awisto Data Privacy Policy:

How we protect your data

With this privacy policy and these data protection provisions, we inform you about the nature, scope and purposes of the processing of personal data within our website and the associated pages, functions and content, as well as external online presences such as our profiles on social media networks and platforms. Because we protect your data.

  • „awisto“ and/or „we“ refers to awisto business solutions GmbH, Mittlerer Pfad 4, 70499 Stuttgart, Germany, as the controller operating this website.
  • „Newsletter“ means newsletters, emails and other electronic notifications containing promotional information.
  • „Personal data“ or „data“ within the meaning of this privacy policy means personal data pursuant to Art. 4 No. 1 GDPR.
  • „You“ refers to the visitor or user of the website.
  • „Website“ means the homepage of awisto, including its subpages, accessible at the URL www.awisto.de.

In addition, the definitions set out in Art. 4 of the General Data Protection Regulation (GDPR) apply to the terms used in this privacy policy (e.g. „processing“, „controller“, etc.).

awisto collects, processes and uses your personal data in compliance with applicable data protection law. Whenever awisto collects, processes and/or uses personal data, this is always done for a specific purpose.

1. Controller

awisto business solutions GmbH,
represented by Managing Directors Ingolf Blocher and Kaj Mähner, Mittlerer Pfad 4,  70499 Stuttgart, Germany

2. Purposes and legal bases of data processing

2.1 We process the following types of data

  • Master data (e.g. first and last names, addresses)
  • Contact data (e.g. email, phone numbers)
  • Content data (e.g. text entries)
  • Usage data (e.g. websites visited, access times)
  • Meta/communication data (e.g. device information, IP addresses)

2.2 Purposes of processing personal data

  • Provision of our website, its functions and content,
  • Processing inquiries via our contact form,
  • Sending newsletters,
  • Processing job applications,
  • Security measures,
  • Marketing (including in the form of reach measurement)

The legal basis for obtaining consent is Art. 6 (1)(a) and Art. 7 GDPR; the legal basis for processing to perform our services, carry out contractual measures and respond to inquiries is Art. 6 (1)(b) GDPR; the legal basis for processing to fulfil our legal obligations is Art. 6 (1)(c) GDPR; and the legal basis for processing to safeguard our legitimate interests is Art. 6 (1)(f) GDPR. In the event that vital interests of the data subject or of another natural person require the processing of personal data, Art. 6 (1)(d) GDPR serves as the legal basis.

In addition, the further legal bases expressly mentioned in this privacy policy apply.

If, in the course of our processing, we disclose data to other persons and companies (processors or third parties), transfer it to them, or otherwise grant them access to the data, this is done only on the basis of a legal permission (e.g. if the transfer of data to third parties, such as payment service providers, is necessary pursuant to Art. 6 (1)(b) GDPR for the performance of a contract), you have given your consent, a legal obligation provides for this, or on the basis of our legitimate interests (e.g. when engaging processors, web hosts, etc.).

If we engage third parties to process data on the basis of a so-called data processing agreement, this is done on the basis of Art. 28 GDPR.

3. Data collection on this website

3.1 Cookies

„Cookies“ are small files that are stored on users‘ computers. Various pieces of information can be stored within cookies. A cookie primarily serves to store information about a user (or the device on which the cookie is stored) during or after their visit to an online service. Temporary cookies, also known as „session cookies“ or „transient cookies“, are cookies that are deleted after a user leaves an online service and closes their browser. Such a cookie may, for example, store the contents of a shopping cart in an online shop or a login status. Cookies that remain stored even after the browser is closed are referred to as „permanent“ or „persistent“ cookies. For example, the login status can be saved if users visit the service again after several days. Such a cookie can likewise store the interests of users, which are used for reach measurement or marketing purposes. „Third-party cookies“ are cookies offered by providers other than the controller operating the online service (otherwise, if they are only the controller’s own cookies, they are referred to as „first-party cookies“).

We may use temporary and permanent cookies and provide information about this within our privacy policy.

