Information in accordance with the GDPR
Privacy Policy
The protection of your personal data is of great importance to us. We therefore wish to provide you here with full details regarding the processing and storage of your data when you visit our website and within our company. In order to make use of all the functions and services on our site, it is necessary to collect your personal data. However, processing and storage are carried out solely in accordance with the legal guidelines and requirements of the General Data Protection Regulation (GDPR), the Federal Data Protection Act (BDSG) and the Telecommunications and Digital Services Data Protection Act (TDDDG).
1. Data controller
Aidera GmbH
Leopoldstraße 20
80802 Munich
Germany
Further information can be found in the legal notice.
2. Data Protection Officer
Mag. Elisa Drescher
Contact: office@scaleline-ltd.com
3. Collection and processing of personal data on this website
Note: To protect your data as comprehensively as possible against unauthorised access, we implement technical and organisational measures and use an encryption method on our website. Your data is transmitted via the internet from your computer to ours and vice versa using TLS encryption. TLS stands for “Transport Layer Security” and is an encryption protocol for data transmission over the internet. You can usually recognise “TLS” by the fact that the padlock symbol in your browser’s status bar is closed and the address begins with https://.
4. Collection of access and log data
This website automatically collects and stores server log file information that your browser transmits to us. This includes
- – the user’s IP address,
- – date and time of access,
- – type of request,
- – customer information such as type and version,
- – the user’s operating system (device, device OS version),
- – referrer information (i.e. the source of the access)
The legal basis for this data processing is the legitimate interest pursuant to Article 6(1)(f) of the GDPR. This legitimate interest is based on the need to identify indications of unlawful use of our website (e.g. defence against hacker attacks) and to ensure a smooth connection. The data collected is stored in server log files, which your browser automatically transmits to us in encrypted form. We only store the server log files in the event of attacks on our server infrastructure or other legal violations. This extended storage period is based on our legitimate interest pursuant to Article 6(1)(f) of the GDPR and serves solely to preserve evidence.
We use “Vercel Web Analytics” to compile anonymous statistics on visits to our website. When using Vercel Web Analytics, no personal identifiers are collected that track and match end-user data across different applications or websites. By default, Vercel Web Analytics only uses aggregated data that does not allow for the identification or re-identification of the customer’s end users. Vercel Web Analytics does not collect or store any information that would enable you to reconstruct an end user’s browsing session across different applications or websites and/or to personally identify an end user. Only a minimal amount of data is collected, which is used solely for aggregated statistics.
We have entered into a data processing agreement in accordance with Article 28 of the GDPR with the provider of this website, Vercel Inc., which is based in the USA. This is a contract required under data protection law that ensures Vercel Inc. processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR. Vercel Inc. is certified under the Data Privacy Framework. This can be viewed at dataprivacyframework.gov/list.
5. Embedding of YouTube videos
On individual pages of our website we embed videos from the YouTube platform. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
The videos are deactivated by default. Simply visiting our website does not transmit any data to YouTube or Google. Only when you choose “Accept all” in the cookie notice or click “Accept and load video” in the video frame is the video embedded and a connection to YouTube’s servers established. In doing so, your IP address is transmitted to YouTube and cookies or comparable technologies may be stored on your device. If you are logged into your YouTube account at the same time, YouTube may associate your usage behaviour with your personal profile. You can prevent this by logging out of your YouTube account before starting a video.
We embed YouTube in extended data protection mode (youtube-nocookie.com). According to the provider, information about your visit is only stored once you start playing the video.
The legal basis for the transfer is your consent pursuant to Article 6(1)(a) of the GDPR and Section 25(1) TDDDG. You give this consent via the cookie notice or the button in the video frame. Your choice is stored exclusively locally in your browser (local storage entry “aidera-consent”, technically necessary pursuant to Section 25(2) no. 2 TDDDG); no data is transmitted to us or third parties for this purpose. You may withdraw your consent at any time with effect for the future by clicking “Cookie settings” in the footer and choosing “Essential only”.
A transfer of your data to the USA cannot be ruled out in this context. Google LLC is certified under the EU-US Data Privacy Framework.
Alternatively, you can watch the videos directly on YouTube without a connection to Google being established when you visit our website. Further information on the handling of user data can be found in Google’s privacy policy.
