Privacy Notice
The German original version of the privacy notice shall be the only legally binding version.
The English translation is provided solely for reference purposes and shall have no legal effect.
1. General Section
1.1. Information on the collection of personal data and contact details of the controller
1.1.1. Below, we, rising systems AG (hereinafter the “Company”, “we” or “us”), inform you about the processing of personal data in our company. Personal data are all data that relate to you personally, e.g., name, address, email address, user behavior.
1.1.2. Although wording in this text may use the generic masculine, all genders are of course addressed equally.
1.1.3. The controller responsible for processing personal data is the natural or legal person who, alone or jointly with others, determines the purposes and means of processing personal data.
1.1.4. The controller within the meaning of the General Data Protection Regulation (GDPR) is rising systems AG
Benrather Schloßallee 99
40597 Düsseldorf
Phone: +49 (0) 211 90 32 94 0
Email: [email protected]
Further information about the controller can be found in the legal notice (https://www.rising-systems.de/impressum).
1.1.5. You can reach our Data Protection Officer at the following contact details:
Matthias Bungartz
Benrather Schloßallee 99
40597 Düsseldorf
Phone: 0211 903294 0
Email [email protected].
1.2. Processing principles and legal bases
1.2.1. As a rule, the legal basis for processing operations for which we obtain consent for a specific processing purpose is Art. 6(1) sentence 1 point (a) GDPR. The processing of personal data that we require in order to fulfill contractual or pre-contractual obligations (e.g., under a software development agreement) is based on Art. 6(1)(b) GDPR. If processing is necessary for compliance with a legal obligation (e.g., statutory retention obligations under section 257 HGB, section 147 AO) to which the controller is subject, Art. 6(1)(c) GDPR serves as the legal basis. If processing is necessary for the purposes of our legitimate interests or those of a third party and the interests, fundamental freedoms, and fundamental rights of the data subject do not override these, Art. 6(1)(f) GDPR serves as the legal basis for the processing of personal data.
1.2.2. Insofar as processing requires the storage of information on the user’s terminal equipment or access to information already stored on the terminal equipment—especially cookies—the legal basis is section 25(1) TTDSG (consent), section 25(2) no. 1 TTDSG (carrying out the transmission of a communication over a public telecommunications network) or section 25(2) no. 2 TTDSG (provision of a telemedia service expressly requested by the user).
1.2.3. Processing may also be based on multiple legal bases.
1.3. Disclosure of data
Your personal data will generally not be transferred to third parties. Otherwise, this may apply if:
– you have given your explicit consent pursuant to Art. 6(1) sentence 1 point (a) GDPR;
– the disclosure is necessary pursuant to Art. 6(1) sentence 1 point (f) GDPR for the establishment, exercise, or defense of legal claims and there is no reason to assume that you have an overriding legitimate interest in not disclosing your data;
– there is a legal obligation to disclose pursuant to Art. 6(1) sentence 1 point (c) GDPR; and
– it is legally permissible and necessary pursuant to Art. 6(1) sentence 1 point (b) GDPR for the performance of contractual relationships with you.
1.4. Categories of recipients and third-country transfer
1.4.1. Within our company, only those persons have access to your data who are responsible for handling your data (e.g., for billing purposes). We also use external service providers, in particular processors pursuant to Art. 28 GDPR, insofar as we cannot perform services ourselves or not sensibly. These external service providers are primarily providers of IT services and telecommunications services, such as:
- Odoo S.A., Chaussée de Namur, 40, 1367 Grand Rosière, Belgium. Information on data protection at this company can be found in the privacy notice athttps://www.odoo.com/privacy
1.4.2. Section 1.5 applies to the transfer of personal data to third countries.
1.5. Categories of recipients and third-country transfer
1.5.1. In the context of our business relationships, your personal data may be transferred or disclosed to third-party companies. These may also be located outside the European Economic Area (EEA), i.e., in third countries. Such processing takes place solely to fulfill contractual and business obligations and in the interest of effective business operations (the legal basis is Art. 6(1)(b) or (f), each in conjunction with Art. 44 et seq. GDPR).
1.5.2. The European Commission has determined, by means of so-called adequacy decisions, that some third countries ensure a level of data protection comparable to that of the EEA (a list of these countries and a copy of the adequacy decisions can be found here:https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en).
1.5.3. In other third countries to which personal data may be transferred, there may not be a consistently high level of data protection due to a lack of statutory provisions. Where this is the case, we ensure adequate protection of data. This can be achieved through binding corporate rules, the European Commission’s standard contractual clauses for the protection of personal data pursuant to Art. 46(1), (2)(c) GDPR (the 2021 standard contractual clauses are available athttps://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32021D0915&locale-en), certifications, or recognized codes of conduct. Please contact our Data Protection Officer if you would like further information.
