Privacy Policy
We welcome you to our websites and are pleased about your interest. Protecting your personal data is an important concern for us. We therefore conduct our activities in accordance with the applicable legal provisions on the protection of personal data and on data security. In the following, we would like to inform you about which data collected during your visit is used for which purposes.
Controller Responsible for Processing under the GDPR
The controller within the meaning of the General Data Protection Regulation and other data protection laws applicable in the member states of the European Union, as well as other provisions of a data protection nature, is:
neowire GmbH
Rheinpromenade 13
40789 Monheim am Rhein
Email: contact@neowire.ai
Data Protection Officer
Nils Möllers
Keyed GmbH
Siemensstraße 12
48341 Altenberge
Email: info@keyed.de
What Is Personal Data?
The term "personal data" is defined in the German Federal Data Protection Act and in the EU GDPR. Accordingly, this means any information relating to the personal or material circumstances of an identified or identifiable natural person. This includes, for example, your civil name, your address, your telephone number, or your date of birth.
Scope of Anonymous Data Collection and Processing
Unless otherwise stated in the following sections, no personal data is generally collected, processed, or used when you use our websites. However, through the use of analysis and tracking tools we do obtain certain technical information based on the data transmitted by your browser (for example, browser type/version, operating system used, websites visited on our site including time spent, previously visited website). We evaluate this information for statistical purposes only.
Relevant Legal Bases for the Processing of Personal Data
- Insofar as we obtain the consent of the data subject for processing operations involving personal data, Art. 6(1)(a) of the EU General Data Protection Regulation (GDPR) serves as the legal basis for the processing of personal data.
- For the processing of personal data that is necessary for the performance of a contract to which the data subject is a party, Art. 6(1)(b) GDPR serves as the legal basis. This also applies to processing operations that are necessary to carry out pre-contractual measures.
- Insofar as the processing of personal data is necessary to fulfil a legal obligation to which our company is subject, Art. 6(1)(c) GDPR serves as the legal basis.
- In the event that vital interests of the data subject or of another natural person make the processing of personal data necessary, Art. 6(1)(d) GDPR serves as the legal basis.
- If the processing is necessary to safeguard a legitimate interest of our company or of a third party, and if the interests, fundamental rights, and freedoms of the data subject do not override the aforementioned interest, then Art. 6(1)(f) GDPR serves as the legal basis for the processing.
Use of Cookies
The website of neowire GmbH uses cookies. Cookies are data that are stored by the internet browser on the user's computer system. Cookies can be transmitted to a page when it is accessed and thus enable the user to be recognized. Cookies help to make the use of websites easier for users.
It is possible at any time to object to the setting of cookies by changing the settings in your internet browser accordingly. Cookies that have been set can be deleted. Please note that if cookies are deactivated, it may not be possible to use all functions of our website to their full extent. The data collected in this way is pseudonymized by technical means. It is therefore no longer possible to associate the data with the user accessing the site. The data is not stored together with any other personal data of the users. When our website is accessed, users are informed by an information banner about the use of cookies for analysis purposes and are referred to this Privacy Policy. In this context, a note is also provided on how the storage of cookies can be prevented in the browser settings. The legal basis for the processing of personal data using technically necessary cookies is Art. 6(1)(f) GDPR. The legal basis for the processing of personal data using cookies for analysis purposes is, where the user has given corresponding consent, Art. 6(1)(a) GDPR. Whether and to what extent cookies are used on our website can be found in our cookie banner and in the notes in this Privacy Policy.
Creation of Log Files
Each time the website is accessed, neowire GmbH collects data and information by means of an automated system. This data is stored in the server's log files. The data is also stored in the log files of our system. This data is not stored together with other personal data of the user.
The following data may be collected in this process:
- Information about the browser type and the version used
- The user's operating system
- The user's internet service provider
- The user's IP address
- The date and time of access
- Websites from which the user's system reaches our website (referrer)
- Websites that are accessed by the user's system via our website
Duration of Storage of Personal Data
Personal data is stored for the duration of the respective statutory retention period. After the period has expired, the data is routinely deleted, unless it is still required for the initiation or performance of a contract.
