Datenschutzerklärung

1. Datenschutz auf einen Blick

Allgemeine Hinweise

Die folgenden Hinweise geben einen einfachen Überblick darüber, was mit Ihren personenbezogenen Daten passiert, wenn Sie diese Website besuchen. Personenbezogene Daten sind alle Daten, mit denen Sie persönlich identifiziert werden können. Ausführliche Informationen zum Thema Datenschutz entnehmen Sie unserer unter diesem Text aufgeführten Datenschutzerklärung.

Wer ist verantwortlich für die Datenerfassung auf dieser Website?

Die Datenverarbeitung auf dieser Website erfolgt durch den Websitebetreiber. Die Kontaktdaten finden Sie im Abschnitt „Angaben zum Verantwortlichen“ sowie im Impressum dieser Website.

Wie erfassen wir Ihre Daten?

Ihre Daten werden zum Teil dadurch erhoben, dass Sie uns diese zur Verfügung stellen – beispielsweise über unser Kontaktformular. Andere Daten werden automatisch beim Besuch der Website durch die von uns eingesetzten IT-Systeme erhoben. Dabei handelt es sich vor allem um technische Daten wie Browsertyp, Betriebssystem, Zeitpunkt des Seitenbesuchs und IP-Adresse. Eine Reichweitenmessung erfolgt nur nach Ihrer ausdrücklichen Einwilligung.

Wofür nutzen wir Ihre Daten?

Ein Teil der Daten wird erfasst, um einen fehlerfreien Betrieb der Website zu gewährleisten. Mit Ihrer Einwilligung werten wir darüber hinaus die Nutzung der Website pseudonym aus, um unser Angebot zu verbessern. Dabei wird Ihre IP-Adresse an unseren Analyseanbieter übermittelt und dort in eine täglich wechselnde Kennung umgewandelt; Einzelheiten hierzu finden Sie im Abschnitt „Reichweitenmessung (PostHog)“.

Welche Rechte haben Sie bezüglich Ihrer Daten?

Sie haben jederzeit das Recht, unentgeltlich Auskunft über die Herkunft, die Empfänger und den Zweck Ihrer gespeicherten personenbezogenen Daten zu erhalten, sowie das Recht auf Berichtigung, Löschung oder Einschränkung der Verarbeitung und auf Datenübertragbarkeit. Sie können eine erteilte Einwilligung jederzeit mit Wirkung für die Zukunft widerrufen. Sie haben außerdem ein Widerspruchsrecht und das Recht, eine Beschwerde bei der zuständigen Aufsichtsbehörde einzureichen.

2. Allgemeine Hinweise und Pflicht­informationen

Datenschutz

Die Betreiber dieser Seiten nehmen den Schutz Ihrer persönlichen Daten sehr ernst. Wir behandeln Ihre personenbezogenen Daten vertraulich und entsprechend der gesetzlichen Datenschutzvorschriften sowie dieser Datenschutzerklärung.

Wenn Sie diese Website benutzen, werden verschiedene personenbezogene Daten erhoben. Personenbezogene Daten sind Daten, mit denen Sie persönlich identifiziert werden können. Die vorliegende Datenschutzerklärung erläutert, welche Daten wir erheben und wofür wir sie nutzen. Sie erläutert auch, wie und zu welchem Zweck das geschieht.

Wir weisen darauf hin, dass die Datenübertragung im Internet (z. B. bei der Kommunikation per E-Mail) Sicherheitslücken aufweisen kann. Ein lückenloser Schutz der Daten vor dem Zugriff durch Dritte ist nicht möglich.

Hinweis zur verantwortlichen Stelle

Die verantwortliche Stelle für die Datenverarbeitung auf dieser Website ist:

iits-consulting GmbH
Am Bahndamm 10
84072 Au in der Hallertau, Germany
Phone: +49 2132 6530048
Email: kontakt@iits-consulting.de.

Verantwortliche Stelle ist die natürliche oder juristische Person, die allein oder gemeinsam mit anderen über die Zwecke und Mittel der Verarbeitung von personenbezogenen Daten (z. B. Namen, E-Mail-Adressen o. Ä.) entscheidet.

