Privacy Policy

At WSW Software GmbH, privacy and data security are among our most important principles. WSW Software GmbH attaches great importance to the protection of your privacy and complies with all applicable data protection legislation. In the following, we explain how we process your personal data.

1. Data controller

The data controller with responsibility for the collection, processing and use of your personal data within the meaning of the GDPR is:

WSW Software Gesellschaft mit beschränkter Haftung
Fußbergstraße 1
D-82131 Gauting
Phone: +49 (0) 89 89 50 89-0
Fax: +49 (0) 89 89 50 89-190
CEO: Klaus Müer

1.1 Name and contact details of the Data Protection Officer

Stefan Herz
Phone: +49 (0) 89 89 50 89-160
datenschutz@wsw.de

1.2 Legal basis for the processing of personal data

Insofar as we obtain the data subject's consent to process their personal data, Article 6 (1) (a) of the General Data Protection Regulation (GDPR) provides the legal basis.

We process your personal data for the purposes of the contract, whereby Article 6 (1) (b) GDPR provides the legal basis. This also applies to processing operations which serve the implementation of pre-contractual measures.

To the extent that it is necessary to process personal data in order to fulfill a legal obligation on the part of our company, Article 6 (1) (c) GDPR provides the legal basis.

In the event that vital interests of the data subject or any other natural person require the processing of personal data, Article 6 (1) (d) GDPR provides the legal basis.

Where the processing is necessary to safeguard the legitimate interests of our company, and provided that the interests, fundamental rights and freedoms of the data subject do not outweigh the former interests, then Article 6 (1) (f) GDPR provides the legal basis for the processing. Our interests in the processing include, in particular, ensuring the operation and security of the website, analyzing the usage of the website by visitors and simplifying the use of the website.

1.3 General information

Types of processed data:

  • Contact details (e.g., e-mail, telephone numbers)
  • Content data (e.g., text entries, photographs)
  • Usage data (e.g., visited websites, content of interest, access times)
  • Meta/communication data (e.g., device information, IP addresses)

Data subjects

The data subjects are the visitors to – and users of – our online services. In the following, we also refer to the data subjects as "users".

Purpose of the processing

  • To deliver our online services, including the related functions and content
  • To respond to contact requests and communicate with users
  • Reach measurement/marketing

Terms used

"Personal data" means any information relating to an identified or identifiable natural person (hereinafter "data subject"). A natural person is considered to be identifiable if they can be identified directly or indirectly, in particular by association with an identifier such as a name, identification number, location data, an online identifier (e.g., a cookie) or by means of one or more unique features which express the physical, physiological, genetic, psychological, economic, cultural or social identity of said natural person.

"Processing" means any process performed with or without the aid of automated procedures or any such process associated with personal data. This term covers a wide range of activities and covers virtually every type of interaction with data.

The "data controller" refers to the natural or legal person, public authority, institution or body which, either alone or in concert with others, decides on the purposes and means of the processing of personal data.

Hosting

We have leased data centers for the purpose of providing and operating this website. These data centers possess various certifications, including ISO 27001.

The hosting services we use serve to provide the following services: infrastructure and platform services, computing capacity, disk space and database services, collateral and technical maintenance services, which we use to operate this online service.

In doing so, we (or our hosting provider) process the inventory data, contact data, content data, contract data, usage data, meta and communication data submitted by customers, interested parties and visitors to this website on the basis of our legitimate interest in making this online offer available in an efficient and secure manner in accordance with Article 6 (1) (f) GDPR in conjunction with Article 28 GDPR (conclusion of an order processing contract).

The data centers are located in the European Union. To the extent that personal data of EU citizens is stored in data centers outside the European Union, the respective data centers have established an equivalent level of protection via Privacy Shield or standard contractual clauses.

Storage period

Unless specifically stated, we store personal data only for as long as necessary to fulfill the stated purpose.

2. General use of this website

2.1 Cookies

Each time you contact us, we receive and store certain information. Among other things, we use so-called "cookies" and "Flash cookies" and receive certain information as soon as your web browser opens the WSW website and/or other content that is provided by or on behalf of WSW on other websites. Cookies and Flash cookies are text files that are transmitted to your computer via your web browser or other programs. As a result, our system is able to recognize your browser and to offer you various services. In this way, our use of cookies facilitates your visit to our site.

