This data protection declaration informs you about the nature, scope and purpose of the processing of personal data (hereinafter referred to as “data”) within our online offer and the websites, functions and content associated with it, as well as external online presences, such as our social media profiles (hereinafter collectively referred to as “online offer”). With regard to the terminology used, such as “processing” or “responsible party”, we refer to the definitions in Article 4 of the General Data Protection Regulation (DSGVO).

Controller’s name and address

Setlog GmbH
Alleestrasse 80
44793 Bochum
GERMANY

T: +49 234 720 285 00
F: +49 234 720 285 99
info@setlog.com

Managing Directors
Ralf Düster, Guido Brackelsberg, Dmitry Chaykin

Headquarters of the company
Bochum
HRB 8032 Local Court Bochum

VAT ID No. DE 314 083 513

If you have any questions about our privacy policy, please feel free to send us an e-mail to the following address:

datenschutz@setlog.com

PRIVACY POLICY

We are very pleased about your interest in our company. Data protection has a particularly high priority for Setlog GmbH. The use of the Internet pages of the Setlog GmbH is possible without any indication of personal data. However, if a data subject wants to use special services of our enterprise via our website, processing of personal data could become necessary. If processing of personal data is necessary and there is no legal basis for such processing, we will generally obtain the consent of the data subject.

The processing of personal data, such as the name, address, e-mail address, or telephone number of a data subject shall always be in line with the General Data Protection Regulation, and in accordance with the country-specific data protection regulations applicable to the Setlog GmbH. By means of this data protection declaration, our company would like to inform the public about the nature, scope and purpose of the personal data we collect, use and process. Furthermore, data subjects are informed of their rights by means of this data protection declaration.

As the controller, the Setlog GmbH has implemented numerous technical and organizational measures to ensure the most complete protection of personal data processed through this website. Nevertheless, Internet-based data transmissions can always be subject to security vulnerabilities, so that absolute protection cannot be guaranteed. For this reason, every data subject is free to transmit personal data to us by alternative means, for example by telephone.

  1. Definitions

The data protection declaration of the Setlog GmbH is based on the notions used by the European Directive and Ordinance when issuing the Data Protection Regulation (DS-GVO). Our privacy policy should be easy to read and understand for the public as well as for our customers and business partners. To ensure this, we would like to explain the terminology used in advance.

We use the following terms, among others, in this data protection declaration:

a) personal data

Personal data is any information relating to an identified or identifiable natural person (hereinafter “data subject”). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

b) Data subject

Data subject means any identified or identifiable natural person whose personal data are processed by the controller.

c) Processing

Processing means any operation or set of operations which is performed upon personal data, whether or not by automatic means, such as collection, recording, organization, filing, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

d) Restriction of processing

Restriction of processing is the marking of stored personal data with the aim of limiting their future processing.

e) Profiling

Profiling is any type of automated processing of personal data that consists of using such personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects relating to that natural person’s job performance, economic situation, health, personal preferences, interests, reliability, behavior, location or change of location.

f) Pseudonymization

Pseudonymization is the processing of personal data in such a way that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separate and is subject to technical and organizational measures to ensure that the personal data is not attributed to an identified or identifiable natural person.

g) Controller or person responsible for processing.

The controller or person responsible for processing is the natural or legal person, public authority, agency or other body which alone or jointly with others determines the purposes and means of the processing of personal data. Where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its designation may be provided for under Union or Member State law.

h) Processor

Processor means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the Controller.

i) Recipient

Recipient means a natural or legal person, public authority, agency or other body to whom personal data are disclosed, whether or not a third party. However, public authorities that may receive Personal Data in the context of a specific investigative task under Union or Member State law shall not be considered as recipients.

j) Third Party

Third party means a natural or legal person, public authority, agency or other body other than the data subject, the controller, the processor and the persons authorized to process the personal data under the direct responsibility of the controller or the processor.

k) Consent

Consent shall mean any freely given indication of the data subject’s wishes for the specific case in an informed and unambiguous manner, in the form of a declaration or any other unambiguous affirmative act by which the data subject indicates that he or she consents to the processing of personal data relating to him or her.

  1. Name and address of the controller

The controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and other provisions of a data protection nature is:

Setlog GmbH
Alleestrasse 80
44793 Bochum
Germany
Phone: +49 234 720 285 78
E-Mail: info@setlog.com
Website: http://www.setlog.com

  1. Right of revocation 

You have the right to revoke given consents in accordance with Art. 7 (3) DSGVO with effect for the future.

  1. Right of objection

You may object to the future processing of data concerning you in accordance with Art. 21 DSGVO at any time. The objection can be made in particular against the processing for purposes of direct advertising.