If users do not want cookies to be stored on their computer, they are asked to disable the corresponding option in their browser’s system settings. Stored cookies can be deleted in the browser’s system settings. Excluding cookies may lead to functional limitations of this online service.

A general objection to the use of cookies used for online marketing purposes can be declared for a large number of services, particularly in the case of tracking, via the US website http://www.aboutads.info/choices/ or the EU website http://www.youronlinechoices.com/. Furthermore, the storage of cookies can be prevented by disabling them in the browser settings. Please note that in this case not all functions of this online service may be usable.

We use so-called pixels, web beacons, clear GIFs or similar mechanisms (hereinafter referred to collectively as „pixels“). A pixel is an image file, or a link to an image file, that is inserted into the website code but is not located on your device (e.g. computer, smartphone, etc.). We primarily use pixels for the same reasons as cookies. For example, they allow us to count the number of users visiting our website or, if the user’s email program allows HTML, to determine whether and when an email was opened. Pixels help us to review and optimize the effectiveness of our website and advertising measures. We do not establish any link to a specific person through the use of pixels. Nor does any personal tracking take place. Pixels usually work in conjunction with cookies. If you have disabled cookies, the pixel will only determine an anonymous website visit.

Consent with Complianz

Our website uses the consent technology of Complianz to obtain your consent to the storage of certain cookies on your device, or to the use of certain technologies, and to document this consent in a manner compliant with data protection law. The provider of this technology is Complianz B.V., Kalmarweg 14-5, 9723 JG Groningen, Netherlands (hereinafter „Complianz“).

Complianz is hosted on our own servers, so that no connection is made to the servers of the Complianz provider. Complianz stores a cookie in your browser so that the consents you have given, or their withdrawal, can be attributed to you. The data collected in this way is stored until you ask us to delete it, you delete the Complianz cookie yourself, or the purpose for storing the data no longer applies. Mandatory statutory retention obligations remain unaffected. Complianz is used to obtain the legally required consents for the use of cookies. The legal basis for this is Art. 6 (1)(c) GDPR.

3.2 Server log files

We host our website on our own web server and, on the basis of our legitimate interests within the meaning of Art. 6 (1)(f) GDPR, collect data on every access to the server on which this service is located (so-called server log files). Access data includes the name of the website retrieved, file, date and time of retrieval, amount of data transferred, notification of successful retrieval, browser type and version, the user’s operating system, referrer URL (the previously visited page), IP address and the requesting provider. Servers in this sense are our web, content, application and database servers that we use to operate the website.

We automatically collect the IP address (from which you access the site), files (that you access), and the date and time of your access in order to identify and subsequently fix website errors, i.e. technical and functional deficiencies.
We store server log files for security reasons (e.g. to investigate cases of abuse or fraud) for a maximum period of xx and then delete them. Data whose further retention is required for evidentiary purposes will only be deleted once the respective incident has been finally clarified.

3.3 Contacting us via the contact form

When you contact us (e.g. via the contact form, email, telephone or social media), the user’s information is processed pursuant to Art. 6 (1)(b) GDPR in order to handle and process the contact request. Users‘ information is stored in the Dynamics 365 Customer Insights customer relationship management system („CRM system“).

When you submit a form, Dynamics 365 Customer Insights Journeys associates a behavioral analysis cookie ID with the incoming contact data. The cookie ID is assigned to a Dynamics 365 Customer Insights Journeys contact ID. This allows us to determine who has visited the website. This data is used to analyze behavior on our website and to enable a personalized experience for you. 

If you do not allow these cookies, you will not be able to access the contact form.

The provider of Dynamics 365 Customer Insights Journeys is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. Details on data processing can be found in Microsoft’s privacy policy: https://privacy.microsoft.com/de-de/privacystatement.

