At WSW Software GmbH, privacy and data security are among our most important principles. WSW Software GmbH attaches great importance to the protection of your privacy and complies with all applicable data protection legislation. In the following, we explain how we process your personal data.
The data controller with responsibility for the collection, processing and use of your personal data within the meaning of the GDPR is:
WSW Software Gesellschaft mit beschränkter Haftung
Phone: +49 (0) 89 89 50 89-0
Fax: +49 (0) 89 89 50 89-190
CEO: Klaus Müer
Phone: +49 (0) 89 89 50 89-160
Insofar as we obtain the data subject's consent to process their personal data, Article 6 (1) (a) of the General Data Protection Regulation (GDPR) provides the legal basis.
We process your personal data for the purposes of the contract, whereby Article 6 (1) (b) GDPR provides the legal basis. This also applies to processing operations carried out for the purpose of implementing pre-contractual measures.
To the extent that it is necessary to process personal data in order to fulfill a legal obligation on the part of our company, Article 6 (1) (c) GDPR provides the legal basis.
Where the processing is necessary to safeguard the legitimate interests of our company, and provided that the interests, fundamental rights and freedoms of the data subject do not outweigh the former interests, then Article 6 (1) (f) GDPR provides the legal basis for the processing. Our interests in the processing include, in particular, ensuring the operation and security of the website, analyzing the usage of the website by visitors and simplifying the use of the website.
Types of processed data:
The data subjects are the visitors to – and users of – our online services. In the following, we also refer to the data subjects as "users."
Purpose of the processing
"Personal data" means any information relating to an identified or identifiable natural person (hereinafter "data subject"). A natural person is considered to be identifiable if they can be identified directly or indirectly, in particular by association with an identifier such as a name, identification number, location data, an online identifier (e.g., a cookie) or by means of one or more unique features which express the physical, physiological, genetic, psychological, economic, cultural or social identity of said natural person.
"Processing" means any process performed with or without the aid of automated procedures or any such process associated with personal data. This term covers a wide range of activities and covers virtually every type of interaction with data.
The "data controller" refers to the natural or legal person, public authority, institution or body which, either alone or in concert with others, decides on the purposes and means of the processing of personal data.
We have leased data centers for the purpose of providing and operating this website. These data centers possess various certifications, including ISO 27001.
The hosting services we use serve to provide the following services: infrastructure and platform services, computing capacity, disk space and database services, collateral and technical maintenance services, which we use to operate this online service.
In doing so, we (or our hosting provider) process the inventory data, contact data, content data, contract data, usage data, meta and communication data submitted by customers, interested parties and visitors to this website on the basis of our legitimate interest in making this online offer available in an efficient and secure manner in accordance with Article 6 (1) (f) GDPR in conjunction with Article 28 GDPR (conclusion of an order processing contract).
The data centers are located in the European Union. To the extent that personal data of EU citizens is stored in data centers outside the European Union, we only transfer data to a third country if an adequacy decision pursuant to Article 45 GDPR or appropriate safeguards pursuant to Article 46 GDPR are in place. As a rule, we achieve appropriate safeguards under Article 46 of the GDPR and an adequate level of data protection by concluding the Standard Contractual Clauses (SCC) issued by the European Commission with the receiving entity.
Unless specifically stated, we store personal data only for as long as necessary to fulfill the stated purpose.
If you wish to prevent additional cookies from being accepted by your browser, or to be notified when you receive new cookies, or if you wish to disable all cookies, please access the help function via your web browser's menu bar. You can disable or delete Flash cookies or similar features that are used by certain browser add-ons either by changing the settings of the respective browser add-on or by following the instructions on disabling them provided on the manufacturer's website.
In order to ensure that fonts are displayed consistently, this site uses so-called "web fonts" provided by MyFonts Inc., 600 Unicorn Park Drive, Woburn, MA 01801, United States. Whenever you access a web page, your browser loads the required web fonts into your browser cache in order to correctly display text and fonts.