    5. Cookies

The internet pages of Setlog GmbH use cookies. Cookies are text files that are placed and stored on a computer system via an Internet browser.

Numerous Internet sites and servers use cookies. Many cookies contain a so-called cookie ID. A cookie ID is a unique identifier of the cookie. It consists of a string of characters by which Internet pages and servers can be assigned to the specific Internet browser in which the cookie was stored. This enables the visited Internet pages and servers to distinguish the individual browser of the data subject from other Internet browsers that contain other cookies. A specific internet browser can be recognized and identified via the unique cookie ID.

Through the use of cookies, the Setlog GmbH can provide the users of this website with more user-friendly services that would not be possible without the cookie setting.

By means of a cookie, the information and offers on our website can be optimized for the user. Cookies enable us, as already mentioned, to recognize the users of our website. The purpose of this recognition is to make it easier for users to use our website.

The data subject can prevent the setting of cookies by our website at any time by means of an appropriate setting of the Internet browser used and thus permanently object to the setting of cookies. Furthermore, cookies that have already been set can be deleted at any time via an Internet browser or other software programs. This is possible in all common Internet browsers. If the data subject deactivates the setting of cookies in the Internet browser used, not all functions of our website may be fully usable.

The following cookie types and functions are distinguished:

– Necessary cookies: on the one hand, cookies may be absolutely necessary for the operation of a website (e.g. to store user input or for security reasons).

– Statistical, marketing and personalization cookies: Furthermore, cookies are generally also used in the context of range measurement and when a user’s interests or behavior (e.g. viewing certain content, using functions, etc.) on individual websites are stored in a user profile. Such profiles are used, for example, to show users content that matches their potential interests. This process is also referred to as “tracking”, i.e., tracking the potential interests of users. Insofar as we use cookies or “tracking” technologies, we will inform you separately in our privacy policy or in the context of obtaining consent.

  1. Hosting and e-mail dispatch

The hosting services used by us serve to provide the following services: Infrastructure and platform services, computing capacity, storage space and database services, e-mail dispatch, security services and technical maintenance services, which we use for the purpose of operating this online offer.

In doing so, we, or our hosting provider, process inventory data, contact data, content data, contract data, usage data, meta data and communication data of customers, interested parties and visitors of this online offer on the basis of our legitimate interests in an efficient and secure provision of this online offer pursuant to Art. 6 (1) lit. f DSGVO in conjunction with Art. 28 DSGVO. Art. 28 DSGVO (conclusion of order processing contract).

  1. Online presences in social media

We maintain online presences within social networks and platforms in order to be able to communicate with customers, interested parties and users active there and to inform them about our services there. When calling up the respective networks and platforms, the terms and conditions and data processing policies of their respective operators apply.

Unless otherwise stated in our privacy policy, we process the data of users insofar as they communicate with us within the social networks and platforms, e.g. write posts on our online presences or send us messages.

 a) Youtube

We integrate the videos of the platform “YouTube” of the provider Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Privacy policy: https://www.google.com/policies/privacy/, Opt-Out: https://adssettings.google.com/authenticated.

 b) Use of Facebook social plugins

We use on the basis of our legitimate interests (i.e. interest in the analysis, optimization and economic operation of our online offer within the meaning of Art. 6 para. 1 lit. f. DSGVO) social plugins (“plugins”) of the social network facebook.com, which is operated by Facebook Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (“Facebook”). The plugins can display interaction elements or content (e.g. videos, graphics or text contributions) and are recognizable by one of the Facebook logos (white “f” on blue tile, the terms “Like”, “Like” or a “thumbs up” sign) or are marked with the addition “Facebook Social Plugin”. The list and appearance of Facebook social plugins can be viewed here: https://developers.facebook.com/docs/plugins/.

Facebook is certified under the Privacy Shield agreement and thereby offers a guarantee of compliance with European data protection law (https://www.privacyshield.gov/participant?id=a2zt0000000GnywAAC&status=Active).

When a user calls up a function of this online offering that contains such a plugin, his or her device establishes a direct connection with the Facebook servers. The content of the plugin is transmitted by Facebook directly to the user’s device and integrated into the online offer by the latter. In the process, usage profiles of the users can be created from the processed data. We therefore have no influence on the scope of the data that Facebook collects with the help of this plugin and therefore inform users according to our level of knowledge.

By integrating the plugins, Facebook receives the information that a user has accessed the corresponding page of the online offer. If the user is logged into Facebook, Facebook can assign the visit to his Facebook account. If users interact with the plugins, for example by clicking the Like button or posting a comment, the corresponding information is transmitted from your device directly to Facebook and stored there. If a user is not a member of Facebook, there is still the possibility that Facebook will learn and store his or her IP address. According to Facebook, only an anonymized IP address is stored in Germany.

