Privacy Notice

Privacy Notice

Whether you are a customer or prospective customer, a supplier or service provider, an attendee at one of our events, a visitor to our website, or otherwise in contact with us, the following applies: We respect and protect your privacy!

In the following, you can get an overview of which personal data we process from you in which context, e.g. as a contact person or contact person at our customers and business partners. Which data is processed in detail and how it is used depends largely on the individually requested, agreed or provided services. Therefore, not all of the following information may apply to you. In addition, we will inform you about your rights under applicable data protection law and tell you who to contact if you have any questions.

Privacy notice for website visitors

Definition of terms
I. Controller within the meaning of Art. 4 Nr. 7 GDPR
II. Data Protection Officer
III. Collection of data
IV. Processing of data within the group of companies
V. Newsletter
VI. Inclusion of services from external providers
VII. Web analysis services
VIII. Online Marketing
IX. Cookies
X. Rights of data subjects
XI. Deletion and blocking of personal data
XII. Information and the right of objection
XIII. Social Plugins
XIV. Data Security
Amendments to this Data Protection Declaration

 

Definition of terms

This privacy statement is based on terms used in European regulations and by European regulators on the enactment of the General Data Protection Regulations (GDPR). Our privacy statement is intended to be simple to read and to understand for both the general public and our customers. In order to ensure this we would like to describe and explain the terms used.

In this privacy statement we have used the following terms:

Personal data (Art. 4 Nr. 1 GDPR)
Personal data is all data relating to an identified or identifiable natural person (hereinafter referred to the “data subject”). A natural person is one who can be identified, directly or indirectly, in particular through the attribution of an identifier to this natural person such as a name, an identification number, data on location, an on-line identifier or one or more particular characteristic, which gives expression to their physical, physiological, economic, cultural or social identity.

Processing (Art. 4 Nr. 2 GDPR)
Processing is any process executed, with or without automated procedures, or any such operational sequence in connection with personal data such as collection, recording, organization, arranging, saving, amendment or changing, reading, querying, usage, disclosure through transmission, distribution or any other form of provision, comparing or linking, limitation, deletion or destruction.

Controller or Processor (Art. 4 Nr. 7 GDPR)
The controller or processor is the natural or legal person, authority, agency or other body who alone or jointly with others determines the purposes and means of the processing of personal data; where the purposes and means of processing are determined by national or European laws or regulations, the controller or the specific criteria for his nomination may be designated by national or European law.

Third Party (Art. 4 Nr. 10 GDPR)
Third party’ means any natural or legal person, public authority, agency or anybody other than the data subject, the controller, the processor and the persons who, under the direct authority of the controller or the processor, are authorized to process data.

Consent (Art. 4 Nr. 11 GDPR)
Consent is any indication given freely, unambiguously and unmistakably and in specific cases by the data subject in the form of a declaration or any other explicit confirmatory act with which the data subject indicates their agreement with the processing of personal data relating to them.

I. Controller within the meaning of Art. 4 Nr. 7 GDPR:

The Controller within the meaning of GDPR and other provisions with data protection implications is:

Scheer PAS Deutschland GmbH
Uni-Campus Nord
D-66123 Saarbrücken
Phone: +49 681 96777-0
E-Mail: info@scheer-pas.com (general)
E-Mail: karriere@scheer-group.com (Concerning recruiting and application procedure)

Comprehensive provider identification can be found in the Imprint.

II. Data Protection Officer

Should you have any questions about this Privacy statement please contact our data protection officer:

Scheer PAS Deutschland GmbH
The Data Protection Officer
Uni-Campus Nord
D-66123 Saarbrücken
E-Mail: datenschutz@scheer-group.com

III. Collection of data

On visiting our website diverse sets of data from you will be processed. In so doing we can differentiate between the exclusively informative use of the website and the use of specific functions within the website.

The contents and services of this website are fundamentally not addressed to persons under 16 years of age. If you are not yet 16 years of age we request that you do not enter or make available any personal data via the website.

a. Collection of (personal) data during the information only use of the website
Please note that on the purely informational use of our internet pages, by which no registration or other transfer of details is necessary, no personal data will be collected. Excepted from this is data that is transmitted by your browser to enable your visit to the website. Our webserver temporarily saves each access locally in a protocol file.

The following data is collected:

• IP-Address

• Date and time of access

• Name and URL of the accessed file

• Data volume transferred

• Notification whether or not the data retrieval was successful

• Identification data from the browser used and the operating system

• Website (URL), from where the access took place

• Time zone difference to Greenwich Mean Time (GMT)

• Content of the request (actual page)

• Access stature / HTTP-Status code

The processing of this data takes place for the purpose of enabling the use of the website (connection establishment) as well as for the purpose of system security, diagnosis of problems and the technical administration of the network infrastructure. The IP address will only be evaluated on attacks on the network infrastructure or for other reasons relating to data and information security.

b. Collection of personal data by the use of particular functions within our website

Alongside the purely informational use of the website we offer particular services for which specific personal data is processed.

Should you be asked to provide personal data on our website, for example when registering for one of our events, this information is given voluntarily. It serves the provision of information and services to you within the framework of your request as well as the care of the relationship with you as an interested party or customer. Should the information requested not be given then we cannot unfortunately make the relevant offer available to you as we will not be able to process your request.

Your details will be treated in accordance with legal provisions, in particular for the purposes for which you have given them to us voluntarily. The processing of your data for reasons going beyond these purposes will only take place if you have given your consent or if this is permitted by legal provision.

• Contact form/ Email
Because of legal requirements the Scheer GmbH website contains details which enable quick electronic contact as well as immediate communication with us. When you make contact with us via email or via a contact form the personal data you have provided will be saved automatically. Such personal data, provided voluntarily by you, will be saved for the purpose of contacting you and processing your request. We base the data processing on the fulfilment of a legal requirement in accordance with Art. 6 para 1 S.1 c GDPR.

• Registration for a webinar
If you wish to participate in one of our webinars you must register for this event and make your personal data available to us. Your personal data will be used exclusively for the planning (e.g. to make contact with you on the cancellation or re-scheduling of the webinar) and conduct of the webinar, insofar as you have given no further consent for its use. In connection with this please also note Section VI „Inclusion of Services from external providers” – subsection LogMeIn, Inc. 7414 Hollister Avenue Goleta, CA 93117, USA of this Privacy statement. The collection of your data in this context is based on our legitimate interest in accordance with Article 6 Para 1 Sub-para 1 f) of GDPR. Here we have a legitimate interest in knowing to whom we are passing our skills and our know-how in respect of products and services.

• Registration for an activity (event)
If you wish to participate in one of our events you must register for this event and make your personal data available to us. Your personal data will be used exclusively for the planning (e.g. to make contact with you on the cancellation or re-scheduling of the event) and conducting of the event as well as the possible processing of payment insofar as the event is chargeable, insofar as you have given no further consent for its use. The collection of your data in this context is based on our legitimate interest in accordance with Article 6 Para 1 Sub-para 1 f) of GDPR. Here we have a legitimate interest in knowing who is registering on an event organized by us or in cooperation with others. Furthermore the collection of the data, insofar as it relates to a chargeable event, is based on the performance of the contract in accordance with Article 6 Para 1 Sub-para 1 b) of GDPR.

• Access to whitepapers, case studies, information brochures, specialist articles, reports and studies as well as recorded webinars.
If you wish to access a whitepaper, a case study, an information brochure, a specialist article, a report / a study or one of our recorded webinars you must register for this purpose and submit your personal data to us. Your personal data will be used in order for us to know to whom we are passing our skills and our know-how for our products and services and also possibly for the purpose of contacting you. The collection of your data in this context is based on our legitimate interest in accordance with Article 6 Para 1 Sub-para 1 f) of GDPR, the making of contact in accordance with Article 6 Para 1 Sub-para 1 a) of GDPR.

• Applications for Employment
If you are interested in working for our company you can find information on our current vacancies on our website at https://jobs.scheer-group.com/. Alongside extensive information about us as an employer or about the application process you will find our current job offers which we coordinate via the application portal of a service provider (SAP SuccessFactors).

Fundamentally we process your personal data in the application process on your request in accordance with Article 6 Para 1b of GDPR, Article 88 Para 1 of GDPR in conjunction with § 26 Para 1 of BDSG (Federal Data Protection Act) for the purpose of the conducting of the application procedure. You are neither legally nor contractually obliged to submit your data to us. As we need information on your person as part of the application process, the possible consequence of a failure to provide it is that we will unfortunately not be able to consider you in the application process.

Using our online application portal you can make a direct application as a candidate for employment in the positions advertised. A corresponding process of registration is necessary for this. During the input of your online application you have the possibility at any time of seeing, deleting, disabling and re-releasing your data. We inform you about data processing in the application process at the start of the registration process.

IV. Processing of data within the group of companies

Within the responsible areas of the business only those areas which require it for the safeguarding of our legitimate interests or for the fulfilment of our contractual and legal obligations will be enabled access to your data.

It is possible that your request requires the transfer of your data within the company group or connected companies in accordance with § 15 of the German Stock Companies Act.

V. Newsletter

You have the opportunity of registering to receive our newsletter.

