Better safe than sorry – data protection
1. Data protection at a glance
Information sheets
The information sheets required under Articles 13 and 21 of the General Data Protection Regulation (GDPR) are available for download here:
Information sheet for applicants
Information sheet for customers and suppliers
General information
The following information provides a simple overview of what happens to your personal data when you visit our website. Personal data is any data that can be used to personally identify you. Detailed information on data protection can be found in our privacy policy, which is linked below.
This privacy policy applies to our website. The privacy policy for mQuest customers and other users (e.g., survey participants) of mQuest services can be found at: https://www.cluetec-audit.de/privacy-statement-mquest
Data collection on our website
Data processing on this website is carried out by the website operator. Their contact details can be found in the legal notice of this website.
How do we collect your data?
Your data is collected in two ways: firstly, when you provide it to us, for example, by entering information into a contact form; and secondly, automatically by our IT systems when you visit our website. This automatically collected data is primarily technical information such as your internet browser, operating system, and the time of your visit. This data is collected automatically as soon as you access our website.
What do we use your data for?
Some of the data is collected to ensure the error-free provision of the website. Other data may be used to analyze your user behavior.
What rights do you have regarding your data?
You have the right to obtain information free of charge at any time regarding the origin, recipients, and purpose of your stored personal data. You also have the right to request the correction, blocking, or deletion of this data. For this purpose, as well as for any further questions regarding data protection, you can contact us at any time at the address provided in the legal notice. Furthermore, you have the right to lodge a complaint with the competent supervisory authority.
Analytics tools and third-party tools
When you visit our website, your browsing behavior may be statistically analyzed. This is primarily done using cookies and so-called analytics programs. The analysis of your browsing behavior is generally anonymous; your browsing behavior cannot be traced back to you. You can object to this analysis or prevent it by not using certain tools. For details, please see our privacy policy under the heading “Third-party modules and analytics tools”.
You can object to this analysis. We will inform you about your options for objecting in this privacy policy.
2. General information and mandatory disclosures
Data protection
The operators of this website take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.
When you use this website, various personal data are collected. Personal data is data that can be used to identify you personally. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this is done.
Please note that data transmission over the internet (e.g., when communicating via email) can have security vulnerabilities. Complete protection of data against access by third parties is not possible.
Note regarding the responsible body
The responsible body for data processing on this website is:
cluetec GmbH
Wilhelm-Schickard-Str. 9
76131 Karlsruhe
Phone: +49 721 83179-0
Email: info@cluetec.de
The responsible entity is the natural or legal person who, alone or jointly with others, decides on the purposes and means of processing personal data (e.g. names, email addresses, etc.).
Revocation of your consent to data processing
Many data processing operations are only possible with your explicit consent. You can revoke your consent at any time. An informal notification by email (datenschutz@cluetec.de) to us is sufficient. The legality of data processing carried out before the revocation remains unaffected by the revocation.
Right to lodge a complaint with the competent supervisory authority
In the event of data protection violations, the data subject has the right to lodge a complaint with the competent supervisory authority. The competent supervisory authority for data protection matters is the State Data Protection Commissioner of the federal state in which our company is based. A list of data protection commissioners and their contact details can be found at the following link: https://www.bfdi.bund.de/DE/Service/Anschriften/anschriften_table.html
SSL or TLS encryption
This site uses SSL/TLS encryption for security reasons and to protect the transmission of confidential information, such as orders or inquiries that you send to us as the site operator. You can recognize an encrypted connection by the fact that the browser’s address bar changes from “http://” to “https://” and by the lock symbol in your browser’s address bar.
If SSL or TLS encryption is activated, the data you send to us cannot be read by third parties.
Information, blocking, deletion
Under applicable law, you have the right to request information, free of charge, about your stored personal data, its origin and recipients, and the purpose of data processing. You also have the right to rectification, blocking, or erasure of this data. For this purpose, and for any further questions regarding personal data, you can contact us at any time at datenschutz@cluetec.de or at the address provided in the legal notice.
