At WSW Software GmbH, privacy and data security are among our most important principles. WSW Software GmbH attaches great importance to the protection of your privacy and complies with all applicable data protection legislation. In the following, we explain how we process your personal data.
The data controller with responsibility for the collection, processing and use of your personal data within the meaning of the GDPR is:
WSW Software Gesellschaft mit beschränkter Haftung
Phone: +49 (0) 89 89 50 89-0
Fax: +49 (0) 89 89 50 89-190
CEO: Klaus Müer
Phone: +49 (0) 89 89 50 89-160
Insofar as we obtain the data subject's consent to process their personal data, Article 6 (1) (a) of the General Data Protection Regulation (GDPR) provides the legal basis.
We process your personal data for the purposes of the contract, whereby Article 6 (1) (b) GDPR provides the legal basis. This also applies to processing operations carried out for the purpose of implementing pre-contractual measures.
To the extent that it is necessary to process personal data in order to fulfill a legal obligation on the part of our company, Article 6 (1) (c) GDPR provides the legal basis.
In the event that vital interests of the data subject or any other natural person require the processing of personal data, Article 6 (1) (d) GDPR provides the legal basis.
Where the processing is necessary to safeguard the legitimate interests of our company, and provided that the interests, fundamental rights and freedoms of the data subject do not outweigh the former interests, then Article 6 (1) (f) GDPR provides the legal basis for the processing. Our interests in the processing include, in particular, ensuring the operation and security of the website, analyzing the usage of the website by visitors and simplifying the use of the website.
Types of processed data:
The data subjects are the visitors to – and users of – our online services. In the following, we also refer to the data subjects as "users."
Purpose of the processing
"Personal data" means any information relating to an identified or identifiable natural person (hereinafter "data subject"). A natural person is considered to be identifiable if they can be identified directly or indirectly, in particular by association with an identifier such as a name, identification number, location data, an online identifier (e.g., a cookie) or by means of one or more unique features which express the physical, physiological, genetic, psychological, economic, cultural or social identity of said natural person.
"Processing" means any process performed with or without the aid of automated procedures or any such process associated with personal data. This term covers a wide range of activities and covers virtually every type of interaction with data.
The "data controller" refers to the natural or legal person, public authority, institution or body which, either alone or in concert with others, decides on the purposes and means of the processing of personal data.
We have leased data centers for the purpose of providing and operating this website. These data centers possess various certifications, including ISO 27001.
The hosting services we use serve to provide the following services: infrastructure and platform services, computing capacity, disk space and database services, collateral and technical maintenance services, which we use to operate this online service.
In doing so, we (or our hosting provider) process the inventory data, contact data, content data, contract data, usage data, meta and communication data submitted by customers, interested parties and visitors to this website on the basis of our legitimate interest in making this online offer available in an efficient and secure manner in accordance with Article 6 (1) (f) GDPR in conjunction with Article 28 GDPR (conclusion of an order processing contract).
The data centers are located in the European Union. To the extent that personal data of EU citizens is stored in data centers outside the European Union, the respective data centers have established an equivalent level of protection via standard contractual clauses.
Unless specifically stated, we store personal data only for as long as necessary to fulfill the stated purpose.
If you wish to prevent additional cookies from being accepted by your browser, or to be notified when you receive new cookies, or if you wish to disable all cookies, please access the help function via your web browser's menu bar. You can disable or delete Flash cookies or similar features that are used by certain browser add-ons either by changing the settings of the respective browser add-on or by following the instructions on disabling them provided on the manufacturer's website.
In order to ensure that fonts are displayed consistently, this site uses so-called "web fonts" provided by MyFonts Inc., 600 Unicorn Park Drive, Woburn, MA 01801, United States. Whenever you access a web page, your browser loads the required web fonts into your browser cache in order to correctly display text and fonts.
