Privacy Policy
When you use this website and other external online services, such as our social media presences on LinkedIn or Xing, your personal data is processed by us as the controller responsible for data processing. With this privacy policy, we inform you, as the data subject whose personal data we process, about the nature, scope, purpose and duration of the processing of your personal data. You will receive information about which data is processed, which purposes we pursue, which legal obligations we have to fulfil and which rights you are entitled to.
According to Art. 4 No. 1 of the EU General Data Protection Regulation (GDPR), personal data is any information relating to an identified or identifiable natural person.
I. Name and Address of the Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) and other international and national data protection provisions is:
cloudworx GmbH
Rupert-Mayer-Straße 44, Gebäude 64.07a
81379 München
Germany
Phone: +49 800 25 68 396
info@cloudworx.agency
cloudworx.agency
Commercial register: HRB 238863, Register court: Munich
Represented by the Managing Director: Timo Müller
II. Name and Address of the Data Protection Officer
We are not obliged to appoint a data protection officer. If you have any questions about data protection, please contact:
Timo Müller
Phone: +49 800 25 68 396
Email: privacy@cloudworx.agency
III. Rights of the Data Subject
If your personal data is processed by us, you are entitled to the following data subject rights under the GDPR.
- Right of access
You may request confirmation from the controller as to whether personal data concerning you is being processed by us. Where such processing takes place, you may request information from the controller about the following:
- the purposes for which the personal data is processed;
- the categories of personal data being processed;
- the recipients or categories of recipients to whom the personal data concerning you has been or will be disclosed;
- the planned period for which the personal data concerning you will be stored or, if specific information on this is not possible, the criteria used to determine the storage period;
- all available information about the source of the data, if the personal data was not collected from you as the data subject;
- the existence of automated decision-making, including profiling, pursuant to Art. 22 GDPR and meaningful information about the logic involved and its consequences.
In addition, you have the right to request information as to whether the personal data concerning you is transferred to a third country or to an international organisation. In this context, you may request to be informed about the appropriate safeguards pursuant to Art. 46 GDPR relating to the transfer.
- Right to rectification
You have a right to rectification and/or completion vis-à-vis the controller if the processed personal data concerning you is inaccurate or incomplete. The controller must carry out the rectification without undue delay.
- Right to restriction of processing
You may request the restriction of the processing of personal data concerning you under the following conditions:
- if you contest the accuracy of the personal data concerning you, for a period enabling the controller to verify the accuracy of the personal data;
- the processing is unlawful and you oppose the erasure of the personal data and request the restriction of its use instead;
- the controller no longer needs the personal data for the purposes of processing, but you require it for the establishment, exercise or defence of legal claims; or
- if you have objected to the processing pursuant to Art. 21(1) GDPR and it has not yet been determined whether the legitimate grounds of the controller override your grounds.
Where the processing of personal data concerning you has been restricted, such data may – with the exception of storage – only be processed with your consent or for the establishment, exercise or defence of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest of the Union or of a Member State.
If the processing has been restricted under the above conditions, you will be informed by the controller before the restriction is lifted.
- Right to erasure
a) Obligation to erase
You may request the controller to erase the personal data concerning you without undue delay, and the controller is obliged to erase this data without undue delay where one of the following grounds applies:
- The personal data concerning you is no longer necessary in relation to the purposes for which it was collected or otherwise processed.
- You withdraw your consent on which the processing was based pursuant to Art. 6(1)(a) or Art. 9(2)(a) GDPR, and there is no other legal basis for the processing.
- You object to the processing pursuant to Art. 21(1) GDPR and there are no overriding legitimate grounds for the processing, or you object to the processing pursuant to Art. 21(2) GDPR.
- The personal data concerning you has been processed unlawfully.
- The erasure of the personal data concerning you is required for compliance with a legal obligation under Union or Member State law to which the controller is subject.
- The personal data concerning you has been collected in relation to the offer of information society services referred to in Art. 8(1) GDPR.
b) Information to third parties
Where the controller has made the personal data concerning you public and is obliged to erase it pursuant to Art. 17(1) GDPR, the controller, taking account of available technology and the cost of implementation, shall take reasonable steps, including technical measures, to inform controllers which are processing the personal data that you as the data subject have requested the erasure by such controllers of any links to, or copies or replications of, that personal data.
c) Exceptions
The right to erasure does not apply to the extent that processing is necessary:
- for exercising the right of freedom of expression and information;
- for compliance with a legal obligation which requires processing under Union or Member State law to which the controller is subject, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
- for reasons of public interest in the area of public health in accordance with Art. 9(2)(h) and (i) and Art. 9(3) GDPR;
- for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Art. 89(1) GDPR, insofar as the right referred to in section a) is likely to render impossible or seriously impair the achievement of the objectives of that processing; or
- for the establishment, exercise or defence of legal claims.
- Right to notification
If you have asserted the right to rectification, erasure or restriction of processing against the controller, the controller is obliged to communicate this rectification or erasure of the data or restriction of processing to all recipients to whom the personal data concerning you has been disclosed, unless this proves impossible or involves disproportionate effort. You have the right vis-à-vis the controller to be informed about these recipients.
- Right to data portability
You have the right to receive the personal data concerning you, which you have provided to the controller, in a structured, commonly used and machine-readable format. You have the right to transmit this data to another controller without hindrance from the controller to which the personal data has been provided, where the processing is based on consent pursuant to Art. 6(1)(a) GDPR or Art. 9(2)(a) GDPR or on a contract pursuant to Art. 6(1)(b) GDPR and the processing is carried out by automated means.
In exercising this right to data portability, you also have the right to have the personal data transmitted directly from one controller to another, where technically feasible.
The right to data portability must not adversely affect the rights and freedoms of others.
The right to data portability does not apply to processing necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.
