Privacy Policy
Below, we provide information about how your personal data is processed when you visit our online platforms and, where applicable, during any subsequent processes.
According to Article 4(1) of the GDPR, personal data refers to any information relating to an identified or (in combination with other data) identifiable natural person, or from which such a person can be identified. According to Article 4(2) of the GDPR, “processing” means any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment or combination, restriction, erasure, or destruction.
Unless otherwise specified below, the provision of your personal data is not required by contract or by law, is not necessary for the conclusion of a contract, and is not otherwise mandatory; therefore, failure to provide such data will not result in any adverse consequences for you.
Our Privacy Policy is organized as follows:
I. Data Controller | Data Protection Officer
II. Data Processing Through Our Website
III. Data Processing in Customer Satisfaction Surveys
IV. Data Processing When Using an Electronic Signature
V. Data Processing in Connection with Job Applications
VI. Data Processing When Visiting Our Company’s LinkedIn Page
VII. Data Processing When Visiting Our Company’s Social Media Pages on Facebook and Instagram
VIII. Your Rights
I. Data Controller | Data Protection Officer
The entity responsible for processing your personal data is:
IT Sonix Custom Development GmbH (hereinafter „we“)
Georgiring 3
04103 Leipzig
Phone: +49 341 355 76-0
Email: info@itsonix.eu
You can contact our Data Protection Officer at:
EPRO Consult GmbH
Email: itsonix-gmbh@epro-consult.de
II. Data Processing Through Our Website
Unless otherwise specified below, we will delete the personal data processed when you use our website immediately after the respective purpose of processing has been achieved or no longer applies. Any storage beyond this period is based exclusively on our legitimate interest in asserting, enforcing, and defending our legal claims for the duration of any contractual or statutory limitation periods, as well as to comply with retention periods to which we are legally obligated, for example, under commercial or tax law. In cases where statutory retention periods apply, personal data will be blocked for further processing rather than deleted.
Server Log Files
When you visit our website, data is automatically transmitted to us or our web hosting provider and stored in so-called server log files to log requests and visits to our website, as well as error messages from our website. This data processing is technically necessary to ensure a secure and stable website. The following data is stored temporarily:
- Information About the Browser You Are Using
- Information About the Operating System in Use
- URL of the website visited
- Date and time of access
- Amount of data sent
- Website from which the user was redirected to our website (referrer URL)
- IP address
The data is used solely for statistical analysis and to improve our website; it is not stored together with other personal data relating to you and is automatically deleted after 7 days. It is stored for a longer period only in exceptional cases, when this is necessary for evidentiary purposes based on concrete indications of unlawful use.
Your personal data is processed to safeguard our legitimate interests in the stability, security, functionality, and optimization of our website, in accordance with Article 6(1)(f) of the GDPR.
Contact
If you contact us by email or through our contact form, we will receive and process the personal data you provide (specifically, your name, email address, and the content of your message) in order to handle your inquiry.
If your inquiry is intended to lead to the conclusion of a contract (e.g., requests for quotes) or relates to a contract already in place between you and us, your personal data will be processed for the purpose of carrying out the requested precontractual measures or for the performance of the existing contract in accordance with Article 6(1)(b) of the GDPR.
In all other cases, your personal data is processed to safeguard our legitimate interest in handling and responding to your inquiry, pursuant to Article 6(1)(f) of the GDPR.
Online Appointment Scheduling and Conducting Meetings
You have the option to request or book appointments with us via links provided in emails or on our website. In this context, we process the personal data you provide when scheduling an appointment or that is generated during your use of the service, including, in particular, your name, your business contact information, your company, your job title, preferred appointment dates, voluntary information provided in the inquiry field, and technical usage data related to accessing and using the appointment scheduling feature.
Your personal data is processed for the purpose of initiating, organizing, and conducting meetings with prospective clients, customers, and other business partners, as well as for preparing for and following up on these meetings.
To the extent that the scheduling of an appointment is related to the initiation or performance of a contract, the legal basis for the processing is Article 6(1)(b) of the GDPR. In all other cases, the processing is carried out to safeguard our legitimate interest in the efficient organization and conduct of business communications, as well as in user-friendly appointment scheduling, pursuant to Article 6(1)(f) of the GDPR.
We may use external service providers to organize appointments and document communications. If meetings are held online, we use Microsoft Teams for this purpose. In the course of conducting online meetings, participant data, connection data, technical usage data, and the content of communications may be processed, to the extent necessary for conducting the respective meeting.
To the extent that external service providers are engaged in connection with scheduling appointments and conducting meetings, this is done within the framework of data processing on behalf of the controller or another arrangement permitted under data protection law. Personal data will be transferred to third countries only if the specific requirements of Articles 44 et seq. of the GDPR are met.
