Data protection and privacy
1. name and address of the person responsible
The controller within the meaning of the EU General Data Protection Regulation (GDPR) and other national data protection laws of the member states as well as other data protection regulations is the:
LM IT Services AG
Represented by the Executive Board:
Marc Liepe, Manuel Mummert, Claus Haase, Alexander Plato, Antje Henneke, Ralf Minning
Rheiner Landstr. 189
49078 Osnabrück
Germany
Tel: +49 541 40 66 40
e-mail: info@lm-ag.de
Website: www.lm-ag.de
2. name and address of the data protection officer
The data protection officer of the controller is
Dr Marija Stambolieva
Postal address - as above
e-mail: datenschutz@lm-ag.de
3. general information on data processing
3.1 Scope of the processing of personal data
We collect and use our users' personal data only to the extent necessary to provide a functional website and our content and services. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this is done.
3.2 Legal basis for the processing of personal data
The collection and use of personal data from our users generally only takes place with the user's consent. An exception applies in cases where the processing of data is permitted by legal regulations. To the extent that we obtain the consent of the data subject for the processing of personal data, Article 6 (1) lit. a of the EU General Data Protection Regulation (GDPR) serves as the legal basis for the processing of personal data. When processing personal data that is necessary for the fulfilment of a contract to which the data subject is party, Article 6 (1) lit. b GDPR serves as the legal basis. This also applies to processing operations that are necessary to carry out pre-contractual measures. To the extent that the processing of personal data is necessary to fulfil a legal obligation to which our company is subject, Article 6 (1) lit. c GDPR serves as the legal basis. In cases where processing personal data is necessary to protect the vital interests of the data subject or of another natural person, Article 6 (1) lit. d GDPR serves as the legal basis. If the processing of personal data is necessary to protect a legitimate interest of our company or of a third party and the interests, fundamental rights and fundamental freedoms of the data subject do not outweigh the aforementioned interest, then Article 6 (1) lit. f GDPR serves as the legal basis for the processing.
3.3 Data erasure and storage duration
The data subject's personal data will be erased or blocked as soon as the purpose for storing it no longer applies. Data may also be stored if this has been provided for by the European or national legislator in EU regulations, laws or other provisions to which the controller is subject. The data will also be blocked or deleted if a storage period prescribed by the aforementioned standards expires, unless there is a need for further storage of the data for the conclusion or fulfilment of a contract.
3.4 Transfer of data to external third parties
We only disclose personal data to third parties where it is necessary for the performance of a contract (Art. 6(1)(b) GDPR), where we are legally obliged to do so (Art. 6(1)(c) GDPR), where we have a legitimate interest in disclosure under Art. 6(1)(f) GDPR, or where you have given your consent under Art. 6(1)(a) GDPR. When using processors, we only disclose personal data on the basis of a valid contract for order processing. In the event of joint processing, a contract for joint processing will be concluded. Please note that with data processing in third countries outside the EU, there is generally no level of protection equivalent to European data protection law. Your data will only be transferred if you have expressly consented or if one of the following exceptions applies: an adequacy decision by the EU Commission exists or the processing is based on appropriate safeguards, particularly the standard data protection clauses established by the EU Commission.
3.5 Data security
We use SSL or TLS encryption to protect your confidential data when it is sent to us as the site operator. You can recognise an encrypted connection by the address line of your browser, which changes from "http://" to "https://", and by the lock symbol in your browser line. However, it is important to note that data transmission over the Internet can have security gaps, which means that complete protection against access by third parties cannot be guaranteed. Nevertheless, we have taken appropriate technical and organisational measures to ensure the confidentiality, integrity and availability of your data.
4. provision of the website and creation of log files
4.1 Description and scope of data processing
Each time our website is accessed, our system automatically and temporarily collects data and information from the computer system of the accessing computer.
The following data is collected:
- Information about the browser type and version used
- The IP address of the user
- Date and time of access
The data is also stored in the log files of our system. This does not affect the user's IP addresses or other data that allow the data to be assigned to a user. We do not store this data.
