Privacy Policy

At DATANET GmbH (hereinafter «DATANET», «we» or «us»), the protection and security of your personal data is our highest priority. You can expect us to handle your data sensitively and carefully and to ensure a high level of data security.

We collect and use your personal data exclusively within the framework of the applicable statutory provisions, in particular the European General Data Protection Regulation (DSGVO).

With this privacy policy, we inform you about which personal data we process about you, why we need this data, and which rights you have in connection with the processing of your personal data. This privacy policy applies to the following applications: datanet.de, *.datanet.de, datanet.cloud, *.datanet.cloud, business-analyzer.net, *.business-analyzer.net, CT-UserView App (hereinafter together «websites», «services» or «applications»).

1. Responsibility and data processing

DATANET provides the portal environment technically and operates it on behalf of a large number of companies. DATANET provides the service and the associated data processing as a processor for these customers. The respective customer is accordingly the controller within the meaning of data protection law for the processing of personal data, where relevant. Information on the controllers for each customer project can be requested from the data protection officer of DATANET.

2. Controller under the DSGVO

DATANET is the controller under the EU General Data Protection Regulation (DSGVO):

DATANET GmbH
Hardtbrücke 7-13
53902 Bad Münstereifel
Germany

Tel. +49 22 57 95 28 0
Fax: +49 22 57 95 28 444
Mail: info@datanet.de

3. Data protection officer

The data protection officer of DATANET is:

Stefan Frings
DATANET GmbH
Hardtbrücke 7-13
53902 Bad Münstereifel
Germany

Tel. +49 22 57 95 28 0
Fax: +49 22 57 95 28 444
Mail: sfrings@datanet.de

DATANET is aware of its responsibility as controller and processor and does everything it can to protect the data of its customers and users in accordance with the applicable data protection laws. Customers and users can rely on their personal data being processed in accordance with the provisions of the DSGVO and other applicable data protection laws. The data protection officer of DATANET is available to customers and users for questions and concerns relating to data protection.

4. General information on data processing

4.1 Scope of the processing of personal data

As a processor, DATANET provides various services that are set out in a data processing agreement pursuant to Artikel 28 der Datenschutzgrundverordnung (DSGVO). One of these services is the provision of a personalised customer portal solution that is accessible via the website visited. Personal data is already processed even if the user does not have access to the protected area. A precise description of the data processing is contained in the following sections.

4.2 Legal basis for the processing of personal data

The legal basis for the processing of personal data is determined by the controller responsible for the data processing. Unless different provisions have been laid down by the controller in the respective customer project, processing by this platform is necessary to safeguard a legitimate interest within the meaning of Art. 6 Abs. 1 lit. f DSGVO. The legitimate interest consists in providing a customer portal solution in order to provide the functionalities and data agreed with the controllers and to protect the portal environment against unauthorised use.

4.3 Erasure of data and storage period

Personal data is erased or blocked as soon as the purpose of storage ceases to apply or the erasure periods set out in a contract under Artikel 28 DSGVO have been reached. Storage periods are generally determined by the controller for the data processing and implemented by DATANET. If the controller is not known, the data protection officer of DATANET can be contacted for further information. Storage may also take place if this has been provided for by the European or national legislator in Union law regulations, laws or other provisions to which the controller is subject. Compliance with the storage periods is reviewed regularly to ensure that personal data is not stored for longer than necessary.

5. Collection and storage of personal data, and the nature and purpose of its use

5.1 Provision of the website and creation of log files

Each time this website is visited, data and information are automatically collected from the user's computer system. The data is stored in the log files of our system and is not combined with other personal data of the user. This data includes:

  • IP address of the user
  • Name and URL of the file retrieved
  • Date and time of access
  • SSL/TLS variant/Cypher
  • Unsuccessful logins
  • Referrer-URL

After authentication on the website, the following data is additionally collected:

  • User-Agent of the user
  • Logged-in user account
  • Transaction changes to data records
  • Date and time of login
  • Date and time of logout

This data is processed for the following purposes:

  • Historisation of transaction changes
  • Ensuring a smooth connection setup of the website
  • Ensuring comfortable use of our website
  • Optimisation of the website
  • Ensuring the security of our information technology systems
  • Further administrative purposes
  • Support of law enforcement authorities in the event of a cyberattack

The data is likewise stored in the log files of our system. This data is not stored together with other personal data of the user.