Data collection within the framework of newsletter distribution is based on your voluntary consent in accordance with Article 6 Para 1 Sub-para 1 of GDPR. You give this to us within the framework of a double opt in process so that we can check that you are the rightful owner of the email address stated and that you consent to receiving the newsletter. This consent can be withdrawn for the future at any time.

a. Registration process
In order to subscribe to our newsletter you must submit your email address in our newsletter form as well as sending us the form by clicking on the “send” button. After receipt of the data we will send you confirmation by email. Within this email is a button which must be clicked in order for you to conclusively complete your newsletter registration (double opt-in).

In order for us to send you a personalized newsletter with information relating directly to your interests we would be pleased to receive more voluntary information from you.

b. Withdrawal of Consent
As a matter of course you have the possibility to de-register from your newsletter subscription at any time and to withdraw the consent you have given for the future. You can do this either by clicking on the corresponding button within the newsletter or by sending an email to the followingAs a matter of course you have the possibility to de-register from your newsletter subscription at any time and to withdraw the consent you have given for the future. You can do this either by clicking on the corresponding button within the newsletter or by sending an email to info@scheer-pas.com.

VI. Inclusion of services from external providers

Individual pages in our web offering include content provided by third parties. In these cases your IP address will be recognized by third parties in order to make the information available to you. In doing so these third parties will receive your personal data, whereby the processing of your data outside the EU cannot be excluded.

The transfer of personal data is independent of whether you have a user account with the third party and whether you are logged in with them at the same. In cases where a user account exists and you are logged in it must be assumed that your data will be allocated to your user account. IN order to prevent this you should log out of the third party site.

You have the possibility of preventing the execution of scripts by these providers by installing a corresponding browser plug-in (for example NoScript with a Mozilla-Firefox browser). This may however as a consequence lead to limitations in the functions of this website.

We are not responsible for the online collection of data on the websites of third parties and recommend that you familiarize yourself with the data protection information of these providers. The following sections include an overview of the external providers included in the context of the offer made here:

• Google Inc., Amphitheatre Parkway, Mountain

We use Java-Script from Google in order to include maps with Google Maps APIs. Further we use the „g+“ button from the Google Plus social network. The button is recognizable via the “g+” sign on a red background. You can access further information on Google’s privacy statement here: https://policies.google.com/privacy?hl=en

• Google Ads and Conversion Tracking, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland,

We use the Google “Ads” online marketing method to place ads on the Google advertising network (e.g., in search results, videos, websites, etc.) so that they are displayed to users who have an alleged interest in the ads. We also measure the conversion of the ads. However, we only know the anonymous total number of users who clicked on our ad and were redirected to a page tagged with a conversion tracking tag. However, we ourselves do not receive any information that can be used to identify users. Parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Website: https://marketingplatform.google.com; Privacy Policy: https://policies.google.com/privacy.

• HubSpot:

Marketing software for lead generation, marketing automation and analysis of marketing activities, Email marketing platform, Chatbot and assistance software and related services, Customer relations and service software (management of customer inquiries from various channels), ticketing system, feedback, satisfaction and other surveys; Service provider: HubSpot, Inc., 25 First St., 2nd floor, Cambridge, Massachusetts 02141, USA; Website: https://www.hubspot.de; Privacy Policy: https://legal.hubspot.com/privacy-policy.

• Cloudflare Inc., 101 Townsend St, San Francisco, CA 94107, USA (Hereinafter referred to as „Cloudflare“)

We use Java-Scrip from Cloudflare in order to display the cookie warning notification. You can access further information on Cloudflare’s privacy statement here: https://www.cloudflare.com/security-policy/

• YouTube, LLC 901 Cherry Ave, San Bruno, CA 94066, USA (Hereinafter referred to as „YouTube“)

We use Java-Scrip from YouTube in order to include YouTube videos in our website. As YouTube is owned by Google please see further information on data protection from Google: https://policies.google.com/privacy?hl=en

• SAP Germany SE & CO. KG, Hasso-Plattner-Ring 7, 69190 Walldorf

We use the application management software SuccessFactors from SAP for our application process. For this purpose an agreement covering data processing for SAP cloud services amongst others has been made with the service provider. 

• DocuSign, Inc., 221 Main Street Suite 1000 San Francisco, CA 94105, USA

DocuSign provides a digital transaction management platform to facilitate digital transactions that include the signing process of contractual documents and other documents; Website: https://www.docusign.com/; Privacy Policy: https://www.docusign.com/company/privacy-policy; The processing as processor and controller is carried out on the basis of approved Binding Corporate Rules, which ensure a level of data protection in accordance with the requirements of the GDPR (Article 47 GDPR): https://www.docusign.com/trust/privacy/binding-corporate-rules.

• Jira, Atlassian Inc. (San Francisco, Harrison Street Location), 1098 Harrison Street, San Francisco, California 94103, USA

Web application for error management, troubleshooting and operational project management; Website: https://www.atlassian.com/de/software/jira; Privacy Policy: https://www.atlassian.com/legal/privacy-policy.

• LogMeIn, Inc. 7414 Hollister Avenue Goleta, CA 93117, USA (Hereinafter referred to as „GoToWebinar“)

In order to run our web-sessions we use the „GoToWebinar“ tool (https://www.goto.com/de/webinar) from the provider LogMeIn inc. The “GoToWebinar” tool is marketed by the following Irish company: LogMeIn Ireland Limited, Bloodstone Building Block C70 Sir John Rogerson’s Quay, Dublin 2, Ireland.In order to offer the service the data you submit at log-in is transferred to LogMeIn Inc. whereby a data transfer outside the EU is possible. You can access further information on data protection from LogMeIn Inc. at https://www.logmein.com/legal

• Facebook Pixel and Custom Audiences (Custom Audiences) Meta Platforms Ireland Ltd. 4 Grand Canal Square Grand Canal Harbour Dublin 2 Irland („Facebook“)

Service provider: https://www.facebook.com, parent company: Facebook, 1 Hacker Way, Menlo Park, CA 94025, USA; Website: https://www.facebook.com; Privacy Policy: https://www.facebook.com/about/privacy; Opt-Out: https://www.facebook.com/adpreferences/ad_settings (login at Facebook is required).

• LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA

e.g. Insights Tag / Conversion tracking; Website: https://www.linkedin.com; Privacy Policy: https://www.linkedin.com/legal/privacy-policy, cookie policy: https://www.linkedin.com/legal/cookie_policy; Opt-Out: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.

• Microsoft Bookings

We use the Microsoft Bookings service (part of Microsoft Office 365) of the provider Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18 D18 P521 (hereinafter: “Microsoft”) to make online appointments. The service enables the booking of a personal or telephone consultation appointment with an employee of Scheer GmbH (e.g. for a consultation before and / or after the conclusion of a contract).

The connection to the service is only established if you actually make an appointment using the online booking function via Microsoft Bookings (e.g. via a link or button on our website, in an e-mail or in the newsletter). For the appointment arrangement, your entries from the appointment arrangement form are transferred to Microsoft. You can find further information on the handling of your data in Microsoft’s privacy policy.

The legal basis for the processing of your data in relation to the “Microsoft Bookings” service is Art. 6 §1 p. 1 letter f) DS-GVO (German General Data Protection Regulation, here referring to the legitimate interest in data processing). The beforementioned legitimate interest arises from our claim to offer you a user-friendly website with a wide range of functions, giving you the opportunity to make a telephone appointment with our staff in a quick and easy manner, at any time, if necessary. We would like to point out that you are not obliged to use Microsoft Bookings to make an appointment. If you do not wish to use the service, please use a different kind of contact option provided to schedule an appointment.

• SurveyMonkey Inc., 1 Curiosity Way, San Mateo, California 94403, USA

SurveyMonkey Survey Services; Service provider: Website: https://www.surveymonkey.co.uk; Privacy Policy: https://www.surveymonkey.co.uk/mp/legal/privacy-policy/?ut_source=footer.

• Socialbakers Emplifi Czech Republic a.s., Pod Všemi svatými 17, Plzeň 301 00, Czech Republic

Socialbakers is a social media planning tool that can be used, among other things, to pre-plan posts in various social media channels, publish them or evaluate their performance. Privacy Policy at: https://www.socialbakers.com/privacy-policy.

VII. Web analysis services

• Google Analytics

This website uses Google Analytics, a web analysis service by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (hereinafter referred to as “Google”). Google Analytics uses the cookies listed below.

• Google Tag Manager

Google Tag Manager is a solution with which we can manage so-called website tags via an interface and thus integrate other services into our online services (please refer to further details in this privacy policy). With the Tag Manager itself (which implements the tags), for example, no user profiles are created or cookies are stored. Google only receives the IP address of the user, which is necessary to run the Google Tag Manager. Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Website: https://marketingplatform.google.com/about/; Privacy Policy: https://policies.google.com/privacy.

In case of your consent, the cookies are going to be saved on your computer and enable an analysis of your usage of the website.

In cases where IP anonymization has been activated on this website, your IP address will be shortened beforehand by Google but within member states of the European Union or in other contracting party states to the agreement within the European Economic Area. The full IP address will only be transferred to a Google server in the USA and then shortened in exceptional cases. For the exceptional cases in which personal data is transferred to the USA, Google has subjected itself to the EU-US Privacy Shield, https://www.privacyshield.gov/list.

