Privacy Notice
Data protection is of particularly high priority for the management of TreuITConsult GmbH. This notice informs you of the nature, scope and purpose of the personal data we process, as well as your rights.
This is an English-language courtesy translation of our German privacy notice. In case of any discrepancy, the German original is authoritative.
We are delighted that you are interested in our company. Data protection is of particularly high priority for the management of TreuITConsult GmbH. It is generally possible to use our website without providing any personal data. However, if a data subject wants to use special services offered through our website, it may become necessary to process personal data. Where such processing is necessary and there is no statutory basis for it, we generally obtain the data subject's consent.
The processing of personal data — such as name, address, email address or phone number — always takes place in accordance with the General Data Protection Regulation (GDPR) and in line with the country-specific data protection provisions applicable to TreuITConsult GmbH. Through this privacy notice, our company wishes to inform the public about the nature, scope and purpose of the personal data we collect, use and process. Data subjects are also informed of the rights to which they are entitled.
TreuITConsult GmbH, as the party responsible for processing, has implemented numerous technical and organisational measures to ensure the most complete protection possible of personal data processed via this website. Nevertheless, internet-based data transmissions can generally have security gaps, so absolute protection cannot be guaranteed. For this reason, every data subject is free to transfer personal data to us via alternative means, such as by telephone.
1. Definitions
This privacy notice is based on the terminology used by the European legislator when adopting the GDPR. We aim for this notice to be easy to read and understand for the public as well as for our customers and business partners. Among other terms, we use the following:
a) Personal data
Personal data means any information relating to an identified or identifiable natural person ("data subject"). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more factors specific to that person.
b) Data subject
Data subject means any identified or identifiable natural person whose personal data is processed by the controller.
c) Processing
Processing means any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
d) Restriction of processing
Restriction of processing means the marking of stored personal data with the aim of limiting its processing in the future.
e) Profiling
Profiling means any form of automated processing of personal data consisting of using personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.
f) Pseudonymisation
Pseudonymisation means the processing of personal data in such a way that it can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures.
g) Controller
Controller means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
h) Processor
Processor means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
i) Recipient
Recipient means a natural or legal person, public authority, agency or another body to which the personal data are disclosed, whether a third party or not.
j) Third party
Third party means a natural or legal person, public authority, agency or body other than the data subject, the controller, the processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data.
k) Consent
Consent means any freely given, specific, informed and unambiguous indication of the data subject's wishes by which they, by a statement or by a clear affirmative action, signify agreement to the processing of personal data relating to them.
2. Name and address of the controller
The controller within the meaning of the GDPR, other data protection laws applicable in EU member states, and other provisions of a data-protection nature is:
TreuITConsult GmbH
Lorscher Straße 90
60489 Frankfurt
Germany
Phone: +49 69 79538898-0
Email: info@treuitconsult.de
Website: treuitconsult.de
3. Name and address of the data protection officer
The data protection officer of the controller is:
Dipl.-Wirtsch.-Ing. (TU) H. J. Kiefer
TreuITConsult GmbH
Lorscher Straße 90
60489 Frankfurt
Germany
Phone: +49 69 79538898-0
Email: info@treuitconsult.de
Any data subject may contact our data protection officer directly at any time with questions or suggestions regarding data protection.
4. Collection of general data and information
The TreuITConsult GmbH website collects a series of general data and information each time the website is accessed by a data subject or automated system. This data is stored in the server's log files. The following may be recorded: (1) the browser types and versions used, (2) the operating system used, (3) the website from which an accessing system reaches our site (referrer), (4) the sub-pages accessed, (5) the date and time of access, (6) an internet protocol (IP) address, (7) the internet service provider of the accessing system, and (8) other similar data used to help prevent danger in the event of attacks.
