Thank you for your interest in our website. The protection of your privacy is very important to us. In accordance with Art. 13 DS-GVO, we inform you in detail below about the processing of your data that takes place when you use our website and its functionalities.
The controller of the data processing carried out through the website www.oraylis.de is:
ORAYLIS GmbH
Werkstraße 10 | 40670 Meerbusch
Phone: +49 211 179456-0 | Email: info@oraylis.de
Data Protection Officer of the company:
Prof. Thomas Jäschke, DATATREE AG
Heubesstraße 10 | 40597 Düsseldorf
Phone: +49 211 931 907 00 | Email: dsb@datatree.eu
You can visit our websites without providing any personal information. When you visit, we automatically store the following access data in so-called server log files without any action on your part:
- IP address of the requesting computer,
- Website from which the access is made (referrer URL),
- Browser type and version as well as other information transmitted by the browser (such as the operating system of your computer).
According to Article 6 (1) (f) of the GDPR (legitimate interest), this data processing is carried out to ensure the trouble-free operation of the website — for example, to guarantee a smooth connection setup, to evaluate system security and stability, to detect and prevent attacks on our website, among other purposes.
The information is stored in the log files for a period of 7 days and then deleted, unless further retention is necessary for evidence purposes until final clarification.
The provision, maintenance, adaptation, and servicing of our website is ensured by a service provider who processes your data on our behalf (data processing pursuant to Article 28 GDPR). If additional service providers are involved or data is transferred to third parties in any other way, this will be listed separately in the corresponding sections.
Our website provides you with contact forms, a feature through which we collect, process, and store personal data when used. Below, we explain what happens to this data: The data entered via our contact forms (required fields: name, surname, email address, phone number, inquiry) are used (based on your consent, contract fulfillment, or our legitimate interest – Art. 6(1)(a), (b), and (f) GDPR) solely for processing inquiries submitted through the forms. Additional information in the contact form (company, position) is voluntary. To process your inquiry, we record your contact details in our CRM and may contact you via email if we believe we have an offer that may interest you. The legal basis is our legitimate interest in establishing contacts in a B2B environment and using contact details obtained through the contact forms for this purpose (Art. 6(1)(f) GDPR). We store the personal data collected via our contact form for the duration of communication and processing of your inquiry. You may object to this data processing at any time without providing reasons, effective for the future, by emailing us at info@oraylis.de. Upon objection, your data will be deleted immediately unless you have provided it in another context (e.g., for an application) and it may be subject to legal retention obligations. If further communication arises from the contact, such as an offer, interview, or contract, data processing (including storage duration) will follow the procedures defined therein. Additionally, contractual obligations under § 257 of the German Commercial Code (HGB) may apply.
Newsletter
You also have the option to subscribe to our newsletter. Through this newsletter, we inform you about our company, products, and services. If you wish to receive the newsletter, we process your email address, salutation, and surname (required fields) based on your consent (Art. 6(1)(a) GDPR). Additional details (company, title, first name) are voluntary. For verification purposes, we store (Art. 6(1)(f) GDPR) your IP address and the time of registration and confirmation.
Furthermore, the data you enter is transmitted in pseudonymized form via an interface to the social networks LinkedIn and Facebook so that you may receive information about our offers and company news while using these networks. More details can be found in the sections “Use of LinkedIn Conversion API” and “Use of Meta Conversion API.”
Your information is stored in our CRM system. For this purpose and to send the newsletter, your data is stored in the CRM software HubSpot. More details about HubSpot can be found in the section below.
You can unsubscribe from the newsletter at any time without providing reasons, effective for the future, via a link in the newsletter. Alternatively, you may email us at info@oraylis.de. Upon objection, your personal data will be deleted immediately unless you have provided it in another context (e.g., for an application) and it may be subject to legal retention obligations.
We inform you that we analyze your user behavior when sending the newsletter. For this analysis, the emails contain web beacons or tracking pixels, which are single-pixel image files stored on our website. For evaluation, we link data and web beacons with your email address and a unique ID. The data mentioned above includes the IP address, date and time of the request, time zone difference to Greenwich Mean Time, request content (specific page), access status/HTTP status code, data volume transmitted, referring website, browser, operating system and its interface, browser language, and version. Links in the newsletter also contain this ID.
