×

Privacy Policy

In this Privacy Policy, we, Testfabrik Consulting + Solutions AG, inform you about the collection of personal data when using our website (docs.webmate.io). This privacy policy is based on the terms used by the European Directive and Regulatory Authority when issuing the General Data Protection Regulation (GDPR); you can find more information about this under Art. 4 GDPR.

Person Responsible

Person Responsible according to Art. 4 Par. 7 EU-General Data Protection Regulation (GDPR) is
Testfabrik AG
Fasanerieweg 15
66121 Saarbrücken Tel. +49 681 410 978-0
Email info@testfabrik.com
We have appointed a Data Protection Officer; you can reach them at datenschutz@testfabrik.com or our address with the addition „Data Protection Officer“.

Processing Activities

Calling up websites

When using our website for information purposes only, i.e. even if you do not actively transmit any further information, data such as your IP address, web browsers used by you, operating system, domain name of your internet provider, etc. will be automatically collected in the server log files. This serves the purpose of a smooth connection setup, the usability, and the stability and security of the websites and is based on our legitimate interest in improving the stability and functionality of our websites according to Art. 6 Par. 1 S. 1 lit. f GDPR. The recipients of the data may be technical service providers for the operation and maintenance of our websites who are acting on our behalf according to Art. 28 GDPR. Generally, the data is deleted after quitting the current session as it is no longer required for the aforementioned purposes.

Collection of Data through Forms

On our websites, you will find forms for individual communication (e.g., for making contact, requesting a demo appointment, etc). If you use these, the data entered in the input mask will be transmitted to us and stored. This data is typically names, company names, email addresses, telephone numbers, and possibly other information that you provide us. The legal bases for the processing of data that is transmitted to us via the contact form are Art.6 para.1 lit. f GDPR, as the purpose pursued and our legitimate interest lies in easy contact and processing of your enquiry. Insofar as the contact is aimed at the conclusion of a contract, the legal basis for processing is Art.6 para.1 lit. b GDPR (“pre-contractual measures”). The recipients of your data may be the service providers we integrate in compliance with data protection regulations. On the one hand, our websites are maintained by such providers, on the other hand, service providers can receive your data if this is necessary for the fulfilment of their respective services. The data will be deleted at the latest 6 months after the matter concerned by the enquiry has been finally clarified. If a contractual relationship arises, the statutory retention periods apply, after which your data will be deleted after 6 or 10 years.

Matomo

We use the open-source analytics service Matomo on our website. This allows us to collect and analyze data about your use of the website. The following data is collected:

  • which sections of the website are viewed
  • which elements are clicked
  • which browser version and operating system are used
  • Anonymized IP address (only the first 16 bits are recorded)
  • the approximate location of the accessing system to the accuracy of the city and the country
  • the approximate duration of stay on the different subpages
  • which browser APIs are available.

We do not use analytics cookies and host Matomo internally. However, our infrastructure sets a technically necessary cookie for load balancing. All data remains with us and is not passed on to third parties. The use is based on the legal basis Art. 6 para. 1 lit. f DSGVO (German equivalent of GDPR). Our legitimate interest lies in improving the user experience on our websites.

We respect the “Do Not Track” (DNT) option of your browser. If this is set, we do not collect any tracking information. How to activate DNT in your browser can be found in the documentation/help of your browser.

Cookies

We use so-called cookies when using our websites. These are small text files that are stored on your device. Cookies cannot run programs or transmit viruses to your device. Certain, so-called transient cookies are automatically deleted when you log out or close the browser. Other, so-called persistent cookies are automatically deleted after a specified duration, which can vary depending on the cookie.

Technically necessary cookies

For the purpose of making websites more user-friendly, efficient, and simple, certain cookies are necessary. Some functions of websites require your browser to be identified even after a page change. It is also necessary to save the settings you have chosen concerning the use of technically unnecessary cookies. The processing of cookies in this respect is carried out according to Art. 6 para. 1 lit. f GDPR, based on our legitimate interest in a user-friendly design of our website. Such data may be passed on to technical service providers if they act as contract processors according to Art. 28 GDPR for the operation and maintenance of our websites. The storage period is usually a maximum of one year, counted from the last visit to the respective website.

