GOe Future —
Privacy Policy
1. Data Protection at a Glance
General Information
The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can be used to personally identify you. Detailed information on data protection can be found in the privacy policy set out below.
Data Collection on This Website
Who is responsible for data collection on this website?
Data processing on this website is carried out by the website operator. You can find the operator’s contact details in the section “Information on the Controller” in this privacy policy.
How do we collect your data?
Some data is collected when you provide it to us. This may, for example, be data that you enter into a contact form.
Other data is collected automatically or after you have given your consent by our IT systems when you visit the website. This primarily concerns technical data (e.g. internet browser, operating system or time of page access). This data is collected automatically as soon as you enter this website.
What do we use your data for?
Some of the data is collected to ensure that the website is provided without errors. Other data may be used to analyse your user behaviour.
What rights do you have regarding your data?
You have the right at any time to receive information free of charge about the origin, recipients and purpose of your stored personal data. You also have the right to request the correction or deletion of this data. If you have given consent to data processing, you may revoke this consent at any time with effect for the future. You also have the right, under certain circumstances, to request restriction of the processing of your personal data. Furthermore, you have the right to lodge a complaint with the competent supervisory authority.
You may contact us at any time regarding this or any other questions relating to data protection.
Analytics Tools and Third-Party Tools
When you visit this website, your browsing behaviour may be statistically evaluated. This is carried out primarily using analytics programs.
Detailed information about these analytics programs can be found in the following privacy policy.
2. Hosting
We host the content of our website with the following provider:
External Hosting
This website is hosted externally. The personal data collected on this website is stored on the servers of the hosting provider(s). This may include, in particular, IP addresses, contact requests, metadata and communication data, contractual data, contact details, names, website access data and other data generated via a website.
External hosting is carried out for the purpose of fulfilling contracts with our potential and existing customers (Art. 6(1)(b) GDPR) and in the interest of providing our online offering securely, quickly and efficiently through a professional provider (Art. 6(1)(f) GDPR). Where corresponding consent has been requested, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG, insofar as the consent covers the storage of cookies or access to information on the user’s terminal device (e.g. device fingerprinting) within the meaning of the TDDDG. Consent can be revoked at any time.
Our hosting provider(s) will process your data only to the extent necessary to fulfil their contractual obligations and will follow our instructions regarding this data.
We use the following hosting provider:
Hetzner Online GmbH
Industriestr. 25
91710 Gunzenhausen
Germany
Data Processing Agreement
We have concluded a data processing agreement (DPA) for the use of the above-mentioned service. This is a contract required under data protection law that ensures that the provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.
3. General Information and Mandatory Information
Data Protection
The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the applicable data protection regulations and this privacy policy.
When you use this website, various personal data is collected. Personal data is data that can be used to personally identify you. This privacy policy explains which data we collect and what we use it for. It also explains how and for what purpose this takes place.
Please note that data transmission via the Internet (e.g. communication by email) may be subject to security vulnerabilities. Complete protection of data against access by third parties is not possible.
Information on the Controller
The controller responsible for data processing on this website is:
GOe FUTURE Management GmbH
Startup Factory for Life Sciences
City Campus
Hermann-Rein-Straße 3
37075 Göttingen
Germany
Tel.: +49 151 43351842
Email: hello@goe-future.de
The controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of processing personal data (e.g. names, email addresses or similar information).
Storage Period
Unless a more specific storage period is stated in this privacy policy, your personal data will remain with us until the purpose for data processing no longer applies. If you assert a legitimate request for deletion or revoke your consent to data processing, your data will be deleted unless we have other legally permissible reasons for storing your personal data (e.g. retention periods under tax or commercial law); in the latter case, the data will be deleted once these reasons no longer apply.
General Information on the Legal Bases for Data Processing on This Website
If you have consented to data processing, we process your personal data on the basis of Art. 6(1)(a) GDPR or Art. 9(2)(a) GDPR if special categories of data pursuant to Art. 9(1) GDPR are processed. In the event of explicit consent to the transfer of personal data to third countries, data processing is also carried out on the basis of Art. 49(1)(a) GDPR. If you have consented to the storage of cookies or access to information on your terminal device (e.g. via device fingerprinting), data processing is additionally carried out on the basis of Section 25(1) TDDDG. Consent can be revoked at any time. If your data is required for the performance of a contract or for the implementation of pre-contractual measures, we process your data on the basis of Art. 6(1)(b) GDPR. Furthermore, where your data is required for compliance with a legal obligation, we process it on the basis of Art. 6(1)(c) GDPR. Data processing may also be carried out on the basis of our legitimate interest pursuant to Art. 6(1)(f) GDPR. Information on the legal basis applicable in each individual case is provided in the following sections of this privacy policy.
