Privacy Policy
1. Data protection at a glance
General information
The following notes give a simple overview of what happens to your personal data when you visit this website. Personal data is any data by which you can be personally identified. For detailed information on data protection, please refer to the sections below in this privacy policy.
Who is responsible for collecting data on this website?
Data processing on this website is carried out by the website operator. You will find their contact details in the section "Information on the responsible party" and in the imprint of this website.
How do we collect your data?
Your data is collected in part by you providing it to us — for instance through our contact form. Other data is collected automatically when you visit the website by the IT systems we use. This is primarily technical data such as browser type, operating system, time of the page visit and IP address. Reach measurement takes place only after your explicit consent.
What do we use your data for?
Some of the data is collected to ensure the website is provided without errors. With your consent, we additionally evaluate the use of the website pseudonymously in order to improve our offering. In the course of this, your IP address is transmitted to our analytics provider and processed there into a daily rotating identifier; for details see the section "Reach measurement (PostHog)".
What rights do you have regarding your data?
You have the right at any time to obtain information free of charge about the origin, recipients and purpose of your stored personal data, as well as a right to rectification, erasure or restriction of processing and to data portability. You can withdraw consent you have given at any time with future effect. You also have a right to object and a right to lodge a complaint with the competent supervisory authority.
2. General information and mandatory information
Privacy
The operators of this website take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with applicable data protection laws and this Privacy Policy.
When you use this website, various types of personal data are collected. Personal data is data that can be used to personally identify you. This privacy policy explains what data we collect and how we use it. It also explains how and for what purpose this is done.
Please note that data transmission over the Internet (e.g., when communicating via email) may be subject to security vulnerabilities. It is not possible to completely protect data from access by third parties.
Information on the responsible party
The party responsible for data processing on this website is:
iits-consulting GmbH
Am Bahndamm 10
84072 Au in der Hallertau, Germany
Phone: +49 2132 6530048
Email: kontakt@iits-consulting.de.
The responsible party is the natural or legal person who, alone or jointly with others, determines the purposes and means of processing personal data (e.g., names, email addresses, etc.).
Data protection officer
Our data protection officer is:
Graham Reilly (DPO)
Email: graham.reilly@workstreet.com
Phone: +44 7777 116858
If you have any questions about the processing of your personal data or about exercising your rights as a data subject, you can contact them directly at any time.
Your rights
Within the framework of the statutory requirements you have the right of access to the personal data we process (Article 15 GDPR), to rectification of inaccurate data (Article 16 GDPR), to erasure (Article 17 GDPR), to restriction of processing (Article 18 GDPR) and to data portability with respect to data we process by automated means on the basis of your consent or for the performance of a contract (Article 20 GDPR). You can withdraw consent you have given at any time with future effect; the lawfulness of the processing carried out until then remains unaffected (Article 7(3) GDPR). Regarding your right to object, please see the separate section "Right to object under Article 21 GDPR". A message to the address stated in the section "Information on the responsible party" is sufficient to exercise your rights.
Right to restriction of processing
You have the right to request the restriction of the processing of your personal data (Article 18 GDPR). This right exists in the following cases: if you dispute the accuracy of the data we hold about you — for the duration of our verification; if the processing was or is unlawful and you request restriction instead of erasure; if we no longer need your data but you need it to assert, exercise or defend legal claims; and if you have objected under Article 21(1) GDPR — for as long as the balancing of your interests against ours is undecided.
Where you have requested restriction, the data concerned may — apart from being stored — only be processed with your consent, or to assert, exercise or defend legal claims, or to protect the rights of another natural or legal person, or for reasons of an important public interest of the European Union or a member state.
Whether provision is required
You are neither legally nor contractually obliged to provide us with personal data. No data needs to be provided in order to use this website. However, if you wish to send us an enquiry or apply for a position, we need the information marked as required in the respective form; without it we cannot process your enquiry or application. Not filling in the optional fields has no disadvantage whatsoever.
No automated decision-making
No decision based solely on automated processing which produces legal effects concerning you or similarly significantly affects you takes place. We do not carry out profiling within the meaning of Article 4(4) GDPR and do not create user profiles for evaluation or scoring purposes.