In order to do this, the browser you are using must connect to the MyFonts servers. During this process, MyFonts is able to determine that our website was accessed from your IP address. Our use of MyFonts corresponds to our interest in ensuring of a consistent and attractive presentation of our online services. This constitutes a legitimate interest within the meaning of Art. 6 (1) (f) GDPR. If your browser does not support web fonts, a default font will be used by your computer.
Further information about MyFonts is available at:
WSW collects information about you when you use this website. We automatically collect information about your usage behavior and interactions with us, and record information about your computer or mobile device. We collect, store and use data each time you access our online service (so-called "server log files"). This access data includes the name and URL of the retrieved file, the date and time of the retrieval, the quantity of data transferred, a notification of successful retrieval, the browser type and version, the operating system, the referrer URL (i.e. the previously visited page), the IP address, and the requesting provider.
We do not use this log data to identify you or for other profiling purposes, and instead use it for statistical analysis for the purpose of operation, security and optimization of our online services, and also to anonymously determine the number of visitors to our website (traffic) as well as the extent and nature of your use of our website and services. This information enables us to analyze traffic, find and fix bugs, and improve our services. We reserve the right to check the log data retrospectively in cases where we have legitimate grounds to suspect unlawful use of our services on the basis of concrete evidence. We store IP addresses in the log files for a limited period and to the extent necessary for security purposes or for the provision of services or the billing of a service. We also store IP addresses if we have compelling reasons to suspect criminal activity in connection with the use of our website. We also save the date of your last visit (e.g., when registering, logging in, clicking links, etc.) as part of your account data.
The legal basis for this data processing is provided by Article 6 (1) (1) (f) GDPR. Our legitimate interest follows from the data collection purposes listed above.
Processing purposes and legal bases
We enable you to contact us in an uncomplicated manner by means of a general e-mail address as well as a contact form. In doing so, the data you provide or enter will be stored for the purpose of individual communication, such as processing your inquiry. We thus ensure that an exchange with you as well as the processing of further inquiries always takes place in a timely manner.
By entering your data in our contact form, you consent to the processing of this data. The consent constitutes the legal basis for the processing in accordance with Article 6(1)(a) of the GDPR.
If you contact us to request a quote, the data entered in the contact form will be processed to carry out pre-contractual measures pursuant to Article 6(1)(b) GDPR.
Recipient of the Data
Our website is maintained by a service provider who acts on our behalf as a commissioned processor.
If you send us an inquiry about an offer, the service providers we use may received data for this purpose, provided they require these data to fulfill their respective service. All service providers are contractually obligated to treat your data in confidence.
Data will be deleted no later than 6 months after the inquiry has been processed.
If a contractual relationship arises, we are legally bound to keep the data on file for up to ten years.
Necessity of Provision
The provision of personal data is not required by law or contractual agreement. However without it, the inquiry cannot be processed.
Information regarding your right of revocation can be found in Point 3.6 of this data privacy statement.
On our website, we use the service "SALESmanago" of BENHAUER Sp. z o.o. 21 Grzegórzecka St. 31-532 Krakow, Poland.
This service stores text files (cookies) locally on your terminal device in order to enable recognition when you visit our website again. With this recognition possibility, we create - initially pseudonymous - user profiles in order to be able to provide you with personalized advertising.
This initially pseudonymous usage profile will not be merged with your personal data without your express consent. Insofar as such aggregation takes place, this is based on the legal basis of consent previously given by you pursuant to Article 6(1)a GDPR. In this case, your user profile can be merged with the following, possibly personal data and used:
Furthermore, you can subscribe to our newsletter, which is also sent via SALESmanago, on the basis of your consent pursuant to Article 6(1)a GDPR. The only information required for sending the newsletter is your e-mail address. The provision of further, separately marked data is voluntary and will be used to address you personally.
For the registration to our newsletter we use the "double opt-in" procedure. Thus, after your registration, we will send you an e-mail to the specified e-mail address, in which we ask you to confirm that you wish to receive the newsletter. After your confirmation, we will store the data you provide for the purpose of sending you the newsletter. If you do not confirm your registration, your information will be automatically deleted. In addition, we will store your IP address and the time of registration and confirmation in order to prove your registration and, if necessary, to clarify a possible misuse of your personal data.