4.2 Legal basis for data processing
The legal basis for temporarily storing the data is Article 6(1)(f) of the GDPR.
4.3 Purpose of data processing
The system's temporary storage of the IP address is necessary in order to deliver the corresponding website to the user's computer. For this purpose, the user's IP address must be stored for the duration of the session. Our legitimate interest in data processing pursuant to Art. 6(1)(f) GDPR also lies in this purpose.
4.4 Storage period
The data is deleted as soon as it is no longer required to fulfil the purpose for which it was collected. In the case of the collection of data for the provision of the corresponding website, this is the case when the respective session has ended.
4.5 Possibility of objection and removal
The collection and storage of data for the provision of the corresponding website is absolutely necessary for the operation of the website. Consequently, there is no possibility for the user to object.
5. use of cookies
5.1 Description and scope of data processing
We use cookies on the website. Cookies are text files that are stored in the Internet browser or by the Internet browser on the user's computer system. When a user accesses a website, a cookie may be stored on the user's operating system. This cookie contains a characteristic string of characters that enables the browser to be uniquely identified when the website is called up again.
We also use cookies on our website that enable an analysis of the user's surfing behaviour. The following data can be transmitted in this way:
- Frequency of page views
- Utilisation of website functions
The user data collected in this way is pseudonymised by technical precautions. It is therefore not possible to assign the data to the calling user. The data is not stored together with other personal user data. When accessing our website, users are informed by an information banner about the use of cookies for analysis purposes and referred to this privacy policy. In this context, there is also a reference to how the storage of cookies can be prevented in the browser settings.
5.2 Legal basis for data processing
The legal basis for the processing of personal data using cookies is Art. 6 para. 1 lit. f GDPR (technically necessary cookies) and Art. 6 para. 1 lit. a GDPR (optional cookies).
5.3 Purpose of data processing
Cookies are technically necessary, as certain website functions would not work without them. The purpose of using analytics cookies is to improve the quality of our website and its content. Through the analysis cookies, we learn how the website is used and can thus constantly optimise our offer. We find out which pages are the most popular, where the focus needs to be adjusted and which pages need to be optimised.
5.4 Storage period, objection and removal options
Cookies are only stored on the user's computer and transmitted to our website if the user agrees to their storage by clicking on "accept" in our cookie notice. Otherwise, no cookies will be set. As a user, you therefore have full control over the use of cookies. You can deactivate or restrict the transmission of cookies by changing the settings in your Internet browser. Cookies that have already been saved can be deleted at any time. This can also be done automatically. If cookies are deactivated for our website, it may no longer be possible to use all the functions of the website to their full extent.
6. google analytics
This website uses Google Analytics, a web analytics service provided by Google Ireland Limited, Gordon House Barrow Street Dublin 4, Ireland (hereinafter: Google).
6.1 Scope of the processing of personal data
Google Analytics uses „cookies“, which are text files saved on your computer, enabling an analysis of your use of the website.
The information generated by the cookie about your use of our website, such as:
- Browser type / version
- Operating system used
- Referrer URL (the previously visited page)
- Host name of the accessing computer (IP address)
- Time of the server request
Since Google servers are distributed worldwide, a transfer to third countries (for example to the USA) cannot be completely ruled out. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data. We have also added the code "anonymiseIP" to Google Analytics on this website. This guarantees that your IP address is masked so that all data is collected anonymously. Only in exceptional cases is the full IP address transmitted to a server in a third country and truncated there.
6.2 Legal basis for data processing
The legal basis for the processing of your data is the consent you have given via the cookie consent tool (Art. 6 para. 1 sentence 1 lit. a) GDPR).
6.3 Purpose of data processing
On behalf of the operator of this website, Google will use this information to evaluate your use of the websites, to compile reports on website activities, and to provide other services to the website operator related to website and internet usage. We use Google Analytics for the purpose of improving the quality of our website and its content. Through the analysis cookies, we learn how the websites are used and can thus continuously optimise our offering. We find out which pages are most popular, where focus needs to be directed, and which pages need to be optimized.
6.4 Storage period
The storage duration of Google Analytics cookies can be found in the settings of our cookie notice under "Analytics, Show details".