Gesetzlich vorgeschriebener Datenschutz­beauftragter

Unser Datenschutzbeauftragter ist:

Graham Reilly (DPO)
Email: graham.reilly@workstreet.com
Phone: +44 7777 116858

Bei Fragen zur Verarbeitung Ihrer personenbezogenen Daten oder zur Ausübung Ihrer Betroffenenrechte können Sie sich jederzeit an unseren Datenschutzbeauftragten wenden.

Your rights

Within the framework of the statutory requirements you have the right of access to the personal data we process (Article 15 GDPR), to rectification of inaccurate data (Article 16 GDPR), to erasure (Article 17 GDPR), to restriction of processing (Article 18 GDPR) and to data portability with respect to data we process by automated means on the basis of your consent or for the performance of a contract (Article 20 GDPR). You can withdraw consent you have given at any time with future effect; the lawfulness of the processing carried out until then remains unaffected (Article 7(3) GDPR). Regarding your right to object, please see the separate section "Right to object under Article 21 GDPR". A message to the address stated in the section "Information on the responsible party" is sufficient to exercise your rights.

Recht auf Einschränkung der Verarbeitung

Sie haben das Recht, die Einschränkung der Verarbeitung Ihrer personenbezogenen Daten zu verlangen (Artikel 18 DSGVO). Dieses Recht besteht in folgenden Fällen: wenn Sie die Richtigkeit der über Sie gespeicherten Daten bestreiten – für die Dauer unserer Überprüfung; wenn die Verarbeitung unrechtmäßig war oder ist und Sie statt der Löschung die Einschränkung verlangen; wenn wir Ihre Daten nicht mehr benötigen, Sie diese jedoch zur Geltendmachung, Ausübung oder Verteidigung von Rechtsansprüchen benötigen; und wenn Sie Widerspruch gemäß Artikel 21 Absatz 1 DSGVO eingelegt haben – solange die Abwägung Ihrer Interessen gegen unsere noch nicht entschieden ist.

Haben Sie die Einschränkung beantragt, dürfen die betreffenden Daten – abgesehen von ihrer Speicherung – nur mit Ihrer Einwilligung oder zur Geltendmachung, Ausübung oder Verteidigung von Rechtsansprüchen oder zum Schutz der Rechte einer anderen natürlichen oder juristischen Person oder aus Gründen eines wichtigen öffentlichen Interesses der Europäischen Union oder eines Mitgliedstaats verarbeitet werden.

Whether provision is required

You are neither legally nor contractually obliged to provide us with personal data. No data needs to be provided in order to use this website. However, if you wish to send us an enquiry or apply for a position, we need the information marked as required in the respective form; without it we cannot process your enquiry or application. Not filling in the optional fields has no disadvantage whatsoever.

No automated decision-making

No decision based solely on automated processing which produces legal effects concerning you or similarly significantly affects you takes place. We do not carry out profiling within the meaning of Article 4(4) GDPR and do not create user profiles for evaluation or scoring purposes.

SSL / TLS encryption

Diese Seite nutzt aus Sicherheitsgründen und zum Schutz der Übertragung vertraulicher Inhalte, wie zum Beispiel Bestellungen oder Anfragen, die Sie an uns als Seitenbetreiber senden, eine SSL- bzw. TLS-Verschlüsselung. Eine verschlüsselte Verbindung erkennen Sie daran, dass die Adresszeile des Browsers von „http://“ auf „https://“ wechselt.

Wenn die SSL- bzw. TLS-Verschlüsselung aktiviert ist, können die Daten, die Sie an uns übermitteln, nicht von Dritten mitgelesen werden.

3. Right to object under Article 21 GDPR

You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is carried out on the basis of Article 6(1) subparagraph 1 point (f) GDPR.

On this website this concerns in particular the processing of server log data, the prevention of abuse and automated requests at the contact form, and the delivery of media content. If you object, we will no longer process the data concerned unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims. Your objection is not subject to any particular form; a message to the address stated in the section "Information on the responsible party" is sufficient and is free of charge for you.

