Data Protection Statement

Information on data protection

This privacy policy informs you about our handling of your data. In order to make the processing of your data comprehensible to you, we would like to provide you with the following information to give you an overview of this processing. In order to ensure fair processing, this data protection declaration contains general information about our handling of your data as well as information about your rights according to the European General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).

We also inform you in detail about

1. General information

2. Data processing on our website

3. Data processing on our Facebook fan page

4. Further data processing

Responsible for data processing is AGNITAS AG (hereinafter referred to as “we” or “us”).

1. General Information

If you have any questions or suggestions regarding this information or if you wish to contact us regarding the assertion of your rights, please send your request to

AGNITAS AG

Werner-Eckert-Str. 6, 81829 Munich, Germany

Phone: 0049 895529080

E-mail: info@agnitas.ag

The data protection term “personal data” refers to all information relating to an identified or identifiable individual.

We process personal data in compliance with the relevant data protection regulations, in particular the GDPR and the BDSG. Data processing by us is only carried out on the basis of a legal permission. We process personal data only with your consent (Art. 6 para. 1 letter a) GDPR), for the performance of a contract to which you are a party or at your request for the implementation of pre-contractual measures (Art. 6 para. 1 letter b) GDPR), for the fulfilment of a legal obligation (Art. 6 para. 1 letter c) GDPR) or if the processing is necessary to protect our legitimate interests or the legitimate interests of a third party, unless your interests or fundamental rights and freedoms that require the protection of personal data outweigh these (Art. 6 para. 1 letter f) GDPR).

Unless otherwise stated in the following information, we only store the data for as long as necessary to achieve the purpose of processing or to fulfil our contractual or legal obligations. Such statutory storage obligations may result in particular from commercial or tax law regulations.

We use commissioned service providers for individual processing. This includes, for example, hosting, marketing measures or the destruction of files and data media. These service providers process the data only after explicit instructions and are contractually obliged to guarantee suitable technical and organisational measures for data protection. In addition, we may transfer personal data of our customers to entities such as postal and delivery services, house bank, tax advisors/auditors or the fiscal authorities.

If you exercise your rights in accordance with Articles 15 to 22 of the GDPR, we process the personal data transmitted for the purpose of implementing these rights by us and to be able to provide proof of this. We will process data stored for the purpose of providing information and preparing it only for this purpose and for the purposes of data protection control and otherwise restrict processing in accordance with Art. 18 GDPR.

These processing operations are based on the legal basis of Art. 6 para. 1 letter c) GDPR in conjunction with Articles 15 to 22 GDPR and § 34 (2) BDSG.

As a data subject, you have the right to assert your data subject rights against us. In particular, you have the following rights:

  • In accordance with Art. 15 GDPR and § 34 BDSG, you have the right to request information as to whether and, if applicable, to what extent we process personal data relating to your person or not.
  • In accordance with Art. 16 GDPR, you have the right to demand that we correct your data.
  • You have the right to demand that we delete your personal data in accordance with Art. 17 GDPR and § 35 BDSG.
  • You have the right to have the processing of your personal data restricted in accordance with Art. 18 GDPR.
  • In accordance with Art. 20 GDPR, you have the right to receive the personal data concerning you that you have provided us with in a structured, common and machine-readable format and to transfer this data to another person responsible.
  • If you have given us separate consent to data processing, you may revoke this consent at any time in accordance with Art. 7 Para. 3 GDPR. Such a revocation does not affect the lawfulness of the processing, which has been carried out on the basis of the consent until revocation.
  • If you are of the opinion that the processing of personal data concerning you is in breach of the provisions of the GDPR, you have the right to appeal to a supervisory authority in accordance with Art. 77 GDPR.

Under Article 21(1) of the GDPR, you have the right to object to processing operations based on the legal basis of Article 6(1)(e) or (f) of the GDPR for reasons arising from your particular situation. If personal data relating to you is processed by us for the purpose of direct advertising, you may object to this processing in accordance with Art. 21 Paragraphs 2 and 3 of the GDPR.

You can reach our data protection officer at this email address:

datenschutz@agnitas.de

2. Data processing on our website

When using the website, we collect information that you provide yourself. We also automatically collect certain information about your use of the website during your visit of the website. In data protection law, the IP address is also considered as personal data. An IP address is assigned to every device connected to the Internet by the Internet provider so that it can send and receive data.

