Privacy Policy

We hereby inform you about the processing of your personal data ("Data") when you visit our website (A.), receive our invitation mailings (B.), when you are in business contact with us (D.), when you apply for a job with us (E.) or when you visit our social media profiles (F.) Under (G.) we inform you about your rights which you are entitled to in all the aforementioned cases of data processing by us.

We are responsible for the following data processing in each case:

abat AG
An der Reeperbahn 10
28217 Bremen
Germany
Fon: 0421 / 43 04 6-0
Fax: 0421 / 43 04 6-77
E-mail: info@abat.de

You can reach our data protection officer at: datenschutz@abat.de

A. Data processing on our website

In this section we inform you about the processing of your data when you visit our website.

A.I. Joint responsibility

We operate the website jointly with abat+ GmbH and process personal data with abat+ GmbH under joint responsibility.

Jointly responsible with us (Art. 26 DSGVO):

abat+ GmbH
Innovation Park at the Beckerturm
Kaiserstrasse 170 - 174
66386 St. Ingbert
Phone: +49 6894-38808-00
Fax:+49 6894-38808-99
You can reach the abat+ company data protection officer at: daten-schutz@abatplus.de


We have concluded an agreement with abat+ on joint processing in accordance with Art. 26 (1) DSGVO. Essentially, we have agreed therein which data protection principles are to be adhered to, which contact persons are available at each company with regard to data protection law, which IT security measures are to be taken and that you can contact abat or abat+ at your request with regard to the assertion of data subject rights (e.g. right of information, right of deletion). Details on your data subject rights can be found below in the section "Your rights".

A.II. Operation of the website

Scope of data processing
When you call up our website, the following data is transmitted to our web server and stored in a log file:

  • IP address
  • date and time of the respective access to a page of the website
  • amount of data transferred to your device
  • files retrieved via the homepage
  • URL of the page/homepage from which you accessed our website
  • Browser used by you (type and version)
  • operating system used by you (type and version)

Purposes of the data processing
The processing of this data is necessary to display the contents of the website in the best possible way on your device. In addition, we process this data to defend against, investigate and clarify attacks on our IT.

Legal basis of data processing
The processing of this data is carried out in accordance with Art. 6 (1) lit. f DSGVO based on our legitimate interest already mentioned above in being able to display the website to you in the best possible way and to be able to track attacks on our IT.

Recipients of the data
Our web hosting service provider processes the aforementioned data strictly in accordance with instructions on our behalf on the basis of a contract for commissioned processing pursuant to Art. 28 DSGVO. These are: Mittwald CM Service GmbH & Co. KG, Königsberger Straße 4-6, 32339 Espelkamp.
As part of the operation of the website, we are supported by the advertising agency ARTWORXX - Anne Pralle, An der Reeperbahn 10, 28217 Bremen with whom we have also concluded a contract for order processing in accordance with Art. 28 DSGVO.

Storage period
The log data is stored for a period of 7 days and then deleted, unless it is necessary to keep it longer by way of exception in order to follow up on an identified attack.

 

A.III.Use of cookies

When you visit our websites, we set so-called cookies. These are small text files that are stored on your terminal device. Cookies usually contain a characteristic sequence of characters, the so-called cookie ID, with which your browser can be identified when you call up our web pages again.
The cookies of the website contain personal data. Cookies save you from having to enter data several times, facilitate the transmission of specific content and help us to identify particularly popular areas of our website. They thus enable us to continuously improve the structure and content of our website.
The data processing involved in the use of cookies is described in more detail below.

1. technically necessary cookies

Scope of data processing
Technically necessary cookies enable basic functions and are required for the proper functioning of the website. On our website, we use the session cookie PHPSESSID, which can only be used by the current website. No information is stored in the user's browser.

Purposes of data processing
This cookie is used to increase the user experience.

Legal basis of data processing
The legal basis for the use of the cookie is Art. 6 para. 1 sentence 1 lit. f DSGVO.
We use the cookie to increase the usability of the website. This session cookie saves your current session with regard to PHP applications and thus ensures that all functions of the site based on the PHP programming language can be fully displayed. This is also where the particular interest in data processing lies.

Storage period
The information is stored only until the end of the browser session.

 

2. analysis cookies (statistics)

2.1 Matomo

This website uses the open-source web analysis service Matomo.
Through Matomo, we are able to collect and analyze data on the use of our website-by-website visitors. This enables us to find out, for instance, when which page views occurred and from which region they came. In addition, we collect various log files (e.g. IP address, referrer, browser, and operating system used) and can measure whether our website visitors perform certain actions (e.g. clicks, purchases, etc.).

Legal basis
The use of this analysis tool is based on Art. 6(1)(f) GDPR. The website operator has a legitimate interest in the analysis of user patterns, in order to optimize the operator’s web offerings and advertising. If appropriate consent has been obtained, the processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and § 25 (1) TTDSG, insofar the consent includes the storage of cookies or the access to information in the user’s end device (e.g., device fingerprinting) within the meaning of the TTDSG. This consent can be revoked at any time.

IP anonymization
For analysis with Matomo we use IP anonymization. Your IP address is shortened before the analysis, so that it is no longer clearly assignable to you.

Recipients of the data
The recipient data is managed in the Matomo Cloud.
This provides a secure infrastructure for servers, databases and logs in Frankfurt, Germany. Offsite backups are stored in Dublin, Ireland. This service is provided by AWS New Zealand and all data is hosted in Europe.

Order processing
We have concluded an order processing agreement (AVV) for the use of the above-mentioned service. This is a contract required by data protection law, which ensures that this processes the personal data of our website visitors only according to our instructions and in compliance with the GDPR.

