Privacy Policy

We are pleased that you are visiting our website. The protection and security of your personal information when using our website is very important to us. We would therefore like to inform you at this point which of your personal data we collect when you visit our website and for what purposes it is used.

This data protection declaration applies to the website of the STEERYO SOFTWARE GMBH, which can be reached under the domain steeryo.de as well as the various subdomains ("our website").

Who is responsible and how do I contact you?

Responsible

for the processing of personal data within the meaning of the EU General Data Protection Regulation (GDPR)

STEERYO SOFTWARE GMBH
Gildemeisterstraße 96
DE 33689 Bielefeld

Data protection officer

Dennis Jung
Gildemeisterstraße 96
DE 33689 Bielefeld
datenschutz@steeryo.de

What is this about?

This data protection declaration meets the legal requirements for transparency in the processing of personal data. This is all information that relates to an identified or identifiable natural person. This includes, for example, information such as your name, your age, your address, your telephone number, your date of birth, your e-mail address, your IP address or user behavior when visiting a website. Information with which we cannot (or only with disproportionate effort) relate to you personally, e.g.through anonymization, are not personal data. The processing of personal data (e.g. the collection, querying, use, storage or transmission) always requires a legal basis and a defined purpose.

Stored personal data are deleted as soon as the purpose of the Processing has been achieved and there are no legitimate reasons for further retention of the data. We will inform you about the specific storage periods and criteria for storage in the individual processing operations. Regardless of this, we store your personal data in individual cases to assert, exercise or defend legal claims and if there are statutory retention requirements.

Who gets my data?

We only pass on your personal data that we process on our website to third parties if this is necessary for the fulfillment of the purposes and in individual cases is covered by the legal basis (e.g. consent or protection of legitimate interests). In addition, we pass on personal data to third parties in individual cases if this serves to assert, exercise or defend legal claims. Possible recipients can then e.g. law enforcement authorities, lawyers, auditors, courts, etc.

Insofar as we use service providers for the operation of our website who, as part of order processing on our behalf, provide personal data in accordance with. Process Art. 28 GDPR, these recipients of your personal data can be. You can find more detailed information on the use of processors and web services in the overview of the individual processing operations.

Do you use cookies?

Cookies are small text files that we send to the browser of your device and store them as part of your visit to our website. As an alternative to using cookies, information can also be stored in the local storage of your browser. Some functions of our website cannot be offered without the use of cookies or local storage (technically necessary cookies). Other cookies, on the other hand, allow us to perform various analyses, so that we are able, for example, to recognize the browser you use when you visit our website again and to transmit various information to us (not necessary cookies). Cookies enable us to make our website more user-friendly and effective for you, for example by tracking your use of our website and by determining your preferred settings (e.g. country and language settings). If third parties process information via cookies, they collect the information directly through your browser. Cookies do not cause any damage to your device. They can not run programs or contain viruses.

We inform you about the respective services for which we use cookies in the individual processing operations. Detailed information on the cookies used can be found in the cookie settings or in the Consent Manager of this website.

What rights do I have?

Under the conditions of the statutory provisions of the General Data Protection Regulation (GDPR), you as a data subject have the following rights:

  • Information in accordance with Art. 15 GDPR about the data stored about you in the form of meaningful information on the details of the processing and a copy of your data;
  • Correction in accordance with Art. 16 GDPR of inaccurate or incomplete data stored by us;
  • Deletion in accordance with Art. 17 GDPR of the data stored by us, insofar as the processing is not necessary for the exercise of the right to freedom of expression and information, for the fulfilment of a legal obligation, for reasons of public interest or for the assertion, exercise or defence of legal claims;
  • Restriction of the processing in accordance with Art. 18 GDPR, insofar as the correctness of the data is disputed, the processing is unlawful, we no longer need the data and you refuse to delete it, because you need it to assert, exercise or defend legal claims or you have objected to the processing in accordance with Art. 21 GDPR.
  • Data portability in accordance with Art. 20 GDPR, insofar as you have provided us with personal data within the framework of consent pursuant to Art. 6 sec. 1 lit. a GDPR or on the basis of a contract pursuant to Art. 6 sec. 1 lit.b GDPR and these were processed by us by means of automated procedures. You receive your data in a structured, common and machine-readable format or we transmit the data directly to another responsible person, as far as this is technically feasible.
  • In accordance with Art. 21 GDPR, you object to the processing of your personal data, insofar as they are carried out on the basis of Art. 6 sec. 1 lit. e, f GDPR and there are reasons for doing so, which arise from     your particular situation or if the objection is directed against direct marketing. The right to object does not exist if overriding, overriding reasons for processing are proven or if the processing is carried out for the assertion, exercise or defence of legal claims. Insofar as there is no right to object in individual processing operations, this is indicated therein.
  • Revocation in accordance with Art. 7 sec. 3 GDPR of your given consent with effect for the future.
  • Complaint under Art. 77 GDPR to a supervisory authority if you believe that the processing of your personal data violates the GDPR. As a rule, you can contact the supervisory authority of your usual place of     residence, your workplace or our company headquarters.