If you wish to prevent additional cookies from being accepted by your browser, or to be notified when you receive new cookies, or if you wish to disable all cookies, please access the help function via your web browser's menu bar. You can disable or delete Flash cookies or similar features that are used by certain browser add-ons either by changing the settings of the respective browser add-on or by following the instructions on disabling them provided on the manufacturer's website.

Please take into account, however, that certain features of the WSW website require the use of cookies.

2.2 Use of web fonts

In order to ensure that fonts are displayed consistently, this site uses so-called "web fonts" provided by MyFonts Inc., 600 Unicorn Park Drive, Woburn, MA 01801, United States. Whenever you access a web page, your browser loads the required web fonts into your browser cache in order to correctly display text and fonts.

In order to do this, the browser you are using must connect to the MyFonts servers. During this process, MyFonts is able to determine that our website was accessed from your IP address. Our use of MyFonts corresponds to our interest in ensuring of a consistent and attractive presentation of our online services. This constitutes a legitimate interest within the meaning of Art. 6 (1) (f) GDPR. If your browser does not support web fonts, a default font will be used by your computer.

Further information about MyFonts is available at:

https://www.monotype.com/de/rechtshinweise/nutzungsbedingungen/ und https://www.monotype.com/de/rechtshinweise/datenschutzrichtlinie/.

2.3 Access data

WSW collects information about you when you use this website. We automatically collect information about your usage behavior and interactions with us, and record information about your computer or mobile device. We collect, store and use data each time you access our online service (so-called "server log files"). This access data includes the name and URL of the retrieved file, the date and time of the retrieval, the quantity of data transferred, a notification of successful retrieval, the browser type and version, the operating system, the referrer URL (i.e. the previously visited page), the IP address, and the requesting provider.

We do not use this log data to identify you or for other profiling purposes, and instead use it for statistical analysis for the purpose of operation, security and optimization of our online services, and also to anonymously determine the number of visitors to our website (traffic) as well as the extent and nature of your use of our website and services. This information enables us to analyze traffic, find and fix bugs, and improve our services. We reserve the right to check the log data retrospectively in cases where we have legitimate grounds to suspect unlawful use of our services on the basis of concrete evidence. We store IP addresses in the log files for a limited period and to the extent necessary for security purposes or for the provision of services or the billing of a service. We also store IP addresses if we have compelling reasons to suspect criminal activity in connection with the use of our website. We also save the date of your last visit (e.g., when registering, logging in, clicking links, etc.) as part of your account data.

The legal basis for this data processing is provided by Article 6 (1) (1) (f) GDPR. Our legitimate interest follows from the data collection purposes listed above.

2.4 Contact by e-mail

If you contact us (e.g., by e-mail), we will store your details for the purpose of processing your request and for any follow-up questions that may arise. We will only store and use other personal data if you consent to this, or if we are permitted by law to do so without your explicit consent.

2.5 Access and reach measurement

Wiredminds

WSW uses tracking pixel technology provided by wiredminds GmbH (www.wiredminds.de) for the purpose of analyzing visitor behavior. This involves the collection, processing and storing of data, which is used to create usage profiles under a pseudonym. Where possible and useful, these usage profiles are anonymized completely – cookies may be used for this purpose. Cookies are small text files that are stored in the visitor’s internet browser and used to recognize their internet browser. The collected data, which may also contain personal data, is sent to wiredminds or is collected directly by wiredminds. wiredminds may use information obtained during visits to the websites to create anonymized usage profiles. The data collected in this process will not be used to personally identify the website visitor without the data subject's explicit consent, nor will it be merged with personal data relating to the pseudonymized user. To the extent that IP addresses are recorded, they are immediately anonymized via deletion of the last number block.

You can prevent the collection of your data by wiredminds by clicking on the following link. An opt-out cookie will be stored on your device to prevent collection of your data when you visit this website:

Exclude from tracking.

Matomo

The following data is processed via Matomo for the purpose of reach analysis:

  • The user's browser type/version
  • The user's operating system
  • The user's country of origin
  • The date and time of the request via the server
  • The number of visits
  • The duration of the visit to the website
  • The external links selected by the visitor

Each user's IP address is anonymized before it is saved.

Matomo uses cookies stored on users' computers to analyze their use of our online services. The processed data may be used to create pseudonymous usage profiles. The storage period of the cookies is one week. The information generated by the cookie about your use of this website will only be stored on our server and will not be shared with third parties.