SSL / TLS encryption
For security reasons and to protect the transmission of confidential content, this site uses SSL or TLS encryption. You can recognise an encrypted connection by the browser address line changing from "http://" to "https://".
When encryption is active, the data you transmit to us cannot be read by third parties.
3. Right to object under Article 21 GDPR
You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is carried out on the basis of Article 6(1) subparagraph 1 point (f) GDPR.
On this website this concerns in particular the processing of server log data, the prevention of abuse and automated requests at the contact form, and the delivery of media content. If you object, we will no longer process the data concerned unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims. Your objection is not subject to any particular form; a message to the address stated in the section "Information on the responsible party" is sufficient and is free of charge for you.
If your data is processed for the purpose of direct marketing, you have the right to object to that processing at any time without giving reasons; following such an objection the data will no longer be processed for that purpose (Article 21(2) and (3) GDPR).
4. Right to lodge a complaint with a supervisory authority
In the event of violations of the GDPR, data subjects have the right to file a complaint with a supervisory authority, in particular in the Member State of their habitual residence, their place of work, or the location of the alleged violation. This right to file a complaint is without prejudice to any other administrative or judicial remedies.
5. Storage periods
We store personal data only for as long as is necessary for the purposes stated below, and delete it thereafter unless a statutory retention obligation applies. In detail:
For the operation of the website, the runtime logs are deleted after 30 days. For the other services named in the section "Hosting and delivery", the respective providers’ own retention periods apply. We do not carry out any additional logging or archiving of our own.
The IP address processed to prevent abuse at the contact form is held only transiently in our server memory, is no longer taken into account after 24 hours at the latest, and is deleted with the next clean-up or when the application restarts.
For the event data of the reach measurement, a retention period of twelve months is configured at our analytics provider.
Your selection in the consent banner is stored on your device; the storage period is up to 365 days, or until you delete the data in your browser.
We keep the record of your consent decision for as long as the accountability obligation requires; its deletion follows the limitation periods for potential claims (sections 195, 199 BGB).
We delete contact enquiries as soon as they are no longer necessary for the purposes stated and no statutory retention obligation applies; commercial or business letters are retained for six years and accounting vouchers for eight years, in each case from the end of the calendar year.
We delete application documents no later than six months after the application procedure has been concluded.
Where a storage period cannot be determined in advance in an individual case, it is governed by how long your matter takes to handle, whether the purpose of collection continues to apply, whether statutory retention obligations exist, and the limitation periods for potential claims. For technical reasons, data may still be contained in backup copies for a short transitional period; these are deleted on a rolling basis.
6. Hosting and delivery
We host this website and deliver its content via the following service providers. All providers named below process the data solely on our behalf and on our instructions. A data processing agreement pursuant to Article 28 GDPR is in place with each of the providers listed below; it forms part of the contract terms agreed with them and therefore came into effect when that agreement was concluded.
Processing locations. For every service we use we have selected European processing regions: the website is executed in Frankfurt am Main, the database is likewise operated in Frankfurt am Main, image and media files are stored in the "West Europe" region (Netherlands), and the storage location of the fallback store is contractually restricted to the European Union. Section 9 covers reach measurement. In regular operation, your data does not leave the European Economic Area.
Website operation
The provider is Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA. Vercel provides the server and execution infrastructure; technically necessary connection data including your IP address is processed in the course of this. For this website we have selected the Frankfurt am Main region exclusively; the website is executed and this connection data is processed there. In our account settings we have refused any use of the data for the provider’s own purposes.
Database
To store the website and editorial content as well as the consent record, we use a database service. Our contractual counterparty is Databricks, Inc., 160 Spear Street, 15th Floor, San Francisco, CA 94105, USA; the service is operated by Neon, LLC. Region selected by us: Frankfurt am Main.
Media store
Images and files are delivered via an object store. The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. The files are stored in the "West Europe" region (Netherlands) and therefore within the European Economic Area. When images and files are retrieved, your browser connects directly to this object store; technically necessary connection data including your IP address is processed in the course of this. Access by Microsoft Corporation, USA, in particular in the context of support and group processes, cannot be ruled out; the safeguards stated in the section "Transfers to third countries" apply to this.