1.6. Storage period
1.6.1. For the data processing we carry out, we state in this Privacy Notice how long your personal data are stored with us and when they are deleted or blocked. If no explicit storage period is specified, your personal data will be deleted or blocked as soon as the purpose or the legal basis for storage ceases to apply.
1.6.2. However, storage may continue beyond the specified period in the event of a (threatened) legal dispute with you or any other legal proceedings, or if storage is required by statutory provisions to which we as controller are subject (e.g., section 257 HGB, section 147 AO). When the storage period prescribed by law expires, your personal data will be blocked or deleted unless further storage is necessary and there is a legal basis for this.
1.7. No obligation to provide personal data
As a rule, you are under no statutory or contractual obligation to provide us with your personal data; however, we may only be able to provide certain services to a limited extent or not at all if you do not provide the data required for this and/or do not consent to processing.
1.8. Data security
1.8.1. We use appropriate technical and organizational security measures to protect your data against accidental or intentional manipulation, partial or complete loss, destruction, or unauthorized access by third parties. Our security measures are continuously improved in line with technological developments.
1.8.2. During your visit to the website, we use the common SSL (Secure Socket Layer) method in conjunction with the highest encryption level supported by your browser. As a rule, this is 256-bit encryption. If your browser does not support 256-bit encryption, we resort to 128-bit v3 technology instead. You can tell whether an individual page of our website is transmitted in encrypted form by the closed display of the key or lock symbol in the lower status bar of your browser.
1.9. Your rights as a data subject
1.9.1. You may assert your rights as a data subject regarding your processed personal data at any time using the contact details provided at the beginning. As a data subject, you have the right:
1.9.2. to obtain information pursuant to Art. 15 GDPR about the data concerning you that we process. In particular, you may obtain information about the purposes of processing, the category of data, the categories of recipients to whom your data have been or will be disclosed, the planned storage period, the existence of a right to rectification, erasure, restriction of processing or the right to object, the existence of a right to lodge a complaint, the origin of your data if they were not collected by us, and the existence of automated decision-making including profiling and, where applicable, meaningful information about its details;
1.9.3. to demand without delay the rectification of inaccurate data or the completion of your data stored with us pursuant to Art. 16 GDPR;
1.9.4. to request the erasure of your data stored by us pursuant to Art. 17 GDPR, unless processing is necessary for exercising the right of freedom of expression and information, for compliance with a legal obligation, for reasons of public interest, or for the establishment, exercise, or defense of legal claims;
1.9.5. to request the restriction of processing of your data pursuant to Art. 18 GDPR insofar as you contest the accuracy of the data or the processing is unlawful;
1.9.6. to receive your data that you have provided to us in a structured, commonly used, and machine-readable format or to request the transmission to another controller (“data portability”) pursuant to Art. 20 GDPR;
1.9.7. to object to processing pursuant to Art. 21 GDPR where the processing is based on Art. 6(1) sentence 1 point (e) GDPR (performance of a task carried out in the public interest) or Art. 6(1) sentence 1 point (f) GDPR (legitimate interests of the controller). This is particularly the case where processing is not necessary for the performance of a contract with you. In the event of your justified objection, we will examine the situation and either stop or adjust the data processing or demonstrate our compelling legitimate grounds on the basis of which we continue processing;
1.9.8. to withdraw at any time your consent once given—i.e., your freely given, informed, and unambiguous indication of wishes, signified by a statement or by a clear affirmative action, by which you signify your agreement to the processing of the relevant personal data for one or more specific purposes—pursuant to Art. 7(3) GDPR. As a result, we may no longer continue in the future the data processing that was based on this consent;
1.9.9. to lodge a complaint with a supervisory authority pursuant to Art. 77 GDPR regarding the processing of your personal data by our company, e.g., with the data protection supervisory authority responsible for us. The supervisory authority responsible for us is:
State Commissioner for Data Protection and Freedom of Information NRW
Kavalleriestraße 2-4
40213 Düsseldorf
Phone: +49 (0)211 38424-0
Fax: +49 (0)211 38424-999
Email: [email protected]
A list of the federal state data protection authorities can be found athttps://www.bfdi.bund.de/DE/Service/Anschriften/Laender/Laender-node.html.
1.10. No automated decision-making (including profiling)
The personal data collected from you are not used for a procedure involving automated decision-making (including profiling).
2. Data processing when visiting our website and contacting us by email
2.1. Personal data processed
When you use the website for informational purposes only, i.e., when you do not otherwise transmit information to us, we only collect the personal data that your browser transmits to our server. If you wish to view our website, we collect the following data, which are technically necessary to display our website to you and to ensure stability and security (the legal basis is Art. 6(1) sentence 1 point (f) GDPR):
– IP address
– date and time of the request
– time zone difference to Greenwich Mean Time (GMT)
– content of the request (specific page)
– access status/HTTP status code
– each amount of data transmitted
– website from which the request comes
– browser
– operating system and its interface
– user’s internet service provider
– websites accessed by the user’s system via our website
– language and version of the browser software.