By clicking on the link below you can object to the collection of anonymized data by Matomo at any time with effect for the future. This will result in your browser saving a so-called "opt-out cookie", which will prevent Matomo from collecting session data. Please note, however, that deleting cookies also deletes the opt-out cookies, which will then have to be reactivated.

Logs containing user data will be deleted after six months at the latest. If we ask users for their consent (e.g., to our use of cookies), the legal basis for this processing is provided by Article 6 (1) (a) GDPR. Otherwise, the users' personal data will be processed on the basis of our legitimate interest (i.e. our interest in the analysis, optimization and operation of our online services within the meaning of Article 6 (1) (f) GDPR).

2.6 Online presence in social media

We maintain an online presence within social networks and platforms in order to communicate with customers, interested parties and users there, and to inform them about our services. When you access the respective networks and platforms, the terms and conditions and the data processing policies of the respective operators apply.

Unless otherwise stated in our Privacy Policy, we will process users' data to the extent that they communicate with us within social networks and platforms, e.g., by creating posts on our online service or sending us messages.

Integration of third-party services and content

On the basis of our legitimate interest (i.e. our interest in the analysis, optimization and economic operation of our online services within the meaning of Article 6 (1) (f) GDPR), we include content and services offered by third parties within our online services, e.g., for the purpose of integrating videos and/or fonts (collectively referred to as "content").

This always requires the user's IP address to be shared with the respective third-party providers, since they require the user's IP address in order to send the content to their browser. The user's IP address is therefore required for the presentation of this content. We endeavor only to use content whose respective providers will use the IP address exclusively for the purpose of delivering the respective content. Third parties may also use so-called "pixel tags" (invisible graphics, also referred to as "web beacons") for statistical or marketing purposes. These "pixel tags" can be used to evaluate specific information, such as visitor traffic on the pages of this website. This pseudonymous information may also be stored in cookies on the user's device and may include, but is not limited to, technical information about the respective browser and operating system, the referring web pages, the time of the visit, as well as other information regarding the use of our online services.

XING

The "XING share button" is used on this website. When this button is activated, a short-term connection is established via your browser to the servers of XING SE ("XING"), which provide the "XING share button" functions (in particular, the calculation/display of the counter value). XING does not store any personal data about you when this website is accessed. In particular, XING does not store any IP addresses. In addition, no evaluation of your usage behavior takes place via the cookies used in connection with the "XING share button". The current data protection information regarding the "XING share button", as well as supplementary information, can be found on this website:

https://www.xing.com/app/share?op=data_protection

kununu

On our web pages, we use the plugin provided by the XING social network in the form of the "XING share button" and the "kununu" service. kununu is an application provided via the XING service. When you visit our web pages, a short-term connection is established by your browser to the servers of XING SE ("XING"), which provide the "XING share button" functions (in particular the calculation/display of the counter value).

We would like to point out that, as the provider of the web pages, we have no knowledge of the contents of the transmitted data or its use by kununu. We have no control over the quantity of data collected by kununu via the button. For information about the purpose and scope of the data collection, its further processing and the use of your data by kununu, as well as your rights in this context and your options with regard to protecting your privacy, please refer to the latest version of kununu's privacy policy:

https://www.kununu.com/info/agb
https://privacy.xing.com/de/datenschutzerklaerung

If you do not want kununu to be able to associate your visit to our website with your user account, please log out of your kununu user account before accessing the respective content.

LinkedIn

Our online services may include integrated functions and content provided by the LinkedIn service (LinkedIn Ireland Unlimited Company Wilton Place, Dublin 2, Ireland). This may include, for example, content such as images, videos, or text and buttons that allow users to share content from our online services within LinkedIn. If the users are members of the LinkedIn platform, LinkedIn is able to link their use of the aforementioned content and functions to their user profiles.

The LinkedIn privacy policy is available here: https://www.linkedin.com/legal/privacy-policy.

LinkedIn is certified under the Privacy Shield agreement, which guarantees compliance with European data protection legislation:

https://www.privacyshield.gov/participant?id=a2zt0000000L0UZAA0&status=Active

Opt-Out: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.

YouTube

We integrate videos hosted on the "YouTube" platform provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

Privacy policy: https://www.google.com/policies/privacy/

Opt-Out: https://adssettings.google.com/authenticated.