 

2.2 Meta-Pixel (formerly Facebook Pixel)
If analysis / statistics cookies have been selected, the website uses the visitor action pixel from Facebook/Meta for conversion measurement. The provider of this service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. However, according to Facebook, the collected data is also transferred to the USA and other third countries. 

This tool allows the tracking of page visitors after they have been linked to the website of the provider after clicking on a Facebook ad. This makes it possible to analyze the effectiveness of Facebook ads for statistical and market research purposes and to optimize future advertising campaigns.

For us as the operators of this website, the collected data is anonymous. We are not in a position to arrive at any conclusions as to the identity of users. However, Facebook archives the information and processes it, so that it is possible to make a connection to the respective user profile and Facebook is in a position to use the data for its own promotional purposes in compliance with the Facebook Data Usage Policy ( https://www.facebook.com/about/privacy/). This enables Facebook to display ads on Facebook pages as well as in locations outside of Facebook. We as the operator of this website have no control over the use of such data.

Legal basis
The use of these services occurs on the basis of your consent pursuant to Art. 6(1)(a) GDPR and § 25(1) TTDSG. You may revoke your consent at any time.

Insofar as personal data is collected on our website with the help of the tool described here and forwarded to Facebook, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland are jointly responsible for this data processing (Art. 26 DSGVO). The joint responsibility is limited exclusively to the collection of the data and its forwarding to Facebook. The processing by Facebook that takes place after the onward transfer is not part of the joint responsibility. The obligations incumbent on us jointly have been set out in a joint processing agreement. The wording of the agreement can be found under: https://www.facebook.com/legal/controller_addendum. According to this agreement, we are responsible for providing the privacy information when using the Facebook tool and for the privacy-secure implementation of the tool on our website. Facebook is responsible for the data security of Facebook products. You can assert data subject rights (e.g., requests for information) regarding data processed by Facebook directly with Facebook. If you assert the data subject rights with us, we are obliged to forward them to Facebook.

Data transmission to the US is based on the Standard Contractual Clauses (SCC) of the European Commission. Details can be found here: https://www.facebook.com/legal/EU_data_transfer_addendum and https://de-de.facebook.com/help/566994660333381.

In Facebook’s Data Privacy Policies, you will find additional information about the protection of your privacy at: https://www.facebook.com/about/privacy/.

You also have the option to deactivate the remarketing function “Custom Audiences” in the ad settings section under https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen. To do this, you first have to log into Facebook.

If you do not have a Facebook account, you can deactivate any user-based advertising by Facebook on the website of the European Interactive Digital Advertising Alliance: http://www.youronlinechoices.com/de/praferenzmanagement/.

 

2.3 LinkedIn Insight Tag
If analysis / statistics cookies have been selected, the website uses the Insight tag from LinkedIn. The provider of this service is LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland.

We use the LinkedIn Insight tag to obtain information about visitors to our website. Once a website visitor is registered with LinkedIn, we can analyze the key occupational data (e.g., career level, company size, country, location, industry, job title) of our website visitors to help us better target our site to the relevant audience. We can also use LinkedIn Insight tags to measure whether visitors to our websites make a purchase or perform other actions (conversion measurement). Conversion measurement can also be carried out across devices (e.g. from PC to tablet). LinkedIn Insight Tag also features a retargeting function that allows us to display targeted advertising to visitors to our website outside of the website. According to LinkedIn, no identification of the advertising addressee takes place. LinkedIn itself also collects log files (URL, referrer URL, IP address, device and browser characteristics and time of access). The IP addresses are shortened or (if they are used to reach LinkedIn members across devices) hashed (pseudonymized). The direct identifiers of LinkedIn members are deleted by LinkedIn after seven days. The remaining pseudonymized data will then be deleted within 180 days. The data collected by LinkedIn cannot be assigned by us as a website operator to specific individuals. LinkedIn will store the personal data collected from website visitors on its servers in the USA and use it for its own promotional activities. For details, please see LinkedIn’s privacy policy at https://www.linkedin.com/legal/privacy-policy#choices-oblig.

Legal basis
If your approval (consent) has been obtained the use of the abovementioned service shall occur on the basis of Art. 6(1)(a) GDPR and § 25 TTDSG (German Telecommunications Act). Such consent may be revoked at any time. If your consent was not obtained, the use of the service will occur on the basis of Art. 6(1)(f) GDPR; the website operator has a legitimate interest in effective advertising promotions that include the utilization of social media.

Data transmission to the US is based on the Standard Contractual Clauses (SCC) of the European Commission. Details can be found here: https://www.linkedin.com/legal/l/dpa and https://www.linkedin.com/legal/l/eu-sccs.

Objection to the use of LinkedIn Insight Tag
You can object to LinkedIn’s analysis of user behavior and targeted advertising at the following link: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.

In addition, LinkedIn members can control the use of their personal information for promotional purposes in the account settings. To prevent LinkedIn from linking information collected on our site to your LinkedIn account, you must log out of your LinkedIn account before you visit our site.

Data processing
We have concluded a data processing agreement (DPA) for the use of the above-mentioned service. This is a contract mandated by data privacy laws that guarantees that they process personal data of our website visitors only based on our instructions and in compliance with the GDPR.

 

2.4 Echobot "Target" (third-party survey)

If analysis / statistics cookies have been selected, the website uses the "Target" tool of Echobot Media Technologies GmbH, Durlacher Allee 73, D-76131 Karlsruhe.
 
Data processing by Echobot "Target
The "Target" tool is a search engine for which Echobot itself is the data controller. It enables searches in publicly available data from online news, blogs, company websites, register databases and social media networks with a business connection.
Through this use, we collect and process data that is not collected from the data subject, but which we receive via this tool. This is a so-called third-party collection, so the information in this passage is provided in accordance with Art. 14 DSGVO.
 