As a general rule, your personal data will be stored only for as long as is necessary to process your inquiry, conduct the appointment, and handle the preparation and follow-up for the meeting. If the contact leads to a further business relationship, additional processing may take place in accordance with statutory retention requirements or to assert, exercise, or defend legal claims.
HubSpot
To manage contact information, schedule appointments, and document inquiries and communications, we use the HubSpot service provided by HubSpot Ireland Limited, 2nd Floor, 30 North Wall Quay, Dublin 1, Ireland, and HubSpot Inc., 25 First Street, Cambridge, MA 02141, USA, under a data processing agreement. Processing may also take place in the United States. The transfer of personal data is based on the Adequacy Decision regarding the EU-U.S. Data Privacy Framework and, additionally, on appropriate safeguards within the meaning of Articles 44 et seq. of the GDPR.
Microsoft Teams
When online meetings are held with us, we use Microsoft Teams, a service provided by Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. When using Microsoft Teams, the following data may be processed in particular: participant data, meeting details, connection data, device/usage data, and communication content—to the extent necessary for conducting the online meeting.
Data processing is carried out for the purpose of conducting business communications, discussing inquiries, projects, and contract terms, as well as preparing for and following up on related meetings. To the extent that such discussions take place in connection with the initiation or performance of a contract, the legal basis is Article 6(1)(b) of the GDPR. In all other cases, processing is based on our legitimate interest in efficient and timely communication with prospective clients, customers, and business partners pursuant to Article 6(1)(f) of the GDPR.
To the extent that personal data is transferred to recipients outside the European Union or the European Economic Area in connection with the use of Microsoft Teams, such transfers are made only in compliance with the specific requirements set forth in Articles 44 et seq. of the GDPR.
For more information about data protection at Microsoft, visit: https://www.microsoft.com/de-de/privacy/privacystatement. For additional information on data collection in Microsoft Teams, see: https://www.microsoft.com/de-de/privacy/data-collection-teams.
IT-Sonix Newsletter
You have the option to subscribe to our IT-Sonix newsletter. In this case, we will store and process the data you provide during registration (email address and, if applicable, optional information such as your name) in order to send you, as requested, email promotions and other information about our services, events, news, and other company-related topics. In addition, we collect the IP address you used during registration, as well as the date and time of registration.
Your personal data is processed based on your consent in accordance with Article 6(1)(a) of the GDPR. To confirm your consent, we use the so-called double opt-in procedure, in which you will receive a one-time confirmation link via email after signing up. Only after you click this link will your data be permanently added to our newsletter distribution list. If you do not confirm your registration within one week, your data will be automatically deleted.
HubSpot
To manage newsletter subscriptions and the associated contact information, we use the HubSpot service provided by HubSpot Ireland Limited, 2nd Floor, 30 North Wall Quay, Dublin 1, Ireland, and HubSpot Inc., 25 First Street, Cambridge, MA 02141, USA, under a data processing agreement. Processing may also take place in the United States. The transfer of personal data is based on the Adequacy Decision regarding the EU-U.S. Data Privacy Framework and, additionally, on appropriate safeguards within the meaning of Articles 44 et seq. of the GDPR.
Lemlist
We use the Lemlist service provided by Lempire SAS, 128 rue La Boétie, 75008 Paris, France, on a data processing basis to organize, send, and manage our IT-Sonix newsletter.
In connection with the distribution of the newsletter, delivery and status data, in particular, may be processed. To the extent that any analysis is conducted in connection with the newsletter, it is limited to aggregated metrics that do not relate to individual recipients, specifically for the purpose of measuring general reach, improving deliverability, and optimizing our newsletter service from a technical and organizational standpoint. We do not conduct any individual analysis of the behavior of specific recipients.
Withdrawal
You may revoke your consent to receive the IT-Sonix newsletter at any time, effective for the future. You will find an unsubscribe link at the bottom of each newsletter. Alternatively, you can also revoke your consent by sending an email to vertrieb@itsonix.eu align.
Retention period
Your data will be stored for the duration of your subscription to the newsletter. After you unsubscribe from the newsletter or revoke your consent, your personal data will be deleted, provided that no legal retention requirements prevent this. If only aggregated statistical information remains after you stop receiving the newsletter, this information no longer allows for any identification of individual recipients.
Cookies | Third-Party Content
Our website stores cookies or uses similar technologies, which we use to provide certain features.
Cookies are small text files that are placed and stored on your device by your browser. Cookies contain a unique string of characters that allows your browser to be recognized when you visit the website again. In doing so, certain information—including personal data such as location data and your IP address (in anonymized form, if applicable)—may be processed to varying degrees.
