statistics help us to track and improve the usage of our offer as well as to create user categories. The user categories form the foundation for an alignment of advertising material or advertising action based on interests.

You can find the complete Unity privacy statement (in English) here:
https://unity3d.com/legal/privacy-policy

Additional information about the SIEGENIA world app

We provide our customers with a SIEGENIA world app. The SIEGENIA world is a sustainable virtual presentation platform, which shows with appealing animations the appearance, workings and design variations of our products in detail. You have to sign up for it in the app. On doing so, the following are collected: first name, last name, e-mail address. Usage data and diagnostic data are linked with your account in the process. We process this data to be able to refine our products and services as effectively as possible. The legal basis on which we process this data is Art. 6 para. 1 lit. a GDPR, i.e. consent. You have the right to revoke your consent at any time. Please take into account that after which the use of the app is no longer possible. 

Within the app we use Unity Analytics from the American provider Unity Technologies Inc., 30 3rd Street, San Francisco, CA 94103, USA. This involves the tracking service that we use. In this connection, a data transfer to the USA may result. The data processing is therefore based on the standard contractual clauses posted by the company. You can examine them here: https://unity.com/legal/unity-data-processing-addendum-dpa. Further information can be found in the provider's data protection declaration: https://unity.com/legal/game-player-and-app-user-privacy-policy. 

For SIEGENIA world we use the Auth0 by Okta service from Auth0 Inc. (10800 NE 8th Street, Suite 700, Bellevue, WA 98004, USA) and from Okta Inc. (100 First Street, Floor 6, San Francisco, CA, 94105 USA). Involved here is an authentication service by which the identity of the customer can be guaranteed. Auth0 processes data from you, whereby a forwarding outside of the European Economic Area cannot be precluded. The provider has been certified according to the Data Privacy Framework. The compliant transfer of data to the USA is controlled at present as a result. More about the data which are processed by the use of Auth0 can be found in the data protection declaration at https://www.okta.com/privacy-policy/.

12. BIM

We have services on our website from BIMobject (BIMobject AB, Nordenskiöldsgatan 24, 21119 Malmö, Sweden). Building Information Modeling (BIM) is a method by which 3D models of buildings or infrastructure can be created. We use the service so that you have the option of planning the use of our products in a 3D model. In so doing, the provider processes every piece of data which you place at BIMobject's disposal. Processing of your data is based on Art. 6 para. 1 lit. a GDPR, i.e. consent. You have the right to cancel your consent via the cookie banner at any time.

Further information about BIMobject's data processing can be found in the provider's data protection declaration: https://business.bimobject.com/privacy-policy/

13. Social media channels

We create online presences inside social networks to be able to communicate with the active interested persons and users and to be able to provide these with information about us.

User data can be processed by the service provider beyond the area of the European Union. This could involve risks for users because the assertion of user rights, for example, could be made more difficult.

The data of users are usually processed by the service provider for market research and advertising purposes. For example, interests of users resulting from their behaviour can be used to place advertisements inside and outside the platform, which could correspond to the interests of users. Cookies are usually saved on the computers of users for this purpose. Furthermore, data can also be saved in the user profiles regardless of the devices used (especially when the users are members of the respective platforms and are logged in to these platforms).

The social media page you have visited offers you the possibility to react to our articles, to comment on our articles, to create a user post yourself and to send us private messages concerning personal matters. The data provided by you in this context and accessible to us where necessary (e.g. user name, images, interests where necessary, contact data) will be used by us exclusively for the purpose of customer and interest communication. It is in our interest to offer you a platform on which we can show you current information and which will help you to address your concerns to us and help us to respond to your concerns as quickly as possible.

We undertake no further data processing via the site beside the basic functions. Please note that the service provider can use tracking tools and cookies independently of our use of the site.

We will inform you below about our processing of your personal data in the scope of the online presences we provide. In its judgement of 5th June 2018 the ECJ (European Court of Justice) confirmed the mutual responsibility of the service provider and the website operator.

Also in the case of information requests and the assertion of user rights, we wish to point out that these can be asserted most effectively from the providers. Only the providers have respective access to the data of users and can take the corresponding measures directly and give information. Please contact us if you should need help.

For a detailed presentation of the respective processing and the possibilities to object (opt-out options), we refer you to the following linked information of the provider(s) we have commissioned.

