Privacy Statement

We are pleased that you use our website. The protection of your personal data is important to us, and we want you to feel secure when using our website.

Information on the Collection of Personal Data

(1) In the following, we inform you about the collection of personal data when using our website. Personal data means all data that can be related to you personally, for example your name, address, email addresses or user behaviour.

(2) The controller within the meaning of Art. 4(7) of the EU General Data Protection Regulation (GDPR) is:

MMM Multi-Media-Marketing GmbH
Hohenzollernstr. 145
41061 Mönchengladbach
Germany

Phone: 02161 / 40601 - 0
Fax: 02161 / 40601 - 339
Email: info@mmm-gmbh.com

You can contact our Data Protection Officer at datenschutz@mmm-gmbh.com or by post using the addition “Data Protection Officer”.

(3) If we use commissioned service providers for individual functions of our offering or if we wish to use your data for advertising purposes, we will inform you in detail below about the respective processes.

Your Rights as a Data Subject

(1) You have the following rights vis-à-vis us with regard to the personal data concerning you:

  • Right of access (Art. 15 GDPR):
    You have the right to request information about your personal data processed by us. In particular, you may request information about the purposes of processing, the category of personal data, the categories of recipients to whom your data has been or will be disclosed, the planned storage period, the existence of a right to rectification, erasure, restriction of processing or objection, the existence of a right to lodge a complaint, the origin of your data if it was not collected from you, and the existence of automated decision-making including profiling and, where applicable, meaningful information about its details.
  • Right to rectification (Art. 16 GDPR):
    You have the right to obtain without undue delay the rectification of inaccurate personal data stored by us or the completion of incomplete personal data.
  • Right to erasure (Art. 17 GDPR):
    You have the right to request the erasure of your personal data stored by us, unless processing is necessary for exercising the right of freedom of expression and information, for compliance with a legal obligation, for reasons of public interest or for the establishment, exercise or defence of legal claims.
  • Right to restriction of processing (Art. 18 GDPR):
    You have the right to request the restriction of processing of your personal data where you contest the accuracy of the data, the processing is unlawful but you oppose its erasure, we no longer need the data but you require it for the establishment, exercise or defence of legal claims, or you have objected to processing pursuant to Art. 21 GDPR.
  • Right to data portability (Art. 20 GDPR):
    You have the right to receive the personal data that you have provided to us in a structured, commonly used and machine-readable format or to request transmission to another controller.
  • Right to object to processing (Art. 21 GDPR):
    You have the right, on grounds relating to your particular situation, to object at any time to processing of personal data concerning you. In particular, you may object to the processing of your personal data for advertising and data analysis purposes as well as to related profiling. If you exercise such an objection, we ask you to explain the reasons why we should not process your personal data as we have done. In the event of your justified objection, we will review the situation and either stop or adjust the data processing or demonstrate our compelling legitimate grounds on the basis of which we continue the processing.
  • Right to withdraw consent (Art. 7(3) GDPR):
    You have the right to withdraw consent once given to us at any time. As a result, we may no longer continue the data processing based on this consent for the future.

(2) Please address inquiries regarding your data subject rights to info@mmm-gmbh.com or by post to our address with the addition “Data Protection Officer”.

(3) You also have the right to lodge a complaint with a data protection supervisory authority about our processing of your personal data. The supervisory authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia: www.ldi.nrw.de.

Collection of Personal Data When Visiting Our Website

When you use the website for purely informational purposes, meaning if you do not register or otherwise transmit information to us, we collect only the personal data that your browser transmits to our server. If you wish to view our website, we collect the following data, which is technically necessary for us to display our website to you and to ensure stability and security. The legal basis is Art. 6(1) sentence 1 lit. f GDPR:

  • IP address
  • Date and time of the request
  • Time zone difference from Greenwich Mean Time (GMT)
  • Content of the request (specific page)
  • Access status / HTTP status code
  • Amount of data transferred in each case
  • Website from which the request originates
  • Browser
  • Operating system and its interface
  • Language and version of the browser software

We process the aforementioned data for the following purposes:

  • Ensuring a smooth connection setup of the website
  • Ensuring comfortable use of our website
  • Evaluation of system security and stability and for further administrative purposes

This information is temporarily stored in a so-called log file. The information is collected without any action on your part and stored only for as long as required for the stated purposes and then deleted.