Withdrawal of Your Consent to Data Processing
Many data processing operations are only possible with your express consent. You may revoke consent already given at any time. The lawfulness of data processing carried out prior to revocation remains unaffected by the revocation.
Right to Object to Data Collection in Special Cases and to Direct Marketing (Art. 21 GDPR)
IF DATA PROCESSING IS CARRIED OUT ON THE BASIS OF ART. 6(1)(E) OR (F) GDPR, YOU HAVE THE RIGHT AT ANY TIME, ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION, TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE RESPECTIVE LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR PERSONAL DATA CONCERNED UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING THAT OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS, OR THE PROCESSING SERVES THE ESTABLISHMENT, EXERCISE OR DEFENCE OF LEGAL CLAIMS (OBJECTION PURSUANT TO ART. 21(1) GDPR).
IF YOUR PERSONAL DATA IS PROCESSED FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT AT ANY TIME TO OBJECT TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR THE PURPOSE OF SUCH MARKETING; THIS ALSO APPLIES TO PROFILING TO THE EXTENT THAT IT IS RELATED TO SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL SUBSEQUENTLY NO LONGER BE USED FOR DIRECT MARKETING PURPOSES (OBJECTION PURSUANT TO ART. 21(2) GDPR).
Right to Lodge a Complaint with the Competent Supervisory Authority
In the event of infringements of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, their place of work or the place of the alleged infringement. The right to lodge a complaint is without prejudice to other administrative or judicial remedies.
The supervisory authority responsible for us is:
The State Commissioner for Data Protection of Lower Saxony
Prinzenstraße 5
30159 Hannover
Germany
Telephone: +49 (0511) 120 45 00
Email: poststelle@lfd.niedersachsen.de
Right to Data Portability
You have the right to have data that we process automatically on the basis of your consent or in performance of a contract handed over to you or to a third party in a commonly used, machine-readable format. If you request the direct transfer of the data to another controller, this will only be carried out where technically feasible.
Access, Erasure and Rectification
Within the scope of the applicable legal provisions, you have the right at any time to receive information free of charge about your stored personal data, its origin and recipients, and the purpose of the data processing, and, where applicable, a right to have this data rectified or erased. You may contact us at any time regarding this or any other questions relating to personal data.
Right to Restriction of Processing
You have the right to request restriction of the processing of your personal data. You may contact us at any time for this purpose. The right to restriction of processing exists in the following cases:
- If you dispute the accuracy of your personal data stored by us, we generally require time to verify this. For the duration of the verification, you have the right to request restriction of the processing of your personal data.
- If the processing of your personal data was/is unlawful, you may request restriction of data processing instead of erasure.
- If we no longer require your personal data, but you require it for the exercise, defence or establishment of legal claims, you have the right to request restriction of processing instead of erasure.
- If you have lodged an objection pursuant to Art. 21(1) GDPR, your interests and ours must be weighed against each other. As long as it has not yet been determined whose interests prevail, you have the right to request restriction of the processing of your personal data.
If you have restricted the processing of your personal data, such data may – apart from storage – only be processed with your consent, for the establishment, exercise or defence of legal claims, for the protection of the rights of another natural or legal person, or for reasons of important public interest of the European Union or a Member State.
SSL or TLS Encryption
For security reasons and to protect the transmission of confidential content, such as orders or inquiries that you send to us as the website operator, this site uses SSL or TLS encryption. You can recognise an encrypted connection by the fact that the address line of the browser changes from “http://” to “https://” and by the lock symbol in your browser bar.
If SSL or TLS encryption is enabled, the data you transmit to us cannot be read by third parties.
Objection to Promotional Emails
We hereby object to the use of contact data published as part of the legal notice obligation for the purpose of sending unsolicited advertising and informational materials. The website operators expressly reserve the right to take legal action in the event of unsolicited advertising information being sent, for example by spam email.