Purpose of processing
Purpose of data processing: we use the tool "Target" from Echobot to identify companies that are interested in our offer. If they have given consent, e.g. via the Newspaper, that contact is permitted, we reserve the right to use the data for this purpose.

Legal basis
The legal basis is the principle of "accuracy" Art. 5 para. 1 d DSGVO as well as the protection of our legitimate interests for the purpose of verification and updating of our database in accordance with Art. 6 para. 1 letter f) DSGVO. The data is used exclusively for the purposes stated in this data protection declaration. The use for advertising purposes only takes place if we have received the corresponding consent. By way of exception, advertising without consent may be legally permissible (e.g. in the case of presumed consent in the B2B area in the case of telephone contact pursuant to Section 7 (2) No. 2 UWG). If this is the case, the associated data processing is based on our overriding legitimate interest in the form of the purposes described above pursuant to Art. 6 (1) (f) DSGVO.

Duration of storage
We only store personal data by using "Target" if we can assume the existence of a presumed consent to contact you by telephone in order to then enable this telephone contact. We store the data until we no longer need it to fulfill the purposes pursued. In all other cases, we only use the search engine for the above-mentioned purposes and do not store any personal data ourselves.

Objection to the use of Echobot "Target".
You may exercise a right of revocation, if the conditions of Art. 21 DSGVO are met, in the case of data processing that is carried out on the basis of an overriding legitimate interest, if the data processing must be refrained from for reasons arising from your particular situation or, if the data processing is carried out for the purpose of direct advertising.

Order processing
No order processing takes place in this context, as we use personal data provided by Echobot in its "Target" search engine and no data is processed by Echobot on our behalf (see https://echobot.app.box.com/s/6m9xlm3z4kactvypjxg8z6h2qoj4l8hq). Further information on Echobot can be found at https://www.echobot.de. Privacy policy: https://www.echobot.de/datenschutz

 

3. deactivation of cookies

You have full control over the use of cookies and can delete cookies in your browser, disable the storage of cookies altogether, selectively accept certain cookies and, if necessary, set your browser to notify you if a cookie is to be set. Please use the help functions of your browser to learn how to change these settings. This may limit the functionality of our websites.

Firefox: https://support.mozilla.org/en-US/kb/clear-cookies-and-site-data-firefox
Chrome: https://support.google.com/chrome/answer/95647?co=GENIE.Platform%3DDesktop&hl=en
Safari: https://support.apple.com/guide/safari/manage-cookies-and-website-data-sfri11471/mac
Edge: https://support.microsoft.com/en-us/topic/delete-and-manage-cookies-168dab11-0753-043d-7c16-ede5947fc64d
Internet Explorer: https://support.microsoft.com/en-us/topic/how-to-delete-cookie-files-in-internet-explorer-bca9446f-d873-78de-77ba-d42645fa52fc

A.IV. contact form

Scope of data processing
You can contact us via a contact form on the website. In doing so, we collect the following data:

  • First name, last name
  • E-mail address
  • Telephone number
  • Street, No.
  • Postal code, city
  • Company, position
  • Message

Purpose of data processing
We process your data in order to be able to handle your inquiry, registration and/or appointment with us in the best possible way.

Legal basis of data processing
We process your data on the basis of Art. 6 para. 1 sentence 1 lit. f DSGVO. Our legitimate interest lies in responding to your inquiry directed to us.

Recipients of the data
The data is only processed by the abat AG contact persons responsible internally for the contact inquiries.

Storage period
The storage period depends on the content of your contact request. In principle, the data is deleted as soon as it is no longer required to achieve the purpose for which it was collected and any statutory retention obligations have expired.

A.V. Data security

To protect your personal data against manipulation, loss, destruction or access by unauthorized persons, ongoing technical and organizational security measures are taken. In particular, we use TLS encryption when transmitting data via our website. You can recognize this by the fact that the lock symbol is closed in the status bar of your browser and the address bar begins with https://.

B. Invitation mailings

Scope of data processing
We use the invitation mailings to inform you about various dates, e.g. about our "expert knowledge", upcoming free events or downloads, or events about new product features. You can register for these events on our website.
To register, you must fill in the mandatory fields marked with an asterisk. Your e-mail address, name and title are required for registration. In addition, we store your IP addresses and the times of registration and confirmation. The purpose of this storage is to be able to prove your registration and, if necessary, to clarify a possible misuse of your personal data.
To verify your e-mail address, we use the so-called double opt-in procedure. This means that after you have provided us with your e-mail address, we will send you a confirmation e-mail to the e-mail address you have provided, in which we ask you to confirm that you wish to receive the invitation mailings.

Data analysis
We use the CleverReach service to send the invitation mailings. With the help of CleverReach, we are able to analyze the invitation mailings. This allows us to see, among other things, whether an information mail has been opened and which links, if any, have been clicked on. In this way, we can determine, among other things, which links were clicked on particularly often and thus optimize our invitation mailings. For detailed information on the functions of CleverReach, please refer to the following link: https://www.cleverreach.com/en/features/privacy-security/eu-general-data-protection-regulation-gdpr/

Purposes of data processing
We process your data for the purpose of sending you the invitation mailings and providing you with up-to-date information.

Legal basis of data processing
We process the data on the basis of consent given by you on a voluntary basis in accordance with Art. 6 para. 1 sentence 1 lit. a DSGVO.
You can revoke your consent at any time with effect for the future and unsubscribe from the invitation mailings. You can declare the revocation by clicking on the link provided in each information mail or by sending an e-mail to datenschutz@abat.de.