Additional Features and Offers

Newsletter

If you have subscribed to our newsletter on our website, we use your email address to regularly send you the newsletter and inform you about news of our products. This is done according to legal basis Art. 6 para. 1 lit. a GDPR. The distribution of the newsletter takes place with your consent. You can revoke your consent at any time to stop receiving the newsletter. For this, you can click on “unsubscribe” at the bottom of the newsletter email or the registration email, or contact us directly.

Brevo

We use the newsletter provider Brevo (Brevo GmbH, Köpenicker Straße 126, 10179 Berlin, Germany) for registration and distribution of newsletters. The data you provide to us for the newsletter are stored on Brevo’s servers within the EU. Using Brevo, we can analyze our newsletters to see whether they have been opened and which links have been clicked. This way, we can see for example, which links are particularly popular and what actions you might have taken after opening the newsletter. Furthermore, we can group the recipients of our newsletters in different groups using Brevo to better tailor our newsletters to your interests. If you don’t want your data to be analyzed by Brevo, you can unsubscribe from the newsletter at any time. In each email, you will find a link to unsubscribe. After your opt-out, your data will be erased unless they need to be retained for other reasons. If you opt out, your email address may be stored in a blacklist to prevent future mailings. These data are used for this purpose only and are not merged with other data. If you disagree, you can object to the storage. We have concluded a contract processing agreement with the service provider. More details can be found in the privacy policy of Brevo: https://www.brevo.com/de/legal/privacypolicy/.

Online Calendar Pipedrive

For scheduling appointments, we use Pipedrive Calendar (Pipedrive Inc, 490 1st Ave South, Suite 800 St. Petersburg, FL 33701, USA) within the scope of our legitimate interests in a technically flawless online offer and its economically efficient design and optimization according to Art. 6 para. 1 lit. f DSGVO. For scheduling the appointment, we request the data asked for in the Pipedrive form and record your IP address at the time of entry. This data is not shared with third parties by us and Pipedrive and is solely used by us for statistical purposes and the organization of appointments. The input of your data is encrypted, preventing third parties from reading your data during entry. For more information on the data collected by Pipedrive and how your data is handled, please refer to Pipedrive’s privacy policy at https://www.pipedrive.com/en/privacy. Your data will remain stored as long as the reason for the appointment is still relevant, particularly while the storage is still necessary for fulfilling/processing the contract, for legal action by us, or other legitimate interests, or we are legally obliged to retain your data (e.g., within the scope of tax retention periods). If your appointment is completed without further action, your data will be deleted.

Social Links

Links to the following named social media services are included on our website. After clicking the link, you will be redirected to our respective page, i.e. only then data will be transferred to the respective service. Please refer to the respective privacy policies for information on how your data is handled when using these services:

Remember, by clicking on these links, you are consenting to the transfer of data to these third-party providers. The management of this data is subject to the relevant company’s own data privacy policy. To learn more, we recommend reading these policies using the links provided.

Social Media

We use social media platforms provided by providers such as LinkedIn, Instagram and others (hereinafter referred to as providers) to represent our company and for direct communication with you, through which we maintain our presence (e.g. within the framework of company and employee profiles) and process your data.

Joint Responsibility

If data is collected on our presence that both the provider and we process and use for common purposes (e.g. within the framework of analysis or advertising), there is joint responsibility for the operator and us. Often this function cannot be deactivated by us. Therefore, you can address your concerns to both the respective provider and us. We currently use the following providers:

  • LinkedIn (including LinkedIn Sales Navigator) of LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland;
  • Instagram of Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland;
  • Twitter: X Corp. , 1355 Market Street, Suite 900, San Francisco, CA 94103
  • Vimeo Inc., 555 West 18th Street, New York, New York 10011, USA;
  • Xing from New Work SE, Dammtorstraße 30, 20354 Hamburg.