4. Data Collection on This Website
Cookies
Our websites use so-called “cookies”. Cookies are small data packages and do not cause any damage to your terminal device. They are stored either temporarily for the duration of a session (session cookies) or permanently (persistent cookies) on your terminal device. Session cookies are automatically deleted at the end of your visit. Persistent cookies remain stored on your terminal device until you delete them yourself or they are automatically deleted by your web browser.
In some cases, cookies from third-party companies may also be stored on your terminal device when you visit our site (third-party cookies). These enable us or you to use certain services provided by the third party (e.g. cookies for processing payment services).
Cookies have various functions. Many cookies are technically necessary because certain website functions would not work without them (e.g. shopping cart functionality or the display of videos). Other cookies are used to evaluate user behaviour or display advertising.
Cookies that are required to carry out the electronic communication process, to provide certain functions requested by you (e.g. shopping cart functionality), or to optimise the website (e.g. cookies for measuring web audiences) (“necessary cookies”) are stored on the basis of Art. 6(1)(f) GDPR unless another legal basis is specified. The website operator has a legitimate interest in storing necessary cookies to ensure the technically error-free and optimised provision of its services. Where consent to the storage of cookies and comparable recognition technologies has been requested, processing is carried out exclusively on the basis of this consent (Art. 6(1)(a) GDPR and Section 25(1) TDDDG); consent can be revoked at any time.
You can configure your browser so that you are informed about the setting of cookies and only allow cookies in individual cases, exclude the acceptance of cookies in certain cases or in general, and activate the automatic deletion of cookies when closing the browser. Disabling cookies may limit the functionality of this website.
If cookies from third-party companies or cookies for analytics purposes are used, we will inform you separately within this privacy policy and request your consent where applicable.
Consent with Cookiebot by Usercentrics
Our website uses the Cookiebot by Usercentrics consent technology to obtain your consent to the storage of certain cookies in your browser or to the use of certain technologies and to document this in compliance with data protection law. The provider of this technology is Usercentrics A/S, Havnegade 39, 1058 Copenhagen, Denmark (“Usercentrics”).
When you enter our website, a Usercentrics cookie is stored in your browser in which the consent you have given or the withdrawal of such consent is stored. This data is not passed on to the provider of Cookiebot.
The data collected will be stored until you request us to delete it, delete the Cookiebot cookie yourself, or the purpose for storing the data no longer applies. Mandatory statutory retention periods remain unaffected.
Usercentrics consent technology is used to obtain the legally required consent for the use of cookies. The legal basis for this is Art. 6(1)(c) GDPR.
Server Log Files
The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:
- browser type and browser version,
- operating system used,
- referrer URL,
- host name of the accessing computer,
- date and time of the server request,
- IP address.
This data is not merged with other data sources.
This data is collected on the basis of Art. 6(1)(f) GDPR in conjunction with Section 25(2) TDDDG. The website operator has a legitimate interest in the technically error-free display and optimisation of the website; for this purpose, server log files must be recorded.
Contact Form
If you send us inquiries via the contact form, the information you provide in the inquiry form, including the contact details you enter there, will be stored by us for the purpose of processing the inquiry and in case of follow-up questions. We will not pass on this data without your consent.
This data is processed on the basis of Art. 6(1)(b) GDPR if your inquiry is related to the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, processing is based on our legitimate interest in effectively handling inquiries addressed to us (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR), where this has been requested; consent can be revoked at any time.
The data you enter in the contact form will remain with us until you request its deletion, revoke your consent to storage, or the purpose for storing the data no longer applies (e.g. after your inquiry has been fully processed). Mandatory statutory provisions – in particular retention periods – remain unaffected.
Inquiries by Email, Telephone or Fax
If you contact us by email, telephone or fax, your inquiry including all personal data arising from it (name, inquiry) will be stored and processed by us for the purpose of handling your request. We will not pass on this data without your consent.
This data is processed on the basis of Art. 6(1)(b) GDPR if your inquiry is related to the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, processing is based on our legitimate interest in effectively handling inquiries addressed to us (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR), where this has been requested; consent can be revoked at any time.