You can find all the details regarding the processing of your personal data that takes place in each instance—in particular, whether it occurs with or without your consent—in the relevant sections of this Privacy Policy.
You have full control over the use of cookies on your device and can restrict or prevent their storage by adjusting certain settings in your browser. Cookies that have already been stored can also be deleted at any time in your browser settings. In such cases, however, you may not be able to use all features of our website to their full extent.
Technically Necessary Cookies – Overview
We use technically necessary cookies on our website—that is, cookies that are essential for the operation of our website and make our services more user-friendly, secure, and effective.
These cookies are stored in accordance with § 25(2) of the TDDDG. To the extent that personal data is processed in this context, this is done to safeguard our legitimate interests in ensuring a secure and stable online presence, optimal functionality, and a user-friendly and effective design of our website, in accordance with Article 6(1)(f) of the GDPR. You have the right to object to the processing of your personal data for reasons arising from your particular situation (e.g., by adjusting the settings in your browser accordingly).
The following technically necessary cookies are stored through our website:
| Name | Description (Stored Information and Purpose) | Domain | Duration |
|---|---|---|---|
| grav-site-430ee58 | CMS session cookie to ensure a smooth website experience | itsonix.eu | 30 minutes |
| matomo_sessid | Matomo session cookie used to provide the opt-out feature, without visitor or analytics data | analytics.itsonix.eu | Meeting, up to 14 days |
| mtm_consent* | Recording of the Objection to Tracking | itsonix.eu | 1 year |
| complianceCookie | Storing the Website Visitor's Cookie Preferences | itsonix.eu | 1 year |
Matomo
We use the web analytics tool Matomo to analyze user behavior on our website. Matomo is hosted on our own servers, so the information collected when you use our website is not shared with third parties.
Data collection is based on a privacy-friendly configuration. Information from server log data as well as certain technical information about your device is processed in order to statistically analyze the use of our website and identify repeat visits. In particular, this may include information about your browser type, operating system, language settings, screen resolution, and a truncated IP address. Your IP address is truncated before processing so that it is not possible to directly identify individual users.
You may opt out of the statistical tracking of your visit at any time, effective for the future. Your data is processed exclusively on our server.
Information on Data Processing:
- Provider:
We ourselves (local hosting of the Matomo software) - Purpose:
Statistical analysis of website usage to optimize content and functionality - Legal basis:
Processing of Personal Data: Article 6(1)(f) of the GDPR (legitimate interest in web analytics) - Data processed:
truncated IP address, pages visited, time of access, duration of visit, technical information about the browser, operating system, screen resolution, language settings, referrer URL - Retention period:
Technical identification characteristics: max. 25 hours; analysis data: max. 6 months - Transfers to third countries:
Cancelled - Objection:
You can opt out of having your visit tracked for statistical purposes at any time by adjusting your cookie settings: Open Cookie Settings.
Uncheck the box next to „Matomo Tracking“ and save your selection. Your data will then no longer be processed for analysis.
For information on Matomo's privacy policy, please visit: https://matomo.org/privacy-policy/
YouTube (external video player)
We use YouTube on our website to display video content. For privacy reasons, video playback is disabled by default and will only be loaded after you have given your explicit consent (2-click solution).
When you activate the video (by clicking „Load Video“), a connection is established to YouTube’s servers. In the process, personal data (such as your IP address, location data if applicable, technical device information, and information about your use of YouTube features) is transmitted, and information on your device is accessed (e.g., through cookies or similar technologies). We use YouTube’s enhanced privacy mode, which, according to YouTube, ensures that data is not actually transmitted until the video begins playing.
If you are signed in to your Google account via your browser when the video is loading, YouTube (Google) may associate this information with your Google account. If you wish to prevent this association, you must sign out of your Google user account before using the service or adjust your account settings accordingly.
Consent to Borlab's Cookies
Our website uses Borlabs Cookie’s consent technology to obtain your consent to the storage of certain cookies in your browser or to the use of certain technologies, and to document this in compliance with data protection regulations. This technology is provided by Borlabs GmbH, Hamburger Str. 11, 22083 Hamburg (hereinafter “Borlabs”).
Information on Data Processing:
- Provider:
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (with data transferred to Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) - Purpose:
Integration of multimedia content to enhance the user experience - Legal Basis:
Access to Terminal Equipment: § 25(1) TDDDG
Processing of Personal Data: Art. 6(1)(a) of the GDPR (Consent of the Data Subject) - Data Processed:
IP address, location data (if shared by the browser), device information, referrer URL (if applicable), browser data, information about the use of embedded videos - Retention period:
May vary depending on the type of cookie and usage patterns (in some cases, several months) - Transfers to third countries:
Data may be transferred to the United States.
