Detailed Privacy Policy
1. Scope and Subject Matter of this Privacy Policy
The subject matter of this Privacy Policy is to inform you about which personal data we collect via our website and for what purposes we process such data. Where links to other websites are provided, we have neither influence nor control over the linked content or the privacy policies applicable there. We recommend that you review the privacy policies of the linked websites in order to determine whether and to what extent personal data is collected, processed, used or made available to third parties.
For reasons of better readability, the differentiated use of various linguistic forms has been dispensed with. All references to persons apply equally to all genders (male/female/diverse).
The subject matter of this Privacy Policy is to inform you about which personal data we collect via our website and for what purposes we process such data. Where links to other websites are provided, we have neither influence nor control over the linked content or the privacy policies applicable there. We recommend that you review the privacy policies of the linked websites in order to determine whether and to what extent personal data is collected, processed, used or made available to third parties.
For reasons of better readability, the differentiated use of various linguistic forms has been dispensed with. All references to persons apply equally to all genders (male/female/diverse).
The subject matter of this Privacy Policy is to inform you about which personal data we collect via our website and for what purposes we process such data. Where links to other websites are provided, we have neither influence nor control over the linked content or the privacy policies applicable there. We recommend that you review the privacy policies of the linked websites in order to determine whether and to what extent personal data is collected, processed, used or made available to third parties.
For reasons of better readability, the differentiated use of various linguistic forms has been dispensed with. All references to persons apply equally to all genders (male/female/diverse).
2. Important Definitions and Terms
Below you will find a selection of certain statutory definitions that may be helpful for understanding this Privacy Policy. The full text of the General Data Protection Regulation (GDPR), including the additional definitions and terms, is available under the following link.
Personal Data:
- Any information relating to an identified or identifiable natural person (hereinafter referred to as the “data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
Processing:
- Any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
Controller:
- Any natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data;
Recipient:
- A natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients; the processing of those data by those public authorities shall be in compliance with the applicable data protection rules according to the purposes of the processing;
Third Party:
- A natural or legal person, public authority, agency or body other than the data subject, the controller, the processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data.
3. Contact Details of the Controller
SGP Schneider Geiwitz & Partner Wirtschaftsprüfer Steuerberater Rechtsanwälte PartGmbB, Ziegelländeweg 4, 89077 Ulm, Germany
4. Contact Details of the Data Protection Officer
datenschutz@schneidergeiwitz.de
5. Log Files / Hosting
When you access our website, we collect so-called access data and store this data in a log file (so-called log file). This access data also includes the IP address. In addition, the log file contains the name of the website accessed, the file accessed, the date and time of access, the amount of data transferred and a notification of successful retrieval, the browser type and version, the operating system, the so-called referrer URL (the previously visited website) and the requesting provider.
Personal Data
IP address
Purpose of Data Processing
We collect the log file data, including the IP address, in order to ensure a smooth connection to the website and to enable users to use our website conveniently. The log file is also used to analyse system security and stability and for administrative purposes.
Legitimate Interest in Data Processing
The log file data, including the IP address, are used solely for the technical and design optimisation of the website and to secure our systems (e.g. in the event of an attack on our IT systems or a security incident). In the event of accessing our website, we are unable to establish a connection between the log file data, including the IP address, and a specific individual.
Provider: Amazon Inc.
Purpose of Data Processing: Web hosting
Details / Information on Data Protection: GDPR – Amazon Web Services (AWS)
Duration of Data Storage
The log files, including the IP address contained therein, are automatically deleted eight weeks after collection.
Legal Basis
Art. 6(1)(f) GDPR
Mandatory or Required Provision
The provision of the aforementioned personal data is neither required by law nor by contract. However, without the IP address, the service and functionality of the website cannot be guaranteed or may be restricted.
6. Cookies
Cookies are small text files that enable us to make the use of our services and our website more convenient for users, e.g. by determining whether you have already visited a particular page of our website and thereby storing information about your preferred activities on the website, or by tailoring our website to your individual interests. As soon as a user accesses our platform, a cookie is stored on the user's end device (laptop, tablet, smartphone or PC). Cookies that are not necessary for the provision of our website are only placed on your end device with your consent (Art. 6(1)(a) GDPR).