On behalf of the operator of this website, Google will use this information to evaluate your use of the website, to compile reports on the website activities and to provide further services to the website operator in connection with the use of the website and the internet.

Google may also transfer this information to third parties where required to do so by law, or where such third parties process the information on Google’s behalf. The IP address transmitted by your browser within the framework of Google Analytics is not merged with other data from Google.

Further information can be found in the Google privacy policy: https://policies.google.com/privacy, an overview of the protection and security of your data: https://support.google.com/analytics/answer/6004245?hl=de, and the Google Analytics conditions at: https://policies.google.com/terms?hl=en.

• Fastbase

This website uses the Fastbase Webleads Add-On from Fastbase Inc, State File No.: 56484453422 Old Capitol Trail, Suit 700 City of Welmington County of New Castle, Zip Code 19808-6192, USA, which matches data from Google Analytics with the Fastbase Database, an internet business registry. This database provides us with specific company information and contact information about visitors to our website.
For more information, please refer to Fastbase’s privacy policy: https://analytics.fastbase.com/privacy-policy

• Google Maps

This page uses the map service Google Maps via an API. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, a company of Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (hereinafter referred to as „Google“). In order to use Google Maps functionality it is necessary to save your IP address. This information is, as a rule, transferred to a Google server in the USA and saved there. We have no influence over this transfer of data. The use of Google Maps takes place in the interest of an appealing presentation of our online offerings and in the ease of locating the sites given by us on the website. We do this based on our legitimate interest in accordance with Article 6 Para 1 letter f of GDPR. You can access further information on Google’s privacy statement here: https://policies.google.com/privacy

VIII. Online Marketing

We process personal data for the purposes of online marketing, which may include in particular the marketing of advertising space or the display of advertising and other content (collectively referred to as “Content”) based on the potential interests of users and the measurement of their effectiveness.

For these purposes, so-called user profiles are created and stored in a file (so-called “cookie”) or similar procedure in which the relevant user information for the display of the aforementioned content is stored. This information may include, for example, content viewed, websites visited, online networks used, communication partners and technical information such as the browser used, computer system used and information on usage times. If users have consented to the collection of their sideline data, these can also be processed.

The IP addresses of the users are also stored. However, we use provided IP masking procedures (i.e. pseudonymisation by shortening the IP address) to ensure the protection of the user’s by using a pseudonym. In general, within the framework of the online marketing process, no clear user data (such as e-mail addresses or names) is secured, but pseudonyms. This means that we, as well as the providers of online marketing procedures, do not know the actual identity of the users, but only the information stored in their profiles.

The information in the profiles is usually stored in the cookies or similar memorizing procedures. These cookies can later, generally also on other websites that use the same online marketing technology, be read and analyzed for purposes of content display, as well as supplemented with other data and stored on the server of the online marketing technology provider.

Exceptionally, clear data can be assigned to the profiles. This is the case, for example, if the users are members of a social network whose online marketing technology we use and the network links the profiles of the users in the aforementioned data. Please note that users may enter into additional agreements with the social network providers or other service providers, e.g. by consenting as part of a registration process.

As a matter of principle, we only gain access to summarised information about the performance of our advertisements. However, within the framework of so-called conversion measurement, we can check which of our online marketing processes have led to a so-called conversion, i.e. to the conclusion of a contract with us. The conversion measurement is used alone for the performance analysis of our marketing activities.

Unless otherwise stated, we kindly ask you to consider that cookies used will be stored for a period of two years.

Information on legal basis: If we ask users for their consent (e.g. in the context of a so-called “cookie banner consent”), the legal basis for processing data for online marketing purposes is this consent. Otherwise, user data will be processed on the basis of our legitimate interests (i.e. interest in the analysis, optimisation and economic operation of our online services. In this context, we would also like to refer you to the information on the use of cookies in this privacy policy.

Google Analytics Audiences: We use Google Analytics to display ads placed by Google and its partnersonly to users who have shown an interest in our online services or who have specific characteristics (e.g. interests in specific topics or products determined on the basis of the websites visited) that we transmit to Google (so-called “Remarketing Audiences” or “Google Analytics Audiences”). With the help of remarketing audiences, we also want to ensure that our ads match the potential interest of users.

Facebook Pixel and Custom Audiences (Custom Audiences): With the help of the Facebook pixel  (or equivalent functions, to transfer Event-Data or Contact Information via interfaces or other software in apps), Facebook is on the one hand able to determine the visitors of our online services as a target group for the presentation of ads (so-called “Facebook ads”). Accordingly, we use Facebook pixels to display Facebook ads placed by us only to Facebook users and within the services of partners cooperating with Facebook (so-called “audience network” https://www.facebook.com/audiencenetwork/ ) who have shown an interest in our online services or who have certain characteristics (e.g. interests in certain topics or products that are determined on the basis of the websites visited) that we transmit to Facebook (so-called “custom audiences”). With the help of Facebook pixels, we also want to ensure that our Facebook ads correspond to the potential interest of users and do not appear annoying. The Facebook pixel also enables us to track the effectiveness of Facebook ads for statistical and market research purposes by showing whether users were referred to our website after clicking on a Facebook ad (known as “conversion tracking”).

We are jointly responsible (so-called “joint-controllership”) with Meta Platforms Ireland Ltd. for the collection or transmission (but not the further processing) of “event data” that Facebook collects or receives as part of a transmission for the following purposes using the Facebook pixel and comparable functions (e.g. APIs) that are implemented in our online services: a) displaying content advertising information that matches users’ presumed interests; b) delivering commercial and transactional messages (e.g. b) delivering commercial and transactional messages (e.g., addressing users via Facebook Messenger); c) improving ad delivery and personalizing features and content (e.g., improving recognition of which content or advertising information is believed to be of interest to users). We have entered into a special agreement with Facebook (“Controller Addendum”, https://www.facebook.com/legal/controller_addendum), which specifically addresses the security measures that Facebook must take (https://www.facebook.com/legal/terms/data_security_terms) and in which Facebook has agreed to comply with the rights of data subjects (i.e., users can, for example, submit information access or deletion requests directly to Facebook). Note: If Facebook provides us with measurements, analyses and reports (which are aggregated, i.e. do not contain information on individual users and are anonymous to us), then this processing is not carried out within the scope of joint responsibility, but on the basis of a DPA (“Data Processing Terms”, https://www.facebook.com/legal/terms/dataprocessing), the “Data Security Conditions” (https://www.facebook.com/legal/terms/data_security_terms) and, with regard to processing in the USA, on the basis of Standard Contractual Clauses (“Facebook EU Data Transfer Addendum, https://www.facebook.com/legal/EU_data_transfer_addendum). The rights of users (in particular to access to information, erasure, objection and complaint to the competent supervisory authority) are not restricted by the agreements with Facebook.

Settings/ Opt-Out:

At this point, you can enter information about individual opt-out-links or HTML code. However, this information is not necessary if you use a cookie opt-in banner and users can decide there which cookies they want to set:

  • Processed data types: Usage data (e.g. websites visited, interest in content, access times), Meta/communication data (e.g. device information, IP addresses), Event Data (Facebook) (“Event Data” is data that can be transmitted from us to Facebook, e.g. via Facebook pixels (via apps or other means) and relates to persons or their actions; the data includes, for example, information about visits to websites, interactions with content, functions, installations of apps, purchases of products, etc.; Event data is processed for the purpose of creating target groups for content and advertising information (Custom Audiences); Event Data does not include the actual content (such as written comments), login information, and Contact Information (such as names, email addresses, and phone numbers). Event Data is deleted by Facebook after a maximum of two years, the Custom Audiences created from them with the deletion of our Facebook account).
  • Data subjects: Users (e.g. website visitors, users of online services).
  • Purposes of Processing: Marketing, Profiles with user-related information (Creating user profiles), Remarketing, Custom Audiences (Selection of relevant target groups for marketing purposes or other output of content), Conversion tracking (Measurement of the effectiveness of marketing activities), Affiliate Tracking.
  • Security measures: IP Masking (Pseudonymization of the IP address).
  • Legal Basis: Consent (Article 6 (1) (a) GDPR), Legitimate Interests (Article 6 (1) (f) GDPR).
  • Opt-Out: We refer to the privacy policies of the respective service providers and the possibilities for objection (so-called “opt-out”). If no explicit opt-out option has been specified, it is possible to deactivate cookies in the settings of your browser. However, this may restrict the functions of our online offer. We therefore recommend the following additional opt-out options, which are offered collectively for each area:a) Europe: https://www.youronlinechoices.eu. b) Canada: https://www.youradchoices.ca/choices. c) USA: https://optout.aboutads.info/. d) Cross-regional: https://optout.aboutads.info.

IX. Cookies

On our website, we use both internal and external cookies, such as essential cookies, statistic cookies, marketing cookies and external media. Essential cookies facilitate the optimal presentation and use of the website and all of its functions. We use statistic cookies to generate aggregated data about the website use and statistics. Marketing cookies are used in order to display ads that are relevant to the visitors of our website. The External Media Cookies enable the access to video platforms and social media platforms.

If you click “Accept all cookies”, you agree with the use of all cookies. Alternatively, you can make your individual selection about which cookies you want to accept. The given consent can be withdrawn at any time with effect for the future.

a. What are cookies?

