Privacy Policy
This privacy policy informs you about the nature, scope, and purpose of the processing of personal data (hereinafter referred to as “data”) within our online services and the associated websites, functions, and content, as well as external online presences such as our social media profiles (hereinafter collectively referred to as “online services”). With regard to the terminology used, such as “processing” or “controller,” we refer to the definitions in Art. 4 of the General Data Protection Regulation (GDPR).
Controller slidesupgrade c/o Bosse & Otte GmbH, Poststraße 6, 49477 Ibbenbüren, Germany
Email: team@slidesupgrade.com | Managing Director: Arne Bosse | Imprint: slidesupgrade.com/imprint
Responsible for data protection: Mr. Arne Bosse | Email: team@slidesupgrade.com | Phone: +4954519542210
Types of Data Processed – Inventory data (e.g., names, addresses) – Contact data (e.g., email, phone numbers) – Content data (e.g., text entries, photographs, videos) – Usage data (e.g., websites visited, interest in content, access times) – Meta/communication data (e.g., device information, IP addresses)
Categories of Data Subjects Visitors and users of the online services (hereinafter collectively referred to as “users”).
Purpose of Processing – Providing the online services, their functions, and content – Responding to contact requests and communicating with users – Security measures – Reach measurement/marketing
Definitions “Personal data” means any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g., cookie), or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that person.
“Processing” means any operation or set of operations performed with or without the aid of automated means in connection with personal data. The term is broad and encompasses practically any handling of data.
“Pseudonymization” means the processing of personal data in such a manner that the data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures ensuring that the data cannot be attributed to an identified or identifiable person.
“Profiling” means any form of automated processing of personal data used to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that person’s work performance, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements.
“Controller” means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
“Processor” means a natural or legal person, public authority, agency, or other body which processes personal data on behalf of the controller.
Legal Bases In accordance with Art. 13 GDPR, we inform you of the legal bases for our data processing. Where a legal basis is not specified in this privacy policy, the following applies: The legal basis for obtaining consent is Art. 6(1)(a) and Art. 7 GDPR; for processing to fulfill our services and carry out contractual measures, as well as to respond to inquiries, it is Art. 6(1)(b) GDPR; for processing to fulfill legal obligations, it is Art. 6(1)(c) GDPR; and for processing to protect our legitimate interests, it is Art. 6(1)(f) GDPR. Where the vital interests of the data subject or another natural person require processing, Art. 6(1)(d) GDPR serves as the legal basis.
Security Measures In accordance with Art. 32 GDPR, and taking into account the state of the art, implementation costs, the nature, scope, circumstances, and purposes of processing, as well as the varying likelihood and severity of risks to the rights and freedoms of natural persons, we implement appropriate technical and organizational measures to ensure a level of protection appropriate to the risk.
These measures include, in particular, safeguarding the confidentiality, integrity, and availability of data by controlling physical access to data, as well as access, input, disclosure, ensuring availability, and separation of data. We have also established procedures to ensure the exercise of data subject rights, data deletion, and response to data threats. Furthermore, we take data protection into account from the earliest stages of hardware, software, and process development, in accordance with the principle of privacy by design and privacy by default (Art. 25 GDPR).
Collaboration with Processors and Third Parties Where we disclose, transfer, or otherwise grant access to data to other persons or companies (processors or third parties) in the course of our processing, this is done only on the basis of a legal permission (e.g., where transmission to a third party, such as a payment service provider, is required for contract performance under Art. 6(1)(b) GDPR), with your consent, under a legal obligation, or on the basis of our legitimate interests (e.g., when using agents, web hosts, etc.).
Where we engage third parties to process data under a data processing agreement, this is done on the basis of Art. 28 GDPR.
Transfers to Third Countries Where we process data in a third country (i.e., outside the European Union or the European Economic Area), or where this occurs in the context of using third-party services or disclosing or transferring data to third parties, this only takes place where necessary to fulfill our (pre-)contractual obligations, on the basis of your consent, under a legal obligation, or on the basis of our legitimate interests. Subject to legal or contractual permissions, we process or have data processed in a third country only where the specific conditions of Art. 44 et seq. GDPR are met — for example, on the basis of specific guarantees such as an officially recognized determination of a level of data protection equivalent to that of the EU (e.g., for the USA via the “Privacy Shield”) or compliance with officially recognized specific contractual obligations (so-called “standard contractual clauses”).
Rights of Data Subjects You have the right to request confirmation as to whether relevant data is being processed, and to obtain information about that data as well as further details and a copy of the data, in accordance with Art. 15 GDPR.
You have the right under Art. 16 GDPR to request the completion of data concerning you or the correction of inaccurate data concerning you.