Furthermore, this service evaluates on our behalf whether you open the newsletter and which links you click on. This information is provided to us in aggregated form by the service provider so that we can determine whether the contents of our newsletter are of interest to you as a recipient and whether we can improve our newsletter if necessary. The legal basis for this processing is Article 6(1)f of the GDPR.
For the purpose of sending the newsletter, the data will only be used until your consent is revoked. Any collection, processing or use of personal data in connection with SALESmanago takes place within the territory of the European Union. There is no obligation on the part of the visitor to provide personal data in the context of the processes described above, and a refusal to do so will not have any detrimental effects.
You can revoke your consent to receive the newsletter and unsubscribe at any time. You can declare revocation of consent by clicking on the link provided in every newsletter e-mail, by sending an e-mail to firstname.lastname@example.org, or by sending a message to the contact details given in the imprint.
By registering, you are confirming that you agree to our data privacy conditions in relation to events.
The personal data you share on the event registration form and at event registrations will be used for the purposes of event registration and organization. We will only share your personal data with third parties if this is required for the organization of the event you are attending. The information requested is essential for your participation. Consent is given voluntarily and without prejudice to the right of revocation, with effect for the future, unless there are legal grounds to the contrary. Failure to provide consent, however, may mean that participation in the event in question will not be possible.
By registering, you declare that you consent to any image or sound recordings that may be made during the event being used as part of public relations activities. Photographs taken at an event may subsequently be published in printed products, on the WSW website and within its employee network. They will not be passed directly by WSW to third parties for other purposes. That said, however, we must point out that the photographs are freely available to view worldwide once published on the Internet. The reuse of these photographs by third parties therefore cannot be completely excluded. The declaration of consent applies from the date of registration up to the point at which you leave the event. This declaration of consent can be revoked at any time with effect for the future. Revocation means that any published photographs will be removed from the WSW website and no further photographs will be uploaded. The deletion of images from the website may take a few working days to complete following receipt of your revocation. If a group photograph is published, any later revocation by one individual will not generally lead to the imaging having to be removed.
The following data is processed via the Matomo tool in self-hosting for the purpose of reach analysis:
Each user's IP address is anonymized before it is saved.
Logs containing user data will be deleted after 13 months at the latest.
If we request consent via our privacy settings, the legal basis of this processing is article 6 para 1 (a) GDPR. Otherwise, the users' personal data will be processed on the basis of our legitimate interest (i.e. our interest in the analysis, optimization and operation of our online services within the meaning of Article 6 (1) (f) GDPR).
Google Analytics is a web analysis service. It collects usage data from our websites and enables us to generate reports on website activity and thus improve the website. The information generated by the service about your use of this website is usually transmitted to a Google server in the USA and stored there. However, due to IP anonymization on this website, your IP address will be anonymized beforehand by Google within member states of the European Union or the EEA. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there.
Google Ireland Limited, Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland
Data Processing Purposes
This list represents the purposes of data collection and processing.
This list contains all the technologies that this service uses to collect data. Typical technologies are cookies and pixels placed in the browser.
This list contains all (personal) data collected during or through the use of the Service.
The following is the required legal basis for the processing of data
Article 6 paragraph 1 sentence 1 letter a) DSGVO
This is the primary location where the collected data is processed. If the data is also processed in other countries, you will be informed separately.
The storage duration is the period of time during which the collected data is stored for processing. The data must be deleted as soon as it is no longer needed for the specified processing purposes.
The data collected with Google Analytics is stored for a period of 14 months.
Transfer to Third Countries
Transfer to Third Countries
This service may transfer the collected data to another country. Please note that this service may transfer data outside the European Union and the EEA and to a country that does not provide an adequate level of data protection. If the data is transferred to the U.S., there is a risk that your data may be processed by U.S. authorities for control and monitoring purposes, without you possibly having any legal remedies. Below is a list of countries to which the data will be transferred. This may be for various purposes, such as storage or processing.
The following is a list of the recipients of the data collected.