Contact Options
On the websites of neowire GmbH it is possible to make contact via the email address provided. If the data subject makes contact with the controller via this channel, the personal data transmitted by the data subject is stored automatically. Such storage serves solely for the purpose of processing the matter or making contact with the data subject. This data is not passed on to third parties. The legal basis for the processing of data that is transmitted in the course of sending an email is Art. 6(1)(f) GDPR. Where the email contact is aimed at concluding a contract, the additional legal basis for the processing is Art. 6(1)(b) GDPR. The data is deleted as soon as it is no longer required to achieve the purpose for which it was collected. For personal data sent by email, this is the case when the respective conversation with the user has ended. A conversation is deemed to have ended when it can be inferred from the circumstances that the matter concerned has been conclusively clarified.
Routine Deletion and Blocking of Personal Data
The controller processes and stores the personal data of the data subject only for as long as is necessary to achieve the purpose of storage. Storage beyond this may take place where this has been provided for by the European or national legislator in Union regulations, laws, or other provisions to which the controller is subject. As soon as the purpose of storage ceases to apply or a storage period prescribed by the aforementioned provisions expires, the personal data is routinely blocked or deleted.
Rights of the Data Subject
If personal data relating to you is processed, you are a data subject within the meaning of the GDPR and you have the following rights vis-à-vis the controller:
Right of Access under Art. 15 GDPR
You may request confirmation from the controller as to whether personal data relating to you is being processed by us. If such processing is taking place, you may request information from the controller about the following:
- the purposes for which the personal data is processed;
- the categories of personal data being processed;
- the recipients or categories of recipients to whom your personal data has been or will be disclosed;
- the planned duration for which your personal data will be stored or, if specific information on this is not possible, the criteria for determining the storage period;
- the existence of a right to rectification or erasure of your personal data, a right to restriction of processing by the controller, or a right to object to such processing;
- the existence of a right to lodge a complaint with a supervisory authority;
- all available information about the origin of the data, where the personal data is not collected from the data subject;
- the existence of automated decision-making, including profiling pursuant to Art. 22(1) and (4) GDPR and — at least in these cases — meaningful information about the logic involved as well as the significance and the envisaged consequences of such processing for the data subject.
You have the right to request information as to whether your personal data is transferred to a third country or to an international organization. In this context, you may request to be informed about the appropriate safeguards pursuant to Art. 46 GDPR in connection with the transfer.
Right to Rectification under Art. 16 GDPR
You have a right to rectification and/or completion vis-à-vis the controller, insofar as the processed personal data relating to you is incorrect or incomplete. The controller must carry out the rectification without undue delay.
Right to Erasure under Art. 17 GDPR
You may request the controller to erase your personal data without undue delay, and the controller is obliged to erase such data without undue delay, where one of the following grounds applies:
- The personal data relating to you is no longer necessary for the purposes for which it was collected or otherwise processed.
- You withdraw your consent on which the processing was based pursuant to Art. 6(1)(a) or Art. 9(2)(a) GDPR, and there is no other legal basis for the processing.
- You object to the processing pursuant to Art. 21(1) GDPR and there are no overriding legitimate grounds for the processing, or you object to the processing pursuant to Art. 21(2) GDPR.
- The personal data relating to you was processed unlawfully.
- The erasure of the personal data relating to you is necessary to fulfil a legal obligation under Union law or the law of the member states to which the controller is subject.
- The personal data relating to you was collected in relation to information society services offered pursuant to Art. 8(1) GDPR.
If the controller has made your personal data public and is obliged to erase it pursuant to Art. 17(1) GDPR, the controller shall, taking into account the available technology and the cost of implementation, take reasonable measures, including of a technical nature, to inform controllers that process the personal data that you, as the data subject, have requested from them the erasure of all links to, or copies or replications of, that personal data.
The right to erasure does not exist insofar as the processing is necessary
- for exercising the right of freedom of expression and information;
- for compliance with a legal obligation that requires processing under the law of the Union or of the member states to which the controller is subject, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
- for reasons of public interest in the area of public health pursuant to Art. 9(2)(h) and (i) as well as Art. 9(3) GDPR;
- for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes pursuant to Art. 89(1) GDPR, insofar as the right referred to above is likely to render impossible or seriously impair the achievement of the objectives of that processing; or
- for the establishment, exercise, or defense of legal claims.