The company holds a certification under the „EU-US Data Privacy Framework“ (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards for data processing carried out in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. For further information, please see the following link provided by the provider: https://www.dataprivacyframework.gov/s/participant-search/participant-
detail?contact=true&id=a2zt0000000KzNaAAK&status=Active

We process incoming inquiries exclusively for the purpose of responding to them and delete incoming inquiries as soon as their further processing is no longer necessary, but at the latest after a period of 2 years. This period begins upon receipt of the respective inquiry on our servers. This deletion period does not apply if the person making the inquiry is an existing customer, or if an inquirer becomes an existing customer within the above-mentioned 2-year deletion period.

Data processing agreement
We have concluded a data processing agreement (DPA) for the use of the above-mentioned service. This is a contract required under data protection law that ensures that the service processes our website visitors‘ personal data only on our instructions and in compliance with the GDPR.

3.4 Newsletter

We send newsletters only with the consent of the recipients or on the basis of a statutory permission. If the contents of a newsletter are specifically described as part of the sign-up process, these are decisive for the recipients‘ consent. Otherwise, our newsletters contain information about our services and/or about us.

Signing up to receive our newsletters takes place using a so-called double opt-in procedure, i.e. after signing up you will receive an email asking you to confirm your sign-up. This confirmation is necessary to ensure that no one can sign up using someone else’s email address. Sign-ups to receive our newsletters are logged in order to be able to prove the sign-up process in a legally compliant manner. This includes storing the time of sign-up and confirmation, as well as the IP address. Changes to your data stored with the mailing service provider are also logged. It is sufficient to provide your email address to sign up for our newsletters. Optionally, you can provide a name during the sign-up process, e.g. for personal address in the newsletter.

We use Microsoft Dynamics 365 Customer Insights Journeys to send our newsletters. The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. Details on data processing can be found in Microsoft’s privacy policy: https://privacy.microsoft.com/de-de/privacystatement.

The company holds a certification under the „EU-US Data Privacy Framework“ (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards for data processing carried out in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. For further information, please see the following link provided by the provider: https://www.dataprivacyframework.gov/s/participant-search/participant-
detail?contact=true&id=a2zt0000000KzNaAAK&status=ActiveThe provider of the software is Microsoft Corp. A data processing agreement (DPA) has been concluded for this purpose.

Sending our newsletters and the associated success measurement is based on the consent of the recipients pursuant to Art. 6 (1)(a), Art. 7 GDPR in conjunction with Section 7 (2) No. 3 of the German Act Against Unfair Competition (UWG), or on the statutory permission pursuant to Section 7 (3) UWG. The logging of the sign-up process is based on our legitimate interests pursuant to Art. 6 (1)(f) GDPR. Our interest lies in using a user-friendly and secure newsletter system that serves our business interests, meets user expectations, and allows us to prove that consent has been given.

You are entitled to withdraw your consent to receive our newsletter for the future at any time. For this purpose, a clickable so-called „unsubscribe“ or withdrawal button is available at the end of every newsletter you receive. After a withdrawal, we are entitled to store email addresses used to receive our newsletters for up to three years on the basis of our legitimate interests before finally deleting them. This storage allows us to prove that consent was previously given. Any further processing of this data takes place exclusively for the purpose of defending against possible claims based on an allegedly missing, insufficient, or improperly given consent. Immediate deletion is possible if the previously given consent is confirmed at the same time as the corresponding request.

Newsletter – success measurement

The newsletters contain a so-called „web beacon“, i.e. a pixel-sized file that is retrieved from our server, or from the server of our mailing service provider if we use one, when the newsletter is opened. As part of this retrieval, technical information such as information about your browser and system, as well as your IP address and the time of retrieval, is initially collected.

This information is used for the technical improvement of the services based on the technical data, or for the target groups and their reading behavior based on their retrieval locations (which can be determined using the IP address) or access times. The statistical surveys also include determining whether the newsletters are opened, when they are opened, and which links are clicked. For technical reasons, this information can be attributed to individual newsletter recipients. However, it is neither our intention, nor, if used, that of the mailing service provider, to monitor individual users. Rather, these evaluations serve to help us recognize our users‘ reading habits and adapt our content to them, or to send different content according to the interests of our users.

3.5 Disclosure of data to third parties, data transfer to third countries

Unless stated otherwise in this privacy policy, data is not disclosed to third parties.

