Data protection

Privacy Policy

We are pleased that you are visiting our website. Protecting and securing your personal information during your use of our website is very important to us. Therefore, we would like to inform you here about which of your personal data we collect when you visit our website and for what purposes it is used. Personal data refers to individual details about the personal or factual circumstances of a specific or identifiable natural person (data subject), such as name, address, email addresses, and user behaviour. These are data that can be used to identify you. Additionally, you will find occasional information here about data processing activities outside of this website (e.g., video conferences or newsletters).

Responsible for Data Processing

Controller

For the processing of personal data in accordance with the EU General Data Protection Regulation (GDPR) 

tetys GmbH & Co. KG 

Campus Boulevard 51

 52074 Aachen 

Phone: 0241 88 93 00 

Email: info@tetys.de 

Data Protection Officer

exkulpa gmbh

Waldfeuchterstr. 266

52525 Heinsberg

Phone: 02452 / 99 33 11

Email: datenschutz@tetys.de

General Information

In addition to the data you actively provide to us on this page (e.g., via our contact form), we collect some technical data. These so-called metadata are automatically transmitted from your computer to our servers as soon as you access our website (including browser, operating system, or timestamp). Such data help us ensure the error-free display of our website. Additionally, we may collect data through integrated third-party providers (e.g., for external media such as map services or analytics tools). We will inform you about the specific purposes and legal bases throughout this privacy policy.

Retention Period

Unless a specific retention period is stated within this privacy policy, we retain your personal data for as long as the purpose of the data processing is applicable. If you submit a legitimate request for deletion or withdraw your consent, we will delete your data. Statutory retention obligations remain unaffected.

Legal Bases for Data Processing

If you have consented to data processing, your personal data will be processed based on Art. 6(1)(a) GDPR or Art. 9(2)(a) GDPR if special categories of data are processed according to Art. 9(1) GDPR. In cases of explicit consent for the transfer of personal data to third countries, the data will also be processed in accordance with Art. 49(1)(a) GDPR. If you have consented to the storage of cookies or access to information on your device (e.g., through device fingerprinting), data processing will additionally occur based on s. 25(1) TDDDG / applicable national law. Your consent can be withdrawn at any time. If your data are necessary for contract fulfilment or pre-contractual measures, we process your data according to Art. 6(1)(b) GDPR. Furthermore, we process your data if necessary to fulfil a legal obligation based on Art. 6(1)(c) GDPR. Data processing may also occur due to our legitimate interests in accordance with Art. 6(1)(f) GDPR. In the following sections of this privacy policy, you will be informed about the respective legal bases in individual cases.

Notice on Data Transfer to Third Countries and US Companies without DPF Certification

Please note that we use tools from companies based in third countries or the USA that are not covered by the EU-US Data Privacy Framework (DPF). When using these tools, your personal data may be transferred to and processed in these countries. Please be aware that in these insecure third countries, a level of data protection comparable to that of the EU cannot be guaranteed.

We wish to clarify that the USA generally offers a level of data protection comparable to that of the EU. Data transfer to the USA is permitted if the recipient has DPF certification or provides appropriate additional guarantees. Information about data transfers to third countries, including data recipients, can be found in our privacy policy.

Automated Decision-Making

Your personal data will not be processed for the purpose of automated decision-making.

Your Rights

As a data subject under the General Data Protection Regulation (GDPR), you have the following rights:

  • Right of access: You have the right to request confirmation from us as to whether your personal data are being processed and, if so, to obtain further information about the processing and copies of the processed data (Art. 15 GDPR).
  • Right to rectification: You have the right to request the immediate correction of inaccurate personal data concerning you and, if necessary, the completion of incomplete personal data (Art. 16 GDPR).
  • Right to erasure: You have the right to request the immediate deletion of personal data concerning you if the legal requirements are met, particularly if the data are no longer necessary for the purposes pursued and the processing is unlawful (Art. 17 GDPR).
  • Right to restriction of processing: You have the right to request the restriction of processing of your personal data from us if the legal requirements are met, particularly if you contest the accuracy of the data, the processing is unlawful, and you oppose deletion (Art. 18 GDPR).
  • Right to data portability: You have the right to receive the personal data concerning you, which you have provided to us, in a structured, commonly used, and machine-readable format, and you have the right to transmit those data to another controller without hindrance from us, where technically feasible (Art. 20 GDPR).
  • Right to object: You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you if the processing is based on Art. 6(1)(e) or (f) GDPR (Art. 21 GDPR).
  • Right to withdraw consent: You have the right to withdraw your consent to the processing of personal data at any time with effect for the future. The withdrawal of your consent does not affect the lawfulness of processing based on consent before its withdrawal (Art. 7(3) GDPR).
  • Right to lodge a complaint with a supervisory authority: You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data violates the GDPR (Art. 77 GDPR).