6.5 Possibility of objection and removal
You can prevent the saving of cookies by adjusting your browser software accordingly; however, we would like to point out that in this case you may not be able to fully use all functions of this website. You can also prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) by Google, as well as the processing of this data by Google, by downloading and installing the browser plug-in available at the following link: http://tools.google.com/dlpage/gaoptout?hl=de
7 Google Ads
This website uses the online advertising and analysis service Google Ads to provide and analyse advertisements. The Google Ads services are provided by Google Ireland Limited, Gordon House Barrow Street Dublin 4, Ireland (hereinafter: Google).
7.1 Scope of the processing of personal data
Google Ads uses so-called „cookies“, text files that are stored on your computer and allow an analysis of your use of the website.
The information generated by the cookie about your use of our website, such as:
- Search terms entered
- Information about the ad clicks that brought users to our website
- The frequency of visits to the website
- Above mentioned information regarding cookies
7.2 Legal basis for data processing
The legal basis for the processing of your data is the consent you have given via the cookie consent tool (Art. 6 para. 1 sentence 1 lit. a GDPR).
7.3 Purpose of data processing
With the help of Google Ads, Google and we can recognise whether the user has carried out certain actions. For example, we can analyse which buttons on our website were clicked how often and which products were viewed particularly frequently. This information is used to create conversion statistics. We find out the total number of users who have clicked on our adverts and which actions they have carried out. We do not receive any information with which we can personally identify the user. Google itself uses cookies or comparable recognition technologies for identification purposes. Further information on the purpose and scope of data collection and its processing as well as further information on your rights in this regard and setting options to protect your privacy can be found in Google's privacy policy for advertising: https://policies.google.com/technologies/ads.
7.4 Storage period
The storage duration of Google Analytics cookies can be found in the settings of our cookie notice under "Analytics, Show details".
7.5 Possibility of objection and removal
You can configure your browser according to your wishes and, for example, set it so that you are always informed about the setting of cookies, refuse the acceptance of cookies for certain cases or in general and activate the automatic deletion of cookies when closing the browser.
8. making contact
8.1 Description and scope of data processing
When you contact us (e.g. via the provided email address, telephone, a video conferencing service or a contact form), the personal data you submit will be stored. For contact via social networks, please see section 10, „Company Pages on Social Networks“.
The following data will be processed
- Contact via e-mail: Data such as first and last name, e-mail address, time stamp for sending and receiving
- Contact via telephone: Data such as telephone number, date and time of the call
- Contact via the contact form (Microsoft Bookings, Microsoft Forms or Calendly): Data such as first and last name, e-mail address, telephone number, date and time of the entry and the desired appointment
- Contact via the video conferencing service (Microsoft Teams):
- User and communication data such as name, display name, e-mail address, preferred language, profile picture,
- Metadata of the conference, such as date, time, location, meeting ID, duration of the conference, start and end of participation in the conference, number of participants,
- Content data such as text entries via a chat function, cloud recordings, instant messages, voicemails, uploaded photos and videos, files, whiteboards and other information,
- Contact via chat (Tawk.to): Data such as name or e-mail address, technical connection data of the server access (date, time, requested page, browser information), information about your enquiry.
The data will be used exclusively for processing the conversation. The data you send us via Microsoft Bookings or Calendly will be processed in our CRM system. In this context, your data will not be passed on to third parties without your consent. For telephony and video conferences, we use Microsoft Teams, and for contact forms, we use Microsoft Bookings or Microsoft Forms, services of Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA. As part of these video conferences, Microsoft Copilot may also be used, an AI-powered assistant from Microsoft Corporation that provides functions such as automatic minute-taking, summaries, or suggestions for follow-up tasks. In addition, for contact purposes, we also use Calendly, a service from Calendly Inc., 115 E Main St., Ste. A1B, Bufort, GA 30518, USA, represented by DPO Centre Europe, Friedrichstraße 88, 10117 Berlin, Germany., eurep@calendly.com. For the chat function, we use the service Tawk.to inc, 187 East Warm Springs Rd, SB298 Las Vegas, NV 89119, USA. It cannot be ruled out that Microsoft, Calendly or Tawk.to may transfer your personal data to third countries outside the European Union, in particular to the USA. The transfer of data to the USA is carried out in accordance with Art. 45 GDPR in conjunction with the European Commission's adequacy decision C(2023) 4745, as these data recipients have undertaken to comply with the principles of the Data Privacy Framework (DPF).