Google LLC is certified under the EU–U.S. Data Privacy Framework (DPF), which ensures an adequate level of data protection in accordance with Article 45 of the GDPR. - Voluntary participation:
Consent is voluntary and is not required to use the website in any other way. - Right of Withdrawal:
You can revoke your consent at any time by refreshing the page. The video will then not be reloaded.
For more information about data protection when using YouTube, please visit:https://policies.google.com/privacy and in the Terms of Use at: https://www.youtube.com/t/terms
Social media links via graphics or text links
We also promote our presence on the social networks listed below on our website. This is done by embedding a linked image from the respective network. The use of this linked graphic prevents a connection from being automatically established with the respective social network’s server when a website featuring a social media promotion is accessed, in order to display an image from that network itself. Only when the user clicks on the corresponding graphic will they be redirected to the respective social network’s service.
After the user is redirected, the respective network collects information about the user. It cannot be ruled out that the data collected in this manner may be processed in the United States.
This initially includes data such as the IP address, date, time, and page visited. If the user is logged into their account on the respective social network during this time, the network operator may be able to associate the information collected during the user’s specific visit with the user’s personal account. If the user interacts with a „Share“ button on the respective network, this information may be stored in the user’s personal account and, if applicable, published. If the user wishes to prevent the collected information from being directly associated with their user account, they must log out before clicking the button. It is also possible to configure the respective user account accordingly.
The following social media platforms are linked to our site:
LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland, a subsidiary of LinkedIn Corporation, 1000 W. Maude Avenue, Sunnyvale, CA 94085, USA. Privacy Policy: https://www.linkedin.com/legal/privacy-policy
Data Processing in Connection with the World Usability Day (WUD) Event
WUD Newsletter
You have the option to subscribe to our WUD newsletter. If you do so, we will store and process the data you provide during registration (email address and, if applicable, optional information such as your name) in order to send you email advertisements and other information as requested. In addition, we collect the IP address you used during registration, as well as the date and time of registration.
Your personal data is processed based on your consent in accordance with Article 6(1)(a) of the GDPR. To confirm your consent, we use the so-called double opt-in procedure, in which you will receive a one-time confirmation link via email after signing up. Only after you click this link will your data be permanently added to our newsletter distribution list. If you do not confirm your registration within one week, your data will be automatically deleted.
CleverReach
We use the CleverReach service provided by CleverReach GmbH & Co. KG (Mühlenstr. 43, 26180 Rastede, Germany; hereinafter „CleverReach“) as part of a data processing agreement. Your personal data is stored and processed on CleverReach’s servers in Germany. In particular, CleverReach allows us to analyze how many recipients have opened our newsletter and how often each link in the newsletter was clicked. You can find information on data protection at CleverReach at: https://www.cleverreach.com/de/datenschutz/
Registration (via Guestoo) and Participation in the WUD
To participate in or register for our events (especially WUD), we use the online event and ticket management platform „Guestoo,“ which is operated by code piraten GmbH, Am Ruhmbach 44, 45149 Essen.
If you would like to register on our site and click the corresponding button or link, you will be redirected to the Guestoo website.
As part of the technical setup and operation of the platform, Guestoo may process personal data on its own. We have no control over this. For more information on Guestoo’s data processing, please see Guestoo’s privacy policy at https://www.guestoo.de/datenschutzerklaerung.
To the extent that Guestoo collects, stores, and transmits personal data to us as the event organizer in connection with registration for our events, it does so on our behalf. To ensure an adequate level of data protection, we have entered into a data processing agreement with the service provider.
Guestoo collects personal data when you voluntarily provide such information as part of your registration for one of our events and subsequently transmits this data to us as the event organizer. To register for an event with Guestoo, you must provide Guestoo with the following information, among other things:
- Last Name, First Name
- Email address
- Event ID
- IP address
- Characteristics of the access device and/or browser
As the event organizer, Guestoo provides us with access to the following data regarding participants in the registered event: last name, first name, and email address. We use this data for the purposes of preparing for and following up on the respective registered events. In addition, registered participants receive information about the respective event and our contact details via email before and after the registered event. The processing of this data is based on Article 6(1)(b) of the GDPR.
You can opt out at any time of the future use of this data for advertising purposes via the platform www.guestoo.de, through which you registered. If you made a booking with us outside of Guestoo Events, please send your cancellation request to wud.leipzig@itsonix.eu.
