We, iteratec GmbH, are certain that you should have absolute control over your data. We therefore take the protection of your personal data very seriously and adhere strictly to all data protection laws. The following data protection declaration gives an overview of how we ensure this protection, what kind of data we collect (and for what purpose) and what your rights are with regard to your personal data.
Should you have any questions regarding data protection, feel free to contact us at any time.
Any changes that we make in future to the “Data Protection Declaration of iteratec GmbH” will be posted on this page.
This data protection declaration came into force on 18.05.2018.
Street, building no.:
Post code, city:
Commercial register number:
Klaus Eberhardt, Mark Goerke, Jörg-Stefan Rauch, Michael Schulz
+49 89 61 45 51 0
1.1. This data protection declaration explains the nature, scope and purpose of the processing of personal data within the scope of our web pages, functions and contents (hereinafter jointly referred to as the “website”). This data protection declaration applies irrespective of the domains, systems, platforms and devices (e.g. desktop or mobile) on which the online offer is executed.
1.2. The terms used, such as “personal data” or their “processing”, refer to the definitions contained in Art. 4 General Data Protection Regulation (GDPR).
1.3. The personal data of users processed within the framework of the online offer includes usage data (browser type and version, operating system used, the URL of the previously visited site, the IP address of the accessing computer and the time of the enquiry), as well as the content details (e.g. entries made on the application form).
1.4. The term “user” covers all categories of the data subjects. These include our business partners, customers, interested parties and other browsers of our online offer. The terms used, such as “user”, should be understood as being gender-neutral.
1.5. We process users' personal data exclusively in compliance with the relevant data protection regulations. This means that user data will be processed only if legal permission has been granted, in particular if data processing is required by law, if user consent has been obtained, and also on the basis of our legitimate interests (i.e. an interest in the analysis, optimisation and efficient operation and security of our online service as defined in Art. 6(1)(f) GDPR, in particular, when measuring reach, creating profiles for advertising and marketing purposes, and when collecting access data and using the services of third parties).
1.6. We would like to point out that a legal basis is established either by consent, by the need for processing in order to render our services and implement our contractual measures, by the need for processing in order to fulfil our legal obligations, or by the need for processing in order to protect our legitimate interests (Art. 6(1)(a) and Art. 7 GDPR).
1.7. Which sources and data do we use? We process the personal data of customers, suppliers, interested parties, applicants and employees. We process this data in the context of business relations, application procedures or employment relationships. We also use data from publicly accessible sources, the processing of which is permissible. The legal basis is the fulfilment of (pre-)contractual obligations, a legitimate interest, a legal provision or an existing consent as provided by the person concerned.
2.1. We take organisational, contractual and technical security measures in line with state-of-the-art technological standards, in order to ensure that the regulations set out under data protection laws are observed and thus to protect the data processed by us against accidental or intentional manipulation, loss, destruction or access by unauthorised persons.
2.2. The security measures include, in particular, the encrypted transmission of data between your browser and our server.
2.3. As the security team at iteratec, we take care of your online security. If you have any complaints about the misuse of our (or your) network access, or if you receive spam from one of our addresses, please get in touch by e-mail via email@example.com.
3.1. Data will be passed on to third parties only within the scope of statutory requirements. We will pass on user data to third parties only if this is deemed necessary for contractual purposes, e.g. on the basis of Art. 6(1)(b) GDPR or on the basis of a justified interest in accordance with Art. 6 (1)(f) GDPR, and the efficient and effective operation of our business operations.
3.2. If we use subcontractors to render our services, we take appropriate legal precautions, as well as appropriate technical and organisational measures, to ensure that personal data are protected in accordance with the relevant statutory provisions.
3.3. If contents, tools or other resources from other providers (hereinafter referred to jointly as “third-party providers”) are used within the scope of this data protection declaration, these are transferred only to countries with an appropriate level of data protection and to countries that fall within the scope of the GDPR.
4.1. Applicant management: for our online application form and applicant management, we use the platform from the service provider Talention (TFI GmbH, Delphiplatz 1, 42119 Wuppertal, Germany) to ensure fast and secure processing when recruiting new employees. For this purpose, we have concluded a contract processing agreement with the provider in which the provider undertakes to comply with all data protection regulations and to process the data only in accordance with our instructions and only for the corresponding purpose. Further information can be found here.
4.2. With regard to applicant data that we receive (by post, e-mail or online), our technical and organisational measures ensure that your personal data is treated confidentially and in line with statutory requirements. Following the completion of the application procedure, your data will be deleted, unless you agree to its storage over a longer period of time. Deletion takes place after four months (due to compliance with deadlines for possible legal action as per the General Equal Treatment Act [AGG]).
4.3. init(U) – Application entry via app for recruiting events
The app can be used to collect data from interested parties, in order to initiate an application process. This includes a person’s name, e-mail address, gender, photo, a self-assessment of technical skills and, if appropriate, application documents.
This data is
(a) stored on an internal system and remains accessible only to authorised persons.
b) transferred to the Applicant Management System of our service provider, Talention.