The data you send to us via contact inquiries will remain with us until you request its deletion, revoke your consent to storage, or the purpose for storing the data no longer applies (e.g. after your request has been fully processed). Mandatory statutory provisions – in particular statutory retention periods – remain unaffected.
5. Newsletter and Contact Information
Newsletter Data
If you wish to receive the newsletter offered on the website, we require an email address from you as well as information that allows us to verify that you are the owner of the email address provided and that you agree to receive the newsletter. No additional data is collected, or it is collected only on a voluntary basis. We use this data to send the requested information and store it as contact information.
Registration for our newsletter is carried out using the so-called double opt-in procedure. After registering, you will receive an email asking you to confirm your registration. Your registration is complete only after this confirmation. This ensures that no one can register using someone else’s email address. Logging of the registration and confirmation process (time, IP address, content of the consent) is carried out on the basis of Art. 6(1)(c) and (f) GDPR in order to demonstrate compliance with data protection requirements.
The data entered into the newsletter registration form is processed on the basis of your consent (Art. 6(1)(a) GDPR) and our legitimate interest in being able to contact you outside the newsletter distribution where appropriate. You may revoke the consent you have given to the storage of the data, the email address and its use for sending the newsletter at any time, for example via the “unsubscribe” link in the newsletter. The lawfulness of data processing operations already carried out remains unaffected by the revocation.
The data you provide to us for the purpose of receiving the newsletter will be stored by us or the newsletter service provider until you unsubscribe from the newsletter and will be deleted from the newsletter distribution list after you unsubscribe or once the purpose no longer applies. We reserve the right to delete or block email addresses from our newsletter distribution list at our own discretion within the scope of our legitimate interest pursuant to Art. 6(1)(f) GDPR.
Data stored by us for other purposes remains unaffected.
After you unsubscribe from the newsletter distribution list, your email address may be stored by us or the newsletter service provider in a blacklist if this is necessary to prevent future mailings. The data from the blacklist is used only for this purpose and is not merged with other data. This serves both your interest and our interest in complying with the legal requirements for sending newsletters (legitimate interest within the meaning of Art. 6(1)(f) GDPR). Storage in the blacklist is not limited in time. You may object to the storage if your interests outweigh our legitimate interest.
For sending our newsletter, we use the “Mailchimp” service of Intuit Inc. (USA) as a technical service provider. Mailchimp processes your email address and, where applicable, other data provided as part of the newsletter registration on our behalf in order to technically send and statistically evaluate the newsletter. We have concluded a data processing agreement with Mailchimp in accordance with Art. 28 GDPR.
Data processing by Mailchimp takes place, among other locations, on servers in the USA. Mailchimp / Intuit participates in the EU-US Data Privacy Framework, which governs the correct and secure transfer of personal data of EU citizens to the USA. In addition, Mailchimp uses so-called Standard Contractual Clauses, which are intended to ensure that data processing complies with European data protection standards when data is transferred to and stored in third countries such as the USA. Further information is available at: Mailchimp GDPR information.
6. Plugins and Tools
Google Fonts (Local Hosting)
This site uses so-called Google Fonts, provided by Google, for the consistent display of fonts. The Google Fonts are installed locally. No connection to Google servers is established.
Further information about Google Fonts can be found at https://developers.google.com/fonts/faq and in Google’s privacy policy at https://policies.google.com/privacy?hl=en.
Web Analytics with Matomo
We use the Matomo web analytics service on our website to statistically evaluate the use of our website and to continuously improve our online offering.
Matomo is operated on our own server. The information collected by Matomo is processed exclusively on our own servers and is not passed on to third parties.
In particular, the following information may be collected:
- shortened or anonymised IP address,
- date and time of access,
- pages and content accessed,
- referrer URL,
- browser and operating system used,
- screen resolution,
- approximate geographical region,
- duration of use and interactions on our website.
Processing is carried out on the basis of Art. 6(1)(f) GDPR. Our legitimate interest lies in the statistical analysis of the use of our website, the optimisation of our online offering and the improvement of user-friendliness.
Where Matomo is configured so that only anonymised or aggregated data is processed and no cookies or comparable technologies are used, audience measurement is carried out without the user’s consent. The collected data is not merged with other personal data.