Right to Restriction of Processing under Art. 18 GDPR
You may request the restriction of the processing of your personal data under the following conditions:
- if you contest the accuracy of your personal data for a period enabling the controller to verify the accuracy of the personal data;
- the processing is unlawful and you oppose the erasure of the personal data and instead request the restriction of the use of the personal data;
- the controller no longer needs the personal data for the purposes of the processing, but you require it for the establishment, exercise, or defense of legal claims; or
- if you have objected to the processing pursuant to Art. 21(1) GDPR and it has not yet been determined whether the legitimate grounds of the controller override your grounds.
Where the processing of your personal data has been restricted, such data may — apart from being stored — only be processed with your consent or for the establishment, exercise, or defense of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest of the Union or of a member state. Where the restriction of processing has been imposed in accordance with the above conditions, you will be informed by the controller before the restriction is lifted.
Right to Notification under Art. 19 GDPR
If you have exercised your right to rectification, erasure, or restriction of processing vis-à-vis the controller, the controller is obliged to notify all recipients to whom the personal data relating to you has been disclosed of this rectification or erasure of the data or restriction of processing, unless this proves impossible or involves disproportionate effort. You have the right to be informed by the controller about these recipients.
Right to Data Portability under Art. 20 GDPR
You have the right to receive the personal data that you have provided to the controller in a structured, commonly used, and machine-readable format. You also have the right to transmit this data to another controller without hindrance from the controller to whom the personal data was provided, provided that
- the processing is based on consent pursuant to Art. 6(1)(a) GDPR or Art. 9(2)(a) GDPR or on a contract pursuant to Art. 6(1)(b) GDPR; and
- the processing is carried out by automated means.
In exercising this right, you also have the right to have your personal data transmitted directly from one controller to another, insofar as this is technically feasible. The freedoms and rights of other persons must not be adversely affected as a result. The right to data portability does not apply to processing of personal data that is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.
Right to Object under Art. 21 GDPR
You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data that is based on Art. 6(1)(e) or (f) GDPR; this also applies to profiling based on those provisions. The controller will no longer process your personal data unless it can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or unless the processing serves the establishment, exercise, or defense of legal claims. Where your personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of your personal data for the purpose of such marketing; this also applies to profiling insofar as it is related to such direct marketing. If you object to the processing for direct marketing purposes, your personal data will no longer be processed for these purposes. In connection with the use of information society services, and notwithstanding Directive 2002/58/EC, you may exercise your right to object by automated means using technical specifications.
Right to Withdraw Consent under Data Protection Law pursuant to Art. 7(3) GDPR
You have the right to withdraw your consent under data protection law at any time. The withdrawal of consent does not affect the lawfulness of the processing carried out on the basis of the consent up until the withdrawal.
Right to Lodge a Complaint with a Supervisory Authority under Art. 77 GDPR
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the member state of your habitual residence, your place of work, or the place of the alleged infringement, if you consider that the processing of your personal data infringes the GDPR. The supervisory authority with which the complaint has been lodged will inform the complainant of the status and outcome of the complaint, including the possibility of a judicial remedy pursuant to Art. 78 GDPR.
Automated Decision-Making in Individual Cases, Including Profiling
You have the right not to be subject to a decision based solely on automated processing — including profiling — which produces legal effects concerning you or similarly significantly affects you. This does not apply if the decision
- is necessary for entering into, or the performance of, a contract between you and the controller;
- is authorized by Union or member state law to which the controller is subject, and such law lays down suitable measures to safeguard your rights and freedoms and your legitimate interests; or
- is based on your explicit consent.
However, these decisions may not be based on special categories of personal data pursuant to Art. 9(1) GDPR, unless Art. 9(2)(a) or (g) applies and suitable measures to safeguard your rights and freedoms and your legitimate interests have been taken. With regard to the cases referred to in points 1. and 3., the controller shall implement suitable measures to safeguard your rights and freedoms and your legitimate interests, including at least the right to obtain human intervention on the part of the controller, to express your point of view, and to contest the decision.