- Right to object
You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is based on Art. 6(1)(e) or (f) GDPR. This also applies to profiling based on these provisions.
The controller will then no longer process the personal data concerning you unless it can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.
Where personal data concerning you is processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for such marketing. In this case, we will stop the processing immediately. It is not necessary to state a particular situation. If you wish to exercise your right to object, an email to privacy@cloudworx.agency is sufficient.
- Right to withdraw consent under data protection law
You have the right to withdraw your consent to the processing of personal data at any time vis-à-vis the controller. As a result, we may no longer continue the data processing based on this consent in the future. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
- Automated individual decision-making, including profiling
You have the right not to be subject to a decision based solely on automated processing – including profiling – which produces legal effects concerning you or similarly significantly affects you.
This right does not apply if the decision
a) is necessary for entering into, or the performance of, a contract between you and the controller,
b) is authorised by Union or Member State law to which the controller is subject and which also lays down suitable measures to safeguard your rights and freedoms and legitimate interests, or
c) is based on your explicit consent.
However, these decisions must not be based on special categories of personal data referred to in Art. 9(1) GDPR, unless Art. 9(2)(a) or (g) GDPR applies and suitable measures to safeguard your rights and freedoms and legitimate interests are in place.
In the cases referred to in a) and c), the controller shall implement suitable measures to safeguard your rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the controller, to express your own point of view and to contest the decision.
- Right to lodge a complaint with a supervisory authority
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the GDPR. The supervisory authority responsible for the controller is:
Bayerisches Landesamt für Datenschutzaufsicht (Bavarian Data Protection Authority)
Promenade 27
91522 Ansbach
Germany
Phone: +49 981 53 1300
Email: poststelle@lda.bayern.de
IV. General Information on the Processing of Personal Data
- Scope of the processing of personal data
The controller processes personal data of data subjects insofar as this is necessary to provide this website and other external online services and for the use of our content and services. Personal data is generally processed only with the consent of the data subject. An exception applies in cases where obtaining prior consent is not possible for factual reasons and the processing of the data is permitted or required by law.
- Legal basis for the processing of personal data
The legal basis for the processing of personal data is Art. 6(1)(1)(a) GDPR where the processing is based on the consent of the data subject.
The legal basis for the processing of personal data is Art. 6(1)(1)(b) GDPR where the processing is carried out for the performance of a contract to which the data subject is a party. This legal basis also applies to processing operations necessary to carry out pre-contractual measures.
The legal basis for the processing of personal data is Art. 6(1)(1)(c) GDPR where the processing is necessary for compliance with a legal obligation.
The legal basis for the processing of personal data is Art. 6(1)(1)(d) GDPR where vital interests of the data subject or of another natural person require the processing.
The legal basis for the processing of personal data is Art. 6(1)(1)(f) GDPR where the processing is necessary for the purposes of the legitimate interests of the controller or a third party and the interests, fundamental rights and freedoms of the data subject do not override the interest of the controller.
- Data erasure and storage period
The personal data of the data subject will be erased or blocked as soon as the purpose for which it was collected or otherwise processed no longer applies. Processing may continue if it is necessary for compliance with a legal obligation to which the controller is subject under Union or Member State law, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller. Furthermore, processing may continue if it is necessary for the establishment, exercise or defence of legal claims.
V. Hosting
- Description and scope of the processing of personal data
This website is hosted by Amazon Web Services (AWS), a service of Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg (hereinafter "AWS"). When you visit our website, the data listed in the section "Provision of the Website and Creation of Log Files", in particular your IP address, is processed on AWS servers. The servers are located in the AWS data centre in Frankfurt am Main. For fast and secure delivery of the website, we additionally use the Amazon CloudFront service. In this context, requests may also be routed via AWS servers outside the European Union that are located near you.
The XRSF Validator is also operated on AWS. The backend of the XRSF Visualizer is operated by Host Europe GmbH, Hansestraße 111, 51149 Köln, Germany (hereinafter "Host Europe"). When you use the Validator or the Visualizer, only the file you upload is processed; for the Visualizer, this takes place on Host Europe servers in Germany. No further data about you is processed there.
We have concluded a data processing agreement pursuant to Art. 28 GDPR with both AWS and Host Europe.
It cannot be ruled out that AWS transfers data to its parent company Amazon Web Services, Inc. in the USA. For the transfer of personal data to the USA, Amazon Web Services, Inc. is certified under the EU-U.S. Data Privacy Framework (DPF). On the basis of the European Commission's adequacy decision of 10 July 2023, an adequate level of data protection exists for companies certified under the DPF. You can view the certification here: https://www.dataprivacyframework.gov/list. In addition, AWS has concluded the European Commission's Standard Contractual Clauses. Further information on data protection at AWS can be found here: https://aws.amazon.com/privacy/.
- Legal basis for the processing of personal data
The legal basis for hosting is Art. 6(1)(1)(f) GDPR. The legitimate interest of the controller lies in the secure, fast and reliable provision of its website. Where you use the XRSF Validator or Visualizer, the legal basis is Art. 6(1)(1)(b) GDPR.
- Purpose of the processing of personal data
The purpose of the processing is the provision of this website and of the XRSF Validator and Visualizer.
- Data erasure and storage period
The storage period for connection data is as set out in the section "Provision of the Website and Creation of Log Files". Files you upload to the Validator or Visualizer are deleted immediately after processing.
- Possibility of objection and removal
Hosting is strictly necessary for the operation of the website. Consequently, there is no possibility to object.
VI. Provision of the Website and Creation of Log Files
- Description and scope of the processing of personal data
Each time this website is used, the controller's server automatically collects data and information from the browser of the accessing device.
The following data is collected:
- Information about the browser type and version used
- The operating system of the device
- The internet service provider of the device
- The IP address of the device
- Date and time of access
- Websites from which the user's device reaches our website
- Websites accessed by the user's system via our website
The data is stored in so-called log files of our system. This data is not stored together with other personal data of the user.