In order to do this, the browser you are using must connect to the MyFonts servers. During this process, MyFonts is able to determine that our website was accessed from your IP address. Our use of MyFonts corresponds to our interest in ensuring of a consistent and attractive presentation of our online services. This constitutes a legitimate interest within the meaning of Art. 6 (1) (f) GDPR. If your browser does not support web fonts, a default font will be used by your computer.
Further information about MyFonts is available at:
WSW collects information about you when you use this website. We automatically collect information about your usage behavior and interactions with us, and record information about your computer or mobile device. We collect, store and use data each time you access our online service (so-called "server log files"). This access data includes the name and URL of the retrieved file, the date and time of the retrieval, the quantity of data transferred, a notification of successful retrieval, the browser type and version, the operating system, the referrer URL (i.e. the previously visited page), the IP address, and the requesting provider.
We do not use this log data to identify you or for other profiling purposes, and instead use it for statistical analysis for the purpose of operation, security and optimization of our online services, and also to anonymously determine the number of visitors to our website (traffic) as well as the extent and nature of your use of our website and services. This information enables us to analyze traffic, find and fix bugs, and improve our services. We reserve the right to check the log data retrospectively in cases where we have legitimate grounds to suspect unlawful use of our services on the basis of concrete evidence. We store IP addresses in the log files for a limited period and to the extent necessary for security purposes or for the provision of services or the billing of a service. We also store IP addresses if we have compelling reasons to suspect criminal activity in connection with the use of our website. We also save the date of your last visit (e.g., when registering, logging in, clicking links, etc.) as part of your account data.
The legal basis for this data processing is provided by Article 6 (1) (1) (f) GDPR. Our legitimate interest follows from the data collection purposes listed above.
Purpose, Legal Basis, and Justified Interest
The data you enter will be saved for the purpose of establishing personalized communication with you. Through the provision of a contact form, we make it easy for you to contact us. The information you provide will be saved for the purpose of processing your inquiry and for possible follow-up inquiries. The data entered into the contact form are processed on the basis of a justified interest according to Article 6 (1) f of the GDPR.
If you get in touch with us to inquire about an offer, the data entered into the contact form will be processed for the implementation of pre-contractual measures as defined in Article 6 (1) b of the GDPR.
Recipient of the Data
Our website is maintained by a service provider who acts on our behalf as a commissioned processor.
If you send us an inquiry about an offer, the service providers we use may received data for this purpose, provided they require these data to fulfill their respective service. All service providers are contractually obligated to treat your data in confidence.
Data will be deleted no later than 6 months after the inquiry has been processed.
If a contractual relationship arises, we are legally bound to keep the data on file for up to ten years.
Necessity of Provision
The provision of personal data is not required by law or contractual agreement. However without it, the inquiry cannot be processed.
Information regarding your right of revocation can be found in Point 3.6 of this data privacy statement.
On our website, we use the service "SALESmanago" of BENHAUER Sp. z o.o. 21 Grzegórzecka St. 31-532 Krakow, Poland.
This service stores text files (cookies) locally on your terminal device in order to enable recognition when you visit our website again. With this recognition possibility, we create - initially pseudonymous - user profiles in order to be able to provide you with personalized advertising.
This initially pseudonymous usage profile will not be merged with your personal data without your express consent. Insofar as such aggregation takes place, this is based on the legal basis of consent previously given by you pursuant to Article 6(1)(a) GDPR. In this case, your user profile can be merged with the following, possibly personal data and used:
Furthermore, this service evaluates on our behalf whether you open the newsletter and which links you click on. This information is provided to us in aggregated form by the service provider so that we can determine whether the contents of our newsletter are of interest to you as a recipient and whether we can improve our newsletter if necessary. The legal basis for this processing is Article 6 (1) f of the GDPR.
For the above-mentioned purpose, the data will only be used until the consent is revoked. Any collection, processing or use of personal data in connection with SALESmanago takes place within the territory of the European Union. There is no obligation on the part of the visitor to provide personal data in the context of the processes described above, and a refusal to do so will not have any detrimental effects.
