Data privacy statement
1. Data protection at a glance
General information
The purpose of this document is to give you a quick overview of what happens to your personal data when you visit our website. Personal data is any data that can be used to identify you. For more details on data protection please refer to our privacy policy set out below.
Data collection on our website
Who is responsible for data collection on this website?
The data collected on this website is processed by the website operator. For the operator's contact details, please refer to the company and legal information page of this website.
How do we collect your data?
We primarily collect data that you provide us with. This could be, for example, the data you enter into a contact form.
Our IT systems collect other data automatically when you visit our website. These are mainly technical data (e.g. information about your browser, operating system or the time you accessed our website). This data is collected automatically whenever you use our website.
What do we use your data for?
We collect some of the data to ensure the proper functioning of the website. Some data can be used to analyse your user behaviour.
What rights do you have in relation to your data?
You have the right to obtain information about the personal data we store on you, its source and recipients as well as the purpose of storing the data at any time and free of charge. You also have a right to obtain rectification, erasure or restriction of processing with respect to this data. To do this, or if you have any other questions about data protection, you can contact us at any time using the address specified in the company and legal information. Furthermore, you have the right to lodge a complaint with the competent supervisory authority.
You also have the right to obtain restriction of processing under certain circumstances. For more information, please refer to the privacy policy under "Right to restriction of processing".
Analysis tools and third-party tools
When you visit our website, your browsing behaviour may be statistically evaluated. This happens primarily through the use of cookies and analysis programs. As a general rule, the analysis of your browsing behaviour is anonymous, i.e. this data will not be used to identify you. You can object to this analysis or prevent it by not using specific tools. For further details, please refer to our privacy policy set out below.
You have the right to object to this analysis. In this privacy policy, we inform you how you can object to this use of your personal data.
Changes to our privacy policy
We reserve the right to make changes to this privacy policy at any time. The privacy policy is updated regularly and all changes are automatically published on our website.
2. General and mandatory information
Privacy policy
We as the operators of this website take the protection of your personal data very seriously. We will treat your personal data as confidential and in accordance with the applicable data protection legislation and this privacy policy.
When you use this website, we collect various types of personal data. Personal data is any data that can be used to identify you. This privacy policy explains what information we collect, how we collect it and what we use it for. We also provide you with information about the purpose of collecting your data.
We would like to point out in this context that any transfer of data over the internet (for example, when communicating by email) can pose a security risk. It is impossible to provide blanket protection against unauthorised third-party access.
Information about the controller
The controller responsible for processing of data on this website is:
Cotecda GmbH
Sebastian-Kneipp-Straße 41
60439 Frankfurt am Main, Germany
support@cotecda.de
Telephone: +49 69 505064-135
Fax +49 69 505064-136
Managing directors: Carsten Wesner, Silke Brücher
The controller is a natural or legal person which, alone or jointly with others, determines the purposes and means of the processing of personal data (e.g. names, email addresses, etc.).
Data protection officer required by law
The data protection officer of the controller is
DataCo GmbH
Nymphenburger Strasse 86
80636 München
Germany
Phone: +49 89 7400 45840
Withdrawal of your consent to data processing
Many data processing operations are only possible with your express consent. You have the right to withdraw your consent at any time. To do this, an informal notice of withdrawal by email will suffice. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
Right to object to data collection on grounds relating to the data subject's particular situation or to data processing for direct marketing purposes (Article 21 of the General Data Protection Regulation (GDPR))
You have the right to object to processing of personal data on grounds relating to your particular situation at any time, where the processing of personal data is based on Article 6 (1) (e) or (f) GDPR, including profiling based on those provisions. The respective legal basis on which processing is based is provided in this privacy policy. If you make use of this right to object, we will no longer process your personal data, unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms or for the establishment, exercise or defence of legal claims (right to object under Article 21 (1) GDPR).
Where personal data are processed for direct marketing purposes, you as the data subject have the right to object at any time to processing of personal data concerning you for such marketing, which includes profiling to the extent that it is related to such direct marketing. If you object, your personal data will no longer be used for direct marketing purposes (right to object under Article 21 (2) GDPR).
