Skip to the main content.

Privacy Statement

Privacy Statement

Thank you for visiting our website. Compliance with data protection regulations is of particular importance to us. The purpose of this privacy policy is to inform you, as a user of the website, about the type, scope, and purpose of the processing of personal data, as well as the rights available to you, insofar as you qualify as a data subject within the meaning of Article 4, No. 1 of the General Data Protection Regulation (GDPR).


1. Controller

This website and its service offerings are operated by:

BCT Technology AG
Im Lossenfeld 9
77731 Willstätt
Germany

Tel.: +49 7852 996-0
Fax: +49 7852 996-100


For Switzerland:
BCT Technology GmbH
Suurstoffi 37
6343 Rotkreuz
Switzerland

 

2. Data Protection Officer

We have appointed data protection officers who can be reached as follows:

For GDPR jurisdiction:

Herold Unternehmensberatung GmbH
Mr. Philipp Herold
Hafenstraße 1a
23568 Lübeck
Email: bct_datenschutz@bct-technology.com

For Switzerland:
Email: bct-schweiz_datenschutz@bct-technology.com

 

3. General Information

We have designed our website to collect as little data as possible from you. We always ensure that your personal data is processed only in accordance with a legal basis or based on your consent. We adhere to the provisions of the GDPR, effective since May 25, 2018, as well as applicable national regulations, such as the German Federal Data Protection Act (BDSG), the Telecommunications-Telemedia Data Protection Act (TTDSG), and other specific laws (e.g., the Swiss Data Protection Act).


4. Purpose and Legal Basis for Processing Personal Data

We always process your personal data for specific purposes. In summary, we process your personal data for the following purposes:

  1. To address your inquiries (e.g., email address, first name, last name);
  2. To manage your customer account and provide the requested products and services (registration);
  3. To register you for events and organize those events;
  4. To technically realize our website and provide you with information (e.g., IP address, cookies, browser information);
  5. To send newsletters containing information about our services and updates (e.g., name, email address);
  6. To facilitate the download of e-books and white papers related to our services;
  7. To process and handle your application for one of our job postings.

The legal basis for processing your personal data is as follows:
Personal data that is required for the establishment, execution, or fulfillment of our service offering (contract execution) is processed based on the legal foundation of Article 6(1)(b) of the General Data Protection Regulation (GDPR).
If we obtain your consent for the processing of your personal data, such consent serves as the legal basis for processing under Article 6(1)(a) of the GDPR.
Data processing is also permissible if we process your data to safeguard our legitimate interests, provided that your interests or fundamental rights and freedoms concerning the processing of personal data do not outweigh these interests (Article 6(1)(f) of the GDPR).
When we engage external service providers as part of data processing on behalf of the controller, the processing is conducted based on the legal foundation of Article 28 of the GDPR.


5. Collection of Personal Data When Visiting Our Website

When using the website for informational purposes only, i.e., when you do not register or otherwise provide information, we collect only the personal data that your browser transmits to our server. If you view our website, we collect the following data, which is necessary to display the website and ensure stability and security (legal basis: Article 6(1)(1)(f) GDPR):

  • IP address
  • Date and time of the request
  • Time zone difference to Greenwich Mean Time (GMT)
  • Content of the request (specific page)
  • Access status/HTTP status code
  • Amount of data transferred
  • Referring website
  • Browser
  • Operating system and interface
  • Language and version of the browser software

This website is hosted by an external service provider (host).

The personal data collected on this website is stored on the host's servers:

TelemaxX Telekommunikation GmbH
Amalienbadstraße 41, Bau 61
76227 Karlsruhe

We have concluded a data processing agreement (DPA) with the provider to ensure that personal data of website visitors is processed solely according to our instructions and in compliance with the GDPR.

In addition to the mentioned data, cookies are stored on your device when you use our website. For more information, refer to the "Cookies" section of this privacy policy and the consent management tool implemented.


6. Integration of Services from Other Providers

Our website uses content, services, and features from third-party providers. These may include services for statistical analysis of website usage. To display this data in the user's browser, the user's IP address must be transmitted to the respective third-party providers.

While we strive to work only with providers that use IP addresses solely to deliver content or anonymize them, we have no control over whether IP addresses may be stored. Details on third-party providers used can be found later in this privacy policy.

 

AWS CloudFlare

Nature and Scope of Processing

We use AWS CloudFlare, a service by Amazon Web Services, Inc., as a Content Delivery Network (CDN) to ensure proper delivery of website content.

A CDN helps to make content such as graphics or scripts available more quickly via servers distributed regionally or internationally. When you access this content, a connection to servers of Amazon Web Services, Inc., is established, transmitting your IP address and potentially browser data like your User-Agent. These data are processed solely for the purposes mentioned above and to maintain the security and functionality of AWS CloudFlare.

Purpose and Legal Basis

The use of the CDN is based on our legitimate interests in providing a secure, efficient, and optimized online service (Article 6(1)(f) GDPR).

We intend to transfer personal data to countries outside the European Economic Area (EEA), particularly the USA. Data transfers to the USA are based on Article 45(1) GDPR, according to the European Commission's adequacy decision. The US companies involved are certified under the EU-U.S. Data Privacy Framework (EU-U.S. DPF).

Storage Period

The exact storage duration of processed data is determined by Amazon Web Services, Inc., and is beyond our control. For more information, please refer to AWS CloudFlare's privacy policy: https://aws.amazon.com/de/privacy/.

 

Brightcove (boltdns.net)

Nature and Scope of Processing

Our website uses Brightcove, a service provided by Brightcove Inc., 290 Congress Street, Boston, MA 02210, USA, to deliver video content. When you access a page containing a Brightcove video, a connection to Brightcove servers is established, transmitting data such as your IP address, technical information about your device, and browser.

Purpose and Legal Basis

The processing is carried out to deliver video content and improve our online services. The legal basis for using Brightcove is your consent (Article 6(1)(a) GDPR).

We intend to transfer personal data to countries outside the EEA, particularly the USA. Data transfers to the USA are based on Article 45(1) GDPR, according to the European Commission's adequacy decision. The US companies involved are certified under the EU-U.S. Data Privacy Framework (EU-U.S. DPF).

Storage Period

The exact storage duration of processed data is determined by Brightcove Inc. For more details, see Brightcove's privacy policy: https://www.brightcove.com/en/legal/privacy.

 

Plyr

Nature and Scope of Processing

We use Plyr CDN, a service provided by Plyr, to ensure proper delivery of website content. A CDN facilitates faster access to content such as graphics or scripts through distributed servers. When accessing this content, a connection to Plyr servers is established, transmitting your IP address and potentially browser data like your User-Agent.