In connection with in-person participation in the event, we process participants’ data to create a participant list at the registration desk and to prepare name tags. The purpose is to monitor capacity at the event venue. To improve future event planning, we also use data on event attendance to analyze event participation and capacity utilization. This processing is based on Article 6(1)(f) of the GDPR.
Participants' data will be deleted 12 months after the event.
III. Data Processing in Customer Satisfaction Surveys
Email Invitation
In certain cases, we send our customers email invitations to participate in a customer satisfaction survey.
The legal basis in this case is Article 6(1)(f) of the GDPR. Our legitimate interest lies in improving and optimizing our services and products. The purpose of the customer survey is to identify opportunities for improvement in our collaboration with current project clients, as well as clients„ future strategic and sales needs. You may object to the processing of your data for the purpose of the “customer satisfaction survey” at any time for reasons arising from your particular situation, provided you specify those reasons (Article 21(1) of the GDPR): Link to the survey
In the event of a valid objection, we will generally no longer process the personal data for the purposes in question and will delete the data, unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the processing is necessary for the establishment, exercise, or defense of legal claims.
Participation in the Customer Satisfaction Survey – Consent Form
If you participate in the survey, we will ask you a few questions about customer satisfaction with our services and products. We conduct the survey ourselves on our „Lime Survey“ platform. The survey results are analyzed exclusively by us in Germany.
The survey may not be anonymous (voluntary disclosure of name/position). In the event of particularly negative or positive feedback, we would like to contact the customer („customer-specific feedback“). Customer-specific feedback is deleted 90 days after the process is completed (including clarification/communication) and transferred to the customer satisfaction survey analysis as „project-related survey results.“ Your data is processed exclusively on the basis of your consent (Art. 6(1)(a) GDPR).
You may revoke your consent to personalized analysis and any subsequent contact at any time, with future effect, in accordance with Article 7(3) of the GDPR. To do so, simply notify us of your revocation: sales@itsonix.eu
Survey Analyses – Project-Specific Survey Results
Survey data is analyzed without reference to specific individuals, but only in relation to the client name (company) and the project. All relevant analysis results (project-related survey results) are retained for up to 5 years.
IV. Data Processing When Using an Electronic Signature
We use the LIONWARE software—the MultiConnect Portal from Lionware GmbH, located at Im Kaisemer 13a, 70191 Stuttgart, Germany („Lionware“)—for the digital signing of contracts and documents ready for signature.
For this purpose, Lionware processes the data you enter when using the electronic signature services, usage data from your device, and transaction-related data. The legal basis is Article 88(1) of the GDPR in conjunction with Section 26(1) of the BDSG, or for the purpose of fulfilling a contract with the data subject based on Article 6(1)(b) and (f) of the GDPR. The legitimate interest lies in the efficient and cost-effective processing of the signing of contracts and documents.
Failure to provide this data may result in the inability to generate an electronic signature. We transfer personal data to employees, customers, and the relevant departments within the company. We have entered into a data processing agreement with Lionware. Lionware stores all personal data on servers located within the EU. For more information on data processing by Lionware, please click here: https://www.lionware.de/datenschutzhinweise/.
We retain the data collected for the electronic signature until the expiration of the statutory retention period of 10 years following the termination of the respective digitally signed contract. Upon expiration of this period, the data collected for the electronic signature will be deleted.
V. Data Processing in Connection with Job Applications
If you apply via email or through our application form on our website—either as a speculative application or in response to a job posting we have published—we will receive and process your personal data to the extent you provide it. Within our company, only those departments that need your data to perform their duties and are authorized to do so will have access to it. Your data will not be shared with third parties.
Your personal data is processed pursuant to Article 6(1)(b) of the GDPR for the purpose of conducting the application process and, thereby, carrying out the precontractual measures you have requested.
If you are hired following a successful application process, we will store your application documents in your personnel file for organizational and administrative purposes. This processing of your data is also based on Article 6(1)(b) of the GDPR for the purpose of performing your employment contract.
If your application is rejected, we will delete your personal data without being asked no later than 6 months after notifying you of the rejection. This storage is based on our legitimate interest in defending and enforcing our rights pursuant to Article 6(1)(f) of the GDPR. You have the right to object to the processing of your personal data by notifying us, for reasons arising from your particular situation.