You have the right under Art. 17 GDPR to request the immediate erasure of relevant data, or alternatively, under Art. 18 GDPR, to request a restriction of the processing of that data.
You have the right to receive data concerning you that you have provided to us, in accordance with Art. 20 GDPR, and to request its transmission to other controllers.
You also have the right under Art. 77 GDPR to lodge a complaint with the competent supervisory authority.
Right of Withdrawal You have the right to withdraw consent you have given, in accordance with Art. 7(3) GDPR, with effect for the future.
Right to Object You may object at any time to the future processing of data concerning you in accordance with Art. 21 GDPR. The objection may in particular be directed against processing for direct marketing purposes.
Cookies and Right to Object to Direct Marketing “Cookies” are small files stored on users’ computers. Cookies can store various types of information. A cookie is primarily used to store information about a user (or the device on which the cookie is stored) during or after their visit to an online service. Temporary cookies, also known as “session cookies” or “transient cookies,” are deleted after a user leaves an online service and closes their browser. Such a cookie may store, for example, the contents of a shopping cart or a login status. “Permanent” or “persistent” cookies remain stored even after the browser is closed. For example, a login status may be saved so that users can access it after several days. Cookies may also store user interests used for reach measurement or marketing purposes. “Third-party cookies” are cookies offered by providers other than the controller operating the online service (if only the controller’s own cookies are used, these are called “first-party cookies”).
We may use both temporary and permanent cookies, and we inform you of this in our privacy policy.
If users do not wish to have cookies stored on their device, they are asked to disable the relevant option in their browser’s system settings. Stored cookies can be deleted in the browser’s system settings. Blocking cookies may result in limited functionality of this online service.
A general objection to the use of cookies for online marketing purposes can be made for a wide range of services, especially in the case of tracking, via the US site http://www.aboutads.info/choices/ or the EU site http://www.youronlinechoices.com/. Furthermore, cookies can be blocked by disabling them in the browser settings. Please note that this may mean that not all features of this online service can be used.
You can edit your cookie settings again here! Current status: Accepted
Deletion of Data Data processed by us is deleted or restricted in accordance with Arts. 17 and 18 GDPR. Unless expressly stated in this privacy policy, data stored by us will be deleted as soon as it is no longer required for its intended purpose and there are no statutory retention obligations preventing deletion. Where data is not deleted because it is required for other legally permissible purposes, its processing will be restricted — meaning the data will be blocked and not processed for other purposes. This applies, for example, to data that must be retained for commercial or tax law reasons.
Under German legal requirements, retention applies in particular for 10 years pursuant to §§ 147(1) AO, 257(1) nos. 1 and 4, (4) HGB (books, records, management reports, accounting documents, commercial books, documents relevant to taxation, etc.) and for 6 years pursuant to § 257(1) nos. 2 and 3, (4) HGB (commercial correspondence).
Under Austrian legal requirements, retention applies in particular for 7 years pursuant to § 132(1) BAO (accounting records, vouchers/invoices, accounts, receipts, business papers, records of income and expenditure, etc.), for 22 years in connection with real property, and for 10 years for documents relating to electronically supplied services, telecommunications, broadcasting, and television services provided to non-entrepreneurs in EU member states for which the Mini One Stop Shop (MOSS) scheme is used.
Business-Related Processing In addition, we process — contract data (e.g., subject matter of the contract, duration, customer category) and payment data (e.g., bank details, payment history) from our customers, prospects, and business partners for the purpose of providing contractual services, customer service and care, marketing, advertising, and market research.
Agency Services We process our clients’ data as part of our contractual services, which include conceptual and strategic consulting, campaign planning, software and design development/consulting or maintenance, implementation of campaigns and processes/handling, server administration, data analysis/consulting services, and training services.
In doing so, we process inventory data (e.g., customer master data such as names and addresses), contact data (e.g., email, phone numbers), content data (e.g., text entries, photographs, videos), contract data (e.g., subject matter, duration), payment data (e.g., bank details, payment history), usage and metadata (e.g., for evaluating and measuring the success of marketing activities). We do not generally process special categories of personal data unless they form part of a commissioned processing activity. Data subjects include our clients, prospects, and their customers, users, website visitors, or employees, as well as third parties. The purpose of processing is the provision of contractual services, billing, and customer service. The legal bases for processing arise from Art. 6(1)(b) GDPR (contractual services) and Art. 6(1)(f) GDPR (analysis, statistics, optimization, security measures). We process data necessary for the establishment and performance of contractual services and indicate which data is required. Disclosure to external parties only occurs where necessary in the context of an engagement. When processing data entrusted to us within the scope of an engagement, we act in accordance with the instructions of our clients and the statutory requirements for commissioned processing under Art. 28 GDPR, and we do not process data for any purposes other than those specified in the engagement.