You can also prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) to Google and the processing of this data by Google by
This website uses Mouseflow, a web analytics tool from Mouseflow ApS, Flaesketorvet 68, 1711 Copenhagen, Denmark, to record randomly selected individual visits (with anonymized IP address only).
This creates a log of mouse movements and clicks with the intention of randomly sampling individual website visits and deriving potential improvements for the website.
The information is not personal and will not be shared. If you do not want a recording, you can deactivate this in the privacy settings.
We maintain an online presence within social networks and platforms in order to communicate with customers, interested parties and users there, and to inform them about our services. When you access the respective networks and platforms, the terms and conditions and the data processing policies of the respective operators apply.
Integration of third-party services and content
On the basis of our legitimate interest (i.e. our interest in the analysis, optimization and economic operation of our online services within the meaning of Article 6 (1) (f) GDPR), we include content and services offered by third parties within our online services, e.g., for the purpose of integrating videos and/or fonts (collectively referred to as "content").
This always requires the user's IP address to be shared with the respective third-party providers, since they require the user's IP address in order to send the content to their browser. The user's IP address is therefore required for the presentation of this content. We endeavor only to use content whose respective providers will use the IP address exclusively for the purpose of delivering the respective content. Third parties may also use so-called "pixel tags" (invisible graphics, also referred to as "web beacons") for statistical or marketing purposes. These "pixel tags" can be used to evaluate specific information, such as visitor traffic on the pages of this website. This pseudonymous information may also be stored in cookies on the user's device and may include, but is not limited to, technical information about the respective browser and operating system, the referring web pages, the time of the visit, as well as other information regarding the use of our online services.
Within our online presence, functions and content may be integrated from the Facebook service, provided by Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. This may include, for example, content such as images, videos, or text and buttons that allow users to share content from our online services within Facebook. If the users are members of the Facebook platform, Facebook is able to link their use of the aforementioned content and functions to their user profiles.
Facebook: Social network; service provider: Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, parent company: Facebook, 1 Hacker Way, Menlo Park, CA 94025, USA; Website: https://www.facebook.com;
Additional information on data protection: Agreement regarding the shared processing of personal data on Facebook pages: https://www.facebook.com/legal/terms/page_controller_addendum
Data privacy information for Facebook pages: https://www.facebook.com/legal/terms/information_about_page_insights_data.
If you do not wish Facebook to be able to associate your visit to our website with your user account, please log out of your Facebook user account first.
Measurement of User Interaction with our Fanpage
At https://www.facebook.com/wswsoftware/ we use a Facebook Fanpage. Facebook provides us with insights regarding these fanpages. Page insights contain collated data that tell us how users are interacting with our fanpage. The page insights can be based on personal data which has been captured in relation to a visit or an interaction between people on or with our fanpage and its content. Together with Facebook Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland (“Facebook Ireland”), we are jointly responsible under the terms of Art. 26 GDPR, for the processing of insights data and have signed an agreement with Facebook Ireland in this regard. You can find this at https://www.facebook.com/legal/terms/page_controller_addendum. The legal basis for our use of the Facebook Fanpage and page insights is a justified interest as defined in Article 6 (1) f of the GDPR, namely in relation to the fanpage the use of Facebook as a channel for information regarding our company and in relation to the Insights pages the better understanding of the interests of visitors to our fanpage in order to be able to address these interests in a targeted manner.
The "XING share button" is used on this website. When this button is activated, a short-term connection is established via your browser to the servers of XING SE ("XING"), which provide the "XING share button" functions (in particular, the calculation/display of the counter value). XING does not store any personal data about you when this website is accessed. In particular, XING does not store any IP addresses. In addition, no evaluation of your usage behavior takes place via the cookies used in connection with the "XING share button." The current data protection information regarding the "XING share button", as well as supplementary information, can be found on this website:
On our web pages, we use the plugin provided by the XING social network in the form of the "XING share button" and the "Kununu" service. Kununu is an application provided via the XING service. When you visit our web pages, a short-term connection is established by your browser to the servers of XING SE ("XING"), which provide the "XING share button" functions (in particular the calculation/display of the counter value).
If you do not want kununu to be able to associate your visit to our website with your user account, please log out of your kununu user account before accessing the respective content.