Only if you expressly consent to the longer-term storage of your application documents—for example, for inclusion in our applicant database—will we store and process your personal data beyond the 6 months following notification of rejection. In this case, the continued processing of your personal data is based on your consent pursuant to Article 6(1)(a) of the GDPR. You may revoke your consent at any time in accordance with Article 7(3) of the GDPR by notifying us, effective for the future, without affecting the lawfulness of any processing that took place prior to the revocation. We will then delete your personal data without delay.
softgarden
Our online application portal is technically operated by our service provider, softgarden E-Recruiting GmbH, Tauentzienstraße 14, D-10789 Berlin (hereinafter: Softgarden). Softgarden provides only software and computing resources and otherwise has no influence on the application process. This constitutes data processing on behalf of the controller pursuant to Article 28 of the GDPR. Softgarden is contractually obligated to ensure the protection of your personal data through technical and organizational measures. Your data is stored in a secure operating environment that is not accessible to the public. Your data is encrypted during transmission using Transport Layer Security (TLS). This means that communication between your computer and the data servers used takes place using a recognized encryption method. For more information on the collection of data on the products and websites operated by Softgarden, please refer to Softgarden’s Privacy Policy:
- https://softgarden.com/de/datenschutz-software-und-service/
- https://softgarden.com/de/datenschutz-website/
Subscribe to Job Listings
If you subscribe to our job postings, we will process your email address so that we can notify you of new job openings via email.
The legal basis for this is Article 6(1)(a) of the GDPR. You may revoke your consent to this subscription at any time with future effect in accordance with Article 7(3) of the GDPR. To do so, you simply need to notify us of your revocation or click the unsubscribe link included in the respective email.
VI. Data Processing When Visiting Our Company’s LinkedIn Page
Person in Charge
Below is an overview of how we collect and process your personal data through our online presence on the social media platform:
- LinkedIn: https://www.linkedin.com/company/it-sonix-custom-development-gmbh/, hereinafter referred to as „LinkedIn profile“
In addition to us, the following operators of the respective social media platforms (hereinafter referred to as „Providers“) are also data controllers for data processing via our LinkedIn social media profile:
LinkedIn Ireland Unlimited Company (hereinafter „LinkedIn“)“
Attn: Legal Department (Privacy Policy and User Agreement)
Wilton Plaza
Wilton Place, Dublin 2
Ireland
Please note that you use our social media pages and their features—as well as social media platforms in general—at your own risk. This applies in particular to the use of interactive features (e.g., liking, commenting, sharing, rating). For more information and contact details, please visit:
Terms of Use: https://de.linkedin.com/legal/user-agreement
Data Policy: https://de.linkedin.com/legal/privacy-policy
Data Protection Officer's Contact Form: https://www.linkedin.com/help/linkedin/ask/TSO-DPO
The operators of the social media platforms are available to you as your primary point of contact. However, you may also exercise your rights regarding processing carried out under joint responsibility by contacting us. If you contact us, we will coordinate with the respective provider to respond to your request and ensure your rights as a data subject are protected.
Information on Data Processing
We maintain our LinkedIn profile to highlight our services and offerings and to interact with our customers and visitors to social media platforms (hereinafter referred to as „users“).
When you use our LinkedIn profile, personal data is processed. The following information explains the nature and scope of the data processing for which we are responsible under data protection law in this context.
We do not store any personal data regarding your use of the respective social media sites.
Information that you post on our respective social media pages (e.g., comments) or send via the respective messaging service is stored by the provider based on your user relationship and can be deleted by you there.
Processing of usage data under the joint responsibility of LinkedIn and us
When you visit our LinkedIn profile, LinkedIn also uses certain usage data (e.g., whether you have „liked“ or commented on specific posts of ours) to provide us with aggregated usage statistics (known as „Page Insights“). Usage statistics do not allow for any conclusions to be drawn about the behavior of individual users; rather, they simply provide us with an overview of the usage of our social media pages (e.g., which posts were clicked on particularly frequently). We ourselves do not have access to the personal data processed for the creation of these statistics. LinkedIn alone determines which user actions are logged on the social media platforms; we cannot set up, change, or otherwise influence this.
We use usage statistics provided by LinkedIn regarding our social media pages to improve the posts published there and make them as interesting as possible for users. This processing is based on a balancing of interests pursuant to Article 6(1), first sentence, letter f of the GDPR, which always takes your interests into account as well. If you are registered on LinkedIn yourself, the processing is also carried out in accordance with Article 6(1), first sentence, letter b of the GDPR, as well as in accordance with the terms of service that apply between you and LinkedIn.
With regard to the processing of personal data for the purpose of compiling these usage statistics, LinkedIn and we are joint controllers in accordance with Article 26 of the GDPR.
Information about LinkedIn Page Insights (https://legal.linkedin.com/pages-joint-controller-addendum) describe what data is processed under the joint controllership arrangement and include the „Page Insights Addendum,“ in which LinkedIn and we have contractually specified who fulfills which obligations under the GDPR.