Recipient of the data
CleverReach GmbH & Co. KG, CRASH Building, Schafjückenweg 2, 26180 Rastede, Germany.
Mail:  info@cleverreach.com Website: www.cleverreach.com.
CleverReach processes the data strictly in accordance with instructions on our behalf on the basis of a contract for commissioned processing in accordance with Art. 28 DSGVO.

Storage period
We process your data for sending the invitation mailings until you unsubscribe from the invitation mailings. So that we can later prove that you lawfully received the invitation mailings in the past, we store information about the granting of your consent and about the unsubscription for the duration of the statutory limitation periods (usually three years).

Google reCAPTCHA
We use "Google reCAPTCHA" (hereinafter "reCAPTCHA") on our websites. The provider is Google Inc, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google").
The purpose of reCAPTCHA is to verify whether data entry on our websites (e.g. in a contact form) is made by a human or by an automated program. For this purpose, reCAPTCHA analyzes the behavior of the website visitor based on various characteristics. This analysis starts automatically as soon as the website visitor enters the website. For the analysis, reCAPTCHA evaluates various information (e.g. IP address, time spent by the website visitor on the website or mouse movements made by the user). The data collected during the analysis is forwarded to Google.
The reCAPTCHA analyses run entirely in the background. Website visitors are not made aware that an analysis is taking place.
The data processing is based on Art. 6 para. 1 lit. f DSGVO. The website operator has a legitimate interest in protecting its web offers from abusive automated spying and from SPAM.

For more information on Google reCAPTCHA and Google's privacy policy, please see the following links: https://policies.google.com/privacy?hl=en and https://www.google.com/recaptcha/intro/android.html.

C. Whitepaper

On our website you have the possibility to download whitepapers for free.
Before downloading, the data from the input mask is transmitted to us. 
If you have received a whitepaper and have entered your e-mail address, this may subsequently be used by us in return for sending an invitation mailing. In such a case, the invitation mailing will only be used to send direct advertising for our own similar topics. No data will be passed on to third parties in connection with the processing of data for the dispatch of invitation mailings. The data is used exclusively for sending the invitation mailing.

In addition, the following data is collected during registration:

  • IP address of the calling computer
  • Date and time of registration

Right of withdrawal
The subscription to the invitation mailing can be cancelled by the user concerned at any time. For this purpose, a corresponding link can be found in each invitation mailing.
This enables a revocation of the consent to the storage of the personal data collected during the registration process for the future.

Purposes of data processing
We process your data for the purpose of sending you the invitation mailings and providing you with up-to-date information.

Legal basis of data processing
We process the data on the basis of consent given by you on a voluntary basis in accordance with Art. 6 Para. 1 Sentence 1 lit. a DSGVO.
You can revoke your consent at any time with effect for the future and unsubscribe from the invitation mailings. You can declare the revocation by clicking on the link provided in each information mail or by sending an e-mail to datenschutz@abat.de.

Recipients of the data
-Web hosting service provider. Mittwald CM Service GmbH & Co. KG, Königsberger Straße 4-6, 32339 Espelkamp.
-Advertising agency ARTWORXX. An der Reeperbahn 10, 28217 Bremen. 
-CleverReach GmbH & Co. KG, CRASH Building, Schafjückenweg 2, 26180 Rastede, Germany.

Storage period
We process your data to send the invitation mailings until you unsubscribe from the invitation mailings. So that we can later prove that you lawfully received the invitation mailings in the past, we store information about the granting of your consent and about the unsubscription for the duration of the statutory limitation periods (usually three years).

D. Business contacts

I. Processing of personal data of business contacts

Scope of data processing

In the course of our business relationship with you as a business customer, service provider or supplier or as an employee of our business partners, we process the data we receive from you or your employer.
In particular, this is data that we receive as soon as you or one of your colleagues make contact with our employees. The contact may, for example, be made electronically (by e-mail) or in person (e.g. contact at trade fairs, handing over a business card).
We may process the following categories of data in this context:

  • Professional contact and organizational data: e.g. surname, first name, title, academic degree, gender, possibly name of the company for which you appear, department, professional e-mail address, address, telephone number
  • Data on professional relationships: e.g. job title, tasks, activity, qualifications
  • Other: In addition, we may process other data that you provide within the interaction with our employees.

We use your data to communicate with you (e.g. by e-mail) for business purposes and, for example, to send you offers. In this context, we store your contact data in our CRM system and, if necessary, in other contact directories (e.g. in Outlook).

Purposes of data processing
Your data will be processed by us for the purpose of establishing and implementing the contractual relationship with you as a business customer, as well as for compliance with legal requirements.

Legal basis for data processing
If you are personally our business partner, the processing is carried out on the basis of Art. 6 (1) lit. b DSGVO for the purpose of implementing or initiating the contract.
For the purpose of fulfilling legal obligations, processing is carried out on the basis of Art. 6 (1) lit. c DSGVO in conjunction with legal and official requirements (for example, from tax and commercial law).
If you are an employee of one of our business partners, your data will be processed on the basis of our overriding legitimate interests pursuant to Art. 6 (1) lit. f DSGVO. In this context, our legitimate interest lies in the functioning and practicable cooperation with our business partners and the employees of our business partners.