Below you will find the links to the privacy statements and information of the respective providers:

For any concerns, you can also contact the following data protection officers of the respective providers:

Informational Use of Our Presence

You can visit our presence without providing personal information. If you only use our presence for informational purposes, i.e. do not register or otherwise provide us with information about yourself, we do not process any personal data, with the exception of the data that the operator collects as part of cookies he uses and transmits to us. For the purpose of analyzing and tracking the use of his social media platform and our presence, the provider uses cookies, which allow an evaluation of your surfing behavior. This can improve the quality of the platform and presence and their content. We learn how the platform and presence are used and can thus constantly optimize our offer. However, we have neither influence on the collected data and data processing operations, nor are we aware of the full extent of data collection, the exact purposes of processing or the storage periods. We also have no information about the deletion of the collected data by the operator of the platform. Web analysis is the collection, gathering and evaluation of data on the behavior of visitors to websites. A web analysis service collects, among other things, data on which website a data subject has come to a website from (so-called referrers), which sub-pages of the website were accessed or how often and for what duration a sub-page was viewed. A web analysis is regularly used to optimize a website and for the cost-benefit analysis of internet advertising. In this context, it may also happen that the information obtained in the course of analysis and tracking of our presence is merged with your other data collected in the course of using the presence and the platform. If you register on the platform, the operator may link data regarding your platform activities with your personal data (including name/email address) based on a given consent, thus collect them personally and inform you individually and in a targeted manner, for example, about the topics you prefer. Statistics that the operator of the platform provides us with can only be influenced by us to a limited extent and cannot be switched off. However, we make sure that we are not provided with any additional optional statistics. We process your personal data on the basis of your consent pursuant to Art. 6 Para. 1 lit. a GDPR, which you have given to the provider when registering for the respective social media platform.

Active Use of the Presence

In addition to the purely informational use of our presence, you can also actively use our presence to get in touch with us. In addition to the processing of your personal data described above for purely informational use, we also process other personal data that we need, for example, to process your enquiry. This also applies in the case that we ourselves actively use the presence, for example, for initiating contact or for initiating business contacts with you.

Sharing and Publishing of and Interaction with Posts, Reviews, Photos etc.

You can comment on the platform of the provider and on our presence, share or interact in a different way (like, recommend, review etc.) with posts, photos, videos etc. created by us. Possibly, we share your contents on our presence if this is a function of the platform of the operator and communicate with you via the platform. Public messages etc. are possibly published by the operator but are never used or processed by us for other purposes. In the case of reviews, we may publish a statement (e.g. to clarify a problem, goodwill actions, etc.) in response to your message and ask you to make further contact. In this context, processing of the personal data that you voluntarily published in the review may take place. Otherwise, we only reserve the right to delete content if this should be necessary. We process your personal data to protect our legitimate interests in accordance with Art. 6 Para. 1 S. 1 lit. f GDPR. The data processing is in the interest of our public relations and communication.

User Requests

In order to process your requests to us, e.g. via contact forms, a chat or our email address, to answer them specifically and to send you the desired information, we process the personal data you provide in this context. These include your contact details, to send you a response or to ask necessary questions, as well as any other information that you transmit to us in this context. If you make a request to us via the platform, we may also refer to other, secure communication channels, depending on the required answer, which guarantee confidentiality. You always have the option to send us confidential inquiries to our address specified in the imprint or in this privacy statement. Our contact can be electronic, by telephone or by mail, depending on the subject of the inquiry and necessity. We process your personal data to answer user inquiries, request materials, etc. on the following legal bases:

  • to safeguard our legitimate interests pursuant to Art. 6 Para. 1 S. 1 lit. f GDPR; our legitimate interest is in the appropriate response or execution of customer inquiries;
  • if the request is aimed at the conclusion of a contract, additional legal basis is Art. 6 Para. 1 lit. b GDPR;
  • with your consent within the scope of using the live chat, Art. 6 Para. 1 lit. a GDPR.

Active Use of Social Media by Us

We actively use our presences on business-oriented platforms such as LinkedIn as well as linked tools such as the LinkedIn Sales Navigator to address, communicate or establish business contacts with you and to receive your application. For this purpose, we process the data that the respective platform provides us with. This can in particular include your name, your employer, your position with your employer, your education as well as further contacts on the respective platform. Depending on the type of contact with you, further data, such as the specific business relationships or the content of the communication with you, may be processed by us. Moreover, it is possible that we transfer your data in such a case to our CRM system and merge or link it with data already existing there from you. We process your personal data for addressing, communication or establishing business contacts with you (also via our CRM) on the basis of the following legal bases:

  • Your consent pursuant to Art. 6 Para. 1 lit. a GDPR, which you have given to the provider when registering for the respective social media platform, provided that it is your platform user data (name, employer, position, user behaviour on the platform, etc.);
  • to fulfill a contract or to carry out pre-contractual measures pursuant to Art. 6 Para. 1 lit. b GDPR, insofar as we already maintain a business relationship with you or carry out pre-contractual measures via the platform due to your request (e.g. further contact or communication);
  • to protect our legitimate interests according to Art. 6 Para. 1 S. 1 lit. f GDPR; our legitimate interest is in the appropriate approach, communication or establishment of business contacts with you for the establishment, execution, maintenance or termination of a business relationship with you.