Purpose and Legal Basis

The use of the CDN is based on our legitimate interests in providing a secure and efficient online service (Article 6(1)(f) GDPR).

We intend to transfer personal data to countries outside the EEA, particularly the USA. Data transfers to the USA are based on Article 45(1) GDPR, according to the European Commission's adequacy decision. The US companies involved are certified under the EU-U.S. Data Privacy Framework (EU-U.S. DPF).

Storage Period

The exact storage duration of processed data is determined by Plyr. For further information, see Plyr's privacy policy: https://www.plyr.com/policy.

 

Google DoubleClick

Nature and Scope of Processing

We have integrated components of Google DoubleClick into our website. DoubleClick is a brand of Google that primarily markets specialized online marketing solutions to advertising agencies and publishers. DoubleClick by Google transmits data to the DoubleClick server with every impression, click, or other activity.

Each of these data transmissions triggers a cookie request to the browser of the individual concerned. If the browser accepts this request, DoubleClick sets a cookie in your browser.

DoubleClick uses a cookie ID that is necessary for the execution of technical processes. For instance, the cookie ID is required to display an advertisement in a browser. Additionally, the cookie ID allows DoubleClick to determine which advertisements have already been displayed in a browser to avoid duplicate ads. Moreover, DoubleClick can use the cookie ID to track conversions. Conversions are recorded, for example, when a user who has previously been shown a DoubleClick advertisement subsequently makes a purchase on the advertiser’s website using the same internet browser.

A DoubleClick cookie does not contain any personally identifiable information but may include additional campaign identifiers. A campaign identifier helps identify campaigns with which you have already interacted on other websites. As part of this service, Google gains access to data that it may also use to generate commission reports. For example, Google can track that you have clicked on certain links on our website.
In this context, your data is transmitted to the operator of DoubleClick, Google Ireland Limited, located at Gordon House, Barrow Street, Dublin 4, Ireland.
For more information and the applicable data protection policies of DoubleClick by Google, please visit Google’s Privacy Policy.

Purpose and Legal Basis

We process your data using the DoubleClick cookie for the purpose of optimizing and displaying advertisements based on your consent in accordance with Article 6(1)(a) GDPR and Section 25(1) of the TDDG (German Telecommunication-Telemedia Data Protection Act). The cookie is used, among other things, to display and deliver user-relevant advertisements, to generate reports on advertising campaigns, and to improve them. Additionally, the cookie helps avoid repeated displays of the same advertisement.
Each time you access an individual page of our website where a DoubleClick component is integrated, your browser is automatically prompted by the respective DoubleClick component to transmit data to Google for the purpose of online advertising and commission billing.
There is no legal or contractual obligation to provide your data. If you do not grant us your consent, you can still visit our website without restriction; however, some features may not be fully available.

We intend to transfer personal data to third countries outside the European Economic Area (EEA), particularly the United States. Data transfers to the U.S. are carried out under Article 45(1) GDPR based on the adequacy decision of the European Commission. The participating U.S. companies and/or their U.S. subcontractors are certified under the EU-U.S. Data Privacy Framework (EU-U.S. DPF).
Storage Period The exact storage duration of processed data is determined by Google Ireland Limited. For more information, see Google DoubleClick's privacy policy: https://policies.google.com/privacy.

 

Google APIs

Nature and Scope of Processing

We use Google APIs from Google Ireland Limited to access additional services and data. When using Google APIs, your IP address is transmitted to Google Ireland Limited. Please note that there is a separate section in this privacy policy for each additional service we use from Google Ireland Limited.

Purpose and Legal Basis

The use of Google APIs is based on our legitimate interests, specifically our interest in optimizing our online offering, in accordance with Article 6(1)(f) of the General Data Protection Regulation (GDPR).

We intend to transfer personal data to third countries outside the European Economic Area (EEA), particularly to the United States. The data transfer to the U.S. is conducted under Article 45(1) of the GDPR, based on the adequacy decision of the European Commission. The involved U.S. companies and/or their U.S. subcontractors are certified under the EU-U.S. Data Privacy Framework (EU-U.S. DPF).

Storage Period

The exact storage duration of processed data is determined by Google Ireland Limited. For further information, see Google's privacy policy: https://policies.google.com/privacy.

 

Google Analytics

Nature and Scope of Processing

We use Google Analytics, provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, as an analytics service for statistical evaluation of our online offerings. This includes analyzing metrics such as the number of visits to our website, pages viewed, and the time visitors spend on the website.
Google Analytics uses cookies and other browser technologies to evaluate user behavior and recognize users. For example, the data collected is used to compile reports about website activity.
Purpose and Legal Basis
The use of Google Analytics is based on your consent in accordance with Article 6(1)(a) GDPR and § 25(1) TTDSG.
We intend to transfer personal data to countries outside the European Economic Area (EEA), particularly the USA. Data transfers to the USA are conducted in compliance with Article 45(1) GDPR, based on the European Commission's adequacy decision. The US-based companies involved are certified under the EU-U.S. Data Privacy Framework (EU-U.S. DPF).
Storage Period
The exact storage duration of processed data is determined by Google Ireland Limited and is beyond our control. For more information, refer to Google's privacy policy: https://policies.google.com/privacy.


Google AdSense

Nature and Scope of Processing

Our website uses Google AdSense, a service for embedding advertisements provided by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
Google AdSense uses cookies—text files stored on your computer—that allow for an analysis of website usage. Google AdSense also uses web beacons (invisible graphics) to collect data on visitor traffic.
Information generated by these cookies and web beacons (including your IP address and ad delivery data) is transmitted to Google servers in the USA and stored there. Google may share this information with its contractual partners.


Purpose and Legal Basis

The use of Google AdSense is based on your consent in accordance with Article 6(1)(a) GDPR and § 25(1) TTDSG.
We intend to transfer personal data to countries outside the EEA, particularly the USA. Data transfers to the USA are conducted in compliance with Article 45(1) GDPR, based on the European Commission's adequacy decision. The US-based companies involved are certified under the EU-U.S. Data Privacy Framework (EU-U.S. DPF).


Storage Period

The exact storage duration of processed data is determined by Google Inc. and is beyond our control. For more information, refer to Google's privacy policy: https://policies.google.com/privacy.

 

Google Ads and Google Ads Conversion

Nature and Scope of Processing

Our website uses Google Ads, a service provided by Google Ireland Limited, to display targeted advertisements to users. Google Ads uses cookies and other browser technologies to evaluate user behavior and recognize users.