Essential:
These providers are used to operate the website or certain functions thereof, for example to ensure security or to arrange an appointment with us. These providers are strictly necessary and cannot be deselected.
Name: lang
Domain: schneidergeiwitz.de
Purpose of Data Processing: A session cookie that stores the language version of a website selected by the user.
Standard Expiration: Session
7. Web and User Analytics
Our website uses so-called tracking and web analytics tools. These involve collecting access data on our website and analysing the behaviour of our visitors for the purpose of optimising our services. With the help of these tools, we can analyse how and from where visitors arrive at our website, which areas of a website are accessed particularly frequently, and how often and for how long individual subpages and categories are viewed. We can also determine which search terms and websites users have entered and analyse how many users visit our pages overall and which information or services are most in demand. The aim is to use the knowledge gained in this way to make our services and our website as user-friendly as possible. Statistical analysis of usage profiles allows us to draw conclusions about the functionality and success of our websites and functions, such as how frequently information pages on certain product groups have been accessed or how many visitors have clicked on specific services. Tracking tools enable us to tailor our services more specifically to our customers, visitors and interested parties.
Personal Data
IP address; user agent (browser information); time of website visit; pages visited and interactions; device information; location data; referrer URL
Purpose of Data Processing
Tracking tools enable us to evaluate the behaviour of website visitors and analyse their interests. For this purpose, we create a pseudonymous user profile.
Recipients
We do not disclose your data to third parties. However, in the area of web and user analytics, we work with professional service providers who create user statistics on our behalf. The basis of this contractual relationship includes the providers' obligation to take special precautions to protect your data and to process all personal data only in accordance with our instructions (Art. 28 GDPR).
Provider: Google
Purpose of Data Processing: Google Tag Manager. It is used to centrally manage tracking and marketing codes (“tags”).
Details / Information on Data Protection: Privacy Policy – Privacy & Terms – Google
Duration of Data Storage
Further details regarding the providers, the functionality of web tracking and information about technologies used as part of these tracking tools; the storage period is 14 days.
Legal Basis
Art. 6(1)(a) GDPR
Mandatory or Required Provision:
The provision of the aforementioned personal data is neither required by law nor by contract.
8. Contact Form
Personal Data
First name, surname, email address, telephone number and the relevant message
Purpose of Data Processing
We use a contact form on our website to communicate with our customers and interested parties and to respond to their concerns and enquiries.
Duration of Data Storage
For the duration of processing and handling of the enquiry or until we are requested to delete the data.
Legal Basis
In principle, we do not require personal data in order to respond to enquiries. The legal basis is Art. 6(1)(a) GDPR. If you are already a customer/client or contractual partner, data processing is based on Art. 6(1)(b) GDPR.
Mandatory Provision
The provision of the aforementioned personal data is neither required by law nor by contract. However, without providing this information, we cannot process your enquiry.
9. Mapbox
We use the mapping service ‘Mapbox’ on our website to display interactive maps and create visual content. Mapbox is a service provided by Mapbox Inc., 740 15th Street NW, 5th Floor, Washington, DC 20005, USA.
Personal Data
IP address, browser type, operating system, time of access, device information, location data, interaction data
Purpose of Data Processing
Mapbox is integrated to make it easier to locate the places specified by us:
- Display of maps and locations on websites or in apps
- Improvement of navigation and user experience
- Analysis and optimisation of usage and services
- Ensuring the operation, security and improvement of the services
Recipients
We do not disclose your data to third parties. However, we work with professional service providers. The basis of this contractual relationship includes the providers' obligation to take special precautions to protect your data and to process all personal data only in accordance with our instructions (Art. 28 GDPR).
Provider: Mapbox Inc.
Service: Mapbox
Details / Information on Data Protection: Legal information about Privacy
Duration of Data Storage
The log files, including the IP address contained therein, are automatically deleted 30 days after collection. ID/usage data are stored for 36 months and then automatically deleted.
Legal Basis
This use is based on your consent pursuant to Art. 6(1)(a) GDPR.
Mandatory or Required Provision
The provision of the aforementioned personal data is neither required by law nor by contract.
10. Social Networks
We maintain presences on several online platforms and social networks in order to interact with potential or existing customers, exchange information with interested parties and users, or promote our products and services.