By registering, you are confirming that you agree to our data privacy conditions in relation to events.
The personal data you share on the event registration form and at event registrations will be used for the purposes of event registration and organization. We will only share your personal data with third parties if this is required for the organization of the event you are attending. The information requested is essential for your participation. Consent is given voluntarily and without prejudice to the right of revocation, with effect for the future, unless there are legal grounds to the contrary. Failure to provide consent, however, may mean that participation in the event in question will not be possible.
By registering, you declare that you consent to any image or sound recordings that may be made during the event being used as part of public relations activities. Photographs taken at an event may subsequently be published in printed products, on the WSW website and within its employee network. They will not be passed directly by WSW to third parties for other purposes. That said, however, we must point out that the photographs are freely available to view worldwide once published on the Internet. The reuse of these photographs by third parties therefore cannot be completely excluded. The declaration of consent applies from the date of registration up to the point at which you leave the event. This declaration of consent can be revoked at any time with effect for the future. Revocation means that any published photographs will be removed from the WSW website and no further photographs will be uploaded. The deletion of images from the website may take a few working days to complete following receipt of your revocation. If a group photograph is published, any later revocation by one individual will not generally lead to the imaging having to be removed.
The following data is processed via the Matomo tool in self-hosting for the purpose of reach analysis:
Each user's IP address is anonymized before it is saved.
Logs containing user data will be deleted after 13 months at the latest.
If we request consent via our privacy settings, the legal basis of this processing is article 6 para 1 (a) GDPR. Otherwise, the users' personal data will be processed on the basis of our legitimate interest (i.e. our interest in the analysis, optimization and operation of our online services within the meaning of Article 6 (1) (f) GDPR).
This website uses Mouseflow, a web analytics tool from Mouseflow ApS, Flaesketorvet 68, 1711 Copenhagen, Denmark, to record randomly selected individual visits (with anonymized IP address only).
This creates a log of mouse movements and clicks with the intention of randomly sampling individual website visits and deriving potential improvements for the website.
The information is not personal and will not be shared. If you do not want a recording, you can deactivate this in the privacy settings.
We maintain an online presence within social networks and platforms in order to communicate with customers, interested parties and users there, and to inform them about our services. When you access the respective networks and platforms, the terms and conditions and the data processing policies of the respective operators apply.
Integration of third-party services and content
On the basis of our legitimate interest (i.e. our interest in the analysis, optimization and economic operation of our online services within the meaning of Article 6 (1) (f) GDPR), we include content and services offered by third parties within our online services, e.g., for the purpose of integrating videos and/or fonts (collectively referred to as "content").
This always requires the user's IP address to be shared with the respective third-party providers, since they require the user's IP address in order to send the content to their browser. The user's IP address is therefore required for the presentation of this content. We endeavor only to use content whose respective providers will use the IP address exclusively for the purpose of delivering the respective content. Third parties may also use so-called "pixel tags" (invisible graphics, also referred to as "web beacons") for statistical or marketing purposes. These "pixel tags" can be used to evaluate specific information, such as visitor traffic on the pages of this website. This pseudonymous information may also be stored in cookies on the user's device and may include, but is not limited to, technical information about the respective browser and operating system, the referring web pages, the time of the visit, as well as other information regarding the use of our online services.
Within our online presence, functions and content may be integrated from the Facebook service, provided by Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. This may include, for example, content such as images, videos, or text and buttons that allow users to share content from our online services within Facebook. If the users are members of the Facebook platform, Facebook is able to link their use of the aforementioned content and functions to their user profiles.
Facebook: Social network; service provider: Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, parent company: Facebook, 1 Hacker Way, Menlo Park, CA 94025, USA; Website: https://www.facebook.com;
Additional information on data protection: Agreement regarding the shared processing of personal data on Facebook pages: https://www.facebook.com/legal/terms/page_controller_addendum
Data privacy information for Facebook pages: https://www.facebook.com/legal/terms/information_about_page_insights_data.