Processing of Your Data When You Communicate with Us Through Our LinkedIn Page
If you contact us through our LinkedIn page—for example, by commenting on a post or sending a message via LinkedIn Messenger—we will process your data (such as your name and the content of your communication) in order to address your inquiry.
To the extent necessary, we also process your data to assert legal claims and defend ourselves in legal disputes, as well as to prevent and investigate criminal offenses (e.g., hate speech or inflammatory comments).
The legal basis for processing the data transmitted when contacting us is Article 6(1)(f) of the GDPR. If the purpose of establishing contact is to enter into a contract or if it takes place within the framework of an existing contractual relationship, the additional legal basis for processing is Article 6(1)(b) of the GDPR.
Your data will be deleted once your inquiry has been fully resolved and provided that no legal retention requirements prevent its deletion—such as in the case of any subsequent contract fulfillment.
VII. Data Processing When Visiting Our Company’s Social Media Pages on Facebook and Instagram
Person in Charge
Below is an overview of how we collect and process your personal data on our pages on the following social media platforms:
- Facebook: https://www.facebook.com/ITSonixGmbH/, hereinafter referred to as „Facebook profile“
- Instagram: https://www.instagram.com/itsonixleipzig/, hereinafter referred to as „Instagram profile“
Please note that you use our social media pages and their features—as well as social media platforms in general—at your own risk. This applies in particular to the use of interactive features (e.g., liking, commenting, sharing, rating). You can find the relevant terms of use here:
- Facebook: https://de-de.facebook.com/legal/terms/
- Instagram: https://help.instagram.com
You can access the joint data policy here: https://de-de.facebook.com/about/privacy
In addition to us, the operator of the social media platform (hereinafter referred to as the „Provider“) is also responsible for data processing on our social media pages (Facebook and Instagram), hereinafter also referred to as „Meta“ or „Facebook.“.
Meta Platforms Ireland Ltd.
4 Grand, Canal Square
Grand Canal Harbour, Dublin 2
Ireland
Online contact form for the Data Protection Officer at Facebook and Instagram: https://de-de.facebook.com/help/contact/540977946302970.
The operators of the social media platforms are available to you as your primary point of contact. However, you may also exercise your rights regarding processing carried out under joint responsibility by contacting us. If you contact us, we will coordinate with the respective provider to respond to your request and ensure your rights as a data subject are protected.
Notes
Please note that Meta also processes personal data of users and other visitors to its social media platforms for its own purposes, such as personal information (registration data, status updates, photos, location data), IP addresses, or cookie information. We have no control over this. For information on what data Meta processes, the purposes for which it is processed, and the legal basis on which Meta bases this processing, please refer to Meta’s privacy policy at: https://www.facebook.com/privacy/policy/
It cannot be ruled out that, in this context, personal data may also be transferred to or processed by recipients in countries outside the European Union (EU) or the European Economic Area (EEA), particularly in the United States. To the extent that data is transferred to Meta Platforms, Inc. in the United States and the conditions are met in each individual case, such transfer may be based on the EU-U.S. Data Privacy Framework. Regardless of this, it should be noted that Meta also processes personal data for its own purposes, and the nature, scope, and further processing of this data are largely beyond our control.
We have an agreement with Meta regarding joint controllership pursuant to Article 26 of the GDPR, which, among other things, specifies how the respective roles and responsibilities regarding the processing of personal data are structured and who fulfills which data protection obligations. Meta provides the key provisions of this agreement at the following link: https://www.facebook.com/legal/terms/page_controller_addendum
Information on Data Processing
We maintain our Facebook and Instagram profiles to promote our services and offerings and to interact with our customers and visitors to these social media platforms (hereinafter referred to as „users“).
When you use our Facebook and Instagram profiles, personal data is processed. The following information explains the nature and scope of the data processing for which we are responsible under data protection law in this context.
We do not store any personal data regarding your use of the respective social media sites. Information that you post on our respective social media sites (e.g., comments) or send via the respective messaging service is stored by the provider based on your user relationship with them and can be deleted by you there.
Processing of usage data under the joint responsibility of Meta and us
Page Insights
When you visit our social media pages, Meta also uses certain usage data (e.g., whether you have „liked“ or commented on specific posts of ours) to provide us with aggregated usage statistics (so-called „Page Insights“). Usage statistics do not allow for any conclusions to be drawn about the behavior of individual users; rather, they simply provide us with an overview of how our social media pages are used (e.g., which posts were clicked on particularly frequently). We ourselves do not have access to the personal data processed for the creation of these statistics. Meta alone determines which user actions are logged on the social media platforms; we cannot set up, change, or otherwise influence this.