6. Booking online appointments
To simplify the booking of appointments, we use the “lemcal” software provided by Lempire SAS, 128 rue la Boétie, 75008 Paris, France, with whom a data processing agreement has been concluded in accordance with Article 28 of the GDPR. Furthermore, we do not pass on your data to third parties. As Lempire SAS is a French company based in the EU, no data is transferred to third countries; processing takes place within the European Economic Area.
To process the booking, we collect your name and email address. After booking, you will receive an appointment confirmation by email, including the access link to the online meeting, as well as a reminder message prior to the appointment to help you avoid missing it. You may cancel the booked appointment or reschedule it at any time.
The legal basis for data processing when booking via lemcal, as well as for the confirmation and reminder emails sent in this context, is your consent pursuant to Article 6(1)(a) of the GDPR. Booked appointments are deleted after 6 months.
7. Data processing of business partners and customers
Fulfilment of contractual obligations (Article 6(1)(b) GDPR)
The purposes of data processing arise from the implementation of pre-contractual measures and the fulfilment of obligations arising from the concluded contract.
To process the contract with you, we process master data such as your first and last name, your billing address, and your billing and payment details. We use your email address for communication purposes. Furthermore, we process your data in our accounting system sevDesk provided by sevDesk GmbH, based in Offenburg, Germany. We have a data processing agreement with sevDesk GmbH in accordance with Article 28 of the GDPR.
To fulfil legal obligations (Article 6(1)(c) GDPR)
The purposes of data processing are determined on a case-by-case basis by legal requirements. These legal obligations include, for example, compliance with retention and identification requirements—such as those relating to tax audit and reporting obligations—and data processing in response to requests from public authorities. In this context, data may also be transferred to our appointed tax adviser.
To fulfil our legitimate interests (Article 6(1)(f) GDPR)
We process the contact details of contact persons at customers, prospective customers, suppliers and other business partners for communication by email, telephone and post. The legal basis for data processing is the legitimate interest pursuant to Article 6(1)(f) of the GDPR. This legitimate interest arises from the need to conduct or initiate business relationships with customers, prospective customers, suppliers and other business partners, as well as to maintain personal contact with contact persons.
We do not, as a matter of principle, pass on data to third parties.
Personal data is stored for the purpose of conducting business relationships for as long as there is a legitimate interest in doing so. It may be necessary to process the personal data you have provided beyond the actual fulfilment of the contract with business partners. The legitimate interests in this context are, in particular, the selection of suitable business partners, compliance with regulatory requirements, the assertion of legal claims, the defence against liability claims, the prevention of criminal offences and the settlement of claims arising from the business relationship.
Who receives the personal data you provide?
Within the scope of contractual relationships, we may also engage data processors or service providers who may have access to your personal data. Compliance with data protection regulations is contractually ensured in this regard.
Retention period
Personal data will be retained for as long as is necessary to fulfil the purposes set out above.
Data processing for the purpose of documenting compliance with the GDPR
Where your data is processed on the basis of consent pursuant to Article 6(1)(a) of the GDPR or Article 9(2)(a) of the GDPR, we process your data exclusively for the specified purpose and following separate notification, in order to be able to demonstrate, within the framework of our accountability obligation under Article 5(2) of the GDPR, that you have consented to the data processing in question.
Where you exercise your rights as a data subject under the GDPR vis-à-vis us, we also process and store your data in order to be able to demonstrate, within the framework of the accountability obligation under Article 5(2) of the GDPR, that we have complied with the GDPR when processing your request.
Where you exercise your rights under the GDPR against us, your data may be transferred to our external data protection consultancy (SCALELINE Datenschutz).
8. Data processing in the context of application processes
You may send us your application documents by email for the purpose of receiving and managing your application and thus for the purpose of (potentially) establishing an employment relationship. As part of the application process, we only collect data from you that is necessary for the establishment of an employment relationship with us. The legal basis for this data processing is Article 6(1)(b) of the GDPR and Section 26(1) of the BDSG. Within our company, only those persons involved in the decision-making process have access to your personal data.
In the event of a successful application, your personal data will be stored for the duration of your employment. Furthermore, following the termination of your employment, your tax-related data will be archived in accordance with statutory retention periods. In the event of an unsuccessful application, your personal data will be deleted six months after the rejection.
9. Data processing in connection with video conferences via Google Meet
We use the Google Meet tool provided by Google Ireland Limited to conduct telephone conferences, online meetings and video conferences. You will receive access to the agreed appointments via a link sent by email. By clicking on the link, you can join the video room. Before joining, you can decide for yourself whether to activate your video feed. You are muted by default and must manually unmute your microphone if you wish to do so. If you switch on your camera and/or microphone, this data will be processed during the meeting.