We operate our presences under so-called joint controllership under data protection law with the respective providers. We process data that you directly share or publish via the online platforms and networks (e.g. through comment and chat functions) as controllers, where applicable, in order to interact or communicate with you. As part of this interaction, the platform operators may also provide us with statistical data concerning the use of our “channels and fan pages”. This may include information about interactions, likes, comments or aggregated information and statistics (e.g. IP address; origin of followers), which help us understand interactions with our page. The legal basis for data processing within our area of responsibility is Art. 6(1)(f) GDPR.
However, the aforementioned providers also process data under their own responsibility. We have no influence over data that the providers process under their own responsibility in accordance with their own terms of use and privacy policies. We would like to point out that when accessing the aforementioned providers, additional data (e.g. relating to your usage and “surfing behaviour”) may be collected and, where applicable, transmitted to the provider. Please also note that, when interacting via the aforementioned media, data may also be processed outside the European Union. Furthermore, user data is generally processed for market research and advertising purposes. For example, usage profiles may be created based on users' behaviour and the interests derived from it. The usage profiles may in turn be used to display advertisements within and outside the platforms that are presumed to correspond to users' interests. Further information can be found in the privacy information provided by the respective providers. If we have personal data relating to you in connection with your use of the online platforms and networks, please address your concerns to us. If you also wish to assert rights against a specific provider, please contact the respective provider.
Provider / Platform / Information
- Meta / Facebook / Meta Privacy Policy
- LinkedIn / LinkedIn / LinkedIn Privacy Policy
- New Work / Xing / Privacy at XING
11. Creditor Information System (GIS)
We attach great importance to protecting your personal data. Below, we inform you about how your data is processed when logging into and using our Creditor Information System (GIS).
If you use our GIS, you will be redirected to the platform's website. The personal data processed in this context are described in the following Privacy Policy.
12. Applications
If you use our application platform, you will be redirected to the website karriere.schneidergeiwitz.de. The personal data processed in this context are described below:
On our careers website, we use the services of BITE GmbH. This service includes the provision of applicant management software.
Personal Data
IP address, browser type, operating system, time of access, content accessed and referrer URL
Purpose of Data Processing
The purpose of this processing is the technical loading of the careers page or the BITE portal.
Recipients
We do not disclose your data to third parties. However, we work with professional service providers. The basis of this contractual relationship includes the providers' obligation to take special precautions to protect your data and to process all personal data only in accordance with our instructions (Art. 28 GDPR).
Provider / Transfers / Details and Information on Data Protection
- BITE GmbH / jobs-cdn.b-ite.com / Legal Notice
- BITE GmbH / cs-assets.b-ite.com / Legal Notice
- BITE GmbH / jobs.b-ite.com / Legal Notice
Duration of Data Storage
The log files, including the IP address contained therein, are automatically deleted no later than 30 days after collection.
Legal Basis
The legal basis for data collection is Art. 6(1)(f) GDPR. The purpose and legitimate interest are to ensure the stability, functionality and security of our website.
Mandatory or Required Provision
The provision of the aforementioned personal data is neither required by law nor by contract. However, without the transmission of this data, we cannot provide you with the relevant application platform.
Application Procedure
A description of the processing in connection with the actual application process can be found in the relevant job advertisement under the button “Privacy Information”.
13. Video Conferencing and Transcription
With this Privacy Information, we inform you about the processing of your personal data in connection with the use of video conferencing software and possible transcriptions, as well as about the rights to which you are entitled. We use various tools to conduct video conferences, telephone conferences and meetings (hereinafter “Meetings”). Please note that you can protect your privacy by using a neutral background image during the video conference. You can set this in the preceding window (“waiting room”). If you do not wish to transmit a video image of yourself, you can also deactivate the camera in the same window.
Who is responsible for data protection?
The specific responsibility for the respective data processing may be determined in individual cases by the contract concluded with you (engagement agreement, service agreement, etc.) or by the invitation to the respective Meeting itself. The following link shows the respective locations of the SGP companies and their addresses for service of process.
Note: If you access the website of the service provider of the video conferencing software, the provider of the service is responsible for the data processing.
How can you contact our Data Protection Officer?
You can contact our Data Protection Officer by email at: datenschutz@schneidergeiwitz.de
What data do we process and where does it come from?