Recipients of your data
On the basis of contracts pursuant to Art. 28 DSGVO, personal data may be processed by external service providers (e.g. cloud, support, hosting or analysis service providers). The external service providers have been carefully selected and commissioned by us. They are contractually bound to our instructions, have appropriate technical and organizational measures to protect the rights of the data subjects and are regularly monitored by us.
To the extent necessary for the above purposes, we transfer your data to our subsidiaries. Our subsidiaries are:

- abat+ GmbH, Innovation Park am Beckerturm, Kaiserstrasse 170-174, 66386 St. Ingbert, Germany
- abatUS LLC, 950 22nd Street North, Suite 700, Birmingham, AL 35203, USA
- STAA BELabat, Pritytskogo Str. 156, Office 29, 220017 Minsk, Belarus
- ID-Impuls GmbH, Technologie- und Gründerzentrum Oldenburg, Marie-Curie-Straße 1, 26129 Oldenburg, Germany
- MEXabat, Calz. Zavaleta 3922 4to-6, Santa Cruz Buenavista, Puebla, Pue. CP. 72170, México
- ABAT LT, UAB, 08100 Vilnius, Lithuania
- abatCN Consulting (Beijing) Co., Ltd., 3F, No. 7 of Huihai Middle Rd., Airport Economic Core Area Shunyi District, Beijing

Transfer of your data to a third country
As a matter of principle, we endeavor to process your data in the European Union or the European Economic Area. If we transfer your data to a third country i.e. outside the European Union or the European Economic Area, this will only be done in accordance with the legal requirements.
Should a transfer of your personal data nevertheless take place, this will only be done insofar as an adequate level of data protection of the third country is ensured in accordance with an adequacy decision of the European Commission or appropriate safeguards (e.g. data protection contracts using the standard data protection clauses of the European Commission) can ensure adequate protection of your personal data.
We have concluded standard data protection clauses with our subsidiaries in non-EU countries.

Storage period
We store your data for as long as we need it for the specific processing purpose. We regularly store your data at least for the duration of our business relationship with you or the business customer for whom you work.
We also store certain data for the duration of statutory periods of limitation (usually three years, in individual cases up to thirty years) and for as long as required by statutory retention periods (e.g. from the German Commercial Code, the German Fiscal Code) (but usually for a maximum of ten years).
Under certain circumstances, we may have to retain your data for longer. This is the case, for example, if in connection with official or judicial proceedings a ban on data deletion is ordered for the duration of the proceedings.

D. II. Video Conferencing, Online Meetings and Webinars

We use platforms and applications from other providers ("Third-Party Providers") for purposes of conducting video and audio conferences, webinars, and other types of video and audio meetings. When selecting the third-party providers and their services, we observe the legal requirements. In this context, data of the communication participants are processed and stored on the servers of the third-party providers, insofar as these are part of communication processes with us. This data may include, in particular, registration and contact data, visual as well as vocal contributions and entries in chats and shared screen contents. If users are referred to the third-party providers, or their software or platforms, in the course of communication, business or other relationships with us, the third-party providers may process usage data and metadata for security, service optimization or marketing purposes. We therefore ask you to observe the data protection notices of the respective third-party providers.

Scope of data processing
When you participate in video conferences, online meetings or webinars from us, we generally process the following data:

  • Inventory data (e.g. names, addresses),
  • Meta/communication data (e.g. device information, IP addresses).

In individual cases, the following data could also be processed, for example if you have stored this information in your user profile or if you share content with us:

  • Contact data (e.g. e-mail, telephone numbers),
  • Content data (e.g. text input, photographs, videos),
  • Usage data (e.g. web pages visited, interest in content, access times).

Purposes of processing
We use the applications mentioned below to conduct video and audio conferences, webinars and other types of video and audio meetings.

Legal basis
If we ask users for their consent to use the third-party providers or certain features (e.g. consent to a recording of conversations), the legal basis of the processing is consent pursuant to Art. 6 (1) p. 1 lit. a DSGVO. Furthermore, their use may be a component of our (pre)contractual services pursuant to Art. 6 para. 1 p. 1 lit. b. DSGVO, provided that the use of the third-party providers was agreed in this context. Otherwise, the users' data is processed on the basis of our legitimate interests in efficient and secure communication with our communication partners pursuant to Art. 6 para. 1 p. 1 lit. f. DSGVO processed.

Recipients of the data
We currently use Microsoft Teams and Skype for Business. In this context, personal data is transferred to the operator of both services - Microsoft Ireland Operations Ltd, The Atrium Building, Block B, Carmanhall Road, Sandyford Business Estate, Dublin 18, Ireland ("Microsoft") - and processed on our behalf in accordance with instructions based on a commissioning agreement pursuant to Art. 28 DSGVO.

Microsoft Teams
Website: https://www.microsoft.com/en-us/microsoft-365?rtc=1
Privacy policy: https://privacy.microsoft.com/en-us/privacystatement
Security Information: https://www.microsoft.com/en-us/trustcenter

Skype for Business
Website: https://www.skype.com/en/
Privacy policy: https://privacy.microsoft.com/en-us/privacystatement
Security Information: https://www.microsoft.com/en-us/trustcenter

Transfer of your data to a third country
We have agreed with the third-party providers that the data will generally be processed within the EU. However, it cannot be technically ruled out that personal data may also be transferred to the USA when using the above services. In order to ensure sufficient guarantees for data transfers to the USA, we have concluded standard data protection clauses with Microsoft.

Storage period
Your data will be stored by us for as long as we need it for the specific processing purpose.

D. III. Music and Podcasts

We use hosting and analytics services provided by service providers to offer our audio content for listening or downloading and to obtain statistical information about the retrieval of the audio content.

Types of Data Processed: Usage data (e.g. web pages visited, interest in content, access times), meta/communication data (e.g. device information, IP addresses).

Data subjects: Users (e.g., website visitors, users of online services).

Purposes of processing: reach measurement (e.g. access statistics, recognition of returning visitors), conversion measurement (measurement of the effectiveness of marketing measures), profiling (creation of user profiles).