Cookies are small text files that are saved locally in the cache of your internet browser on your computer or mobile device. The information stored in the cookies serves the automatic recognition of you when you next visit our website which makes our offer to you more user-friendly, for example simplifying navigation for you.

b. Deletion of cookies

You have the possibility of choosing settings for your browser so that it will reject cookies or inform you that they have been saved. To find out exactly how this functions for each browser type, please refer to the instructions from the corresponding manufacturer. If you decline to accept cookies, this may lead to limitations in functionality in our offerings. Cookies may also be used on sites with which we are linked without being able to inform you of this prior to your visit.

Please note that on deletion of cookies, for example through the use of corresponding browser add-ons, other opt-out cookies you have installed may also be deleted.

Further possible data input will not be linked with the saved information from the cookies. The different data will be saved separately from each other.

Under the following links you can find out how you can manage the cookies of the most important browsers (including deactivating them):

Chrome Browser: https://support.google.com/accounts/answer/61416?hl=en

Internet Explorer: https://support.microsoft.com/en-GB/topic/168dab11-0753-043d-7c16-ede5947fc64d

Mozilla Firefox: https://support.mozilla.org/en-US/kb/how-clear-firefox-cache

Safari: https://support.apple.com/guide/safari/manage-cookies-and-website-data-sfri11471/mac

c. Objection to data processing

You can prevent the saving of cookies by an applicant setting in your browser software. However, we would like to point out that as a consequence, you may not be able to use the scope of functions of this website to its full extent.
Furthermore, you can prevent the acquisition of data that has been collected and referred to your personal usage of the website through cookies, including your IP-address, from being sent to Google and from being reprocessed from Google. To do so, please use the following link to install the add-on to deactivate Google Analytics from your browser: https://tools.google.com/dlpage/gaoptout?hl=en. The tracking code of our website is used with a feature that processes your IP address in an abbreviated form. As a consequence, the collected data cannot be linked to individuals.

d. Types of Cookies

We subdivide cookies into the following categories, according to the designated use:

  1. Essential
  2. Statistics
  3. Marketing
  4. External media

In the following paragraphs we will inform you about the different types of cookies more specifically. We will also inform you which cookies are going to be placed and used in case of your consent.

  • Essential cookies

Essential cookies are used to ensure essential functions and proper use of the website.

Name: borlabs-cookie
Description: Saves settings of users that were selected in the cookie box of Borlabs Cookie.
Duration: 1 year

  • Statistic cookies

Statistic cookies collect aggregated information about how the website is used. This information is used to improve functionality, appeal and content of the website.

Google Inc., Amphitheatre Parkway, Mountain View, CA 94043, USA

The following statistic cookies are in use within the framework of this website and the use of Google Analytics:

Name: _ga
Description: This cookie is used to collect information about how visitors use our website. We use said information to make reports and improve our website. The cookie collects data anonymously, including the number of website visits and which websites have led users to come to the website.
Duration: 2 years

Name: _gat
Description: This cookie is used to restrict inquiries and to limit the collection of data on highly frequented websites.
Duration: 1 day

Name: _gid
Description: This cookie contains a Google Analytics client ID and is responsible for tracking user behavior.
Duration: 1 day

  • Marketing cookies

Marketing cookies are used by third parties in order to gather information to display target-group-specific content.

HubSpot Inc.

HubSpot is a user database management service provided by HubSpot, Inc. We use HubSpot on this website for our online marketing activities.

Name: __hs_opt_out, __hs_d_not_track, hs_ab_test, hs-messages-is-open, hs-messages-hide-welcome-message, __hstc, hubspotutk, __hssc, __hssrc, messagesUtk

Runtime: session / 30 minutes / 1 day / 1 year / 13 months

Google Inc., Amphitheatre Parkway, Mountain View, CA 94043, USA

Name: GPS
Description: This cookie registers a distinct ID on mobile devices to facilitate tracking based on geographical gps location.
Duration: 1 day

Facebook Pixel (Meta Platforms Ireland Ltd.)

Cookie from Facebook used for website analytics, ad targeting and ad measurement.

Name: _fbp,act,c_user,datr,fr,m_pixel_ration,pl,presence,sb,spin,wd,xs

Runtime: Session / 1Year

LinkedIn Insight Tag (LinkedIn Ireland Unlimited Company)

The LinkedIn Insight tag enables the collection of data about visits to this website. LinkedIn does not share any personally identifiable information with the owner of this website, but only provides aggregate reports about website audience and ad performance.

Name: _ga, _gat; _lipt, bcookie, lang, lidc

Runtime: 90 days

  • External media

Content from video platforms and social media platforms is blocked by default. If cookies from external media are accepted, access to this content no longer requires manual consent.

YouTube, LLC 901 Cherry Ave, San Bruno, CA 94066, USA

Name: YSC
Description: A distinct identification that is assigned to the website user while watching a YouTube video.
Duration: Session

X. Rights of data subjects

Within the framework of the corresponding legislation (Article 15 – 21 GDPR) you have many rights regarding the processing of your personal data: the right to information, rectification, deletion, limitation of processing as well as the right of data portability. By the rights of information and deletion there are limitations in accordance with §§ 34, 35 of the German Data Protection Act.

In addition you have the right to object to the processing of your personal data for the purpose of direct marketing. Should we process your data for the purposes of safeguarding our legitimate interests you are entitled to object to this processing if, for reasons of your particular situation, grounds exist for an objection to this data processing.

You also have the right not to be subject to a decision based solely on the automated processing of data. Likewise you have the right to complain to a responsible data protection authority.

If you have given us your consent for the processing of personal information for specific purposes, you are entitled to withdraw this consent at any time with effect for the future.

Should you wish to exercise your rights as a data subject you can do so at any time by making contact with us as detailed in I. or II.

XI. Deletion and blocking of personal data

Fundamentally we will delete your data the moment it is not required for the purposes detailed above unless further temporary storage is necessary. We save your data because of statutory obligations of proof and storage resulting among other things from the Commercial Code of Law and the Tax Code in Germany. The retention periods can be up to 10 full years.

In addition we retain your data for the period of time in which claims can be asserted against our company (the statutory period of limitation is from three to 30 years).

XII. Information and the right of objection

You have the right to request information from us about the personal data relating to you that we have processed. Under certain conditions you can request the rectification of your data (should it no longer be applicable to you), supplements to it or its deletion. Further you have the right to withdraw, in part or in total, any consent for the future to the use of your data that you may have given. Please direct your inquiry to: Scheer PAS GmbH The Data Protection Officer Uni-Campus Nord D-66123 Saarbrücken E-Mail: datenschutz@scheer-group.com In order to prevent any unauthorized access or misuse of your data we may contact you immediately to verify your request.

XIII. Social Media Plugins/ Third Party Cookies

Fundamentally we do not permanently include any direct “share” or “like” buttons from social networks on our website.

We would be very pleased if your interest in our company and our products and services were not limited to this visit to our website only but if you were also to visit our presence in social media networks. To access these we offer you the option of clicking on the corresponding links at the end of our website.

We have neither any influence on the data collected and the data processing procedures of plug-in providers, nor is the full extent of the data collection, the purpose of the processing or the retention period known to us. No information is available to us about the deletion of data collected by plug-in providers.

The following sections include information on our social media presence:

  • Twitter Inc., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA

Within our social media offering from Twitter we include functions and content such as pictures, videos or texts as well as buttons with which you can confirm your approval in respect of the content or subscribe to our posts. Insofar as you have a Twitter account, Twitter is able match access to the content and functions mentioned above to your profile. You can access further information on data protection from Twitter at https://twitter.com/de/privacy.

Instagram Inc., 1601 Willow Road, Menlo Park, CA, 94025, USA
Within our social media offering from Instagram we include functions and content such as pictures, videos or texts as well as buttons with which you can confirm your approval in respect of the content or subscribe to our posts. Insofar as you have an Instagram account, Instagram is able match access to the content and functions mentioned above to your profile. You can access further information on data protection from Instagram at https://help.instagram.com/519522125107875.

  • LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland

LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland
Within our social media offering from LinkedIn we include functions and content such as pictures, videos or texts as well as buttons with which you can confirm your approval in respect of the content or subscribe to our posts. Insofar as you have a LinkedIn account, LinkedIn is able match access to the content and functions mentioned above to your profile. You can access further information on data protection from LinkedIn at https://www.linkedin.com/legal/privacy-policy.

  • Meta Platforms Ireland Ltd. 4 Grand Canal Square Grand Canal Harbour Dublin 2 Irland („Facebook“)

Within our social media offering from Facebook we include functions and content such as pictures, videos or texts as well as buttons with which you can confirm your approval in respect of the content or subscribe to our posts. Insofar as you have a Facebook account, Facebook is able match access to the content and functions mentioned above to your profile. You can access further information on data protection from Facebook at https://de-de.facebook.com/policy.php.

You can find additional information on data collection by Facebook here:
https://www.facebook.com/help/186325668085084
https://www.facebook.com/about/privacy/your-info#everyoneinfo

In addition the following agreement applies between Facebook and the data Controller named in Section 1, which describes the respective responsibilities in greater detail:
https://de-de.facebook.com/legal/terms/page_controller_addendum

  • YouTube, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland

​​​​​​​Social network and video platform; Parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Privacy Policy: https://policies.google.com/privacy; Opt-Out: https://adssettings.google.com/authenticated.

