Privacy Policy of wdp GmbH

The requirements of the EU General Data Protection Regulation (hereinafter GDPR) apply throughout Europe. We guide you through our processing of personal data in accordance with this Regulation (see Articles 13 and 14 GDPR). If you have any questions or comments about this privacy statement, you can address them to the e-mail address indicated under points I.2. and I.3. below.

Contents:

I. Overview

  1. Scope
  2. Responsibility
  3. Data Protection Officer

II. Data processing in detail

  1. General information about data processing
  2. Visiting/opening the website/application
  3. Newsletter
  4. Applicants
  5. Tracking

III. Rights of data subjects

  1. Right to object
  2. Right to information
  3. Right of rectification
  4. Right to deletion (“right to be forgotten”)
  5. Right to restriction of processing
  6. Right to data portability
  7. Right to withdrawal after given consent
  8. Right of appeal

IV. Glossary

I. Overview

In this section of the privacy policy you will find information on the scope, the data controller (i.e. the body responsible for data processing described below) and our data protection officer.

Specifically, you will find information on the following questions:

  • What kind of personal data do we collect?
  • What do we do with the data collected?
  • What rights do you have under the applicable data protection law?
  • Who can you contact if you have any questions?

1. Scope

The data processing by wdp GmbH can essentially be divided into two categories:

  • For the purpose of recruiting staff we process personal data of applicants in order to determine whether or not to hire these person. In case external service providers are involved in this process, e.g. form providers or storage service providers, your data will, to the extent required, be passed on and encrypted and stored.
  • By visiting/opening the website/application of wdp GmbH, various information is exchanged between your device and our server. This information may also contain personal data. The information collected in this way will be used among other things to optimize our website or to display advertisements in the browser of your device. In addition to visiting our website, we may also contact you via post / telephone as a customer or potential customer.

This Privacy Policy applies to the following items:

  • our online offer is available at www.wdp.de; or jobs.wdp.de or analytics.wdp.de
  • If one of our presences (such as websites, subdomains, mobile applications, web services, or third-party affiliations) refers you to this privacy policy, regardless of the way in which you access or use it.

All these online presences are collectively referred to as “Services”.

2. Responsibility

Data Controller – ie the one who decides on purposes and means of processing personal data – in relation to the Services is

wdp GmbH – one of the leading strategy and implementation consultancies for digital business models and digital transformation. Both on a strategic and operational level, we assist our customers in digitizing their value creation, their products, their processes, in M ​​& A processes as well as in a possible reorganization.

Contact address of wdp GmbH:

wdp GmbH
Friesenwall 5-7
50672 Köln
kontakt@wdp.de
+49 (0) 221 677 874 10

3. Data Protection Officer

You can contact our data protection officer as follows:

Contact form
https://www.dsextern.de/anfragen

DS EXTERN GmbH
Dipl.-Kfm. Marc Althaus
Frapanweg 22
D-22589 Hamburg

II. Data processing in detail

In this section of the privacy policy, we will inform you in detail about the processing of personal data as part of our services. For better clarity, we divide this information by certain functionalities of our services. During the normal use of the services, different functionalities and thus also different processing operations may be used successively or simultaneously.

1. General information about data processing

For all processing operations described below, unless stated otherwise:

a. No obligation to provide

There is no contractual or legal obligation to provide personal data. You are not required to provide data.

b. Consequences of non-provision

In the case of required data (data which are marked as obligatory when entering data), non-provisioning means that the service concerned cannot be provided. Otherwise, non-provisioning may mean that our services cannot be provided in the same form and quality.

c. Consent

In some cases, you may also give us your consent to further processing in connection with the processing described below (possibly for some of the data). In this case, we will separately inform you in connection with the submission of the respective declaration of consent of all modalities and the scope of the consent and the purposes that we pursue with these processing operations.

d. Transfer of personal data to third countries

When we send data to third countries, meaning countries outside the European Union, then the transfer takes place in compliance with the statutory requirements.