The legal basis for the data processing is Art. 6 Abs. 1 S. 1 lit. f DSGVO and Art. 28 DSGVO respectively. Our legitimate interests arise from the stated purposes of the data collection. The standard erasure period for the data listed is 180 Tage. However, different storage periods may be agreed with the controller in individual customer projects. The controller provides information on this upon request. The data protection officer of DATANET also provides information on the controllers for each customer project upon request.

5.2 Use of cookies

Our website uses Session-Cookies. Cookies are text files that are stored in the internet browser or by the internet browser on the user's computer system. When a user accesses a website, a cookie may be stored on the user's operating system.

The Session-Cookies contain a session ID with which the user's browser and our servers can communicate unambiguously, so that a user does not have to log in again each time they change a screen. This type of cookie and the associated data processing is based on the legitimate interest pursuant to Art. 6 (1) lit. f DSGVO, the legitimate interest being to offer a technically customary and as compatible a solution as possible. After the browser is closed, the Session-Cookie, including the user data, is automatically removed from the user's device.

5.3 Provision of customer-specific data in accordance with the agreement

The subject of the collection, processing and/or use of personal data is the types/categories of data agreed in the data processing agreement with the respective controller. These may be the following data:

  • Organisational data (e.g. company code, cost centre)
  • Personal master data (e.g. name, email, telephone number, assignment to organisational data)
  • Technical data (e.g. call number, connection identifier, contract number, customer number)
  • Usage and billing data (e.g. telecommunications data)

Persistent data required for regular processing is retained for the duration of the project, but at most for as long as required for the processing and specified by the controller. This includes organisational data, personal master data and technical data. The standard erasure periods for usage and billing data are 24 Monate for billing data and 3 Monate for usage data. In individual customer projects, different storage periods may be agreed with the controller. The controller provides information on specific erasure periods and on data retained upon request. The data protection officer of DATANET will, upon request, inform you of the controllers for each customer project.

6. Disclosure of data

In the course of the services to be provided, it may be necessary to disclose personal data to third parties. Disclosure takes place only on the instruction of the client or if we are legally obliged to do so (Art. 6 Abs. 1 S. 1 lit. c DSGVO). In every case, the controller is informed immediately of the disclosure. We do not disclose personal data to third parties unless this is necessary to fulfil our contractual or statutory obligations. We ensure that all third parties to whom we disclose personal data are contractually obliged to use the data only for the agreed purposes and to take appropriate security precautions.

7. Rights of data subjects

You have the right:

  • pursuant to Art. 15 DSGVO to request information about your personal data processed by us. In particular, you may request information about the purposes of processing, the category of personal data, the categories of recipients to whom your data has been or will be disclosed, the planned storage period, the existence of a right to rectification, erasure, restriction of processing or objection, the existence of a right to lodge a complaint, the origin of your data if it was not collected by us, and the existence of automated decision-making including profiling and, where applicable, meaningful information about its details;
  • pursuant to Art. 16 DSGVO to request the immediate rectification of inaccurate personal data stored by us or the completion of such data;
  • pursuant to Art. 17 DSGVO to request the erasure of your personal data stored by us, unless the processing is necessary for exercising the right of freedom of expression and information, for compliance with a legal obligation, for reasons of public interest, or for the establishment, exercise or defence of legal claims;
  • pursuant to Art. 18 DSGVO to request the restriction of the processing of your personal data insofar as you contest the accuracy of the data, the processing is unlawful but you oppose its erasure and we no longer need the data, yet you require it for the establishment, exercise or defence of legal claims, or you have objected to the processing pursuant to Art. 21 DSGVO;
  • pursuant to Art. 20 DSGVO to receive the personal data you have provided to us in a structured, commonly used and machine-readable format or to request its transmission to another controller;
  • pursuant to Art. 7 Abs. 3 DSGVO to withdraw consent you have given us at any time. As a result, we may no longer continue, for the future, the data processing that was based on this consent; and
  • pursuant to Art. 77 DSGVO to lodge a complaint with a supervisory authority. As a rule, you may contact the supervisory authority of your usual place of residence or workplace for this purpose.
  • right to object pursuant to Art. 21 DSGVO

Where your personal data has been made available to us by the client in the context of processing on behalf of a controller, we will forward your request to the client and accept the corresponding instructions from the client.