Further Data Processing Procedures

General Information Obligations

This information is directed at customers, prospective clients, suppliers, and employees. We process your personal data for the following purposes:

  • To fulfil our contractual obligations to you (Art. 6(1)(b) GDPR).
  • To carry out pre-contractual obligations (Art. 6(1)(b) GDPR).
  • To respond to enquiries (Art. 6(1)(b) GDPR).
  • If you have given us consent to process your personal data for specific purposes (such as receiving our newsletter), the data processing is based on your consent (Art. 6(1)(a) GDPR).
  • To comply with legal obligations to which our company is subject (Art. 6(1)(c) GDPR).
  • Where necessary, we also process your data to safeguard our legitimate interests, particularly for asserting legal claims and defending in legal disputes, ensuring IT security, consulting and exchanging data with credit agencies to determine credit and default risks, direct marketing and market research unless you have objected to the use of your data for this purpose, in measures for business management and development of services and products, in measures for product and sales optimisation, in risk management measures, and for the prevention or investigation of criminal offences (Art. 6(1)(f) GDPR).

Categories of Recipients of Personal Data

Within our company, only those employees who need access to the data to perform their tasks have access (need-to-know principle). Individual processes and services are carried out by carefully selected service providers who are commissioned in compliance with data protection regulations and are based within the EEA. If service providers commissioned by us gain access to personal data while performing their services, data processing agreements have been concluded with them in accordance with Art. 28(3) GDPR.

Duration of Data Storage

The data we process is stored for the duration of the existence and execution of the contractual relationship and in compliance with statutory retention periods. These are particularly the commercial and tax retention obligations under the German Commercial Code (HGB) and the Fiscal Code (AO). The regular retention or documentation periods are up to ten years. If no contractual relationship is established, we process the data only as long as the specific purpose requires.

Cookies

Cookies are small text files stored by your browser on your device to retain certain information during your use of the website. Cookies enable us to enhance various aspects of our website and make your visit more comfortable.

There are different types of cookies serving various purposes. Temporary cookies, also known as session cookies, are stored only for the duration of your website visit and are automatically deleted when you close your browser. Persistent cookies, on the other hand, remain on your device for a longer period, allowing us to recognise you and your preferences during repeated visits to the website.

Cookies can also be categorised into first-party and third-party cookies. First-party cookies are set by our website, while third-party cookies are set by other websites or service providers whose content is integrated into our website, such as plugins or analytics tools.

The use of cookies serves various purposes, such as ensuring the website functions properly, saving user settings, creating anonymous statistics about user behaviour, or displaying personalised content and advertising. The legal basis for using cookies varies depending on their purpose. In some cases, the setting of cookies is based on your legitimate interest under Art. 6(1)(f) GDPR, to make our website functional and user-friendly. As website operators, we have a legitimate interest in storing necessary cookies for the technically error-free and optimised provision of our services. When we obtain your consent for the use of cookies, processing is based on Art. 6(1)(a) GDPR in conjunction with s. 25(1) TDDDG. Your consent can be withdrawn at any time.

Consent with iubenda Cookie Solution

Nature and Scope of Processing

We have integrated iubenda Cookie Solution on our website. iubenda Cookie Solution is a consent management solution by iubenda s.r.l, Via San Raffaele, 1 – 20121 Milano MI, Italy, which allows for obtaining and documenting consent for the storage of cookies. iubenda Cookie Solution uses cookies or other web technologies to recognise users and store the consent given or withdrawn.

Purpose and Legal Basis

The use of the service is based on the legal requirement to obtain consent for the use of cookies in accordance with Art. 6(1)(c) GDPR and s. 25(2)(2) TDDDG.

Retention Period

The specific retention period of the processed data is not within our control but is determined by iubenda s.r.l. Further information can be found in the privacy policy for iubenda Cookie Solution: https://usercentrics.com/privacy-policy/.