These admissibility requirements are stipulated by Art. 44-49 GDPR.

e. Hosting with external service providers

Our data processing takes to a large extent place with the involvement of so-called hosting service providers, who provide us with storage space and processing capacities in their data centers and, according to our instructions, also process personal data on our behalf. These service providers process data either exclusively in the EU or we have guaranteed an appropriate level of data protection using EU standard contractual clauses.

f. Transmission to state authorities

We transfer personal data to governmental authorities (including law enforcement agencies) when required to fulfill a legal obligation to which we are subject (legal basis: Art. 6 (1) (c) GDPR) or to assert, exercise or defend legal claims (legal basis Art. 6 para. 1 f) GDPR).

g. Storage time

We do not store your data longer than we need for the respective processing purposes. If the data is no longer required for the fulfillment of contractual or legal obligations, these data will be deleted on a regular basis, unless their temporary storage is still necessary. Reasons for this may e.g. be the following:

  • The fulfillment of commercial and tax retention requirements
  • The receipt of evidence for legal disputes within the framework of the statutory limitation regulations

It is possible for us to store your data further with us, if you have expressly given your consent.

h. Categories of recipients

In addition to the categories of recipients listed below, personal data are also transmitted to the following categories of recipients: shipping service providers, telephone and fax providers.

i. Data categories

  • Account data:
    Login / user ID and password
  • Personal master data:
    Title, salutation, gender, first name, last name, date of birth
  • Address data:
    Street, house number, if necessary adress extension, zip code, city, country
  • Contact details:
    Telephone number(s), fax number(s), e-mail address(es)
  • Credentials:
    Information from the service you have signed up for; date and technical information on registration, confirmation and deregistration; data you specified at registration
  • Access data:
    Date and time of the visit of our service; the page from which the accessing system came to our site; pages accessed during use; Session identification data; and the following information about the accessing computer system: Internet Protocol address (IP address), browser type and version, device type, operating system and similar technical information.
  • Application data:
    Curriculum vitae, certificates, evidence, work samples, certificates, pictures

2. Visiting/opening the website/application

Here’s how we process your personal information when you visit our services. In particular, we point out that the transmission of access data to external content providers (see b.) is inevitable due to the technical functioning of information transmission on the internet.

a. Information about processing

Data CategoryPurpose Legal basisLegitimate interestStorage period
Access dataconnection establishment, presentation of the contents of the service, detection of attacks on our side based on unusual activities, fault diagnosisArt. 6 para. 1 f) GDPRproper function of the services, security of data and business processes, prevention of abuse, prevention of damage by interference with Information systems7 days

b. Recipient of personal data

Recipient categoryData concernedLegal basis of the transfer
IT security service provideraccess dataorder processing (Art. 28 GDPR)

c. External content providers submitting to third countries

Title of the serviceFunctionality Data transfer to third country?Appropriateness decision (Article 45 GDPR)Suitable guarantees (Art. 46 GDPR)
Google MapsIntegration for directionsyesEU-U.S. Privacy Shield

https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active

Facebooklink to Facebook pageyesEU-U.S. Privacy Shield

https://www.privacyshield.gov/participant?id=a2zt0000000GnywAAC&status=Active

MyFontsembedding fontsyes

3. Newsletter

This happens to your personal data in connection with a subscription to our newsletter:

a. Information about processing

Data CategoryPurposeLegal basisLegitimate interestStorage period
E-mail-addressVerification of the application (double-opt-in procedure), sending of the newsletterArt. 6 (1) (a) GDPRDuration of the newsletter subscription
User profile data NewsletterInterest-oriented design of the newsletterArt. 6 (1) (f) GDPRImprovement of our service, advertising purposesDuration of the newsletter subscription

b. Recipient of personal data

Recipient categoryData concernedLegal basis of the transfer
Service provider for newsletter distributionall data mentioned under a.order processing (Art. 28 GDPR)

4. Application

In an ongoing application process, we process your personal data in the following ways:

a. Information about processing

Data CategoryPurposeLegal basisLegitimate interestStorage period
Address data, contact detailsIdentification, establishment of contact, communication for the initiation of a contractArt. 6 para. 1 b) GDPRNecessity for contact as well as matching of application documents6 months
Personal master dataIdentification, establishment of contact, age verification Art. 6 para. 1 b) GDPRNecessity for contact as well as matching of application documents6 months
Application dataApplicant selectionArt. 6 para. 1 b) GDPRNecessity for objective selection6 months

b. Recipient of personal data

Recipient categoryData concernedLegal basis of the transfer
Online form service

Formstack Inc.
8604 Allisonville Rd., Ste. 300
Indianapolis, IN 46250
USA

Address and contact dataOrder processing (Art. 28 GDPR) and EU-U.S. Privacy Shield
Cloud storage service