8.2 Legal basis for data processing
This data is processed on the basis of Art. 6 para. 1 lit. b GDPR if your enquiry is related to the fulfilment of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective processing of the enquiries addressed to us (Art. 6 para. 1 lit. f GDPR) or on your consent (Art. 6 para. 1 lit. a GDPR) if this has been requested. The legal basis for possible data processing in third countries when using Microsoft Teams, Microsoft Bookings, Microsoft Forms, Microsoft Copilot Calendly and Tawk.to is your consent in accordance with Art. 6 para. 1 lit. a in conjunction with Art. 49 para. 1 lit. a GDPR.
8.3 Purpose of data processing
The purposes for processing your personal data result from the respective context of the communication or collaboration. Further information on the purpose and scope of data collection and processing as well as further information on your rights in this regard and setting options to protect your privacy can be found in Microsoft's privacy policy: https://privacy.microsoft.com/de-de/privacystatement, Tawk.to: https://www.tawk.to/data-protection/ and from Calendly: https://calendly.com/legal/privacy-notice .
8.4 Storage period
Your personal data will only be processed and stored until the respective purpose is fulfilled or you revoke your consent to storage and then deleted, unless longer storage is required due to legal provisions and retention periods or for the exercise or defence of legal claims.
8.5 Possibility of objection and removal
The user has the option to withdraw their consent to the processing of personal data at any time. If data processing is carried out on a legal basis other than consent, the user can object to the storage of their personal data at any time. To exercise this right, please simply contact us informally (contact details, see legal notice). Please note that if the recordings of the virtual conferences are published, it will not always be possible to remove your data. If you do not agree to any image or sound recordings, please let us know in advance. In the case of a group chat, you can manage your participation directly in Microsoft Teams: https://support.microsoft.com/de-de/office/verlassen-oder-entfernen-einer-person-aus-einem-gruppenchat-in-microsoft-teams-7db55a67-0ba4-4409-a399-5ed502a1d094.
9. application process
9.1 Description and scope of data processing
During the application process, personal data that you provide to us is processed. This includes, for example, contact details, date of birth, gender, marital status, professional background, qualifications and position-related application data. When using the electronic route, via e-mail or via the online application portal, additional technical data such as IP address, date and time of application, browser information and operating system data may also be collected.
For the online application portal on our website, we use the service of Personio / Personio SE & Co. KG, Seidlstraße 3, 80335 Munich (hereinafter referred to as "Personio"). This is an applicant management portal. Further information can be found in Personio's privacy policy: https://www.personio.de/datenschutzerklaerung
9.2 Legal basis for data processing
Your data will be processed on the basis of Art. 6 para. 1 lit. b GDPR in conjunction with Section 26 para. 1 sentence 1 BDSG to review your application and to carry out the application process and - if you have given your consent - Art. 6 para. 1 lit. a GDPR. In the case of special categories of personal data, processing is also based on your consent in accordance with Art. 9 para. 2 lit. a GDPR.
9.3 Purpose of data processing
The purpose of data processing is to review your application, to plan and implement the application process and, if necessary, to establish an employment relationship. Disclosure to third parties is only permitted if it is related to this purpose or if the applicant has expressly given their consent.
9.4 Storage period
Your personal data will be deleted no later than six months after completion of the application process, unless longer storage is required by law or necessary for the defence of legal claims or you have expressly consented to longer storage. If we are currently unable to offer you a suitable position, we reserve the right to consider your application for future vacancies. With your consent in accordance with Art. 6 para. 1 lit. a GDPR, we will store your data for up to two years in order to contact you again within this period.