All data will be deleted after four months, unless the interested party explicitly consents to its storage for a longer time for the purpose of establishing contact at a later date. In this case, the data is stored for one year and then deleted.
To facilitate the booking of tickets for some of our events, we use Eventbrite Inc., Delaware, 155 5th Street, Floor 7, San Francisco, CA 94103, USA. When you register for one of our events, you transmit your first and last name, e-mail address and, if applicable, the company you work for to the provider and arrange payment. The provider will then send you an e-mail to confirm your booking. Upon registration, and in addition to the above-mentioned data, Eventbrite will save the selected event, including the scheduled event time (date, time) and the time of registration (date, time).
There is no contract for commissioned data processing with Eventbrite, due to the fact that, at present, only a Data Processing Addendum (DPA) is offered for commissioned and subcontracted data processors (can be viewed at: https://www.eventbrite.de/support/articles/de/Troubleshooting/datenverarbeitungsnachtrag-fuer-auftragsverarbeiter-und-unterauftragsverarbeiter?lg=de).
An overview of Eventbrite's corporate policies can be found at https://www.eventbrite.de/l/LegalTerms/
7.2. Google will use this information on our behalf to evaluate the use of our website by users, to compile reports on the activities within this website and to provide us with additional services associated with the use of this website and the Internet. Pseudonymous user profiles of the users can be created from the processed data.
7.3. We use Google Analytics only with activated IP anonymisation. This means that the IP address of users is truncated by Google within Member States of the European Union or in other Contracting States to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transferred to a Google server in the USA and truncated there.
7.4. The IP address transmitted by the user's browser is not merged with other data from Google. Users can prevent the storage of cookies by setting their browser software accordingly; users can also prevent the collection of data generated by the cookie – and relating to their use of the online offer – as well as its transmission to (and processing by) Google, by downloading and installing the browser plugin available via the following link: http://tools.google.com/dlpage/gaoptout?hl=de.
7.5. You can also prevent the collection of your data by Google Analytics by clicking on the following link. https://www.iteratec.de/cookies/
7.6. You can find further information on the use of data by Google, as well as the settings and objection options available, on the websites of Google: https://www.google.com/intl/de/policies/privacy/partners (“Data use by Google when you use websites or apps of our partners”), http://www.google.com/policies/technologies/ads (“Data use for advertising purposes”), http://www.google.de/settings/ads (“Manage information that Google uses to serve ads to you”).
7.7. We use Google Tag Manager. Google Tag Manager is a solution that allows marketers to manage website tags through one interface. The Tag Manager tool itself (which implements the tags) is a cookie-less domain and does not collect personal information. The tool triggers other tags, which in turn may collect data. Google Tag Manager does not access this data. If deactivation has occurred at domain- or cookie level, it will persist for all tracking tags implemented with Google Tag Manager. https://www.google.de/tagmanager/use-policy.html
7.8. In addition, we use the data collected by Google Analytics as part of Google Optimize. Among other things, the use of different variants of our websites is analyzed in Google Optimize through so-called A/B tests. This allows us to better understand the behavior of our users and make the websites more user-friendly.
In its online offer, iteratec provides the option of following its social media offers via so-called “Follow Buttons”. Online maps and videos are also provided by third-parties. In the following, you will find explanations of the individual services.
8.2. Facebook: A “Follow Button” from the social network Facebook (Facebook Inc., 1601 Willow Road, Menlo Park, California, 94025, USA) is integrated into our pages.
When you visit our pages, the button establishes a direct connection between your browser and the Facebook server. In doing so, Facebook receives the information that you have visited our site from your IP address.
8.3. XING: We use features of the professional network XING. The provider is XING AG, Dammtorstraße 29-32, 20354 Hamburg, Germany. Every time one of our pages containing the functions provided by Xing is accessed, a connection to the Xing servers is established. To the best of our knowledge, no personal data is stored. In particular, no IP addresses are stored or user behaviour evaluated. Data protection declaration: https://www.xing.com/app/share?op=data_protection
8.4. LinkedIn: Our online offer uses functions of the professional network LinkedIn. The provider is LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA. Every time one of our pages containing the functions provided by LinkedIn is accessed, a connection to the LinkedIn servers is established. LinkedIn is informed that you have visited our website from your IP address. If you click on LinkedIn's “Recommend Button” and are logged into your LinkedIn account, LinkedIn will be able to associate your visit to our website with you and your account. We would like to point out that, as the provider of these pages, we have no knowledge of the content of the transmitted data or of its use by LinkedIn. Data protection declaration: https://www.linkedin.com/legal/privacy-policy.
8.5. Kununu: Kununu is operated by kununu GmbH, Fischhof 3 Top 7, A - 1010 Vienna. Your browser will establish a direct connection to the Kununu servers as soon as you click the button. We have no control over the data that is then collected by Kununu. For information pertaining to the purpose and scope of data collection, its further processing and use by Kununu, as well as your rights and setting options to protect your privacy, please refer to the information contained in the Kununu data protection declaration: http://www.kununu.com/info/datenschutz
8.6. YouTube: Embedded videos from the “YouTube” platform from the third-party provider Google Inc, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Data protection declaration: https://www.google.com/policies/privacy/ Opt-out: https://www.google.com/settings/ads/. When you click on a link to a video, we allow you only to connect to YouTube services.