We delete data after the expiry of statutory warranty and comparable obligations. The need to retain data is reviewed every three years; in the case of statutory archiving obligations, deletion takes place after those periods expire (6 years pursuant to § 257(1) HGB, 10 years pursuant to § 147(1) AO). In the case of data disclosed to us by the client in the context of an engagement, we delete it in accordance with the requirements of the engagement, generally upon its conclusion.
Contractual Services We process the data of our contractual partners and interested parties, as well as other principals, customers, clients, or contracting parties (collectively referred to as “contractual partners”) in accordance with Art. 6(1)(b) GDPR, in order to provide them with our contractual or pre-contractual services. The data processed, its type, scope, purpose, and the necessity of its processing are determined by the underlying contractual relationship.
Data processed includes the master data of our contractual partners (e.g., names and addresses), contact data (e.g., email addresses and phone numbers), contract data (e.g., services used, contract content, contractual correspondence, names of contact persons), and payment data (e.g., bank details, payment history).
We do not generally process special categories of personal data unless they form part of a commissioned or contractually required processing activity.
We process data that is necessary for the establishment and performance of contractual services and indicate its necessity where this is not self-evident to contractual partners. Disclosure to external persons or companies only occurs where required in the context of a contract. When processing data entrusted to us within the scope of an engagement, we act in accordance with the instructions of our clients and statutory requirements.
In the context of using our online services, we may store the IP address and the time of the respective user action. Storage is carried out on the basis of our legitimate interests, as well as the interests of users in protection against misuse and unauthorized use. These data are generally not passed on to third parties unless required to pursue our claims under Art. 6(1)(f) GDPR or there is a legal obligation under Art. 6(1)(c) GDPR.
Data is deleted when it is no longer needed to fulfill contractual or statutory duties of care and to handle any warranty or comparable obligations, with the necessity of retaining data reviewed every three years; otherwise, the statutory retention obligations apply.
Administration, Financial Accounting, Office Organization, Contact Management We process data in the context of administrative tasks and the organization of our operations, financial accounting, and compliance with legal obligations, such as archiving. In doing so, we process the same data that we process in the context of providing our contractual services. The legal bases are Art. 6(1)(c) GDPR and Art. 6(1)(f) GDPR. Those affected include customers, prospects, business partners, and website visitors. The purpose and our interest in the processing lies in administration, financial accounting, office organization, and data archiving — tasks that serve to maintain our business operations, fulfill our duties, and provide our services. Deletion of data with regard to contractual services and contractual correspondence follows the details provided for those processing activities.
We disclose or transfer data to financial authorities, advisors such as tax consultants or auditors, as well as other fee-charging bodies and payment service providers.
We also store information about suppliers, organizers, and other business partners on the basis of our commercial interests — for example, for the purpose of later contact. We generally store this predominantly business-related data on a permanent basis.
Business Analysis and Market Research In order to operate our business commercially and to identify market trends, wishes of contractual partners and users, we analyze the data available to us relating to business transactions, contracts, inquiries, etc. We process inventory data, communication data, contract data, payment data, usage data, and metadata on the basis of Art. 6(1)(f) GDPR; data subjects include contractual partners, prospects, customers, visitors, and users of our online services.
The analyses are carried out for the purposes of business evaluation, marketing, and market research. We may take into account the profiles of registered users, including, for example, the services they have used. The analyses serve to improve user-friendliness, optimize our offerings, and enhance business efficiency. They are for internal use only and are not disclosed externally, unless they are anonymized analyses with aggregated figures.
Where such analyses or profiles are personal in nature, they are deleted or anonymized upon termination of the user’s contract, or otherwise two years after the conclusion of the contract. Business-wide analyses and general trend assessments are created anonymously where possible.
Data Protection in the Application Process We process applicant data only for the purpose of and within the scope of the application process, in compliance with applicable legal requirements. Processing of applicant data is carried out to fulfill our (pre-)contractual obligations within the application process as defined in Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR, where data processing is required for us in the context of legal proceedings (in Germany, § 26 BDSG additionally applies).
The application process requires applicants to provide us with their application data. Where we offer an online form, the required applicant data is marked accordingly; otherwise it follows from the job descriptions and generally includes personal details, postal and contact addresses, and the documents belonging to the application, such as a cover letter, CV, and certificates. Applicants may also voluntarily provide additional information.
By submitting their application to us, applicants agree to the processing of their data for the purposes of the application process in the manner and to the extent described in this privacy policy.
Where special categories of personal data within the meaning of Art. 9(1) GDPR are voluntarily disclosed during the application process, their processing is additionally governed by Art. 9(2)(b) GDPR (e.g., health data such as severe disability status or ethnic origin). Where special categories of personal data within the meaning of Art. 9(1) GDPR are requested from applicants during the application process, their processing is additionally governed by Art. 9(2)(a) GDPR (e.g., health data where required for the exercise of a profession).