The transfer of personal data to a country or an international organization outside the EU or the EEA takes place, subject to statutory or contractual permissions, exclusively in accordance with the requirements of Art. 44 et seq. GDPR, i.e. that an adequacy decision of the EU Commission pursuant to Art. 45 GDPR exists for the transfer to the country concerned, that suitable safeguards for data protection pursuant to Art. 46 GDPR exist, or that binding internal data protection rules pursuant to Art. 47 GDPR exist.

4. Analytics tools

4.1 Statify

On the basis of our legitimate interests (i.e. interest in the analysis, optimization and economic operation of our online service within the meaning of Art. 6 (1)(f) GDPR), we use the WordPress plugin Statify by pluginkollektiv (https://pluginkollektiv.org/de/).

Statify does not use any personal data such as IP addresses. It counts page views, not visitors, and does not use cookies or other techniques to identify visitors. Statify records page clicks with date and origin and stores this data for 14 days. It is then deleted.

5. Online presence on social media networks and platforms, integration of third-party content and services

We maintain an online presence on social networks and platforms in order to be able to communicate with customers, prospective customers and users who are active there, and to inform them about our services. When you visit the respective networks and platforms, the terms and conditions and data processing policies of their respective operators apply.

Unless stated otherwise in our privacy policy, we process users‘ data if they communicate with us within the social networks and platforms, e.g. by writing posts on our online presence or sending us messages.

On the basis of our legitimate interests (i.e. interest in the analysis, optimization and economic operation of our online service within the meaning of Art. 6 (1)(f) GDPR), we integrate content or service offerings from third-party providers within our online service in order to embed their content and services, such as videos or fonts (hereinafter collectively referred to as „content“).

This always presupposes that the third-party providers of this content perceive the users‘ IP address, since without the IP address they would not be able to send the content to their browsers. The IP address is therefore required for the display of this content. We endeavor to use only such content whose respective providers use the IP address solely to deliver the content. Third-party providers may also use so-called pixel tags (invisible graphics, also referred to as „web beacons„) for statistical or marketing purposes. „Pixel tags“ can be used to evaluate information such as visitor traffic on the pages of this website. The pseudonymous information may also be stored in cookies on the users‘ devices and may contain, among other things, technical information about the browser and operating system, referring websites, visit time, and other details about the use of our online service, and may also be linked with such information from other sources.

5.1 YouTube with extended data protection

This website embeds videos from the YouTube website. The operator of the pages is Google Ireland Limited („Google“), Gordon House, Barrow Street, Dublin 4, Ireland.

We use YouTube in extended data protection mode. According to YouTube, this mode means that YouTube does not store any information about visitors to this website before they watch the video. However, the extended data protection mode does not necessarily rule out the disclosure of data to YouTube partners. For example, YouTube establishes a connection to the Google Marketing network regardless of whether you watch a video.

As soon as you start a YouTube video on this website, a connection is established to YouTube’s servers. This tells the YouTube server which of our pages you have visited. If you are logged into your YouTube account, you enable YouTube to directly associate your browsing behavior with your personal profile. You can prevent this by logging out of your YouTube account.
Furthermore, after starting a video, YouTube can store various cookies on your device or use comparable recognition technologies (e.g. device fingerprinting). In this way, YouTube can obtain information about visitors to this website. This information is used, among other things, to compile video statistics, improve user friendliness, and prevent attempted fraud.

After a YouTube video is started, further data processing operations may be triggered over which we have no influence.
The use of YouTube is in the interest of an appealing presentation of our online services. This constitutes a legitimate interest within the meaning of Art. 6 (1)(f) GDPR. Where a corresponding consent was requested, processing takes place exclusively on the basis of Art. 6 (1)(a) GDPR and Section 25 (1) TTDSG, insofar as the consent covers the storage of cookies or access to information on the user’s device (e.g. device fingerprinting) within the meaning of the TTDSG. Consent can be withdrawn at any time.