Google Ads collects data about user behavior on various websites. This data is used to optimize advertisement relevance. Additionally, Google Ads provides targeted advertisements based on behavioral profiles and geographical locations. Your IP address and other identifiers, such as your User-Agent, are transmitted to Google Ads. If you are registered with a Google Ireland Limited service, Google Ads may associate the visit with your account. Even if you are not registered or logged in, Google Ads can potentially identify and store your IP address and other identifiers.

We also use Google Ads Conversion Tracking. When you click on a Google ad, a cookie is set for Conversion Tracking. Each Google Ads customer receives a unique cookie. Data collected via Conversion Cookies is used to create conversion statistics for Ads customers who opt for Conversion Tracking. Customers are informed about the total number of users who clicked on their ad and were redirected to a page tagged for Conversion Tracking but receive no personal data about users.

For more information about Google Ads and Google Conversion Tracking, refer to Google's privacy policy: https://www.google.de/policies/privacy.

Purpose and Legal Basis

We process your data using Google Ads and Conversion Tracking for the purpose of optimizing our website and for marketing purposes based on your consent in accordance with Article 6(1)(a) GDPR and § 25(1) TTDSG.
We intend to transfer personal data to countries outside the EEA, particularly the USA. Data transfers to the USA are conducted in compliance with Article 45(1) GDPR, based on the European Commission's adequacy decision. The US-based companies involved are certified under the EU-U.S. Data Privacy Framework (EU-U.S. DPF).

Storage Period

The exact storage duration of processed data is determined by Google Ireland Limited and is beyond our control. For more information, refer to Google's privacy policy: https://policies.google.com/privacy.

 

Google Fonts

Nature and Scope of Processing

We use Google Fonts, provided by Google Ireland Limited, to incorporate fonts into our online offering. To fetch these fonts, a connection to Google Ireland Limited servers is established, during which your IP address is transmitted.

Purpose and Legal Basis

The use of Google Fonts is based on your consent in accordance with Article 6(1)(a) GDPR and § 25(1) TTDSG.
We intend to transfer personal data to countries outside the EEA, particularly the USA. Data transfers to the USA are conducted in compliance with Article 45(1) GDPR, based on the European Commission's adequacy decision. The US-based companies involved are certified under the EU-U.S. Data Privacy Framework (EU-U.S. DPF).

Storage Period

The exact storage duration of processed data is determined by Google Ireland Limited and is beyond our control. For more information, refer to Google's privacy policy: https://policies.google.com/privacy.

 

Google Maps

Nature and Scope of Processing

We use Google Maps, a service provided by Google Ireland Limited, to create driving directions and display maps on our website. When you access these contents, a connection to Google Ireland Limited servers is established, transmitting your IP address and, if applicable, browser data such as your User-Agent. This data is processed exclusively for the aforementioned purposes and to maintain the security and functionality of Google Maps.

Purpose and Legal Basis

The use of Google Maps is based on your consent in accordance with Article 6(1)(a) GDPR and § 25(1) TTDSG.
We intend to transfer personal data to countries outside the EEA, particularly the USA. Data transfers to the USA are conducted in compliance with Article 45(1) GDPR, based on the European Commission's adequacy decision. The US-based companies involved are certified under the EU-U.S. Data Privacy Framework (EU-U.S. DPF).

Storage Period

The exact storage duration of processed data is determined by Google Ireland Limited and is beyond our control. For more information, refer to Google's privacy policy: https://policies.google.com/privacy.

 

Google reCAPTCHA

Nature and Scope of Processing

Our website incorporates Google reCAPTCHA components, a service provided by Google Ireland Limited, to differentiate between human and automated interactions when submitting forms or queries. When you access reCAPTCHA, a connection to Google Ireland Limited servers is established, transmitting your IP address and, if applicable, browser data such as your User-Agent. Additionally, Google reCAPTCHA tracks user behavior, such as time spent on the site and mouse movements, to distinguish between human users and bots.

Purpose and Legal Basis

The use of Google reCAPTCHA is based on your consent in accordance with Article 6(1)(a) GDPR and § 25(1) TTDSG.
We intend to transfer personal data to countries outside the EEA, particularly the USA. Data transfers to the USA are conducted in compliance with Article 45(1) GDPR, based on the European Commission's adequacy decision. The US-based companies involved are certified under the EU-U.S. Data Privacy Framework (EU-U.S. DPF).

Storage Period

The exact storage duration of processed data is determined by Google Ireland Limited and is beyond our control. For more information, refer to Google's privacy policy: https://policies.google.com/privacy?hl=en-US.

 

Google Tag Manager

Nature and Scope of Processing

We use Google Tag Manager, a service provided by Google Ireland Limited, located at Gordon House, Barrow Street, Dublin 4, Ireland. Google Tag Manager is utilized to manage website tags via an interface, enabling us to precisely integrate services on our website. This tool allows us to flexibly incorporate additional services to analyze user access to our website.

Purpose and Legal Basis

The use of Google Tag Manager is based on your consent in accordance with Article 6(1)(a) GDPR and § 25(1) TTDSG.
We intend to transfer personal data to countries outside the European Economic Area (EEA), particularly the USA. Data transfers to the USA are conducted in compliance with Article 45(1) GDPR, based on the European Commission's adequacy decision. The US-based companies involved are certified under the EU-U.S. Data Privacy Framework (EU-U.S. DPF).

Storage Period

The exact storage duration of processed data is determined by Google Ireland Limited and is beyond our control. For more information, refer to the privacy policy for Google Tag Manager: https://marketingplatform.google.com/about/analytics/tag-manager/use-policy/.

 

YouTube

Nature and Scope of Processing

Our website integrates YouTube videos, a component of the YouTube platform provided by YouTube LLC. Users can upload content, share it over the internet, and access detailed statistics on YouTube.

YouTube Video allows us to embed platform content into our website.

It uses cookies and other browser technologies to analyze user behavior, recognize users, and create user profiles. These data points are utilized to assess the activity of the videos and generate reports. If a user is registered with YouTube LLC, the videos viewed may be associated with their profile.

When accessing these contents, a connection is established with servers of YouTube LLC and Google Ireland Limited, located at Gordon House, Barrow Street, Dublin 4, Ireland. In this process, your IP address and potentially browser data such as your User-Agent are transmitted.

