Datenschutzerklärung der AGILITA Group AG

1. What is this privacy policy about?

With the following privacy policy we, AGILITA Group AG incl. subsidiaries to inform you comprehensively about the use, storage and management of personal data. Your privacy and the protection of your data are close to our hearts.

The use of our website is generally possible without providing personal data (such as name, address or e-mail address). If personal data is collected, it will be treated as highly confidential and will not be disclosed to third parties. The term “personal data” refers to data that relates to specific or identifiable individuals, i.e., that allows conclusions to be drawn about their identity – either directly or through supplementary data. “Personal data requiring special protection” is a category of personal data that is specially protected by the applicable data protection law. In Section 3 of this Privacy Policy, you will find information about the data that we process within the scope of this Privacy Policy. “Processing” means any handling of personal data, e.g. obtaining, storing, using, adapting, disclosing and deleting.

In this Privacy Policy, we explain how we handle your information when you visit our website, use our services or products, interact with us under a contract, communicate or otherwise interact with us. If additional processing activities occur that are not mentioned in this Privacy Policy, we will notify you in writing in a timely manner.

This Privacy Policy is designed to comply with the requirements of the EU General Data Protection Regulation (“GDPR“), the Swiss Data Protection Act (“DPA“) and the revised Swiss Data Protection Act (“revDSG“). However, whether and to what extent these laws are applicable depends on the individual case.

2. Who is responsible for processing your data?

The data processing described in our data protection declaration is the responsibility of AGILITA Group AG incl. subsidiaries responsible. This responsibility occurs when your data is processed by one of these subsidiaries in connection with your own legal obligations or contracts, or when you share your data with one of the subsidiaries. In such situations, the relevant Group company acts as the responsible entity and is subject to the relevant national legal obligations(see section 6).

You may contact us for your data protection concerns and to exercise your rights under Section 10 as follows:

AGILITA Group AG

New Winterthurstrasse 99

CH – 8304 Wallisellen

info@agilita.ch

3. What data do we process?

We process different categories of data. The main categories are as follows:

3.1 Communication data

As soon as you contact us – whether via our contact form, e-mail, telephone, in writing or other means of communication – we record the information exchanged between you and us. This includes your contact details as well as traffic data.

Communication data includes your name and contact information, the manner of communication and also the content (e.g. the text of e-mails). This data may also include information about third parties.

3.2 Technical data

When you use our website or other electronic offerings, we collect the IP address of your terminal device as well as other technical information (such as user accounts, registrations and access data) to ensure functionality and security. This also includes logs documenting the use of our systems. We usually keep technical data for 6 months. To ensure the functionality of the offer, it may be necessary to assign an individual code to you or your end device (e.g.. e.g. in the form of a cookie, see section 11). In general, the pure technical data do not allow any direct conclusions to be drawn about your identity.

Technical data includes, among other things, the IP address as well as information about the operating system of your terminal device, the date, region and time of use as well as the type of browser with which you access our electronic offers. This information allows us to format the website correctly and, for example, display a version tailored to your region. Based on the IP address, we can identify the provider and thus the region of your use, but we usually cannot determine who you are. A connection between technical data and personal data occurs, for example, when you create a user account. In such cases, personal data may be linked to the technical data, which tells us, for example, which browser you use to use your account on our website. Examples of technical data also includelogsthat occur in our systems, such as records of user logins to our website.

3.3 Registration data

Registration Data includes, but is not limited to, the information you provide when you request a white paper, book a demo, register for an event, or apply for a job on our website (e.g., name, last name, company name, email).

