Informationen zur Datenverarbeitung

Regarding the use of the website https://www.ideas-solutions.net/
including the handling of prospective customer data
and regarding recruitment procedures
Effective as of June 15, 2018

1. Responsible

The entity responsible for data processing on this website within the meaning of Article 4(7) of the GDPR is:
IaS Ideas & Solutions GmbH
Kuno-Liesenberg-Kehre 1a
D-22844 Norderstedt

Tel.: +49 (0)40 539 08 85 0
Email: datenschutz@ideas-solutions.net

Represented by the managing directors:
Oliver Heymann, Daniel Stüwe

– Hereinafter referred to as IaS –

2. Scope of Data Protection

The subject of data protection is personal data. According to Article 4(1) of the GDPR, this refers to any information relating to an identified or identifiable individual. This includes, for example, information such as names, mailing addresses, email addresses, or phone numbers, but may also include usage data—such as IP addresses—or content data—such as inquiries submitted by prospective customers or, for example, job application documents.

3. Scope and Purpose of Data Collection and Storage

In the following, we explain the scope of data collection, storage, and use (hereinafter “data processing,” as defined in Article 4(2) of the GDPR) and the purpose of each data processing activity in connection with the website, with regard to prospective candidate data and our recruitment processes.

4. Processing of Personal Data in Connection with Website Use

In principle, you can use this website without providing any personal data. The IP address is an exception. We absolutely need this information for a short period of time (please see Section 4.1).

4.1. About IP Addresses

Without Internet Protocol addresses—or “IP addresses” for short—the Internet simply wouldn’t work, to put it very simply. In computer networks, an IP address serves as an address that allows web servers and/or individual end devices to be located and reached. Without an IP address, the web server and the end devices cannot communicate—and therefore cannot display anything. The web server hosting the website is thus contacted with a data request—from you, since you want to use the website. To deliver the data, the web server must know the IP address. Consequently, the web server must process your IP address at the moment the data is requested. In doing so, the web server receives information about which website or file was accessed, as well as which browser and operating system were used. Normally, this data is stored in its entirety in what are known as web server log files for an extended period. IaS stores the IP addresses of users in these log files for a period of 7 days. This retention period is necessary for the general security analysis of the systems. No further evaluation of this data takes place.

If you’re wondering why we’re explaining all of this here: According to the prevailing legal opinion, an IP address is now considered personal data. And if an IP address is classified as personal data, then we must inform you that we process it temporarily so that you can use the website at all.

The legal basis for this data processing is generally Article 6(1)(b) of the GDPR, as we need your IP address in order to be able to provide you with the website and the information it contains.

4.2. Cookies

We use cookies on our website. Cookies are small text files that websites store on your computer.

However, IaS uses only those cookies that are strictly necessary for the technical operation of our website. We use session cookies solely to ensure that server requests are routed correctly and to identify multiple requests using a session ID. These cookies do not collect any personal data from you.

You can prevent cookies from being installed by adjusting the settings in your browser software (found under “Settings” in most browsers); however, please note that in this case, you may not be able to use all the features of our website to their full extent.

You can also delete cookies that have already been set (also found under “Settings” in your browser).

4.3. OpenStreetMap

To make it easier for you to find us, we have embedded a map from the open-source project “OpenStreetMap” (OSM) on our website under “Contact Us.” In order for you to view this content, OpenStreetMap must receive your IP address; otherwise, OpenStreetMap would not be able to provide you with this embedded content (see section 4.1 for more information). OpenStreetMap does not store your IP address. For more information, visit https://wiki.osmfoundation.org/wiki/Privacy_Policy.

The legal basis for this data processing is Article 6(1)(b) of the GDPR, as otherwise the content (the OSM map) cannot be displayed to you.

In addition, OpenStreetMap places a cookie. This cookie only tracks visits to the OSM service and does not store any other personal data about you. The purpose of the cookie is to protect against misuse (e.g., brute-force attacks). To the best of our knowledge, the cookie does not store any personal data, such as your IP address.

If the cookie nevertheless collects personal data, this is based on overriding legitimate interests pursuant to Article 6(1)(f) of the GDPR. The cookie allows us to protect not only OSM but also the availability of the content embedded on our website (the OSM map) from misuse, ensuring that the content remains available.

5. Data Processing When Contacting Us

When you contact us by email, phone, or mail, we process your data. The legal basis for this data processing is generally Article 6(1)(b) of the GDPR, since we would not be able to respond to you and address the issue you have described if we did not receive your personal contact information.

If you would like to contact us, you must provide or submit at least the following personal information:

  • First- and Lastname
  • Your inquiry
  • Depending on the communication channel:
    • Your E-Mail-Address
    • Your phonennumber
    • Your address

We use this information solely to process your request and to be able to follow up with you regarding that request.

6. Processing of Prospective Customer Data

If you express interest in our services through your message or other form of contact, we will process your data as prospective customer data. This means that we will process your contact information and the reason for your inquiry beyond the scope of our immediate interaction. This processing is based on Article 6(1)(f) of the GDPR. We have a legitimate interest in maintaining and strengthening contact with prospective clients. This is only possible if we do not delete the data. In this case, there does not appear to be any conflicting interest on your part, since you yourself provided us with the data as part of an expression of interest.