Various types of personal data are processed when conducting Meetings. The scope of the data also depends on which data you provide before or when participating in a Meeting. In particular, the following personal data are subject to processing:
- User information: first name, surname, email address, telephone number (optional), profile picture (optional), department (optional), password (if “Single Sign-On” is not used);
- Metadata: subject of the Meeting, description;
- Text, audio and video data: You may have the opportunity to use chat functions during a Meeting. In this respect, the text entries you make are processed in order to display them in the Meeting and, where applicable, to record them. In order to enable the display of video and playback of audio, the data from the microphone of your end device and any video camera on the end device are processed for the duration of the Meeting. You can switch off or mute the camera or microphone yourself at any time.
- Transcription: Transcription creates text-based records of Meetings in real time, which simplifies documentation.
If we intend to record Meetings, we will inform you transparently in advance. The fact that a recording is being made will also be displayed to you in the app. Recording takes place, for example, for the purposes of documentation, preparation of minutes and traceability of decisions on the basis of Art. 6(1)(f) GDPR (legitimate interest). If a recording is made, the following personal data are processed:
- File containing all video, audio and presentation recordings, text file of the Meeting chat.
If necessary for the purpose of documenting the results of a Meeting, we will record the chat contents.
Note: We would like to point out that the use of the chat cannot be influenced by SGP Schneider Geiwitz & Partner Wirtschaftsprüfer Steuerberater Rechtsanwälte PartGmbH. We also point out that data entered by users via the chat (such as the exchange of email addresses in the chat) is shared voluntarily and at the user's own risk and responsibility. The chat is visible to all participants.
For what purposes do we process your data (purpose of processing) and on what legal basis?
We use the relevant software to conduct video conferences, telephone conferences and Meetings (so-called “Meetings”).
Where personal data of employees of SGP Schneider Geiwitz & Partner Wirtschaftsprüfer Steuerberater Rechtsanwälte PartGmbH is processed, the processing is carried out on the basis of Section 26 BDSG (German Federal Data Protection Act). If, in connection with the use of Teams, personal data is not required for the establishment, implementation or termination of the employment relationship but nevertheless constitutes an essential part of the use of the service, Art. 6(1)(f) GDPR is the legal basis for data processing. In these cases, our interest lies in the effective conduct of “Meetings”. In relation to customers/clients and interested parties, the legal basis for data processing when conducting “Meetings” is Art. 6(1)(b) GDPR, provided that the Meetings are conducted in the context of contractual relationships or, at the request of the interested party, for the implementation of pre-contractual measures.
Use of Transcription:
Recording takes place for purposes such as documentation, preparation of minutes and traceability of decisions on the basis of Art. 6(1)(f) GDPR (legitimate interest). The planned live transcription of selected Meetings serves to reliably document business decisions and measures (preparation of minutes, traceability, quality assurance and organisational safeguards). The processing is necessary to achieve this purpose because equally effective and less intrusive means (purely manual minutes/no documentation) cannot ensure the necessary accuracy, verifiability and efficiency to a comparable extent. The interference with the interests of data subjects is significantly reduced through transparency (prior information and Meeting notification), purpose limitation (no performance or behavioural monitoring), data minimisation (selective use), access restrictions and short retention periods. Against this background, the legitimate interests of the company outweigh the interests in the specific processing scenario; the rights and freedoms of the participants do not take precedence.
To whom do we disclose the data?
Personal data processed in connection with participation in “Meetings” is generally not disclosed to third parties unless this data is expressly intended for disclosure. We only disclose your data within SGP Schneider Geiwitz & Partner Wirtschaftsprüfer Steuerberater Rechtsanwälte PartGmbH to those departments that require it to fulfil contractual and legal obligations or to perform their respective tasks.
Video conferencing: The providers of the respective video conferencing systems (Microsoft, Google, etc.) necessarily have access to the aforementioned data insofar as this is provided for within the scope of our contractual relationship (processing on behalf of the controller). The relevant service providers have been contractually obliged under a data processing agreement pursuant to Art. 28 GDPR to handle the relevant personal data with due care.
Transcription: The provider of the respective transcription service (wespond UG, “Jamie”) necessarily has access to the aforementioned data insofar as this is provided for within the scope of our contractual relationship (processing on behalf of the controller). The relevant service provider has been contractually obliged under a data processing agreement pursuant to Art. 28 GDPR to handle the relevant personal data with due care.