Purpose and Legal Basis

The use of YouTube services is based on your consent in accordance with Article 6(1)(a) GDPR and § 25(1) TTDSG.
We intend to transfer personal data to countries outside the EEA, particularly the USA. Data transfers to the USA are conducted in compliance with Article 45(1) GDPR, based on the European Commission's adequacy decision. The US-based companies involved are certified under the EU-U.S. Data Privacy Framework (EU-U.S. DPF).

Storage Period

The exact storage duration of processed data is determined by YouTube LLC and is beyond our control. For more information, refer to the privacy policy for YouTube: https://policies.google.com/privacy.

 

Haufe Talent Management

Nature and Scope of Processing

We use Haufe Talent Management, a tool provided by Haufe-Lexware GmbH & Co. KG, located at Munzinger Straße 9, 79111 Freiburg im Breisgau, to manage and process applications and personnel-related processes. If you apply for a position or use the talent management system, personal data such as your name, contact details, application documents, and other information you provide during the application process are processed. Data transmission occurs directly between your device and Haufe's servers.

Purpose and Legal Basis

Your data is processed to manage applications, conduct the selection process, and communicate regarding job placements. The legal basis for this processing is Article 6(1)(b) GDPR, as it is necessary for initiating and processing an employment relationship. Where consent is required, processing is based on Article 6(1)(a) GDPR.

Storage Period

Applicant data is stored for the duration of the application process. In the event of a rejection, your data will be deleted no later than six months after the application process concludes unless you consent to a longer retention period (e.g., for a talent pool) and no legal retention periods prevent deletion. For more details on data processing by Haufe, refer to their privacy policy: https://www.haufe.com/de/datenschutzerklaerung.

 

HubSpot Consent Management

Nature and Scope of Processing

Our website integrates the HubSpot Cookie Banner locally. This consent solution is provided by HubSpot, Inc., based in Cambridge, Massachusetts, USA. The HubSpot Cookie Banner enables the collection and documentation of user consent for cookie storage. HubSpot Cookie Banner uses cookies or other web technologies to recognize users and store their granted or revoked consent.

Purpose and Legal Basis

The use of this service is based on the legal requirement to obtain consent for the use of cookies in accordance with Article 6(1)(c) GDPR.

 

HubSpot API

Nature and Scope of Processing

We utilize the HubSpot API provided by HubSpot, Inc., located in Cambridge, Massachusetts, USA, to access additional services and data from HubSpot, Inc. During this process, your IP address is transmitted to HubSpot, Inc. Please note that this privacy policy includes a dedicated section for each additional service we use from HubSpot, Inc.

Purpose and Legal Basis

The use of the HubSpot API is based on our legitimate interests in optimizing our online offerings in accordance with Article 6(1)(f) GDPR.
We intend to transfer personal data to countries outside the European Economic Area (EEA), particularly the USA. Data transfers to the USA are conducted in compliance with Article 45(1) GDPR, based on the European Commission's adequacy decision. The US-based companies involved are certified under the EU-U.S. Data Privacy Framework (EU-U.S. DPF).

Storage Period

The exact storage duration of processed data is determined by HubSpot, Inc., and is beyond our control. For more information, refer to HubSpot's privacy policy: https://legal.hubspot.com/privacy-policy.

 

HubSpot Analytics

Nature and Scope of Processing

We use HubSpot Analytics, a service provided by HubSpot, Inc., located in Cambridge, Massachusetts, USA, for statistical evaluation of our online offerings. This includes analyzing metrics such as the number of visits to our website, pages viewed, and the duration of visits.

HubSpot Analytics uses cookies and other browser technologies to evaluate user behavior and recognize users. The collected information is used to compile reports on website activity.

Purpose and Legal Basis

The use of HubSpot Analytics is based on your consent in accordance with Article 6(1)(a) GDPR and § 25(1) TTDSG.
We intend to transfer personal data to countries outside the EEA, particularly the USA. Data transfers to the USA are conducted in compliance with Article 45(1) GDPR, based on the European Commission's adequacy decision. The US-based companies involved are certified under the EU-U.S. Data Privacy Framework (EU-U.S. DPF).

Storage Period

The exact storage duration of processed data is determined by HubSpot, Inc., and is beyond our control. For more information, refer to HubSpot's privacy policy: https://legal.hubspot.com/privacy-policy.

 

HubSpot LeadFlow

Nature and Scope of Processing

Our website integrates HubSpot LeadFlow, a service provided by HubSpot, Inc., located in Cambridge, Massachusetts, USA. HubSpot LeadFlow identifies anonymous website visitors, provides complete contact information, and offers insights into the visit history.
HubSpot LeadFlow uses cookies and other browser technologies to evaluate user behavior and recognize users.
Among other functions, HubSpot LeadFlow informs us about which companies visited our website, tracks your visit history (including pages visited and viewed), and records the duration of your stay on our website. HubSpot LeadFlow collects and processes company data, including company name, phone number, address, web address, industry, company profile, revenue, and key LinkedIn personnel.

Purpose and Legal Basis

The use of HubSpot LeadFlow is based on your consent in accordance with Article 6(1)(a) GDPR and § 25(1) TTDSG.
We intend to transfer personal data to countries outside the EEA, particularly the USA. Data transfers to the USA are conducted in compliance with Article 45(1) GDPR, based on the European Commission's adequacy decision. The US-based companies involved are certified under the EU-U.S. Data Privacy Framework (EU-U.S. DPF).

Storage Period

The exact storage duration of processed data is determined by HubSpot, Inc., and is beyond our control. For more information, refer to HubSpot's privacy policy: https://legal.hubspot.com/privacy-policy.

 

HubSpot Pixel

Nature and Scope of Processing

We use HubSpot Pixel, a service provided by HubSpot, Inc., located in Cambridge, Massachusetts, USA, to create custom audiences, segment visitor groups for our online offerings, calculate conversion rates, and subsequently optimize these. This is particularly useful when users interact with advertisements that we place through HubSpot, Inc.

Purpose and Legal Basis

The use of HubSpot Pixel is based on your consent in accordance with Article 6(1)(a) GDPR and § 25(1) TTDSG.
We intend to transfer personal data to countries outside the EEA, particularly the USA. Data transfers to the USA are conducted in compliance with Article 45(1) GDPR, based on the European Commission's adequacy decision. The US-based companies involved are certified under the EU-U.S. Data Privacy Framework (EU-U.S. DPF).

Storage Period

The exact storage duration of processed data is determined by HubSpot, Inc., and is beyond our control. For more information, refer to HubSpot's privacy policy: https://legal.hubspot.com/privacy-policy.