The log files are stored on AWS servers (see section "Hosting"). In addition, we store the access logs in the log management service DataSet (formerly Scalyr) of SentinelOne, Inc., 444 Castro Street, Suite 400, Mountain View, CA 94041, USA. This allows us to detect and analyse disruptions and attacks more quickly. In this process, the data listed above, including your IP address, is transferred to SentinelOne and stored in the USA. We have concluded a data processing agreement pursuant to Art. 28 GDPR as well as the European Commission's Standard Contractual Clauses with SentinelOne. Further information can be found in SentinelOne's privacy policy: https://www.sentinelone.com/legal/privacy-policy/.
- Legal basis for the processing of personal data
The legal basis for the processing of personal data is Art. 6(1)(1)(f) GDPR.
- Purpose of the processing of personal data
The temporary storage of the IP address of the requesting device by the system is technically necessary to establish a connection between the user's device and the controller's server and to ensure delivery of the website to the device. Furthermore, the controller processes the IP address for technical and administrative purposes when establishing the connection, in order to ensure the stability of the connection, to ensure the security and functionality of the online services and to be able to investigate any unlawful attacks.
Storage in log files takes place to ensure the functionality of the website. The controller does not draw any direct conclusions about your identity from the processing of the IP address and the information in the log files. The data is not evaluated for marketing purposes in this context.
The legal basis for the processing of the IP address and the information in the log files is Art. 6(1)(1)(f) GDPR. The legitimate interest of the controller is the secure and trouble-free provision of our website.
- Data erasure and storage period
The personal data of the data subject will be erased or blocked as soon as the purpose for which it was collected or otherwise processed no longer applies. In the case of processing data for the provision of the website, this is the case when the respective session has ended. In the case of processing data in log files, including in DataSet, this is the case after 30 days at the latest.
- Possibility of objection and removal
The processing of the IP address for the provision of the website and the processing of data in log files is strictly necessary for the operation of the website. Consequently, the user has no possibility to object.
VII. Use of Cookies and Tracking Pixels
- Description and scope of the processing of personal data
On our website, we use so-called cookies and tracking pixels to record the use of our website statistically and to be able to evaluate it for optimisation purposes.
a) Cookies
Cookies are small text files that your internet browser creates and stores on your device (e.g. laptop, tablet) when you visit our website. A cookie contains a characteristic string of characters that enables the device to be uniquely identified when you visit our website again. Cookies do not cause any damage to your device; they do not contain viruses, Trojans or other malware. The use of cookies does not mean that we obtain direct knowledge of your identity.
b) Tracking pixels
A tracking pixel, or web beacon, is a small 1x1 pixel graphic (GIF file) that may be loaded when you visit our website or open our newsletter. Tracking pixels do not cause any damage to your device; they do not contain viruses, Trojans or other malware.
Whether the pixel has been loaded or not makes it possible to check whether a user has visited the page. The pixels send your IP address, the referrer URL of the visited website or opened newsletter, the time at which the pixel was viewed, the browser used, and previously set cookie information to a web server. The data enables the controller to carry out statistical analyses, the results of which are used to optimise the website and its offers. Most browsers accept pixels automatically. You can prevent the use of pixels on the controller's pages by using appropriate tools or browser add-ons.
- Legal basis for the processing of personal data
The legal basis for storing and accessing information on your device (e.g. cookies) is Section 25(2) No. 2 of the German Telecommunications Digital Services Data Protection Act (TDDDG) for technically necessary cookies, and Art. 6(1)(1)(f) GDPR for the subsequent processing of personal data. We only use all other cookies and tracking pixels (e.g. for statistics and marketing) with your consent. In this case, the legal basis is Section 25(1) TDDDG in conjunction with Art. 6(1)(1)(a) GDPR. You can withdraw your consent at any time via the cookie settings (see section "Details on the Cookies Used").
- Purpose of the processing of personal data
The purpose of using technically necessary cookies is to enable the use of our website in the first place or to make it more convenient for you. The controller uses so-called session cookies to recognise that you have already visited individual pages of the website. Some functions of the website cannot be used without cookies. For these functions, it is necessary that the internet browser of the device is recognised even after a page change.
Cookies used to record the use of our website statistically and to evaluate it for the purpose of optimising our offering make it possible to automatically recognise that you have already visited this website when you return.
- Data erasure and storage period
Session cookies are automatically deleted after you leave the website. Cookies and tracking pixels that analyse the use of the website are automatically deleted after the respective specified storage period.
- Possibility of objection and removal
a) Cookies
Cookies are stored on the user's computer and transmitted by it to the controller's web server. Most internet browsers accept cookies automatically. However, you can configure your internet browser so that the transmission of cookies is deactivated or restricted, or so that a notice appears before a new cookie is created. You can delete cookies that have already been stored at any time. This can also be done automatically. As a user, you therefore have full control over the use of cookies. If cookies are deactivated for this website, it may no longer be possible to use all functions of the website to their full extent.
b) Tracking pixels
Most browsers accept pixels automatically. However, you can configure your internet browser or use appropriate tools or browser add-ons to prevent the use of tracking pixels.
VIII. Use of the Consent Management Tool Cookiebot
- Description and scope of the processing of personal data
On its website, the controller uses the consent management tool Cookiebot of Usercentrics A/S, Havnegade 39, 1058 Copenhagen, Denmark (hereinafter "Cookiebot"). Cookiebot obtains and documents your consent to the storage of cookies and the use of comparable technologies. The following data is processed in this context: your IP address in truncated form, date and time of consent, information about your browser, the URL from which consent was given, a randomly generated consent ID and your consent status. Your consent status is additionally stored in the "CookieConsent" cookie in your browser. The data is stored on servers in the European Union. Further information can be found in Cookiebot's privacy policy: https://www.cookiebot.com/en/privacy-policy/.