The purpose and scope of the data collection and the further processing and use of the data by Facebook, as well as the related rights and settings options for protecting the privacy of users, can be found in Facebook’s privacy policy: https://www.facebook.com/about/privacy/.

If a user is a Facebook member and does not want Facebook to collect data about him or her via this online offer and link it to his or her membership data stored on Facebook, he or she must log out of Facebook and delete his or her cookies before using our online offer. Further settings and objections to the use of data for advertising purposes, are possible within the Facebook profile settings: https://www.facebook.com/settings?tab=ads or via the US site http://www.aboutads.info/choices/ or the EU site http://www.youronlinechoices.com/. The settings are platform-independent, i.e. they are applied to all devices, such as desktop computers or mobile devices.

c) Twitter

Within our online offer, functions and contents of the service Twitter, offered by Twitter Inc., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA, can be integrated. This may include, for example, content such as images, videos or texts and buttons with which users can announce their liking of the content, the authors of the content or subscribe to our posts. If the users are members of the Twitter platform, Twitter can assign the call of the above-mentioned content and functions to the profiles of the users there. Twitter is certified under the Privacy Shield agreement and thereby offers a guarantee of compliance with European data protection law (https://www.privacyshield.gov/participant?id=a2zt0000000TORzAAO&status=Active).

Privacy policy: https://twitter.com/de/privacy,

Opt-out: https://twitter.com/personalization.

 d) Instagram

Within our online offer, functions and contents of the service Instagram, offered by Instagram Inc., 1601 Willow Road, Menlo Park, CA, 94025, USA, may be integrated. This may include, for example, content such as images, videos or texts and buttons with which users can make known their liking regarding the content, the authors of the content or subscribe to our posts. If the users are members of the Instagram platform, Instagram can assign the call of the above-mentioned content and functions to the profiles of the users there. Privacy policy of Instagram: http://instagram.com/about/legal/privacy/.

 e) Xing

Within our online offer, functions and contents of the service Xing, offered by XING AG, Dammtorstraße 29-32, 20354 Hamburg, Germany, may be integrated. This may include, for example, content such as images, videos or texts and buttons with which users can make known their liking regarding the content, the authors of the content or subscribe to our posts. If the users are members of the Xing platform, Xing can assign the call of the above-mentioned content and functions to the profiles of the users there. Privacy policy of Xing: https://www.xing.com/app/share?op=data_protection.

 f) LinkedIn

Within our online offer, functions and content of the service LinkedIn, offered by inkedIn Ireland Unlimited Company Wilton Place, Dublin 2, Ireland, may be integrated. This may include, for example, content such as images, videos or texts and buttons with which users can announce their liking of the content, the authors of the content or subscribe to our posts. If the users are members of the LinkedIn platform, LinkedIn can assign the call of the above content and functions to the profiles of the users there. Privacy policy of LinkedIn: https://www.linkedin.com/legal/privacy-policy.. LinkedIn is certified under the Privacy Shield agreement and thereby offers a guarantee of compliance with European data protection law (https://www.privacyshield.gov/participant?id=a2zt0000000L0UZAA0&status=Active).

Privacy policy: https://www.linkedin.com/legal/privacy-policy, Opt-Out: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.

  1. collection of general data and information

The website of the Setlog GmbH collects a series of general data and information with each call-up of the website by a data subject or automated system. This general data and information is stored in the log files of the server. The following data may be collected: (1) the browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our website (so-called referrer), (4) the sub-websites that are accessed via an accessing system on our website, (5) the date and time of an access to the website, (6) an Internet protocol address (IP address), (7) the Internet service provider of the accessing system and (8) other similar data and information that serve to avert danger in the event of attacks on our information technology systems.

When using these general data and information, the Setlog GmbH does not draw any conclusions about the data subject. Rather, this information is needed (1) to deliver the contents of our website correctly, (2) to optimize the contents of our website and the advertising for these, (3) to ensure the long-term functionality of our information technology systems and the technology of our website, and (4) to provide law enforcement authorities with the information necessary for prosecution in the event of a cyber attack. Therefore, the Setlog GmbH analyzes anonymously collected data and information on one hand, and on the other hand, with the aim of increasing the data protection and data security of our enterprise so that we can ultimately ensure an optimal level of protection for the personal data we process. The anonymous data of the server log files are stored separately from any personal data provided by a data subject.