 

HubSpot Forms

Nature and Scope of Processing

Our website integrates HubSpot Forms, a service provided by HubSpot, Inc., that offers marketing automation software for services and products, including SEO and content creation, lead management, email marketing, and web analytics.
HubSpot Forms is used to store data entered into forms, such as contact forms. The provided data can be stored in our Customer Relationship Management (CRM) system.
Your data is transmitted to the operator of HubSpot Forms, HubSpot, Inc., located in Cambridge, Massachusetts, USA.

Purpose and Legal Basis

The use of HubSpot Forms and its integrated services is based on our legitimate interest in processing contact inquiries, managing responses, and optimizing our marketing activities, in accordance with Article 6(1)(f) GDPR.
We intend to transfer personal data to countries outside the EEA, particularly the USA. Data transfers to the USA are conducted in compliance with Article 45(1) GDPR, based on the European Commission's adequacy decision. The US-based companies involved are certified under the EU-U.S. Data Privacy Framework (EU-U.S. DPF).

Storage Period

The exact storage duration of processed data is determined by HubSpot, Inc., and is beyond our control. For more information, refer to HubSpot's privacy policy: https://legal.hubspot.com/privacy-policy.

 

HubSpot Video

Nature and Scope of Processing

Our website uses HubSpot Video, a service provided by HubSpot, Inc., located at 25 First Street, Cambridge, MA 02141, USA, for delivering and embedding video content. When a page containing embedded HubSpot Video is accessed, a connection to HubSpot's servers is established. During this interaction, personal data such as your IP address, technical information about your device and browser, and details about your video usage (e.g., playback behavior) may be processed. This information is directly exchanged between your device and HubSpot's servers.

Purpose and Legal Basis

The use of HubSpot Video is based on your consent in accordance with Article 6(1)(a) GDPR and § 25(1) TTDSG.
We intend to transfer personal data to countries outside the European Economic Area (EEA), particularly the USA. Data transfers to the USA are conducted in compliance with Article 45(1) GDPR, based on the European Commission's adequacy decision. The US-based companies involved are certified under the EU-U.S. Data Privacy Framework (EU-U.S. DPF).

Storage Period

The collected data is retained only for as long as it is necessary for the respective processing purpose. Once the purpose is fulfilled or the statutory retention period expires, the data is deleted unless you have provided consent for longer storage. For further information about HubSpot's data processing, refer to: https://legal.hubspot.com/privacy-policy.

 

LinkedIn Ads

Nature and Scope of Processing

Our website integrates LinkedIn Ads, a service provided by LinkedIn Corporation, located in Sunnyvale, California, USA. LinkedIn Ads delivers targeted advertising to users and employs cookies and other browser technologies to evaluate user behavior and recognize users. LinkedIn Ads collects data on visitor behavior across various websites to optimize advertising relevance. Additionally, LinkedIn Ads provides targeted advertising based on behavioral profiles and geographic location. Data such as your IP address and other identifiers like your user agent are shared with LinkedIn. In this case, data is transferred to the operator of LinkedIn Ads, LinkedIn Corporation.

Web tracking technologies are used to create pseudonymized user profiles. These profiles cannot be linked to you as an individual but serve purposes such as segmentation for ad display.

Purpose and Legal Basis

The use of LinkedIn Ads is based on your consent in accordance with Article 6(1)(a) GDPR and § 25(1) TTDSG.
We intend to transfer personal data to countries outside the EEA, particularly the USA. Data transfers to the USA are conducted in compliance with Article 45(1) GDPR, based on the European Commission's adequacy decision. The US-based companies involved are certified under the EU-U.S. Data Privacy Framework (EU-U.S. DPF).

Storage Period

The exact storage duration of processed data is determined by LinkedIn Corporation and is beyond our control. For more details, refer to LinkedIn's privacy policy: https://www.linkedin.com/legal/privacy-policy.

 

LinkedIn Analytics

Nature and Scope of Processing

We use LinkedIn Analytics, an analytics tool provided by LinkedIn Ireland Unlimited Company, located at Wilton Place, Dublin 2, Ireland, to analyze and improve user behavior on our website. When you visit our website, LinkedIn sets cookies and similar technologies to collect information about your usage of the site. This data may include your IP address, browser information, operating system details, and interactions with our website. The collected data may also be transferred to LinkedIn's servers in the USA.

Purpose and Legal Basis

The use of LinkedIn Analytics is based on your consent in accordance with Article 6(1)(a) GDPR and § 25(1) TTDSG.
We intend to transfer personal data to countries outside the EEA, particularly the USA. Data transfers to the USA are conducted in compliance with Article 45(1) GDPR, based on the European Commission's adequacy decision. The US-based companies involved are certified under the EU-U.S. Data Privacy Framework (EU-U.S. DPF).

Storage Period

The exact storage duration of processed data is determined by LinkedIn Corporation and is beyond our control. For more details, refer to LinkedIn's privacy policy: https://www.linkedin.com/legal/privacy-policy.

 

Matomo

Nature and Scope of Processing

We use the open-source software tool Matomo (formerly PIWIK) on our website. The software places a cookie in your browser (refer to the section on cookies above for more information). When individual pages of our website are accessed, the following data is stored:

  • Two bytes of the user's system IP address (anonymized IP address)
  • The accessed webpage
  • The website from which the user accessed the current webpage (referrer)
  • The subpages accessed from the current webpage
  • The time spent on the webpage
  • The frequency of webpage visits

The software operates exclusively on the servers of our website. Your personal data is stored solely on these servers and is not shared with third parties.

Purpose and Legal Basis

We process your data using the Matomo analytics software to evaluate the usage of individual components and content of our website. This processing is based on your consent as per Article 6(1)(a) GDPR and § 25(1) TTDSG.

Storage Period

The specific storage duration of the processed data is determined by Matomo and is beyond our control. Further details can be found in Matomo's privacy policy: https://matomo.org/privacy/.

 

Meta Pixel

Nature and Scope of Processing

We use Meta Pixel, a service provided by Meta Platforms Ireland Limited, located at 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. This tool allows us to create custom audiences, segment visitor groups on our online platform, calculate conversion rates, and optimize them. This process is especially applicable when you interact with advertisements we run through Meta Platforms Ireland Limited.

Purpose and Legal Basis

The use of Meta Pixel is based on your consent in accordance with Article 6(1)(a) GDPR and § 25(1) TTDSG.
We intend to transfer personal data to countries outside the European Economic Area (EEA), particularly the USA. Data transfers to the USA are conducted in compliance with Article 45(1) GDPR, based on the European Commission's adequacy decision. The US-based companies involved are certified under the EU-U.S. Data Privacy Framework (EU-U.S. DPF).