Data backups
We create regular backup copies of the database and store them in a non-public storage area operated by Microsoft Ireland Operations Limited within the European Union. These backups contain all data held in the database, including the records of consent given. We delete them after 30 days; for a further 35 days they remain technically recoverable before being removed permanently.
Fallback store
In an object store operated by Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA, we currently still keep a copy of the media files as a fallback in the event of a fault; the storage location is contractually restricted to the European Union. We will delete this copy once the migration is complete and the fallback is no longer needed.
Email delivery
To deliver the messages received via the contact form we use the email service of our hosting provider one.com. The provider is established in and processes the data within the European Union. Our mailbox is operated by Microsoft Ireland Operations Limited, Ireland.
The legal basis for using these services is Article 6(1) subparagraph 1 point (f) GDPR; our legitimate interest lies in the secure, performant and reliable provision of this website.
We will provide you on request, free of charge, with a current and complete list of our processors including name, address and processing purpose.
7. Transfers to third countries
Some of the service providers we use are established in the United States of America or can access personal data from there. The USA is a third country within the meaning of Chapter V of the General Data Protection Regulation.
Why a third-country element exists even though processing takes place in the EU. Some of the service providers named are companies established in the United States. Under US law such companies may be compelled to disclose data irrespective of the storage location, and access from the United States — for instance in the course of maintenance and support — cannot be ruled out. That possibility of access alone constitutes a transfer to a third country, about which we inform you below.
Where the recipient is actively certified under the EU-U.S. Data Privacy Framework and relies on that certification contractually, the transfer takes place on the basis of the European Commission’s Implementing Decision (EU) 2023/1795 of 10 July 2023 (Article 45(1) GDPR). The current certification status can be verified at dataprivacyframework.gov/list. With all other recipients in the United States, and in addition for the event that this adequacy decision is repealed, suspended or declared invalid, we have entered into the European Commission’s standard contractual clauses (Implementing Decision (EU) 2021/914) pursuant to Article 46(2)(c) GDPR, have assessed the transfer by way of a risk assessment and have put supplementary measures in place.
In detail:
Vercel Inc., USA (operation and delivery of this website; region selected by us: Frankfurt am Main): 2021 standard contractual clauses (Module Two); for transfers from the United Kingdom the UK IDTA is additionally incorporated.
PostHog, Inc., USA (reach measurement, only after your consent; stored in Germany): the transfer basis is currently being settled contractually; until then no transfer takes place without your consent.
Databricks, Inc., USA, including Neon, LLC (database operation; region selected by us: Frankfurt am Main): 2021 standard contractual clauses, as part of the incorporated data processing agreement.
Cloudflare, Inc., USA (fallback store for media files; the storage location is contractually restricted to the European Union): 2021 standard contractual clauses, as part of the incorporated data processing agreement.
Microsoft Ireland Operations Limited, Ireland (media store, data backups and mailbox): processing takes place within the European Economic Area. The standard contractual clauses apply to any access by Microsoft Corporation, USA, in particular in the context of support and group processes.
Google Ireland Limited and Google LLC, USA: only when a video is actively loaded, see the section "Embedding of YouTube videos".
Note on residual risks. Despite these safeguards it cannot be ruled out that US authorities access personal data on the basis of US surveillance laws, in particular under 50 U.S.C. section 1881a (FISA Section 702) and the CLOUD Act, and that you have no remedies against this which fully meet the requirements of Articles 47 and 8 of the Charter of Fundamental Rights of the European Union. An appeal concerning the validity of the EU-U.S. Data Privacy Framework is currently pending before the Court of Justice of the European Union (Case C-703/25 P). We review the certification of the recipients named and the viability of the transfer bases regularly and adapt this privacy policy when they change.
We will provide you with a copy of the agreed standard contractual clauses on request; please contact the address stated in the section "Information on the responsible party".