If your data is processed for the purpose of direct marketing, you have the right to object to that processing at any time without giving reasons; following such an objection the data will no longer be processed for that purpose (Article 21(2) and (3) GDPR).

4. Beschwerde­recht bei der zuständigen Aufsichts­behörde

Im Falle von Verstößen gegen die DSGVO steht den Betroffenen ein Beschwerderecht bei einer Aufsichtsbehörde, insbesondere in dem Mitgliedstaat ihres gewöhnlichen Aufenthalts, ihres Arbeitsplatzes oder des Orts des mutmaßlichen Verstoßes zu. Das Beschwerderecht besteht unbeschadet anderweitiger verwaltungsrechtlicher oder gerichtlicher Rechtsbehelfe.

5. Storage periods

We store personal data only for as long as is necessary for the purposes stated below, and delete it thereafter unless a statutory retention obligation applies. In detail:

For the operation of the website, the runtime logs are deleted after 30 days. For the other services named in the section "Hosting and delivery", the respective providers’ own retention periods apply. We do not carry out any additional logging or archiving of our own.

The IP address processed to prevent abuse at the contact form is held only transiently in our server memory, is no longer taken into account after 24 hours at the latest, and is deleted with the next clean-up or when the application restarts.

For the event data of the reach measurement, a retention period of twelve months is configured at our analytics provider.

Your selection in the consent banner is stored on your device; the storage period is up to 365 days, or until you delete the data in your browser.

We keep the record of your consent decision for as long as the accountability obligation requires; its deletion follows the limitation periods for potential claims (sections 195, 199 BGB).

We delete contact enquiries as soon as they are no longer necessary for the purposes stated and no statutory retention obligation applies; commercial or business letters are retained for six years and accounting vouchers for eight years, in each case from the end of the calendar year.

We delete application documents no later than six months after the application procedure has been concluded.

Where a storage period cannot be determined in advance in an individual case, it is governed by how long your matter takes to handle, whether the purpose of collection continues to apply, whether statutory retention obligations exist, and the limitation periods for potential claims. For technical reasons, data may still be contained in backup copies for a short transitional period; these are deleted on a rolling basis.

6. Hosting and delivery

We host this website and deliver its content via the following service providers. All providers named below process the data solely on our behalf and on our instructions. A data processing agreement pursuant to Article 28 GDPR is in place with each of the providers listed below; it forms part of the contract terms agreed with them and therefore came into effect when that agreement was concluded.

Processing locations. For every service we use we have selected European processing regions: the website is executed in Frankfurt am Main, the database is likewise operated in Frankfurt am Main, image and media files are stored in the "West Europe" region (Netherlands), and the storage location of the fallback store is contractually restricted to the European Union. Section 9 covers reach measurement. In regular operation, your data does not leave the European Economic Area.

Website operation

The provider is Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA. Vercel provides the server and execution infrastructure; technically necessary connection data including your IP address is processed in the course of this. For this website we have selected the Frankfurt am Main region exclusively; the website is executed and this connection data is processed there. In our account settings we have refused any use of the data for the provider’s own purposes.

Database

To store the website and editorial content as well as the consent record, we use a database service. Our contractual counterparty is Databricks, Inc., 160 Spear Street, 15th Floor, San Francisco, CA 94105, USA; the service is operated by Neon, LLC. Region selected by us: Frankfurt am Main.

Media store

Images and files are delivered via an object store. The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. The files are stored in the "West Europe" region (Netherlands) and therefore within the European Economic Area. When images and files are retrieved, your browser connects directly to this object store; technically necessary connection data including your IP address is processed in the course of this. Access by Microsoft Corporation, USA, in particular in the context of support and group processes, cannot be ruled out; the safeguards stated in the section "Transfers to third countries" apply to this.

Data backups

We create regular backup copies of the database and store them in a non-public storage area operated by Microsoft Ireland Operations Limited within the European Union. These backups contain all data held in the database, including the records of consent given. We delete them after 30 days; for a further 35 days they remain technically recoverable before being removed permanently.