Matomo uses cookies to collect information about the use of our website and to recognise returning visitors. The storage or reading of this information takes place only with your consent pursuant to Section 25(1) TDDDG. You can revoke your consent at any time with effect for the future via the cookie settings.
Further information can be found at https://matomo.org/gdpr-analytics/.
Forms
On our website, we provide various forms that you can use to contact us or submit specific inquiries. When you use these forms, we process the personal data you enter (e.g. name, contact details, content of your message and, where applicable, company affiliation) in order to process and respond to your inquiry.
The legal basis for processing is generally Art. 6(1), sentence 1, lit. b GDPR insofar as your inquiry is related to the initiation or performance of a contract, and otherwise Art. 6(1), sentence 1, lit. f GDPR (our legitimate interest in processing inquiries).
For certain forms, we use the “Innoloft” CRM system as a technical platform for managing and processing incoming inquiries. The data you enter via the respective form is transferred to Innoloft and stored there in our tenant/contact management system. Depending on the form, the transfer may take place directly via a technical interface (API).
Innoloft processes the data either as a joint controller with us pursuant to Art. 26 GDPR or on the basis of a data processing agreement pursuant to Art. 28 GDPR.
7. Our Own Services
Handling Applicant Data
We offer you the opportunity to apply to us (e.g. by email, post or via an online application form). Below, we inform you about the scope, purpose and use of the personal data collected from you as part of the application process. We assure you that the collection, processing and use of your data will be carried out in accordance with applicable data protection law and all other statutory provisions and that your data will be treated in strict confidence.
Scope and Purpose of Data Collection
If you submit an application to us, we process the personal data associated with it (e.g. contact and communication data, application documents, notes taken during interviews, etc.) insofar as this is necessary for the decision on establishing an employment relationship. The legal basis for this is Section 26 BDSG under German law (initiation of an employment relationship), Art. 6(1)(b) GDPR (general contract initiation) and – if you have given your consent – Art. 6(1)(a) GDPR. Consent can be revoked at any time. Within our company, your personal data will be passed on exclusively to persons involved in processing your application.
If your application is successful, the data you have submitted will be stored in our data processing systems on the basis of Section 26 BDSG and Art. 6(1)(b) GDPR for the purpose of carrying out the employment relationship.
Data Retention Period
If we are unable to offer you a position, if you reject a job offer, or if you withdraw your application, we reserve the right to retain the data submitted by you on the basis of our legitimate interests (Art. 6(1)(f) GDPR) for up to 6 months from the end of the application process (rejection or withdrawal of the application). The data will then be deleted and physical application documents destroyed. Retention serves in particular as evidence in the event of a legal dispute. If it becomes apparent that the data will still be required after the expiry of the 6-month period (e.g. due to threatened or pending legal proceedings), deletion will only take place once the purpose for further retention no longer applies.
Longer retention may also take place if you have given corresponding consent (Art. 6(1)(a) GDPR) or if statutory retention obligations prevent deletion.
8. Processing of Personal Data of Business Partners
As part of its cooperation with business partners, GOe FUTURE (GF) processes personal data relating to contact persons at customers, prospective customers, sales partners, suppliers and partners (each a “Business Partner”):
- contact information such as first and last name, business address, business telephone number, business mobile telephone number, business fax number and business email address;
- payment data, such as information required to process payments or prevent fraud, including credit card information and card verification numbers;
- other information whose processing is necessary in the context of a project or the handling of a contractual relationship with GF or which is provided voluntarily by Business Partners, e.g. in connection with bookings, inquiries or project details;
- personal data collected from publicly available sources, information databases or credit agencies; and
- where legally required in the context of compliance screenings: date of birth, identification documents and identification numbers, information on relevant court proceedings and other legal disputes involving Business Partners.
GF processes personal data for the following purposes:
- communication with Business Partners regarding products, services and projects, e.g. to process inquiries from the Business Partner or provide technical information about products;
- planning, implementation and management of the contractual business relationship between GF and the Business Partner, e.g. to process orders for products and services, collect payments, or for accounting and billing purposes;
- conducting customer surveys, marketing campaigns, market analyses, prize draws, competitions or similar promotions and events;
- conducting customer satisfaction surveys and direct marketing;
- maintaining and protecting the security of our products and services as well as our websites, preventing and detecting security risks, fraudulent conduct or other criminal or malicious acts;
- complying with (i) legal requirements (e.g. tax and commercial law retention obligations), (ii) existing obligations to carry out compliance screenings (to prevent economic crime or money laundering); and
- settling legal disputes, enforcing existing contracts, and establishing, exercising and defending legal claims.