How will my data be processed in detail?

In the following we will inform you about the individual processing operations, the scope and purpose of the data processing, the legal basis, the obligation to provide your data and the respective storage period. An automated decision in individual cases, including profiling, does not take place.

Provision of the website

Type and scope of processing

When you visit and use our website, we collect the personal data that your browser automatically transmits to our server. The following information is temporarily stored in a so-called log file:

  • IP address of the requesting computer
  • Date and time of access
  • Name and URL the retrieved file
  • website from which access is made (referrer URL)
  • browser used and, if applicable, the operating system of your computer, as well as the name of your access provider

[Our website is not hosted by us, but by a service provider who for the purpose of the aforementioned data on our behalfin accordance with. Art. 28 GDPR processed.]

Purpose and legal basis

The processing is carried out to safeguard our overriding legitimate interest in displaying our website and ensuring security and stability on the basis of the Art. 6 para. Lit. f GDPR. The collection of data and storage in log files is essential for the operation of the website. There is no right to object to the processing due to the exception according to Art. 21 Paragraph 1 GDPR. Insofar as the further storage of the log files is required by law, the processing takes place on the basis of Art. 6Para. 1 lit. c GDPR. There is no legal or contractual obligation to provide the data, but it is technically not possible to call up our website without providing the data.

Storage duration

The aforementioned data are used for the duration of the display of the website [and for technical reasons beyond that for a maximum of [7 days]].

DataCEO Web App

Type and scope of processing

When you connect your online marketing and sales accounts the following information is temporarily stored in our database:

  • email address of the user
  • marketing KPIs displayed on your dashboard (e.g. number of impressions, clicks and leads per campaign)
  • sales KPIs displayed on your dashboard (e.g. number of calls, offers and deals)

Our web application is hosted in a German data center at Hetzner. The service provider processes the data for the purpose of the above-mentioned data processing on our behalf in accordance with Article 28 GDPR.

Purpose and legal basis

The processing of your data is carried out as part of the operation of our web application and is aimed at ensuring the functionality of the app, as well as ensuring its security and stability. This data processing is based on our predominant legitimate interest according to Article 6(1)(f) of the General Data Protection Regulation (GDPR). The collection and storage of this data are essential for the proper operation of our web application. According to Article 21(1) of the GDPR, there is no right to object to this processing.

Storage period

The aforementioned data is used for the duration of the data display in the app, and for technical reasons for a maximum of 60 days.

Contact Form

Type and scope of processing

On our website, we offer you the option of contacting us using a form provided. The information that is collected via mandatory fields is required to process the request. In addition, you can voluntarily provide additional information that you believe is necessary to process the contact request.

When using the contact form, your personal data will not be passed on to third parties.

Purpose and legal basis

The processing of your data by using our contact form takes place for the purpose of communication and processing of your request on the basis of your consent in accordance with. Art. 6 para. 1lit. a GDPR. If your request relates to an existing contractual relationship with us, processing for the purpose of fulfilling the contract is based on Art.6 Para. 1 lit. b GDPR. There is no legal or contractual obligation to provide your data, but it is not possible to process your request without providing the information in the mandatory fields. If you do not want to provide this data, please contact us by other means.

Storage period

If you use the contact form on the basis of your consent, we will save the data collected each request for a period of three years, starting with the handling of your request or until you withdraw your consent.

[If you use the contact form in the context of a contractual relationship, we will save the data collected for each request Duration of [three years] from the end of the contractual relationship.]