- Legal basis for the processing of personal data
The legal basis is Art. 6(1)(1)(c) GDPR in conjunction with Art. 7(1) GDPR, as the controller is obliged to be able to demonstrate consent that has been given. Storing the "CookieConsent" cookie is permitted under Section 25(2) No. 2 TDDDG.
- Purpose of the processing of personal data
The purpose of the processing is the legally compliant collection, management and documentation of your consent.
- Data erasure and storage period
The "CookieConsent" cookie is deleted after 12 months. The records of consent are also stored by Cookiebot for 12 months and then deleted.
- Possibility of objection and removal
You can change or withdraw your consent at any time via the cookie settings (see section "Details on the Cookies Used"). You can also delete the "CookieConsent" cookie in your browser. You will then be asked for your consent again on your next visit to the website.
IX. Contact Form and Email Contact
- Description and scope of the processing of personal data
If you use a contact form on this website or send an email to the controller, the data you provide is automatically processed by the controller in order to handle your request. When using the contact form, the date and time the message was sent are stored in addition to the contents of the form. Before the message is sent, your consent is obtained along with confirmation that you have understood and accepted the privacy policy. When contacting us by email, your personal data is also stored. The data is processed exclusively to handle your request. The contact form is provided via our own form service (cloudworx Forms). The data entered is transferred to our CRM system Salesforce (see section "Use of Salesforce CRM"). It is not passed on to any other third parties.
- Legal basis for the processing of personal data
The legal basis for the processing of personal data where you have given your consent is Art. 6(1)(1)(a) GDPR.
The legal basis for the processing of personal data in the context of email communication is Art. 6(1)(1)(f) GDPR.
If the processing of personal data serves the purpose of concluding a contract by email or via a form, the legal basis is Art. 6(1)(1)(b) GDPR.
- Purpose of the processing of personal data
The purpose of processing the personal data collected via the contact form or by email is to handle the sender's request. The additionally collected personal data serves to prevent misuse of the forms and to ensure the information security of the controller's systems. The legal basis for processing this information is Art. 6(1)(1)(f) GDPR.
- Data erasure and storage period
The personal data of the data subject will be erased as soon as the purpose for which it was collected or otherwise processed no longer applies. For personal data from the contact form and data sent by email, this is the case when the respective communication with the user has ended. The communication has ended when it can be inferred from the circumstances that the matter in question has been conclusively resolved.
- Possibility of objection and removal
The user may withdraw their consent to the processing of personal data at any time. If the user contacts us by email, they may object to the storage of their personal data at any time. In such a case, the communication cannot be continued.
In this case, all personal data stored in the course of contacting us will be deleted.
X. Support Chat
- Description and scope of the processing of personal data
On this website, we offer a support chat through which you can ask us questions. Your questions are answered automatically with the help of artificial intelligence (AI). The chat is provided via the n8n Cloud service of n8n GmbH, Novalisstraße 10, 10115 Berlin, Germany (hereinafter "n8n"). Before you can start a chat session, you are referred to this privacy policy and must consent to the processing of your data.
When you use the chat, the following data is processed: the content of your messages and the responses, a randomly generated session ID, the language and the address (URL) of the page on which you use the chat, and the technically necessary connection data such as your IP address. The session ID is stored in your browser's local storage. This allows the previous chat history to be displayed again when you reopen the chat.
To generate the responses, your messages are transferred to OpenAI Ireland Ltd., 1st Floor, The Liffey Trust Centre, 117-126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland (hereinafter "OpenAI"). To answer your questions, the AI model may additionally perform a web search. OpenAI also processes the data on servers of OpenAI, L.L.C. in the USA. The data processing agreement pursuant to Art. 28 GDPR forms part of our agreement with OpenAI. The transfer to the USA is based on the European Commission's Standard Contractual Clauses. It is contractually excluded that OpenAI uses your inputs to train its AI models. Further information can be found in OpenAI's privacy policy: https://openai.com/policies/eu-privacy-policy/.
For questions about our products, the chat additionally uses a knowledge base containing our product information. This is provided via the Pinecone Assistant service of Pinecone Systems, Inc., 1375 Broadway, 11th Floor, New York, NY 10018, USA (hereinafter "Pinecone"). In this process, your question is transferred to Pinecone and processed on servers in the USA. A data processing agreement pursuant to Art. 28 GDPR is in place with Pinecone, which includes the European Commission's Standard Contractual Clauses for the transfer to the USA.
Our customers can also use the chat to obtain information about open invoices. To do so, you provide your email address. We send a one-time verification code to this address. The code is sent via Google Workspace (see section "Use of Google Workspace"). Only once you enter the correct code in the chat are the open invoices associated with your email address retrieved from our CRM system Salesforce (see section "Use of Salesforce CRM") and displayed in the chat: invoice number, invoice date, due date, amount and outstanding amount.
Please do not enter any sensitive personal data in the chat, e.g. health data or bank details.
n8n Cloud is operated on Microsoft Azure servers in the European Union. The data processing agreement pursuant to Art. 28 GDPR forms part of n8n's terms of use. Further information can be found in n8n's privacy policy: https://n8n.io/legal/privacy/.
- Legal basis for the processing of personal data
The legal basis for the processing is your consent pursuant to Art. 6(1)(1)(a) GDPR, which you give before starting the chat session. Where your request is aimed at the conclusion or performance of a contract, for example when querying open invoices, the additional legal basis is Art. 6(1)(1)(b) GDPR. Storing the session ID in your browser is permitted under Section 25(2) No. 2 TDDDG, as it is necessary for the chat service you have expressly requested.
- Purpose of the processing of personal data
The purpose of the processing is to answer your questions about our products and services quickly and to provide information about open invoices.