  1. Subscription to our newsletter

On the website of the Setlog GmbH, users are given the opportunity to subscribe to our enterprise’s newsletter. The personal data transmitted to the controller when the newsletter is subscribed to is specified in the input mask used for this purpose.

The dispatch of the newsletter takes place by means of the dispatch service provider Hubspot. The dispatch service provider is used on the basis of our legitimate interests pursuant to Art. 6 para. 1 lit. f DSGVO and an order processing agreement pursuant to Art. 28 para. 3 p. 1 DSGVO.

The Setlog GmbH informs its customers and business partners at regular intervals by means of a newsletter about enterprise offers. In principle, the data subject may only receive our enterprise’s newsletter if (1) the data subject has a valid e-mail address and (2) the data subject registers for the newsletter mailing. For legal reasons, a confirmation e-mail will be sent to the e-mail address entered by a data subject for the first time for newsletter dispatch using the double opt-in procedure. This confirmation e-mail serves to verify whether the owner of the e-mail address as the data subject has authorized the receipt of the newsletter.

When registering for the newsletter, we also store the IP address of the computer system used by the data subject at the time of registration, as assigned by the Internet service provider (ISP), as well as the date and time of registration. The collection of this data is necessary in order to be able to trace the (possible) misuse of the e-mail address of a data subject at a later point in time and therefore serves the legal safeguarding of the controller.

The personal data collected in the context of a registration for the newsletter will be used exclusively for sending our newsletter. Furthermore, subscribers to the newsletter could be informed by e-mail if this is necessary for the operation of the newsletter service or a related registration, as could be the case in the event of changes to the newsletter offer or changes in the technical circumstances. No personal data collected as part of the newsletter service will be passed on to third parties. The subscription to our newsletter can be cancelled by the data subject at any time. The consent to the storage of personal data that the data subject has given us for the newsletter mailing can be revoked at any time. For the purpose of revoking consent, a corresponding link can be found in each newsletter. Furthermore, it is possible to cancel the subscription to the newsletter at any time by e-mail. Please send your cancellation to the following e-mail address: info@setlog.com. We will then immediately delete your data in connection with the newsletter dispatch.

      10. Newsletter tracking

The newsletters of Setlog GmbH contain so-called tracking pixels. A tracking pixel is a miniature graphic that is embedded in such emails that are sent in HTML format to enable log file recording and log file analysis. This enables a statistical evaluation of the success or failure of online marketing campaigns. Based on the embedded tracking pixel, the Setlog GmbH may see if and when an e-mail was opened by a data subject, and which links in the e-mail were called up by the data subject.

Such personal data collected via the tracking pixels contained in the newsletters are stored and analyzed by the controller in order to optimize the newsletter dispatch and to better tailor the content of future newsletters to the interests of the data subject. This personal data will not be disclosed to third parties. Data subjects are entitled at any time to revoke the separate declaration of consent given in this regard via the double opt-in procedure. After revocation, this personal data will be deleted by the controller. The Setlog GmbH automatically regards a withdrawal from the receipt of the newsletter as a revocation.

  1. Contact possibility via the website

Based on statutory provisions, the website of the Setlog GmbH contains information that enables a quick electronic contact to our enterprise, as well as direct communication with us, which also includes a general address of the so-called electronic mail (e-mail address). If a data subject contacts the controller by e-mail or by using a contact form, the personal data transmitted by the data subject will be stored automatically. Such personal data transmitted on a voluntary basis by a data subject to the controller will be stored for the purposes of processing or contacting the data subject. No disclosure of this personal data to third parties will take place.

  1. Web analysis

       a.) Google Analytics

This website uses Google Analytics, a web analytics service provided by Google, Inc. (“Google”). Google Analytics uses “cookies”, which are text files placed on your computer, to help the website analyze how users use the site. The information generated by the cookie about your use of this website is usually transmitted to a Google server in the USA and stored there. In the event that IP anonymization is activated on this website, however, your IP address will be truncated beforehand by Google within member states of the European Union or in other contracting states to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. On behalf of the operator of this website, Google will use this information for the purpose of evaluating your use of the website, compiling reports on website activity and providing other services relating to website activity and internet usage to the website operator. The IP address transmitted by your browser as part of Google Analytics will not be merged with other data from Google.

You may refuse the use of cookies by selecting the appropriate settings on your browser, however please note that if you do this you may not be able to use the full functionality of this website. You can also prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) to Google and the processing of this data by Google by downloading and installing the browser plugin available at the following link: http://tools.google.com/dlpage/gaoptout?hl=de.

  b.) Google Re/Marketing Services

We use on the basis of our legitimate interests (i.e. interest in the analysis, optimization and economic operation of our online offer within the meaning of Art. 6 para. 1 lit. f. DSGVO) the marketing and remarketing services (in short “Google Marketing Services”) of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, (“Google”).