7. Data Processing in the Context of Recruitment Processes

7.1. Candidate Information

For the purpose of staff recruitment, IaS also conducts active recruitment (known as “sourcing”), which means that IaS actively searches for potential employees on social media, in forums, or in other publicly accessible online locations. In this case, IaS processes data that candidates have clearly made public, such as

  • Names
  • Data on Professional Qualifications
  • E-Mail-addresses
  • Accountnames/Links to Social Media Profile (Profile-URLs, Twittername etc.)
  • Phonenumbers

IaS processes such candidate data on the basis of Article 6(1)(f) of the GDPR in conjunction with Article 9(2)(e) of the GDPR. IaS has a legitimate interest in processing the personal data of potential employees—which they themselves have clearly made public—for the purposes of recruitment. There does not appear to be any conflicting overriding interest on the part of the candidates in preventing IaS from collecting this data for these purposes, as only data that has been made public by the data subjects themselves—and which falls within the social sphere—is processed. Furthermore, this data is retained beyond the retention periods specified here only if consent has been obtained from the data subjects.

Candidates whose data is processed as part of an active recruitment process for the purpose of creating an initial talent pool will be notified, but who are ultimately not considered for the position in question and whose data will be deleted after six months in accordance with Section 7, will not be notified due to the disproportionate effort involved, pursuant to Article 14(5)(b) of the GDPR; instead, information regarding the data processing carried out is provided here in accordance with Article 14(5)(b) of the GDPR.

7.2. Applicant Information

If you apply for a position at IaS, submit a speculative application, or—after being actively contacted by IaS—give your consent to the further processing of your data and also provide IaS with additional relevant application documents, then IaS regularly processes the following data about you on the basis of Section 26 of the New Federal Data Protection Act (BDSG-Neu) for the purpose of potentially establishing an employment relationship:

  • Contact Information
  • Biographical information, including
  • Proof of Professional Qualifications
    • Testimonials
    • References
  • If applicable, documentation from the application process (such as transcripts, evaluations from job interviews)

IaS processes applicant data in accordance with Article 88 of the GDPR in conjunction with Section 26 of the New Federal Data Protection Act (BDSG-Neu).

8. Purpose-Limited Use of Data, Recipients of Data, Disclosure of Data

We adhere to the principle of purpose-limited data use. We collect, store, and use all of the aforementioned data solely for the purposes already stated.

Some of IaS’s IT systems are managed by external IT service providers. In this context, these IT service providers become recipients of data to the extent necessary for the management of these systems.

As part of the processing of candidate data in sourcing procedures, recruitment agencies commissioned by IaS become recipients of the candidate data.

To the extent necessary, the recipients are bound by data processing agreements with us.

You can request a list of specific recipients at any time. However, for reasons related to our own IT and data security, we do not wish to publicly name the recipients of the data here.

Personal data will not be disclosed to third parties outside the scope described here without your express consent.

Similarly, data is disclosed to government institutions and authorities entitled to receive such information only in accordance with statutory disclosure obligations or if we are required to disclose the information by a court order.

9. Duration of Processing

Your IP address is stored in the web server log files only from the moment the connection is established and for a period of 7 days.

Cookies expire at the end of your visit to the website or after a maximum of one hour, so the data is never stored for longer than that. You can also delete cookies at any time (under “Settings” in your browser).

9.2. Retention periods for contact requests made via email, phone, or mail

We will delete the information you provide to us as part of a contact request immediately after your inquiry has been resolved.

This does not apply if your inquiries and the associated data are classified as prospect data.

9.3. Retention Periods for Prospective Customer Data

Prospect data is deleted two years after the last point of contact.

A touchpoint refers, for example, to an interaction with an employee at a trade show, via social media, by email, or by phone, or to participation in a webinar, seminar, or event. The long retention period is due to the lengthy planning and budgeting cycles in the IT industry.

If retention periods under Section 257 of the German Commercial Code (HGB) must be observed, the data will be retained for up to 6 years and then deleted. In such cases, once the two-year period has expired, the use of the data will be limited to fulfilling the retention obligation in accordance with Article 18 of the GDPR, and the data will be deleted upon expiration of the aforementioned periods.

If deleting individual pieces of data and data records would require a disproportionate amount of effort—in terms of extraction and separation due to differing retention periods—such data will be uniformly restricted once the matter has been resolved and deleted 6 years after the last point of contact.

The period begins at the end of the calendar year in which the relevant date was recorded.

9.4. Data Retention Periods in Recruitment Processes

9.4.1. Retention Periods for Candidate Data from Active Recruitment Processes

Candidate data from sourcing processes will be deleted six months after the start of the sourcing process, unless the candidates are contacted or their consent to further processing is obtained.

9.4.2. Retention Periods for Applicant Data

Once a recruitment process has been completed, the applicant data of those who were not selected for the position will not be deleted until eight months after the position has been filled (and the new employee has started work). The reason for this timeframe is that the probationary period is typically six months. If the newly established employment relationship is terminated within this period, the employer should still have the option to reconsider the other applicants.

10. Data Subject Rights (including the rights to access, withdraw consent, object, and erasure)

You have the right to request information regarding the data we process about you.

You may object to the processing of your data at any time, provided the conditions set forth in Article 21 of the GDPR are met, and you may withdraw any consent you have given for the processing of your data at any time. If consent to data processing is withdrawn or an objection is raised to the use of the data, this does not affect the lawfulness of the data processing up to the time of the withdrawal or objection. Furthermore, you may at any time request that we correct, restrict, or delete the data we process. We expressly note that there may be legal obligations—such as retention requirements—to continue storing data. In such cases, the data can only be restricted. This means that the data will be processed solely for the purpose of complying with these legal obligations and will not be used for any other purpose. In addition, you also have the right to data portability under Article 20 of the GDPR, as well as the right to lodge a complaint with a supervisory authority pursuant to Article 77 of the GDPR.

If you have any questions, please feel free to contact us at any time at datenschutz@ideas-solutions.net.

11. Data Protection Officer

If you have any questions about data protection, please contact:

IaS Ideas & Solutions GmbH
Data Protection Officer
Kuno-Liesenberg-Kehre 1a
D-22844 Norderstedt

E-Mail: datenschutz@ideas-solutions.net

ISO Cert