Objection to advertising emails
The use of contact details published as part of the legal notice for sending unsolicited advertising and informational materials is hereby prohibited. The operators of these pages expressly reserve the right to take legal action in the event of unsolicited advertising, such as spam emails.
3. Data Protection Officer
Legally required data protection officer
We have appointed a data protection officer for our company.
Thomas Heimhalt | Data Protection perfect GmbH
datenschutz@cluetec.de
4. Data collection on our website
Cookies
These websites sometimes use so-called cookies. Cookies do not harm your computer and do not contain viruses. Cookies serve to make our website more user-friendly, effective, and secure. Cookies are small text files that are stored on your computer and saved by your browser.
Most of the cookies we use are so-called “session cookies.” They are automatically deleted after your visit ends. Other cookies remain stored on your device until you delete them. These cookies allow us to recognize your browser on your next visit.
You can configure your browser to notify you when cookies are set and to allow cookies only in individual cases, to accept cookies in certain cases or to generally reject them, and to automatically delete cookies when you close your browser. Disabling cookies may limit the functionality of this website.
Cookies that are necessary for carrying out electronic communication or for providing certain functions you have requested (e.g., the shopping cart function) are stored on the basis of Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in storing cookies to ensure the technically flawless and optimized provision of its services. Any other cookies (e.g., cookies for analyzing your browsing behavior) are addressed separately in this privacy policy.
Server log files
The website provider automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. This information includes:
- Browser type and browser version
- Operating system used
- Referrer URL
- Hostname of the accessing computer
- Time of server request
- IP address
This data will not be combined with other data sources.
The legal basis for data processing is Art. 6 para. 1 lit. b GDPR, which permits the processing of data for the performance of a contract or pre-contractual measures.
Contact form
If you send us inquiries via the contact form, your information from the inquiry form, including the contact details you provided, will be stored by us for the purpose of processing the inquiry and in case of follow-up questions. We will not share this data without your consent.
The processing of the data entered into the contact form is therefore based solely on your consent (Art. 6 para. 1 lit. a GDPR). You can revoke this consent at any time. An informal notification by email to us is sufficient. The lawfulness of the data processing operations carried out until the revocation remains unaffected by the revocation.
The data you entered in the contact form will remain with us until you request its deletion or revoke your consent to its storage. Mandatory legal provisions – in particular retention periods – remain unaffected.
Processing of data (customer and contract data)
We collect, process, and use personal data only to the extent necessary for establishing, defining the content of, or amending the contractual relationship (master data). This is done on the basis of Article 6(1)(b) GDPR, which permits the processing of data for the performance of a contract or for taking steps prior to entering into a contract. We collect, process, and use personal data relating to the use of our website (usage data) only to the extent necessary to enable the user to access the service or for billing purposes.
The collected customer data will be deleted after completion of the order or termination of the business relationship. Statutory retention periods remain unaffected.
Hubspot CRM
We use HubSpot CRM on this website. The provider is HubSpot Inc., 25 Street, Cambridge, MA 02141 USA (hereinafter referred to as HubSpot CRM). HubSpot CRM allows us, among other things, to manage existing and potential customers and customer contacts. With the help of HubSpot CRM, we are able to record, sort, and analyze customer interactions via email, social media, or telephone across various channels. The personal data collected in this way can be evaluated and used for communication with potential customers or for marketing activities (e.g., newsletter mailings). HubSpot CRM also allows us to record and analyze the user behavior of our contacts on our website. The use of HubSpot CRM is based on Article 6 Paragraph 1 Letter f GDPR. The website operator has a legitimate interest in the most efficient possible customer management and communication. If consent has been requested, processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a GDPR and Section 25 para. 1 TDDDG, insofar as the consent includes the storage of cookies or access to information on the user’s device (e.g., device fingerprinting) within the meaning of the TDDDG. Consent can be withdrawn at any time.
For details, please refer to HubSpot’s privacy policy: The selected server location is in Europe. If data is transferred to the USA, it will be based on the EU Commission’s Standard Contractual Clauses. Details can be found here.