9.5 Possibility of objection and removal
You can revoke your consent with effect for the future and without giving reasons by contacting us at bewerbung@lm-ag.de about your cancellation. In the event of cancellation, we will delete your personal data immediately. The legality of the data processing carried out up to the revocation remains unaffected by the revocation. Mandatory statutory retention periods remain unaffected.
10. company pages in the social networks
10.1 Description and scope of data processing
In addition to our website, we operate publicly accessible company pages on the following social networks:
LinkedInThe data controller is LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland.
InstagramThe data controller is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.
- https://www.instagram.com/lmitservicesag
- https://www.instagram.com/msjobstipendium
- https://www.instagram.com/Trainingsmarkt.de
YouTubeThe controller is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
FacebookThe data controller is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.
- https://www.facebook.com/LMITServicesAG
- https://www.facebook.com/msjobstipendium
- https://www.facebook.com/Trainingsmarkt
XingThe responsible body is New Work SE, Am Strandkai 1, 20457 Hamburg, Germany.
We use the technical platform and services of the respective provider for our presence on the aforementioned social networks. We are responsible for the content of our company pages. Even if there is joint responsibility for this data processing in accordance with Art. 26 GDPR, these social networks remain contractual partners and contact partners for users in data protection issues. The social networks provide us with summarised, anonymised statistics that we cannot trace back to individual persons.
10.2 Storage period
The data we collect via social media will be deleted when the purpose of processing ceases to apply, you revoke your consent, or object to data processing. Statutory retention periods remain unaffected. We have no influence on the storage duration of data collected by the social networks themselves.
Please refer to the privacy policies of the respective networks.
- LinkedIn: https://de.linkedin.com/legal/privacy-policy
- Instagram: https://privacycenter.instagram.com/policy
- YouTube: https://policies.google.com/privacy
- Facebook: https://www.facebook.com/privacy/policy
- Xing: https://privacy.xing.com/en/privacy-policy
10.3 Possibility of objection and cancellation
To exercise your rights as a data subject, you can contact us or the provider of the social network directly. For specific enquiries regarding the processing of your interactions on our company page, please contact us using the contact details provided.
11. Newsletter
11.1 Description and scope of data processing
You can subscribe to a free newsletter on our website. When you register for the newsletter, the data from the input screen is transmitted to us.
- E-mail address
- First name
- Surname
Your consent is obtained for the processing of the data as part of the registration process and reference is made to this privacy policy. The following data is also collected during registration:
- Date and time of registration
- Date and time of opt-in verification
This website uses Brevo (formerly Sendinblue) to send newsletters. The provider is Sendinblue GmbH, Köpenicker Straße 126, 10179 Berlin, Germany. Brevo is a service that can be used to organise and analyse the sending of newsletters, among other things. The data you enter for the purpose of subscribing to the newsletter is stored on Brevo's servers in Germany. The data is used exclusively for sending the newsletter.
11.2 Legal basis for data processing
The legal basis for the processing of data after registration for the newsletter by the user is Art. 6 para. 1 lit. a GDPR if the user has given consent.
11.3 Purpose of data processing
The user's email address is collected for the purpose of delivering the newsletter. Newsletter distribution occurs based on the user's registration on the website. The collection of other personal data during the registration process is for the purpose of preventing misuse of the services or the email address used.
11.4 Storage period
The data is deleted as soon as it is no longer required to fulfil the purpose for which it was collected. The user's email address will therefore be stored for as long as the subscription to the newsletter is active. After you unsubscribe from the newsletter distribution list, your e-mail address may be stored by us or the newsletter service provider in a blacklist to prevent future mailings. The data from the blacklist will only be used for this purpose and will not be merged with other data. This serves both your interest and our interest in complying with the legal requirements when sending newsletters (legitimate interest within the meaning of Section 6 (1) (g) KDG). Storage in the blacklist is not limited in time. You can object to the storage if your interests outweigh our legitimate interest. For more information, please refer to Brevo's privacy policy at: https://www.brevo.com/de/features/data-security/
11.5 Possibility of objection and removal
The subscription to the newsletter can be cancelled by the user concerned at any time. For this purpose, there is a corresponding link in every newsletter. This also makes it possible to revoke consent to the storage of personal data collected during the registration process.