Contact form for applicants

Type and scope of processing

We collect and process the personal data of applicants. Corresponding data processing may also be carried out electronically, for example if applicants submit application documents to us bye-mail or via a web form on our website. On our website, we offer you to send us applications for advertised vacancies by e-mail.

Your data will also only be stored in an applicant database beyond the current application process if you have given us your separate consent to do so.

Purpose and legal basis

The processing of your data in connection with your application takes place for the purpose of processing your application and deciding on the establishment of an employment relationship on the basis of § 26BDSG. In the event of the transfer of your application documents to third parties, in particular to companies affiliated with us, as well as the storage of your data beyond the current application procedure, the processing of your data takes place on the basis of Art. 6 para. 1 sentence 1 lit. a GDPR. There is no legal or contractual obligation to provide your data, but the processing of your application is not possible without the provision of the information.

Storage period

We store the collected data for a period of six months from the date of filling the position.

Presences on social media platforms

We maintain so-called fan pages or accounts or channels on the networks mentioned below in order to provide you with information and offers within social networks and to offer you further ways to contact us and to find out about our offers. In the following, we inform you about what data we or the respective social network process from you in connection with the access and use of our fan pages/accounts.

Data we process from you

If you wish to contact us via Messenger or Direct Message via the respective social network, we will normally process your username, through which you contact us and store any other data you provide if this is necessary to process/respond to your request.

The legal basis is Art. 6(1) sentence 1 f)GDPR (processing is necessary to safeguard the legitimate interests of the controller).

(Static) Usage data we receive from the social networks

We receive automatically provided statistics about our accounts through Insights functionalities. The statistics include the total number of page views, likes, page activity and post interactions, reach, video views/views, and the proportion of men/women among our fans/followers.

The statistics contain only aggregated data which cannot be related to individuals. They are not identifiable to us.

What data you process social networks

In order to view the content of our fan pages or accounts, you do not have to be a member of the respective social network and no user account is required for the respective social network.

Please note, however, that when the respective social network is accessed, the social networks also collect and store data from website visitors without a user account (e..B. technical data in order to be able to view the website to you) and use cookies and similar technologies, which we have no influence on. Details can be found in the privacy policy of the respective social network (see the corresponding links above)

If you wish to interact with the content on our fan pages/accounts, e.B.g. comment, share or like our postings/posts and/or contact us via Messenger functions, prior registration with the respective social network and the provision of personal data is required.

We have no influence on the data processing by the social networks in the context of your use. To our knowledge, your data will be stored and processed in particular in connection with the provision of the services of the respective social network, furthermore for the analysis of the usage behaviour (using cookies, pixel/web beacons and similar technologies)on the basis of which advertising based on your interests is played out both within and outside the respective social network. It cannot be excluded that your data will be stored by the social networks outside the EU/EEA and will be passed on to third parties.

Information on, among other things, the exact scope and purposes of the processing of your personal data, the storage period/deletion as well as guidelines on the use of cookies and similar technologies in the context of the registration and use of social networks can be found in the social protection policy/cookie policy. There you will also find information about your rights and possibilities of objection.

Facebook page

When you visit our Facebook page, Facebook (Meta) collects, among other things, your IP address and other information that is available on your PC in the form of cookies. This information is used to provide us, as the operator of the Facebook pages, with statistical information about the use of the Facebook page. Facebook provides further information on this under the following link: https://facebook.com/help/pages/insights.

By means of the transmitted statistical information, it is not possible for us to draw conclusions about individual users. We only use these in order to be able to respond to the interests of our users and to continuously improve our online presence and to ensure the quality of it.

We collect your data via our fan page only in order to realize a possible provision for communication and interaction with us. This survey usually includes: Your name, message content, comment content, and the profile information you provide "publicly."

The processing of your personal data for our above-mentioned purposes takes place on the basis of our legitimate business and communicative interest in offering an information and communication channel in accordance with Art. 6 para. 1 f) GDPR. If you as a user have given your consent to data processing to the respective provider of the social network, the legal basis of the processing extends to Art. 6 para. 1a), Art. 7 GDPR.

Due to the fact that the actual data processing is carried out by the provider of the social network, our access options are limited to your data. Only the provider of the social network is authorized to have full access to your data. Due to this, only the provider can directly take and implement appropriate measures to fulfill your user rights(request for information, deletion request, objection, etc.). The assertion of corresponding rights is therefore most effectively asserted directly against the respective provider.