The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF is obligated to adhere to these data protection standards. Further information is available from the provider via this link.
Order processing HubSpot
We have concluded a data processing agreement (DPA) for the use of the aforementioned service. This is a legally required contract under data protection law, which ensures that the service provider processes the personal data of our website visitors only according to our instructions and in compliance with the GDPR.
5. Social Media
LinkedIn Plugin
Our website uses features of the LinkedIn network. The provider is LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA. Each time you access one of our pages containing LinkedIn features, a connection to LinkedIn’s servers is established. LinkedIn is then informed that you have visited our website with your IP address. If you click the LinkedIn “Recommend” button and are logged into your LinkedIn account, LinkedIn can associate your visit to our website with you and your user account. Please note that as the website provider, we have no knowledge of the content of the transmitted data or its use by LinkedIn. Further information can be found in LinkedIn’s privacy policy at:
https://www.linkedin.com/legal/privacy-policy
6. Analytics Tools and Advertising
Google Analytics
This website uses functions of the web analytics service Google Analytics. The provider is Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
Google Analytics uses so-called “cookies.” These are text files that are stored on your computer and enable an analysis of your use of the website. The information generated by the cookie about your use of this website is generally transmitted to and stored on a Google server in the USA.
The storage of Google Analytics cookies is based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in analyzing user behavior in order to optimize both its website and its advertising.
IP anonymization
We have activated the IP anonymization function on this website. This means that your IP address is shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area before being transmitted to the USA. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and used there to evaluate your use of the website, to compile reports on website activity, and to provide other services relating to website activity and internet usage to the website operator. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.
Browser Plugin
You can prevent the storage of cookies by adjusting your browser settings; however, please note that in this case you may not be able to fully utilize all the functions of this website. Furthermore, you can prevent Google from collecting and processing data generated by the cookie and related to your use of the website (including your IP address) by downloading and installing the browser plugin available at the following link:
https://tools.google.com/dlpage/gaoptout?hl=de
Objection to data collection: You can prevent the collection of your data by Google Analytics by clicking on the following link. An opt-out cookie will be set, which prevents the collection of your data on future visits to this website. Under section 8. Plugins and Tools, you can edit or revoke your consent. More information on how Google Analytics handles user data can be found in Google’s privacy policy: https://policies.google.com/privacy
We have concluded a data processing agreement with Google and fully implement the strict requirements of the German data protection authorities when using Google Analytics.
Google Tag Manager
We use the service called Google Tag Manager from Google. “Google” is a group of companies consisting of Google Ireland Ltd. (provider of the service), Gordon House, Barrow Street, Dublin 4, Ireland, and Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, as well as other affiliated companies of Google LLC.
We have entered into a data processing agreement with Google.
The Google Tag Manager is a support service and only processes personal data for technically necessary purposes. The Google Tag Manager ensures the loading of other components, which may in turn collect data. The Google Tag Manager does not access this data. Further information about the Google Tag Manager can be found in Google’s privacy policy: policies.google.com/privacy
Please note that American authorities, such as intelligence agencies, may have access to personal data that is inevitably exchanged with Google when integrating this service due to the Internet Protocol (TCP), because of American laws such as the Cloud Act.
Lead Forensics
For marketing and optimization purposes, this website uses products and services from LeadForensics (Communication House, 26 York Street, London, W1U 6PZ, United Kingdom). LeadForensics tracks your actual browsing activity on this website, including all pages you visit and view, and how long you spend on each page. If IP addresses are collected, they are anonymized immediately after collection. On behalf of the operator of this website, LeadForensics will use the collected information to analyze your website visit, compile reports on website activity, and provide other services related to website and internet usage to the website operator.
Further information on data protection can be found at: https://www.leadforensics.com/privacy-andcookies/.
Soweit wir hierbei personenbezogene Daten verarbeiten, tun wir dies aufgrund unserer berechtigten Interessen zur besseren Gestaltung unserer Website. Rechtsgrundlage ist die Wahrung der berechtigten Interessen gemäß Art. 6 Abs. 1 Buchstabe f) DSGVO. Sie können der Datenverarbeitung jederzeit mit Wirkung für die Zukunft durch einen Klick auf You can object to this by clicking this link. We will then no longer store any additional data.