XIV. Data security

To ensure data security we employ various measures corresponding to current relevant technological standards. These serve in particular to protect your personal data. We would like to advise you, however, that data transfer in the internet (for example when communicating by email) may involve gaps in security and cannot be protected completely from access by third parties. For particularly sensitive information we therefore recommend the use of alternative means of encrypted communication or the post.

Amendments to this Privacy Statement

In the course of continuing further developments in the internet and changes in data protection law it will be necessary to amend this privacy statement in line with conditions as they change. Significant amendments will be communicated in a timely manner on this site.

Current status of this declaration is December 2020.

Privacy notice for customers and other data subjects

Information on data protection

As a data processing company for us (see “Who is responsible for data processing?”) the protection of your personal data is very important. We treat your personal data confidentially and in accordance with the applicable local data protection regulations (e.g. European General Data Protection Regulation [GDPR], German Federal Data Protection Act [BDSG], Austrian Data Protection Act 2018 [DSG 2018] and so on).

The GDPR provides that persons who collect data must be informed about the relevant processing context in order to ensure fair and transparent processing.

With the following information, we will give you an overview of the processing of your personal data by us, inform you about your rights under data protection law and will be happy to tell you who you can contact if you have any questions. Which data is processed in detail and in what way is largely determined by the services requested or commissioned by you. Therefore, not all parts of this information will probably apply to you directly.

Who is responsible for data processing?

Within the meaning of the law, the company with which you enter into your contract or/or have made your other agreement. Which this is, please refer to your documents. The following information on the respective person responsible can be found:
 

Scheer PAS Deutschland GmbH
Scheer Tower
Uni-Campus Nord
D-66123 Saarbrücken
Phone: +49 681 96777-0

 
 

Scheer PAS Schweiz AG
Lautengartenstrasse 12
CH-4052 Basel
Phone +41 61 27097-10
Fax +41 61 27097-11
E-Mail: info@scheer-pas.com

Within the European Union, Scheer PAS Deutschland GmbH (see above) acts as a representative within the meaning of Article 27 GDPR of Scheer PAS Schweiz AG.

What and on what legal basis do we process your data?

We process your personal data for the following purposes on the basis of the following legal bases.

For the fulfillment of contractual obligations

If you are already our customer or if you provide us with your personal data in the course of a business initiation ¬ (e.g. in case of your expressed interest in our services, e.g. at trade fairs), if necessary also want to update data, we process this personal data for the execution of the contractual relationship or for pre-contractual purposes at your instigation according to Art. 6 sec. 1 lit. b GDPR. This includes the use for the purpose of in-depth examination of whether an order can be accepted at all as well as for the purpose of fulfilling mutual open claims. The purposes of data processing are primarily based on your product interest and may also include needs analyses and general advice.

The specific services are to be found in the respective contract documents, terms and conditions and product information. In the case of existing contracts, we may collect additional personal data from you in individual cases. This may be the case, for example, if we advise you regarding a contract adjustment or a service extension, which may make sense to consider the entire customer relationship.

Compliance with legal requirements

We also process your personal data in order to fulfil numerous legal obligations, e.g. in connection with the conduct of the contract. This includes in particular commercial, commercial or tax retention periods, e.g. offers, contracts or invoices. This also includes reporting obligations or possible regulatory and sector-specific requirements. Industry-specific specifications may also have been imposed on us by you in the context of the business relationship. We process your personal data in the event of fulfilment of a legal obligation that we are subject to in accordance with Art. 6 sec. 1 lit. c GDPR. A legal obligation arises, for example, in particular from Paragraph 147 of the German Tax Code [AO].

Legitimate interest

We also process your data in order to protect legitimate interests of us or third parties (e.g. cooperation partners) to the extent permitted by law (Art. 6 sec. 1 lit. f GDPR), if no corresponding consent has been obtained and no legal basis for data processing is apparent and only if the conditions of Article 6 (1) lit. f GDPR are met. Not only are we happy to send you personal communications (e.g. invitations) to provide further information about us or our products and services, but also to invite you to customer surveys, for example, so that we can better understand your needs overall, strengthen the relationship with you and design our products and services according to your requirements. We compile customer or market-specific statistics in order to optimize our service portfolio for you and thus for business management. We also process your personal data in order to potentially assert our rights in the event of a dispute and to enforce our legal claims. Finally, we process your personal data, insofar as this is necessary for the prevention or prosecution of criminal offences, in order to ensure a friction-free IT operation, within the framework of measures of building security (e.g. access control) and to ensure the householder´s rights.

Consent

Insofar as you have given us consent to the processing of your data for specific purposes (e.g. receiving our newsletter), the legality under Newsletter Art. 6 sec. 1 lit. a GDPR. Consent can, of course, be revoked at any time with effect for the future. Please note that if processing has already been initiated, a revocation may only be realized with a time delay and that in individual cases, in particular in connection with information that can be accessed on the Internet, a further withdrawal can hardly be impossible to impossible.

What sources and data categories do we use?

In principle, we process personal data that we receive from you in the course of our business relationship. In addition, if necessary for the provision of our service, we process personal data that we have received legitimately (e.g. credit health requests in connection with the execution of orders) from companies of Scheer PAS or other third parties (e.g. credit reporting agencies). On the other hand, we may also process data that we have legitimately obtained and process from publicly available sources (e.g. commercial registers, press).

We may have collected information about the following categories of data:

  • Personal master data (e.g. name, first name, address data)
  • Contact details (e.g. telephone, e-mail, preferred language, time zone)
  • Information about planned projects as well as your interest in products and services
  • Information about your profession /company (e.g. industry, employment, employer, position, title, department, company address)
  • Order characteristics (e.g. customer number)
  • data from the fulfilment of our contractual obligations (e.g. turnover data in payment transactions),
  • Data on legitimation and authentication
  • Documentation data (e.g. logs)
  • Data in the context of the visit to our website (see the privacy notice on the respective page, e.g. https://www.scheer-pas.com/en/privacy-notice-for-website-visitors/).

Obligation to provide the data

As part of our business relationship, you must provide the personal data necessary for the establishment and execution of our business relationship and the fulfilment of the contractual obligations thereto, or which we are legally obliged to collect.

Without the processing of your related data, we will generally not be able to conclude or execute the contract with you or comply with your request.

Who gets access to your data?

Your personal data will only be made available within our group of companies to the bodies that need it for the fulfilment of the above-mentioned purposes (e.g. marketing, sales, projectstaff, accounting). In principle, your data will not be passed on outside our group of companies. However, other entities may be those to which we are legally obliged to surrender in any way (e.g. public authorities and institutions), to enforce open claims (e.g. lawyers) to which you have given us your consent (e.g. as a reference), or such service providers who necessarily assist us in the provision of services. This can be done, for example, there will be in the categories IT service, certification/auditing, logistics, printing service, archiving, disposal, telecommunications, consulting, debt collection or marketing, provided there is a data protection law. If processors are directly involved in the provision of part of the service subject matter, this shall be done taking into account the requirements of Article 28 GDPR. In no case will we sell your data. In principle, we do not transfer your data to third countries. Since our group of companies also includes companies in third countries or, in order to be competitive, support us service providers with their registered office, parent company or data centre in third countries on a case-by-case basis, it may be necessary for this to be passed on. In such cases, we shall ensure, within our means, that only access is provided to data that is necessary for the performance of the specific task and that appropriate security measures have also been taken (e.g. adequacy decision of the EU Commission, standard contractual clauses, other technical measures).

Your rights

Within the framework of the respective regulations(in particular Articles 15 – 21 GDPR), you have a wide range of rights to the processing of your personal data: right of access, right to rectification, right to erasure, right to restriction of processing and the right to data portability. You also have the right to be subject to a non-exclusively automated individual decision. Finally, you have the right to complain to a competent data protection supervisory authority.

The right of access and the cancellation are subject to legal restrictions. You also have the right to object to the processing of your personal data for direct marketing purposes. If we process your data for the protection of legitimate interests, you may object to this processing if there are reasons for your particular situation that speak against data processing. For more information on the right of objection, see below.

Is there an exclusive automated decision-making process?

Neither full automated decision-making (a decision based on purely automated processing) takes place in accordance with Article 22 GDPR, either in the event of a statement of reasons or for the conduct of the business relationship.

Is profiling taking place?

We process some of your data in a partially automated manner (e.g. click rate in the online area, credit rating, customer management, payment history) with the aim of getting to know and understand you and your needs better. This enables us to communicate and promote in a way that meets needs, including market and opinion research. There is no fully automated profiling.

Period of data storage

Unless you request deletion of the data, it will be stored by us as long as it is required for the purpose for which it was collected. In addition, the storage, in particular if a contractual relationship exists or existed, can be carried out for the fulfilment of commercial and tax retention obligations (e.g. 2 to 10 years) or for the preservation of evidence within the framework of statutory limitation regulations (e.g. up to 30 years).