The processing of personal data is necessary to achieve the purposes stated above. Unless expressly stated otherwise when personal data is collected, the legal basis for data processing is:
- the performance and fulfilment of a contract with you (Art. 6(1)(b) GDPR),
- compliance with legal obligations to which GF is subject (Art. 6(1)(c) GDPR), or
- the protection of GF’s legitimate interests (Art. 6(1)(f) GDPR).
GF’s legitimate interest lies in the initiation, implementation and handling of the business relationship. Where necessary, we will expressly inform you of additional or different legitimate interests before the respective data processing takes place. If, in an individual case, you have expressly consented to the processing of your personal data, this consent constitutes the legal basis for processing (Art. 6(1)(a) GDPR).
9. Processing of Personal Data for Direct Marketing
Within the framework of applicable law, GF may use your contact details for direct marketing purposes (e.g. invitations to events, newsletters), including by email.
If you consent to receiving GF marketing information based on your personal interests, GF determines your personal interests by storing information about your visits to LGFSV websites using cookies. This information may include viewed articles, downloaded documents, as well as the date and time of access (“Usage Data”) and is stored in a personal user profile. Information about whether and when you opened a marketing email sent to you by GF is also added to the profile.
In addition, the following information that you have provided directly on a GF website or that may be stored in GF customer relationship management systems is added to the profile:
- personal contact details (e.g. name, title, company, function/role, country, telephone number);
- information about the company you work for (e.g. address, industry and other publicly available information).
The data described above (“Data”) is used by GF to send you marketing content (e.g. newsletters, invitations to events and trade fairs, etc.) about products and services that may be of interest to you. In addition, the Data may be used by GF sales employees to make offers to you and to provide the best possible support to you and/or your company.
Your Data will be deleted from GF’s marketing automation system when it is no longer required for marketing purposes or when you have withdrawn your consent.
You have the right at any time to object to the use of your contact details for these purposes by sending an email to hello@goe-future.de or by using the objection option provided in the message you received.
10. Transfer and Disclosure of Personal Data
GF may transfer your personal data to:
- other companies of the Sartorius Group or other third parties – e.g. sales partners or suppliers – where this is necessary in connection with the offering and operation of the GF websites or the initiation, implementation or handling of the business relationship;
- IT service providers that process data as part of their service provision (e.g. providers of IT maintenance services), process data in accordance with GF’s instructions and have been contractually obliged to comply with applicable data protection law; and/or
- third parties where this is necessary to comply with applicable law or to establish, exercise or defend legal claims (e.g. in connection with arbitration or court proceedings, to courts, arbitration tribunals, authorities or legal advisers).
Some recipients are located in countries whose data protection laws provide a level of protection that does not correspond to that of the European Union or the European Economic Area. In such cases, where legally required, GF takes measures to otherwise ensure appropriate and adequate safeguards for the protection of personal data.
GF transfers personal data to recipients in such countries only if they (i) have concluded EU Standard Contractual Clauses with GF, (ii) have implemented Binding Corporate Rules, or (iii) – in the case of recipients located in the USA – are certified under the EU/US Data Privacy Framework.
11. Processing of Data Using AI-Based Tools
a) Creation of Meeting Minutes in Microsoft Teams (e.g. with Notion, Copilot or Comparable Applications)
We use Microsoft Teams as well as integrated or connected AI-supported applications, e.g. Microsoft Copilot, Notion or comparable tools (provider: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-7329, USA), to conduct online meetings and to automatically or semi-automatically create and manage meeting notes, minutes and task lists from them. The purpose is to document meetings efficiently, track tasks and optimise workflows.
In particular, the following data is processed:
- master data and contact details of participants (e.g. name, email address, username, organisational affiliation),
- connection and usage data (e.g. time, duration, meeting ID, metadata relating to the use of Teams),
- content data from meetings (e.g. spoken contributions, chat messages, shared documents, presentation content), and
- the summaries, minutes and tasks generated from this data.