We use usage statistics provided by Meta regarding our social media pages to improve the posts published there and make them as engaging as possible for users. This processing is based on a balancing of interests pursuant to Article 6(1), first sentence, letter f of the GDPR, which always takes your interests into account as well. If you are logged into Instagram or Facebook yourself, the processing is also carried out in accordance with Article 6(1), first sentence, letter b of the GDPR, in compliance with the terms of service that apply between you and Meta. For the processing of personal data to generate these usage statistics, Facebook and we are joint controllers pursuant to Article 26 of the GDPR.
Information about Page Insights from Instagram and Facebook (https://de-de.facebook.com/legal/terms/page_controller_addendum) describe what data is processed under the joint controller arrangement and include the „Page Insights Addendum,“ in which Meta and we have contractually specified who fulfills which obligations under the GDPR.
Meta-AI
Since May 27, 2025, Meta has also been using personal data generated through the use of the Facebook and Instagram platforms to train generative AI systems. This applies in particular to publicly available content posted by users of these platforms, such as:
- Articles,
- Comments,
- Likes,
- Shared images and text.
Meta relies on a legitimate interest within the meaning of Article 6(1)(f) of the GDPR for this data processing for AI training, and it therefore takes place without the explicit consent of the data subjects.
We have objected to Meta’s use of this data for AI training, so your interactions with our Facebook and Instagram pages will not be used for AI training. However, unless you, as a user, have objected yourself, Meta may still use your public interactions on the Facebook and Instagram platforms for AI training. If you do not wish this to happen, you can object to the use of your data. You can object either within the respective apps or via objection forms.
We recommend that users actively familiarize themselves with Meta's appeal process and, if necessary, make use of it.
You may object to the processing with future effect. Information and how to object:
- Facebook: https://www.facebook.com/help/contact/712876720715583
- Instagram: https://help.instagram.com/contact/767264225370182
Processing of Your Data When You Communicate with Us Through Our Instagram Page
On Instagram, you can communicate directly with us using the „Instagram Direct Messaging“ feature. If you contact us via Instagram Direct Messaging, we will process your data (e.g., your name and the content of your messages) in order to address your inquiry. If necessary, we also process your data to assert legal claims and defend against legal disputes, as well as to prevent and investigate criminal offenses (e.g., in the case of hate speech or inflammatory comments).
The legal basis for processing the data transmitted when contacting us is Article 6(1)(f) of the GDPR. If the purpose of contacting us is to enter into a contract or if contact is made within the framework of an existing contractual relationship, the additional legal basis for processing is Article 6(1)(b) of the GDPR. Your data will be deleted once your inquiry has been fully resolved and provided that no statutory retention requirements preclude such deletion, such as in the case of any subsequent contract fulfillment.
Processing of Your Data When You Communicate with Us Through Our Facebook Page
If you contact us through our Facebook page—for example, by commenting on a post or sending a message via Facebook Messenger—we will process your data (such as your name and the content of your communication) in order to address your inquiry.
To the extent necessary, we also process your data to assert legal claims and defend ourselves in legal disputes, as well as to prevent and investigate criminal offenses (e.g., hate speech or inflammatory comments).
The legal basis for processing the data transmitted when contacting us is Article 6(1)(f) of the GDPR. If the purpose of establishing contact is to enter into a contract or if it takes place within the framework of an existing contractual relationship, the additional legal basis for processing is Article 6(1)(b) of the GDPR.
Your data will be deleted once your inquiry has been fully resolved and provided that no legal retention requirements prevent its deletion—such as in the case of any subsequent contract fulfillment.
VIII. Your Rights
With regard to the processing of your personal data described above, you, as the data subject, have the following rights with respect to us:
- Right to Information regarding your personal data pursuant to Article 15 of the GDPR
- Right to Correction the personal data concerning you pursuant to Article 16 of the GDPR
- Right to Deletion the personal data concerning you pursuant to Article 17 of the GDPR
- Right to Restriction the processing of your personal data pursuant to Article 18 of the GDPR
- Right to Data Portability the personal data concerning you, pursuant to Article 20 of the GDPR
- Right to Objection to object to the processing of your personal data pursuant to Article 21 of the GDPR, to the extent that the processing is carried out to protect vital interests pursuant to Article 6(1)(e) of the GDPR or to protect our legitimate interests pursuant to Article 6(1)(f) of the GDPR
If you believe that our processing of your personal data is not in compliance with applicable data protection laws, you also have the right to file a complaint with the competent supervisory authority.
You can find a list, including contact information for the regulatory authorities, at: https://www.bfdi.bund.de/DE/Service/Anschriften/Laender/Laender-node.html