Use of Cookies

(1) In addition to the data mentioned above, cookies are stored on your computer when you use our website. Cookies are small text files that are stored on your hard drive assigned to the browser you use and through which certain information flows to the party setting the cookie, in this case us. Cookies cannot execute programs or transmit viruses to your computer. They serve to make the internet offering more user-friendly and effective overall.

(2) Types of cookies

This website uses the following types of cookies, the scope and functionality of which are explained below:

  • Transient cookies
  • Persistent cookies

Transient cookies are automatically deleted when you close the browser. These include, in particular, session cookies. They store a so-called session ID, by which various requests from your browser can be assigned to the common session. This allows your computer to be recognized when you return to our website, for example to prevent you from having to log in again on every page change. Session cookies are deleted when you log out or close the browser.

Persistent cookies are automatically deleted after a specified period, which may vary depending on the cookie. How long the cookie remains on your device depends on the duration or expiration date of the respective cookie and your browser settings. You can delete cookies at any time in your browser’s security settings. These cookies allow the website to remember your information and settings on your next visit. This gives you faster and more convenient access to the website because, for example, you do not have to set your language preference again.

(3) We use cookies either on the basis of our legitimate interests (technically necessary cookies) or on the basis of your consent (optional cookies), according to your selection in the cookie banner displayed when accessing the website. You can also configure your browser settings according to your wishes and, for example, reject third-party cookies or all cookies. This may restrict the functionality of our offerings.

Recipients or Categories of Recipients

(1) In the course of our activities and services, it may be necessary for us to disclose personal data stored about you to natural persons, legal entities or other bodies. Where applicable, we conclude data processing agreements with our service providers to ensure that they may process your personal data only in the manner explicitly instructed by us. We also ensure that they have implemented the necessary technical and organizational measures to process your data securely and that they store your personal data only for as long as truly necessary. External service providers that may receive personal data generally fall into the following categories of recipients:

  • Credit institutions and payment service providers for invoicing and payment processing, including online payment providers
  • Parcel delivery companies
  • IT service providers for maintaining our IT infrastructure
  • Cloud providers
  • Service providers for optimizing the online offering
  • Debt collection service providers and lawyers for collecting receivables and enforcing claims in court. If personal data is transferred to a debt collection service provider in a collection case, including customer and contact data, payment data, point-of-consumption data and data relating to the claim, we will inform you in advance of the intended transfer
  • Service providers for applicant management systems and providers of marketing and tracking tools
  • Providers of CRM and marketing automation systems

(2) If data is processed in countries outside the EU, we ensure that your personal data is processed in accordance with the European level of data protection. If there is no adequacy decision by the European Commission, we transfer data only to service providers in third countries that provide appropriate safeguards pursuant to Art. 46 GDPR, generally EU Standard Contractual Clauses.

Applications

(1) If you apply to us via our website, we process the data that you provide to us as part of the application process for this purpose. The legal basis is Art. 88 GDPR in conjunction with Section 26 BDSG as well as Art. 6(1) GDPR for the initiation or performance of contractual relationships. If an employment relationship is established between you and us, we process the personal data already received from you for employment purposes pursuant to Art. 88 GDPR in conjunction with Section 26 BDSG.

(2) The data will be deleted where there are no legal retention obligations and no overriding legitimate interests, generally after six months. If you have additionally given explicit consent in your application for extended storage in an applicant tool, the duration of processing extends to that period. Consent granted may be withdrawn at any time with effect for the future.

Social Media Presences and Portals

(1) We maintain online presences in the social networks and platforms listed below, including employer rating portals, as the operator. These social networks are operated exclusively by the respective provider. These presences serve to communicate with customers, interested parties and users and for advertising and market research purposes. If you contact us via our social media channels, we process the data you provide to us as well as the data necessary to handle the inquiry pursuant to Art. 6(1) lit. b GDPR. Further data processing is based on Art. 6(1) lit. f GDPR due to our legitimate interest in direct communication with users and the optimization of our online presences. If you have given your consent to the operators of the respective social media platforms, for example by checkbox opt-in, processing is based on Art. 6(1) lit. a GDPR. You may withdraw your consent at any time with effect for the future vis-à-vis the operator of the respective platform.