Information on your right to object under Article 21 GDPR

Case-by-case right to object: You have the right, for reasons arising from your particular situation, to object at any time to the processing of personal data concerning you, which is carried out pursuant to Article 6 (1) lit. f of the GDPR (data processing based on a balance of interests), and this also applies to profiling based on that provision within the meaning of Article 4(4) GDPR, which we use for credit assessment or advertising purposes. If you object, we will no longer process your personal data unless we can prove compelling legitimate grounds for processing that outweigh your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims. Right to object to the processing of data for direct marketing purposes: In individual cases, we process your personal data in order to conduct direct marketing. You have the right to object at any time individually to the processing of personal data concerning you for the purpose of such advertising; this also applies to profiling in so far as it is related to such direct marketing. If you object to the processing for direct marketing purposes, we will no longer process your personal data for these purposes. The objection can be made without form and should be addressed as far as possible to the person responsible above.

Data Protection Officer

You can reach our data protection officer or a contact person for data protection at: datenschutz@scheer-group.com as well as by mail via the address of the responsible person mentioned at the beginning.

Other notes

As the recipient of this information, please inform other persons of your house who are affected by this information. The status of this information is 2022, September. We reserve the right to update this information if necessary.

Privacy notices for participants in online meetings via Microsoft services

Informationen zum Datenschutz

Die EU-Datenschutz-Grundverordnung [DS-GVO] sieht vor, dass Personen deren Daten erhoben werden, zur Gewährleistung einer fairen und transparenten Verarbeitung über den jeweiligen Verarbeitungskontext informiert werden. Mit den nachfolgenden Informationen geben wir Ihnen einen Überblick über die Verarbeitung Ihrer perso­nenbezogenen Daten im Zusammenhang mit der Nutzung von durch uns (vgl. „Wer ist für die Datenverarbeitung verantwortlich?“) veranlasste „Online-Meetings“ wie Telefonkonferenzen, Videomeetings, Chats oder Schulungen/ Webinare mittels Produkten der Microsoft Ireland Operations Ltd. bzw. der Microsoft Corporation (insbesondere „Teams“, nachfolgend: „Tools“).

Bitte beachten Sie, dass Sie diese Information nur über die Verarbeitung Ihrer personenbezogenen Daten durch uns informiert, wenn Sie gemeinsam mit uns Anwendungen von Microsoft auf unsere Veranlassung hin nutzen.

Wer ist für die Datenverarbeitung verantwortlich?

Verantwortlicher im Sinne des Gesetzes ist regelmäßig diejenige Gesellschaft, durch die Sie im unmittelbaren Zusammenhang mit der Durchführung von „Online-Meetings“ eingeladen worden sind. Welche Gesellschaft dies ist, entnehmen Sie bitte den nachfolgenden Angaben:
 

Scheer GmbH

Scheer Tower
Uni-Campus Nord
D-66123 Saarbrücken
Telefon: +49 681 96777-0
E-Mail: info@scheer-group.com

Unseren Datenschutzbeauftragten erreichen Sie postalisch unter der nebenstehenden Adresse mit dem Zusatz „z.Hd. Datenschutzbeauftragter“ oder elektronisch unter: datenschutz<at>scheer-group.com

 

Scheer Austria GmbH

Ernst Melchior Gasse 22
AT-1020 Wien
T +43 1 36 136 00
F +43 1 36 136 00 99

 
 

Scheer Schweiz AG

Industriestrasse 50b
CH-8304 Wallisellen
T +49 681 96 777-0

Innerhalb der Europäischen Union agiert die Scheer GmbH (s.o.) als Vertreter im Sinne des Art. 27 DS-GVO der Scheer Schweiz AG.

 

Scheer PAS Deutschland GmbH

Scheer Tower
Uni-Campus Nord
D-66123 Saarbrücken
Telefon: +49 681 96777-0

 
 

Scheer PAS Schweiz AG

Lautengartenstrasse 12
CH-4052 Basel
T +41 61 27097-10
F +41 61 27097-11
E-Mail: info@scheer-pas.com

Innerhalb der Europäischen Union agiert die Scheer PAS Deutschland GmbH (s.o.) als Vertreter im Sinne des Art. 27 DS-GVO der Scheer E2E Schweiz AG.

Hinweise

Vertragspartner der Microsoft Ireland Operations Ltd. ist, unabhängig von welchem Unternehmen der Scheer Gruppe Sie zu einem Online-Meeting eingeladen werden, die Scheer GmbH. Diese erbringt ebenso einen Großteil der infrastrukturellen Leistungen, die unsererseits zur Durchführung von Online-Meetings erforderlich sind.
Soweit Sie die Internetseite von Microsoft aufrufen, ist der Anbieter von „Microsoft Teams“ für die Datenverarbeitung verantwortlich. Ein Aufruf der Internetseite ist für die Nutzung von „Microsoft Teams“ jedoch nur erforderlich, um sich die Software für die Nutzung von „Microsoft Teams“ herunterzuladen. Wenn Sie die „Microsoft Teams“-App nicht nutzen wollen oder können, können Sie „Microsoft Teams“ auch über Ihren Browser nutzen. Der Dienst wird dann insoweit auch über die Website von „Microsoft Teams“ erbracht.

Wofür und auf welcher Rechtsgrundlage verarbeiten wir Ihre Daten?

Wir nutzen die Tools, um die Kommunikation und Zusammenarbeit von Menschen über Telefonkonferenzen, Videokonferenzen, Online-Treffen, Chats und/oder Schulungen/Webinare durchzuführen. Die Tools sind Services der Microsoft Ireland Operations Ltd. (Irland) bzw. der Microsoft Corporation (USA). Die Rechtsgrundlage unterscheidet sich, je nachdem wer daran teilnimmt.
Soweit personenbezogene Daten von Beschäftigten der Scheer GmbH oder eines Unternehmens der Scheer Gruppe in Deutschland verarbeitet werden (inkl. sich Bewerbende), ist § 26 BDSG die Rechtsgrundlage für die Datenverarbeitung. Für unsere Gesellschaften außerhalb der Bundesrepublik Deutschland gelten, sofern vorhanden, die dortigen landesspezifischen Datenschutzregelungen zum Beschäftigtendatenschutz, hilfsweise die Bestimmungen der DS-GVO.
Für weitere Teilnehmende an „Online-Meetings“ ist, soweit diese im Rahmen von Vertragsbeziehungen zu den Betroffenen durchgeführt werden, Art. 6 Abs. 1 lit. b) DS-GVO die Rechtsgrundlage für die Datenverarbeitung.
Sollten keine vertraglichen Beziehungen zwischen Verantwortlichem und betroffener Person bestehen oder Dritte teilnehmen, ist die Rechtsgrundlage Art. 6 Abs. 1 lit. f) DS-GVO. Dies ist insbesondere dann der Fall, wenn eine Verarbeitung elementarer Bestandteil der Toolnutzung ist oder die Verarbeitung auf einer geschäftlichen oder behördlichen Zusammenarbeit (inkl. Anbahnung) der Beteiligten beruht, wobei hier unser Interesse an der effektiven Durchführung von „Online-Meetings“ besteht.

Welche Daten werden verarbeitet und in welchem Umfang?

Bei der Nutzung der Tools werden verschiedene Datenarten verarbeitet. Der Umfang der Daten hängt dabei auch
davon ab, welche Angaben zu Daten Sie vor bzw. während der Teilnahme an einem „Online-Meeting“ machen.

Folgende personenbezogene Daten sind Gegenstand der Verarbeitung:

Angaben zum Benutzer: z.B. Anzeigename („Display name“), Vorname, Nachname, Telefon (optional), E-Mail-
Adresse, Profilbild (optional), Abteilung (optional), bevorzugte Sprache

Meeting-Metadaten: z.B. Datum, Uhrzeit, Thema, Statusangabe, Teilnehmer-IP-Adresse, Meeting-ID, Ort,
Geräte-/ Hardware-Informationen

Bei Aufzeichnungen (optional): MP4-Datei der Video-, Audio- und Präsentationsaufnahmen, M4A-Datei aller
Audioaufnahmen, Textdatei des Online-Meeting-Chats.

Bei Einwahl mit dem Telefon: Angabe zur eingehenden und ausgehenden Rufnummer, Ländername, Start- und
Endzeit. Ggf. können weitere Verbindungsdaten wie z.B. die IP-Adresse des Geräts gespeichert werden.

Text-, Audio- und Videodaten: Sie haben ggf. die Möglichkeit, in einem „Online-Meeting“ die Chat-, Fragenoder
Umfragefunktionen zu nutzen. Insoweit werden die von Ihnen gemachten Texteingaben verarbeitet, um
diese im „Online-Meeting“ anzuzeigen und ggf. zu protokollieren. Um die Anzeige von Video und die Wiedergabe
von Audio zu ermöglichen, werden entsprechend während der Dauer des Meetings die Daten vom Mikrofon Ihres
Endgeräts sowie von einer etwaigen Videokamera des Endgeräts verarbeitet. Sie können die Kamera oder das
Mikrofon jederzeit selbst über die Tool-Applikationen abschalten bzw. stummstellen.

Um an einem „Online-Meeting“ teilzunehmen bzw. den „Meeting-Raum“ zu betreten, müssen Sie zumindest
Angaben zu Ihrem Namen bzw. Anzeigenamen machen.