13.1 Use of social plugins

Social plugins are used on our website. You will recognize the plugins of the respective providers by their logo. Whenever you visit a page with such a plugin, the provider of the service will be informed which pages you are visiting. This could enable the creation of user profiles of the user out of the processed data. Therefore, we have no influence on the extent of the data that is collected by an activated plugin and how this is used by the provider. There is also a possibility of the service providers attempting to store cookies on the computer used.

When you are logged in with your relevant account, the provider is also able to assign your surf behaviour to your personal profile.  You can prevent this by logging out of your account beforehand and deleting any set cookies.

You can find out which concrete data are collected and how these are used in the privacy statement of the respective providers.

We use the following plugins on our website:

13.2 Use of YouTube

We use components (videos) of the YouTube company (YouTube LLC, 901 Cherry Ave., San Bruno, CA 94066, USA) eon our website. The responsible party is Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland, for users of Google services who have their usual domicile in the European Economic Area or Switzerland. We have activated YouTube's extended data protection mode. When you visit a site which has an embedded video, a connection is made to the YouTube servers and as a result, the content is shown on the website via communication to your browser. According to YouTube's information, in the "extended data protection mode" data to the YouTube server is transmitted only while you are watching the video. If you are logged in to YouTube at the same time, this information is correlated with your member account at YouTube. You can prevent this by signing out of your member account before visiting our website. Further information about YouTube's data protection is provided by Google at the following link: https://www.google.de/intl/de/policies/privacy/.

13.3 Administration of social media channels

We have appointed Hootsuite for the administration of our social media channels with the purpose of planning, creation and administration of the post in social media. Advance planning is possible. The entire communication with the users in social media can be controlled via the portal. In the process, your data will be forwarded to the third country Canada, for which, however, in compliance with Art. 45 Section 3 DSGVO, a so-called appropriateness resolution of the European Commission exists which enables the transmission of personal data.

The responsible authority for the processing is:

Hootsuite Inc.
111 East 5th Avenue
Vancouver, BC, Canada V5T 4L1.

14. Note on external links

This website contains links to websites of third parties ("external links"). These websites are subject to the liability of the respective provider. The provider has therefore checked the third party contents at the initial linkage of the external links for any legal violations. No legal violations were evident at this time. The provider has no influence at all on the current and future design nor on the contents of the linked pages. The setting of external links does not mean that the provider adopts the contents of the reference or link as his own. A continual check of the external links is unreasonable for providers unless there are concrete indications of legal violations. However, in case of the knowledge of legal violations, such links will be deleted without delay.

15. Legal basis for the processing

If we obtain consents for specific processing procedures, these are based on Art. 6 I lit. a DS-GVO. If the processing of personal data is necessary for the fulfilment of a contract e.g. for a delivery of goods or for pre-contractual measures e.g. for inquiries, the processing is based on Art. 6 I lit. b DS-GVO. If our company is subject to a legal obligation that necessitates the processing of personal data, for example, for the fulfilment of fiscal obligations, the processing is based on Art. 6 I lit. c DS-GVO. Provided that the processing of personal data is not based on any of the aforementioned legal grounds, we process data in such a way that the justified interests of our company are safeguarded (enhancement of the performance of business activities). We always ensure that no legitimate interests of the person concerned, which take precedence over our justified interests, are in conflict.

16. Duration for which the personal data are stored

The duration of storage of personal data is based on the statutory retention periods. As soon as the purpose for which the data have been recorded ceases to be relevant, the data will be deleted after the expiry of this period. 

17. Right to information and right of revocation, right to complaint and right to restriction of processing, to rectification and deletion

You have the right at any time to obtain information about data stored by us and the purpose of the storage. You can revoke your consent to the storage or usage of your personal data at any time in written form. Besides the right of revocation, you also have the right to demand the rectification as well as the restriction of the processing and blocking or deletion of your data.

Please refer to our data protection officer for further information.

You have the right to refer to the appropriate supervisory authority in case of complaint (for NRW: The State Officer for Data Protection and Freedom of Information North Rhine Westphalia in Düsseldorf).

18. Security

We employ technical and organisation security measures to protect um any personal data you have made available to us against incidental or intentional manipulation, loss, destruction or against access by unauthorised persons. Our security measures will be continually improved and adapted in accordance with state-of-the-art technology.