1. Name and contact details of the controller
sovanta AG (in the following: „we“):
sovanta AG
X-House
Mittermaierstr. 31
69115 Heidelberg
Germany
Tel.: +49 (0)6221 18733-0
info@sovanta.com
You can contact our Data Protection Officer at:
sovanta AG
Data Protection Officer X-House
Mittermaierstr. 31
69115 Heidelberg
Germany
privacy@sovanta.com
2. Processing of your personal data; type of data; purposes of processing; legal basis
If you enter into a contract with us or act on behalf of a company or other organization that enters into a contract with us or if we are in contact with you because we are interested in your or your company’s services or you are interested in our services or if we are in contact with you in any other way for business purposes, we collect the following personal and company-related data as necessary:
- Salutation, first name, last name;
- E-mail address;
- Name of the company;
- Address of the company;
- Telephone number (landline and/or mobile);
- If applicable, position in the company / organization, signing authority, power of attorney;
- VAT identification number of the company;
- Information required to process the order (e.g. credit card number, order number, etc.)
- any other information required for the fulfillment of the contract.
a) Purpose of processing your data
This data is collected and processed
- to be able to identify you as our business partner or as a natural person acting on behalf of our business partner or as our contact person for our business partner;
- for correspondence with our business partner or with you;
- for invoicing;
- for the settlement of any liability claims and the assertion of any claims against you;
- for marketing purposes.
b) Legal basis of processing your data
The processing of the above-mentioned data is based on various legal basis. The processing of all data that we require for the performance of a contract to which the data subject is a contractual party or for the implementation of pre-contractual measures taken at the request of the data subject takes place on the basis of Art. 6 para. 1 sentence 1 lit. b of the General Data Protection Regulation (GDPR). The provision of contact data as well as payment data or other financial data such as tax numbers and their processing by sovanta is necessary for the fulfillment of obligations from a contract by both parties. If you are the contact person of our contractual partner, the processing of your contact data for the same purposes takes place on the basis of Art. 6 para. 1 sentence 1 lit. f GDPR, because we have a legitimate interest in a specific contact person at our contractual partner.
On the basis of Art. 6 para. 1 sentence 1 lit. f GDPR and accordingly due to our legitimate interests, the processing of information takes place for the settlement of any existing liability claims and the assertion of any claims against our contractual partner (e.g. late payment). We also have a legitimate interest in processing your data for direct marketing purposes. For marketing purposes, we use not only the postal address, but also the e-mail addresses of our contractual partners or the contact persons in their companies. However, we only use your e-mail address if we have received it from you in connection with the sale of goods or services and only for direct advertising for our own similar goods or services. In general, you can object to the processing of your data for direct marketing purposes. To do so, please use the contact details provided in section 1. The legal basis here is Section 7 para. 3 UWG (Gesetz gegen den unlauteren Wettbewerb – Act against Unfair Competition).
3. Categories of data recipient; data transmissions to a third country
We have appointed IT service providers as well as infrastructure and platform service providers to process your data. Our legitimate interest is to ensure reliable and secure processing of data in the performance of our activities and administration of our company with the support of professional service providers.
This data processing may also take place in a third country, i.e. in a country outside the European Union (EU) or the European Economic Area (EEA), due to the location of our service providers or the location of their servers. Such data transfers are carried out on the basis of Art. 49 para. 1 sentence 1 lit. b or e. GDPR, unless there are other guarantees for compliance with an adequate level of data protection (such as an adequacy decision by the EU Commission).
If these service providers and subcontractors are acting on our behalf, they are only acting in accordance with our instructions and are contractually bound by us accordingly. This also applies to service providers based in a third country.
Specifically, we use the CRM platform “Hubspot” from Hubspot Inc, 25 First St., 2nd floor, Cambridge, Massachusetts 02141, USA to manage contact data. The data categories mentioned in section 2 may be collected and stored in Hubspot for the purposes listed in that section. For more information about how Hubspot works, please refer to the Hubspot Inc. privacy policy, available at: http://legal.hubspot.com/de/pr….
4. Your rights
You have the following rights with regard to personal data related to you:
- Right of access (Art. 15 GDPR),
- Right to rectification (Art. 16 GDPR),
- Right to erasure (Art. 17 GDPR, “right to be forgotten”),
- Right to restriction of processing (Art. 18 GDPR),
- Right to object to processing (Art. 21 GDPR),
- Right to data portability (Art. 20 GDPR).
If you have given us consent to process your data, you can revoke this consent at any time with effect for the future. The lawfulness of the processing of your data until revocation remains unaffected.
We will fulfil your aforementioned rights insofar as the legal requirements for asserting the rights are met. To assert your rights or for other data protection concerns, you can contact our data protection officer via the contact channels mentioned in point 1 above.
a) Your right to complain to a data protection supervisory authority
You also have the right to complain about our processing of your personal data to a data protection supervisory authority in the Member State of your residence, your place of work or the place of the alleged infringement if you consider that the processing of personal data related to you is carried out unlawfully. The supervisory authority responsible for us is:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg
Lautenschlagerstraße 20
70173 Stuttgart
Germany
Email: poststelle@lfdi.bwl.de
Telephone: +49 711 61 55 41 0
b) Additional information on your right of objection
In addition, we would like to point out that as far as a processing of your personal data takes place on the basis of the legitimate interest according to Art. 6 para. 1 sentence 1 lit. f GDPR and/or your personal data is processed for purposes of direct marketing, you have the right to object to the processing of your personal data at any time.
5. Retention period
Unless explicitly specified in this data privacy statement, we process and store personal data only for the period required in order to achieve the purpose of the processing or if specified in laws or regulations to which we are subject. If the storage purpose ceases to exist or if a statutory retention period expires, the personal data are blocked or erased routinely and in accordance with the statutory provisions.
6. Changes to this privacy notice
We will update this privacy policy from time to time, for example if we adapt our website or there is a change in the legal or regulatory requirements.sere Angebote anpassen oder sich die gesetzlichen oder behördlichen Vorgaben ändern.