PRIVACY POLICY
IN ACCORDANCE WITH THE GDPR
Name and contact details of the controller responsible for processing and of the company data protection officer
This Privacy Policy informs you about the personal data collected when you use this website. Personal data means any data that can be related to you personally, such as your name, address, telephone number, email address, etc.
This privacy information applies to data processing by:
Controller pursuant to Art. 4 (7) of the EU General Data Protection Regulation (GDPR):
SPACT GmbH (hereinafter: Controller),
Eupener Straße 161, 50933 Cologne, Germany
Email: info@spact.de
Telephone: +49 221 485-2222
Fax: +49 221 485-2001
Our data protection officer is:
Rechtsanwalt Eckhart Baum
Waisenhausgasse 9, 50676 Cologne
Email: anwalt.baum [@] email.de
The supervisory authority responsible pursuant to Art. 55 GDPR is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestr. 2-4, 40213 Düsseldorf
Telephone: +49 211 38424-0
Fax: +49 211 38424-999
Email: poststelle@ldi.nrw.de
Collection and storage of personal data as well as the nature and purpose of its use
a) When visiting the website
When you access our website, only the personal data that the browser you use automatically transmits to our website server is collected. This information is temporarily stored in a so-called log file. The following information is collected without any action on your part and stored until it is automatically deleted:
- IP address of the requesting computer,
- date and time of access,
- the selected privacy settings/privacy level,
- name and URL of the retrieved file,
- website from which access is made, referrer URL,
- browser used and, where applicable, the operating system of your computer as well as the name of your access provider.
We process the data listed above for the following purposes:
- to ensure a smooth connection to the website,
- to ensure convenient use of our website,
- to evaluate system security and stability, and
- for other administrative purposes.
The legal basis for data processing is Art. 6 (1) sentence 1 lit. f GDPR. Our legitimate interest follows from the purposes of data collection listed above. Under no circumstances do we use the collected data for the purpose of drawing conclusions about your person.
In addition, we use cookies when you visit our website. Further explanations can be found under section 4 of this Privacy Policy.
b) When you contact us by email
You are welcome to contact us by email with any questions. In doing so, we store the information you voluntarily provide, such as your email address, possibly your name and a callback number, as well as your request, in order to respond to your enquiry.
We delete the data stored in this context when it is no longer required and when there are no statutory provisions preventing deletion.
Here you can change your privacy settings for the use of our website.
Disclosure of data
Your personal data will not be transferred to third parties for purposes other than those listed below.
We only disclose your personal data to third parties if:
- you have given your express consent pursuant to Art. 6 (1) sentence 1 lit. a GDPR,
- the disclosure is necessary pursuant to Art. 6 (1) sentence 1 lit. f GDPR for the establishment, exercise or defence of legal claims and there is no reason to assume that you have an overriding legitimate interest in your data not being disclosed,
- there is a legal obligation to disclose the data pursuant to Art. 6 (1) sentence 1 lit. c GDPR, or
- this is legally permissible and necessary pursuant to Art. 6 (1) sentence 1 lit. b GDPR for the performance of contractual relationships with you.
Cookies
We use cookies on our website. These are small text files that your browser automatically creates and that are stored on your device, such as laptop, tablet or smartphone, when you visit our website. Cookies do not cause any damage to your device and do not contain viruses, Trojans or other malware. Information is stored in the cookie that is connected to the specific device used. However, this does not mean that we obtain direct knowledge of your identity as a result. The use of cookies serves, on the one hand, to make the use of our offering more convenient for you. We use so-called session cookies to recognise that you have already visited individual pages of our website. These are automatically deleted after you leave our website.
In addition, we also use temporary cookies to optimise user-friendliness. These are stored on your device for a specified period of time. If you visit our website again to use our services, it is automatically recognised that you have already visited us and which inputs and settings you made, so that you do not have to enter them again.
Most browsers accept cookies automatically. However, you can configure your browser so that no cookies are stored on your computer, cookies are automatically deleted when the program is closed, or a notice always appears before a new cookie is created.
However, completely disabling cookies may mean that you cannot use all functions of our website.
The data processed by cookies is necessary for the purposes mentioned above in order to safeguard our legitimate interests and those of third parties pursuant to Art. 6 (1) sentence 1 lit. f GDPR.
Google Web Fonts
This website uses so-called web fonts provided by Google for the uniform display of fonts. When you access a page, your browser loads the required web fonts into your browser cache in order to display texts and fonts correctly. These Google Fonts are installed locally; no connection to Google servers is established in this process.