Fallback store

In an object store operated by Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA, we currently still keep a copy of the media files as a fallback in the event of a fault; the storage location is contractually restricted to the European Union. We will delete this copy once the migration is complete and the fallback is no longer needed.

Email delivery

To deliver the messages received via the contact form we use the email service of our hosting provider one.com. The provider is established in and processes the data within the European Union. Our mailbox is operated by Microsoft Ireland Operations Limited, Ireland.

The legal basis for using these services is Article 6(1) subparagraph 1 point (f) GDPR; our legitimate interest lies in the secure, performant and reliable provision of this website.

We will provide you on request, free of charge, with a current and complete list of our processors including name, address and processing purpose.

7. Transfers to third countries

Some of the service providers we use are established in the United States of America or can access personal data from there. The USA is a third country within the meaning of Chapter V of the General Data Protection Regulation.

Why a third-country element exists even though processing takes place in the EU. Some of the service providers named are companies established in the United States. Under US law such companies may be compelled to disclose data irrespective of the storage location, and access from the United States — for instance in the course of maintenance and support — cannot be ruled out. That possibility of access alone constitutes a transfer to a third country, about which we inform you below.

Where the recipient is actively certified under the EU-U.S. Data Privacy Framework and relies on that certification contractually, the transfer takes place on the basis of the European Commission’s Implementing Decision (EU) 2023/1795 of 10 July 2023 (Article 45(1) GDPR). The current certification status can be verified at dataprivacyframework.gov/list. With all other recipients in the United States, and in addition for the event that this adequacy decision is repealed, suspended or declared invalid, we have entered into the European Commission’s standard contractual clauses (Implementing Decision (EU) 2021/914) pursuant to Article 46(2)(c) GDPR, have assessed the transfer by way of a risk assessment and have put supplementary measures in place.

In detail:

Vercel Inc., USA (operation and delivery of this website; region selected by us: Frankfurt am Main): 2021 standard contractual clauses (Module Two); for transfers from the United Kingdom the UK IDTA is additionally incorporated.

PostHog, Inc., USA (reach measurement, only after your consent; stored in Germany): the transfer basis is currently being settled contractually; until then no transfer takes place without your consent.

Databricks, Inc., USA, including Neon, LLC (database operation; region selected by us: Frankfurt am Main): 2021 standard contractual clauses, as part of the incorporated data processing agreement.

Cloudflare, Inc., USA (fallback store for media files; the storage location is contractually restricted to the European Union): 2021 standard contractual clauses, as part of the incorporated data processing agreement.

Microsoft Ireland Operations Limited, Ireland (media store, data backups and mailbox): processing takes place within the European Economic Area. The standard contractual clauses apply to any access by Microsoft Corporation, USA, in particular in the context of support and group processes.

Google Ireland Limited and Google LLC, USA: only when a video is actively loaded, see the section "Embedding of YouTube videos".

Note on residual risks. Despite these safeguards it cannot be ruled out that US authorities access personal data on the basis of US surveillance laws, in particular under 50 U.S.C. section 1881a (FISA Section 702) and the CLOUD Act, and that you have no remedies against this which fully meet the requirements of Articles 47 and 8 of the Charter of Fundamental Rights of the European Union. An appeal concerning the validity of the EU-U.S. Data Privacy Framework is currently pending before the Court of Justice of the European Union (Case C-703/25 P). We review the certification of the recipients named and the viability of the transfer bases regularly and adapt this privacy policy when they change.

We will provide you with a copy of the agreed standard contractual clauses on request; please contact the address stated in the section "Information on the responsible party".

8. Datenerfassung auf dieser Website

Cookies und Speicherung auf Ihrem Gerät

We use only such cookies and comparable storage technologies as are strictly necessary for the operation of this website — in particular storing your selection in the consent banner and storing the language you have chosen. The legal basis is section 25(2) no. 2 TDDDG in conjunction with Article 6(1) subparagraph 1 point (f) GDPR; our legitimate interest lies in providing you with the website you requested in working order and in respecting your privacy decision.