For more information about data protection at YouTube, please see their privacy policy at: https://policies.google.com/privacy?hl=de.
The company holds a certification under the „EU-US Data Privacy Framework“ (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards for data processing carried out in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. For further information, please see the following link provided by the provider: https://www.dataprivacyframework.gov/s/participant-search/participant-
detail?contact=true&id=a2zt000000001L5AAI&status=Active

6. Video and audio conferencing

Data processing

We use, among other things, online conferencing tools to communicate with our customers. The specific tools we use are listed below. If you communicate with us by video or audio conference via the internet, your personal data will be collected and processed by us and by the provider of the respective conferencing tool.
The conferencing tools collect all data that you provide/use in order to use the tools (email address and/or your telephone number). Furthermore, the conferencing tools process the duration of the conference, the start and end (time) of participation in the conference, the number of participants, and other „contextual information“ relating to the communication process (metadata).
In addition, the provider of the tool processes all technical data required to carry out the online communication. This includes, in particular, IP addresses, MAC addresses, device IDs, device type, operating system type and version, client version, camera type, microphone or speaker, and the type of connection.
If content is exchanged, uploaded, or otherwise made available within the tool, this is also stored on the servers of the tool providers. Such content includes, in particular, cloud recordings, chat/instant messages, voicemails, uploaded photos and videos, files, whiteboards, and other information shared while using the service.
Please note that we do not have full control over the data processing operations of the tools used. Our options depend largely on the corporate policy of the respective provider. For further information on data processing by the conferencing tools, please refer to the privacy policies of the tools used, which we have listed below this text.

Purpose and legal bases

The conferencing tools are used to communicate with prospective or existing contractual partners, or to offer certain services to our customers (Art. 6 (1)(b) GDPR). Furthermore, the use of these tools serves to generally simplify and speed up communication with us or our company (legitimate interest within the meaning of Art. 6 (1)(f) GDPR). Where consent has been requested, the use of the relevant tools is based on that consent; consent can be withdrawn at any time with future effect.

Storage period

Data collected directly by us via the video and conferencing tools will be deleted from our systems as soon as you ask us to delete it, withdraw your consent to storage, or the purpose for storing the data no longer applies. Stored cookies remain on your device until you delete them. Mandatory statutory retention periods remain unaffected.
We have no influence on the storage period of your data that is stored by the operators of the conferencing tools for their own purposes. For details on this, please contact the operators of the conferencing tools directly.

Conferencing tools used:

6.1 TeamViewer

We use TeamViewer. The provider is TeamViewer Germany GmbH, Jahnstr. 30, 73037 Göppingen. Details on data processing can be found in TeamViewer’s privacy policy: https://www.teamviewer.com/de/datenschutzerklaerung/.

Data processing agreement
We have concluded a data processing agreement (DPA) for the use of the above-mentioned service. This is a contract required under data protection law that ensures that the service processes our website visitors‘ personal data only on our instructions and in compliance with the GDPR.

6.2 Microsoft Teams

We use Microsoft Teams. The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. Details on data processing can be found in Microsoft Teams‘ privacy policy:
https://privacy.microsoft.com/de-de/privacystatement.

The company holds a certification under the „EU-US Data Privacy Framework“ (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards for data processing carried out in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. For further information, please see the following link provided by the provider: https://www.dataprivacyframework.gov/s/participant-search/participant-
detail?contact=true&id=a2zt0000000KzNaAAK&status=Active

Data processing agreement
We have concluded a data processing agreement (DPA) for the use of the above-mentioned service. This is a contract required under data protection law that ensures that the service processes our website visitors‘ personal data only on our instructions and in compliance with the GDPR.

7. Our own services

Handling of applicant data

We offer you the opportunity to apply to us (e.g. by email, by post, or via an online application form). Below, we inform you about the scope, purpose and use of your personal data collected during the application process. We assure you that the collection, processing and use of your data takes place in accordance with applicable data protection law and all other statutory provisions, and that your data is treated in strict confidence.