Services used and service providers:

Podigee: Podigee - music and podcast hosting; service provider: Podigee GmbH, Schlesische Straße 20, 10997 Berlin, Germany; website: https://www.podigee.com/en; privacy policy: https://www.podigee.com/en/about/privacy

Spotify: Spotify - music hosting and widget; service provider: Spotify AB, Regeringsgatan 19, SE-111 53 Stockholm, Sweden; website: https://www.spotify.com/us/; privacy policy: https://www.spotify.com/us/legal/privacy-policy/

Apple Podcast:
Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA.
Privacy policy: https://www.apple.com/legal/privacy/.

Deezer: 
Registered office:  24 rue de Calais 75009 Paris – FRANCE – +33 (0)1 84 25 25 00
Privacy Policy: https://www.deezer.com/legal/personal-datas

Google Podcast:
Gordon House, Barrow Street, Dublin 4, Ireland
E-Mail: support-deutschland@google.com
Privacy Policy: https://policies.google.com/privacy?hl=en

PlayerFM:
1880 Century Park East, Suite 1108, Los Angeles, CA 90067. support@player.fm.
Privacy Policy: https://de.player.fm/privacy

Pocket Casts:
Podcast Media LLC  support@pocketcasts.com 
Privacy Policy: https://support.pocketcasts.com/article/privacy-policy/

Podcast Addict:
https://podcastaddict.com/contact
Privacy Policy: https://podcastaddict.com/privacy

Stitcher:
Attn: Stitcher - Privacy, 8550 Freeport Parkway, Irving, Texas 75063 USA.  contact us at privacy@stitcher.com
Privacy Policy: https://www.stitcher.com/privacy

©Section D III: Dr.Schwenke

E. Applicants

The application process requires that applicants provide us with the data necessary for their assessment and selection. The information required can be found in the job description or, in the case of online forms, in the information provided there.
In principle, the required information includes personal information such as the name, address, a means of contact and proof of the qualifications required for a position. Upon request, we will be happy to provide additional information as to what information is required.
If provided, applicants can submit their applications to us using an online form. The data is transmitted to us in encrypted form in accordance with the state of the art. Applicants can also send us their applications by e-mail. Please note, however, that e-mails sent via the Internet are generally not encrypted. As a rule, e-mails are encrypted in transit, but not on the servers from which they are sent and received. Therefore, we cannot assume any responsibility for the transmission path of the application between the sender and the reception on our server.
For purposes of applicant search, submission of applications, and selection of applicants, we may use third-party applicant management, or recruitment software and platforms and services, subject to legal requirements.
Applicants are welcome to contact us regarding the method of submission of the application or to send us the application by mail.

Processing of special categories of data
Insofar as special categories of personal data within the meaning of Art. 9 (1) DSGVO (e.g. health data, such as severely disabled status or ethnic origin) are requested from applicants in the context of the application process in order for the controller or the data subject to exercise the rights accruing to him or her under labor law and social security and social protection law and to comply with his or her obligations in this regard, their processing is carried out in accordance with Art. 9 (2) letter b. DSGVO, in case of protection of vital interests of the applicants or other persons according to Art. 9 para. 2 lit. c. DSGVO or for the purposes of preventive health care or occupational medicine, for the assessment of the employee's ability to work, for medical diagnostics, for care or treatment in the health or social sector or for the management of systems and services in the health or social sector pursuant to Art. 9 para. 2 lit. h. DSGVO. In the case of notification of the special categories of data based on voluntary consent, their processing is based on Art. 9 para. 2 lit. a. DSGVO.

Deletion of data
The data provided by applicants may be further processed by us for the purposes of the employment relationship in the event of a successful application. Otherwise, if the application for a job offer is not successful, the applicants' data will be deleted. Applicants' data will also be deleted if an application is withdrawn, which applicants are entitled to do at any time. Subject to a justified withdrawal by the applicants, the deletion will take place at the latest after the expiry of a period of six months so that we can answer any follow-up questions about the application and meet our obligations to provide evidence under the regulations on equal treatment of applicants. Invoices for any reimbursement of travel expenses will be archived in accordance with tax law requirements.

Inclusion in an applicant pool
Inclusion in an applicant pool, if offered, is based on consent. Applicants are informed that their consent to inclusion in the talent pool is voluntary, has no influence on the current application process and that they can revoke their consent at any time for the future.

Duration of data retention in the applicant pool in months: 6 months

  • Types of data processed: applicant data (e.g. personal details, postal and contact addresses, the documents belonging to the application and the information contained therein, such as cover letter, CV, certificates and other information provided with regard to a specific position or voluntarily by applicants regarding their person or qualifications).
  • Data subjects: Applicants.
  • Purposes of processing: application procedure (establishment and possible subsequent implementation as well as possible subsequent termination of the employment relationship.).
  • Legal basis: Art. 9 para. 1 p. 1 lit. b DSGVO (application procedure as a pre-contractual or contractual relationship) (Insofar as special categories of personal data within the meaning of Art. 9 para. 1 DSGVO (e.g. health data, such as severely disabled status or ethnic origin) are requested from applicants so that the data controller or the data subject can exercise the rights accruing to him or her under labor law and social security and social protection law and fulfill his or her obligations in this regard, their processing is carried out in accordance with Art. 9 (2) lit. b. DSGVO, in case of protection of vital interests of the applicants or other persons according to Art. 9 para. 2 lit. c. DSGVO or for the purposes of preventive health care or occupational medicine, for the assessment of the employee's ability to work, for medical diagnostics, care or treatment in the health or social sector or for the management of systems and services in the health or social sector pursuant to Art. 9 para. 2 lit. h. DSGVO. In the case of communication of special categories of data based on voluntary consent, their processing is based on Art. 9 para. 2 lit. a. DSGVO.).