- Data erasure and storage period
Chat histories are stored in n8n's execution logs and automatically deleted after 7 days. So that the chat can take earlier messages into account, the last 30 messages of a session are additionally held in n8n's working memory. They are deleted at the latest when the service is restarted. According to its own information, OpenAI stores the transferred data for up to 30 days to detect misuse and deletes it thereafter. The session ID remains in your browser's local storage until you delete it.
- Possibility of objection and removal
You can withdraw your consent at any time with effect for the future, e.g. by email to privacy@cloudworx.agency. You can delete the session ID by clearing the website data in your browser. Without your consent, you cannot use the chat. However, you can reach us at any time by email or phone.
XI. Use of Salesforce CRM
- Description and scope of the processing of personal data
The controller uses the customer relationship management system (CRM system) provided by Salesforce (Salesforce). Salesforce.com is a service of Salesforce.com Germany GmbH, Erika-Mann-Str. 31, 80636 München, Germany. The controller uses Salesforce to process requests from website users as well as from customers and prospective customers more quickly and efficiently. Salesforce uses this data only for the technical processing of the requests and does not pass it on to third parties. To use Salesforce, at least a valid email address is required. Pseudonymous use is possible. In the course of processing service requests, it may be necessary to collect further data (name, address).
Information on data protection at Salesforce can be found in Salesforce's privacy policy: https://www.salesforce.com/company/privacy/.
For the transfer of personal data to the USA, Salesforce, Inc. is certified under the EU-U.S. Data Privacy Framework (DPF). On the basis of the European Commission's adequacy decision of 10 July 2023, an adequate level of data protection exists for companies certified under the DPF. You can view the certification here: https://www.dataprivacyframework.gov/list.
- Legal basis for the processing of personal data
The legal basis for the processing of personal data in connection with the use of the Salesforce CRM system is Art. 6(1)(1)(f) GDPR.
- Purpose of the processing of personal data
The purpose of using Salesforce is the fast and efficient management of relationships with customers and prospective customers and the answering of related requests.
- Data erasure and storage period
We delete CRM data once it is no longer required. We review whether it is still required every two years. In addition, statutory retention obligations apply.
- Possibility of objection and removal
If you do not agree to the processing of your data in Salesforce's systems, we offer you alternative ways of contacting us. You can reach us by email, phone or post.
XII. Applications by Post, Application Form and Email
- Description and scope of the processing of personal data
When handling the application process, the controller processes the personal data of applicants (e.g. contact and communication data, application documents, notes taken during interviews, etc.) insofar as this is necessary to decide on the establishment of an employment relationship. Processing may take place physically or electronically. Electronic processing takes place in particular when an applicant submits their application documents electronically to the controller, for example by email or via an online application form.
If the controller concludes an employment contract with an applicant, the submitted data will be stored for the purpose of carrying out the employment relationship in compliance with the statutory provisions. If the controller does not conclude an employment contract, or if the applicant declines a job offer, withdraws their application, withdraws their consent or requests the controller to delete their data, the application documents will be automatically deleted six months after notification of the decision to end the process, provided that no other legitimate interests of the controller prevent deletion. Another legitimate interest in this sense is, for example, a burden of proof in proceedings under the German General Equal Treatment Act (AGG).
- Purpose of the processing of personal data
The purpose of the processing is to decide on the establishment of an employment relationship. The legal basis for the processing of personal data is Art. 6(1)(b) GDPR (initiation of an employment relationship). Where the controller processes the data on the basis of consent given, the legal basis is Art. 6(1)(a) GDPR. Consent may be withdrawn at any time. In certain cases, the controller processes personal data on the basis of legitimate interest. The legal basis for the processing of personal data is then Art. 6(1)(f) GDPR.
- Data erasure and storage period
If the controller is unable to make a job offer, or if the applicant declines a job offer, withdraws their application, withdraws their consent or requests the controller to delete their data, the application documents, including any physical application documents, will be deleted no later than six months after the conclusion of the application process, provided that no other legitimate interests of the controller prevent deletion. Another legitimate interest in this sense is, for example, a burden of proof in proceedings under the German General Equal Treatment Act (AGG).
- Possibility of objection and removal
The applicant may withdraw their consent to the processing of personal data at any time. If the applicant contacts the controller by email, they may object to the storage of their personal data at any time. In such a case, the application process cannot be continued.
XIII. Use of Our Company Profile on LinkedIn
- Description and scope of the processing of personal data
For its company presence, the controller uses the platform of LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland. On our company page, we provide information and offer LinkedIn users the opportunity to communicate and interact with us. If you perform an action on our company page on LinkedIn, your personal data may be made public. Information on the processing of your personal data by LinkedIn and on data protection at LinkedIn can be found in LinkedIn's privacy policy, available here: https://privacy.linkedin.com/
- Legal basis for the processing of personal data
The legal basis for the processing of personal data in connection with the use of our company page on LinkedIn is Art. 6(1)(1)(f) GDPR.
- Purpose of the processing of personal data
The purpose of the company page on LinkedIn is to inform LinkedIn users about the controller's products and services. Every user is free to publish personal data through their activities.
- Data erasure and storage period
The controller stores the activities and personal data published via LinkedIn until withdrawal. In addition, the controller complies with the statutory retention periods.
- Possibility of objection and removal
You can object at any time to the processing of your personal data collected by the controller in the context of using the company page on LinkedIn and assert your data subject rights.
LinkedIn offers the option to manage the settings for the processing of personal data by LinkedIn at https://www.linkedin.com/psettings/.