11.6 Conclusion of a contract for order processing
We have concluded a contract with Brevo in which we oblige Brevo to protect our customers' data and not to pass it on to third parties.
12. Using Microsoft Copilot
12.1 Description and scope of data processing
To support internal work and documentation processes, we use Microsoft Copilot, an AI-powered service from Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA, which is integrated into the Microsoft 365 (M365) environment.
Microsoft Copilot will be used for the following purposes:
- Summarisation of emails, meetings and documents, as well as general support for information and documentation work
- AI-powered creation of text drafts, wording assistance, and structured content suggestions
- Support with researching and preparing information in the M365 work context.
In the context of this usage, the following personal data may be processed:
- Names, professional email addresses, phone numbers, job titles, and communication content of general business relevance
- Photo, video or audio content, insofar as Microsoft Copilot is used in the context of video conferences or meeting recordings. For the use of Microsoft Copilot in the context of establishing contact and video conferences (e.g. automatic minute-taking or meeting summaries in Microsoft Teams), please refer to the separate provisions under Point 8 referred to in this privacy policy.
This may affect employees of LM-IT Services AG as well as – insofar as their data is contained in processed documents or communications – customers, prospective customers, suppliers and service providers. Microsoft Copilot only accesses content to which the user in question already has access under their M365 permissions. Our internal regulations prohibit the deliberate entry of special categories of personal data, as defined in Article 9 of the GDPR, into prompts. The data processor responsible for operating the Microsoft 365 and Copilot infrastructure is Microsoft Ireland Operations Ltd., One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. Microsoft Corporation, USA, is engaged as a sub-processor for the Azure OpenAI Service. In certain circumstances, Anthropic, PBC, 548 Market St, San Francisco, CA 94104, USA, may also act as a further sub-processor.
12.2 Legal basis for data processing
The processing of personal data of employees is based on Section 26 of the German Federal Data Protection Act (BDSG) in conjunction with Article 88 of the GDPR for the purpose of carrying out the employment relationship and optimising work processes. Where data of customers, prospects or business partners is concerned, the processing is based on our legitimate interest in efficient and high-quality task fulfilment (Article 6(1)(f) GDPR). Where Microsoft Copilot processes photo, video or audio content – particularly in the context of recorded meetings or video conferences – the processing is based on your explicit consent. Consent pursuant to Art. 6(1)(a) GDPR. Consent will be obtained before each recording begins and can be revoked at any time with future effect. The regulations under [insert link or reference here] apply additionally to the use of Microsoft Copilot within the scope of contact initiation and video conferences. Point 8 this privacy policy; the legal bases set out therein – including Article 6(1)(a) in conjunction with Article 49(1)(a) of the GDPR for transfers to third countries – apply accordingly in this context.
12.3 Purpose of data processing
The processing of personal data by Microsoft Copilot is exclusively for the support of internal work and communication processes within the M365 work context. Data will not be used for the training of AI models by Microsoft.
12.4 Transfer to third countries
The core services of Microsoft 365 are primarily operated in EU data centres (Germany and the Netherlands). The AI model underlying the Copilot service (Azure OpenAI Service) is operated by Microsoft Corporation in the USA. Transmission to the USA is based on EU Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR in conjunction with the Microsoft Data Protection Addendum (DPA, available at https://aka.ms/DPAand on the basis of the adequacy decision for the EU-U.S. Data Privacy Framework pursuant to Art. 45 GDPR.
Provided optional plugins or connectors – particularly Anthropic Claude – are activated, data may also be transferred to the USA or other countries outside the European Economic Area. The legal basis for this is also EU Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR; Anthropic is additionally certified under the EU-U.S. Data Privacy Framework. Anthropic's privacy policy can be accessed at: https://www.anthropic.com/legal/privacy.
12.5 Storage duration
Personal data will only be processed and stored for as long as is necessary for the respective purpose, or until any consent is withdrawn. Longer storage will only occur if statutory retention periods or the assertion or defence of legal claims necessitate it.