Right to lodge a complaint with the competent supervisory authority
In cases of infringement of GDPR, the data subject has the right to lodge a complaint with a supervisory authority, in particular, in the member state of their habitual residence, place of work or place of the alleged infringement. You have the right to lodge a complaint without prejudice to any other administrative or judicial remedy.
Right to data portability
You have the right to receive the data we process based on your consent or on a contract by automated means in a commonly used and machine-readable format and have the right to transmit those data to another controller. In exercising your right to data portability, you have the right to have the personal data transmitted directly from one controller to another, where technically feasible.
SSL or TLS encryption
This website uses SSL or TLS encryption for security reasons and for the protection of the transmission of confidential content, such as orders or inquiries, you send us as the website operator. You can recognize an encrypted connection in your browser's address bar when it changes from "http://" to "https://" and the lock icon is displayed in your browser's address bar.
If SSL or TLS encryption is enabled, the data you submit to us cannot be read by third parties.
Access, restriction of processing, erasure and rectification
You have the right to request access to the personal data we store on you, information about the source of the data and its recipients as well as the purpose of storing the data at any time and free of charge. You also have the right to obtain rectification, restriction of processing or erasure of this data. If you have any further questions regarding our privacy policy or the processing of your personal data, you can contact us at any time using the address specified in the company and legal information.
Right to restrict processing
You have the right to obtain restriction of processing of your personal data. To do this, you can contact us at any time using the address specified on the company and legal information page. You have the right to obtain restriction of processing in the following cases:
-
- If you contest the accuracy of your personal data we store, we will generally need time to verify this. During the verification period, you have the right to obtain restriction of processing of your personal data.
-
- If the processing is unlawful, and you oppose the erasure of the personal data and request the restriction of their processing instead.
-
- If we no longer need the personal data, but you need the data for the establishment, exercise or defence of legal claims, you have the right to request a restriction of processing of your personal data instead of erasure.
-
- If you have objected to processing pursuant to Article 21(1) pending the verification whether our legitimate grounds override yours. As long as it is not clear whose legitimate interest is overriding, you have the right to obtain restriction of processing of personal data.
Where you have restricted the processing of your personal data, such personal data can, with the exception of storage, only be processed with your consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the European Union or of a member state.
3. Data collection on our website
Cookies
We use so-called cookies in certain areas of our website. Cookies do not damage your computer and do not contain viruses. They are used to make our website more user-friendly, effective and secure. Cookies are small text files stored on your computer by your browser.
Most of the cookies we use are so-called "session cookies." They are automatically deleted at the end of your visit. Other cookies remain stored on your device until you erase them. These cookies allow us to recognise your browser the next time you visit.
You can set your browser to notify you every time before storing cookies and decide on a case-by-case basis, whether to accept them. You can also limit the acceptance of cookies to certain cases, block the acceptance of cookies altogether or enable automatic deletion of cookies when you close the browser. If you disable cookies you may not be able to use all the functions and features of our website.
The legal basis for the storing of cookies, which are necessary for the performance of electronic communication processes or the provision of certain functions you require (e.g. shopping cart) is Article 6 (1) (f) GDPR. The operator of this website has a legitimate interest in the storage of cookies for the technically fault-free and optimised provision of our services. Where we store other types of cookies (such as those used to analyse your browsing patterns) we will discuss this separately in this privacy policy.
Server log files
The website provider automatically collects and stores data in server log files, which your browser automatically transmits to us. These are:
-
- Browser type and browser version
-
- Operating system used
-
- Referrer URL
-
- Hostname of the accessing computer
-
- Time of the server request
-
- IP address
The data obtained in this way will not be linked to other data sources.
The legal basis for collection of this data is Article 6 (1) (f) GDPR. The website operator has a legitimate interest in the technically correct display and optimisation of its website; for this purpose, the server log files must be stored.
Inquiries by email, telephone or fax
If you contact us by email, telephone or fax, we will process and store your data (name, query details) to deal with your query. We will not share this information without your consent.
This data is processed on the basis of Article 6 (1) (b) GDPR if your request is related to the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases the processing is based on your consent ( Article 6 (1) (a) GDPR) and / or on our legitimate interests ( Article 6 (1) (f) GDPR), since we have a legitimate interest in the effective processing of the inquiries addressed to us.