2.7 Newsletter

In order to distribute our newsletter, we use the distribution service provider Newsletter2Go GmbH, Köpenicker Str. 126, 10179 Berlin, Germany. The privacy policy of Newsletter2Go can be found here: https://www.newsletter2go.de/datenschutz/.

The distribution service provider may retrieve the recipients' data in pseudonymous form, i.e. without assigning it to a user, in order to optimize or improve its own services, e.g., for technical improvements related to the distribution, the presentation of newsletters and/or for statistical purposes. However, the distribution service provider does not use the data submitted by our newsletter recipients in order to contact them directly, nor does it share this data with third parties.

If you wish to receive the newsletter offered on our website, we require your e-mail address. To ensure that you have consented to receive our newsletter, we use a "double-opt-in" procedure, during which the potential recipient can choose to be included in a distribution list. Afterwards, the user receives a confirmation e-mail via which they can confirm their newsletter subscription in accordance with the data protection legislation. The user's e-mail address will not be included in the distribution list until we receive this confirmation.

The newsletter will be sent on the basis of your consent in accordance with Article 6 (1) (a) GDPR.

Performance assessment

The newsletters contain a so-called "web beacon", i.e. a pixel-sized file that is either retrieved from our server – or if we use a distribution service provider, from the latter's server – when you open the newsletter. As part of this retrieval process, technical information is collected, including information about your browser and system, as well as your IP address and the time of retrieval.

This information is used to improve the technical performance of the respective services based on their specifications and/or on the target audience and its reading habits on the basis of its location (which can be determined via the IP address) and/or the time of access. These statistical surveys also include a determination of whether/when the newsletters are opened and which links are clicked. For technical reasons, this information can be assigned to the individual newsletter recipients. However, neither we nor the distribution service provider (if used) endeavor to observe the behavior of individual users. The evaluations merely allow us to identify the reading habits of our users and to adapt our content to suit them, or to send them different content in line with their interests.

3. Rights of data subjects

Under the applicable laws, you have various rights regarding your personal data. If you wish to assert these rights, please send us your request by post or e-mail, clearly identifying yourself and using the contact details listed under points 1 and 1.1. As a data subject you have the following rights.

3.1 Right to information

You have the right to request information about your personal data that is processed by us. In particular, you may request information about the purposes of the processing, the category of personal data, the categories of recipients to whom your data has been disclosed, the planned retention period, your right of rectification, deletion, restriction of or objection to the processing, your right of appeal, the source of your data if it was not collected from us, and the existence of automated decision-making, including profiling, and if applicable, detailed information about this.

3.2 Right to rectification

You have the right to demand the immediate rectification of any incorrect personal data concerning you. In light of the stated purposes, you have the right to request the completion of any incomplete personal data concerning you, including by means of a supplementary statement.

3.3 Right to deletion ("right to be forgotten")

You have the right to ask us to delete your personal data without delay. Furthermore, we are obliged to delete your personal data immediately if one of the following reasons applies:

  • The personal data is no longer necessary for the purposes for which it was collected or otherwise processed.
  • You have revoked your consent on which the processing was based pursuant to Article 6 (1) (a) GDPR or Article 9 (2) (a) GDPR, and no other legal basis for the processing exists.
  • You object to the processing pursuant to Article 21 (1) GDPR and there are no legitimate grounds for the processing (e.g. statutory retention periods), or you object to the processing pursuant to Article 21 (2) GDPR.
  • The personal data was processed unlawfully.
  • The deletion of the personal data is required to fulfill a legal obligation under applicable union or national law.
  • The personal data was collected in relation to information society services which were offered pursuant to Article 8 (1) GDPR.

Where we have made personal information public and are required to delete it, we will implement appropriate measures – taking into account the available technology and implementation costs, including technical measures – to inform the respective data controllers processing your personal data that you have requested the deletion of any links to – or copies or replications of – said personal data.

3.4 Right to restrict processing

You have the right to ask us to restrict the processing of your personal data if one of the following conditions applies:

  • The accuracy of your personal data is contested by you for a period of time that enables us to verify its accuracy.
  • The processing is unlawful and you have objected to the deletion of your personal data and have instead requested the restriction of its use.
  • The personal data is no longer needed for the stated purposes; however you need access to the data in order to assert, exercise or defend against legal claims.
  • You have objected to the processing pursuant to Article 21 (1) GDPR, provided that it has not been established that the legitimate reasons of our company outweigh your interests.