Google is certified under the Privacy Shield agreement and thereby offers a guarantee of compliance with European data protection law (https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active).

Google’s marketing services allow us to display advertisements for and on our website in a more targeted manner in order to present users only with ads that potentially match their interests. If, for example, a user is shown ads for products he or she was interested in on other websites, this is referred to as “remarketing”. For these purposes, when our website and other websites on which Google marketing services are active are called up, a code is executed directly by Google and so-called (re)marketing tags (invisible graphics or code, also referred to as “pixels”) are integrated into the website. With their help, an individual cookie, i.e. a small file, is stored on the user’s device (comparable technologies can also be used instead of cookies). The cookies can be set by various domains, including google.com, doubleclick.net, invitemedia.com, admeld.com, googlesyndication.com or googleadservices.com. This file records which websites the user has visited, which content he is interested in and which offers he has clicked on, as well as technical information on the browser and operating system, referring websites, time of visit and other information on the use of the online offer. The IP address of the user is also recorded, whereby we inform Google Analytics that the IP address is shortened within Member States of the European Union or in other contracting states to the Agreement on the European Economic Area and only in exceptional cases is transferred in full to a Google server in the USA and shortened there. The IP address will not be merged with data of the user within other offers of Google. The aforementioned information may also be linked on the part of Google with such information from other sources. If the user subsequently visits other websites, he can be shown ads tailored to his interests.

The user’s data is processed pseudonymously as part of Google’s marketing services. This means that Google does not store and process the name or e-mail address of the user, for example, but processes the relevant data on a cookie basis within pseudonymous user profiles. I.e. from Google’s perspective, the ads are not managed and displayed for a specifically identified person, but for the cookie holder, regardless of who this cookie holder is. This does not apply if a user has expressly allowed Google to process the data without this pseudonymization. The information collected by Google marketing services about users is transmitted to Google and stored on Google’s servers in the USA.

The Google marketing services we use include, among others, the online advertising program “Google Ads”. In the case of Google Ads, each Ads customer receives a different “conversion cookie”. Cookies can therefore not be tracked across Ads customers’ websites. The information obtained using the cookie is used to generate conversion statistics for Ads customers who have opted in to conversion tracking. Ads customers learn the total number of users who clicked on their ad and were redirected to a page tagged with a conversion tracking tag. However, they do not receive any information that can be used to personally identify users.

Furthermore, we use the “Google Tag Manager” to integrate and manage the Google analysis and marketing services on our website.

For more information on the use of data for marketing purposes by Google, please visit the overview page: https://www.google.com/policies/technologies/ads, Google’s privacy policy is available at https://www.google.com/policies/privacy.

If you wish to object to interest-based advertising by Google marketing services, you can use the settings and opt-out options provided by Google: http://www.google.com/ads/preferences.

      c.) HubSpot 

We use Hubspot for our online marketing activities. This is an integrated software solution that we use to cover the following aspects of our marketing, among others:

– Content Management

– Email marketing (newsletters as well as automated mailings, e.g. to provide downloads)

– Social media publishing & reporting

– Reporting (e.g. traffic sources, accesses, etc. …)

– Contact management (e.g. user segmentation & CRM)

– Landing pages and contact forms

All information we collect is subject to this privacy policy. We use all collected information exclusively to optimize our marketing. Of course, you can exercise your right to delete your data at any time.

We allow visitors to our website to learn more about our company, download content, and provide their contact information and other demographic information.

This information, as well as some of the content on our website, is stored on servers operated by our software partner HubSpot. It may be used by us to determine which of our company’s services are of interest to our customers.

HubSpot is a software company from the USA with a branch in Ireland.

Contact:

HubSpot
2nd Floor 30 North Wall Quay
Dublin 1, Ireland
Phone: +353 1 5187500.

HubSpot is certified under the terms of the “EU – U.S. Privacy Shield Framework” and is subject to TRUSTe ‘s Privacy Seal as well as the “U.S. – Swiss Safe Harbor” Framework.

We have concluded a corresponding contract with the provider for commissioned data processing.

The data processing is carried out on the basis of the legal provisions of § 96 para 3 TKG as well as Art 6 para 1 lit a (consent) and/or f (legitimate interest) of the DSGVO.

Our concern in terms of the DSGVO (legitimate interest) is the improvement of our offer and our web presence.

  1. Facebook Pixel, Custom Audiences and Facebook Conversion.

Within our online offer, the so-called “Facebook pixel” of the social network Facebook, which is operated by Facebook Inc, 1 Hacker Way, Menlo Park, CA 94025, USA, or if you are a resident of the EU, Facebook Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (“Facebook”), is used due to our legitimate interests in the analysis, optimization and economic operation of our online offer and for these purposes.