Integration of Other Third-Party Services and Content
Description and Purpose
It may happen that third-party content, such as videos, fonts, or graphics from other websites, is integrated within this online offering. This always presupposes that the providers of this content (hereinafter referred to as "third-party providers") are aware of the users' IP address. Without the IP address, they would not be able to send the content to the respective user's browser. The IP address is therefore necessary for the display of this content. We endeavor to use only content whose respective providers use the IP address solely to deliver the content. However, we have no influence over whether the third-party providers store the IP address, for example for statistical purposes. Insofar as this is known to us, we inform users accordingly. We wish to provide and improve our online offering through these integrations.
Legal Bases
The legal basis for the integration of other third-party services and content is Art. 6(1)(f) GDPR. Our overriding legitimate interest lies in the intention to present our online presence appropriately and to provide user-friendly and economically efficient services on our part. For further information, please refer to the respective privacy notices of the providers.
Contractual or Legal Obligation to Provide Personal Data
The provision of personal data is neither required by law nor by contract, nor is it necessary for the conclusion of a contract. You are also not obliged to provide the personal data. However, failure to provide it may result in you not being able to use this function, or not being able to use it to its full extent.
Data Transfer to Third Countries
The controller may transfer personal data to a third country. In principle, the controller can ensure, by means of various appropriate safeguards, that an adequate level of protection is achieved for the processing operations. There is the possibility to transfer data on the basis of an adequacy decision, binding internal data protection rules, approved codes of conduct, standard data protection clauses, or an approved certification mechanism pursuant to Art. 46(2)(a) – (f) GDPR.
Insofar as the controller carries out a transfer to a third country on the legal basis of Art. 49(1)(a) GDPR, you are informed at this point about the possible risks of a data transfer to a third country.
There is a risk that the third country receiving your personal data may not be able to provide a level of protection equivalent to the protection of personal data in the European Union. This may be the case, for example, if the EU Commission has not adopted an adequacy decision for the respective third country, or if certain agreements between the European Union and the respective third country are declared invalid. Specifically, in some third countries there are risks with regard to the effective protection of EU fundamental rights due to the use of surveillance laws (for example, the USA). In such a case, it is the responsibility of the controller and the recipient to assess whether the rights of the data subjects in the third country enjoy a level of protection equivalent to that in the Union and can also be effectively enforced.
However, the level of protection guaranteed across the Union for natural persons should not be undermined by the General Data Protection Regulation when personal data is transferred from the Union to controllers, processors, or other recipients in third countries or to international organizations, including where personal data is onward-transferred from a third country or an international organization to controllers or processors in the same or another third country, or to the same or another international organization.
Additional Website Functions
Cloudflare
Description and Purpose
The operator of this website uses the functions of Cloudflare. The provider is Cloudflare, Inc., 665 3rd St. #200, San Francisco, CA 94107, USA. Cloudflare offers a so-called globally distributed content delivery network with DNS. Technically, the transfer of information between your browser and our web pages is routed via Cloudflare's network. Cloudflare is thereby able to analyze the data traffic between you and our website, for example in order to detect and defend against attacks on our services. In addition, Cloudflare may store cookies on your computer for optimization and analysis purposes. The following personal data is processed: information about visitors and/or authorized users of a customer's domains, networks, websites, application programming interfaces ("APIs") or applications; IP addresses.
Legal Basis
The legal basis for the processing of your personal data is Art. 6(1)(a) GDPR (setting of cookies) and Art. 6(1)(f) GDPR (processing for the purpose of analyzing and defending against attacks on the services). In the case of processing on the basis of Art. 6(1)(f) GDPR, the legitimate interest lies in the secure and effective provision and operation of our services.
Recipient
The recipient is Cloudflare Germany GmbH, Rosental 7, c/o Mindspace, 80331 Munich, Germany.
Transfer to Third Countries
The personal data is transferred to the United States (Cloudflare's headquarters). The transfer takes place subject to appropriate safeguards pursuant to Art. 46 GDPR. For this purpose, we have concluded standard contractual clauses with the data importer. Furthermore, we are aware of our responsibility and, where necessary, take additional measures to protect the rights and freedoms of natural persons that ensure the protection of personal data.
Duration of Data Storage
The data is deleted as soon as it is no longer required to achieve the purpose for which it was collected. In addition, the data is deleted if you exercise your right to erasure within the meaning of Art. 17(1) GDPR.