XIV. Use of Our Company Profile on Xing
- Description and scope of the processing of personal data
For its company presence, the controller uses the platform of XING SE, Dammtorstraße 30, 20354 Hamburg, Germany. On our company page, we provide information and offer Xing users the opportunity to communicate and interact with us. If you perform an action on our company page on Xing, your personal data may be made public. Information on the processing of your personal data by Xing and on data protection at Xing can be found in Xing's privacy policy, available here: https://privacy.xing.com/en
- Legal basis for the processing of personal data
The legal basis for the processing of personal data in connection with the use of our company page on Xing is Art. 6(1)(1)(f) GDPR.
- Purpose of the processing of personal data
The purpose of the company page on Xing is to inform Xing users about the controller's products and services. Every user is free to publish personal data through their activities.
- Data erasure and storage period
The controller stores the activities and personal data published via Xing until withdrawal. In addition, the controller complies with the statutory retention periods.
- Possibility of objection and removal
You can object at any time to the processing of your personal data collected by the controller in the context of using the company page on Xing and assert your data subject rights.
XING SE provides information on the processing of personal data by XING SE at https://privacy.xing.com/en/privacy-policy.
XV. Use of YouTube
- General
The YouTube videos embedded on this website and this YouTube channel are the editorial responsibility of cloudworx GmbH, Rupert-Mayer-Straße 44, Gebäude 64.07a, 81379 München, Germany.
- Description and scope of the processing of personal data
The controller uses the YouTube platform, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, to play videos.
For embedding YouTube videos on our website, we use the so-called privacy-enhanced mode offered by YouTube. When you start the embedded video, a connection to YouTube servers is established, which may trigger further data processing operations. According to Google, privacy-enhanced mode allows YouTube videos to be embedded without cookies being set to record usage behaviour. Usage behaviour is therefore not observed in order to personalise video playback. Instead, video recommendations are based on the video currently being played. Videos played in an embedded player in privacy-enhanced mode do not influence which videos are recommended to a user on YouTube.
When videos are accessed on our website or our YouTube channel is used, personal data is processed by YouTube as controller, e.g. through the use of cookies. Processing may also take place for users of our pages or our YouTube channel who are not logged in to or registered with YouTube. Information on data collection and further processing by YouTube can be found in YouTube's privacy notice: https://policies.google.com/privacy?hl=en
For the transfer of personal data to the USA, Google LLC is certified under the EU-U.S. Data Privacy Framework (DPF). On the basis of the European Commission's adequacy decision of 10 July 2023, an adequate level of data protection exists for companies certified under the DPF. You can view the certification here: https://www.dataprivacyframework.gov/list.
- Legal basis for the processing of personal data
The legal basis for embedding YouTube videos is your consent pursuant to Section 25(1) TDDDG in conjunction with Art. 6(1)(1)(a) GDPR. The videos are only loaded after you have consented to the "Marketing" category via the cookie settings. Consent may be withdrawn at any time.
- Purpose of the processing of personal data
The purpose of using videos on our website and on our YouTube channel is to inform the users of our website and YouTube users about the controller's products and services.
- Data erasure and storage period
The cookies on our website have a maximum lifetime of 90 days. We have no information on the deletion and storage period of cookies at YouTube.
- Possibility of objection and removal
You can withdraw your consent at any time via the cookie settings. You can also deactivate personalised advertising in your Google account: https://adssettings.google.com/authenticated?hl=en.
Information on data protection at Google can be found in Google's privacy policy: https://policies.google.com/privacy?hl=en.
XVI. Use of Web Analytics and Advertising Tools – Google Analytics
- Description and scope of the processing of personal data
On its website, the controller uses the web analytics service Google Analytics 4, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter "Google"). Google Analytics uses so-called "cookies", text files that are stored on your device and enable an analysis of your use of the website. Pseudonymised usage profiles can be created and evaluated from this data for the same purpose. In Google Analytics 4, IP addresses are not logged or stored. Google only uses the IP address briefly to derive approximate location data (e.g. country or city). The information collected may be transferred to and stored on servers of Google LLC in the USA. On behalf of the controller, Google will use this information to evaluate your use of the website, to compile reports on website activity and to provide the website operator with further services related to website and internet usage. We use Google Consent Mode. Google Analytics is only loaded after you have given your consent. Without your consent, no cookies are set and no data is transferred to Google.
The IP address transmitted by your browser within the scope of Google Analytics is not merged with other Google data.
For the transfer of personal data to the USA, Google LLC is certified under the EU-U.S. Data Privacy Framework (DPF). On the basis of the European Commission's adequacy decision of 10 July 2023, an adequate level of data protection exists for companies certified under the DPF. You can view the certification here: https://www.dataprivacyframework.gov/list.
- Legal basis for the processing of personal data
The legal basis for the use of Google Analytics is your consent pursuant to Section 25(1) TDDDG in conjunction with Art. 6(1)(1)(a) GDPR. Consent may be withdrawn at any time via the cookie settings.
- Purpose of the processing of personal data
The purpose of using Google Analytics is to analyse the use of the controller's website and to be able to improve it regularly. Using the statistics obtained, the controller can better address its target groups and make the website more interesting for users.
- Data erasure and storage period
Event data is automatically deleted after 2 months, user-level data after 14 months.
- Possibility of objection and removal
You can object to the collection and processing of your data by Google Analytics by downloading and installing the browser plug-in available at the following link: https://tools.google.com/dlpage/gaoptout.
You can also withdraw your consent at any time via the cookie settings (see section "Details on the Cookies Used").