Services used and service providers

Stepstone: Recruiting platform and services; service provider: StepStone Deutschland GmbH, Völklinger Straße 1, 40219 Düsseldorf, Germany; Website: https://www.stepstone.de/en/ Datenschutzerklärung: https://www.stepstone.de/ueber-stepstone/legal-notes/data-protection-policy/

Xing: Service provider: XING AG, Dammtorstraße 29-32, 20354 Hamburg, Germany; Website: https://www.xing.com; privacy policy: https://privacy.xing.com/en/privacy-policy.

Multiposting & Bewerbermanagement | JOIN: JOIN Solutions GmbH, Schönhauser Allee 36, 10435 Berlin, Germany; Website: https://join.com/de/
Privacy Policy: https://join.com/de/datenschutz/
 
Bundesagentur für Arbeit: Regensburger Straße 104, 90478 Nürnberg, Germany, Phone: 0911/179-0, Fax: 0911/179-2123; Website: https://www.arbeitsagentur.de/
Privacy Policy: Datenschutzerklärung e-Recruiting - Bundesagentur für Arbeit (arbeitsagentur.de)

©Section E: Dr.Schwenke

F. Social media profiles

We maintain online presences within social networks and process user data in this context in order to communicate with users active there or to offer information about us.

We operate the online presences within social networks jointly with abat+ GmbH and process personal data with abat+ GmbH under joint responsibility.

Jointly responsible with us (Art. 26 DSGVO):

abat+ GmbH
Innovation Park at the Beckerturm
Kaiserstrasse 170 - 174
66386 St. Ingbert
Phone: +49 6894-38808-00
Fax:+49 6894-38808-99
You can reach the abat+ company data protection officer at: daten-schutz@abatplus.de


We have concluded an agreement with abat+ on joint processing in accordance with Art. 26 (1) DSGVO. Essentially, we have agreed therein which data protection principles are to be adhered to, which contact persons are available at each company with regard to data protection law, which IT security measures are to be taken and that you can contact abat or abat+ at your request with regard to the assertion of data subject rights (e.g. right of information, right of deletion). Details on your data subject rights can be found below in the section "Your rights".


We would like to point out that user data may be processed outside the European Union. This may result in risks for the users because, for example, it could make it more difficult to enforce the rights of the users.
Furthermore, user data is usually processed within social networks for market research and advertising purposes. For example, usage profiles can be created based on the usage behavior and resulting interests of the users. The usage profiles can in turn be used, for example, to place advertisements within and outside the networks that presumably correspond to the interests of the users. For these purposes, cookies are usually stored on the users' computers, in which the usage behavior and interests of the users are stored. Furthermore, data independent of the devices used by the users may also be stored in the usage profiles (especially if the users are members of the respective platforms and are logged in to them).
For a detailed presentation of the respective forms of processing and the options to object (opt-out), we refer to the privacy statements and information provided by the operators of the respective networks.

In the case of requests for information and the assertion of data subject rights, we also point out that these can be asserted most effectively with the providers. Only the providers have access to the users' data and can take appropriate measures and provide information directly. If you still need assistance, you can contact us.

  • Types of data processed: inventory data (e.g. names, addresses), contact data (e.g. e-mail, telephone numbers), content data (e.g. text entries, photographs, videos), usage data (e.g. websites visited, interest in content, access times), meta/communication data (e.g. device information, IP addresses).
  • Data subjects: Users (e.g., website visitors, users of online services).
  • Purposes of processing: contact requests and communication, tracking (e.g. interest/behavioral profiling, use of cookies), remarketing, reach measurement (e.g. access statistics, recognition of returning visitors).
  • Legal basis: Legitimate interests (Art. 6 para. 1 p. 1 lit. f. DSGVO).

 

Services used and service providers:

©Section F: Dr.Schwenke

 

Information about our YouTube channel

1. data processed by YouTube
abat AG uses a YouTube channel owned by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland.

We would like to point out that you use the YouTube channel offered here and its functions on your own responsibility.

Information on what data is processed by Google and for what purposes can be found in Google's privacy policy:  https://policies.google.com/privacy?hl=en&gl=de#infocollect

You have options to restrict the processing of your data in the general settings of your Google account. In addition to these tools, Google also offers specific privacy settings on YouTube. You can learn more about this in Google's guide to privacy in Google products: 
https://policies.google.com/technologies/product-privacy?hl=en&gl=de

You can find more information on these points in Google's privacy policy under the term "Privacy settings": https://policies.google.com/privacy?hl=en&gl=de#infochoices

Furthermore, you have the option of requesting information via the Google privacy form: Privacy Help - Policy Help (google.com)

2. data processed by abat AG
Provided you have a YouTube/Google account, are logged in and decide to follow our site, you will appear to us as a "subscriber". We therefore process the personal data contained in your profile name and profile.
We process the same data when you "Like", comment on or share a post of ours, even if you have not subscribed to our site.
Furthermore, we process the same data if you send us a message via the contact function. In doing so, we additionally process the data that you voluntarily provide to us in your messages.
In addition, we receive anonymized statistical data of the users of our site from YouTube/Google. This data is collected with the help of so-called "cookies" and "pixels" that YouTu-be/Google stores on your system or integrates into web pages. These tools allow YouTu-be/Google to identify your browser with a unique user code, which may also be linked to your profile on the platform.
The legal basis for this processing by us in these cases is our legitimate interest pursuant to Art. 6 (1) lit. f DSGVO. You can read more about data processing by YouTube/Google and the cookies used by YouTube/Google in section 1.

G. Data subject rights

As a data subject, you have the following rights:

1. right to information
You have the right, upon request and free of charge, to receive information about whether data concerning you is being processed and, if this is the case, which data we are processing concerning you (Art. 15 DSGVO). You can make this request again within a reasonable time frame. In addition, you have the right to obtain a copy of your data that is the subject of our processing.