Data Processing in Detail

Below, we provide information on the individual processing operations, the scope and purpose of data processing, the legal basis, the obligation to provide your data, and the respective retention period. Automated decision-making, including profiling, does not take place.

Provision of the Website

When you access and use our website, we collect personal data that your browser automatically transmits to our server. The following information is temporarily stored in a so-called log file:

  • IP address of the requesting computer
  • Date and time of access
  • Name and URL of the retrieved file
  • Website from which access is made (referrer URL)
  • Browser used and, if applicable, the operating system of your computer, as well as the name of your access provider

Our website is not hosted by us directly but by a service provider who processes the aforementioned data on our behalf in accordance with Art. 28 GDPR for the purpose of providing the website.

The use of the hosting provider is for the purpose of fulfilling contracts with our potential and existing customers (Art. 6(1)(b) GDPR) and in the interest of a secure, fast, and efficient provision of our online offering by a professional provider (Art. 6(1)(f) GDPR).

We use the following hosting provider:

IONOS SE

Elgendorfer Str. 57

56410 Montabaur

Contact form

Nature and Scope of Processing

If you send us enquiries (e.g. via contact form, email, or telephone), we store all data arising from this (e.g. name, email address, subject of the enquiry, etc.). We require this data to process your enquiry and to respond to any follow-up questions. We do not share this data without your consent.

Purpose and Legal Basis

The processing of this data is based on Art. 6(1)(b) GDPR, provided your enquiry is related to the fulfilment of a contract or is necessary for the implementation of pre-contractual measures. Otherwise, the processing is based on our legitimate interest in effectively handling enquiries addressed to us (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR) if you have given it previously.

Retention Period

The data you enter in the contact form will remain with us until you request its deletion, withdraw your consent for storage, or the purpose for data storage no longer applies (e.g. after your enquiry has been processed). Mandatory legal provisions – especially retention periods – remain unaffected.

Presence on Social Media Platforms

We operate public profiles on various social networks via our website. More detailed information about the social networks we use can be found in the relevant sections of our privacy policy.

Social networks like Facebook, Twitter, and others can comprehensively analyse your user behaviour when you visit their websites or a website with integrated social media content (e.g., like buttons or advertising banners). Visiting our social media presences triggers numerous data protection-related processing operations:

If you are logged into your social media account and visit our social media presence, the operator of the social media portal can associate this visit with your user account. Your personal data may also be collected even if you are not logged in or do not have an account with the respective social media portal. This data collection occurs, for example, through cookies stored on your device or by capturing your IP address.

With the data collected in this way, the operators of social media portals can create user profiles in which your preferences and interests are stored. This allows interest-based advertising to be displayed to you both within and outside the respective social media presence. If you have an account with the respective social network, interest-based advertising can be displayed on all devices on which you are or were logged in.

Please note that we cannot track all processing activities on social media portals. Depending on the provider, additional processing operations may be carried out by the operators of the social media portals. For details, please refer to the terms of use and privacy policies of the respective social media portals.

Legal Basis for Data Processing

Our social media appearances aim to ensure the most comprehensive presence possible on the internet. This constitutes a legitimate interest within the meaning of Art. 6(1)(f) GDPR. The analysis processes initiated by the social networks may be based on different legal grounds, which must be specified by the operators of the social networks (e.g., consent within the meaning of Art. 6(1)(a) GDPR).

Controller and Assertion of Rights

When visiting our social media presences (e.g., Facebook), we are jointly responsible with the operator of the social media platform for the data processing operations triggered during this visit. You can generally assert your rights (access, rectification, deletion, restriction of processing, data portability, and complaint) both against us and against the operator of the respective social media portal (e.g., against Facebook).

Despite the joint responsibility with the social media portal operators, we do not have full influence over the data processing operations of the social media portals. Our options are largely determined by the corporate policy of the respective provider.

Retention Period

The data directly collected by us via the social media presence will be deleted from our systems as soon as you request us to delete it, withdraw your consent for storage, or the purpose for data storage no longer applies. Stored cookies remain on your device until you delete them. Mandatory legal provisions – in particular, retention periods – remain unaffected.

We have no influence on the retention period of your data, which is stored by the operators of the social networks for their own purposes. For details, please refer directly to the operators of the social networks (e.g., via their privacy policy, see below).