3.5 Right of data portability

You have the right to receive the personal data you have submitted to us in a structured, common and machine-readable format, and you have the right to transfer that information to another person without hindrance, provided that

  • the processing is based on consent pursuant to Article 6 (1) (a) GDPR or Article 9 (2) (a) GDPR, or on a contract in accordance with Article 6 (1) (b) GDPR; and
  • the processing is carried out using automated procedures.

In exercising your right to data portability pursuant to paragraph 1, you have the right to arrange for the personal data to be transmitted by us directly to another data controller, insofar as this is technically feasible.

3.6 Right of objection

You have the right, for reasons related to your personal situation, to object at any time to the processing of your personal data pursuant to the first sentence of Article 6 (1) (e) or (f) GDPR; this also applies to profiling based on these provisions. If you object, we will not process your personal data unless we can demonstrate compelling legitimate grounds for the processing that outweigh your interests, rights and freedoms, or if the processing serves the purpose of enforcing, pursuing or defending against legal claims.

If your personal data is processed by us for the purpose of direct advertising, you have the right to object at any time to the processing of personal data concerning you for the purpose of such advertising; this also applies to profiling, to the extent that it is associated with such direct advertising.

3.7 Right to revoke your consent with regard to data protection

You have the right to revoke your consent to the processing of your personal data at any time.

3.8 Right of appeal to a supervisory authority

Should you believe the processing of your personal data to be unlawful, you have the right to appeal to a supervisory authority, in particular in the Member State of your place of residence, your place of work or the place of the alleged breach, in accordance with Article 77 GDPR.

A list of the supervisory authorities (for the non-public area) with addresses can be found at: https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html

4 Privacy relating to applications

On our website, we offer you the opportunity to conveniently apply for a listed vacancy via a specially provided or linked portal. We use the application platform provided by softgarden e-recruiting GmbH, Tauentzienstrasse 14, 10789 Berlin.

Further privacy information about the softgarden portal is available via the following link: https://wsw-software.softgarden.io/de/data-security.

5. Data security

We endeavor to implement all technical and organizational security measures that are necessary to protect your personal data against unauthorized access and misuse at all times. We only process your personal data if we are able to do so in accordance with the applicable data protection legislation.

If personal data is stored or processed, the associated activities are carried out exclusively by certified data center operators (see "Hosting"). To ensure the security of your data during transmission, we use encryption technologies (such as SSL) over HTTPS. Our servers are protected by firewalls and antivirus software. Furthermore, back-up and recovery procedures as well as role and authorization concepts are a matter of course for us.

Our employees are obliged to observe the regulations of the GDPR and the German Federal Data Protection Act (BDSG) when handling data.

6. Automatic decision-making

We do not conduct automated decision-making on the basis of the personal data we collect.

7. Transfer of data to third parties, no data transfer to non-EU/EEA countries

In principle, we use your personal data exclusively within our company.

If and to the extent that we engage third parties for the performance of contracts, they only receive transmitted personal data within the scope necessary to perform the corresponding service.

In the event that we outsource certain parts of the data processing ("order processing"), we contractually obligate our processors to use the personal data exclusively in accordance with the applicable data protection legislation and to ensure the protection of the data subject's rights.

Apart from the cases specified in this Privacy Policy, no data is transmitted to bodies or persons outside the EU; neither is such a transfer planned.

8. Collection of personal data when using WSW products

In principle, you can visit our website without submitting any personal information. When you register to access our personalized member's area (customer login), our support staff will ask you to submit personal information, such as your name and e-mail address. All data and information relating to your identity will be stored on the server of WSW and its respective contractors; however only if you explicitly provide us with this information. This process is made visible to you and requires your explicit consent.

9. Changes to the Privacy Policy

WSW Software GmbH reserves the right to change this Privacy Policy in order to adapt it to changes to the legislation or to changes to the service and the data processing. However, this only applies to our policy with regard to data processing. To the extent that the users' consent is required or if elements of the Privacy Policy contain provisions governing the contractual relationship with users, the changes shall only be made with the users' consent.

We request that the users of our services regularly review the contents of our Privacy Policy.

Version date: April 1, 2019 / Version 1.0