Applications

When you apply for a job with us, we will process your personal data as follows: We collect information from applicants provided by them, especially: Names, addresses, date of birth, phone numbers, nationality, email address, image data (passport photo), data on school education and professional qualification, assessments and work references, information on reliability, health data (if relevant, e.g. in the case of severe disability).

We process your personal data in accordance with the provisions of the GDPR as far as necessary for the establishment, execution, design and termination of employment relationships. The legal basis for this is Art. 6 paragraph 1 lit. b GDPR. In case you give us your consent for certain types of processing, this constitutes the relevant legal basis, rendering the legality of the processing based on Art. 6 paragraph 1 lit. a GDPR (e.g. consent to be included in an applicant pool).

Recipients of application data are generally only those within the company involved in the decision-making process. There is no transfer to a third country. In case of unsuccessful applications, data is generally deleted after 3 months, unless there is consent for further storage.

Rights of the Data Subject

With regard to personal data concerning you, you have the following rights which can generally be asserted informally (e.g. via datenschutz@testfabrik.com or our postal address - preferably with the subject line “Rights of the Data Subject”).

Rights to information, correction, deletion, restriction and data portability

Every affected person has the right to information under Art. 15 GDPR, the right to correction under Art. 16 GDPR, the right to deletion under Art. 17 GDPR, the right to restriction of processing under Art. 18 GDPR, and the right to data portability under Art. 20 GDPR. Restrictions apply to the right of information and the right of deletion according to §§ 34 and 35 BDSG.

Right to object from Art. 21 GDPR

Insofar as we base the processing of your personal data on a balance of interests, you can object to the processing. Our legitimate interests are usually in answering inquiries, conducting direct marketing measures, providing services and/or information meant for you, processing and transferring personal data for internal or administrative purposes, operating and managing our websites, technical support, preventing and detecting fraud and crimes, ensuring network and data security. When exercising an objection, we ask you to explain your interests that, in your opinion, outweigh ours. In the case of your justified objection, we will either stop or adjust the data processing or show our compelling legitimate grounds on the basis of which we will continue the processing.

If you object to our processing of our (legitimate interest-based) direct advertising, no further reasons need to be given from your side; further processing will then cease without further ado.

Revocation of Consents

You can revoke your consent to the processing of personal data at any time. This also applies to the revocation of declarations of consent that were given to us before the General Data Protection Regulation came into effect, i.e., before May 25, 2018. Please note that the revocation only applies to the future. Processing that occurred before the revocation is not affected by this.

Right to lodge a complaint

Finally, you have the right to complain to a data protection supervisory authority about the processing of your personal data by us. The supervisory authority responsible for us is the Independent Data Protection Centre Saarland, Fritz-Dobisch-Straße 12, 66111 Saarbrücken.

Data Security

We take measures in accordance with Art. 32 GDPR, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, to ensure a level of security appropriate to the risk.

The measures include in particular the safeguarding of the confidentiality, integrity and availability of data by controlling physical access to the data, as well as access, input, transmission, ensuring availability and separation of data. In addition, we have set up processes that guarantee the exercise of data subjects’ rights, data deletion and response to data dangers. Furthermore, we consider the protection of personal data already in the development or selection of hardware, software and procedures, according to the principle of data protection through technology design and privacy-friendly default settings (Art. 25 GDPR).

We would like to point out that data transmission over the Internet (especially when communicating by email) can have security gaps.

Changes to the Privacy Policy

This privacy policy is current as of July 2023; however, it is subject to continuous adaptation and further development. The latest privacy policy can always be accessed at www.testfabrik.com/datenschutzerklärung.

×