 

In the case of purely informative use of our website, general information is initially stored automatically (i.e. not via registration), which your browser sends to our server. This includes by default: browser type/version, operating system used, page called up, the previously visited page (referrer URL), IP address, date and time of the server request and HTTP status code. The processing is carried out to protect our legitimate interests and is based on the legal basis of Art. 6 para. 1 letter f) GDPR. This processing serves the technical administration and security of the website. The stored data will be deleted after 4 weeks, unless there is a justified suspicion of illegal use based on concrete evidence and further examination and processing of the information is necessary for this reason. We are not in a position to identify you as a data subject on the basis of the stored information. Therefore, according to Art. 11 para. 2 GDPR, Art. 15 to 22 GDPR are not applicable, unless you provide additional information to enable us to exercise your rights set out in these articles, which will enable us to identify you.

Visiting our website may involve the transfer of certain personal data to the USA. For data transfer to the USA as a third country, i.e. a country in which the GDPR is not applicable law, the European Commission has decided in accordance with Art. 45 GDPR that an adequate level of data protection is required with regard to companies certified under the EU-US Privacy Shield. The transfer to the USA will then take place in a permissible manner. Certified companies are included in this list of the U.S. Department of Commerce: https://www.privacyshield.gov/list.

Our website contains a contact form which you can use to send us messages. The transfer of your data is encrypted (recognizable by the “https” in the address line of the browser). All data fields marked as mandatory fields are required to process your request. If they are not provided, we will not be able to process your request. The provision of further data is voluntary. Alternatively, you can also send us a message via e-mail. We process the data for the purpose of answering your request. Insofar as your enquiry is directed towards the conclusion or implementation of a contract with us, Art. 6 Paragraph 1 Letter b) GDPR is the legal basis for data processing. Otherwise, we process the data on the basis of our legitimate interest in making contact with inquiring persons. The legal basis for data processing is then Art. 6 Para. 1 letter f) GDPR.

When you register for training courses and webinars, we process personal data such as your name, your e-mail address and the company you work for. Further information is provided voluntarily. The processing is carried out for the execution of the contract. The legal basis for the processing is Art. 6 para. 1 letter b) GDPR.

In our download center we provide you with various contents for download. Some downloads are free of charge, others require registration or payment. For registration your name and e-mail address will be processed. This processing is done for the purpose of providing services. The legal basis is Art. 6 para. 1 letter b) GDPR.

By registering, you also agree to receive our newsletter. The legal basis for the processing is Art. 6 para. 1 letter a) GDPR. You can unsubscribe from the newsletter at any time using the “Unsubscribe” link in the newsletter or by contacting us through the channels mentioned above. If you have already subscribed to the newsletter, nothing will change for you.

a) Registration and deregistration

On our website we offer the possibility to register for our newsletter. After registration we will inform you regularly about the latest news about our offers. A valid e-mail address is required to register for the newsletter. To verify the e-mail address, you will first receive a registration e-mail, which you must confirm via a link (double opt-in). If you subscribe to the newsletter on our website, we process personal data such as your e-mail address, your title, your name, the company you belong to and your language preference based on the consent you have given. The data will not be transferred to third parties. The processing is based on the legal basis of Art. 6 para. 1 letter a) GDPR. You can revoke the consent you have given at any time with effect for the future, for example by using the “unsubscribe” link in the newsletter or by contacting us via the above-mentioned channels. The legality of the data processing operations already carried out remains unaffected by the revocation. When registering for the newsletter, we also save the IP address and the date and time of registration. The processing of this data is necessary to be able to prove that you have given your consent. The legal basis results from our legal obligation to document your consent (Art. 6 para. 1 letter c) in conjunction with Art. 7 para. 1 GDPR)

b) Newsletter analysis

We also analyse the reading behaviour and opening rates of our newsletter. For this purpose, we collect and process usage data, which we merge with your e-mail address or your IP address. The legal basis for this tracking is your consent in accordance with Art. 6 para. 1 letter a) GDPR. As the recipient, you have the possibility to revoke your consent at any time by contacting one of the above-mentioned contact channels or by using the “Change profile” link in the newsletter.

You can receive notifications on our website. In this way we can draw your attention to particularly interesting aspects of our website. To do this, you must activate the browser notifications. We process your data on the basis of the consent you have given us in accordance with Art. 6 Paragraph 1 Letter a) GDPR. The data will not be transferred to third parties. You have the right to revoke this consent with effect for the future at any time by issuing browser notifications via your browser settings or by clicking on the button “Unsubscribe from Push Service” (recognisable by the bell symbol) at the bottom left of the website. We only store your data as long as you have not revoked your consent.

You have direct access to EMM via our website. With the various features of EMM you have the possibility to organize the dispatch of your newsletters via our servers. For access you need a user name and a password. The legal basis for data processing is the consent you have given by subscribing to the service in accordance with Art. 6 Paragraph 1 Letter a) GDPR. You have the right to revoke this consent with effect for the future at any time. In this case, however, access to the EMM is no longer possible.