Where an online form is available, applicants may submit their applications via our website. Data is transmitted to us in encrypted form in accordance with the current state of the art. Applicants may also submit applications by email; however, please note that emails are generally not transmitted in encrypted form and that applicants themselves are responsible for encryption. We therefore cannot assume responsibility for the transmission path of the application between the sender and its receipt on our server, and therefore recommend using an online form or postal submission. Applicants may alternatively send their application by post.
Where an application is successful, the data provided by applicants may be further processed for employment purposes. Otherwise, if the application is unsuccessful, applicant data will be deleted. Applicant data is also deleted if an application is withdrawn, which applicants may do at any time.
Deletion takes place, subject to a justified revocation by the applicant, after a period of six months, so that we may answer any follow-up questions relating to the application and fulfill our obligations under equal treatment legislation. Invoices for any reimbursement of travel expenses are archived in accordance with tax regulations.
Contact When you contact us (e.g., via contact form, email, phone, or social media), the user’s information is processed for the purpose of handling the contact request and its processing pursuant to Art. 6(1)(b) GDPR (within the context of contractual/pre-contractual relationships) and Art. 6(1)(f) GDPR (other inquiries). User data may be stored in a customer relationship management system (“CRM system”) or comparable inquiry management system.
We delete inquiries once they are no longer required. We review necessity every two years; statutory archiving obligations also apply.
Hosting and Email Delivery The hosting services we use serve to provide the following: infrastructure and platform services, computing capacity, storage space and database services, email delivery, security services, and technical maintenance services, which we use for the purpose of operating this online service.
In doing so, we, or our hosting provider, process inventory data, contact data, content data, contract data, usage data, meta and communication data of customers, prospects, and visitors to this online service, on the basis of our legitimate interests in the efficient and secure provision of this online service pursuant to Art. 6(1)(f) GDPR in conjunction with Art. 28 GDPR (conclusion of a data processing agreement).
Collection of Access Data and Log Files We, or our hosting provider, collect data on the basis of our legitimate interests within the meaning of Art. 6(1)(f) GDPR about each access to the server on which this service is hosted (so-called server log files). Access data includes the name of the webpage retrieved, file, date and time of access, volume of data transferred, notification of successful retrieval, browser type and version, the user’s operating system, referrer URL (the previously visited page), IP address, and the requesting provider.
Log file information is stored for security purposes (e.g., for the investigation of abusive or fraudulent activity) for a maximum of 7 days and then deleted. Data whose further retention is required for evidentiary purposes is exempt from deletion until the final resolution of the relevant incident.
Facebook Pixel This website uses the visitor action pixel of Facebook for conversion measurement. The provider of this service is Facebook Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. According to Facebook, the data collected may also be transferred to the USA and other third countries.
This enables tracking of the behavior of site visitors after they have been redirected to the provider’s website by clicking on a Facebook advertisement. This allows the effectiveness of Facebook advertisements to be evaluated for statistical and market research purposes and future advertising measures to be optimized.
The data collected is anonymous to us as the operator of this website; we cannot draw any conclusions about the identity of the users. However, the data is stored and processed by Facebook, so that a connection to the respective user profile is possible, and Facebook may use the data for its own advertising purposes in accordance with the Facebook Data Use Policy. This enables Facebook to display advertisements on Facebook pages and outside of Facebook. This use of data cannot be influenced by us as the website operator.
The use of the Facebook Pixel is based on Art. 6(1)(f) GDPR. The website operator has a legitimate interest in effective advertising measures that include social media. Where corresponding consent has been obtained (e.g., consent to the storage of cookies), processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR; consent may be withdrawn at any time.
Further information on the protection of your privacy can be found in Facebook’s privacy policy: https://de-de.facebook.com/about/privacy/.
You can also deactivate the remarketing function “Custom Audiences” in the advertising settings section at https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen. To do so, you must be logged in to Facebook.
If you do not have a Facebook account, you can opt out of usage-based advertising by Facebook on the website of the European Interactive Digital Advertising Alliance: http://www.youronlinechoices.com/de/praferenzmanagement/.
Online Presence on Social Media We maintain online presences within social networks and platforms in order to communicate with customers, prospects, and users who are active there, and to inform them about our services. When accessing the respective networks and platforms, the terms and conditions and data processing policies of their respective operators apply.
Unless otherwise specified in this privacy policy, we process data of users who communicate with us within social networks and platforms — for example, by posting on our online presences or sending us messages.
Created with Datenschutz-Generator.de by RA Dr. Thomas Schwenke