3.4 Master data

By master data, we mean the basic information that we use – if you agree – together with the contractual data (see below) to process our contractual and business relationships or for marketing and advertising purposes. This includes, for example, your name, contact details and information about your position and function, the history of your customer relationship, powers of attorney and authority. We will process your master data if you are a customer or have another business relationship or if you are acting on behalf of a business partner (e.g. as a contact person of the business partner, in the context of marketing and advertising, invitations to events, newsletters, etc.). We receive master data from you yourself (e.g. when concluding a contract or as part of a registration) or from third parties such as our contractual partners, associations, address dealers or publicly accessible sources such as registers or Internet sources (websites, social media, etc.). We generally retain this data for 10 years from the last exchange with you, but at least from the end of the contractual relationship. In some cases, this retention period may be longer for evidentiary reasons or to comply with legal or contractual requirements, or may be necessary for technical reasons.

Master Data includes, but is not limited to, data such as name, address, websites, email address, phone number, gender, photos and videos; In addition, it includes information about your relationship with us (customer, prospect, partner, supplier, etc.), your status with us, assignments, classifications, role and function in the company, information about our interactions with you (if applicable, a history thereof with corresponding entries), reports (e.g. from the media) or official documents (e.g. trade register excerpts, permits, etc.). As payment details we collect e.g. your bank details and account number. Consent or blocking notes are also part of the master data, as is information about third parties, e.g. contact persons, recipients of services, advertising recipients or representatives.

Master data is not fully captured for all contacts. The specific data collected varies depending on the specific processing purposes.

3.5 Contract data

Contract data is the information that occurs in connection with the conclusion or execution of a contract. Here, bsw. Information about contracts themselves and the services provided or to be provided is recorded. Also included are the data from the run-up to the conclusion of a contract, which are necessary for the processing, the required or used data and data on communications (e.g. complaints or data on satisfaction, etc.). This data is usually collected from you, contractual partners and other third parties involved in the execution of the contract and may also come from publicly available sources. Typically, we store this information for a period of 10 years from the last activity under the contract, but at least from the end of the contract. In certain cases, this retention period may be longer, for example, for evidentiary reasons or to comply with legal or contractual requirements, or for technical requirements.

Contract data includes information about the conclusion of the contract, about contracts, e.g. type and date of the conclusion of the contract, information from the application process or about the contract in question (e.g. its duration). Also included is information on processing and management of contracts. This includes aspects such as invoicing, customer service, technical support and enforcement of contractual claims. Information on defects, complaints, contract adjustments and customer satisfaction, which can be identified during the meeting, for example, also falls within the scope of contract data. Contract data also includes financial data such as credit information, reminders, and collections. Some of this data is provided by you, while others may come from credit reporting agencies, collection agencies, or publicly available sources such as commercial registers.

3.6 Behavioral and preference data

Depending on the nature of our connection with you, we strive to get to know you better and tailor our products, services and offerings accordingly. For this purpose, we collect and use information about your preferences and your interactions on our website. For a detailed explanation of how tracking works on our website, please see Section 11 of our Privacy Policy.

Behavioral data includes information about specific actions, such as your response to electronic communications (such as opening emails and when they are sent) or your location. Likewise, this includes your interactions with our social media profiles and your participation in our events. If you use our website, we may also collect location data.

Preference data provides us with valuable insights into your individual needs as well as products or services that may pique your interest. We gain these insights by analyzing existing data, including behavioral data. This enables us to get to know you even better and to tailor our consulting and offers specifically to you, in order to achieve a higher overall quality of our offers. To increase the precision of our analyses, we may combine this information with additional data that we also obtain from external sources such as address dealers, government agencies, and publicly available sources such as the Internet.

We receive much of this aforementioned data from you directly (e.g., via forms, communications, contracts, or use of the website). When concluding contracts or using services, certain data is required in accordance with the contractual obligations, in particular master data, contract data and registration data. The use of our website requires the processing of technical data, and registration data is required for access to special systems or buildings.

Certain services require your registration data to ensure who uses our offers or accepts invitations to events, whether for technical reasons, communication or contracting. If you or a person represented by you (e.g. your employer) wish to enter into or fulfill contracts with us, we require your master, contract and communication data.