8. Data security

We attach great importance to the protection of your data and have therefore taken appropriate technical and organisational security measures to protect your data against accidental or intentional manipulation, partial or complete loss, destruction or unauthorised access by third parties. In doing so, we use the widespread SSL method (Secure Socket Layer) during the visit to the website in order to ensure the best possible encryption between your browser and our server. We therefore use SSL certificates from SwissSign (https://www.swisssign.com/de/). This ensures encrypted transmission of data between your browser and our server in order to safeguard the security of your data. By using SSL certificates, we can ensure that no third parties can access your data while it is being transmitted between your browser and our server. You can tell whether an individual page of our website is transmitted in encrypted form by the closed display of the key or padlock symbol in the status bar of your browser.

We also use appropriate technical and organisational security measures to ensure that your data is protected against unauthorised access. Our security measures are reviewed regularly to ensure that they are state of the art and that we continuously make improvements in line with technological development. We work to ensure that your data is always secure and protected, and we endeavour to optimise our security measures in order to guarantee the best possible protection.

9. Currency and amendment of this privacy policy

It is important to us to ensure the security of your personal data and compliance with the applicable data protection regulations. We expressly reserve the right to amend and supplement this privacy policy at any time. The version current at the time and published on our websites applies. An update may become necessary, for example, if we provide new functions or services on our website or if the applicable data protection regulations change.

To ensure that you are informed at all times about the processing of your personal data, we recommend that you check the privacy policy regularly for changes. You can find the current version on our website at any time. There you will find a comprehensive overview of the nature, scope and purpose of the personal data processed by us and of your rights in connection with the processing of this data.

10. Further information and actions

If you have questions or concerns regarding the processing of your personal data, or if you wish to exercise your rights in relation to the processing of your data, you may contact our data protection officer at any time. You will find the contact details in section 2 of this privacy policy.

Terms of use of the DATANET services

The terms of use of the portal / the application describe the rules and requirements that must be observed when using the portal. These guidelines are of great importance in order to ensure the integrity and security of the portal and its services. Compliance with these guidelines is essential for every user in order to ensure that the portal / the application remains a secure and reliable place in which to use the services offered. The following points explain the most important requirements and rules to be observed when using the portal / the application.

1

The portal and the services provided on it are to be used exclusively for the intended purpose. Misuse is strictly prohibited in order to ensure the integrity of the portal and its services. In particular, it is prohibited to use the portal via protocol services other than HTTPS or to carry out load tests that could impair the performance of the portal.

2

User authentication data such as user name and password are confidential and must under no circumstances be passed on to third parties. For this reason, it is prohibited for several persons to log in to the portal at the same time with the same access data. Each user is responsible for protecting their access data in order to prevent unauthorised access.

3

The security of data downloaded via the portal is the responsibility of the user. It is therefore important that appropriate security precautions are taken to ensure that downloaded data is protected against unauthorised access. The user should download only data that is required for the intended purpose and ensure that it is stored securely.

4

Any kind of alteration or manipulation of the portal and of the data provided on it is strictly prohibited in order to ensure the integrity and security of the portal. Examples include the unauthorised deletion or modification of data, the insertion of harmful code or the introduction of malware. Any alteration or manipulation of the portal is not permitted.

5

It is prohibited to use the portal for commercial purposes unless there is express written permission from the operator of the portal. Commercial use of the portal without the operator's permission is not permitted and may lead to legal consequences.

6

The user is obliged to report immediately to the operator of the portal any kind of technical problem or security breach that occurs in connection with the portal. This enables the operator to react quickly and to ensure that the portal remains secure and reliable.

7

Any kind of spamming, phishing or other forms of fraudulent activity affecting the portal is prohibited. Such activities endanger the security and integrity of the portal and may lead to legal consequences.

8

The user undertakes to comply with the applicable laws and provisions connected with the use of the portal. This includes in particular data protection laws, copyright and other relevant provisions. The user should ensure that they do not violate any laws or provisions.

9

It is prohibited to collect, store or process personal data of other users of the portal without their express consent. The protection of personal data is of great importance in order to ensure the privacy and security of users.

10

The user is legally obliged to use the portal and its content in accordance with applicable laws and regulations. It is not permitted to publish or distribute content that violates laws for the protection of public order, security and morality. The user should ensure that they do not infringe the rights of third parties, such as copyrights or trademark rights, which are protected by applicable laws.

In summary, these terms of use are important in order to ensure the integrity and security of the portal. The user should ensure that they comply with these guidelines in order to use the portal securely and reliably. By complying with these guidelines, every user can help ensure that the portal remains a secure and reliable place in which to use the services offered.