Together with Facebook, we are responsible for the personal content of the fan page. Data subject rights can be asserted with Meta Platforms Ireland Ltd. as well as with us.

According to the GDPR, the primary responsibility for the processing of Insights data lies with Facebook andFacebook fulfils all obligations under the GDPR with regard to the processing of Insights data, Meta Platforms Ireland Ltd. makes the essence of the PageInsights supplement available to the data subjects.

We do not make any decisions regarding the processing of Insights data and the storage period of cookies on user devices.

Further information can be found directly on Facebook (supplementary agreement with Facebook): https://www.facebook.com/legal/terms/page_controller_addendum.

Further information on the exact scope and purposes of the processing of your personal data, the storage period/deletion as well as guidelines for the use of cookies and similar technologies in the context of registration and use can be found in Facebook's privacy policy/cookie policy:
https://www.facebook.com/privacy/policy/?entry_point=data_policy_redirect&entry=0
https://www.facebook.com/policies/cookies

LinkedIn page

LinkedIn is a social network of LinkedInInc. based in Sunnyvale, California, USA, which enables the creation of private and professional profiles of natural persons and company profiles. Users can maintain their existing contacts within the social network and make new ones. Companies and other organizations can create profiles where photos and other company information are uploaded to present themselves as employers and hire employees. Other LinkedIn users have access to this information and can write their own articles and share this content with others. The focus of the network is on the professional exchange on specialist topics with people who have the same professional interests.

When using or visiting the network, LinkedIn automatically collects data from users or visitors during use or visit, such as user name, job title and IP address. This is done with the help of various tracking technologies. LinkedIn provides benefits based on the data collected in this way, among other things, information, offers and recommendations.

We collect your data via our company profile only in order to realize a possible provision for communication and interaction with us. This survey usually includes: Your name, message content, comment content, and the profile information you provide "publicly."

The processing of your personal data for our above-mentioned purposes takes place on the basis of our legitimate business and communicative interest in offering an information and communication channel in accordance with Art. 6 para. 1 f GDPR. If you as a user have given your consent to data processing to the respective provider of the social network, the legal basis for the processing extends to Art. 6 para.1 a, Art. 7 GDPR.

Due to the fact that the actual data processing is carried out by the provider of the social network, our access options are limited to your data. Only the provider of the social network is authorized to have full access to your data. Due to this, only the provider can directly take and implement appropriate measures to fulfill your user rights(request for information, deletion request, objection, etc.). The assertion of corresponding rights is therefore most effectively asserted directly against the respective provider.

Together with LinkedIn, we are responsible for the personal content of our company profile. Data subject rights can be asserted at LinkedIn Inc. as well as with us.

We do not make any decisions regarding the data collected on the LinkedIn site using tracking technologies.

For more information about LinkedIn, visit: https://about.linkedin.com.

Further information on data protection atLinkedIn can be found at: https://www.linkedin.com/legal/privacy-policy.

Further information on the storage period/deletion as well as guidelines for the use of cookies and similar technologies in the context of registration and use on LinkedIn can be found at: https://de.linkedin.com/legal/cookie-policy?trk=homepage-basic_footer-cookie-policy.

XING page

XING is a social network of New Work SE based in Hamburg, Germany, which enables the creation of private and professional profiles of natural persons and company profiles. Users can maintain their existing contacts within the social network and make new ones. Companies and other organizations can create profiles where photos and other company information are uploaded to present themselves as employers and hire employees. Other XING users have access to this information and can write their own articles and share this content with others. The focus of the network is on the professional exchange on specialist topics with people who have the same professional interests.

When using or visiting the network, XING orby third parties used automatically collects data from users or visitors during use or visit, such as user name, job title and IP address. This is done with the help of various tracking technologies. XING provides benefits on the basis of the data collected in this way, among other things, information, offers and recommendations.

We collect your data via our company profile only in order to realize a possible provision for communication and interaction with us. This survey usually includes: Your name, message content, comment content, and the profile information you provide "publicly."

The processing of your personal data for our above-mentioned purposes takes place on the basis of our legitimate business and communicative interest in offering an information and communication channel in accordance with Art. 6 para. 1 f GDPR. If you as a user have given your consent to data processing to the respective provider of the social network, the legal basis for the processing extends to Art. 6 para. 1 a,Art. 7 GDPR.