Instagram Page

Our company has a profile on Instagram. The service provider is Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.

The company is certified under the “EU-US Data Privacy Framework” (DPF), an agreement between the European Union and the USA aimed at ensuring compliance with European data protection standards when processing data in the USA. Certification under the DPF obliges companies to adhere to these data protection standards.

Data transfer to the USA is based on the EU Commission”s standard contractual clauses. Details can be found here: https://www.facebook.com/legal/EU_data_transfer_addendum, https://help.instagram.com/519522125107875 and https://de-de.facebook.com/help/566994660333381.

For further information on how your personal data is handled, please refer to Instagram”s privacy policy: https://help.instagram.com/519522125107875.

LinkedIn Page

Our company has a profile on LinkedIn. The provider is LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland. LinkedIn uses advertising cookies.

If you wish to disable LinkedIn advertising cookies, please use the following link: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.

The company is certified under the “EU-US Data Privacy Framework” (DPF), an agreement between the European Union and the USA aimed at ensuring compliance with European data protection standards when processing data in the USA. Certification under the DPF obliges companies to adhere to these data protection standards.

Data transfer to the USA is based on the EU Commission”s Standard Contractual Clauses. Details can be found here: https://www.linkedin.com/legal/l/dpa and https://www.linkedin.com/legal/l/eu-sccs.

For more information on how your personal data is handled, please refer to LinkedIn”s privacy policy: https://www.linkedin.com/legal/privacy-policy.

Video Conferences

Data Processing

We use online conferencing tools to communicate with our clients. The specific tools we use are listed below. When you communicate with us via video or audio conference, your personal data is collected and processed by us and the provider of the respective tool.

The tools collect the data you provide, including your email address and phone number. They also process the duration of the conference, when you participated, the number of participants, and other metadata.

Additionally, the provider of the tool processes all technical data necessary for conducting the conference. This includes, in particular, IP addresses, MAC addresses, device IDs, device type, operating system type and version, client version, camera type, microphone or speaker, and the type of connection.

If you share content using this service, it will be stored on the provider”s servers. This includes cloud recordings, chat messages, voice messages, as well as photos and videos you share during the use of this service.

Please note that we do not have full control over the data processing operations of the tools used. For more detailed information on data processing by the conferencing tools, please refer to the privacy policies of the respective tools used.

Purpose and Legal Basis

The conferencing tools are used to communicate with prospective or existing contractual partners or to offer certain services to our clients (Art. 6(1)(b) GDPR). Furthermore, the use of the tools serves the general simplification and acceleration of communication with us or our company (legitimate interest within the meaning of Art. 6(1)(f) GDPR). If you have previously given consent for data processing, your data will be processed solely on the basis of Art. 6(1)(a) GDPR; consent can be withdrawn at any time.

Retention Period

The data directly collected by us through video and conferencing tools will be deleted from our systems as soon as you request us to delete it, withdraw your consent for storage, or the purpose for data storage no longer applies. Stored cookies remain on your device until you delete them. Mandatory statutory retention periods remain unaffected.

We have no influence on the retention period of your data, which is stored by the operators of the conferencing tools for their own purposes. For details, please refer directly to the operators of the conferencing tools.

Video Conferencing Tools Used

We use the following tools for video conferences:

Microsoft Teams

We use Microsoft Teams. The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. For details on data processing, please refer to the Microsoft Teams privacy statement: https://privacy.microsoft.com/en-gb/privacystatement.

The company is certified under the “EU-US Data Privacy Framework” (DPF), an agreement between the European Union and the USA aimed at ensuring compliance with European data protection standards when processing data in the USA. Certification under the DPF obliges companies to adhere to these data protection standards.

Data transfer to the USA is based on the EU Commission”s standard contractual clauses. Details can be found here: https://privacy.microsoft.com/en-gb/privacystatement.

Data Processing Agreement

To ensure that personal data is processed according to our instructions and in compliance with the GDPR, we have concluded a data processing agreement with the provider. Website visitors are processed only according to our instructions and in compliance with the GDPR.

Zoom

We use Zoom. The provider of this service is Zoom Communications Inc., San Jose, 55 Almaden Boulevard, 6th Floor, San Jose, CA 95113, USA. For details on data processing, please refer to the Zoom privacy statement: https://zoom.us/en-gb/privacy.html.