2.2. Retention periods
We delete or anonymize your above personal data as soon as they are no longer required for the purposes for which we collected or used them as stated above. With regard to the storage of data in log files, deletion or anonymization takes place no later than after 14 days.
2.3. Hosting
2.3.1. The website is hosted by an external service provider. This also means that the personal data collected on the website are stored on the servers of this host. These mainly include the personal data listed in section 2.1.
2.3.2. The external hosting is provided for us by the company https://www.google.com/about/datacenters/locations/st-ghislain/. This company processes the personal data on our behalf and under our instructions. We have concluded a corresponding data processing agreement with this company. The company’s privacy notice can be found at the following link:https://cloud.google.com/terms/data-processing-addendum
2.3.3. Your personal data are forwarded pursuant to Art. 6(1) sentence 1 point (b) GDPR for the performance of contractual relationships with prospective and existing customers. We also have a legitimate interest within the meaning of Art. 6(1)(f) GDPR in the fast, efficient, and secure provision of our website by a web hosting provider.
2.4. Use of cookies
2.4.1. In addition to the aforementioned data, cookies are stored on your computer when you use our website. Cookies are small data sets that are stored on your persistent storage medium and assigned to the browser you use and through which certain information flows to the entity that sets the cookie (here, us). Cookies cannot execute programs or transmit viruses to your computer.
2.4.2. We use technically necessary cookies on our website to operate the website. These technically necessary cookies ensure that the website is usable by enabling basic functions. Without these cookies, the website would not function properly. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR). Our legitimate interest lies in providing a functional website. These cookies are stored until the end of the respective browser session.
2.4.3. We also use functional and performance cookies to collect information about how you use the website. Users are not identified. The information serves only to find out what our users are interested in and how we can possibly optimize the website. These cookies are also stored only until the end of the respective browser session. The legal basis is your consent pursuant to section 25(1) sentence 1 TTDSG. You can withdraw your consent at any time. However, processing prior to the time of withdrawal is not affected.
2.4.4. Most browsers accept cookies automatically. You can configure your browser so that no cookies are stored on your end device or that a prompt always appears before a new cookie is set. However, completely disabling cookies may mean that you cannot fully use all functions of our website.
2.4.5. Details of the cookies we use can be found in our cookie policy (https://www.rising-systems.de/cookie-policy).
2.5. Data processing when using the contact form and by email
2.5.1. A contact form is available on our website that can be used for electronic contact. If a user makes use of this option, the data entered in the input mask are transmitted to us and stored (such data include e.g., name, address, email, phone number, input text).
2.5.2. At the time the message is sent, the following data are also stored:
- the user’s IP address
- date and time of the request
2.5.3. Alternatively, it is possible to contact us via the email address provided. In this case, the personal data transmitted with the email are stored. In this context, the data are not passed on to third parties. The data are used exclusively for processing the conversation.
2.5.4. The legal basis for processing the data transmitted in the course of contacting us via the contact form or by sending an email is Art. 6(1)(f) GDPR. If the contact/ email contact aims at concluding a contract, Art. 6(1)(b) GDPR is an additional legal basis for the processing.
2.5.5. The processing of personal data from the input mask/email serves solely to handle the contact request. The other personal data processed during the sending process serve to prevent misuse of the contact form and to ensure the security of our information technology systems. These purposes also constitute the necessary legitimate interest in processing the data.
2.5.6. The data are deleted as soon as they are no longer necessary to achieve the purpose of their collection. For the personal data from the input mask of the contact form and those transmitted by email, this is the case when the respective conversation with the user has ended. The conversation is deemed ended when the circumstances indicate that the matter in question has been conclusively clarified.
2.5.7. The personal data additionally collected during the sending process are deleted at the latest after a period of seven days.
2.5.8. You may object to the storage of your personal data by sending an email to [email protected]. In such a case, the conversation cannot be continued. All personal data stored in the course of making contact will then be deleted.
3. Processing of personal data of third parties, customers and suppliers
3.1. Pursuant to Art. 6(1)(b) GDPR, personal data are processed when you provide them to us for the initiation and performance of a contract, and performance of the contract is not possible without providing them (e.g., the name of the contact person).
3.2. Which personal data are collected can be seen from the respective contract forms or results from the information you proactively provide in connection with the conclusion and performance of the contract.