Scope and purpose of data collection

When you send us an application, we process your associated personal data (e.g. contact and communication data, application documents, notes taken during job interviews, etc.) to the extent required to decide on establishing an employment relationship. The legal basis for this is Section 26 of the German Federal Data Protection Act (BDSG) under German law (initiation of an employment relationship), Art. 6 (1)(b) GDPR (general contract initiation), and – if you have given your consent – Art. 6 (1)(a) GDPR. Consent can be withdrawn at any time. Within our company, your personal data is only disclosed to persons involved in processing your application. If your application is successful, the data you have submitted will be stored in our data processing systems on the basis of Section 26 BDSG and Art. 6 (1)(b) GDPR for the purpose of carrying out the employment relationship.

Data retention period

If we are unable to offer you a position, you decline a job offer, or you withdraw your application, we reserve the right to retain the data you have submitted for up to 6 months from the end of the
application process (rejection or withdrawal of the application) on the basis of our legitimate interests (Art. 6 (1)(f) GDPR). The data will then be deleted and the physical application documents destroyed. This retention serves, in particular, evidentiary purposes in the event of a legal dispute. If it is apparent that the data will be required after the 6-month period has expired (e.g. due to an impending or pending legal dispute), deletion will only take place once the purpose for further retention no longer applies.

Longer retention may also take place if you have given corresponding consent (Art. 6 (1)(a) GDPR) or if statutory retention obligations prevent deletion.

8. Deletion of personal data

We delete the data we process in accordance with Art. 17 and 18 GDPR, or restrict its processing. Unless otherwise stipulated in this privacy policy, we delete the data stored with us as soon as it is no longer required for the purpose of processing and no statutory retention obligations prevent deletion. If the data is not deleted because it is required for other, legally permissible purposes, its processing is restricted, i.e. the data is blocked and not processed for other purposes. This applies in particular to data subject to retention obligations under commercial or tax law.

German law currently provides for the following retention periods: 6 years pursuant to Section 257 (1) of the German Commercial Code (HGB) (commercial books, inventories, opening balance sheets, annual financial statements, commercial letters, accounting vouchers, etc.) and 10 years pursuant to Section 147 (1) of the German Fiscal Code (AO) (books, records, management reports, accounting vouchers, commercial and business letters, documents relevant for taxation, etc.).

9. Your rights

Pursuant to Art. 7 (3) GDPR, you have the right to withdraw consent given pursuant to Art. 7 (3) GDPR with effect for the future.

Pursuant to Art. 15 GDPR, you have the right to request confirmation as to whether the data concerned is being processed, as well as information about this data and further information and a copy of the data.

Pursuant to Art. 16 GDPR, you have the right to request the completion of data concerning you or the correction of inaccurate data concerning you.

Pursuant to Art. 17 GDPR, you have the right to request that the data concerned be deleted without delay, or alternatively, pursuant to Art. 18 GDPR, to request a restriction of the processing of the data.

Pursuant to Art. 20 GDPR, you have the right to receive the data concerning you that you have provided to us, and to request that it be transmitted to other controllers.

Pursuant to Art. 21 GDPR, you may object at any time to the future processing of data concerning you. This objection may, in particular, be directed against processing for the purposes of direct marketing.

Pursuant to Art. 77 GDPR, you have the right to lodge a complaint with the competent supervisory authority. The authority responsible for our company is the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg (Landesbeauftragte für Datenschutz und Informationsfreiheit Baden-Württemberg), postal address: Postfach 10 29 32, 70025 Stuttgart, office address: Königstraße 10a, 70173 Stuttgart, Tel.: 0711/615541-0, Fax: 0711/615541-15, Email: poststelle@lfdi.bwl.de. You can also find them on the internet at https://www.baden-wuerttemberg.datenschutz.de

10. Contact

For all data protection related matters, you can contact us as follows:

Email: info@awisto.de
Tel.: +49 (711) 490 534-0

Address:
awisto business solutions GmbH
Data Protection Officer
Mittlerer Pfad 4
70499 Stuttgart

awisto business solutions GmbH, last updated December 14, 2023

Nach oben scrollen