DATA PRIVACY
Data Privacy AMCON Software GmbH
Our company attaches great importance to the protection of your personal data. The processing of this data by us is carried out strictly in accordance with data protection regulations. These are the European General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and other legal provisions.
The GDPR obliges us to provide you with the following information about the processing of your data.
Controller
AMCON Software GmbH
Osterstraße 15
49661 Cloppenburg
Phone +49 4471 91 42-0
Fax +49 4471 91 42-29
Email: info@amcongmbh.de
Olaf Clausen (CEO)
Darius Rauert (CEO)
Data Protection Officer
Isabel Tolzmann
AMCON Software GmbH
Osterstraße 15
49661 Cloppenburg
Phone +49 4471 91 42-0
Email: datenschutz@amcongmbh.de
If you contact us with a concern
You can contact us with concerns at any time. You can do this by telephone, letter,
e-mail, fax or in person. If you provide us with data, the following applies:
- Personal data: all information that you voluntarily provide to us
- Purposes of processing: processing your request
- Legal basis: Art. 6 para. 1 lit. a GDPR
- Recipients of the data:
- internal departments
- bodies to which we forward the data at your request
- Retention period: The data is archived after processing has been completed. The data in the archive will be deleted after 10 years.
Visitors to our website
When you visit our website, the following data is automatically processed:
- Personal data:
- Your IP address (Internet identification number of your device)
- Your Internet service provider
- Information that your browser automatically transmits
- Operating system of your device
- Browser type, browser version
- Last page accessed
- Websites that you have accessed via our website
- Date and time of your access to our website
- Cookies: A so-called “session cookie” is set. This is technically necessary. It is automatically deleted by your browser after you leave our website. No other cookies are used.
- Purposes of processing: Operation of the website, evaluation of malfunctions
- Legal basis: Art. 6 para. 1 lit. f GDPR
- Recipients of the data: none
- Retention period: 3 months
We use SSL encryption to ensure a high level of security. SSL-encrypted data cannot be read by third parties. Therefore, please ensure that SSL encryption is activated. The use of encryption is easy to recognize: The display in the browser line changes from “http://” to “https://”.
If you access a link to an external website from a third party, the data protection provisions of the third party apply. We cannot influence the data processing procedures.
Web analysis
We use the statistical analysis tool “Matomo” (https://matomo.org/) to continuously improve our website. Matomo is an open source project. Information from the third-party provider on data protection can be found at matomo.org/privacy-policy. Matomo does not transmit any data to servers that are outside our control. Matomo is deactivated when you visit our website. Your usage behavior is only recorded anonymously if you actively consent to this.
Matomo uses so-called cookies. These are text files that are stored on your computer and enable us to analyze the use of our website. For this purpose, the usage information obtained by the cookie is transmitted to our server and stored so that usage behavior can be evaluated. Your IP address is immediately anonymized. You therefore remain anonymous as a user. The information generated by the cookie about your use of this website is not passed on to third parties.
We use Matomo on the basis of Art. 6 para. 1 lit. f GDPR. We can use the statistics obtained to regularly improve our offer and make it more interesting for you as a user.
Newsletter Subscribers
You can subscribe to our free newsletter.
When registering, the following personal data is processed:
Mandatory information: Your email address
Optional information:
– Salutation
– First name
– Last name
– Company
Your newsletter registration is logged for legal reasons. The following will be stored: your registration data, the date and time of registration and confirmation, and the IP address used at the time. This data collection is necessary to be able to trace any misuse of your email address and to legally document your consent to receiving the newsletter.
There is no obligation to provide your data. However, we cannot send the newsletter without it. Therefore, there is a legitimate interest in this processing.
We use the so-called double opt-in procedure for sending the newsletter. This means we will only send you newsletters via email once you have explicitly confirmed that you wish to receive them. After submitting your data, you will receive a confirmation email with a link. This link must be clicked to authorize the newsletter subscription. Only upon confirmation will your email be added to our mailing list.
Please note that we analyze your user behavior when sending newsletters. This analysis includes tracking pixels in the emails, which let us see whether a message was opened and which links were clicked. If you do not want this tracking, you must unsubscribe from the newsletter.
We use the service provider rapidmail GmbH, Wentzingerstraße 21, 79106 Freiburg im Breisgau, Germany, for the delivery of newsletters. For more information, visit: https://www.rapidmail.de/
Purpose of processing: Sending newsletters, personalized addressing, preventing misuse of the email address, birthday greetings
Legal basis: Art. 6 (1) lit. a GDPR, Art. 6 (1) lit. f GDPR
Recipients:
– Internal departments
– Data processors
There is no transfer to third parties.
Retention period: Your data is stored as long as the newsletter subscription is active.
You can unsubscribe at any time via the link provided in each newsletter. The lawfulness of processing before withdrawal remains unaffected.