Depending on the relationship, processing takes place on the basis of Art. 6(1)(b) GDPR (performance of a contract or pre-contractual measures), Art. 6(1)(f) GDPR (legitimate interest in efficient communication, documentation and follow-up of meeting results) and – where required – Art. 6(1)(c) GDPR (statutory documentation obligations). Where special categories of personal data within the meaning of Art. 9 GDPR are concerned, processing takes place only on the basis of an applicable exception (e.g. Art. 9(2)(b) or (f) GDPR) or explicit consent pursuant to Art. 9(2)(a) GDPR.
Recipients of the data are initially the internal departments involved in the respective meeting. In addition, Microsoft as the provider of Microsoft Teams and, where applicable, other service providers used by us (e.g. Notion Labs, Inc. or comparable providers) obtain access to the data within the framework of processing on our behalf pursuant to Art. 28 GDPR, insofar as this is necessary to provide the services. Complete control over Microsoft’s actual use of data cannot currently be ensured in all respects because Microsoft provides for further use of data for certain purposes of its own.
Depending on the configuration, data may be transferred to countries outside the European Union or the European Economic Area, in particular to the USA. Where possible, we rely on appropriate safeguards (e.g. EU Standard Contractual Clauses). Microsoft is certified under the EU/US Data Privacy Framework, under which legally compliant and secure data transfer is ensured. Nevertheless, due to Microsoft’s own purposes and the involvement of subcontractors that are not individually named, a completely risk-free transfer to third countries cannot be guaranteed.
Minutes and accompanying meeting data are stored only for as long as is necessary to fulfil the purposes stated above and any statutory retention obligations. In all other respects, our company’s general deletion periods apply.
b) Correction and Optimisation of Emails in Outlook (e.g. with Copilot or Comparable AI Functions)
We use integrated or connected AI functionalities in Microsoft Outlook (provider: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-7329, USA), e.g. Microsoft Copilot or comparable services, to linguistically correct, structure and stylistically optimise email drafts. The purpose is to make business communication more efficient and improve its quality.
The following categories of data may be processed: sender, recipient and, where applicable, other communication data (e.g. name, email address, signature details), content data from email drafts (including any personal information about third parties contained in the text), and metadata relating to the use of Outlook (e.g. time, assignment to the user account).
Processing is carried out on the basis of Art. 6(1)(b) GDPR (communication for the implementation of pre-contractual and contractual relationships) and Art. 6(1)(f) GDPR (legitimate interest in efficient, understandable and error-free business communication). Where email drafts contain special categories of personal data, processing takes place only if a corresponding legal basis pursuant to Art. 9 GDPR exists.
Recipients are the internal departments involved in the respective communication. In addition, Microsoft and, where applicable, other cloud or AI providers used may have access to content and metadata as processors. Where providers contractually reserve rights to use content and communication data for their own purposes, the controller cannot completely rule out further use of the data.
Personal data may be transferred to third countries, in particular the USA. Where possible, we rely on appropriate safeguards (e.g. EU Standard Contractual Clauses). Microsoft is certified under the EU/US Data Privacy Framework, under which legally compliant and secure data transfer is ensured. Due to the complex cloud infrastructure and the involvement of multiple subcontractors, a residual risk remains with regard to access by non-European bodies.
Email drafts processed as part of correction and optimisation are stored or deleted in accordance with the general retention and deletion periods for email communication in our company. Any temporary storage in AI services is limited to what is technically necessary.
c) Use of ChatGPT for Various Text-Based Applications
We use the AI-based service ChatGPT (provider: OpenAI, L.L.C., 3180 18th St, San Francisco, CA 94110, or affiliated companies) for internal text-based applications, e.g. creating and revising text drafts, generating ideas, summarising content or supporting the drafting of business correspondence.
As a general rule, we refrain from entering personal data into ChatGPT. Our employees are instructed not to use information that enables individuals to be identified. If, in an individual case, personal information is nevertheless contained in the prompt or uploaded texts, the following data in particular may be affected:
- master data (e.g. name, position, contact details of employees or Business Partners),
- content data from documents, emails or other texts transmitted to ChatGPT for processing,
- usage data (e.g. time, scope and content of communication with the service).