In detail we use: the cookie "c15t" and an entry of the same name in your browser’s local storage for your selection in the consent banner (lifetime up to 365 days); the cookie "NEXT_LOCALE" for the language you have chosen (lifetime: until the end of the browser session); and, if you access an internal area, the cookie "payload-admin-return-to" in order to return you to the page originally requested after signing in (lifetime: 10 minutes).

The reach measurement operates without cookies: no cookies are set for it and no data is stored in your browser’s local or session storage. It nevertheless requires consent, because information is read from your device and transmitted to a service provider in the course of it; for details see the section "Reach measurement (PostHog)".

To obtain and manage your consent we use the c15t solution, which runs entirely within our own application; no transfer to third parties takes place. Your selection is stored on your device (an entry in local storage and the cookie "c15t") so that the banner is not shown to you again on every page visit; the storage period is up to 365 days, or until you delete the data in your browser. The legal basis is section 25(2) no. 2 TDDDG in conjunction with Article 6(1) subparagraph 1 point (f) GDPR.

Separately, we document your decision in our system in order to provide the proof required under Article 7(1) and Article 5(2) GDPR. We store only the type of decision (full consent, full rejection, individual selection or withdrawal), the categories and preferences consented to, the version of the consent texts, the language version, the technical identifier of your browser and the timestamp. No IP address and no name are stored. The legal basis is Article 6(1) subparagraph 1 point (c) GDPR in conjunction with the accountability obligations referred to above. We keep these records for as long as the accountability obligation requires; their deletion follows the limitation periods for potential claims (sections 195, 199 BGB).

Server log data

When this website is accessed, our service providers process technically necessary connection data: date and time of the request, the resource requested, the referring page, the access status, the volume of data transferred, browser type and operating system, and the IP address of the requesting system. This data arises at the providers named in the section "Hosting and delivery" — in the operation of the website, the database, the media store and email delivery. It is not merged with other data sources.

The legal basis is Article 6(1) subparagraph 1 point (f) GDPR; our legitimate interest lies in the secure, stable and technically error-free operation of the website and in detecting and preventing attacks. The logs of the website operation are deleted after 30 days; for the other services the respective providers’ own retention periods apply. We do not carry out any additional logging or archiving of access data of our own.

Contact form

Purpose and scope. You can send us an enquiry via our contact form. Your name, your email address and your message are required, and your company in addition for a project enquiry. All further details — phone number, website, desired time frame, budget range, roles sought and project types — are optional and serve solely to let us handle your matter more quickly and more precisely. We process this data exclusively in order to handle and answer your enquiry and to conduct any subsequent correspondence.

Legal bases. If your enquiry concerns the initiation or performance of a contractual relationship, for example a project or service enquiry, the legal basis is Article 6(1) subparagraph 1 point (b) GDPR (pre-contractual measures at your request). In all other cases the legal basis is Article 6(1) subparagraph 1 point (f) GDPR; our legitimate interest lies in answering enquiries addressed to us and in communicating with prospective clients and business partners. We do not obtain consent for answering your enquiry; it is not required for this.

Recipients. The data submitted via the form is not stored in the database of this website but transmitted directly to our mailbox by email. The service providers involved are named in the section "Email delivery". If you have additionally consented to reach measurement, the fact of the submission — without your message and without your contact details — is also transmitted to our analytics provider; for details see the section "Reach measurement (PostHog)".

Protection against misuse. In order to prevent the mass automated submission of form messages, the form contains an additional field that is not visible to you and which automated programs fill in, and we limit the number of submissions per IP address. For this purpose we process your IP address only transiently in our server memory. It is not stored permanently, is not linked to your message, is no longer taken into account after 24 hours at the latest, and is deleted with the next clean-up or when the application restarts. The legal basis is Article 6(1) subparagraph 1 point (f) GDPR; our legitimate interest lies in the security, availability and abuse-free usability of our offering.