4 For what purposes do we process your data?

We use your data according to the purposes explained below. Further information for the online area can be found in section 11. For more details on the legal basis of our processing, please refer to section 5.

We process your data to enable us to communicate with you and to send you relevant documents and information. In doing so, we mainly use communication and master data as well as the registration data provided by you. In the context of initiating business, we collect personal data, in particular master data, contract data and communication data, from potential customers or other contractual partners, whether via order forms, contracts or communication. In addition, we process data as part of the conclusion of the contract for the purpose of checking creditworthiness and opening a customer relationship. Some of this information is verified for regulatory compliance.

We establish a variety of contracts with customers and other contractors, including project partners. Here, we mainly process master data, contract data and communication data. Depending on the situation, registration data of the customer or of persons to whom the customer provides a service may also be processed.

Provided you consent, we process data for marketing purposes and relationship management, for example, by sending our customers and other contractors the marketing materials that contain information about our products and services. This communication is regular and can be done electronically, by mail or by telephone. In doing so, we use the contact information you provide and also conduct occasional marketing activities such as events or promotional materials. You have the option at any time to refuse such contacts or to refuse or revoke your consent to be contacted for advertising purposes. With your consent, we are also able to target our online advertising on the Internet more specifically to your interests (for more information, see section 11).

Another aspect of relationship management involves addressing our existing customers and their contacts individually, possibly using behavioral and preference data for personalization. We also operate a customer relationship management system (“CRM“) as part of our relationship management activities. In this system, we store data necessary for maintaining the relationship with customers, prospects and other business partners. This includes information about contacts, relationship history (such as products and services, interactions, etc.), interests, marketing activities (such as newsletters, invitations to events, etc.) and other relevant information.

5 On what basis do we process your data?

Insofar as we ask for your consent for certain processing (e.g. for marketing mailings), we will inform you separately about the corresponding purposes of the processing and evaluation of your data. You can revoke your consent at any time with future effect by notifying us in writing (by mail) or by e-mail; you will find our contact details in section 2. For revocation of your consent for online tracking, see section 11. Once we have received notification of the withdrawal of your consent, we will no longer process your data for the purposes to which you originally consented, unless we have another legal basis for doing so. The revocation of your consent does not affect the legality of the processing carried out on the basis of the consent until the revocation.

6 Who do we disclose your data to?

We disclose your personal data only in limited cases and under strict protective measures. In the context of concluding contracts, providing our services and products, and in the context of the purposes set out in section 4, we also transfer your data to third parties, in particular to the following categories of recipients:

AGILITA Group AG

Data must be shared within the entire group of companies. This internal data transfer enables us to use synergies and to process your requests efficiently.

Third

In situations where we use services from external partners, we are required to share relevant information with those partners. This is particularly the case if these service providers are involved in the execution of the services ordered by you. These service providers, also referred to as service providers, work closely with us to perform the requested tasks.

Our obligation to share data with third parties is always in accordance with applicable data protection laws and only when necessary to fulfill our contractual and business obligations. We ensure that these third parties also treat your data confidentially and ensure that your privacy remains protected.

7 Do your personal data also end up abroad?

Our close cooperation extends to cloud providers (bsw. ERP, CRM, BTP and others). These cloud systems are used worldwide, which is why the processing of data takes place on an international level.

It is important to emphasize that these cloud partners have their own privacy policies to which we refer and which are in accordance with the applicable data protection regulations. This policy ensures adequate protection of your data and privacy when it is processed abroad.

8 How long do we process your data?

We retain your data for as long as is necessary for our processing purposes, applicable legal retention periods and our legitimate interests in documentation, or as long as storage is necessary for technical reasons. For more information on the respective storage and processing periods, please refer to section 3 for the individual data categories or section 11 for the cookie categories. Unless there are legal or contractual obligations to the contrary, we will delete or anonymize your data in accordance with our usual procedures after the specified storage or processing period has expired.