The company is certified under the “EU-US Data Privacy Framework” (DPF), an agreement between the European Union and the USA aimed at ensuring compliance with European data protection standards when processing data in the USA. Certification under the DPF obliges companies to adhere to these data protection standards.

Data transfer to the USA is based on the EU Commission”s standard contractual clauses. Details can be found here: https://zoom.us/en-gb/privacy.html.

Data Processing Agreement

To ensure that personal data is processed according to our instructions and in compliance with the GDPR, we have concluded a data processing agreement with the provider. Website visitors are processed only according to our instructions and in compliance with the GDPR.

Third-Party Services and Tools

Google Analytics

We use services and features from Google Analytics on this website, offered by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Nature and Scope of Data Processing

With the help of Google Analytics, we as website operators can determine how our website is used. Through the analysis, we learn how often our website is accessed, how long visitors stay on the site, and which devices or systems they use to access the website. We can also track your mouse movements and clicks. Google Analytics uses machine learning and other technologies to analyse and enhance your data. The processing of the collected data usually takes place on Google”s servers in the USA.

Legal Basis

When using Google Analytics, we rely on Art. 6(1)(f) GDPR as the legal basis for storing and analysing personal data, as we have a legitimate interest in analysing the use of our website. This allows us to optimise our online offering for you. If you have previously given consent for data processing by Google Analytics on this website, your data will be processed solely on the legal basis of Art. 6(1)(a) GDPR. You can withdraw your consent at any time.

The transfer of your personal data to the USA is based on the EU Commission”s Standard Contractual Clauses. Further information can be found at https://privacy.google.com/businesses/controllerterms/mccs/.

Data Processing Agreement

To ensure that personal data is processed according to our instructions and in compliance with the GDPR, we have concluded a data processing agreement with the provider.

Retention Period

Google stores data linked to cookies, user IDs, or advertising IDs for two months, after which they are anonymised or deleted. Further information on the retention period or the deletion of your data can be found at https://support.google.com/analytics/answer/7667196?hl=en.

Google Tag Manager

We use services and features from Google Tag Manager on this website, offered by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

The Google Tag Manager is a tool that allows us to deploy other tools on our website. It does not create user profiles, store cookies, or conduct independent analyses. However, your IP address is collected and may be transferred to the United States. The Google Tag Manager itself is used solely for managing the tools integrated through it.

Purpose & Legal Basis

When using Google Tag Manager on this website, we rely on Art. 6(1)(f) GDPR as the legal basis, as we have a legitimate interest in implementing and managing tracking tools on this website easily and efficiently. If you have previously given consent for data processing on this website via Google Tag Manager, your data will be processed solely on the legal basis of Art. 6(1)(a) GDPR in conjunction with s. 25(1) TDDDG / applicable national law. You can withdraw your consent at any time.

The company is certified under the “EU–US Data Privacy Framework” (DPF), an agreement between the European Union and the United States aimed at ensuring compliance with European data protection standards when processing data in the US. Certification under the DPF obliges companies to adhere to these data protection standards. For more information, please visit: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt000000001L5AAI&status=Active

Cloudflare CDN

We use a so-called “Content Delivery Network” (CDN) provided by Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA.

A CDN enables us to deliver certain content quickly, particularly large media files. This is achieved through a network of regionally distributed servers connected via the Internet. The provider can thus analyse data transmission between your browser and our servers and filter potentially malicious traffic. The processing of user data is solely for the aforementioned purposes and serves to maintain the security and functionality of the CDN.

The use of Cloudflare is based on our legitimate interest in providing our web services as error-free and securely as possible (Art. 6(1)(f) GDPR).

Data transfer to the USA is based on the EU Commission”s Standard Contractual Clauses. Details can be found here: https://www.cloudflare.com/privacypolicy/.

Further information on security and data protection at Cloudflare can be found here: https://www.cloudflare.com/privacypolicy/.

The company is certified under the “EU-US Data Privacy Framework” (DPF), an agreement between the European Union and the USA aimed at ensuring compliance with European data protection standards when processing data in the USA. Certification under the DPF obliges companies to adhere to these data protection standards. More information is available at: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt0000000GnZKAA0&status=Active

Data Processing Agreement

To ensure that personal data is processed according to our instructions and in compliance with the GDPR, we have concluded a data processing agreement (DPA) with the provider.