Depending on the individual case, the service is used on the basis of Art. 6(1)(f) GDPR (legitimate interest in using efficient text-based support systems and improving internal workflows) as well as Art. 6(1)(b) GDPR (insofar as text processing directly serves the preparation or performance of a contract). The entry of special categories of personal data (Art. 9 GDPR) into ChatGPT is prohibited; no such processing is carried out by us.
The recipient of the data is OpenAI or the respective operator of the AI service used. Use is based on contractual arrangements that define data protection obligations (in particular confidentiality, data security and, where applicable, processing on behalf of the controller). According to the current state of discussion, it remains unclear to what extent the underlying models themselves may contain or output personal data and whether such data may be reused for the providers’ own purposes.
The service is generally provided by providers based in a third country (in particular the USA); therefore, a transfer of personal data to third countries cannot be ruled out. Where possible, we base such transfers on appropriate safeguards within the meaning of Chapter V GDPR (e.g. EU Standard Contractual Clauses). Nevertheless, a residual risk, in particular with regard to access by public authorities in the recipient country, cannot be completely ruled out.
We have issued internal guidelines that include the following:
- no entry of personal data relating to customers, employees or other third parties into ChatGPT;
- avoidance of entries that allow persons to be identified from the context;
- no use of ChatGPT for automated individual decisions with legal effect or a similarly significant impact (Art. 22 GDPR);
- review of AI-generated results for accuracy, absence of discrimination and legal permissibility before use.
The storage period depends on the account settings we use (e.g. disabling history and training where available) and our internal deletion concepts. Permanent storage of personal data in ChatGPT is avoided by organisational measures, in particular the prohibition on entering such data.
d) Creation of Presentations with Gamma (AI Presentation Tool)
We use the cloud-based Gamma service (provider: Gamma Tech, Inc., 2261 Market Street #4544, San Francisco, CA 94114) to automatically create, structure and design presentations from text instructions and provided content. The purpose is the efficient creation of high-quality presentations and support for internal and external communication processes.
We have issued internal guidelines that include the following:
- no entry of personal data relating to customers, employees or other third parties into Gamma;
- avoidance of entries that allow persons to be identified from the context;
- review of AI-generated results for accuracy, absence of discrimination and legal permissibility before use.
Where personal data is processed when using Gamma, this concerns in particular content data entered into or uploaded to the application (e.g. texts, tables, images that may contain personal data).
We ensure that only such personal data as is necessary for the respective purpose is entered into Gamma. Processing of special categories of personal data (Art. 9 GDPR) via Gamma is generally not intended.
Processing is carried out on the basis of Art. 6(1)(f) GDPR (legitimate interest in the efficient creation and design of presentations and in improving internal processes) and – insofar as presentations serve the initiation or performance of contractual relationships – Art. 6(1)(b) GDPR.
The recipient of the data is the operator of Gamma as well as any subcontractors used by it in connection with the provision and maintenance of the platform. Where providers contractually reserve the right to use content data for their own purposes, use of data beyond pure processing on our behalf cannot be completely ruled out, as is the case with other cloud and AI services.
The service is provided by a provider based in a third country (USA); therefore, a transfer of personal data to third countries cannot be ruled out. Where possible, we base such transfers on appropriate safeguards within the meaning of Chapter V GDPR (e.g. EU Standard Contractual Clauses). Nevertheless, a residual risk, in particular with regard to access by public authorities in the recipient country, cannot be completely ruled out.
Presentations created in Gamma are stored by us only for as long as necessary for the respective purpose and unless statutory retention obligations prevent deletion. In all other respects, our general deletion concepts for documents and presentations apply.
12. Storage Periods
Unless an explicit storage period is specified when the data is collected (e.g. as part of a declaration of consent), your personal data will be deleted when it is no longer required to fulfil the purpose for which it was stored, unless statutory retention obligations (e.g. commercial and tax law retention obligations) prevent deletion.
13. Revocability of Consent Given
If you have given GF consent to process your personal data, you have the right to revoke that consent at any time with effect for the future. Revocation does not affect the lawfulness of processing carried out on the basis of consent before its revocation. After revocation, GF may continue to process personal data only insofar as GF can base the processing on another legal basis.
14. Minors
The GF websites are not directed at children under the age of 16.