Withdrawal or Objection
In the case of processing of your personal data on the basis of Art. 6(1)(a) GDPR, you have the right to withdraw the consent you have given at any time, cf. Art. 7(3) sentence 1 GDPR. This can be done informally and without stating reasons and takes effect for the future. The withdrawal of consent does not affect the lawfulness of the processing carried out up until the withdrawal. You can find further information on this above in our Privacy Policy under "Rights of the Data Subject."
In the event that the legal basis for the processing of your personal data is Art. 6(1)(f), you have the right under Art. 21(1) GDPR to object at any time to the processing of your personal data. If you exercise your right, processing for this purpose will no longer take place. You can find further information on this above in our Privacy Policy under "Rights of the Data Subject."
Contractual or Legal Obligation
There is no contractual or legal obligation to provide the data.
Further Data Protection Notices
You can find further information on the processing of your personal data here: https://www.cloudflare.com/de-de/gdpr/introduction/
Job Applications (Apprenticeships & Vacancies)
By submitting an application to us, applicants consent to the processing of their data for the purposes of the application procedure in accordance with the nature and scope set out in this Privacy Policy. The legal basis for the processing of applicant data is Art. 88 GDPR, § 26 BDSG (new), and Art. 9(2)(b) GDPR. Insofar as special categories of personal data within the meaning of Art. 9(1) GDPR are voluntarily disclosed during the application procedure, their processing is additionally carried out pursuant to Art. 9(2)(b) GDPR (e.g., health data such as severe disability status or ethnic origin). Insofar as special categories of personal data within the meaning of Art. 9(1) GDPR are requested from applicants during the application procedure, their processing is additionally carried out pursuant to Art. 9(2)(a) GDPR (e.g., health data, where this is required for the exercise of the profession). Where provided, applicants can submit their applications to us by means of an online form on our website. The data is transmitted to us in encrypted form in accordance with the state of the art. Applicants can also submit their applications to us via email. In this regard, however, we ask you to note that emails are generally not sent in encrypted form and that applicants must ensure encryption themselves. We can therefore not accept responsibility for the transmission path of the application between the sender and receipt on our server, and we therefore recommend using an online form or postal delivery instead. Because instead of applying via the online form and email, applicants still have the option of sending us their application by post. The data provided by applicants may, in the event of a successful application, be further processed by us for the purposes of the employment relationship. Otherwise, if the application for a vacancy is not successful, the applicant's data is deleted. The applicant's data is also deleted if an application is withdrawn, which applicants are entitled to do at any time. Deletion takes place after a period of six months has elapsed, so that we can answer any follow-up questions regarding the application and comply with our obligations to provide evidence under the German General Equal Treatment Act. Invoices for any reimbursement of travel expenses are archived in accordance with tax law requirements.
Data Recipients
Insofar as this is legally permitted or required, or insofar as you have consented, we also share your personal data with other recipients who provide services for us. In doing so, we limit the disclosure of your personal data to what is necessary. In some cases, our service providers receive your personal data as processors and are then strictly bound by our instructions when handling your personal data (data processing agreement pursuant to Art. 28 GDPR). In some cases, the recipients act independently with the data that we transmit to them. The following categories of service providers/recipients may receive your data:
- Providers of email marketing via newsletter
- Providers of hosting services for the operation of our servers
- Service providers in the area of applications to support the selection of applicants
- Service providers for development work, including programming, development, maintenance, and support of software applications
- Service providers for postal services
- External legal advisors
- Marketing agencies / website management
- Other IT service providers (e.g., system houses)
- Other services and tools
The service providers we engage must meet strict confidentiality requirements. They are granted only the access to your data that is necessary to perform the assigned tasks.
In the event of suspicion of a criminal offense, data may be passed on to law enforcement authorities.
Security
We have taken extensive technical and operational protective measures to protect your data against accidental or intentional manipulation, loss, destruction, or access by unauthorized persons. Our security procedures are reviewed regularly and adapted to technological progress. In addition, data protection is continuously ensured at our company through the ongoing auditing and optimization of the data protection organization.
Conclusion
neowire GmbH reserves all rights to make changes and updates to this Privacy Policy. This Privacy Policy was created by Keyed GmbH.