If you do not wish Facebook to be able to associate your visit to our website with your user account, please log out of your Facebook user account first.
Measurement of User Interaction with our Fanpage
At https://www.facebook.com/wswsoftware/ we use a Facebook Fanpage. Facebook provides us with insights regarding these fanpages. Page insights contain collated data that tell us how users are interacting with our fanpage. The page insights can be based on personal data which has been captured in relation to a visit or an interaction between people on or with our fanpage and its content. Together with Facebook Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland (“Facebook Ireland”), we are jointly responsible under the terms of Art. 26 GDPR, for the processing of insights data and have signed an agreement with Facebook Ireland in this regard. You can find this at https://www.facebook.com/legal/terms/page_controller_addendum. The legal basis for our use of the Facebook Fanpage and page insights is a justified interest as defined in Article 6 (1) f of the GDPR, namely in relation to the fanpage the use of Facebook as a channel for information regarding our company and in relation to the Insights pages the better understanding of the interests of visitors to our fanpage in order to be able to address these interests in a targeted manner.
The "XING share button" is used on this website. When this button is activated, a short-term connection is established via your browser to the servers of XING SE ("XING"), which provide the "XING share button" functions (in particular, the calculation/display of the counter value). XING does not store any personal data about you when this website is accessed. In particular, XING does not store any IP addresses. In addition, no evaluation of your usage behavior takes place via the cookies used in connection with the "XING share button." The current data protection information regarding the "XING share button", as well as supplementary information, can be found on this website:
On our web pages, we use the plugin provided by the XING social network in the form of the "XING share button" and the "Kununu" service. Kununu is an application provided via the XING service. When you visit our web pages, a short-term connection is established by your browser to the servers of XING SE ("XING"), which provide the "XING share button" functions (in particular the calculation/display of the counter value).
If you do not want kununu to be able to associate your visit to our website with your user account, please log out of your kununu user account before accessing the respective content.
Our online services may include integrated functions and content provided by the LinkedIn service (LinkedIn Ireland Unlimited Company Wilton Place, Dublin 2, Ireland). This may include, for example, content such as images, videos, or text and buttons that allow users to share content from our online services within LinkedIn. If the users are members of the LinkedIn platform, LinkedIn is able to link their use of the aforementioned content and functions to their user profiles.
LinkedIn is certified under the Privacy Shield agreement, which guarantees compliance with European data protection legislation:
We integrate the videos of the platform "YouTube" of the provider Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
The distribution service provider may retrieve the recipients' data in pseudonymous form, i.e. without assigning it to a user, in order to optimize or improve its own services, e.g., for technical improvements related to the distribution, the presentation of newsletters and/or for statistical purposes. However, the distribution service provider does not use the data submitted by our newsletter recipients in order to contact them directly, nor does it share this data with third parties.
If you wish to receive the newsletter offered on our website, we require your e-mail address. To ensure that you have consented to receive our newsletter, we use a "double-opt-in" procedure, during which the potential recipient can choose to be included in a distribution list. Afterwards, the user receives a confirmation e-mail via which they can confirm their newsletter subscription in accordance with the data protection legislation. The user's e-mail address will not be included in the distribution list until we receive this confirmation. The newsletter will be sent on the basis of your consent in accordance with Article 6 (1) (a) GDPR.
The newsletters contain a so-called "web beacon", i.e. a pixel-sized file that is either retrieved from our server – or if we use a distribution service provider, from the latter's server – when you open the newsletter. As part of this retrieval process, technical information is collected, including information about your browser and system, as well as your IP address and the time of retrieval.