Facebook is certified under the Privacy Shield agreement and thereby offers a guarantee of compliance with European data protection law (https://www.privacyshield.gov/participant?id=a2zt0000000GnywAAC&status=Active).

With the help of the Facebook pixel, it is possible for Facebook, on the one hand, to determine the visitors to our online offer as a target group for the display of advertisements (so-called “Facebook ads”). Accordingly, we use the Facebook pixel to display the Facebook ads placed by us only to those Facebook users who have also shown an interest in our online offer or who have certain characteristics (e.g. interests in certain topics or products determined on the basis of the websites visited) that we transmit to Facebook (so-called “Custom Audiences”). With the help of the Facebook pixel, we also want to ensure that our Facebook ads correspond to the potential interest of users and do not have a harassing effect. With the help of the Facebook pixel, we can also track the effectiveness of the Facebook ads for statistical and market research purposes by seeing whether users were redirected to our website after clicking on a Facebook ad (so-called “conversion”).

The processing of the data by Facebook takes place within the framework of Facebook’s data usage policy. Accordingly, general information on the display of Facebook ads, in Facebook’s data usage policy: https://www.facebook.com/policy.php. Specific information and details about the Facebook Pixel and how it works can be found in Facebook’s help section:

https://www.facebook.com/business/help/651294705016616.

You can object to the collection by the Facebook pixel and use of your data to display Facebook ads. To adjust which types of ads are displayed to you within Facebook, you can visit the page set up by Facebook and follow the instructions there regarding the settings for usage-based advertising: https://www.facebook.com/settings?tab=ads. The settings are done in a platform-independent manner, which means that they are applied to all devices, such as desktop computers or mobile devices.

You may further opt-out of the use of cookies used for reach measurement and advertising purposes via the Network Advertising Initiative opt-out page (http://optout.networkadvertising.org/) and additionally the U.S. website (http://www.aboutads.info/choices) or the European website (http://www.youronlinechoices.com/uk/your-ad-choices/).

      14. Routine deletion and blocking of personal data

The controller shall process and store personal data of the data subject only for the period of time necessary to achieve the purpose of storage or where provided for by the European Directive and Regulation or other legislator in laws or regulations to which the controller is subject.

If the storage purpose ceases to apply or if a storage period prescribed by the European Directive and Regulation Maker or another competent legislator expires, the personal data will be routinely blocked or deleted in accordance with the statutory provisions.

  1. Rights of the data subject

a.) Right to confirmation

Every data subject has the right granted by the European Directive and Regulation to obtain confirmation from the controller as to whether personal data concerning him or her are being processed. If a data subject wishes to exercise this right of confirmation, he or she may, at any time, contact any employee of the controller.

b) Right of access

Any person concerned by the processing of personal data has the right granted by the European Directive and Regulation to obtain at any time from the controller, free of charge, information about the personal data stored about him or her and a copy of that information. In addition, the European Directive and Regulation Legislator has granted the data subject access to the following information:

  • the purposes of the processing
  • the categories of personal data processed
  • the recipients or categories of recipients to whom the personal data have been or will be disclosed, in particular in the case of recipients in third countries or international organizations
  • if possible, the planned duration for which the personal data will be stored or, if this is not possible, the criteria for determining this duration
  • the existence of a right to obtain the rectification or erasure of personal data concerning him or her, or to obtain the restriction of processing by the controller, or a right to object to such processing
  • the existence of a right of appeal to a supervisory authority
  • if the personal data are not collected from the data subject: Any available information on the origin of the data
  • the existence of automated decision-making, including profiling, pursuant to Article 22(1) and (4) of the GDPR and, at least in these cases, meaningful information about the logic involved and the scope and intended effects of such processing for the data subject.

Furthermore, the data subject shall have the right to obtain information as to whether personal data have been transferred to a third country or to an international organization. If this is the case, the data subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.