(2) When our social media pages are accessed, your user data is collected and provided to us by the operator. The exact types of data vary from provider to provider but generally include the following information:

  • Followers: number and stored profiles; information on growth and development over a defined period
  • Reach: number of people who see a specific post; number of interactions with a post. This can be used, for example, to derive which content is better received by the community than other content
  • Ad performance: how many people were reached by a post or paid advertisement and interacted with it
  • Demographics: average age of visitors, gender, place of residence, language

(3) Since our social media channels are operated by the providers of the respective social network, there may be supplementary use of your personal data by the respective operator over which we have no influence. This often involves collecting your IP address, creating statistical evaluations and processing further information stored in the form of cookies. These data are frequently also used to display interest-based advertising to you inside and outside the platforms. As the operator, we have no influence on the creation and display of this advertising and cannot disable this function or prevent data processing.

(4) The assertion of data subject rights and requests for information can be addressed most effectively directly to the platform providers, as only they have access to your data and can take immediate measures. If our cooperation is required for this purpose, we will support you as needed in enforcing your data subject rights.

(5) The network operators used are listed below. Further information on terms of use and data protection of the respective platform as well as a detailed description of further data processing and objection options can be found on the providers’ pages:

Facebook: Meta Platforms Ireland Ltd., Merrion Road, Dublin 4, D04 X2K5, Ireland. Parent company: Meta Platforms, Inc., 1 Hacker Way, Menlo Park, CA 94025, USA. Privacy Policy: www.facebook.com/privacy/policy/

Instagram: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. Privacy Policy: privacycenter.instagram.com/policy/

Xing: New Work SE, Baumwall 7, 20459 Hamburg, Germany. Privacy Policy: privacy.xing.com/de/datenschutzerklaerung/allgemeine-hinweise

WhatsApp: WhatsApp Ireland Limited / Meta Platforms Ireland Ltd., Merrion Road, Dublin 4, D04 X2K5, Ireland. Privacy Policy: www.whatsapp.com/legal/privacy-policy-eea?eea=1

LinkedIn: LinkedIn Ireland, Privacy Policy Issues, Wilton Plaza, Wilton Place, Dublin 2, Ireland. Privacy Policy: www.linkedin.com/legal/privacy-policy

Facebook Page Insights – “Facebook Fan Pages”

(1) When you visit our Facebook page, Facebook collects, among other things, your IP address and further information stored on your PC in the form of cookies. This information is used to provide us, as the operator of the Facebook page, with statistical information about the use of the Facebook page. These statistics are available to us as the page operator via so-called “Insights” of the Facebook page. These statistics are created and provided solely by Facebook. As the operator, we have no influence on their creation and presentation. We cannot disable this function or prevent the generation and processing of the data. Further information on “Insights” is provided by Facebook at: www.facebook.com/privacy/center/.

(2) The following data are provided to us by Facebook via “Insights”: number of page views, likes, page activities, reach, video views, post interactions, post reach, comments, shared content, responses, gender ratio, regional distribution of users by country and city, language, views and clicks in the shop, clicks on route planner and clicks on telephone numbers.

(3) The operation of this Facebook page and the associated processing of users’ personal data is based on Art. 6(1) lit. f GDPR, our legitimate interest in a contemporary and supportive information and interaction opportunity for and with users and visitors to our Facebook page.

(4) We, as the operator of the fan page, are jointly responsible with Facebook for processing. Therefore, a Page Insights Controller Addendum has been agreed with Facebook, specifying which party fulfils which obligations under the GDPR. The primary responsibility under the GDPR for the processing of Insights data lies with Facebook. Facebook therefore fulfils all obligations under the GDPR with regard to the processing of Insights data, including Articles 12 and 13 GDPR, Articles 15 to 22 GDPR and Articles 32 to 34 GDPR. Your data subject rights may be asserted against us or Facebook Ireland Limited. If you contact us as a data subject under the GDPR regarding the processing of Insights data and the obligations assumed by Facebook Ireland under the Page Insights Addendum, we are required to forward all relevant information to Facebook Ireland.

The full Page Insights Controller Addendum can be found at: www.facebook.com/legal/terms/page_controller_addendum

(5) Facebook address and privacy notice URL: Facebook Inc., 1601 S California Ave, Palo Alto, California 94304, USA; www.facebook.com/policy.php.