Newspaper Subscribers
You can subscribe to our free postal newspaper. In the future, we may send the newspaper electronically via email free of charge. The following data is processed upon registration:
Personal data – Mandatory information:
– Salutation
– First name, Last name
– Company
– Address
– Email address
Your newspaper subscription is logged for legal reasons. The following will be stored: your registration data, date and time of registration and confirmation, and your IP address. This is necessary to trace misuse and provide legally valid proof of your consent.
We use the double opt-in procedure. This means we will only send you the newspaper once you have explicitly confirmed your consent. You will receive a confirmation email with a link. Only after clicking the link will your data be added to the mailing list.
We use Google reCaptcha to determine whether a human or computer is making entries in our newspaper form. Google collects data such as:
– IP address
– Visited page
– Date/time
– Browser/system details
– Google account (if logged in)
– Mouse movements and image-based challenges
Legal basis: Art. 6 (1) lit. a GDPR. There is a legitimate interest in protecting our website from automated access (spam/attacks).
Purpose of processing: Sending newspapers, personalized addressing, preventing misuse within the double opt-in process
Legal basis: Art. 6 (1) lit. a GDPR
Recipients: Internal departments
There is no transfer to third parties.
Retention period: Your data is stored as long as the newspaper subscription is active.
You can unsubscribe at any time. The lawfulness of prior processing remains unaffected.
There is no obligation to provide data, but the newspaper cannot be sent without it.
Use of the transfer tool
You can use our transfer tool to send us large data files. When using the tool, the following applies:
Personal data: None
However, all uploaded files may contain personal data.
Purpose of processing: Data transfer
Legal basis: Art. 6 (1) lit. b and f GDPR
Source: Provided by the user
Recipients: Internal departments
Retention period: Depends on expiration date chosen; max. 3 months.
There is no obligation to use the tool; data can also be sent by post or other means. However, its use implies a legitimate interest.
Service Providers and Suppliers
Most of our service providers assign a specific contact person to AMCON Analytical Marketing Consulting GmbH. We process the contact information as follows:
Personal data:
– Name
– Company, company address
– Position, role
– Phone, fax
– Email address
Purpose of processing: Coordination of services and deliveries
Legal basis: Art. 6 (1) lit. f GDPR
Source of data: Provided by the contact person or their company
Recipients: Internal departments
Retention period: Archived after business relationship ends; deleted after 10 years.
There is no obligation to provide this data, but doing so facilitates efficient communication. Therefore, a legitimate interest exists.
Job Applicants
You may apply by post or preferably by email. We process the following data:
Personal data: Any data you submit with your application
Purpose of processing: Hiring decisions
Legal basis:
– Art. 88 GDPR in conjunction with §27 BDSG
– Art. 6 (1) lit. a GDPR (for longer data retention with your consent)
Recipients: Internal departments
Retention period:
– If hired: 10 years after end of employment
– If not hired: 6 months after rejection, unless consent for longer storage is given
Data is required to assess employment eligibility. Employment contracts are not possible without this data.
Use of Indeed
When clicking “Apply easily” on job postings on Indeed, a form appears where you can submit your name, email, phone number, resume, and a message.
For details on how Indeed processes your data, your rights, and settings, visit: https://de.indeed.com/legal.
Visitors to Our Facebook Page
Our Facebook privacy policy is available at: https://amcon.de/datenschutz/facebook
Visitors to Our Instagram Profile
Our Instagram privacy policy is available at: https://amcon.de/datenschutz/instagram
Visitors to Our LinkedIn Page
Our LinkedIn privacy policy is available at: https://amcon.de/datenschutz/linkedin
Hosting
Our website is hosted by Amazon Web Services (AWS), EMEA SARL, Germany Branch, Marcel-Breuer-Str. 12, 80807 Munich. Data is stored in a German data center (Frankfurt/Main), certified to ISO 27001, 27017, 2018, and PCI DSS Level 1.
When you visit our website, your personal data is processed on AWS servers. Data may be transferred to the AWS parent company in the USA. Transfers are based on EU Standard Contractual Clauses. Details: https://aws.amazon.com/de/blogs/security/aws-gdpr-data-processing-addendum/
AWS privacy policy: https://aws.amazon.com/de/privacy/?nc1=f_pr
Use of AWS is based on Art. 6 (1) lit. f GDPR, with a legitimate interest in reliable website performance.
We have signed a data processing agreement with AWS to ensure compliance with GDPR.
Your Rights
You have the following rights concerning your personal data:
– Right of access (Art. 15 GDPR)
– Right to rectification (Art. 16 GDPR)
– Right to erasure (Art. 17 GDPR)
– Right to restriction of processing (Art. 18 GDPR)
– Right to notification (Art. 19 GDPR)
– Right to data portability (Art. 20 GDPR)
– Right to object (Art. 21 GDPR)
– Right to lodge a complaint (Art. 77 GDPR)
– Right to withdraw consent at any time (Art. 7 GDPR)
To exercise your rights, please contact our data protection officer.
Automated Decision-Making and Profiling
We do not conduct any automated decision-making or profiling.