Storage period. We delete your enquiry and the associated correspondence as soon as it is no longer necessary to achieve the purposes stated. Where the correspondence constitutes a commercial or business letter, we retain it for six years pursuant to section 257(1) nos. 2 and 3, (4) HGB and section 147(1) nos. 2 and 3, (3) AO; for accounting vouchers the period is eight years under section 257(1) no. 4, (4) HGB and section 147(1) no. 4, (3) AO. These periods begin at the end of the calendar year in which the correspondence was received or sent (section 257(5) HGB, section 147(4) AO). During the retention period we restrict processing: the data is held solely to comply with the statutory retention obligation and is no longer actively used.

Whether provision is required. You are neither legally nor contractually obliged to provide us with this data. Without the details the form marks as required, however, we cannot process or answer your enquiry. Not filling in the optional fields has no disadvantage whatsoever.

Enquiries by email, telephone or post

If you contact us by email, by telephone or by post, we process the information you provide, including all personal data arising from it, in order to handle your request. We do not pass this data on without your consent.

The legal basis is Article 6(1) subparagraph 1 point (b) GDPR insofar as your enquiry relates to the initiation or performance of a contract. In all other cases the legal basis is Article 6(1) subparagraph 1 point (f) GDPR; our legitimate interest lies in handling the enquiries addressed to us. The periods stated in the section "Contact form" apply accordingly to the storage period.

9. Reach measurement (PostHog)

Purpose. We evaluate the use of this website statistically in order to improve our content and its structure, to monitor the technical quality of delivery, and to detect and remedy errors.

Used only after your consent. The analytics function is loaded and executed only if you have previously consented in the "Analytics" category. Without your consent no analysis takes place; for this purpose no information is stored on or read from your device, and no data is transmitted to the analytics service.

Legal bases. The legal basis for reading information from your device is your consent under section 25(1) TDDDG. The legal basis for the subsequent processing of the personal data thereby collected is your consent under Article 6(1) subparagraph 1 point (a) GDPR. We do not process data for these purposes on the basis of legitimate interests.

Provider. The provider is PostHog, Inc., 2261 Market Street #4008, San Francisco, CA 94114, USA. PostHog processes the data solely on our behalf and on our instructions. The event data is stored in PostHog’s European instance on servers in Germany (Frankfurt am Main region).

Integration via our own domain. The analytics requests are not sent from your browser directly to PostHog but first to an endpoint operated by us on our own domain ("/ingest") and forwarded from there to PostHog. Your browser therefore does not establish a direct connection to PostHog. PostHog is nevertheless the recipient of the data. Our endpoint removes cookies and authentication information from the request and discards cookies set by PostHog; it does, however, transmit your IP address to PostHog.

No storage on your device. The analytics is set up without cookies. For analytics purposes no cookies are set and no data is stored in your browser’s local or session storage. No automatic capture of all click and input events and no session recording take place.

Data processed. We process in particular the page accessed and the time of access, the previously visited page, the browser and device information transmitted by your browser, measurements of page presentation quality (Core Web Vitals), leaving a page, clicks on individually tagged buttons and on suggested further articles, clicks on email and telephone links, and technical error messages. When you submit the contact form, the fact of the submission is additionally recorded — with the form tab used, the number of roles and project types you selected and the budget range you set, but not your name, your email address or the text of your message. Error messages are automatically stripped of personal content before transmission. Your IP address is processed as described below.

Pseudonymous, not anonymous processing. From your IP address, the browser and device information, the hostname, a project identifier and a daily rotating random value, PostHog forms an irreversible hash value. It serves solely to relate page views to one another within a single calendar day; on the following day a different identifier arises, so that no recognition across days takes place. The IP address itself is not stored by PostHog as an attribute of the event. This is pseudonymous processing within the meaning of Article 4(5) GDPR and not anonymous data. No merging across several days or devices, no profiling and no attribution to your name take place.

Storage period. A retention period of twelve months for the event data is configured with the provider for our project; we cannot technically enforce a shorter period. The daily rotating random value is deleted at the end of the respective day.