When using this general data and information, TreuITConsult GmbH does not draw any conclusions about the data subject. This information is required to correctly deliver and optimise content, to ensure the long-term functionality of our systems, and to provide law enforcement with the information necessary for prosecution in the event of a cyberattack. Anonymously collected data is evaluated statistically with the aim of increasing data protection and data security. The anonymous data from the server log files is stored separately from any personal data provided.
5. Routine erasure and blocking of personal data
The controller processes and stores personal data of the data subject only for the period necessary to achieve the purpose of storage, or as otherwise provided by law. If the purpose of storage no longer applies, or a legally prescribed retention period expires, personal data is routinely blocked or erased in accordance with statutory provisions.
6. Rights of the data subject
a) Right of confirmation
Every data subject has the right to obtain confirmation from the controller as to whether personal data concerning them is being processed.
b) Right of access
Every data subject has the right to obtain free information at any time about their personal data stored and a copy of this information. Furthermore, there is a right to information about: the purposes of processing; the categories of personal data processed; the recipients or categories of recipients; the envisaged storage period or the criteria used to determine it; the existence of a right to rectification, erasure, restriction or objection; the right to lodge a complaint with a supervisory authority; all available information on the origin of the data; and the existence of automated decision-making, including profiling, pursuant to Art. 22(1) and (4) GDPR.
c) Right to rectification
Every data subject has the right to obtain the prompt correction of inaccurate personal data concerning them, as well as the completion of incomplete data.
d) Right to erasure ("right to be forgotten")
Every data subject has the right to request that personal data concerning them be erased promptly, provided one of the statutory grounds applies and the processing is not necessary.
e) Right to restriction of processing
Every data subject has the right to request the restriction of processing where one of the statutory conditions is met.
f) Right to data portability
Every data subject has the right to receive personal data concerning them in a structured, commonly used and machine-readable format and to transmit it to another controller, where technically feasible.
g) Right to object
Every data subject has the right, on grounds relating to their particular situation, to object at any time to the processing of personal data concerning them. In the case of direct marketing, there is a right to object at any time.
h) Automated individual decision-making, including profiling
Every data subject has the right not to be subject to a decision based solely on automated processing — including profiling — which produces legal effects concerning them or significantly affects them in a similar way.
i) Right to withdraw data-protection consent
Every data subject has the right to withdraw their consent to the processing of personal data at any time.
7. Legal basis for the processing
Art. 6(1)(a) GDPR serves as the legal basis for processing operations for which we obtain consent. If processing is necessary for the performance of a contract, it is based on Art. 6(1)(b) GDPR; the same applies to pre-contractual measures. Where our company is subject to a legal obligation, processing is based on Art. 6(1)(c) GDPR. Where processing is necessary to protect vital interests, it is based on Art. 6(1)(d) GDPR. Finally, processing operations may be based on Art. 6(1)(f) GDPR where processing is necessary for the purposes of a legitimate interest, unless overridden by the interests, fundamental rights and freedoms of the data subject.
8. Legitimate interests pursued
Where processing of personal data is based on Art. 6(1)(f) GDPR, our legitimate interest is the conduct of our business for the benefit of all our employees and shareholders.
9. Duration for which personal data is stored
The criterion for the duration of storage of personal data is the applicable statutory retention period. After expiry of that period, the corresponding data is routinely deleted, provided it is no longer required for the performance or initiation of a contract.
10. Statutory or contractual provisions for the provision of personal data
We inform you that the provision of personal data is partly required by law (e.g. tax regulations) or can result from contractual provisions. Data subjects may sometimes be required to provide personal data to us so that it can be processed by us in connection with concluding a contract. Failure to provide the data may mean the contract cannot be concluded. Before providing personal data, the data subject may contact our data protection officer, who will clarify on a case-by-case basis.
11. Existence of automated decision-making
As a responsible company, we do not use automated decision-making or profiling.
The German original of this privacy notice was created using the privacy-notice generator of DGD Deutsche Gesellschaft für Datenschutz GmbH, external data protection officer, in cooperation with data protection lawyer Christian Solmecke.