Leadinfo
We use the lead generation service from Leadinfo B.V., Rotterdam, Netherlands. This service identifies visits from companies to our website based on IP addresses and displays publicly available information such as company names and addresses. Leadinfo also sets two first-party cookies to analyze user behavior on our website and processes domains from form entries (e.g., “leadinfo.com”) to correlate IP addresses with companies and improve its services.
Further information can be found at www.leadinfo.com. You have the option to opt out on this page: www.leadinfo.com/en/opt-out. If you opt out, Leadinfo will no longer collect your data.
Newsletter
Newsletter data
If you wish to subscribe to the newsletter offered on this website, we require your email address and information that allows us to verify that you are the owner of the email address provided and that you agree to receive the newsletter. No further data is collected, or only on a voluntary basis. We use this data exclusively for sending the requested information and do not share it with third parties.
The processing of the data entered in the newsletter registration form is based solely on your consent (Art. 6 para. 1 lit. a GDPR). You can revoke your consent to the storage of your data, your email address, and its use for sending the newsletter at any time, for example, via the “Unsubscribe” link in the newsletter. The lawfulness of the data processing operations already carried out remains unaffected by the revocation.
The data you provided for the purpose of subscribing to our newsletter will be stored by us until you unsubscribe and will be deleted after you unsubscribe. Data stored for other purposes (e.g., email addresses for the members’ area) will remain unaffected.
8. Plugins and Tools
YouTube
Our website uses plugins from the Google-operated site YouTube. The operator of the site is YouTube, LLC, 901 Cherry Ave., San Bruno, CA 94066, USA.
When you visit one of our pages that includes a YouTube plugin, a connection is established to YouTube’s servers. This informs the YouTube server which of our pages you have visited.
If you are logged into your YouTube account, you are allowing YouTube to directly associate your browsing behavior with your personal profile. You can prevent this by logging out of your YouTube account.
The use of YouTube is in the interest of presenting our online content in an appealing way. This constitutes a legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR.
This website embeds videos from YouTube. The operator of the site is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
We use YouTube in enhanced privacy mode. According to YouTube, this mode prevents YouTube from storing information about visitors to this website before they watch the video. However, enhanced privacy mode does not necessarily prevent data from being shared with YouTube partners. For example, YouTube establishes a connection to the Google DoubleClick network regardless of whether you watch a video.
Further information on how user data is handled can be found in YouTube’s privacy policy at: https://www.google.de/intl/de/policies/privacy
Google Web Fonts (local hosting)
This website uses web fonts provided by Google for consistent font display. The Google Fonts are installed locally. No connection to Google servers is established.
Google DoubleClick
This website uses features of Google DoubleClick. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter “DoubleClick”).
DoubleClick is used to show you interest-based ads across the Google advertising network. With DoubleClick, these ads can be tailored to the interests of each individual viewer. For example, our ads may appear in Google search results or in banner ads connected to DoubleClick.
To show users interest-based ads, DoubleClick needs to recognize each viewer and associate them with the websites they visit, clicks, and other information about their user behavior. DoubleClick uses cookies or similar recognition technologies (e.g., device fingerprinting) for this purpose.
Google Photos (ggpht.com)
Our website loads a web service from Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter: ggpht.com).
We use this data to ensure the full functionality of our website. In this context, your browser may transmit personal data to ggpht.com.
The legal basis for data processing is Article 6(1)(f) GDPR. The legitimate interest lies in ensuring the website functions correctly. If consent has been requested, processing is carried out exclusively on the basis of Article 6(1)(a) GDPR; this consent can be withdrawn at any time.
The data will be deleted as soon as the purpose for which it was collected has been fulfilled. Further information on the handling of the transferred data can be found in the privacy policy of ggpht.com: www.google.com/intl/de/policies/privacy/.