Egnyte Inc.
1350 W. Middlefield Road
Mountain View, CA 94043
USA

all data cited under a., encrypted filedOrder processing (Art. 28 GDPR) and EU-U.S. Privacy Shield
Online Task Management

Asana Inc.
1550 Bryant Street, 8th Floor
San Francisco, CA 94103
USA

all data cited under a.Order processing (Art. 28 GDPR) and EU-U.S. Privacy Shield

5. Tracking

Below we describe how your personal information is processed using tracking technologies to analyze and optimize our services and for promotional purposes.

The description of the tracking methods also includes information on how to prevent or object to the processing of data. Please note that the so-called “opt-out”, ie the rejection of processing, is usually stored via cookies. If you use our services via a new device or in another browser, or if you have deleted the cookies set by your browser, you need to carry out the opt-out-process again.

The tracking methods described below process personal data only in pseudonymous form. A connection with a specific, identified natural person, ie a combination of the data with information about the carrier of the pseudonym, does not take place.

Tracking to analyze and optimize our services and their use, as well as measuring the success of advertising campaigns and optimizing advertising

a. Purposes of processing

Data processing and analysis for marketing purposes

Your individual needs are important to us and we try to give you information about our services that suit you. In order to do so we use findings from our business relationship with you, your usage behavior on wdp.de or from market research and opinion polls.

The main objective of the processing of your data is the relevant communication in the context of advertisements. Through the structured collection and processing of the data, we specify our marketing and minimize the appearance of inappropriate advertising to you and third parties.

We guarantee that we process your personal data (as far as legally possible) in accordance with the provisions of applicable data protection law.

Please note: You can object to the use of your personal data for these purposes at any time.

E-mail or print direct mail

We will send you letters or emails with a personal address and content to your business contact information. You have the right to object to this personalized advertising at any time.

Measures for your safety:

  • To ensure IT security
  • In order to be able to understand and prove facts in case of legal disputes

b. Legal basis of processing

Legitimate interest in accordance with Art. 6 para. 1 f) of the GDPR

c. The tracking methods used in detail

Name of serviceService ProviderFunctionality Possibility to prevent processing (opt-out)Data transfer to third country?Appropriateness resolution (Article 45 GDPR)suitable guarantees (Art. 46 GDPR)
Google Analytics with anonymization functionGoogle Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043 USAWeb Analytics & Remarketing

Google Analytics uses so-called “cookies”, text files that are stored on your computer and thereby allow an analysis of the use of the website by you.
The information generated by these cookies, such as the time, location and frequency of your website visit, including your IP address, is transmitted to Google in the United States and stored there.
We use Google Analytics on our website with an IP anonymization feature. In this case, your IP address will already be shortened and thus anonymised by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area.
Google will use this information to evaluate your use of our site, to compile reports on our website activity, and to provide other services related to website activity and internet usage. Google may also transfer this information to third parties if required by law or as far as third parties process this data on behalf of Google.

tools.google.com/dlpage/gaoptout?hl=de)

OptOut Google Analytics

Nohttps://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active
Google AdwordsGoogle Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043 USAConversion Tracking

The information obtained by means of the “Conversion Cookies” is used by Google to create visitor statistics for our web site. These statistics tell us the total number of users who clicked on our ad, and which pages on our site were subsequently accessed by their respective users. However, we or others through “Google Adwords” advertisers do not receive any information that personally identifies users.

http://www.google.com/settings/adsYeshttps://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active
Google RemarketingGoogle Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043 USARemarketing

Google Remarketing can show ads to people who have already visited our website in the past. Within the Google ad network, advertisements tailored to their interests can be displayed on our site.

http://www.google.com/settings/adsYeshttps://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active
Google Tag ManagerGoogle Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043 USATag Management

With the Google Tag Manager, the here mentioned Trackers are flexibly turned on / off.

https://www.google.com/analytics/tag-manager/use-policy/

OptOut Google Tag Manager

Yeshttps://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active
Facebook PixelFacebook Inc., 1601 S. Califor-nia Ave, Palo Alto, CA 94304, USAWeb Analytics & Remarketing

Each time you visit our website that has such a component, this component causes the browser you are using to download a corresponding representation of the Facebook component. Through this process, Facebook is informed about which specific page of our website is being visited by you.
If you visit our site and are logged in to Facebook, Facebook recognizes through the information collected by the component, which specific page you visit and assigns this information to your personal account on Facebook.