Storage Period

The specific storage duration of the processed data is determined by Meta Platforms Ireland Limited and is beyond our control. Further details can be found in Meta Pixel's privacy policy: https://www.facebook.com/privacy/explanation.

 

New Relic

Nature and Scope of Processing

We have integrated the New Relic JS Agent on our website. New Relic JS Agent is a service provided by New Relic, Inc., which develops cloud-based software that enables website and application owners to monitor the performance of their services.

The New Relic JS Agent allows us to assess and improve the stability of our services by monitoring the system and identifying code errors. In this context, your IP address and activities performed on our website are collected. This data is shared with the operator of New Relic JS Agent, New Relic, Inc., based in San Francisco, California, USA.

Purpose and Legal Basis

The use of the New Relic JS Agent is based on your consent as per Article 6(1)(a) GDPR and § 25(1) TTDSG.
We intend to transfer personal data to countries outside the European Economic Area (EEA), particularly the USA. Data transfers to the USA are conducted in compliance with Article 45(1) GDPR, based on the European Commission's adequacy decision. The US-based companies involved are certified under the EU-U.S. Data Privacy Framework (EU-U.S. DPF).

Storage Period

The specific storage duration of the processed data is determined by New Relic, Inc., and is beyond our control. Further details can be found in New Relic's privacy policy: https://newrelic.com/termsandconditions/privacy.

 

Ohrbeit

Nature and Scope of Processing

We use Ohrbeit, a service provided by Fair Recruitment GmbH, located at Untere Hauptstr. 1, 85354 Freising, to manage audio and communication solutions on our website. Ohrbeit is an online platform through which companies and public authorities can produce Jobcasts® for job advertisements or present themselves in topic-specific podcasts.

When using the Ohrbeit widget, no personal data is collected on our website. Only an anonymized session cookie is placed on the user's device. This means Ohrbeit only stores data using a 2-byte process, making localization impossible, and replaces the user ID with a pseudonym. If the widget's link function is used, users are redirected to ohrbeit.de.

Purpose and Legal Basis

The processing of data serves to provide and enhance our audiovisual content and communication options. The legal basis for this is our legitimate interest under Article 6(1)(f) GDPR. Where consent is required, for example, for specific features, the processing is based on Article 6(1)(a) GDPR.

Storage Period

The collected data is stored only as long as necessary to achieve the respective processing purpose or until you withdraw your consent. Upon completion of the purpose or withdrawal of consent, the data is deleted unless legal retention obligations apply. Further information on Ohrbeit's data processing can be found in Ohrbeit's privacy policy: https://ohrbeit.de/datenschutz/.

 

7. Cookies

Nature and Scope of Processing

Cookies are small text files stored on your device that save certain settings and data for communication with our system via your browser. A cookie typically contains the name of the domain from which the cookie data was sent, information about the cookie's age, and an alphanumeric identifier.

Cookies enable our systems to recognize the user’s device and make any preset options immediately available. When a user accesses the platform, a cookie is transmitted to the user's computer's hard drive. Cookies help us improve our website and provide better, more personalized service. They enable us to recognize your computer or mobile device when you return to our website and, therefore:

  • Store information about your preferred activities on the website to customize our website to your individual interests.
  • Speed up the processing of your requests.

We collaborate with third-party services to make our online offerings and website more engaging for you. Thus, cookies from these partner companies (third-party providers) are also stored on your hard drive when you visit the website. These cookies automatically delete themselves after a predefined period.

For more details about individual third-party providers, refer to the cookie consent tool and the privacy notices provided within.

If you do not wish to use browser cookies, you can configure your browser to prevent cookies from being stored. Please note that this may limit or prevent the use of some parts of our website. If you only want to accept our cookies but not the cookies of our service providers and partners, you can select the "block third-party cookies" setting in your browser. We do not assume responsibility for the use of third-party cookies.

 

8. Contacting Us

Nature and Scope of Processing

You can contact us via email, our contact form, or other forms (e.g., for E-Book/Whitepaper downloads). In such cases, we store the personal data you provide to process your request and communicate with you to handle your inquiry. Required fields for contacting us through forms are marked accordingly (with an asterisk). Voluntary information helps us better address your request and process it more effectively. The data you provide is transmitted to us entirely on a voluntary basis.

Depending on the nature of your inquiry, the legal basis for this processing is Article 6(1)(b) GDPR for inquiries made as part of a pre-contractual measure, or Article 6(1)(f) GDPR for other types of inquiries. Legitimate interests derive from the purposes outlined in Section 4. If personal data is requested that is not necessary for fulfilling a contract or protecting legitimate interests, the data is provided to us based on your consent in accordance with Article 6(1)(a) GDPR.


9. Order Processing

Nature and Scope of Processing

We process orders you place with us. To fulfill the order, we collect the following data, among others:

  • Contact details (e.g., company, first name, last name, email address)
  • Billing and, if necessary, delivery address
  • Other contractual data

This data is used to fulfill your order in line with contractual obligations, manage the order, invoice, and deliver the order. Additionally, your email address is used to confirm your order and for further communication necessary for contract execution.

Where required for order fulfillment, we will share necessary information with third-party service providers (e.g., shipping companies).

Legal Basis

The legal basis for this processing is the performance of a contract under Article 6(1)(b) GDPR.

 

10. Event Registration and Training Requests

Nature and Scope of Processing

On our website, you have the opportunity to register for events (e.g., webinars). For this, we collect the following data, with mandatory fields marked accordingly (e.g., with an asterisk): company, email, first name, last name, and job title.

This data is used to process your registration and carry out the event. The legal basis for this data processing is the fulfillment of the contract with you under Article 6(1)(b) GDPR.

Additionally, our website allows you to submit training requests. For this, we collect the following data, with mandatory fields marked accordingly (e.g., with an asterisk): email, first name, last name, and preferred dates.

We process this data solely to respond to your inquiry as effectively as possible. The legal basis for this data processing is our legitimate interest in answering your inquiry under Article 6(1)(f) GDPR or, if your request pertains to entering into or performing a contract, the execution of your contract under Article 6(1)(b) GDPR.

 

11. Customer Account Creation

Nature and Scope of Processing

If you create a customer account on our website, we collect the following data, with mandatory fields marked accordingly (e.g., with an asterisk): first name, last name, email, job title, company, address line, postal code, city, state/region, and country/region.