If your browser does not support web fonts, a standard font from your computer will be used.
Social networks in detail
LinkedIn:
We maintain a profile on LinkedIn. The provider is LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland. LinkedIn has certification under the EU-US Privacy Shield. LinkedIn uses advertising cookies.
If you wish to deactivate LinkedIn advertising cookies, please use the following link: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
If you apply to us via the LinkedIn platform, please note the following information:
We use job advertisements on LinkedIn with the most privacy-friendly default settings possible. This means that we do not use automated applicant preselection, see Art. 22 GDPR, nor do we use the aptitude tests and questions offered by LinkedIn that would be associated with a preselection label.
If, contrary to our request, you have applied for our job advertisement via the “Apply” button on LinkedIn, we will transfer your data from LinkedIn and inform you without delay pursuant to Art. 13/14 GDPR about the transfer of data. We will then delete your application from LinkedIn. From that point onward, the same privacy information applies to your application as for the “traditional” application process.
XING:
We maintain a profile on XING. The provider is XING AG, Dammtorstraße 29-32, 20354 Hamburg, Germany. Details on how XING handles your personal data can be found in XING’s privacy policy: https://privacy.xing.com/de/datenschutzerklaerung.
Rights of data subjects
You have the right:
-
pursuant to Art. 15 GDPR, to request information about your personal data processed by us. In particular, you may request information about the purposes of processing, the category of personal data, the categories of recipients to whom your data has been or will be disclosed, the planned storage period, the existence of a right to rectification, erasure, restriction of processing or objection, the existence of a right to lodge a complaint, the origin of your data if it was not collected by us, as well as the existence of automated decision-making, including profiling, and, where applicable, meaningful information about its details;
-
pursuant to Art. 16 GDPR, to request the immediate rectification of inaccurate personal data stored by us or the completion of incomplete personal data stored by us;
-
pursuant to Art. 17 GDPR, to request the erasure of your personal data stored by us, unless the processing is necessary for exercising the right of freedom of expression and information, for complying with a legal obligation, for reasons of public interest or for the establishment, exercise or defence of legal claims;
-
pursuant to Art. 18 GDPR, to request the restriction of the processing of your personal data where the accuracy of the data is contested by you, the processing is unlawful but you oppose its erasure, we no longer need the data but you require it for the establishment, exercise or defence of legal claims, or you have objected to processing pursuant to Art. 21 GDPR;
-
pursuant to Art. 20 GDPR, to receive your personal data that you have provided to us in a structured, commonly used and machine-readable format or to request that it be transmitted to another controller;
-
pursuant to Art. 7 (3) GDPR, to withdraw your consent once given to us at any time. This means that we may no longer continue the data processing based on this consent in the future; and
-
pursuant to Art. 77 GDPR, to lodge a complaint with a supervisory authority. As a rule, you may contact the supervisory authority of your usual place of residence or workplace or of our company headquarters for this purpose. A list of contact details can be found at https://www.bfdi.bund.de/DE/Service/Anschriften/anschriften_table.html.
Right to object
If your personal data is processed on the basis of legitimate interests pursuant to Art. 6 (1) sentence 1 lit. f GDPR, you have the right pursuant to Art. 21 GDPR to object to the processing of your personal data, provided that there are grounds relating to your particular situation or that the objection is directed against direct advertising. In the latter case, you have a general right to object, which we will implement without you having to provide reasons relating to a particular situation. If you wish to exercise your right of withdrawal or objection, sending an email to info@spact.de is sufficient.
Data security
During visits to our website, we use the widely used SSL method, Secure Socket Layer, in combination with the highest level of encryption supported by your browser. This is usually 256-bit encryption. If your browser does not support 256-bit encryption, we use 128-bit v3 technology instead. You can recognise whether an individual page of our website is transmitted in encrypted form by the closed key or lock symbol in the lower status bar of your browser.
We also use appropriate technical and organisational security measures to protect your data against accidental or intentional manipulation, partial or complete loss, destruction, or unauthorised access by third parties. Our security measures are continuously improved in line with technological development.
Current status and amendment of this Privacy Policy
This Privacy Policy is currently valid and was last updated in September 2023.
Due to the further development of our website and services offered on it, or due to changed legal or regulatory requirements, it may become necessary to amend this Privacy Policy. The current Privacy Policy can be accessed and printed out at any time on the website at https://spact.de/en/privacy-statement.html.