Do we transfer data to third countries?
As part of the use of video conferencing systems and transcription services, personal data is transferred to the service providers' European data centres and stored there. However, access by persons from a third country cannot be ruled out, as support may also be provided by employees who are not based in the European Union. SGP Schneider Geiwitz & Partner Wirtschaftsprüfer Steuerberater Rechtsanwälte PartGmbH observes the special requirements of Arts. 44 to 50 GDPR in this respect. The necessary agreements (EU Standard Contractual Clauses) have been concluded. We do not otherwise transfer your personal data to recipients in so-called third countries, i.e. countries outside the European Economic Area (EEA), or to international organisations.
How long do we store your data?
We store your personal data only for as long as this is necessary to provide the associated contractual services. This includes not only the duration of the actual business relationship but also data processing in the context of initiating and executing contracts. In addition, we are subject to various retention and documentation obligations arising, among other things, from the German Commercial Code (HGB) and tax regulations (German Fiscal Code – AO). The retention and documentation periods prescribed therein range from five (5) to ten (10) years. Finally, the storage period is also determined by the statutory limitation periods, which, for example, under Sections 195 et seq. of the German Civil Code (BGB), are generally three (3) years but may in certain cases be up to thirty (30) years. The transcript is used solely as a working document and is stored only for as long as necessary to provide the associated contractual services. The corresponding audio recordings are automatically deleted after the Meetings and after the transcription has been created. Neither we nor any of the model providers use your data to train AI.
Is there an obligation to provide personal data?
As part of a video conference and transcription, you only need to provide the personal data that is necessary to use this service.
To what extent is there automated decision-making in individual cases?
In principle, we do not use automated decision-making within the meaning of Art. 22 GDPR for the establishment and conduct of a video conference and transcription.
To what extent do we use your data for profiling?
We do not process your data automatically for the purpose of evaluating certain personal aspects (so-called “profiling” pursuant to Art. 4 No. 4 GDPR).
What data protection rights do you have?
Subject to the respective statutory requirements, you have the right to request confirmation from us at any time as to whether we process personal data and the right to obtain information (Art. 15 GDPR, Section 34 BDSG) about such personal data. In addition, you have the right to rectification (Art. 16 GDPR), erasure (Art. 17 GDPR, Section 35 BDSG) and restriction of data processing (Art. 18 GDPR), as well as the right to object to the processing of personal data at any time (Art. 21 GDPR), to withdraw your consent to data processing at any time or to request data portability (Art. 20 GDPR). Furthermore, you have the right to lodge a complaint with a supervisory authority in the event of data protection violations (Art. 77 GDPR, Section 19 BDSG).
All information on SGP's Privacy Information for video conferencing and transcription can also be found under the following link: Privacy Information for Video Conferencing
14. Fonts
This website uses so-called web fonts for the consistent display of fonts. When a page is accessed, your browser loads the required web fonts into its browser cache in order to display texts and fonts correctly. For this purpose, the browser you use must establish a connection to the servers. We have configured the fonts so that no connection to Adobe servers is established. The use of web fonts is in the interest of a consistent and appealing presentation of our online services. This constitutes a legitimate interest within the meaning of Art. 6(1)(f) GDPR. If your browser does not support web fonts, a standard font from your computer will be used.
Provider: SGP
Service: Web Open Font Format (WOFF2)
Information: WOFF File Format 2.0
15. Data Security
We maintain up-to-date technical measures to ensure data security, in particular to protect your personal data against risks during data transmission and against access by third parties. These measures are continuously adapted and reviewed in accordance with the current state of the art. To maintain the confidentiality and integrity of the data you provide on our website, this data is transmitted via “HTTPS” and Transport Layer Security (TLS).
Your Rights
You have the right to request confirmation from us at any time as to whether we process personal data concerning you and the right to obtain information about such personal data. In addition, you have the right to rectification, erasure and restriction of data processing, as well as the right to object to the processing of personal data at any time, to withdraw your consent to data processing at any time or to request data portability.
Please send all requests for information, access requests, withdrawals of consent or objections to data processing by email to datenschutz@schneidergeiwitz.de. Furthermore, you have the right to lodge a complaint with a supervisory authority in the event of data protection violations.