3.3. We may also use personal data to safeguard, within the legal limits, our legitimate interests or those of third parties pursuant to Art. 6(1)(f) GDPR, insofar as there is no reason to assume that your interests or fundamental rights and freedoms, which require the protection of personal data, override these. A legitimate interest regularly exists when it is necessary to secure evidence in order, for example, to assert or defend our rights in court and to respond to requests from law enforcement authorities.
3.4. Where applicable, we transmit information on payment defaults to credit agencies in order to prevent fraud or similar. This is done, in accordance with legal requirements, insofar as it is necessary to safeguard our legitimate interests and the legitimate interests of third parties and there is no reason to assume that your interests or fundamental rights and freedoms, which require the protection of personal data, override these. Processing is therefore carried out for the purpose of preventing fraud or criminal offenses on the basis of Art. 6(1)(f) GDPR.
3.5. Sources and types of personal data
3.5.1. We primarily process personal data that the data subjects themselves provide to us in the context of contractual and business relationships or that we receive from the respective contractual and business partners (e.g., from your colleagues with whom we are already in contact), for example in the course of processing an inquiry or an order. We also process personal data that we collect from publicly accessible sources (such as the commercial register, press, internet) or receive from third parties (e.g., credit agencies, business partners). We will provide separate notice if we collect personal data from third-party sources.
3.5.2. Relevant personal data include in particular personal details (e.g., name, first name, address, bank details, billing address, tax number/VAT ID) and other contact details (e.g., telephone number, email address). In addition, these may include contract or order data (e.g., sales data, volume, planned quantities), data from the fulfillment of our contractual obligations, information about your financial situation (e.g., creditworthiness data), data about you (e.g., business interests, profession, industry, position, tasks and powers), as well as other data comparable with the categories mentioned.
3.5.3. The scope of the data processed about a person varies depending on the function in which the person appears to us, for example, which position they hold at the respective business partner.
3.6. Legal bases, purposes of processing, and legitimate interests
3.6.1. We process personal data for the following purposes and to pursue the following legitimate interests, in each case on the basis of the following legal bases:
3.6.1.1. Advertising
- Purpose: Advertising
- Processing/legitimate interest: Selection of and direct approach using advertising by electronic mail (including newsletters) and/or telephone
- Legal basis: Art. 6(1)(a) GDPR; Art. 6(1)(f) GDPR in conjunction with section 7(3) UWG
3.6.1.2. Contracts
- Purpose: Preparation, execution, and handling of contracts with you or your employing company
- Processing/legitimate interest:
o Purchase and supply contracts (e.g., processing purchase and sale inquiries, authenticating contractual partners, preparing and signing contract documents, carrying out purchases and sales, billing and handling purchase price payments;
o Service and works contracts as well as other commissioning relationships (e.g., processing and reviewing corresponding offers and inquiries; authenticating contractual partners, preparing and signing contract documents, processing payments; sending information letters);
- Legal basis: Art. 6(1)(b) and (f) GDPR
3.6.1.3. Customer care
- Purpose: Customer care
- Processing/legitimate interest: Optimal contact support/relationship, including with respect to the employees of our business partners;
- Legal basis: Art. 6(1)(f) GDPR
3.6.1.4. Internal processes
- Purpose: Own business purposes including business process optimization
- Processing/legitimate interest:
o Optimization of our business processes, e.g., by maintaining a supplier or prospect database, including as part of customer relationship management;
o Centralization or outsourcing of company functions;
o Reduction of default risks in our business processes by consulting credit agencies (e.g., Creditreform, Bürgel) and determining score values (profiling), which help us to assess, on the basis of a recognized mathematical-statistical procedure, the probability that contractual partners will fulfill their payment obligations in accordance with the contract;
- Legal basis: Art. 6(1)(f) GDPR
3.6.2. We also process your data to safeguard our legitimate interests (Art. 6(1)(f) GDPR) in the establishment and defense of legal claims and the conduct of market research.
3.6.3. Further data processing is carried out on the basis of statutory requirements (Art. 6(1)(c) GDPR): for example, to fulfill tax law and other statutory control and reporting obligations, as well as audits by tax or other authorities, and to comply with statutory retention periods.
4. Changes in corporate structure
As part of the further development of our business, it may happen that the structure of our company changes by changing the legal form or by founding, purchasing, or selling subsidiaries, parts of companies, or components. In such transactions, customer information is passed on together with the part of the company to be transferred. In each case of transfer of personal data to third parties to the extent described above, we ensure that this is done in accordance with this Privacy Notice and the applicable data protection laws.
5. Currency and changes to this Privacy Notice
5.1. This Privacy Notice is valid and current as of 28 March 2024.
5.2. Due to the further development of our internal processes, offerings, and our website or due to changes in statutory or regulatory requirements, it may be necessary to amend this Privacy Notice. You can access and print the current Privacy Notice at any time on our website.