OptOut FacebookYeshttps://www.privacyshield.gov/participant?id=a2zt0000000GnywAAC&status=Active
Facebook Custom AudiencesFacebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USARemarketing & Social Media Analyse

We use personal contact information from you to find you on Facebook about so-called Custom Audiences.

OptOut FacebookYeshttps://www.privacyshield.gov/participant?id=a2zt0000000GnywAAC&status=Active
OutbrainOutbrain Inc., 39 W 13th Street New York, NY 10011 USARemarketing

Diese ermöglicht es, auf Websites unserer Partner gezielt jene Internet User mit Werbung anzusprechen, die sich bereits für unsere Angebote interessiert haben bzw. Daten darüber zu erheben. Die Technologie hängt von einer cookiebasierten Analyse des Benutzerverhaltens ab. Diese Werbung erscheint nur auf Outbrain Werbeplätzen, entweder auf Werbeflächen von Outbrain Engage oder dem Outbrain Extended Network.

OptOut OutbrainYes
LinkedIn-Komponenten / Linkedin-PixelLinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USARemarketing & Social Media Analyse

This makes it possible to specifically target those Internet users with advertising on websites of our partners who are already interested in our offers or to collect data about them. The technology depends on a cookie-based analysis of user behavior. This ad only appears on Outbrain commercials, either on Outbrain Engage’s ad space or the Outbrain Extended Network.

OptOut LinkedInYeshttps://www.privacyshield.gov/participant?id=a2zt0000000L0UZAA0
MyFonts CounterMyFonts Inc., 500 Unicorn Park Drive, Woburn, MA 01801, USAMyFonts obliges wdp GmbH to use the MyFonts Counter to properly account for the calculation of annual license fees for the use of protected fonts on wdp.de. To prevent the execution of Java Script code from MyFonts altogether, you can install a Java Script Blocker (for example, www.noscript.net). Further information on data protection at MyFonts can be found at the following link: https://www.myfonts.com/info/terms-and-conditionsYes
wiredmindsWIREDMINDS GMBH
Lindenspürstr. 32
70176 Stuttgart
Our website uses a counting pixel technology provided by wiredminds GmbH
(www.wiredminds.de) to analyze visitor behavior. If necessary, data is collected, processed
and stored, from which user profiles are created under a pseudonym. Wherever possible and
reasonable, these usage profiles are completely anonymized. Cookies can be used for this
purpose. Cookies are small text files that are stored in the visitor’s Internet browser and
serve to recognize the Internet browser. The collected data, which may also contain personal
data, will be transmitted to wiredminds or collected directly by wiredminds. wiredminds may
use information that is left by visiting the websites to create anonymized usage profiles. The
data obtained without explicit consent of the affected person will not be used to personally
identify the visitor of this website and will not be merged with personal data of the bearer of
the pseudonym. Whenever IP addresses are recorded, their immediate anonymization takes
place by deleting the last number block.
OptOut wiredmindsno

If you want to opt out of interest-based advertising, you can also go to http://www.youronlinechoices.com/en/, click on “Preference Management” and follow the instructions to prevent the listed service providers from using of your data for interest-based advertising completely or individually. You will still receive advertising, but it is not interest-based.

III. Rights of data subjects

1. Right to object

If we process your personal data in order to operate direct marketing, you have the right to object to the processing of personal data concerning you for the purpose of such advertising with future effect at any time; this also applies to profiling insofar as it is associated with such direct marketing.

You also have the right, for reasons arising from your particular situation, to object to the processing of personal data concerning you at any time with future effect in accordance with Article 6 (1) (e) or (f) GDPR; this also applies to profiling based on these provisions.

The right to object can be exercised free of charge.