Our interest in documentation and preservation of evidence includes recording events, interactions, and other facts in the event of legal claims, discrepancies, IT and infrastructure security purposes, and to demonstrate sound governance and compliance. Technically necessary retention may occur when certain data cannot be kept separately from other data and therefore must be kept together with it, for example in backups or document management systems.

9 How do we protect your data?

We take adequate security measures to ensure the confidentiality, integrity and availability of your personal data. Our goal is to protect this data from unauthorized or unlawful processing and to minimize risks such as data loss, accidental alteration, unintentional disclosure or unauthorized access.

Technical and organizational security measures include, for example, measures such as data encryption, logging, access restrictions, the creation of backup copies, training for our employees, confidentiality agreements and monitoring mechanisms. When transmitting data via our website, we protect your information using appropriate encryption procedures. However, it is important to note that we can only secure the areas that are under our control. We also ensure that our processors take appropriate security precautions. However, security risks cannot be completely ruled out in general, so residual risks are unavoidable.

10 What rights do you have?

Under specific circumstances, you have the right to object to the processing of your data in accordance with the applicable data protection regulations.

In order to provide you with better control over the processing of your personal data, the following rights are also available to you within the scope of our data processing, depending on the applicable data protection law:

  • The right to request information from us as to whether and what data we process from you

  • the right to have us correct your data if it is inaccurate

  • the right to request the deletion of data

  • the right to request that we provide certain personal data in a commonly used electronic format or transfer it to another data controller

  • the right to withdraw their consent, insofar as our processing is based on your consent

  • the right to obtain, on request, further information necessary for the exercise of these rights

If you wish to exercise your above rights with us (or against one of our subsidiaries), please contact us in writing by email. Our contact details are listed in section 2. To ensure protection against misuse, it is necessary for us to verify your identity (for example, by presenting a copy of your ID, unless there are no other options).

Please note that conditions, exceptions or limitations apply to these rights under applicable data protection law (e.g., to protect third parties or trade secrets). We will inform you accordingly if necessary.

11 Vdo we use online tracking and online advertising techniques?

Within this section, we provide insight into the various techniques we use on our website to identify you and, where applicable, third parties engaged by us during your use and potentially track you across multiple visits.

11.1 We use the following cookies (techniques):

Cookies are sometimes used by Internet sites. They do not cause any harm to your computer, nor do they contain viruses. Cookies are small text files that are placed on your computer and stored by your browser (Chrome, Safari, Firefox, etc.).

We mainly use so-called “session cookies“, which are automatically deleted at the end of your visit. Other cookies remain stored on your terminal device until you delete them. These allow us to recognize your browser the next time you visit our website.

You can adjust the use of cookies in your browser settings to suit your needs and preferences. However, it should be noted that the functionality of websites may be limited if cookies are disabled.

Google Analytics:

The websites of AGILITA AG and AGILITA Deutschland GmbH use functions of the web analytics service Google Analytics. The provider is Google Inc, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA.

The collection by Google Analytics can be prevented via the following link. An opt-out cookie is set that prevents future collection of your data when visiting this website.

For more information about how Google Inc. handles personal data can be found here: Advertising and Privacy.

12 What data do we process on our pages in social networks?

We may operate pages and other online presences on social networks and other platforms operated by third parties (“fanpages“, “channels“, “profiles“, etc.). We receive this data from you and the platforms when you contact us via our online presence (e.g., when you communicate with us, comment on our content or visit our presences). At the same time, the platforms evaluate your use of our online presences and link this data with other data about you known to the platforms. They also process this data for their own purposes under their own responsibility, in particular for marketing purposes (e.g. to personalize advertising) and to control their platforms (e.g. which content they show you).