12.6 Right to object and request for rectification
Where data processing is based on a legitimate interest, you have the right to object to the processing of your personal data at any time. Where processing is based on consent – particularly for the processing of photo, video, or audio content – you can withdraw this at any time with effect for the future, without affecting the lawfulness of processing carried out up to the withdrawal. Please contact us informally for this purpose (contact details can be found in the imprint). Employees can also contact the responsible IT administration or the company data protection officer.
13. Customer and Supplier Data
13.1 Description and scope of data processing
As part of our business relationship with you, we process your personal data, which may be stored in our internal CRM system. We process the contact details you have provided, such as title, surname, first name, address, email address and telephone number, as well as the data required for the provision of the relevant services and for invoicing. Your personal data will be passed on to those departments (e.g. financial accounting) that require the data for the purposes set out below. Furthermore, where legally permissible, we may transfer your data to public authorities or institutions (e.g. tax and law enforcement authorities, courts) for the aforementioned purposes.
13.2 Legal basis for data processing
Data processing is primarily carried out for the fulfilment of a contract or for the implementation of pre-contractual measures in accordance with Art. 6 para. 1 lit. b GDPR. In addition, it is based, as far as legally permissible, on our legal obligations pursuant to Art. 6 para. 1 lit. c GDPR and on our legitimate interests pursuant to Art. 6 para. 1 lit. f GDPR. If you provide us with data that goes beyond the purpose, we process your data on the basis of your consent in accordance with Art. 6 para. 1 lit. a GDPR.
13.3 Purpose of Data Processing
Your personal data is processed for communication and coordination (including online meetings), for the preparation, implementation and processing of contracts (including the processing of product enquiries, delivery and invoicing), for compliance with legal requirements (including tax and accounting retention obligations), for internal administrative activities (e.g. financial accounting), for the assertion or defence of legal claims (including judicial and official proceedings) and for other necessary measures within the scope of the business relationship.
13.4 Storage duration
Customer and supplier data will be deleted if the purpose for their storage no longer exists (e.g. end of the business relationship), the customer or supplier withdraws their consent to storage, objects or if this is necessary to fulfil a legal obligation. Mandatory statutory retention periods remain unaffected.
13.5 Objection and Rectification Opportunities
To exercise your rights as a data subject, please contact us informally (contact details, see legal notice).
14. Rights of the data subject
If your personal data is processed, you are a data subject within the meaning of the GDPR and you have the following rights vis-à-vis the controller:
14.1 Right of access
You can request confirmation from the controller as to whether personal data concerning you is being processed by us. If such processing is taking place, you can request the following information from the controller:
- the purposes for which the personal data are processed;
- the categories of personal data that are processed;
- the recipients or categories of recipients to whom the personal data concerning you have been or will be disclosed;
- the planned duration of storage of the personal data concerning you or, if specific information on this is not possible, criteria for determining the storage period;
- the existence of a right to rectification or erasure of personal data concerning you, a right to restriction of processing by the controller or a right to object to such processing;
- the existence of a right of appeal to a supervisory authority;
- all available information about the origin of the data if the personal data is not collected from the data subject;
- the existence of automated decision-making, including profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.
You have the right to request information as to whether the personal data concerning you is transferred to a third country or to an international organisation. In this context, you may request to be informed of the appropriate safeguards pursuant to Art. 46 GDPR in connection with the transfer.
14.2 Right of rectification
You have a right to rectification and/or completion vis-à-vis the controller if the processed personal data concerning you is incorrect or incomplete. The controller must make the correction without delay.
14.3 Right to restriction of processing
Under the following conditions, you may request the restriction of the processing of your personal data:
- if you contest the accuracy of the personal data concerning you for a period enabling the controller to verify the accuracy of the personal data;
- the processing is unlawful and you oppose the erasure of the personal data and request the restriction of their use instead;
- the controller no longer needs the personal data for the purposes of the processing, but they are required by you for the establishment, exercise or defence of legal claims, or
- if you have objected to processing pursuant to Art. 21 (1) GDPR and it is not yet certain whether the legitimate grounds of the controller override your grounds.