You can reach us via the contact details listed under I.2.

2. Right to information

You have the right to know whether personal data concerning you is processed, which personal data this may be, and further information in accordance with Art. 15 GDPR.

3. Right of rectification

You have the right to demand that we correct your incorrect personal data without delay (Art. 16 GDPR). Taking into account the purposes of processing, you have the right to request the completion of incomplete personal data, including by means of a supplementary statement.

4. Right to deletion (“right to be forgotten”)

You have the right to demand that personal data relating to you be deleted immediately if one of the reasons stated in Art. 17 (1) GDPR is applicable and the processing is not for one of the purposes set out in Art. 17 (3) GDPR is required.

5. Right to restriction of processing

You are entitled to demand a restriction on the processing of your personal data if one of the conditions laid down in Art. 18 (1) (a) to (d) GDPR is met.

6. Right to Data Portability

You have the right to receive personally identifiable information that you provided us in a structured, common and machine-readable format. Furthermore, you have the right to transmit this data to another person responsible without hindrance or to obtain that a direct transmission takes place by us, if this is technically possible. This should always apply if the basis of the data processing is the consent or a contract and the data is processed automatically. Accordingly, this does not apply to data held in paper form only.

7. Right to withdrawal after consent

If the processing is based on your consent, you have the right to withdraw your consent at any time. The legality of the processing on the basis of the consent up to the time the withdrawal was declared is not affected.

8. Right of appeal

You have the right of appeal to a supervisory authority.

IV. Glossary

Processors:
A natural or legal person, agency, institution or other body that processes personal data on behalf of the controller.

Browser:
Computer program for displaying web pages (e.g., Chrome, Firefox, Safari)

Cookies:
In the context of the World Wide Web, a cookie describes a small text file that is stored locally on the computer of the user when visiting a website. This file stores data about the behavior of the user. When the browser is called up and the corresponding website is visited repeatedly, the cookie is used and uses the stored data to provide the web server with information about the surfing behavior of the user.

In this context, “cookies” are not edible cookies, but information that a website stores locally on a visitor’s computer in a small text file. This can be settings already made by the user on a page, but also information that the website has gathered completely independently from the user. Later, these locally stored text files can then be read out again by the same web server from which they were created. Most browsers accept cookies automatically. You can manage cookies using the browser features (usually under “Options” or “Preferences”). This may disable the storage of cookies, be made dependent on your approval in individual cases or otherwise restricted. You can also delete cookies at any time.

Third countries:
Country that is not bound by the legal requirements of the EU Data Protection Directive (non-EEA country)

Personal data:
Any information relating to an identified or identifiable natural person. A natural person is considered as identifiable, which can be identified directly or indirectly, in particular by association with an identifier such as a name, an identification number, location data, an online identifier or one or more special features, the expression of the physical , physiological, genetic, mental, economic, cultural or social identity of this natural person.

Pixel:
Pixels are also called counting pixels, tracking pixels, web beacons or web bugs. These are small, invisible graphics in HTML emails or on web pages. When a document is opened, this small image is downloaded from a server on the Internet, where the download is registered there. This allows the operator of the server to see if and when an e-mail has been opened or a website has been visited. This function is usually realized by calling a small program (Javascript). This will allow certain types of information to be detected and shared on your computer system, such as the content of cookies, the time and date of the page view, and a description of the page on which the pixel is located.

Profiling:
Any type of automated processing of personal data, which consists in using that personal data to evaluate certain personal aspects relating to a natural person, in particular aspects relating to work performance, economic situation, health, personal preferences, interests To analyze or predict the reliability, behavior, location or change of location of this natural person

Services:
Our offers to which this privacy policy applies (see “Scope”).

Tracking:
The collection of data and their evaluation regarding the behavior of visitors to our services.

Tracking-Technologies:
Tracking can be done either via the activity logs (log files) stored on our web servers or by collecting data from your device via pixels, cookies and similar tracking technologies.

Processing:
Any process or series of operations related to personal information, such as collection, collection, organization, ordering, storage, adaptation or modification, reading, querying, use, disclosure, performed with or without the aid of automated procedures by submitting, distributing or otherwise providing, adjusting, linking, limiting, erasing or destroying.