8. Data collection on this website
Cookies and storage on your device
We use only such cookies and comparable storage technologies as are strictly necessary for the operation of this website — in particular storing your selection in the consent banner and storing the language you have chosen. The legal basis is section 25(2) no. 2 TDDDG in conjunction with Article 6(1) subparagraph 1 point (f) GDPR; our legitimate interest lies in providing you with the website you requested in working order and in respecting your privacy decision.
In detail we use: the cookie "c15t" and an entry of the same name in your browser’s local storage for your selection in the consent banner (lifetime up to 365 days); the cookie "NEXT_LOCALE" for the language you have chosen (lifetime: until the end of the browser session); and, if you access an internal area, the cookie "payload-admin-return-to" in order to return you to the page originally requested after signing in (lifetime: 10 minutes).
The reach measurement operates without cookies: no cookies are set for it and no data is stored in your browser’s local or session storage. It nevertheless requires consent, because information is read from your device and transmitted to a service provider in the course of it; for details see the section "Reach measurement (PostHog)".
Consent management and record of your consent
To obtain and manage your consent we use the c15t solution, which runs entirely within our own application; no transfer to third parties takes place. Your selection is stored on your device (an entry in local storage and the cookie "c15t") so that the banner is not shown to you again on every page visit; the storage period is up to 365 days, or until you delete the data in your browser. The legal basis is section 25(2) no. 2 TDDDG in conjunction with Article 6(1) subparagraph 1 point (f) GDPR.
Separately, we document your decision in our system in order to provide the proof required under Article 7(1) and Article 5(2) GDPR. We store only the type of decision (full consent, full rejection, individual selection or withdrawal), the categories and preferences consented to, the version of the consent texts, the language version, the technical identifier of your browser and the timestamp. No IP address and no name are stored. The legal basis is Article 6(1) subparagraph 1 point (c) GDPR in conjunction with the accountability obligations referred to above. We keep these records for as long as the accountability obligation requires; their deletion follows the limitation periods for potential claims (sections 195, 199 BGB).
Server log data
When this website is accessed, our service providers process technically necessary connection data: date and time of the request, the resource requested, the referring page, the access status, the volume of data transferred, browser type and operating system, and the IP address of the requesting system. This data arises at the providers named in the section "Hosting and delivery" — in the operation of the website, the database, the media store and email delivery. It is not merged with other data sources.
The legal basis is Article 6(1) subparagraph 1 point (f) GDPR; our legitimate interest lies in the secure, stable and technically error-free operation of the website and in detecting and preventing attacks. The logs of the website operation are deleted after 30 days; for the other services the respective providers’ own retention periods apply. We do not carry out any additional logging or archiving of access data of our own.
Contact form
Purpose and scope. You can send us an enquiry via our contact form. Your name, your email address and your message are required, and your company in addition for a project enquiry. All further details — phone number, website, desired time frame, budget range, roles sought and project types — are optional and serve solely to let us handle your matter more quickly and more precisely. We process this data exclusively in order to handle and answer your enquiry and to conduct any subsequent correspondence.
Legal bases. If your enquiry concerns the initiation or performance of a contractual relationship, for example a project or service enquiry, the legal basis is Article 6(1) subparagraph 1 point (b) GDPR (pre-contractual measures at your request). In all other cases the legal basis is Article 6(1) subparagraph 1 point (f) GDPR; our legitimate interest lies in answering enquiries addressed to us and in communicating with prospective clients and business partners. We do not obtain consent for answering your enquiry; it is not required for this.
Recipients. The data submitted via the form is not stored in the database of this website but transmitted directly to our mailbox by email. The service providers involved are named in the section "Email delivery". If you have additionally consented to reach measurement, the fact of the submission — without your message and without your contact details — is also transmitted to our analytics provider; for details see the section "Reach measurement (PostHog)".
Protection against misuse. In order to prevent the mass automated submission of form messages, the form contains an additional field that is not visible to you and which automated programs fill in, and we limit the number of submissions per IP address. For this purpose we process your IP address only transiently in our server memory. It is not stored permanently, is not linked to your message, is no longer taken into account after 24 hours at the latest, and is deleted with the next clean-up or when the application restarts. The legal basis is Article 6(1) subparagraph 1 point (f) GDPR; our legitimate interest lies in the security, availability and abuse-free usability of our offering.