Umfang der Verarbeitung

Wir verwenden die Tools, um „Online-Meetings“ durchzuführen. Wenn wir „Online-Meetings“ aufzeichnen wollen,
werden wir Ihnen das im Vorwege transparent mitteilen und – soweit erforderlich – um eine Zustimmung bitten.
Die Tatsache der Aufzeichnung wird Ihnen zudem im Tool angezeigt.

Wenn es für die Zwecke der Protokollierung von Ergebnissen eines „Online-Meetings“ erforderlich ist, werden wir
die Chatinhalte protokollieren. Das wird jedoch in der Regel nicht der Fall sein. Im Falle von Webinaren können
wir für Zwecke der Aufzeichnung und Nachbereitung von Webinaren auch die gestellten Fragen von Webinar-
Teilnehmenden verarbeiten.

Wenn Sie bei Microsoft für die Tools als Benutzer registriert sind, dann können Berichte über „Online-Meetings“
(Meeting-Metadaten, Daten zur Telefoneinwahl, Fragen und Antworten in Webinaren, Umfragefunktion in
Webinaren) ggf. bei Microsoft gespeichert werden.

Die in „Online-Meeting“-Tools bestehende Möglichkeit einer softwareseitigen Aufmerksamkeitsüberwachung ist
unsererseits deaktiviert. Eine automatisierte Entscheidungsfindung i.S.d. Art. 22 DS-GVO findet unsererseits nicht
statt.

Schließlich verarbeiten wir Ihre personenbezogenen Daten, soweit dies zur Abwehr oder Verfolgung von Straftaten
erforderlich ist, zur Gewährleistung eines reibungsfreien IT-Betriebes, im Rahmen von Maßnahmen der
Gebäudesicherheit (z.B. Zutrittskontrolle) und zur Sicherstellung des Hausrechts.

Wer erhält Zugriff auf Ihre Daten?

Personenbezogene Daten, die im Zusammenhang mit der Teilnahme an „Online-Meetings“ verarbeitet werden, sind grundsätzlich den Teilnehmern am jeweiligen Online-Meeting bekannt. So werden Video-, Bild-, Ton- und/oder Fotoaufnahmen der Teilnehmenden einer Videokonferenz sowie ggfls. Unterlagen zu den Inhalten, freigegebene Bildschirme sowie Teilnehmerlisten und Chats den Teilnehmenden der Webkonferenz offenbar.
Des Weiteren werden Daten innerhalb unserer Unternehmensgruppe nur den Stellen zugänglich gemacht, die diese zur Erfüllung vorstehend genannter Zwecke benötigen (z.B. Marketing, Vertrieb, Projektmitarbeiter, Buchhaltung zur Abrechnung, IT zum sicheren Betrieb der Infrastruktur). Bitte beachten Sie jedoch, dass die Inhalte von Online-Meetings häufig zur Weitergabe an Kunden, Interessenten oder Dritte bestimmt sind.
Weitere Empfänger könnten auch diejenigen sein, gegenüber denen wir in irgendeiner Art gesetzlich zur Herausgabe verpflichtet sind (z.B. öffentliche Stellen und Institutionen), zur Durchsetzung offener Forderungen (z.B. Rechtsanwalt), zu denen Sie uns Ihre Einwilligung erteilt haben (z.B. als Referenz), oder solche Dienstleister, die uns bei der Leistungserbringung notwendigerweise unterstützen, wie etwa der Anbieter des jeweiligen Tools zum „Online-Meeting“. Wir haben mit Anbietern die im Rahmen einer Auftragsverarbeitung für uns tätig sind einen Auftragsverarbeitungsvertrag geschlossen, der den Anforderungen von Art. 28 DS-GVO entspricht.
Eine technische Datenverarbeitung außerhalb der Europäischen Union [EU] erfolgt insofern grundsätzlich nicht, dass wir im Rahmen unserer Möglichkeiten den Speicherort auf Rechenzentren in der Europäischen Union beschränkt haben. Wir können aber nicht ausschließen, dass das Routing von Daten über Internetserver erfolgt, die sich außerhalb der EU befinden. Dies kann insbesondere dann der Fall sein, wenn sich Teilnehmende am „Online-Meeting“ in einem Drittland aufhalten. Keinen Einfluss haben wir zudem auf die systemseitige Verarbeitung technischer Informationen wie Geräte-/Hardware-Informationen (z.B. IP-Adresse, Betriebssystemdaten des Endgeräts sowie Zeitpunkt und Datum des Zugriffs) durch den Diensteanbieter.
Da zu unserer Unternehmensgruppe auch Gesellschaften in Drittstaaten (z.B. Schweiz) gehören oder uns Dienstleister (z.B. Microsoft) mit Firmensitz, Konzernmutter oder einem Rechenzentrum in Drittstaaten fallweise unterstützen, kann hierbei eine Weitergabe leider nicht ausgeschlossen werden. In solchen Fällen stellen wir im Rahmen unserer Möglichkeiten sicher, dass nur Zugriff auf solche Daten erfolgt, die für das Erbringen der konkreten Aufgabe erforderlich sind und zudem entsprechende Sicherheitsmaßnahmen (z.B. Angemessenheitsbeschluss der EU-Kommission, EU-Standardvertragsklauseln) getroffen sind.
Das Datenschutzniveau wird gegenüber Microsoft durch den Abschluss von ergänzten EU-Standard-datenschutzklauseln und technisch-organisatorischer Maßnahmen gewährleistet. Unter anderem dadurch, dass Daten während des Transports über das Internet transportverschlüsselt sind und vor einer Offenlegung gegenüber Dritter generell geschützt sind. Im Hinblick auf personenbezogene Daten, die durch Microsoft in den USA und Europa gespeichert werden und ggf. behördlichen Auskunftsersuchen von Behörden in den USA unterliegen können, garantiert Microsoft in einer Stellungnahme vom 20. Juli 2020, dass solche Verfügungen vor Gericht angefochten werden, mit denen der Zugang zu personenbezogenen Daten möglich wäre. Darüber hinaus hat Microsoft im Rahmen eines rechtlichen Vergleichs das Recht erworben, transparente Berichte über die Anzahl der an Microsoft gerichteten amerikanischen Anweisungen zur nationalen Sicherheit offen zu legen, des Weiteren wurden neue Richtlinien innerhalb der US-Regierung eingeführt, welche die Verwendung von Geheimhaltungsanweisungen eingeschränkt haben (Vgl. https://news.microsoft.com/de-de/stellungnahme-zum-urteil-des-eugh-was-wir-unseren-kunden-zum-grenzueberschreitenden-datentransfer-bestaetigen-koennen/). Das Datenschutzniveau wird gemessen an den voraussichtlichen Inhalten der Online-Meetings als ausreichend angesehen.
Weitere Informationen von Microsoft (Stand September 2021) finden Sie u.a. hier:
https://privacy.microsoft.com/de-de/privacystatement
https://www.microsoft.com/de-de/trust-center/privacy/gdpr-overview
https://news.microsoft.com/de-de/datenschutz-und-sicherheit-in-microsoft-teams-nutzer/
https://news.microsoft.com/de-de/stellungnahme-zum-vermerk-berliner-datenschutzbeauftragte-zur-durchfuehrung-von-videokonferenzen-waehrend-der-kontaktbeschraenkungen/
https://news.microsoft.com/de-de/neue-massnahmen-zum-schutz-von-daten/
Microsofts Blog-Reihe „Im Daten-Dschungel“:
https://news.microsoft.com/de-de/im-daten-dschungel-datenschutz-von-a-bis-z/
https://news.microsoft.com/de-de/im-daten-dschungel-nach-welchen-regeln-wir-daten-verarbeiten/
https://news.microsoft.com/de-de/im-daten-dschungel-ende-zu-ende-verschluesselung-in-microsoft-teams/
Weiterführende Hinweise zur Datensicherheit und zum Datenschutz bei Microsoft Teams finden Sie hier: https://www.microsoft.com/en-us/microsoft-365/blog/2020/04/06/microsofts-commitment-privacy-security-microsoft-teams/

Ihre Rechte

Wir löschen personenbezogene Daten grundsätzlich dann, wenn kein Erfordernis für eine weitere Speicherung mehr besteht. Ein Erfordernis kann insbesondere dann bestehen, wenn die Daten noch benötigt werden, um vertragliche Leistungen zu erfüllen, Gewährleistungs- und ggf. Garantieansprüche prüfen und gewähren oder abwehren zu können. Im Falle von gesetzlichen Aufbewahrungspflichten kommt eine Löschung erst nach Ablauf der jeweiligen Aufbewahrungspflicht in Betracht.

Zeitraum der Datenspeicherung

Sie haben im Rahmen der jeweiligen Regelungen vielfältige Rechte in Bezug auf die Verarbeitung Ihrer personenbezogenen Daten:
Sie haben das Recht auf Auskunft über die Sie betreffenden personenbezogenen Daten. Sie können sich diesbezüglich jederzeit an uns wenden. Bei einer Auskunftsanfrage, die nicht schriftlich erfolgt, bitten wir um Verständnis dafür, dass wir ggf. Nachweise von Ihnen verlangen die belegen, dass Sie die Person sind, für die Sie sich ausgeben. Ferner haben Sie ein Recht auf Berichtigung oder Löschung oder auf Einschränkung der Verarbeitung, soweit Ihnen dies gesetzlich zusteht. Überdies haben Sie ein Widerspruchsrecht gegen die Verarbeitung sowie auf Datenübertragbarkeit jeweils im Rahmen der gesetzlichen Vorgaben. Und schließlich haben Sie das Recht, sich bei einer zuständigen Datenschutzaufsichtsbehörde zu beschweren.