This information is used to improve the technical performance of the respective services based on their specifications and/or on the target audience and its reading habits on the basis of its location (which can be determined via the IP address) and/or the time of access. These statistical surveys also include a determination of whether/when the newsletters are opened and which links are clicked. For technical reasons, this information can be assigned to the individual newsletter recipients. However, neither we nor the distribution service provider (if used) endeavor to observe the behavior of individual users. The evaluations merely allow us to identify the reading habits of our users and to adapt our content to suit them, or to send them different content in line with their interests.
We use the GoToWebinar platform of LogMeIn Ireland Ltd, The Reflector, 10 Hanover Quay, Dublin 2, Ireland as a third-party provider to conduct webinars. The third party provider has self-certified for the EU-US and Swiss-US Privacy Shield with respect to customer data. For more information on how the third party provider handles your data, please visit https://www.logmeininc.com/de/legal/privacy and at https://www.logmeininc.com/de/legal/privacy-shield.
We always observe the legal regulations when selecting third party suppliers and their services.
In the context of our offer, communication participant data is processed and stored on the third party supplier’s servers, provided it is part of the communication processes with us. This data may in particular include registration and contact data, visual and verbal contributions as well as entries in chats and shared screen content.
If users are referred to a third party provider or their software or platforms as part of communication, business or other relations with us, third party providers may process usage data and metadata for security, service optimization or marketing purposes. We therefore ask you to observe the data protection information of the respective third-party providers (see above).
Information about the legal bases:
We use the Microsoft Teams platform from the Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA (hereinafter referred to as “third party supplier”) to carry out video conferences. We observe the legal regulations when selecting third party suppliers and their services.
In this context, communication participant data is processed and stored on the third party supplier’s servers, provided it is part of the communication processes with us. This data may in particular include registration and contact data, visual and verbal contributions as well as entries in chats and shared screen content.
If users are referred to a third party provider or its software or platform as part of communication, business or other relations with us, the third party provider may process usage data and metadata for security, service optimization or marketing purposes. We therefore ask you to observe the third party provider’s data protection notice https://privacy.microsoft.com/de-de/privacystatement
We only process personal data that the applicant provides us or that we receive in a permissible manner as part of the application process. At least the following personal data of the applicant is needed for the use of teams:
As part of the use, teams may process additional personal data. This depends on the settings selected and the content and functions used as part of the utilization. In this respect, the text entries from the applicant are processed in order to display them in the video conference or to log them. To display video and audio, data from the applicant’s end device microphone as well as from any video camera of the end device is processed according to the duration of the conference. Note: You can always switch off or mute the camera or microphone using the teams applications.
Under the applicable laws, you have various rights regarding your personal data. If you wish to assert these rights, please send us your request by post or e-mail, clearly identifying yourself and using the contact details listed under points 1 and 1.1. As a data subject you have the following rights.
You have the right to request information about your personal data that is processed by us. In particular, you may request information about the purposes of the processing, the category of personal data, the categories of recipients to whom your data has been disclosed, the planned retention period, your right of rectification, deletion, restriction of or objection to the processing, your right of appeal, the source of your data if it was not collected from us, and the existence of automated decision-making, including profiling, and if applicable, detailed information about this.
You have the right to demand the immediate rectification of any incorrect personal data concerning you. In light of the stated purposes, you have the right to request the completion of any incomplete personal data concerning you, including by means of a supplementary statement.
You have the right to ask us to delete your personal data without delay. Furthermore, we are obliged to delete your personal data immediately if one of the following reasons applies:
Where we have made personal information public and are required to delete it, we will implement appropriate measures – taking into account the available technology and implementation costs, including technical measures – to inform the respective data controllers processing your personal data that you have requested the deletion of any links to – or copies or replications of – said personal data.
You have the right to ask us to restrict the processing of your personal data if one of the following conditions applies:
You have the right to receive the personal data relating to you that you have provided to us in a structured, commonly used and machine-readable format, and you have the right to transfer that data to another controller without hindrance from us, provided that
In exercising your right to data portability pursuant to paragraph 1, you have the right to arrange for the personal data to be transmitted by us directly to another data controller, insofar as this is technically feasible.