If the processing of personal data concerning you has been restricted, this data - apart from its storage - may only be processed with your consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the Union or of a Member State. If the restriction of processing has been restricted in accordance with the above conditions, you will be informed by the controller before the restriction is lifted.
14.4 Right to erasure
a) Obligation to delete
You have the right to obtain from the controller the erasure of personal data concerning you without undue delay and the controller shall have the obligation to erase personal data without undue delay where one of the following grounds applies:
- the personal data concerning you are no longer necessary in relation to the purposes for which they were collected or otherwise processed.
- You revoke your consent on which the processing was based pursuant to Art. 6 para. 1 lit. a or Art. 9 para. 2 lit. a GDPR and there is no other legal basis for the processing.
- You object to the processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the processing, or you object to the processing pursuant to Art. 21 (2) GDPR.
- the personal data concerning you has been processed unlawfully.
- the deletion of personal data concerning you is necessary to fulfil a legal obligation under Union law or the law of the Member States to which the controller is subject.
- the personal data concerning you have been collected in relation to the offer of information society services referred to in Art. 8 (1) GDPR.
b) Information to third parties
If the controller has made the personal data concerning you public and is obliged to erase that personal data pursuant to Article 17(1) GDPR, the controller shall, taking account of available technology and the cost of implementation, take reasonable steps, including technical measures, to inform other controllers which are processing the personal data that you have requested the erasure by such controllers of any links to, or copy or replication of, those personal data.
c) Exceptions
The right to erasure does not exist if processing is necessary
- to exercise the right to freedom of expression and information;
- for compliance with a legal obligation which requires processing by Union or Member State law to which the controller is subject or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
- for reasons of public interest in the area of public health in accordance with Art. 9 para. 2 lit. h and i and Art. 9 para. 3 GDPR;
- for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Art. 89 para. 1 GDPR, insofar as the right referred to in section a) is likely to render impossible or seriously impair the achievement of the objectives of that processing, or for the establishment, exercise or defence of legal claims.
14.5 Right to information
If you have asserted the right to rectification, erasure or restriction of processing against the controller, the controller is obliged to notify all recipients to whom the personal data concerning you have been disclosed of this rectification or erasure of the data or restriction of processing, unless this proves impossible or involves a disproportionate effort. You have the right vis-à-vis the controller to be informed about these recipients.
14.6 Right to data portability
You have the right to receive the personal data concerning you, which you have provided to the controller, in a structured, commonly used and machine-readable format. You also have the right to transmit this data to another controller without hindrance from the controller to which the personal data has been provided, where
- the processing is based on consent pursuant to Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR or on a contract pursuant to Art. 6 para. 1 lit. b GDPR and
- the processing is carried out using automated procedures.
In exercising this right, you also have the right to have the personal data concerning you transmitted directly from one controller to another, where technically feasible. The freedoms and rights of other persons must not be affected by this. The right to data portability does not apply to the processing of personal data necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.
14.7 Right of objection
You have the right to object, on grounds relating to your particular situation, at any time to the processing of personal data concerning you which is based on Article 6(1)(e) or (f) of the GDPR, including profiling based on those provisions. The controller shall no longer process the personal data concerning you unless the controller demonstrates compelling legitimate grounds for the processing which override your interests, rights and freedoms, or for the establishment, exercise or defence of legal claims. If personal data concerning you are processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for such marketing purposes, including profiling in so far as it is related to such direct marketing. If you object to the processing for direct marketing purposes, the personal data concerning you shall no longer be processed for those purposes. You have the option, in connection with the use of information society services, notwithstanding Directive 2002/58/EC, to exercise your right to object by automated means using technical specifications.
14.8 Right of withdrawal of data protection consent
You have the right to revoke your declaration of consent under data protection law at any time. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
14.9 Right of complaint to a supervisory authority
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement if you consider that the processing of personal data relating to you infringes the GDPR. The supervisory authority with which the complaint has been lodged shall inform the complainant on the progress and the outcome of the complaint including the possibility of a judicial remedy pursuant to Art. 78 GDPR.
Status: July 2026