Storage period. We delete your enquiry and the associated correspondence as soon as it is no longer necessary to achieve the purposes stated. Where the correspondence constitutes a commercial or business letter, we retain it for six years pursuant to section 257(1) nos. 2 and 3, (4) HGB and section 147(1) nos. 2 and 3, (3) AO; for accounting vouchers the period is eight years under section 257(1) no. 4, (4) HGB and section 147(1) no. 4, (3) AO. These periods begin at the end of the calendar year in which the correspondence was received or sent (section 257(5) HGB, section 147(4) AO). During the retention period we restrict processing: the data is held solely to comply with the statutory retention obligation and is no longer actively used.
Whether provision is required. You are neither legally nor contractually obliged to provide us with this data. Without the details the form marks as required, however, we cannot process or answer your enquiry. Not filling in the optional fields has no disadvantage whatsoever.
Enquiries by email, telephone or post
If you contact us by email, by telephone or by post, we process the information you provide, including all personal data arising from it, in order to handle your request. We do not pass this data on without your consent.
The legal basis is Article 6(1) subparagraph 1 point (b) GDPR insofar as your enquiry relates to the initiation or performance of a contract. In all other cases the legal basis is Article 6(1) subparagraph 1 point (f) GDPR; our legitimate interest lies in handling the enquiries addressed to us. The periods stated in the section "Contact form" apply accordingly to the storage period.
9. Reach measurement (PostHog)
Purpose. We evaluate the use of this website statistically in order to improve our content and its structure, to monitor the technical quality of delivery, and to detect and remedy errors.
Used only after your consent. The analytics function is loaded and executed only if you have previously consented in the "Analytics" category. Without your consent no analysis takes place; for this purpose no information is stored on or read from your device, and no data is transmitted to the analytics service.
Legal bases. The legal basis for reading information from your device is your consent under section 25(1) TDDDG. The legal basis for the subsequent processing of the personal data thereby collected is your consent under Article 6(1) subparagraph 1 point (a) GDPR. We do not process data for these purposes on the basis of legitimate interests.
Provider. The provider is PostHog, Inc., 2261 Market Street #4008, San Francisco, CA 94114, USA. PostHog processes the data solely on our behalf and on our instructions. The event data is stored in PostHog’s European instance on servers in Germany (Frankfurt am Main region).
Integration via our own domain. The analytics requests are not sent from your browser directly to PostHog but first to an endpoint operated by us on our own domain ("/ingest") and forwarded from there to PostHog. Your browser therefore does not establish a direct connection to PostHog. PostHog is nevertheless the recipient of the data. Our endpoint removes cookies and authentication information from the request and discards cookies set by PostHog; it does, however, transmit your IP address to PostHog.
No storage on your device. The analytics is set up without cookies. For analytics purposes no cookies are set and no data is stored in your browser’s local or session storage. No automatic capture of all click and input events and no session recording take place.
Data processed. We process in particular the page accessed and the time of access, the previously visited page, the browser and device information transmitted by your browser, measurements of page presentation quality (Core Web Vitals), leaving a page, clicks on individually tagged buttons and on suggested further articles, clicks on email and telephone links, and technical error messages. When you submit the contact form, the fact of the submission is additionally recorded — with the form tab used, the number of roles and project types you selected and the budget range you set, but not your name, your email address or the text of your message. Error messages are automatically stripped of personal content before transmission. Your IP address is processed as described below.
Pseudonymous, not anonymous processing. From your IP address, the browser and device information, the hostname, a project identifier and a daily rotating random value, PostHog forms an irreversible hash value. It serves solely to relate page views to one another within a single calendar day; on the following day a different identifier arises, so that no recognition across days takes place. The IP address itself is not stored by PostHog as an attribute of the event. This is pseudonymous processing within the meaning of Article 4(5) GDPR and not anonymous data. No merging across several days or devices, no profiling and no attribution to your name take place.
Storage period. A retention period of twelve months for the event data is configured with the provider for our project; we cannot technically enforce a shorter period. The daily rotating random value is deleted at the end of the respective day.