When you visit our Facebook page, certain information about you is processed. Facebook Ireland Ltd (Ireland/EU) is solely responsible for this processing of personal data. Further information on the processing of personal data by Facebook can be found here.
9.1. Processing of Page Insights
Facebook provides us with statistics and insights for our Facebook page in anonymous form, which enable us to develop an understanding of the types of actions that people take on our page (so-called “page insights”). These page views are created on the basis of certain information about people who have visited our site. This processing of personal data is carried out by Facebook and us as jointly responsible data controllers. This processing serves our legitimate interest in evaluating the types of actions performed on our site and improving our site based on the insight gleaned. The legal basis for this processing is Article 6(1)(f) GDPR. We will never associate the information obtained through Page Insights with a particular Facebook profile by drawing on “Like” information for our Page.
We have reached an agreement with Facebook on processing as joint data controllers, which defines the distribution of data protection obligations between us and Facebook. You can view the details pertaining to the processing of personal data to create Page Insights and the agreement concluded between us and Facebook here.
9.2. Processing of data communicated to us through our website
We also process information that you have made available to us via our Facebook page. Such information can include the Facebook name, contact details or a message sent to us. We process this personal data only if we have expressly requested you to provide us with this data beforehand. This processing by us takes place with us acting as sole data controller.
If your enquiry is directed at the conclusion or execution of a contract with us, Art. 6(1)(b) GDPR constitutes the legal basis for data processing. Otherwise, we will process data on the basis of our legitimate interest in establishing contact with those individuals submitting an enquiry. The legal basis for data processing in this context is Art. 6(1)(f) GDPR.
We use the LinkedIn Insight Tag for our websites. This tool creates a cookie in your browser which allows us to record the following data, among others:
LinkedIn does not share any personal data with iteratec but offers anonymised reports about the website target group as well as ad performance. Additionally, LinkedIn offers the possibility of retargeting via the Insight Tag. This data allows iteratec to display targeted ads outside its website without you being identified as a website user.
The use of LinkedIn Insight is based on Art. 6 para. 1 lit. a EU GDPR. You can withdraw your consent at any time.
The data collected by LinkedIn is encrypted, anonymised within seven days and the anonymised data is deleted within 90 days.
The offer on the securecodebox.io website is hosted on the third-party platform GitHub. A Data Processing Agreement in line with the GDPR has been concluded. Accordingly, the Terms and Conditions of GitHub apply to Enterprise Subscription customers:
Our website uses the Cookie Consent Tool “Cookiebot” to obtain your consent to the storage of certain cookies in your browser and to document these in accordance with data protection regulations. Cookiebot is operated by Cybot A/S, 1058 Copenhagen, Denmark.
When you enter our website, a Cookiebot cookie is stored in your browser, in which the consents you have issued (or your revocation thereof) are stored.
For more information on the handling of the transferred data, please refer to the data protection declaration from cookiebot.com: https://www.cookiebot.com/de/privacy-policy/
We use HubSpot on our website for marketing activities. We use this integrated software solution for our own marketing, for lead generation and for customer service purposes. These include e-mail marketing, which regulates the dispatch of newsletters and automated mailings, social media publishing and reporting, contact management – such as user segmentation and CRM – landing pages and contact forms.
HubSpot is a software company from the USA with a subsidiary in Ireland.
Contact: HubSpot, 2nd Floor 30 North Wall Quay, Dublin 1, Ireland, Telephone: +353 1 5187500.
15.1. Right to the disclosure of information: Users have the right to request the disclosure, free of charge, of information on the personal data we have stored on them.
15.2. Right of rectification: In addition, users have the right to correct inaccurate data, to restrict the processing and deletion of their personal data and, where applicable, to exercise their rights to data portability.
15.3. Right of revocation: Users may also revoke their consent, in principle with effect for the future. This revocation must be sent to the data protection officer.
15.4. Right of appeal: In the event of a violation of the GDPR, those affected have a right of appeal vis-a-vis the competent supervisory authority. The right of appeal is without prejudice to other administrative or judicial remedies.
The data stored with us will be deleted as soon as it is no longer required for its intended purpose and the deletion does not conflict with any statutory storage obligations. To the extent that user data is not deleted because it is required for other (and legally permissible) purposes, its processing is restricted. This means that the data is blocked and not processed for other purposes. This applies, for example, to user data that must be retained for commercial or tax-related reasons.
Users can object at any time, in accordance with statutory requirements, to the future processing of their personal data. This objection may be made, in particular, against processing for direct marketing purposes. Any objection should be directed to the responsible data controller.
We reserve the right to amend this data protection declaration to align with changes in legislation, or should there be any changes to our service and the associated data processing. However, this applies only with regard to declarations on data processing. To the extent that user consent is required, or if components of the data protection declaration contain provisions of a contractual relationship with the users, changes will be made only with the consent of users.
Users are asked to update their understanding regarding the content of this data protection regulation at regular intervals.