The following additional data may also be processed, depending on the nature and scope of the specific use:
- – Personal details (e.g. first name and surname, email address, profile picture)
- – Meeting metadata (e.g. date, time and duration of the communication, name of the meeting, participant IP address)
- – Device/hardware data (e.g. IP addresses, MAC addresses, client version)
- – Text, audio and video data (e.g. chat histories, video, audio and presentation recordings)
- – Connection data (e.g. phone numbers, country names, start and end times, IP addresses)
Furthermore, personal data relating to you may be processed. This depends specifically on your usage. We expressly draw your attention to the fact that information you provide during the ongoing meeting will be processed at least for the duration of the meeting.
The legal basis for data processing for direct contractual partners is Article 6(1)(b) of the GDPR; for business partners or contact persons at external organisations, it is the legitimate interest pursuant to Article 6(1)(f) of the GDPR. The legitimate interest lies in the organisation of virtual communication.
The provider Google necessarily gains knowledge of the aforementioned data, insofar as this is contractually regulated within the framework of our data processing agreement pursuant to Article 28 of the GDPR. There are no other recipients. We cannot rule out the possibility that data may also be routed via internet servers located outside the EU or the EEA. Google LLC holds a valid certification under the Data Privacy Act as an adequacy decision for the USA.
You are not obliged to communicate with us via Google Meet. Alternatively, communication may also take place by email or telephone.
We generally delete personal data when there is no longer a need for further storage.
10. Rights of data subjects
YOU HAVE THE RIGHT UNDER ART. 15(1) GDPR TO RECEIVE, UPON REQUEST AND FREE OF CHARGE, INFORMATION ABOUT THE PERSONAL DATA STORED ABOUT YOU. FURTHERMORE, PROVIDED THE LEGAL REQUIREMENTS ARE MET, YOU HAVE THE RIGHT TO RECTIFICATION (ART. 16 GDPR), ERASURE (ART. 17 GDPR) AND RESTRICTION OF PROCESSING (ART. 18 GDPR) OF YOUR PERSONAL DATA. IF YOU HAVE PROVIDED THE PROCESSED DATA YOURSELF, YOU HAVE A RIGHT TO DATA PORTABILITY IN ACCORDANCE WITH ART. 20 GDPR.
IF THE DATA PROCESSING IS BASED ON ARTICLE 6(1)(e) OR (f) OF THE GDPR, YOU HAVE THE RIGHT TO OBJECT UNDER ARTICLE 21 OF THE GDPR. IF YOU OBJECT TO DATA PROCESSING, IT WILL CEASE IN THE FUTURE, UNLESS THE CONTROLLER CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR CONTINUING THE PROCESSING WHICH OVERRIDE THE DATA SUBJECT’S INTEREST IN OBJECTING.
IF THE DATA PROCESSING IS BASED ON CONSENT PURSUANT TO ART. 6(1)(a), ART. 9(2)(a) OR ART. 49(1)(a) GDPR, YOU MAY WITHDRAW YOUR CONSENT AT ANY TIME WITH EFFECT FOR THE FUTURE, WITHOUT THIS AFFECTING THE LAWFULNESS OF THE PROCESSING CARRIED OUT UP TO THAT POINT.
YOU ALSO HAVE THE RIGHT TO LODGE A COMPLAINT WITH A DATA PROTECTION SUPERVISORY AUTHORITY. IN PARTICULAR, YOU MAY LODGE A COMPLAINT WITH A SUPERVISORY AUTHORITY IN THE EU MEMBER STATE OF YOUR RESIDENCE, YOUR WORKPLACE OR THE PLACE WHERE THE ALLEGED INFRINGEMENT OCCURRED.
Contact details for the relevant data protection authority
Bavarian State Office for Data Protection Supervision
PO Box 1349
91504 Ansbach, Germany
Telephone: +49 (0) 981 180093-0 · Fax: +49 (0) 981 180093-800 · Email: poststelle@lda.bayern.de
11. No automated decision-making
We do not carry out automated decision-making or profiling.
12. Provision
Unless otherwise stated in the preceding sections, the provision of personal data is neither required by law nor by contract, nor is it necessary for the conclusion of a contract. Failure to provide your personal data may mean, for example, that we are unable to respond to your enquiries.
This privacy notice has been drawn up in collaboration with the consultancy firm SCALELINE Datenschutz. The legal texts are subject to copyright.