CleverReach Newsletter

(1) We send newsletters, emails and other electronic notifications containing advertising information using the newsletter tool CleverReach provided by CleverReach GmbH & Co. KG, Schafjückenweg 2, 26180 Rastede, Germany.

(2) Our newsletters contain information about our products, offers, promotions and our company. With the following information, we inform you about the content of our newsletter as well as the registration, dispatch and statistical evaluation procedure and your rights of objection.

(3) We use a logged double opt-in procedure for newsletter registration. This means that after registration you receive an email asking you to confirm your registration. This confirmation is necessary so that no one can register using someone else’s email address. Newsletter registrations are logged to be able to prove the registration process in accordance with legal requirements. This includes storage of the registration and confirmation times as well as the IP address. Changes to your data stored with the mailing service provider are also logged. The purpose of the procedure is to prove your registration and, if necessary, clarify possible misuse of your personal data.

(4) To register for the newsletter, it is sufficient to provide your email address. Providing further data is voluntary and is used to address you personally. After confirmation, we store your email address for the purpose of sending the newsletter. The sending of the newsletter and performance measurement are based on your consent pursuant to Art. 6(1) lit. a and Art. 7 GDPR.

(5) You can withdraw your consent to receive the newsletter at any time and unsubscribe from the newsletter. You can declare withdrawal by clicking the link provided in every newsletter email, by email to info@mmm-gmbh.com or by sending a message to the contact details provided in the legal notice.

(6) Your data collected during newsletter registration will be stored for as long as you have subscribed to the newsletter. After withdrawal of your consent or unsubscribing from the newsletter, your data will be deleted from the mailing list within 30 days.

(7) Further information on data protection at CleverReach is available at: www.cleverreach.com/en/gdpr-compliant-newsletter-tool/

Matomo

(1) We use the web analytics software Matomo to analyse the use of our website and to understand what visitors are interested in on our websites (reach analysis). The statistics obtained allow us to improve our offering and make it more interesting for you as a user.

(2) For this analysis, cookies are stored on your computer. You can stop the analysis by deleting existing cookies and preventing the storage of cookies. The legal basis for this data processing is your consent pursuant to Art. 6(1) sentence 1 lit. a GDPR, which you gave via the cookie banner. You may withdraw your consent at any time with effect for the future by opening the cookie settings and changing your selection there.

(3) We also use the “AnonymizeIP” extension. This means that IP addresses are shortened before further processing, so that direct personal identification can be excluded. The IP address transmitted by your browser through Matomo is not combined with other data collected by us.

(4) Matomo is an open-source project. Information on data protection by Matomo is available at: matomo.org/privacy-policy/

Applicant Management Systems and HR Systems

(1) To conduct and manage application procedures and human resources administration, we use external software solutions. Personal data of applicants and employees is processed insofar as this is necessary for conducting the application procedure or for establishing, performing or terminating an employment relationship.

(2) For applicant management, we use the software of Softgarden e-recruiting GmbH, Tauentzienstraße 14, 10789 Berlin, Germany. As part of the application process, application documents, contact data, communication data and other information provided by applicants are processed in particular.

(3) For personnel administration, we use the HR system P&I AG (Loga3 HR-System), Kreuzberger Ring 56, 65205 Wiesbaden, Germany. This system processes, in particular, personnel master data, contract data, payroll data, time management data and other employment-related data.

(4) Processing is carried out for the following purposes:

  • Conducting and managing application procedures
  • Communication with applicants
  • Documentation and evidence in the application process

(5) Processing is based on Art. 88 GDPR in conjunction with Section 26 BDSG and Art. 6(1) lit. b GDPR, insofar as data processing is necessary for deciding on the establishment of an employment relationship or for its performance. Where processing goes beyond this, it is based on a legal obligation (Art. 6(1) lit. c GDPR) or consent given (Art. 6(1) lit. a GDPR).

(6) Data processing agreements pursuant to Art. 28 GDPR have been concluded with the aforementioned service providers where required.

Further information is available in the providers’ privacy notices:

Softgarden: softgarden.com/en/privacy-policy/

P&I AG: www.pi-ag.com/datenschutz

Processing of Leads (Heyflow)

To provide interactive forms and to collect and process inquiries from interested parties (leads), we use the services of Heyflow GmbH, Jungfernstieg 49, 20354 Hamburg, Germany.