You have the right, for reasons related to your personal situation, to object at any time to the processing of your personal data pursuant to the first sentence of Article 6 (1) (e) or (f) GDPR; this also applies to profiling based on these provisions. If you object, we will not process your personal data unless we can demonstrate compelling legitimate grounds for the processing that outweigh your interests, rights and freedoms, or if the processing serves the purpose of enforcing, pursuing or defending against legal claims.
If your personal data is processed by us for the purpose of direct advertising, you have the right to object at any time to the processing of personal data concerning you for the purpose of such advertising; this also applies to profiling, to the extent that it is associated with such direct advertising.
You have the right to revoke your consent to the processing of your personal data at any time.
Should you believe the processing of your personal data to be unlawful, you have the right to appeal to a supervisory authority, in particular in the Member State of your place of residence, your place of work or the place of the alleged breach, in accordance with Article 77 GDPR.
A list of the supervisory authorities (for the non-public area) with addresses can be found at: https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html
On our website, we offer you the opportunity to conveniently apply for a listed vacancy via a specially provided or linked portal. We use the application platform provided by softgarden e-recruiting GmbH, Tauentzienstrasse 14, 10789 Berlin.
As part of your application process, documents uploaded by you are processed and analyzed to extract CV data and convert it into a structured form (so-called "CV parsing"). To ensure data subject rights and security standards, an order processing contract was concluded with the service provider. The processor is the ISO27001 certified provider Textkernel B.V. Nieuwendammerkade 26 A 5, (1022AB) Amsterdam, The Netherlands. The data processing takes place within the EU on servers in the Netherlands and Germany.
The legal basis for the processing is § 26 para. 1 sentence 1 Federal Data Protection Act as well as Article 6 para. 1 sentence 1 (f) GDPR , in order to initiate an employment relationship and to make the application process efficient for you. Personal data is not transferred to third countries. Your data will be routinely deleted in accordance with the relevant retention periods.
Further privacy information about the softgarden portal is available via the following link: https://wsw-software.softgarden.io/de/data-security.
We endeavor to implement all technical and organizational security measures that are necessary to protect your personal data against unauthorized access and misuse at all times. We only process your personal data if we are able to do so in accordance with the applicable data protection legislation.
If personal data is stored or processed, the associated activities are carried out exclusively by certified data center operators (see "Hosting"). To ensure the security of your data during transmission, we use encryption technologies (such as SSL) over HTTPS. Our servers are protected by firewalls and antivirus software. Furthermore, back-up and recovery procedures as well as role and authorization concepts are a matter of course for us.
Our employees are obliged to observe the regulations of the GDPR and the German Federal Data Protection Act (BDSG) when handling data.
We do not conduct automated decision-making on the basis of the personal data we collect.
In principle, we use your personal data exclusively within our company.
If and to the extent that we engage third parties for the performance of contracts, they only receive transmitted personal data within the scope necessary to perform the corresponding service.
In the event that we outsource certain parts of the data processing ("order processing"), we contractually obligate our processors to use the personal data exclusively in accordance with the applicable data protection legislation and to ensure the protection of the data subject's rights.
In principle, you can visit our website without submitting any personal information. When you register to access our personalized member's area (customer login), our support staff will ask you to submit personal information, such as your name and e-mail address. All data and information relating to your identity will be stored on the server of WSW and its respective contractors; however only if you explicitly provide us with this information. This process is made visible to you and requires your explicit consent.
If you request a download link on our Qumbu product page for a free, 30-day trial versions, we only require your e-mail address for this.
If you request a quote for a license after the trial version expires, we will also request details of your business address as well as a contact name. All data and information relating to your identity will be stored on servers of corresponding contractual partners as well as WSW, however only if you explicitly provide us this with this information. This process is made visible to you and requires your explicit consent.
Version date: June 2021 / Version 5.0