We will keep the data submitted through the contact form until you ask us to erase the data, withdraw your consent to storage of your data or the data is no longer needed for the purpose for which it has been collected (e.g. after we have completed the processing of your query). This is without prejudice to mandatory provisions and in particular, statutory retention requirements.
4. Social media
Facebook plugins (Like & Share buttons)
Plugins of the social network Facebook, provider Meta Platforms, Inc, 1 Hacker Way, Menlo Park, California 94025, USA, are integrated on our pages. You can recognize the Facebook plugins by the Facebook logo or the "Like" button on our site. You can find an overview of the Facebook plugins here: https://developers.facebook.com/docs/plugins/?locale=de_DE.
When you visit our pages, a direct connection is established between your browser and the Facebook server via the plugin. Facebook receives the information that you have visited our site with your IP address. If you click on the Facebook "Like" button while you are logged into your Facebook account, you can link the content of our pages to your Facebook profile. This allows Facebook to associate your visit to our pages with your user account. We would like to point out that, as the provider of the pages, we have no knowledge of the content of the transmitted data or its use by Facebook. You can find further information on this in Facebook's privacy policy at https://de-de.facebook.com/privacy/explanation.
If you want to prevent Facebook from relating the visit to our website to your Facebook user account, you have to log out from your Facebook account before visiting our website.
The legal basis for use of Facebook plugins is Article 6 (1) (f) GDPR. The website operator has a legitimate interest in achieving the greatest possible visibility on social media.
X Plugin
Functions of the X service are integrated on our pages. These functions are offered by X Corp, 1355 Market Street, Suite 900, San Francisco, CA 94103, USA. By using X and the "Re-Tweet" function, the websites you visit are linked to your X account and made known to other users. Data is also transmitted to X in the process. We would like to point out that, as the provider of the pages, we have no knowledge of the content of the transmitted data or its use by X. Further information on this can be found in X's privacy policy at https://twitter.com/de/privacy.
The X-Plugin is used on the basis of Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in the widest possible visibility in social media.
You can change your data protection settings for X in the account settings under https://twitter.com/account/settings change.
Instagram plugin
Functions of the Instagram service are integrated on our pages. These functions are offered by Meta Platforms, Inc., 1601 Willow Road, Menlo Park, CA 94025, USA.
If you are logged into your Instagram account, you can link the content of our pages to your Instagram profile by clicking on the Instagram button. This also allows Instagram to link your visit to our website with your user account. Please note that we as the provider of the website have no knowledge of the content of the transmitted data or its use by Instagram.
The legal basis for the use of Instagram plugins is Article 6 (1) (f) GDPR. The website operator has a legitimate interest in achieving the greatest possible visibility on social media.
For more information, please refer to Instagram’s privacy policy at https://instagram.com/about/legal/privacy/.
LinkedIn plugin
Our website uses functions and features of the social media platform LinkedIn, operated by LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA.
Every time you visit one of the pages of our website, which contains LinkedIn functions and features, it establishes a connection to LinkedIn servers. LinkedIn is informed that you have visited our website with your IP address. If you click on the LinkedIn "Recommend" button and are logged into your LinkedIn account, it is possible for LinkedIn to associate your visit to our website with you and your user account. Please note that we as the provider of the website have no knowledge of the content of the transmitted data or its use by LinkedIn.
The legal basis for the use of LinkedIn plugins is Article 6 (1) (f) GDPR. The website operator has a legitimate interest in achieving the greatest possible visibility on social media.
For more information, please refer to LinkedIn’s privacy policy at https://www.linkedin.com/legal/privacy-policy.
XING plugin
Our website uses functions and features from the social media platform XING, operated by XING AG, Dammtorstraße 29-32, 20354 Hamburg, Germany.
Every time you visit one of the pages of our website, which contains XING functions and features, it establishes a connection to XING servers. To our knowledge, this data is not being stored by XING. In particular, XING does not store IP addresses or evaluate user behaviour.
The legal basis for the use of XING plugins is Article 6 (1) (f) GDPR. The website operator has a legitimate interest in achieving the greatest possible visibility on social media.
For further information on data protection and the XING Share button, please refer to XING's privacy policy at: https://www.xing.com/app/share?op=data_protection.