We receive data about you when you communicate with us via online presences or view our content on the corresponding platforms, visit our online presences or are active in them (e.g. publish content or submit comments). These platforms also collect from you or about you, among other things, technical data, registration data, communication data, behavioral data and preference data (for the terms see section 3). On a regular basis, these platforms statistically evaluate the way you interact with us, how you use our online presences, our content or other parts of the platform (what you look at, comment on, “like”, redistribute, etc.) and link this data to other information about you (e.g., information about age and gender and other demographic information). In this way, they also create profiles about you and statistics on the use of our online presences. They use this data and profiles to show you our or other advertising and other content on the Platform in a personalized way and to manage Platform behavior, but also for market and user research and to provide us and other entities with information about you and how you use our online presence. We can partially control the evaluations that these platforms generate regarding the use of our online presences.

We process this data for the purposes described in section 4, in particular for communication, marketing purposes (including advertising on these platforms, see section 11) and market research. For the relevant legal bases, please refer to Section 5. We or the operators of the platforms may also delete or restrict content from or to you in accordance with the usage guidelines (e.g. inappropriate comments).

For further information on the processing of the operators of the platforms, please refer to the privacy notices of the platforms. There you can also find out in which countries they process your data, which rights of access, deletion and other data subjects you have and how you can exercise these or obtain further information. We currently use the following platforms:

Facebook:

On the website of AGILITA AG and the website of AGILITA Deutschland GmbH, functions from the Facebook service are integrated. The provider is Facebook Inc, 1 Hacker Way, Menlo Park, California 94025, USA. The Facebook plug-ins are recognizable by the Facebook logo. You can find an overview of the Facebook plug-ins here:

https://developers.facebook.com/docs/plugins/?locale=de_DE

When you visit our website, the plugin creates a direct connection between your web browser and the Facebook server. A message is sent to Facebook that you have visited our website with your IP address. If you click the Facebook “Follow Button” while logged into your Facebook account, you can view, share and comment on the content of our pages on your Facebook profile. Facebook can thus assign the visit to our pages to your user account. We would like to point out that we, as the provider of the website, do not receive any knowledge about the transmitted data as well as its use by Facebook.

You can find Facebook’s detailed privacy policy at the following link: http://de-de.facebook.com/policy.php.

If you do not want Facebook to be able to associate your visit to our pages with your Facebook user account, you should log out of your Facebook user account.

Instagram:

The website of AGILITA AG and the website of AGILITA Deutschland GmbH include functions from the Instagram service. This service is provided by Instagram Inc., 1601 Willow Road, Menlo Park, CA, 94025, USA. If you are connected to your Instagram account, you can see, comment on and share the content of our Instagram profile by clicking on the Instagram “Follow button”. This allows Instagram to associate the visit to our websites with your Instagram user account. We would like to point out that we as a website provider have no knowledge of the content of the transmitted data or its use by Instagram.

The detailed privacy policy of Instagram can be found at the following link: http://instagram.com/about/legal/privacy/

If you do not want Instagram to be able to associate your visit to our pages with your Instagram user account, you should log out of your Instagram user account.

LinkedIn:

Functions of the networking service LinkedIn are integrated on the website of AGILITA AG and the website of AGILITA Deutschland GmbH. The provider is LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA. If you are connected to your LinkedIn account, a connection to LinkedIn servers will be established. LinkedIn is informed that you are visiting or have visited the websites of AGILITA Group AG with your IP address. If you click the “Follow button” of LinkedIn, this enables LinkedIn to assign your visit to our website to you and your user account. We would like to point out that we, as the website provider, have no knowledge of the content of the transmitted data or its use by LinkedIn.

LinkedIn’s detailed privacy policy can be found at the following link: https://www.linkedin.com/legal/privacy-policy

If you do not want LinkedIn to be able to assign the visit to our pages to your LinkedIn user account, you should log out of your LinkedIn user account.