Our online services may include integrated functions and content provided by the LinkedIn service (LinkedIn Ireland Unlimited Company Wilton Place, Dublin 2, Ireland). This may include, for example, content such as images, videos, or text and buttons that allow users to share content from our online services within LinkedIn. If the users are members of the LinkedIn platform, LinkedIn is able to link their use of the aforementioned content and functions to their user profiles.
We integrate the videos of the platform "YouTube" of the provider Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Please note that you are not obligated to use Microsoft Bookings to schedule an appointment. If you do not wish to use the service, please use another of the contact options provided to make an appointment.
The processing of the data you enter in the online form is based exclusively on your consent pursuant to Article 6(1)a GDPR. You can revoke this consent at any time. An informal message sent to us by e-mail is sufficient to do so. Revocation of consent shall not affect the legality of the data processing operations carried out until the time of revocation. The data you enter in the online form will remain with us until you request us to delete it, revoke your consent to store it, or the purpose for storing the data no longer applies (e.g. after we have completed processing your request). Mandatory legal provisions - in particular retention periods - remain unaffected.
Your personal data with regard to the use of the appointment booking option via Microsoft Bookings will not be transferred by us to third countries outside the EU or the European Economic Area. To the best of our knowledge, based on the information available from Microsoft, Microsoft does not transfer personal data to third parties. We have concluded the necessary data protection agreements with Microsoft.
We use the GoToWebinar platform of LogMeIn Ireland Ltd, The Reflector, 10 Hanover Quay, Dublin 2, Ireland as a third-party provider to conduct webinars. The third party provider has self-certified for the EU-US and Swiss-US Privacy Shield with respect to customer data. For more information on how the third party provider handles your data, please visit https://www.logmeininc.com/de/legal/privacy and at https://www.logmeininc.com/de/legal/privacy-shield.
We always observe the legal regulations when selecting third party suppliers and their services.
In the context of our offer, communication participant data is processed and stored on the third party supplier’s servers, provided it is part of the communication processes with us. This data may in particular include registration and contact data, visual and verbal contributions as well as entries in chats and shared screen content.
If users are referred to a third party provider or their software or platforms as part of communication, business or other relations with us, third party providers may process usage data and metadata for security, service optimization or marketing purposes. We therefore ask you to observe the data protection information of the respective third-party providers (see above).
Information about the legal bases:
We use the Microsoft Teams platform from the Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA (hereinafter referred to as “third party supplier”) to carry out video conferences. We observe the legal regulations when selecting third party suppliers and their services.
In this context, communication participant data is processed and stored on the third party supplier’s servers, provided it is part of the communication processes with us. This data may in particular include registration and contact data, visual and verbal contributions as well as entries in chats and shared screen content.
If users are referred to a third party provider or its software or platform as part of communication, business or other relations with us, the third party provider may process usage data and metadata for security, service optimization or marketing purposes. We therefore ask you to observe the third party provider’s data protection notice https://privacy.microsoft.com/de-de/privacystatement
We only process personal data that the applicant provides us or that we receive in a permissible manner as part of the application process. At least the following personal data of the applicant is needed for the use of teams:
As part of the use, teams may process additional personal data. This depends on the settings selected and the content and functions used as part of the utilization. In this respect, the text entries from the applicant are processed in order to display them in the video conference or to log them. To display video and audio, data from the applicant’s end device microphone as well as from any video camera of the end device is processed according to the duration of the conference. Note: You can always switch off or mute the camera or microphone using the teams applications.
Under the applicable laws, you have various rights regarding your personal data. If you wish to assert these rights, please send us your request by post or e-mail, clearly identifying yourself and using the contact details listed under points 1 and 1.1. As a data subject you have the following rights.
You have the right to request information about your personal data that is processed by us. In particular, you may request information about the purposes of the processing, the category of personal data, the categories of recipients to whom your data has been disclosed, the planned retention period, your right of rectification, deletion, restriction of or objection to the processing, your right of appeal, the source of your data if it was not collected from us, and the existence of automated decision-making, including profiling, and if applicable, detailed information about this.