If you enter personal data via our forms, for example contact, inquiry or application forms, these data are transmitted to Heyflow and processed on our behalf. In particular, the following data may be processed:

  • Name and contact details
  • Application or inquiry content
  • Information that you voluntarily provide within the forms
  • Usage data, for example form progress

The purposes of processing are:

  • Provision and technical implementation of interactive forms
  • Processing of contact inquiries and inquiries from interested parties
  • Implementation of pre-contractual measures
  • Optimization of conversion and user guidance
  • Prequalification of inquiries and applications

Processing of your personal data is based on Art. 6(1) lit. b GDPR insofar as the processing is necessary for carrying out pre-contractual measures or initiating a contractual relationship. If we obtain your consent, processing is based on Art. 6(1) lit. a GDPR. In addition, processing may be based on our legitimate interest pursuant to Art. 6(1) lit. f GDPR, in particular for the efficient processing of inquiries and optimization of our online offerings and business processes.

Your data will be stored only for as long as necessary to process your inquiry, carry out pre-contractual measures or comply with statutory retention obligations.

A data processing agreement pursuant to Art. 28 GDPR exists with Heyflow. Data are generally processed on servers within the EU.

Further information: heyflow.com/legal/data-privacy/

Use of Meta Pixel (Facebook Pixel)

(1) We use the “Meta Pixel” service on our website, provided by Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland. Meta Pixel enables us to track the behaviour of visitors to our website after they have reached our website via advertisements on the Facebook or Instagram platforms. This allows us to analyse and optimize the effectiveness of our advertising measures and to create interest-based target groups for future advertisements (so-called remarketing).

(2) The purpose of processing is to analyse the use of our website for advertising measurement and optimization purposes, and to target advertisements to persons who have already visited our website (remarketing), inside and outside Meta platforms.

(3) In connection with the use of Meta Pixel, the following data in particular may be processed:

  • IP address
  • User behaviour on the website
  • Pages visited and interactions
  • Device information

(4) The information collected by Meta Pixel may be transmitted to Meta. Meta may combine this information with further data from your user account and process it for its own purposes in accordance with Meta’s privacy policy. We have no influence over the nature and scope of further processing by Meta.

(5) A transfer of personal data to third countries, in particular to the USA, cannot be excluded. Meta is certified under the EU-U.S. Data Privacy Framework. Data transfers are carried out on the basis of appropriate safeguards pursuant to Art. 46 GDPR, in particular the Standard Contractual Clauses approved by the European Commission.

(6) The legal basis for using Meta Pixel is your consent pursuant to Art. 6(1) lit. a GDPR, which you provide via the cookie banner.

(7) You may withdraw your consent at any time with effect for the future by opening and adjusting the cookie settings.

Further information: www.facebook.com/privacy/policy/

Use of the CRM and Marketing System Brevo

(1) We use the CRM and marketing automation tool Brevo, formerly Sendinblue, provided by Brevo GmbH, Köpenicker Straße 126, 10179 Berlin, Germany.

(2) We use Brevo to manage customer, prospect and contact data and to carry out and automate communication and marketing measures. This includes in particular:

  • Management of contact and prospect data (CRM)
  • Sending email newsletters and other electronic communications
  • Automated communication, for example lead nurturing processes, applicant and customer communication
  • Analysis, evaluation and optimization of our marketing and communication measures

(3) The following personal data may be processed:

  • Name, email address, telephone number
  • Communication content, for example emails and inquiries
  • Interaction data, for example opening and click rates
  • Usage data from forms or lead funnels

(4) Depending on the respective processing purpose, personal data is processed on the basis of:

  • Your consent pursuant to Art. 6(1) lit. a GDPR, for example for sending newsletters or marketing communication
  • The performance of pre-contractual measures or the performance of a contract pursuant to Art. 6(1) lit. b GDPR, for example for inquiries, applications or customer communication
  • Our legitimate interest pursuant to Art. 6(1) lit. f GDPR in the efficient management of contacts, customer relationships and communication processes

(5) Data is generally processed on servers within the European Union. Transfer to third countries cannot be completely excluded. In such cases, processing is carried out on the basis of appropriate safeguards pursuant to Art. 46 GDPR, for example EU Standard Contractual Clauses.