If a data subject wishes to exercise this right of access, he or she may, at any time, contact an employee of the controller.

c) Right to correction

Any person data subject to the processing of personal data shall have the right granted by the European legislator of directives and regulations to request the immediate correction of inaccurate personal data concerning him/her.

d) Right to be forgotten

Any person concerned by the processing of personal data shall have the right granted by the European legislator of directives and regulations to require the data controller to request that the personal data concerning him/her be deleted immediately, provided that one of the following reasons applies and insofar as the processing is not necessary:

  • The personal data have been collected or otherwise processed for such purposes for which they are no longer necessary.
  • The data subject withdraws his/her consent on which the processing was based pursuant to Article 6(1)(a) DS-GMO or Article 9(2)(a) DS-GMO, and there is no other legal basis for the processing.
  • The data subject opposes processing under Article 21(1) DS-GMO and there are no overriding legitimate grounds for processing or the data subject opposes processing under Article 21(2) DS-GMO.
  • The personal data have been processed unlawfully.
  • The deletion of personal data is necessary to fulfil a legal obligation under Union law or the law of the Member States to which the data controller is subject.
  • The personal data was collected in relation to information society services offered in accordance with Art. 8 para. 1 DS-GMO.

If one of the above-mentioned reasons applies and a data subject wishes to have personal data stored at Setlog GmbH deleted, he or she may contact an employee of the data controller at any time. The employee of Setlog GmbH will arrange for the request for deletion to be complied with immediately.

If Setlog GmbH has made the personal data public and our company is obliged to delete the personal data in accordance with Art. 17 para. 1 DS-GMO, Setlog GmbH shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other persons responsible for data processing who process the published personal data, that the person concerned has requested that all links to this personal data or copies or replications of this personal data be deleted by these other persons responsible for data processing, insofar as processing is not necessary. The employee of Setlog GmbH will arrange for the necessary in individual cases.

e) Right to limitation of processing

Any person data subject to the processing of personal data shall have the right granted by the European legislator of directives and regulations to require the controller to restrict the processing if one of the following conditions is met:
The accuracy of the personal data is disputed by the data subject for a period that enables the data controller to verify the accuracy of the personal data.
The processing is unlawful, the data subject refuses to delete the personal data and instead requests that the use of the personal data be restricted.
The data controller no longer needs the personal data for the purposes of the processing, but the data subject needs them to assert, exercise or defend legal claims.
The data subject has lodged an objection to the processing pursuant to Art. 21 para. 1 DS-GMO and it has not yet been determined whether the legitimate reasons of the data subject outweigh those of the data subject.
If one of the above conditions is fulfilled and a data subject wishes to request the restriction of personal data stored by Setlog GmbH, he/she may contact an employee of the data controller at any time. The employee of Setlog GmbH will arrange for the processing to be restricted.

f) Right to data transferability

Any data subject shall have the right granted by the European legislator to receive personal data relating to him/her provided by the data subject to a data controller in a structured, current and machine-readable format. It also has the right to transmit this data to another data controller without hindrance by the data controller to whom the personal data have been provided, provided that the processing is based on the consent provided for in Article 6(1)(a) DS-GMO or Article 9(2)(a) DS-GMO or on a contract pursuant to Article 6(1)(a) DS-GMO.

Furthermore, in exercising his right to data transferability pursuant to Article 20(1) DS-GMO, the data subject has the right to obtain that the personal data be transferred directly by a data controller to another data controller, provided this is technically feasible and provided that the rights and freedoms of other persons are not affected thereby.

The person concerned may contact an employee of Setlog GmbH at any time to assert the right to data transferability.

g) Right of objection

Any person concerned by the processing of personal data shall have the right granted by the European legislator for reasons arising from their particular situation to object at any time to the processing of personal data concerning them under Article 6(1)(e) or (f) of the DS-GMO. This also applies to profiling based on these provisions.

Setlog GmbH will no longer process personal data in the event of an objection, unless we can prove compelling reasons worthy of protection for the processing, which outweigh the interests, rights and freedoms of the data subject, or the processing serves to assert, exercise or defend legal claims.

If Setlog GmbH processes personal data in order to carry out direct advertising, the person concerned has the right to object to the processing of the personal data at any time for the purpose of such advertising. This also applies to profiling insofar as it is connected with such direct advertising. If the person concerned objects to Setlog GmbH processing for direct advertising purposes, Setlog GmbH will no longer process the personal data for these purposes.

Furthermore, the data subject has the right to object to the processing of personal data concerning him/her which is carried out at Setlog GmbH for scientific or historical research purposes or for statistical purposes pursuant to Art. 89 para. 1 DS-GMO for reasons arising from his or her particular situation, unless such processing is necessary to fulfil a task in the public interest.

To exercise the right of objection, the person concerned can directly contact any employee of Setlog GmbH or another employee. The data subject shall also be free to exercise his right of opposition in relation to the use of information society services by means of automated procedures using technical specifications, notwithstanding Directive 2002/58/EC.

h) Automated decisions in individual cases including profiling

Any person data subject to the processing of personal data shall have the right granted by the European legislator of directives and regulations not to be subject to a decision based exclusively on automated processing, including profiling, which has legal effect against him or significantly affects him in a similar manner, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the data subject and the data controller, or (2) is admissible under Union or Member State law to which the data controller is subject and that such law contains appropriate measures to safeguard the rights, freedoms and legitimate interests of the data subject, or (3) with the express consent of the data subject.