This data is used to verify your identity, ensure the registration requirements are met, and confirm and verify your account creation. Additionally, this information is stored in your account for future contract-related transactions. You can also store additional information in your account for easier management of your personal data, administration of your website usage, and contract relationships, including the initiation, content management, execution, and modification of contracts concluded through your customer account.

The processing of the aforementioned personal data for these purposes is based on Article 6(1)(b) GDPR.

You can always update or delete your data, including your user account, within the customer area. With your consent, we may use the provided data to inform you about additional products in our portfolio or to send you technical information emails.

We are legally obliged to store your address, payment, and order data for ten years due to commercial and tax regulations.

To prevent unauthorized access by third parties to your personal data, particularly financial data, the ordering process is encrypted using TLS technology.

We recommend that you always keep your login data confidential and close your browser window when you finish communicating with us to prevent misuse.

 

12. BCT Service Desk

Nature and Scope of Processing

Our website offers you the option to submit support requests through the helpdesk. We process the following data, with mandatory fields marked accordingly (e.g., with an asterisk): email, first name, last name, company, phone number, priority, request type, manufacturer, software version, ticket name, ticket description, and file uploads. Additionally, we collect information automatically sent by your browser or device, such as your IP address, device type, browser type, referring website, accessed websites during your visit, and the date and time of each visitor request. This data is used exclusively for logging purposes and is deleted periodically.

We process this data solely to respond to your support inquiries as effectively as possible. The legal basis for this data processing is the performance of a contract under Article 6(1)(b) GDPR.

Application Process

Nature and Scope of Processing

We publish job postings on our website, which you can apply to using our applicant form. If you decide to apply for an open position, we process the personal data you provide and submit solely for the purpose of conducting the application process.

The legal basis for processing your personal data during the application process is § 26(1) in conjunction with (2) of the BDSG and Article 6(1)(b) GDPR.

In the event of a rejection, we delete your data once a legally mandated retention period of six months has elapsed. This period begins with the sending of the rejection. If you have explicitly consented to further use of your data for future contact regarding potentially interesting positions, we will retain your data in accordance with your consent.

If the application process leads to an employment relationship, the data will be stored further as necessary and permissible, and subsequently transferred to the personnel file.

Your personal data may be processed on our behalf based on data processing agreements under Article 28 GDPR. In such cases, we ensure that the processing of personal data complies with the General Data Protection Regulation.

Data sharing with recipients outside the company occurs only if permitted or required by legal provisions, necessary for meeting legal obligations, or based on your consent. Data transfer to third countries is not intended.

The provision of personal data in the context of application processes is neither legally nor contractually required. Therefore, you are not obligated to provide personal data. However, providing personal data is necessary for deciding on an application or forming an employment relationship with us. You should only provide personal data that is required for initiating and carrying out the application process. If you do not provide personal data in your application, we cannot make a decision regarding the establishment of an employment relationship.

Please note that applications sent to us via email are transmitted unencrypted. This means there is a risk that unauthorized individuals could intercept and misuse this data.

 

13. Social Icons

Nature and Scope of Processing

Our website includes icons for social networks. For improved protection of your data when visiting our website, these buttons are not integrated as unrestricted plugins but as HTML links. This type of integration ensures that when you access a page of our website containing such buttons, no direct connection is established with the servers of the social network operators. Clicking such a button opens the page of the social network (e.g., Facebook) in a new browser window. There, you can interact with the plugins (if logged in beforehand).

The purpose and scope of data collection, further processing, and use of the data by the social networks, as well as your rights and settings options to protect your privacy, can be found in the privacy notices of the respective social network operators.

 

14. Presence on Social Media

To present our company as effectively as possible and to communicate with you as a user, customer, or potential client, as well as to inform you about our offered services, we maintain a presence on social networks. Using social networks involves the processing of data outside the European Union (EU) and the European Economic Area (EEA). An equivalent level of data protection as available within the EU cannot be guaranteed in all countries outside the EU. This may pose risks for you as a user if the transferred data is processed in third countries with an inadequate level of data protection.

This may hinder the enforcement of known user rights. Additionally, it is possible that your data may be processed by the provider in the third country in ways that are not in your best interest. We only transfer personal data to third countries where an adequate level of protection has been confirmed, or when the transfer of personal data can be ensured through contractual agreements or other appropriate safeguards.

In addition to the respective provider of a social network, we also collect and process personal user data on so-called “fan pages.” This notice informs you about which data we collect from you on our social media pages, how we use it, and how you can object to the use of your data. The specific purposes of data processing and data categories can be found in the respective offerings detailed below. Our activities on social media, as described below, are carried out based on a balancing of interests in accordance with Article 6(1)(f) GDPR.

To achieve this, cookies are used to capture user behavior and enable user profiling. A detailed list of the purposes for processing user data can be found in the privacy notices of the respective providers. By adjusting settings in your user account, you can, at least partially, limit profiling. For precise instructions, please refer to the respective provider’s privacy notices.

The relevant platforms are:

Platform

Responsible Party

Privacy Policy of the Platform Operator

Facebook

Meta Platforms Ireland Ltd

4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland

https://privacycenter.instagram.com/
policy/

Instagram

Meta Platforms Ireland Ltd

4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland

https://privacycenter.instagram.com/
policy/

YouTube

Google Ireland Limited

Gordon House, Barrow Street,
Dublin 4, Ireland

https://policies.google.com/
privacy?hl=de

X

Twitter Inc

1355 Market Street, Suite 900, San Francisco, CA 94103, USA

https://x.com/de/privacy

LinkedIn

LinkedIn Ireland Unlimited Company

Wilton Place, Dublin 2, Ireland

https://de.linkedin.com/legal/
privacy-policy?


We maintain profiles on these platforms to promote products and service offerings, as well as to interact with customers, potential clients, and other users of the platforms.

Platform operators use certain data collected from users (e.g., whether a photo on a profile has been "liked" or commented on) to create aggregated usage statistics and make them available to the respective profile operators (referred to as "Insights" or "Analytics"). We, as profile operators, also receive such usage statistics. However, the information provided to us as profile operators does not allow us to identify individual users. As profile operators, we do not have access to the personal data that the platform operators process to create these usage statistics. It is solely the responsibility of the respective platform operator to determine which data is processed and how for these purposes. We, as profile operators, have no legal or practical influence on the processing by the platform operators.

For processing related to the creation of usage statistics, we are considered joint controllers with the respective platform operator as per Article 26 GDPR. Where possible, we have agreements on joint responsibility with the respective platform operators.