All of your customer data stored within the EMM (e.g. e-mail addresses, contact details) are your sole responsibility. For legal protection, we offer you the conclusion of a contract for data processing within the meaning of Art. 28 GDPR. Further information on the use of data in the EMM can be found in the user area.

We use cookies on our website. Cookies are small text files that are stored by your browser when you visit a website. This identifies the browser you are using and allows our web server to recognize it. If this use of cookies results in the processing of personal data, this is based on the legal basis of Art. 6 Para. 1 letter f) GDPR. This processing serves our legitimate interest in making our website more user-friendly, effective and secure. We use so-called “session cookies”, which are deleted again when the browser session is ended. Other cookies (“persistent cookies”) are automatically deleted after a specified period of time, which may vary depending on the cookie. You can delete the cookies in the security settings of your browser at any time. You can object to the use of cookies through your browser settings in principle or for specific cases.

Further information on this subject is available from the Federal Office for Information Security at https://www.bsi-fuer-buerger.de/BSIFB/DE/Empfehlungen/EinrichtungSoftware/EinrichtungBrowser/Sicherheitsmassnahmen/Cookies/cookies_node.html.

For marketing and optimization purposes, products and services of Lead Forensics (UK/EU) are used on this website. Lead Forensics determines the actual history of your visit to this website, including all pages visited and viewed by you and how long you spent on this site. If IP addresses are collected, they are anonymized immediately after collection. On behalf of the operator of this website, Lead Forensics will use the collected information to evaluate your visit to the website, to compile reports on the website activities and to provide further services to the website operator in connection with the use of the website and the internet. You can find further information on data protection at https://www.leadforensics.com/privacy-and-cookies/. As far as we process personal data, we do so on the basis of our legitimate interests to improve the design of our website. The legal basis is the protection of legitimate interests in accordance with Art. 6 Para. 1 Letter f) GDPR. You can object to data processing at any time with effect for the future by clicking on this Link. We will then no longer store any additional data.

We use the online advertising program Google Ads of Google Ireland Limited (Ireland/EU), through which we display ads on the Google search engine. If you reach our website via a Google ad, Google sets a cookie on your end device (“conversion cookie”). Each Google Ads client has a different conversion cookie associated with it, so the cookies are not tracked across the websites of different ads clients. The information collected through the cookie is used to compile conversion statistics. This allows us to know the total number of users who have clicked on one of our Google Ads. However, we do not receive any information that personally identifies users. Insofar as personal data is processed in this context, this is based on the legal basis of Art. 6 Para. 1 letter f) GDPR and the data processing serves our legitimate economic interests. You can object to inclusion in conversion tracking by preventing the setting of cookies via your browser settings. When using Google Ads, a transmission of the processed data to Google LLC, which is based in the USA, cannot be excluded by us. Google LLC (USA) is certified under the EU-US Privacy Shield.

We use on our website services, services and content provided by third parties (hereinafter collectively referred to as “Content”). For such integration, it is technically necessary to process your IP address so that the content can be sent to your browser. Your IP address is therefore transmitted to the respective third party providers. This data processing is carried out in each case to protect our legitimate interests in the optimisation and economic operation of our website and is based on the legal basis of Art. 6 Para. 1 Letter f) GDPR.  You can object to this data processing at any time via the settings of the browser used or certain browser extensions. One such extension is the matrix-based firewall uMatrix for the browsers Firefox and Google-Chrome. Please note that this may result in functional restrictions on the website.

We have incorporated into our website content from the following third-party services:

Services provided by Google Ireland Limited (Ireland/EU):

  • “Google Maps” to display maps;
  • “Google Web Fonts” for displaying fonts.

When using Google services, we may transfer the processed data to Google LLC (USA) based in the USA. Google LLC is certified under the EU-US Privacy Shield.

“YouTube” of YouTube LLC (USA) for the display of videos.

YouTube is certified as a subsidiary of Google under the EU-US Privacy Shield.

“Fontawesome” of the Fonticons Inc. (USA) for displaying fonts and icons.

Fonticons is not certified under the Privacy Shield.

3. Data processing on our Facebook fan page

When you visit our Facebook page, through which we present our company or individual products from our range, certain information about you is processed. The sole responsible party for this processing of personal data is Facebook Ireland Ltd (Ireland/EU). Further information about the processing of personal data by Facebook can be found at https://www.facebook.com/privacy/explanation.