If the decision (1) is necessary for the conclusion or performance of a contract between the data subject and the data controller or (2) is made with the express consent of the data subject, Setlog GmbH shall take appropriate measures to protect the rights and freedoms as well as the legitimate interests of the data subject, including at least the right to obtain the intervention of a data controller, to state his own position and to challenge the decision.

If the data subject wishes to assert rights relating to automated decisions, he or she may contact an employee of the controller at any time.

i) Right to revoke consent under data protection law

Any person concerned by the processing of personal data has the right granted by the European legislator of directives and regulations to revoke consent to the processing of personal data at any time.

If the data subject wishes to exercise his/her right to withdraw his/her consent, he/she may contact an employee of the controller at any time.

j) Right to appeal to the competent supervisory authority

You have the right to appeal to the appropriate regulatory body. The competent supervisory authority is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia, Kavalleriestrasse 2-4, 40213 Düsseldorf.

  1. Data protection for applications and in the application procedure

The controller collects and processes the personal data of applicants for the purpose of processing the application procedure. Processing may also be carried out electronically. This is particularly the case if an applicant sends corresponding application documents to the controller by electronic means, for example by e-mail or via a web form on the website. If the controller concludes an employment contract with an applicant, the data transmitted will be stored for the purpose of processing the employment relationship in compliance with the statutory provisions. If the controller does not conclude an employment contract with the applicant, the application documents shall be automatically deleted two months after notification of the decision of refusal, provided that no other legitimate interests of the controller stand in the way of deletion. Other legitimate interest in this sense is, for example, a burden of proof in proceedings under the General Equal Treatment Act (AGG).

  1. Legal basis of the processing

Art. 6 I lit. a DS-GMO serves our company as a legal basis for processing operations for which we obtain consent for a specific processing purpose. If the processing of personal data is necessary for the performance of a contract to which the data subject is a party, as is the case for example with processing operations necessary for the delivery of goods or the provision of other services or consideration, the processing is based on Art. 6 I lit. b DS-GMO. The same applies to such processing processes that are necessary to carry out pre-contractual measures, for example in cases of enquiries about our products or services. If our company is subject to a legal obligation which requires the processing of personal data, for example to fulfil tax obligations, the processing is based on Art. 6 I lit. c DS-GMO. In rare cases, the processing of personal data may become necessary to protect the vital interests of the data subject or another natural person. This would be the case, for example, if a visitor were injured in our company and his name, age, health insurance data or other vital information had to be passed on to a doctor, a hospital or other third parties. The processing would then be based on Art. 6 I lit. d DS-GMO. Ultimately, processing operations could be based on Art. 6 I lit. f DS-GMO. Processing operations which are not covered by any of the aforementioned legal bases are based on this legal basis if processing is necessary to safeguard a legitimate interest of our company or a third party, provided that the interests, fundamental rights and freedoms of the data subject do not prevail. Such processing procedures are permitted to us in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed if the person concerned is a customer of the person responsible (recital 47, second sentence, DS-GMO).

  1. Legitimate interests in the processing pursued by the controller or a third party

If the processing of personal data is based on Article 6 I lit. f DS-GMO, it is in our legitimate interest to conduct our business for the well-being of all our employees and our shareholders.

  1. Duration for which the personal data is stored

The criterion for the duration of the storage of personal data is the respective legal retention period. After the expiry of this period, the corresponding data will be routinely deleted, provided that it is no longer necessary for the fulfilment or initiation of the contract.

  1. Legal or contractual provisions for the provision of personal data; necessity for the conclusion of the contract; obligation of the data subject to provide the personal data; possible consequences of failure to provide them

 We inform you that the provision of personal data is partly required by law (e.g. tax regulations) or may also result from contractual regulations (e.g. information on the contractual partner). In some cases, it may be necessary for a contract to be concluded if a data subject provides us with personal data which must subsequently be processed by us. For example, the person concerned is obliged to provide us with personal data if our company enters into a contract with him/her. Failure to provide personal data would mean that the contract with the data subject could not be concluded. Prior to the provision of personal data by the data subject, the data subject must contact one of our employees. Our employee will inform the data subject on a case-by-case basis whether the provision of personal data is required by law or contract or required for the conclusion of the contract, whether there is an obligation to provide the personal data and what consequences the failure to provide the personal data would have.

  1. Existence of automated decision making

As a responsible company, we do without automatic decision-making or profiling.