XING:

The website of AGILITA AG and the website of AGILITA Deutschland GmbH include functions of the XING network service. The provider is New Work SE, Am Strandkai 1, 20457 Hamburg, Germany. If you are connected to your XING account, a connection to XING servers will be established. XING is informed that you are visiting or have visited the AGILITA Group AG websites with your IP address. If you click on the “Follow button” of XING, this enables XING to assign your visit to our website to you and your user account. We would like to point out that we, as the website provider, have no knowledge of the content of the transmitted data or its use by XING.

To our knowledge, no personal data is stored by XING. In particular, no IP addresses are stored or usage behavior evaluated.

The detailed privacy policy and further information about XING’s share buttons can be found at the following link: https://privacy.xing.com/de/datenschutzerklaerung

If you do not want XING to be able to associate your visit to our pages with your XING user account, you should log out of your XING user account.

Twitter:

Functions of the Twitter service are integrated on the website of AGILITA AG and the website of AGILITA Deutschland GmbH. These functions are offered by Twitter Inc., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA. By using Twitter and the “Re-Tweet” function, the websites you visit are linked to your Twitter account and made known to other users. In the process, data is also transferred to Twitter. We would like to point out that we, as the website provider, have no knowledge of the content of the transmitted data or its use by Twitter.

Twitter’s detailed privacy policy can be found at the following link: https://twitter.com/de/privacy.

You can change your Twitter privacy settings in your account settings at: http://twitter.com/account/settings change

If you do not want Twitter to be able to associate your visit to our pages with your Twitter user account, you should log out of your Twitter user account.

YouTube:

The website of AGILITA AG and the website of AGILITA Deutschland GmbH include functions of the streaming service YouTube. The provider is YouTube, LLC, 901 Cherry Ave, San Bruno, CA 94066, USA.

If you are connected to your Youtube account, a connection to Youtube servers will be established. Youtube is informed that you are visiting or have visited the websites of AGILITA Group AG with your IP address. If you click on the “Follow button” of Youtube, this enables Youtube to assign your visit to our website to you and your user account. We would like to point out that we, as the website provider, have no knowledge of the content of the transmitted data or its use by Youtube.

If you do not want Youtube to be able to associate your visit to our pages with your Youtube user account, you should log out of your Youtube user account.

The detailed privacy policy of Youtube can be found at the following link: https://www.google.de/intl/de/policies/privacy

SalesViewer® technology

On the website of AGILITA AG and the website of AGILITA Deutschland GmbH, data is collected and stored for marketing, market research and optimization purposes using the SalesViewer® technology of SalesViewer® GmbH based on the legitimate interests of the website operator (Art. 6 para.1 lit.f DSGVO).

For this purpose, a javascript-based code is used to collect company-related data and the corresponding usage. The data collected with this technology is encrypted using a non-reversible one-way function (known as hashing). The data is immediately pseudonymized and not used to personally identify the visitor to this website.

The data stored as part of Salesviewer will be deleted as soon as it is no longer required for its intended purpose and the deletion does not conflict with any statutory retention obligations.

You can object to the collection and storage of data at any time with effect for the future by clicking on this link https://www.salesviewer.com/de/opt-out/ to prevent the collection by SalesViewer® within this website in the future. This places an opt-out cookie for this website on your device. If you delete your cookies in this browser, you must click this link again.

13 Applicant data

The AGILITA Group works with the e-recruiting solution of Personio SE & Co. KG, Seidlstraße 3, 80335 Munich, Germany (UID: DE351718597), which carries out the data storage in relation to application documents for us. Personal data is neither analyzed in detail by machine (“profiling“) nor are automated data processing methods used for decision-making (“matching“).

For more information and the privacy policy of Personio SE & Co. KG, please visit https://www.personio.de/datenschutzerklaerung/.

We reserve the right to keep your application documents stored with us for a maximum of 10 years after completion of the application process, so that we can contact you to fill other interesting positions. If you do not agree with this practice, please let us know briefly.

14 Can this privacy policy be changed?

This privacy policy is not part of any contract with you. We reserve the right to adjust this privacy policy at any time. The currently valid version of this declaration can always be found on our website.