(6) A data processing agreement pursuant to Art. 28 GDPR exists with Brevo.

(7) Further information on data protection at Brevo can be found at: www.brevo.com/de/legal/privacypolicy/

Automated Decision-Making and Profiling

(1) We do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you within the meaning of Art. 22 GDPR.

(2) Where we use marketing automation tools, in particular Brevo, interest profiles may be created on the basis of your user behaviour in order to send you relevant communication, for example personalized newsletters. This profiling is carried out exclusively on the basis of your consent pursuant to Art. 6(1) lit. a GDPR and does not lead to automated individual decisions with legal effect. You may object to this processing at any time by withdrawing your consent.

TTCall by TTUnited

For conducting and managing our telephone sales and customer communication, we use the TTCall software of TTUnited GmbH, Lurgiallee 12, 60439 Frankfurt am Main, Germany. The application supports, in particular, the organization of telephone contacts, the execution of calls and the documentation of sales-relevant information.

In connection with its use, the following personal data in particular may be processed:

  • Contact data, for example name, company, telephone number and email address
  • Communication data, for example time, duration and result of telephone calls
  • Sales and customer information
  • Call notes and documentation

Processing is carried out for the initiation, performance and maintenance of business relationships and for processing customer and prospect inquiries.

The legal basis for processing is Art. 6(1) lit. f GDPR. Our legitimate interest lies in the efficient organization of our sales and communication processes. Where processing serves the initiation or performance of a contract, it is carried out on the basis of Art. 6(1) lit. b GDPR.

The data will be deleted as soon as it is no longer required to achieve the stated purposes and no statutory retention obligations prevent deletion.

We have concluded a data processing agreement with the provider pursuant to Art. 28 GDPR.

Personal data are processed exclusively on servers within the European Union (EU) or the European Economic Area (EEA). Personal data are not transferred to third countries outside the EU or EEA.

Further information on data processing by the provider can be found in its privacy notice: www.ttunited.com/datenschutz

Tribe Technologies

For conducting and managing our telephone sales and customer communication, we use software provided by Tribe Technologies GmbH, Lurgiallee 12, 60439 Frankfurt am Main, Germany. The application supports, in particular, the organization of telephone contacts, the execution of calls and the documentation of sales-relevant information. In connection with the use of this service, conversations with you may be recorded and processed.

The call recordings serve in particular quality assurance, documentation, training, improvement of our services and processing of inquiries and support cases. The following personal data in particular may be processed:

  • Contact data, for example name, company, telephone number and email address
  • Communication data, for example time, duration and result of telephone calls
  • Sales and customer information
  • Call notes and documentation

Processing is carried out for the initiation, performance and maintenance of business relationships and for processing customer and prospect inquiries.

The legal basis for processing is Art. 6(1) lit. f GDPR. Our legitimate interest lies in the efficient organization of our sales and communication processes. Where processing serves the initiation or performance of a contract, it is carried out on the basis of Art. 6(1) lit. b GDPR. Call recording is carried out on the basis of your consent pursuant to Art. 6(1) lit. a GDPR.

The data and recordings will be deleted as soon as they are no longer required to achieve the stated purposes and no statutory retention obligations prevent deletion.

We have concluded a data processing agreement with the provider pursuant to Art. 28 GDPR.

Personal data are processed exclusively on servers within the European Union (EU) or the European Economic Area (EEA). Personal data are not transferred to third countries outside the EU or EEA.

Further information on data processing by the provider can be found in its privacy notice: www.tribetech.de/datenschutz

CRM Provider Monday.com

For the organization and management of our sales activities in the area of B2B acquisition, we use the Monday.com platform of monday.com Ltd, 6 Yitzhak Sadeh Street, Tel Aviv, 6777506, Israel.

Via Monday.com, we manage in particular sales processes, contacts, inquiries from interested parties, tasks and business transactions. The following personal data may be processed:

  • Names of contact persons
  • Business contact data, for example email address and telephone number
  • Company affiliation and position
  • Communication and interaction data
  • Sales and project data
  • Notes and documentation relating to business contacts

Processing is carried out for the purpose of organizing, managing and documenting our sales activities and for initiating and maintaining business relationships.