Limited Data Processing by Us as Profile Operators

Additionally, data processing by us as profile operators occurs only to a very limited extent:

  • Processing of usernames and comments that are deleted due to a violation of netiquette. These are retained within the statute of limitations to provide evidence in case of legal disputes.
  • Processing of usernames and individual messages when you contact us via messenger services.
  • Processing of usernames and posts in the context of inquiries and obtaining consent for re-posting images.
  • Recruiting potential candidates on career platforms.

For these purposes, we typically process only your name, message content, comment content, and publicly available profile information you have provided.

 

15. Newsletter

Subscription and Double-Opt-In Procedure

With your consent, you can subscribe to our newsletter, which informs you about our latest and most interesting offers. The advertised products and services are described in the consent declaration.

We use a double-opt-in process for newsletter registration. This means that after you register, we will send an email to the specified email address asking for your confirmation that you wish to receive the newsletter. Additionally, we store the IP addresses used at the time of registration and confirmation, along with the timestamps. The purpose of this procedure is to verify your registration and, if necessary, investigate any misuse of your personal data.

The only mandatory information required for sending the newsletter is your email address. Any other data you provide, which is explicitly marked as optional, is used to address you personally. After your confirmation, we store your email address for the purpose of sending the newsletter. The legal basis for this processing is Article 6(1)(a) GDPR.

Data Processing and Third-Party Services

Your personal data is processed on our behalf under data processing agreements pursuant to Article 28 GDPR. We use the email marketing software from HubSpot European Headquarters, Ground Floor, Two Dockland Central, Guild Street, Dublin 1, Ireland, for sending marketing emails. Therefore, your data is stored in a database maintained by HubSpot, which may access your data. We ensure that the processing of personal data complies with the GDPR.

Withdrawal of Consent

You can withdraw your consent to receive the newsletter at any time and unsubscribe. You can withdraw your consent by clicking on the link provided in every newsletter email, by emailing us at bct_datenschutz@bct-technology.com, or by contacting us through the information provided in our website's imprint.

Tracking and Usage Analysis

We inform you that when the newsletter is sent, we analyze your user behavior. The emails we send include web beacons or tracking pixels, which are one-pixel image files stored on our website. For these analyses, we link the data collected and the web beacons with your email address and an individual ID.

Using this data, we create a user profile to tailor the newsletter to your individual interests. We record when you read our newsletters, which links you click, and infer your personal interests from this data. We also link this data to actions you take on our website.

You can object to this tracking at any time by clicking the designated link provided in each email or by informing us via another contact method. The information is stored as long as you remain subscribed to the newsletter. After unsubscribing, the data is stored purely for statistical and anonymous purposes.

 

16. Rights of the Data Subject

As a data subject, you have the following rights:

  • Right of Access (Art. 15 GDPR): You have the right to request information about your personal data processed by us. This includes details about the purposes of the processing, the categories of personal data involved, the recipients to whom your data has been or will be disclosed, the planned storage duration, the existence of rights to rectification, erasure, restriction of processing, or objection, the existence of a right to lodge a complaint, the source of your data if not collected by us, and the existence of automated decision-making, including profiling, along with meaningful information about its details.
  • Right to Rectification (Art. 16 GDPR): You have the right to request the immediate correction of inaccurate personal data or the completion of incomplete personal data stored by us.
  • Right to Erasure (Art. 17 GDPR): You can request the deletion of your personal data stored by us, provided that its processing is not required to exercise the right to freedom of expression and information, to fulfill a legal obligation, for reasons of public interest, or to establish, exercise, or defend legal claims.
  • Right to Restriction of Processing (Art. 18 GDPR): You can request the restriction of the processing of your personal data if you contest the accuracy of the data, the processing is unlawful but you oppose its deletion, we no longer need the data but you require it for the establishment, exercise, or defense of legal claims, or you have objected to the processing pursuant to Art. 21 GDPR.
  • Right to Data Portability (Art. 20 GDPR): You have the right to receive your personal data, which you have provided to us, in a structured, commonly used, and machine-readable format or to request its transmission to another controller.
  • Right to Withdraw Consent (Art. 7(3) GDPR): You have the right to withdraw your consent at any time. This will result in us ceasing any data processing based on your consent for the future.
  • Right to Lodge a Complaint (Art. 77 GDPR): You have the right to lodge a complaint with a supervisory authority, typically the one in your habitual residence, workplace, or our company’s headquarters.

Right to Object (Art. 21 GDPR):
If your personal data is processed on the basis of legitimate interests under Art. 6(1)(f) GDPR, you have the right to object to its processing for reasons arising from your particular situation or if your objection concerns direct marketing. In the latter case, you have a general right to object, which we will implement without requiring a specific situation.

To exercise your rights of withdrawal or objection, please email us at bct_datenschutz@bct-technology.com.


17. Disclosure of Your Personal Data

Your personal data will be disclosed as described below.

We may disclose your data when required or permitted by law, such as in response to legal obligations, administrative orders, or court decisions. This may include providing information for law enforcement, risk prevention, or the enforcement of intellectual property rights.

If your data is shared with service providers, it is limited to the extent necessary for them to perform their tasks. These service providers are required to handle your personal data in accordance with applicable data protection laws, particularly the GDPR. Where personal data is processed on our behalf under processing agreements pursuant to Art. 28 GDPR, we ensure compliance with data protection regulations.

We prioritize processing your data within the EU/EEA. However, in cases where service providers outside the EU/EEA are used, we ensure an adequate level of data protection comparable to EU standards before transferring your data. This is achieved through EU Standard Contractual Clauses, Binding Corporate Rules, or special agreements to which the recipient company adheres.


18. Data Security

We secure our website and your data through technical and organizational measures to protect against loss, destruction, unauthorized access, alteration, or distribution.

Your personal data is transmitted to us in encrypted form using SSL/TLS (Secure Sockets Layer/Transport Layer Security) technology. We continuously enhance our security measures to align with technological developments.

 

19. Storage Duration for Personal Data

Personal data is deleted when it is no longer required for the purpose for which it was collected and no legal retention periods apply. Legal retention periods determine the final storage duration of personal data. Once these periods expire, the relevant data is routinely deleted. During the retention period, the processing of data is restricted by locking the data.

 

20. References and Links

When accessing third-party websites linked on our website, you may be asked to provide information such as your name, address, email address, or browser details. This privacy policy does not govern the collection, sharing, or handling of personal data by third parties.

Third-party service providers may have different and independent data handling policies. We recommend reviewing the privacy practices of such third-party websites before providing personal data.

Effective Date: October 2024