You can prevent ggpht.com from collecting and processing your data by disabling the execution of script code in your browser or by installing a script blocker in your browser (you can find these, for example, at www.noscript.net or www.ghostery.com).
Microsoft Bookings
Our website uses the Microsoft Bookings service (part of Microsoft Office 365) from Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18 D18 P521 (hereinafter: “Microsoft”) for online appointment scheduling. This software allows you to book a telephone appointment with one of our employees (e.g., for a consultation before and/or after signing a contract). A connection to the service is only established when you access the online booking function via a link or button on our website, in an email, or in our newsletter.
For appointment scheduling, your entries in the appointment scheduling form will be transmitted to Microsoft. Further information on how your data is handled can be found in Microsoft’s privacy statement. The legal basis for processing your data in relation to the “Microsoft Bookings” service is Article 6(1)(f) GDPR (legitimate interest in data processing).
Our legitimate interest arises from our commitment to providing you with a user-friendly website offering a wide range of functions and enabling you to quickly and easily schedule an appointment with our staff whenever needed. Please note that you are not obligated to use Microsoft Bookings to schedule an appointment. If you prefer not to use this service, please use one of the other contact options provided to schedule an appointment.
9. Handling of applicant data
We offer you the opportunity to apply to us (e.g., by email, post, or via our online application form). Below, we inform you about the scope, purpose, and use of your personal data collected during the application process. We assure you that the collection, processing, and use of your data will be carried out in accordance with applicable data protection law and all other legal provisions, and that your data will be treated with strict confidentiality.
Scope and purpose of data collection
Wenn Sie uns eine Bewerbung zukommen lassen, verarbeiten wir Ihre damit verbundenen personenbezogenen Daten (z. B. Kontakt- und Kommunikationsdaten, Bewerbungsunterlagen, Notizen im Rahmen von Bewerbungsgesprächen etc.), soweit dies zur Entscheidung über die Begründung eines Beschäftigungsverhältnisses erforderlich ist. Rechtsgrundlage hierfür ist § 26 BDSG nach deutschem Recht (Anbahnung eines Beschäftigungsverhältnisses), Art. 6 Abs. 1 lit. b DSGVO (allgemeine Vertragsanbahnung) und – sofern Sie eine Einwilligung erteilt haben – Art. 6 Abs. 1 lit. a DSGVO. Die Einwilligung ist jederzeit widerrufbar. Ihre personenbezogenen Daten werden innerhalb unseres Unternehmens ausschließlich an Personen weitergegeben, die an der Bearbeitung Ihrer Bewerbung beteiligt sind.
If your application is successful, the data you have submitted will be stored in our data processing systems on the basis of Section 26 BDSG and Article 6 Paragraph 1 Letter b GDPR for the purpose of carrying out the employment relationship.
Data retention period
If we are unable to offer you a position, you decline a job offer, or you withdraw your application, we reserve the right to retain the data you submitted for up to six months from the conclusion of the application process (rejection or withdrawal of the application) based on our legitimate interests (Art. 6 para. 1 lit. f GDPR). After this period, the data will be deleted and any physical application documents destroyed. This retention serves, in particular, as evidence in the event of legal proceedings. If it becomes apparent that the data will be required after the six-month period (e.g., due to threatened or pending legal proceedings), deletion will only occur once the purpose for the extended retention no longer applies.
Longer storage may also take place if you have given your consent (Art. 6 para. 1 lit. a GDPR) or if statutory retention obligations preclude deletion.
Inclusion in the applicant pool
If we do not make you a job offer, we may be able to add you to our applicant pool. If you are added, all documents and information from your application will be transferred to the applicant pool so that we can contact you if suitable vacancies arise.
Inclusion in the applicant pool is based solely on your explicit consent (Art. 6 para. 1 lit. a GDPR). Providing this consent is voluntary and is not related to the current application process. You may withdraw your consent at any time. In this case, your data will be permanently deleted from the applicant pool, unless there are legal retention requirements.
The data from the applicant pool will be irrevocably deleted no later than two years after consent has been given.