Datenschutzbeauftragte

Unseren Datenschutzbeauftragten bzw. einen Ansprechpartner zum Datenschutz erreichen Sie unter: datenschutz<at>scheer-group.com sowie postalisch über die zu Beginn genannte Anschrift des Verantwortlichen.

Sonstige Hinweise

Bitte informieren Sie als Empfänger dieser Information entsprechende weitere hiervon betroffene Personen Ihres Hauses, sofern diese an unseren Diensten zur Kommunikation und Kollaboration über unsere Tools teilnehmen. Stand dieser Information ist September 2021. Wir behalten uns vor, diese Information bei Bedarf zu aktualisieren. Sie können zudem jederzeit eine aktuelle Fassung bei uns anfordern.

Privacy notice for the whistleblower system

Information about data security

In the following, we provide information pursuant to Art. 13 of the General Data Protection Regulation (GDPR) on how the Scheer Group company named below processes personal data as part of the reporting system and on the associated data protection regulations, claims and rights.

The Scheer Group uses web-based software, a cloud solution hosted in Germany, to help detect operational irregularities. By introducing such a system, criminal, illegal, morally reprehensible or unfair activities can be detected and prevented at an early stage and incalculable material and immaterial damage as well as loss of reputation can be averted.

Who is responsible for the processing ?

Controller within the meaning of Art. 4 No. 7 GDPR is generally the company to which you submit a report. You make this selection yourself, e.g. by specifying in the system to which company you are sending your report. Information on the respective Controller can be found below:

 

IDS Scheer Holding GmbH

Uni-Campus Nord
D-66123 Saarbrücken
Phone: +49 681 96777-0
E-Mail: info@scheer-group.com

Scheer GmbH

Uni-Campus Nord
D-66123 Saarbrücken
Phone: +49 681 96777-0
E-Mail: info@scheer-group.com

 

Scheer Austria GmbH

Ernst Melchior Gasse 22
AT-1020 Vienna Phone: +43 1 36 136 00
E-Mail: info@scheer-group.com

Scheer PAS Germany GmbH

Scheer Tower
Uni-Campus Nord
D-66123 Saarbrücken
Phone: +49 681 96777-0
E-Mail: info@scheer-pas.com

 

Scheer Adriatic d.o.o. (HRV)

Matrix Office Park
Slavonska avenija 1B (Building B, 6th floor)
HR-10000 Zagreb
E-Mail: info@scheer-group.com

 

Data Protection Officer

If you have any questions about data protection, please contact the Privacy Team at the above address of IDS Scheer Holding GmbH with the addition “Attn: Data Protection” or electronically at: datenschutz@scheer-group.com.

For what purposes do we process the data?

The respective Scheer Group Controller processes the personal data of the reporting person, unless the report was submitted anonymously, as well as the personal data of the accused person(s), such as name and other communication and content data, for the purpose of investigating the reports in order to prevent violations of applicable law or company policies, detect and/or take follow-up action (such as measures to verify the validity of the allegations made in the report and, where appropriate, to address the reported violation, including through internal investigations, inquiries, prosecutions, measures to (re)recover funds or close the case).

On what legal basis do we process the data?

The collection of the reporting person’s personal data in the case of a non-anonymous report is based on consent to the processing through the transmission of the data (implied consent) (Art. 6 para. 1 sentence 1 lit. a GDPR).

The collection, processing and disclosure of personal data of the persons named in the notification serves to safeguard the legitimate interests of the above-mentioned Controller (Art. 6 para. 1 sentence 1 lit. f GDPR). It is a legitimate interest of the company to detect, process, remedy and sanction violations of the law and serious breaches of duty by employees effectively and with a high degree of confidentiality and to avert associated damage and liability risks for companies (Sections 30, 130 Federal Act on Regulatory Offences). Directive (EU) 2019/1937 (“EU Whistleblower Directive”) and the Whistleblower Protection Act in Germany also require the establishment of a reporting system in order to give employees and third parties the opportunity to report legal violations in the company in a protected manner.

The disclosure of personal data in the case of non-anonymous reporting to other recipients (Art. 4 No. 7 GDPR) may be necessary due to a legal obligation (Art. 6 para. 1 sentence 1 lit. c GDPR).

The processing of personal data of employees (for Controllers within the scope of the Federal Data Protection Act – BDSG) is carried out on the basis of Section 26 (1) sentence 2 BDSG. According to this, personal data of employees within the meaning of Section 26 (8) BDSG may be processed to uncover criminal offenses if there are factual indications to be documented that justify the suspicion that the person concerned has committed a criminal offense in the employment relationship, the processing is necessary for detection and the employee’s legitimate interest in the exclusion of processing does not outweigh this, in particular the type and extent are not disproportionate with regard to the reason.

What categories of data are processed?

Basically, we process personal data that we receive directly as part of a report. This may include:

  1. Information about the reporting person (unless he/she wishes to remain anonymous) and the accused person(s), such as
  • First and last name
  • Contact details
  • Other personal data relating to the employment relationship, if applicable
  1. Personal information, such as data subjects identified in a report as a person alleged to have engaged in misconduct and identified in the investigation, including details of the allegations made and supporting evidence.
  2. Date and time of the calls (when the message is received by telephone)
  3. Any other information identified in the investigation results and in any further proceedings, e.g. information on criminal conduct or data on unlawful or improper conduct, insofar as this has been reported.
  4. Information about violations that may also allow conclusions to be drawn about a natural person.

Who has access to the personal data?

Personal data collected via the web-based software is only made accessible to those persons who have a legitimate need to process this data due to their function. If the report is received via the telephone hotline, the report will be recorded in the reporting system while preserving the anonymity of the reporting person.

We have commissioned a neutral Compliance Ombudsperson to receive and qualify a report: THS Treuhand Saar Compliance GmbH, Feldmannstraße 103, 66119 Saarbrücken, Germany.

The latter operates our internal reporting office on our behalf with the aid of a web-based application from lawcode GmbH, Universitätsstraße 3, 56070 Koblenz, Germany.

Depending on the focus of responsibility of the report and for the effective initiation of follow-up measures, the personal data required as part of the report may be passed on to the responsible internal specialist departments.

In some cases, the Controller is obliged to disclose the data to authorities (such as those with legal or regulatory jurisdiction over the employer, law enforcement authorities and legal bodies) or external advisors (such as auditors, accountants, lawyers).

If the reporting person has provided their own name or other personal data (non-anonymous reporting), their identity will not be disclosed – as far as legally possible – and it will also be ensured that no conclusions can be drawn about the identity of the reporting person.

If personal data is processed by external service providers, this is always done based on order processing contracts in accordance with Art. 28 GDPR. In these cases, we ensure that the processing of personal data is carried out in accordance with the provisions of the GDPR and that all persons authorized to process personal data have undertaken to maintain confidentiality or are subject to an appropriate statutory duty of confidentiality.

Your rights as a data subject

Within the framework of the respective regulations (in particular Art. 15-21 GDPR), you have various rights with regard to the processing of your personal data:

  • Right to information,
  • Right to rectification,
  • Right to erasure,
  • Right to restriction of processing
  • Right to data portability.
  • You also have the right not to be subject to an exclusively automated individual decision.
  • Right to lodge a complaint with a competent data protection supervisory authority.

The right to information and the right to erasure are subject to legal restrictions. If we process your data to protect legitimate interests, you can object to this processing if your particular situation gives rise to reasons that speak against data processing.

In accordance with Art. 7 GDPR, you have the right to withdraw your consent to data processing at any time. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

Further information on the right to object can be found below.

Is there an exclusive automated decision-making process?

No.

Does profiling take place?

No.

Duration of data storage

The personal data will be stored in the respective procedure for as long as required for the clarification and final assessment, a legitimate interest of the company or a legal requirement exists. This data is then deleted in accordance with legal requirements. The duration of storage depends in particular on the severity of the suspicion and any reported breaches of duty.

Personal data in connection with reports will be deleted immediately by the Compliance Ombudsperson if they are deemed to be manifestly unfounded.

Right to object pursuant to Art. 21 GDPR

Pursuant to Art. 21 GDPR, you have the right to object to the processing of your personal data on grounds relating to your particular situation. Your personal data will then no longer be processed unless the Controller demonstrates compelling legitimate reasons for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defense of legal claims.

The objection can be made informally and should, if possible, be addressed to the above-mentioned Controller or its internal reporting office.

Information pursuant to Art. 13 para. 2 lit. e GDPR

The provision of data via a notification is neither contractually required nor necessary for the conclusion of a contract. Depending on the individual case, there may be legal obligations to provide us with a report. However, it is necessary to process the data in order to process and investigate the report appropriately.

Other notes

We reserve the right to update this data protection notice if necessary.

 

Status: December 2023