5. Analysis tools and advertising
Google Analytics
This website uses functions and features of the website analysis tool Google Analytics. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
Google Analytics uses "cookies". Cookies are small text files that are stored to your computer and facilitate an analysis of the way you use the website. The information generated by the cookie about your use of the website will typically be transmitted to and stored by Google on servers in the USA.
The legal basis for storage of Google Analytics cookies and the analysis tool is Article 6 (1) (f) GDPR. The website operator has a legitimate interest in analysing user behaviour aimed at optimising its website and its advertising.
IP anonymisation
We have activated the IP anonymisation feature on this website. This means that Google will truncate your IP address within Member States of the European Union or other Contracting States to the Agreement on the European Economic Area before it is transmitted to the USA. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA where it will be truncated. Google will use this information on behalf of the operator of this website for the purpose of evaluating your use of the website, compiling reports on website activity for website operators and providing them other services relating to website activity and internet use. Google will not associate your IP address transmitted by your browser with any other data held by Google.
Browser plugin
You can prevent the storage of cookies by changing the relevant settings of your browser. However, please note that if you do this you may not be able to use all the features of this website. Furthermore, you can prevent the collection of data about the your use of the website (including your IP address) generated by the cookie and its processing by Google by downloading and installing the browser plugin provided under the following link: https://tools.google.com/dlpage/gaoptout?hl=de.
Right to object to data collection
You can prevent the collection of your data by Google Analytics by clicking on the following link. This sets an opt-out cookie which will prevent future collection of your data when visiting this website: Opt out from Google Analytics.
For more information about how Google Analytics handles user data, please refer to Google's privacy policy: https://support.google.com/analytics/answer/6004245?hl=de.
Data processing agreement
We have concluded a data processing agreement with Google and we fully implement the strict requirements of the German data protection authorities when using Google Analytics.
Retention period
Data stored at Google on the user and event level which are linked to cookies, user IDs (e.g. user ID) or advertising IDs (e.g. DoubleClick cookies, Android advertising ID) will be anonymised after 14 months or erased. For details, please refer to the following link: https://support.google.com/analytics/answer/7667196?hl=de
WordPress stats
This website uses the WordPress tool Stats to carry out a statistical analysis of visitor traffic. The provider is Automattic Inc, 60 29th Street #343, San Francisco, CA 94110-4929, USA.
WordPress Stats uses "cookies" stored on your computer, which can be used to analyse the use of the website. The information generated by the cookies about the use of our website is stored on servers in the USA. Your IP address will be anonymised after processing and before storage.
WordPress Stats cookies will remain on your device until you delete them.
The legal basis for storage of WordPress Stats cookies and the use of this analysis tool is Article 6 (1) (f) GDPR. The website operator has a legitimate interest in analysing user behaviour in an anonymised form aimed at optimising its website and its advertising.
You can set your browser to notify you every time before storing cookies and decide on a case-by-case basis, whether to accept them. You can also limit the acceptance of cookies to certain cases, block the acceptance of cookies altogether or enable automatic deletion of cookies when you close the browser. If you disable cookies you may not be able to use all the functions and features of our website.
You can object to the collection and use of your data with effect for the future by setting an opt-out cookie in your browser by clicking on this link: https://www.quantcast.com/opt-out/.
If you delete the cookies on your computer, you will have to set the opt-out cookie again.
6. Plugins and tools
YouTube
Our website uses plugins from YouTube, which is operated by Google. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
When you visit one of our pages featuring a YouTube plugin, you will be connected to YouTube servers. In this way, YouTube will be informed which pages you visit.
Furthermore, YouTube can store various cookies on your end device. With the help of these cookies, YouTube can obtain information about visitors to our website. This information is used i.a. to collect video statistics, improve the user experience and to prevent fraud. The cookies remain on your device until you delete them.
If you're logged into your YouTube account, you will enable YouTube to link your browsing behaviour directly to your personal profile. You can prevent this by logging out of your YouTube account.
We use YouTube to ensure a consistent and appealing presentation of our website. This constitutes a legitimate interest within the meaning of Article 6 (1) (f) GDPR.