Transfer to a third country. Our contractual partner is PostHog, Inc., established in the USA. Even where data is stored in Germany, access from the USA — for example for maintenance and support purposes — cannot be ruled out; this constitutes a transfer to a third country. Details and the agreed safeguards can be found in the section "Transfers to third countries".

Withdrawal. You can withdraw your consent at any time with future effect via the privacy settings in the footer. From the withdrawal onwards no further data is collected; the lawfulness of the processing carried out until the withdrawal remains unaffected. Pseudonymous event data already collected remains stored until the period stated above expires.

Further information from the provider can be found at posthog.com/privacy.

10. Embedded content

Embedding of YouTube videos

On individual pages we embed videos from the YouTube platform. The provider for users in the European Economic Area is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

When a page containing an embedded video is loaded, no connection to Google is established at first. In place of the video we show only a preview image which is delivered from our own server. Your IP address is not disclosed to Google at this point; no data is transmitted to Google and no information is stored on or read from your device.

Only when you actively click the button to load the video is the YouTube player loaded. The legal basis for storing information on your device and accessing it is your consent under section 25(1) TDDDG; the legal basis for the associated processing of personal data is your consent under Article 6(1) subparagraph 1 point (a) GDPR.

After the click, your IP address and technical information about your browser and device are transmitted to Google. Google thereby learns that you have accessed the page in question; if you are signed in to a Google account, Google can attribute the use to your account. We have no influence over Google’s further processing; Google acts as an independent controller in that respect.

We embed the videos via the domain www.youtube-nocookie.com in enhanced privacy mode. This mode does not prevent Google from storing information on your device and reading it when the video is played; in particular, Google places entries in your browser’s local storage under that domain and may set cookies. Google decides on the content and lifetime of that information; Google has access to it, we do not. You can delete information already stored via your browser settings.

The recipients are Google Ireland Limited, Ireland, and Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; a transfer to the United States therefore takes place (see the section "Transfers to third countries").

Your consent applies only to the video you clicked and only to the current page visit; we do not store your decision. You withdraw it with future effect by reloading or leaving the page. The lawfulness of the processing carried out until the withdrawal remains unaffected (Article 7(3) sentence 2 GDPR). Further information: policies.google.com/privacy.

Fonts

For a consistent presentation we use the fonts Archivo and Space Grotesk. The font files reside on our own server and are delivered from there; where they originate from an external font library, they are downloaded once when the website is built and delivered together with it. When you visit this website, no connection is therefore established to servers of Google or other third parties in order to load fonts.

11. Careers and applications

Display of open positions. The job openings shown on our careers page are obtained from our applicant management system at Personio SE & Co. KG, Seidlstraße 3, 80335 Munich, Germany. They are retrieved exclusively by our server; your browser does not establish a connection to Personio in the process. Merely visiting our careers page therefore transmits no data about you to Personio. The job data retrieved contains no personal data of visitors; we cache it for up to four hours.

Moving to our application portal. If you click a job or apply link, you leave this website and are taken to our application portal at iits.jobs.personio.de. Only with that click does your browser establish a connection to Personio; your IP address, the browser and device information and the selected language are transmitted to Personio in the process.

Responsibility. We remain the controller within the meaning of Article 4(7) GDPR for the processing of your application data; Personio acts solely on our behalf and on our instructions in that respect. For the technical operation of the recruiting page itself — in particular its server and error logs (storage period up to seven days each) and the cookies used there (up to one month, or until the end of the browser session) — Personio acts, according to its own statements, as an independent controller. The privacy information at iits.jobs.personio.de/privacy-policy applies in that respect.

Scope and legal bases. In the context of your application we process the information from the application form and the documents you upload. The legal basis is Article 6(1) subparagraph 1 point (b) GDPR; the application procedure is a pre-contractual measure carried out at your request. If you voluntarily provide us with special categories of personal data, for example information about a severe disability, we process it on the basis of Article 9(2)(b) GDPR in conjunction with section 26(3) BDSG.

Storage period. If no employment relationship comes about, we delete your application documents no later than six months after the application procedure has been concluded; this period is based on the periods for asserting and judicially enforcing claims under the German General Equal Treatment Act.