Transfer to a third country. Our contractual partner is PostHog, Inc., established in the USA. Even where data is stored in Germany, access from the USA — for example for maintenance and support purposes — cannot be ruled out; this constitutes a transfer to a third country. Details and the agreed safeguards can be found in the section "Transfers to third countries".
Withdrawal. You can withdraw your consent at any time with future effect via the privacy settings in the footer. From the withdrawal onwards no further data is collected; the lawfulness of the processing carried out until the withdrawal remains unaffected. Pseudonymous event data already collected remains stored until the period stated above expires.
Further information from the provider can be found at posthog.com/privacy.
10. Embedded content
Embedding of YouTube videos
On individual pages we embed videos from the YouTube platform. The provider for users in the European Economic Area is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
When a page containing an embedded video is loaded, no connection to Google is established at first. In place of the video we show only a preview image which is delivered from our own server. Your IP address is not disclosed to Google at this point; no data is transmitted to Google and no information is stored on or read from your device.
Only when you actively click the button to load the video is the YouTube player loaded. The legal basis for storing information on your device and accessing it is your consent under section 25(1) TDDDG; the legal basis for the associated processing of personal data is your consent under Article 6(1) subparagraph 1 point (a) GDPR.
After the click, your IP address and technical information about your browser and device are transmitted to Google. Google thereby learns that you have accessed the page in question; if you are signed in to a Google account, Google can attribute the use to your account. We have no influence over Google’s further processing; Google acts as an independent controller in that respect.
We embed the videos via the domain www.youtube-nocookie.com in enhanced privacy mode. This mode does not prevent Google from storing information on your device and reading it when the video is played; in particular, Google places entries in your browser’s local storage under that domain and may set cookies. Google decides on the content and lifetime of that information; Google has access to it, we do not. You can delete information already stored via your browser settings.
The recipients are Google Ireland Limited, Ireland, and Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; a transfer to the United States therefore takes place (see the section "Transfers to third countries").
Your consent applies only to the video you clicked and only to the current page visit; we do not store your decision. You withdraw it with future effect by reloading or leaving the page. The lawfulness of the processing carried out until the withdrawal remains unaffected (Article 7(3) sentence 2 GDPR). Further information: policies.google.com/privacy.
Fonts
For a consistent presentation we use the fonts Archivo and Space Grotesk. The font files reside on our own server and are delivered from there; where they originate from an external font library, they are downloaded once when the website is built and delivered together with it. When you visit this website, no connection is therefore established to servers of Google or other third parties in order to load fonts.
11. Careers and applications
Display of open positions. The job openings shown on our careers page are obtained from our applicant management system at Personio SE & Co. KG, Seidlstraße 3, 80335 Munich, Germany. They are retrieved exclusively by our server; your browser does not establish a connection to Personio in the process. Merely visiting our careers page therefore transmits no data about you to Personio. The job data retrieved contains no personal data of visitors; we cache it for up to four hours.
Moving to our application portal. If you click a job or apply link, you leave this website and are taken to our application portal at iits.jobs.personio.de. Only with that click does your browser establish a connection to Personio; your IP address, the browser and device information and the selected language are transmitted to Personio in the process.
Responsibility. We remain the controller within the meaning of Article 4(7) GDPR for the processing of your application data; Personio acts solely on our behalf and on our instructions in that respect. For the technical operation of the recruiting page itself — in particular its server and error logs (storage period up to seven days each) and the cookies used there (up to one month, or until the end of the browser session) — Personio acts, according to its own statements, as an independent controller. The privacy information at iits.jobs.personio.de/privacy-policy applies in that respect.
Scope and legal bases. In the context of your application we process the information from the application form and the documents you upload. The legal basis is Article 6(1) subparagraph 1 point (b) GDPR; the application procedure is a pre-contractual measure carried out at your request. If you voluntarily provide us with special categories of personal data, for example information about a severe disability, we process it on the basis of Article 9(2)(b) GDPR in conjunction with section 26(3) BDSG.
Storage period. If no employment relationship comes about, we delete your application documents no later than six months after the application procedure has been concluded; this period is based on the periods for asserting and judicially enforcing claims under the German General Equal Treatment Act.