For further information on handling of user data, please refer to the privacy policy of the service provider at https://policies.google.com/privacy?hl=de.
Google web fonts
This website uses web fonts provided by Google to ensure consistent display of specific fonts. When you open a page, your browser loads the required web fonts into your browser cache to display texts and fonts correctly.
For this purpose, the browser you are using must connect to Google's servers. This informs Google that our website has been accessed via your IP address. The legal basis for the processing of users' personal data is generally the consent of the user in accordance with Art. 6 para. 1 sentence 1 lit. a GDPR.
If your browser does not support web fonts, your computer will use the standard font.
For further information about Google web fonts, please refer to https://developers.google.com/fonts/faq or Google's privacy policy at https://policies.google.com/privacy?hl=de.
Adobe Typekit web fonts
Our website uses web fonts from Adobe Typekit to ensure consistent display of specific fonts. The provider is Adobe Systems Incorporated, 345 Park Avenue, San Jose, CA 95110-2704, USA (Adobe).
When you visit our website, your browser loads the required fonts directly from Adobe to display them correctly on your end device. In doing so, your browser establishes a connection to Adobe's servers in the USA. As a result, Adobe will learn that your IP address has accessed our website. According to Adobe, no cookies are stored when providing the fonts.
Your personal data will also be transferred to the USA übermittelt. Füfor the USA, an adequacy decision has been in place since July 10, 2023. „EU-U.S. Data Privacy Framework“ pursuant to Art. 45 III GDPR. The EuropeanäCommission has adopted the EU-U.S. data protection framework and determined in the decision that the United States provides an adequate level of protection for personal data.üpersonal data is obtainedäThe ÜHowever, the transfer of personal data to the United States only applies if the respective US data recipientäThe company is also certified under the EU-US Data Privacy Framework by the US Department of Commerce. A list of certified companies can be viewed at the following link: https://www.dataprivacyframework.gov/s/participant-search
Adobe Inc. is certified under the Data Privacy Framework.
The use of Adobe Typekit Web Fonts is necessary to ensure a consistent display of fonts on our website. This constitutes a legitimate interest within the meaning of Article 6 (1) (f) GDPR.
For more information on Adobe Typekit web fonts, please visit: https://www.adobe.com/de/privacy/policies/typekit.html.
Adobe's privacy policy is available at: https://www.adobe.com/de/privacy/policy.html
7. Own services
Applications
We offer you the opportunity to submit a job application (e.g. by email, post or using an online application form). In the following, we inform you about the scope, purpose and use of your personal data collected as part of the application process. We collect, process and use your data strictly in accordance with applicable data protection laws and regulations and further statutory provisions and we will treat all your data with strictest confidence.
Scope and purpose of data collection
If you send us an application, we process your associated personal data (e.g. contact and communication data, application documents, notes taken during job interviews, etc.) where this is necessary to decide whether to enter into an employment relationship with you. The legal basis for this is Article 26 of the new German Federal Data Protection Act (BDSG) (initiation of an employment relationship), Article 6 (1) (b) GDPR (contract initiation) and - where you have given your consent - Article 6 (1) (a) GDPR. You can withdraw your consent at any time. Within our company, your personal data will only be disclosed to persons involved in the processing of your application.
If the application is successful, the data you submit will be stored in our data processing systems on the basis of Article 26 (BDSG) and Article 6 (1) (b) GDPR for the purpose of implementing the employment agreement.
Data retention period
If we cannot offer you a job, if you reject a job offer or withdraw your application, withdraw your consent to data processing or ask us to erase the data, the data you have submitted, including any remaining physical application documents, will be stored or retained for a maximum of 6 months after completion of the application process (retention period) in order to be able to trace the details of the application process in the case of any discrepancies (Article 6 (1) (f) GDPR).
YOU MAY OBJECT TO THIS STORAGE IF YOU HAVE LEGITIMATE INTERESTS THAT OVERRIDE OUR INTERESTS.
At the end of the retention period, the data will be erased, provided this does not conflict with statutory retention requirements or other legal requirements. If it is evident that it will be necessary to retain your data after the end of the retention period (e.g. due to an impending or pending legal dispute), the data will only be erased once it is no longer needed. This is without prejudice to other statutory retention requirements.