Facebook provides us with statistics and insights for our Facebook page in an anonymous form, with the help of which we obtain information about the types of actions that people take on our page (so-called “page insights”). These Page-Insights are created on the basis of certain information about people who have visited our site. This processing of personal data is done by Facebook and us as jointly responsible parties. The processing serves our legitimate interest in evaluating the types of actions taken on our site and improving our site based on this information. The legal basis for this processing is Art. 6 para. 1 letter f) GDPR. Under no circumstances will we assign the information obtained via the Page Insights to a specific Facebook profile via the reference to “Like” information for our Page.

We have entered into an agreement with Facebook on processing as jointly responsible parties, which defines the distribution of data protection obligations between us and Facebook. Details of the processing of personal data for the creation of Page Insights and the agreement concluded between us and Facebook can be found at https://www.facebook.com/legal/terms/information_about_page_insights_data.

We also process information that you have provided to us via our Facebook page. Such information may be the Facebook name, contact information or a message to us. We only process this personal data if we have previously expressly asked you to provide us with this information, for example in the context of a survey. We process these data as the solely responsible party.

Insofar as your inquiry is directed towards the conclusion or implementation of a contract with us, Art. 6 Paragraph 1 Letter b) GDPR is the legal basis for data processing. Otherwise, we process the data on the basis of our legitimate interest in making contact with inquiring persons. The legal basis for data processing is then Art. 6 Para. 1 letter f) GDPR.

4. Further data processing

In order to establish or implement the contractual relationship with our customers, it is regularly necessary to process the contact data of the relevant contact persons that we have been provided with. The processing serves our legitimate interest in a smooth course of business. The legal basis for this processing is Art. 6 para. 1 letter f) GDPR. We also process customer and prospective customer data for evaluation and marketing purposes. These processing operations are carried out on the legal basis of Art. 6 para. 1 letter f) GDPR and serve our interest in further developing our offer and informing you specifically about offers from AGNITAS AG. Further data processing may be carried out if you have given your consent (Art. 6 para. 1 letter a) GDPR) or if this serves to fulfil a legal obligation (Art. 6 para. 1 letter c) GDPR.

If you apply to our company, we process your application data exclusively for purposes related to your interest in a current or future employment with us and the processing of your application. Your application will only be processed and acknowledged by the relevant contact persons at our company. All employees entrusted with data processing are obliged to maintain the confidentiality of your data. Should we not be able to offer you employment, we will retain the data you have submitted for up to three months after any rejection for the purpose of answering questions in connection with your application and rejection. This does not apply if legal provisions prevent deletion, if further storage is necessary for the purpose of providing evidence or if you have expressly consented to longer storage. The legal basis for data processing is § 26 para. 1 sentence 1 FDPA. Should we store your applicant data for more than three months and you have expressly consented to this, we would like to point out that this consent can be freely revoked at any time in accordance with Art. 7 Para. 3 GDPR. Such a revocation does not affect the lawfulness of the processing, which has been carried out until revocation on the basis of the consent.

We carry out surveys on customer satisfaction and the improvement of our service on an ad hoc basis. For this purpose, we collect and process the contact data from you that is evident from the surveys.

The legal basis for the use of this information is your consent in accordance with Art. 6 para. 1 letter a) GDPR. Your participation in the survey is voluntary, and the consent you have given to use it can be freely revoked at any time.

We use the service of the company SurveyMonkey Inc (USA) to conduct the surveys. SurveyMonkey collects additional information from cookies on participants. This is done to ensure that the survey service is fully usable and that the surveys run as intended and optimally.

The legal basis for the processing of this additional information is Art. 6 para. 1 letter f) GDPR. If you do not take part in our survey, no information about your person is collected.

SurveyMonkey is certified under the EU-US Privacy Shield.

If you register with us for lectures, workshops or other events, we process your personal data, such as name, e-mail address and the company to which you belong. These data are processed exclusively for the organisation and implementation of the event. The processing is carried out for the purpose of contract implementation. The legal basis is Art. 6 para. 1 letter b) GDPR.

We process contact data which we have received from you in the course of trade fairs or other events for the purpose of contract initiation in accordance with Art. 6 Paragraph 1 Letter b) GDPR.

If you participate in a competition, we process your personal data for the purpose of carrying out and processing the competition. This includes in particular the selection of winners, notification of the prize and delivery of the prize. In the event that the delivery or provision of certain prizes is carried out by another company (e.g. a subsidiary or other cooperation partner), we will transmit the winner’s data to this company to the necessary extent. We will delete the data after completion of the competition, provided that there are no legal storage obligations that prevent immediate deletion. The legal basis for the processing is Art. 6 para. 1 letter b) GDPR.

Newsletter

Stay up to date! Our newsletter keeps you informed about e-mail marketing.