The legal basis is Art. 6(1) lit. f GDPR. Our legitimate interest lies in the efficient and structured implementation of our sales and business processes. Where processing serves the implementation of pre-contractual measures or a contract, it is carried out on the basis of Art. 6(1) lit. b GDPR.

Monday.com may also process personal data in countries outside the European Union or the European Economic Area. Such transfer takes place exclusively in compliance with the requirements of Articles 44 et seq. GDPR. Where required, we base the transfer on an adequacy decision of the European Commission or on appropriate safeguards, in particular the European Commission’s Standard Contractual Clauses.

We have concluded a data processing agreement with the provider pursuant to Art. 28 GDPR.

The data will be deleted as soon as it is no longer required to achieve the stated purposes and no statutory retention obligations prevent deletion.

Further information on data processing by Monday.com can be found in the provider’s privacy notice: monday.com/l/privacy

Use of Microsoft 365 and Microsoft Services

We use various services of the Microsoft 365 platform to support our business processes. The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland.

Microsoft Teams is used as a platform for internal and external collaboration as well as for audio, video and online conferences. In particular, the following data may be processed: name, email address, profile picture, voice and video data during conferences, chat content, shared files and technical connection data such as IP address and device identifiers.

Microsoft Forms is used for the digital collection and management of information, for example as part of digital visitor management. The processed data include in particular name, contact details and the information requested in the respective form, such as reason for visit and contact person. Data provided via forms are processed exclusively for the respective stated purposes.

Microsoft Azure and services of the Microsoft Power Platform are used for hosting databases, providing and processing data and using applications such as Power BI and Power Automate. In this context, master and contact data, usage data, transaction data and other information processed within the applications used may be processed.

When using Microsoft Copilot for Business and Microsoft Copilot Studio, AI-supported systems are used that process inputs, requests and generated content. According to the current status of our contractual agreement, use of these data by Microsoft for the further development of AI models is excluded or prevented by appropriate configuration measures. Automated individual decisions within the meaning of Art. 22 GDPR are not made by these systems.

The processing of personal data is based on Art. 6(1) lit. f GDPR. The legitimate interest lies in the efficient and secure design of our internal and external corporate communication and business processes. Where processing is necessary for carrying out pre-contractual measures or fulfilling a contract, it is based on Art. 6(1) lit. b GDPR.

Where personal data are processed in connection with the services mentioned, we have concluded the required data protection agreements with Microsoft, in particular a data processing agreement pursuant to Art. 28 GDPR. In connection with the use of Microsoft services, personal data may be transferred to the USA and other third countries. The transfer is based on the Standard Contractual Clauses (SCC) issued by the European Commission pursuant to Articles 44 et seq. GDPR. In addition, Microsoft is certified under the EU-U.S. Data Privacy Framework (DPF).

The data will be deleted as soon as it is no longer required to achieve the stated purposes and no statutory retention obligations prevent deletion.

Further information on data processing by Microsoft can be found in the provider’s privacy notice: www.microsoft.com/en-us/privacy/privacystatement

Use of Nextcloud

For secure electronic exchange of documents and information, we use the Nextcloud software provided by Nextcloud GmbH, Hauptmannsreute 44a, 70192 Stuttgart, Germany. This platform can be used to provide, receive, store and manage files and other information.

In connection with the use of Nextcloud, data provided by users as well as technical connection and log data are processed insofar as this is necessary for providing the platform, ensuring IT security and carrying out data exchange. The data processed may include, in particular, master and contact data, documents, communication content and usage and access data.

Processing is carried out for the implementation of pre-contractual measures and for the fulfilment of contractual obligations pursuant to Art. 6(1) lit. b GDPR and on the basis of our legitimate interest in secure and efficient electronic communication pursuant to Art. 6(1) lit. f GDPR.

We have concluded a data processing agreement with the provider pursuant to Art. 28 GDPR.

Where external service providers are used for the operation of Nextcloud, their involvement is based on a data processing agreement pursuant to Art. 28 GDPR. The storage and processing of data generally takes place within the European Union or the European Economic Area, unless otherwise stated.

The data will be deleted as soon as it is no longer required to achieve the stated purposes and no statutory retention obligations prevent deletion.

Further information on data processing by Nextcloud GmbH can be found in the provider’s privacy notice: nextcloud.com/privacy/

700+
Employees

4
Locations

156
satisfied customers