Information on data protection at Google can be found in Google's privacy policy: https://policies.google.com/privacy?hl=en
XVII. Use of Web Analytics and Advertising Tools – Google (Re)marketing Services
- Description and scope of the processing of personal data
On its website, the controller uses the marketing and remarketing services (Google Marketing Services) of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Google Marketing Services allow the controller to display advertisements for its website in a more targeted manner, so that users are only shown ads that potentially match their interests. If, for example, a user is shown ads for products they were interested in on other websites, this is referred to as "remarketing". For these purposes, when the controller's website and other websites on which Google Marketing Services are active are accessed, Google directly executes a Google code and so-called (re)marketing tags (invisible graphics or code, also known as "web beacons") are embedded in the website. With their help, an individual cookie, i.e. a small file, is stored on the user's device (comparable technologies may also be used instead of cookies). The cookies may be set by various domains, including google.com, doubleclick.net, invitemedia.com, admeld.com, googlesyndication.com or googleadservices.com. This file records which websites the user has visited, which content they are interested in and which offers they have clicked, as well as technical information about the browser and operating system, referring websites, time of visit and other information on the use of the online service. The user's IP address is also recorded. The IP address is not merged with the user's personal data within other Google services. The information listed above may also be combined by Google with information from other sources. When the user subsequently visits other websites, they may be shown ads tailored to their interests.
Within the scope of Google Marketing Services, user data is processed pseudonymously. For example, Google does not store and process the name or email address of users, but processes the relevant data on a cookie basis within pseudonymous user profiles. This means that, from Google's perspective, the ads are not managed and displayed for a specifically identified person, but for the cookie holder, regardless of who that cookie holder is. This does not apply if a user has expressly permitted Google to process the data without this pseudonymisation. The information collected about users by Google Marketing Services is transferred to Google and stored on Google's servers in the USA.
The Google Marketing Services used by the controller also include the online advertising programme "Google Ads". In the case of Google Ads, each Google Ads customer receives an individual "conversion cookie". Cookies therefore cannot be tracked across the websites of Google Ads customers. The information collected with the help of the cookie is used to create conversion statistics for Google Ads customers who have opted for conversion tracking. Google Ads customers learn the total number of users who clicked on their ad and were redirected to a page bearing a conversion tracking tag. However, they do not receive any information that could be used to personally identify users.
Further information on Google's use of data for advertising purposes can be found on this overview page: https://policies.google.com/technologies/ads?hl=en.
For the transfer of personal data to the USA, Google LLC is certified under the EU-U.S. Data Privacy Framework (DPF). On the basis of the European Commission's adequacy decision of 10 July 2023, an adequate level of data protection exists for companies certified under the DPF. You can view the certification here: https://www.dataprivacyframework.gov/list.
- Legal basis for the processing of personal data
The legal basis for the use of Google Marketing Services and the storage of conversion cookies is your consent pursuant to Section 25(1) TDDDG in conjunction with Art. 6(1)(1)(a) GDPR. Consent may be withdrawn at any time via the cookie settings. Where the collected data is merged in your Google account, this is additionally based on the consent you have given to Google.
- Purpose of the processing of personal data
The purpose of using Google Marketing Services is to analyse user behaviour in order to optimise the controller's web offering and advertising. Using the statistics obtained, the controller can better address its target groups and make the website more interesting for users.
- Data erasure and storage period
The cookies have a maximum lifetime of 90 days.
- Possibility of objection and removal
You can permanently object to the use and storage of "conversion cookies" or the comparable technology used instead of cookies, and to cross-device remarketing/targeting, by deactivating personalised advertising in your Google account: https://adssettings.google.com/authenticated?hl=en.
Information on data protection at Google can be found in Google's privacy policy: https://policies.google.com/privacy?hl=en.
XVIII. Use of Web Analytics and Advertising Tools – LinkedIn Insight Tag
- Description and scope of the processing of personal data
On its website, the controller uses the "LinkedIn Insight Tag" of LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland (hereinafter "LinkedIn"). The Insight Tag is a small piece of JavaScript code that is loaded when our website is accessed and stores a cookie in your browser. In particular, the following data is transferred to LinkedIn: the URL of the page accessed, the referrer URL, your IP address, device and browser properties and the time of access.
The controller uses the Insight Tag exclusively to measure the effectiveness of its advertisements on LinkedIn (conversion tracking). This allows it to track whether users perform certain actions on its website after clicking on an ad, e.g. submitting a form. The controller only receives aggregated statistics and no information that could be used to identify individual persons. However, LinkedIn may associate the data with your LinkedIn account if you are logged in to LinkedIn.
LinkedIn also transfers data to LinkedIn Corporation in the USA. For the transfer of personal data to the USA, LinkedIn Corporation is certified under the EU-U.S. Data Privacy Framework (DPF). On the basis of the European Commission's adequacy decision of 10 July 2023, an adequate level of data protection exists for companies certified under the DPF. You can view the certification here: https://www.dataprivacyframework.gov/list. Further information can be found in LinkedIn's privacy policy: https://www.linkedin.com/legal/privacy-policy.
- Legal basis for the processing of personal data
The legal basis is your consent pursuant to Section 25(1) TDDDG in conjunction with Art. 6(1)(1)(a) GDPR. The Insight Tag is only loaded after you have consented to the "Marketing" category via the cookie settings.
- Purpose of the processing of personal data
The purpose is to measure the success of and optimise the controller's advertisements on LinkedIn.
- Data erasure and storage period
According to LinkedIn, users' direct identifiers are pseudonymised within seven days and the remaining pseudonymised data is deleted after 180 days. The storage period of the individual cookies can be found in the section "Details on the Cookies Used".
- Possibility of objection and removal
You can withdraw your consent at any time via the cookie settings. If you are a LinkedIn member, you can also control the use of your data for advertising in your account settings: https://www.linkedin.com/psettings/advertising.