Due to the fact that the actual data processing is carried out by the provider of the social network, our access options are limited to your data. Only the provider of the social network is authorized to have full access to your data. Due to this, only the provider can directly take and implement appropriate measures to fulfill your user rights (request for information, deletion request, objection, etc.). The assertion of corresponding rights is therefore most effectively asserted directly against the respective provider.

Together with XING, we are responsible for the personal content of our company profile. Rights of data subjects can be asserted with New Work SE as well as with us.

We do not make any decisions regarding the data collected on the XING site using tracking technologies.

Further information on XING can be found at: https://corporate.xing.com/de/unternehmen.

Further information on data protection at XING can be found at: https://privacy.xing.com/de/datenschutzerklaerung.

Bootstrap CDN

Type and scope of processing

We use Bootstrap CDN to properly provide the content of our website. Bootstrap CDN is a Bootstrap service that acts as the Content Delivery Network (CDN) on our website.

A CDN helps to deliver content from our online offering, especially files such as graphics or scripts, faster with the help of regionally or internationally distributed servers. When you access this content, you connect to Bootstrap servers, , transmitting your IP address and, if applicable, browser data such as your user agent. This data will be processed exclusively for the above purposes and for the maintenance of the security and functionality of Bootstrap CDN.

Purpose and legal basis

The use of the Content Delivery Network is based on our legitimate interests, i.e. interest in a secure and efficient provision and the optimization of our online offer in accordance with Art. 6sec. 1 lit. f. GDPR.

Storage time

The actual storage time of the processed data is not influenced by us, but is determined by Bootstrap. For more information, seethe privacy policy for Bootstrap CDN: https://www.bootstrapcdn.com/privacy-policy/.

Google Analytics

Type and scope of processing

We use Google Analytics from Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irland, as an analysis service for the statistical evaluation of our online offer. This includes, for example, the number of visits to our online offer, visited subpages and the length of stay of visitors.

Google Analytics uses cookies and other browser technologies to evaluate user behavior and recognize users.

This information is used, among other things, to compile reports on website activity.

Purpose and legal basis

The use of Google Analytics is based on your consent in accordance with Art. 6 para. 1 lit. a. GDPR and § 25 para. 1 TTDSG.

We intend to transfer personal data to third countries outside the European Economic Area, in particular the USA. In cases where there is no adequacy decision of the European Commission (e.g. in theUSA), we have agreed other suitable guarantees within the meaning of Art. 44 et seq. GDPR with the recipients of the data. Unless otherwise stated, these are standard contractual clauses of the EU Commission in accordance withImplementing Decision (EU) 2021/914 of 4 June 2021. A copy of these StandardContractual Clauses can be found at https://eur-lex.europa.eu/legal-content/DE/TXT/HTML/?uri=CELEX:32021D0914&from=DE .

In addition, prior to such a third country transfer, we obtain your consent in accordance with Art. 49 para. 1 sentence 1lit. a. GDPR, which you give via the consent in the Consent Manager (or other forms, registrations, etc.). We would like to point out that in the case of transfers to third countries, risks unknown in detail (e.g. data processing by security authorities of the third country, the exact scope and consequences of which we do not know for you, over which we have no influence and of which you may not be aware) may exist.

Storage period

The specific storage period of the processed data cannot be influenced by us, but is determined by Google Ireland Limited.Further information can be found in the privacy policy for Google Analytics: https://policies.google.com/privacy.

Google CDN

Type and scope of processing

We use Google CDN to properly provide the content of our website. Google CDN is a Google Ireland Limited service that acts as the Content Delivery Network (CDN) on our website.

A CDN helps to deliver content from our online offering, especially files such as graphics or scripts, faster with the help of regionally or internationally distributed servers. When you access this content, you connect to Google Ireland Limited servers, Gordon House, BarrowStreet, Dublin 4, Irland, transmitting your IP address and, if applicable, browser data such as your user agent. This data will be processed exclusively for the above purposes and for the maintenance of the security and functionality of Google CDN.

Purpose and legal basis

The use of the Content Delivery Network is based on our legitimate interests, i.e. interest in a secure and efficient provision and the optimization of our online offer in accordance with Art. 6sec. 1 lit. f. GDPR.

Storage time

The actual storage time of the processed data is not influenced by us, but is determined by Google Ireland Limited. For more information, see the privacy policy for Google CDN: https://policies.google.com/privacy.