2. right to rectification
You can also request the correction of incorrect data concerning you in accordance with Art. 16 DSGVO. In addition, you have the right thereafter to request the completion of incomplete data concerning you, taking into account the purposes of the processing.

3. right to erasure
Under the conditions of Art. 17 DSGVO, you can demand the deletion of your data.

4. right to restriction of processing
You have the right to request the restriction of processing from us if the conditions of Art. 18 DSGVO are met. This is the case, for example, if the processing of your data is no longer necessary for our purposes, but you need it to assert, exercise or defend legal claims. If the processing of your data is restricted, this data - apart from storage - may only be processed by us with your consent or in the special cases mentioned in Art. 18 (2) DSGVO.

5 Right to data portability
You may, under the conditions of Art. 20 DSGVO, demand the surrender of your data in a structured, common and machine-readable format. In this case, you may also request that we transfer this data to another responsible party.

6. right of revocation
If we process your data on the basis of your consent, you have the right to revoke the granted consent at any time with effect for the future (Article 7 (3) DSGVO)

7 Right of objection
You have the possibility to object to data processing for direct advertising purposes at any time. In addition, you may object at any time to data processing based on a legitimate interest pursuant to Art. 6 (1) (f) DSGVO, Art. 21 DSGVO, if there are special reasons.

8. assertion of your data subject rights
To assert your data subject rights, please contact our data protection officer by e-mail or by letter (contact details below).

9. contact channels
You can exercise your rights via the following contact channels:
Mail:
abat AG
An der Reeperbahn 10
28217 Bremen
Germany

E-mail:
datenschutz@abat.de

10. right of complaint to a data protection supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your place of residence, your place of work or the place of the alleged infringement (Art. 77 DSGVO).

11. other notices
The provision of personal data is in no case required by law or contract or necessary for the conclusion of a contract. Furthermore, we do not use automated decision-making (including profiling).

H. Sweepstakes

We process personal data that you provide to us as a participant in order to carry out the competition. Among other things, it is necessary to determine whether you are eligible to participate and whether we can notify you by e-mail or direct message in the event of a win. If you do not provide us with the above-mentioned data, it will not be possible for you to participate in the competition or for us to contact you regarding a prize notification.
When you participate in a competition, we usually collect the following data: Salutation, first name, last name, address, telephone number and e-mail address. Depending on the type of competition, further data may be collected from you, e.g. your answers to competition questions, account name of the social media profile.


Legal basis

If you provide us with your personal data as a participant in a competition, we process it in order to run the competition and to contact you if you have won. In the case of competitions on social media platforms, we publish your name as part of a posting. The legal basis for data processing is Art. 6 para. 1 lit. b DSGVO.


Recipients of data
In our company, only those departments that need your personal data for the above-mentioned purposes will have access to it. Your personal data will only be transferred to third parties as follows:

(1) Social media platforms
If we operate the competition on social media platforms, we process your data jointly with the respective operator of the social media platform. Details of this can be found in the Social Media section of this privacy notice.

(2) External service providers (order processors)
As part of the above data processing activities, we use external service providers (e.g. for sending emails, storing your data in its secure data centre and maintaining and analysing databases). These service providers have committed themselves under a contract for commissioned processing (Art. 28 DSGVO) to, among other things, comply with appropriate technical and organisational data security measures and act on our behalf in accordance with instructions.

(3)Other data recipients
We transmit your personal data to third parties insofar as this is necessary for the implementation of a competition or for the transmission of the prize. These may be the following data recipients:

  • Shipping service providers (postal and parcel shipping to send you any prize).
  • Cooperation partners (e.g. partners who provide prizes)

Storage period
We store your personal data as long as this is necessary for the fulfilment of our contractual or legal obligations. We are subject to retention obligations under commercial and tax law and must store certain data for up to ten years for this purpose. After the end of the competition, your data processed as part of the competition will generally be deleted within 14 days. Insofar as we have named you as a winner on our social media pages, we will delete this post after six months.

 

I. Recruiting in career networks (LinkedIn, Xing)

Description and scope of data processing
We use recruiting applications in the career networks LinkedIn and Xing. With these recruiting applications, we can filter users of the respective career network via an advanced search function according to certain search criteria such as, in particular, professional experience, location, references and receive information as to whether these users could potentially be interested in a job change based on their publicly available profile information.

Our recruiting experts use the publicly available information to select potential candidates for a vacant position at abat and contact them directly via the respective career network. Contacting is technically only possible if the candidates concerned have not deactivated contacting via recruiting applications of the respective career network. If the approached candidates inform our recruiting experts that they are interested in the vacant position at abat, they will be referred to the regular application procedure at abat.

If the candidates approached do not signal an interest or do not respond to our enquiry, no further contact will be made. Furthermore, abat will not create user profiles of potential candidates and will not carry out any automated decision-making.

The processing of personal data in the context of the use of recruiting applications is carried out under joint responsibility with abat+ (see F. Social media profiles).
 

Purposes of data processing and legal basis
We use the recruiting applications in the career networks LinkedIn and Xing to increase abat's reach as an employer and to target individuals who meet our job requirements. The data processing is based on our legitimate interests (Art. 6 para. 1 f DSGVO).


Recipients of the data
At our company, only those employees have access to your data who are entrusted with the maintenance of our LinkedIn and Xing pages or recruiting.
Otherwise, your data will be processed by the operators of the respective career network (see F. Social media profiles).


Storage period
We only process your data temporarily for the search for potential candidates and, if necessary, subsequently for contacting them. Beyond that, your data is not stored as part of the recruiting process. If you apply to us, our instructions on the application process apply (see E. Applicants).