You have the right to demand the immediate rectification of any incorrect personal data concerning you. In light of the stated purposes, you have the right to request the completion of any incomplete personal data concerning you, including by means of a supplementary statement.
You have the right to ask us to delete your personal data without delay. Furthermore, we are obliged to delete your personal data immediately if one of the following reasons applies:
Where we have made personal information public and are required to delete it, we will implement appropriate measures – taking into account the available technology and implementation costs, including technical measures – to inform the respective data controllers processing your personal data that you have requested the deletion of any links to – or copies or replications of – said personal data.
You have the right to ask us to restrict the processing of your personal data if one of the following conditions applies:
You have the right to receive the personal data relating to you that you have provided to us in a structured, commonly used and machine-readable format, and you have the right to transfer that data to another controller without hindrance from us, provided that
In exercising your right to data portability pursuant to paragraph 1, you have the right to arrange for the personal data to be transmitted by us directly to another data controller, insofar as this is technically feasible.
You have the right, for reasons related to your personal situation, to object at any time to the processing of your personal data pursuant to the first sentence of Article 6 (1) (e) or (f) GDPR; this also applies to profiling based on these provisions. If you object, we will not process your personal data unless we can demonstrate compelling legitimate grounds for the processing that outweigh your interests, rights and freedoms, or if the processing serves the purpose of enforcing, pursuing or defending against legal claims.
If your personal data is processed by us for the purpose of direct advertising, you have the right to object at any time to the processing of personal data concerning you for the purpose of such advertising; this also applies to profiling, to the extent that it is associated with such direct advertising.
You have the right to revoke your consent to the processing of your personal data at any time.
Should you believe the processing of your personal data to be unlawful, you have the right to appeal to a supervisory authority, in particular in the Member State of your place of residence, your place of work or the place of the alleged breach, in accordance with Article 77 GDPR.
A list of the supervisory authorities (for the non-public area) with addresses can be found at: https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html
On our website, we offer you the opportunity to conveniently apply for a listed vacancy via a specially provided or linked portal. We use the application platform provided by softgarden e-recruiting GmbH, Tauentzienstrasse 14, 10789 Berlin.
As part of your application process, documents uploaded by you are processed and analyzed to extract CV data and convert it into a structured form (so-called "CV parsing"). To ensure data subject rights and security standards, an order processing contract was concluded with the service provider. The processor is the ISO27001 certified provider Textkernel B.V. Nieuwendammerkade 26 A 5, (1022AB) Amsterdam, The Netherlands. The data processing takes place within the EU on servers in the Netherlands and Germany.
The legal basis for the processing is § 26 para. 1 sentence 1 Federal Data Protection Act as well as Article 6 para. 1 sentence 1 (f) GDPR , in order to initiate an employment relationship and to make the application process efficient for you. Personal data is not transferred to third countries. Your data will be routinely deleted in accordance with the relevant retention periods.
Further privacy information about the softgarden portal is available via the following link: https://wsw-software.softgarden.io/de/data-security.
We endeavor to implement all technical and organizational security measures that are necessary to protect your personal data against unauthorized access and misuse at all times. We only process your personal data if we are able to do so in accordance with the applicable data protection legislation.
If personal data is stored or processed, the associated activities are carried out exclusively by certified data center operators (see "Hosting"). To ensure the security of your data during transmission, we use encryption technologies (such as SSL) over HTTPS. Our servers are protected by firewalls and antivirus software. Furthermore, back-up and recovery procedures as well as role and authorization concepts are a matter of course for us.
Our employees are obliged to observe the regulations of the GDPR and the German Federal Data Protection Act (BDSG) when handling data.
We do not conduct automated decision-making on the basis of the personal data we collect.
In principle, we use your personal data exclusively within our company.
If and to the extent that we engage third parties for the performance of contracts, they only receive transmitted personal data within the scope necessary to perform the corresponding service.
In the event that we outsource certain parts of the data processing ("order processing"), we contractually obligate our processors to use the personal data exclusively in accordance with the applicable data protection legislation and to ensure the protection of the data subject's rights.
Version date: September 2021 / Version 6.2