XIX. Use of Google Tag Manager
- Description and scope of the processing of personal data
The controller uses Google Tag Manager provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Tag Manager allows website tags of Google services and other providers to be managed and integrated into our online presence. With the help of Google Tag Manager, small code elements, so-called tags, are placed on web pages. Tags are used by Google Analytics, among other things, to measure visitor behaviour, optimise online advertising and test and optimise the targeting of the website. Google Tag Manager itself does not set any cookies, only tags, and does not collect any personal data. When Google Tag Manager is executed, the user's IP address is transmitted to Google. Further information on Google Tag Manager can be found at https://www.google.com/intl/en/tagmanager/faq.html and in Google's privacy policy: https://policies.google.com/privacy?hl=en
- Legal basis for the processing of personal data
The legal basis for the processing of users' personal data is the user's consent pursuant to Art. 6(1)(1)(a) GDPR and legitimate interest pursuant to Art. 6(1)(1)(f) GDPR.
- Purpose of the processing of personal data
The purpose of using Google Tag Manager is to be able to analyse and regularly improve the use of the controller's website with the help of Google Analytics. Using the statistics obtained, the controller can better address its target groups and make the website more interesting for users.
- Possibility of objection and removal
Google Tag Manager triggers other tags, which in turn may collect data. Google Tag Manager does not access this data. If deactivation has been carried out at domain or cookie level, it remains in place for all tracking tags implemented with Google Tag Manager. Further information is available here: https://marketingplatform.google.com/about/analytics/tag-manager/use-policy/.
XX. Use of Google Workspace
- Description and scope of the processing of personal data
The controller uses Google Workspace provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, and Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Google Workspace is software accessible via the internet and run on Google's servers (cloud service, software as a service). When using Google Workspace, personal data may be processed and stored on Google's servers insofar as it forms part of communication with us or from us. This data may include, in particular, master data and contact data of users, data on transactions, other processes and the content of communications. Google also processes usage data and metadata, which are used to ensure security and to optimise the service. Further information on data protection and the security of processing at Google Workspace can be found here: https://cloud.google.com/product-terms.
- Legal basis for the processing of personal data
The legal basis for the processing of users' personal data is the user's consent pursuant to Art. 6(1)(1)(a) GDPR, pre-contractual enquiries and the performance of a contract pursuant to Art. 6(1)(1)(b) GDPR, and legitimate interest pursuant to Art. 6(1)(1)(f) GDPR.
- Purpose of the processing of personal data
The controller uses Google Workspace to organise its business activities. This includes, among others, the following processing purposes: storing and managing documents in the cloud, managing appointments, contacts and calendars, sending and receiving email, spreadsheets, presentations, exchanging documents, content and information with specific recipients, publishing forms or other content and information, conducting chats and participating in audio and video conferences.
- Data erasure and storage period
The personal data will be erased or blocked as soon as the purpose of storage no longer applies. Storage may also take place beyond this if provided for by the European or national legislator in EU regulations, laws or other provisions to which we are subject. Data will also be blocked or erased when a storage period prescribed by the aforementioned provisions expires, unless further storage of the data is necessary for the conclusion or performance of a contract.
- Possibility of objection and removal
You can withdraw your consent to the processing of personal data at any time and object to the storage of your personal data at any time. In such a case, the communication and the customer relationship may not be able to continue.
XXI. Use of Matomo (formerly Piwik)
- Description and scope of the processing of personal data
The controller uses the software "Matomo" (www.matomo.org), a software of InnoCraft Ltd., 150 Willis St, 6011 Wellington, New Zealand. Matomo does not set any cookies on our website and enables anonymised analysis of user behaviour on the website. The following is stored: the user's IP address, shortened by the last two bytes (anonymised); the page accessed and the time of access; the page from which the user reached our website (referrer); which browser with which plugins, which operating system and which screen resolution is used; the time spent on the website; the pages accessed from the visited subpage. The data collected with Matomo is stored on servers operated by us in Germany. It is not passed on to third parties.
- Legal basis for the processing of personal data
The legal basis for the processing of users' personal data is legitimate interest pursuant to Art. 6(1)(1)(f) GDPR.
- Purpose of the processing of personal data
The controller needs the data to analyse users' browsing behaviour and to obtain information on the use of the individual components of the website. This enables it to continuously optimise the website and its user-friendliness. These purposes constitute the legitimate interest pursuant to Art. 6(1)(f) GDPR. Through anonymisation, the controller takes into account users' interest in the protection of their personal data. The data is never used to personally identify the user of the website and is not merged with other data.
- Data erasure and storage period
The personal data is deleted after 12 months and summarised in monthly reports without any personal reference.
- Possibility of objection and removal
You can object to the processing of your data by Matomo at any time. To do so, you can:
a) activate the "Do Not Track" setting in your browser. The Matomo system is configured to respect this setting.
b) create a so-called opt-out cookie with one click below, which is valid for two years. As a result, Matomo will not register your further visits. Please note, however, that the opt-out cookie will be deleted if you delete all cookies.
XXII. Use of cloudworx Website Tracking
- Description and scope of the processing of personal data
On its website, the controller uses a self-developed tracking script to identify which companies are interested in its products and services. The script is operated by cloudworx GmbH itself; no external provider is involved.
While you are active on the website, the script regularly transmits the following data to our server (api.cloudworx.agency): the address (URL) of the page accessed, the time, the number of your clicks and how far you have scrolled on the page. Based on the technical data of your visit, we determine whether the visit originates from a company and assign company data such as the company name and website to it. Individual persons are not identified in this process. The script does not set any cookies and does not store any information in your browser.
- Legal basis for the processing of personal data
The legal basis is Art. 6(1)(1)(f) GDPR. The legitimate interest of the controller lies in identifying companies that are interested in its products and services and aligning its offering accordingly.
- Purpose of the processing of personal data
The purpose is to identify companies visiting the website and to evaluate their interest in individual content.
- Data erasure and storage period
The data is deleted if no activity has been recorded on our websites for the respective company for 12 months.
- Possibility of objection and removal
You can object to the processing at any time, e.g. by email to privacy@cloudworx.agency.
XXIII. Details on the Cookies Used
Last updated: October 2026