Blog
You can comment on our blog posts. The data provided is used only for publishing the comment. As the website operator, we are responsible for the content. Based on our legitimate interest (Art. 6(1)(f) GDPR), we store your IP address when you leave a comment to trace potential comments containing insults, polemics, racism, or other unlawful content. Comments remain published and stored until revoked. You may object to this data processing and the publication of your comment at any time without providing reasons, effective for the future, by emailing us at info@oraylis.de.
Event Registration (In-Person Events, Webinars, Strategy Meetings, etc.)
If you register for an event via our website, we process your personal data (required fields: first name, last name, company, email address) based on your consent (Art. 6(1)(a) GDPR) to ensure your participation (e.g., inclusion in the attendee list, sending booking confirmation). If we conduct events in cooperation with another company or with a service provider (e.g., event hotel, webinar software provider), your data will be forwarded to them for event execution. Our contracts with partners/service providers ensure GDPR-compliant data handling. Note that some events are hosted by partners, and you enter data directly on their site. In such cases, refer to their privacy policy.
To promote events/webinars and implement registration forms, we use Mobile Funnel (hereinafter: Funnel). Details about this provider and functionality are in the “Use of Mobile Funnel” section below. Alternatively, you can register via our contact form or LinkedIn. When using the Funnel, our contact form, or LinkedIn, we record your contact details in our CRM and may email you with relevant offers. The legal basis is our legitimate interest in establishing B2B contacts (Art. 6(1)(f) GDPR).
Your data is also pseudonymized and shared with LinkedIn/Facebook for targeted advertising. More details are in the “LinkedIn Conversion API” and “Meta Conversion API” sections.
You may object to this processing at any time without reasons by emailing info@oraylis.de. Data will be deleted immediately unless legally required for retention (e.g., applications). Further communication (e.g., offers, contracts) follows respective procedures.
Career Magazine Download
To request our career magazine, we need your first name and email address. We use this data to send you a download link based on your consent (Art. 6(1)(a) GDPR). We may also use it to track prior contact or notify you of relevant job openings (legal basis: Art. 6(1)(f) GDPR). Object anytime via info@oraylis.de. Deletion follows unless legally retained (e.g., applications). Further communication (e.g., hiring processes) follows respective procedures.
Whitepaper Download
For whitepaper downloads, we use Mobile Funnel (see section below). Alternatively, use our form or LinkedIn. When downloading, we record your contact details (required: first/last name, company, position, email) in our CRM and may contact you with offers (Art. 6(1)(f) GDPR). Object via info@oraylis.de.
Data is pseudonymized and shared with LinkedIn/Facebook (see relevant sections). Whitepaper downloads require newsletter consent (Art. 6(1)(a) GDPR). Unsubscribe anytime via link or email. See “Newsletter” section for details.
Data is deleted upon objection unless legally retained. Further communication (e.g., contracts) follows respective procedures.
Use of HubSpot as CRM Software, for Contact Forms, and Newsletter Delivery
For contact forms, newsletters, and contact management, we use HubSpot (HubSpot Inc., 25 First Street, Cambridge, MA 02141, USA). Data is hosted in EU data centers but may transfer to US servers. We have a Data Processing Agreement (DPA) (https://legal.hubspot.com/dpa) and EU Standard Contractual Clauses to ensure GDPR compliance. HubSpot’s Privacy Shield certification guarantees equivalent data protection. Privacy policy: https://legal.hubspot.com/privacy-policy.
Use of Mobile Funnel
We use “involve.me” for quiz funnels to engage (potential) customers. Behavioral analysis improves conversion rates. Form data processing is based on consent (Art. 6(1)(a) GDPR).
We record contact details (required: first/last name, company, position, email) in our CRM and may email relevant offers (Art. 6(1)(f) GDPR). Object via info@oraylis.de. Data is deleted unless legally retained. Further communication follows respective procedures.
Quiz funnels are powered by stereosense GmbH (Austria). A data processing agreement (Art. 28(3) GDPR) is in place. Data is SSL-encrypted. Server logs (domain, browser, OS, timestamp) are stored for 7 days; session IDs track interactions (storage: 1 month/browser session). Legal basis: Art. 6(1)(f) GDPR (security) or performance optimization.
With consent (Art. 6(1)(a) GDPR), data is used for analytics. Revoke consent anytime via info@oraylis.de.
Signature
For email signature marketing, we use mailtastic (NETSTAG GmbH, Mainz). Clicking a signature banner redirects to our website or a funnel (see above).
Webinars
We use Banzai International Inc.’s webinar tool for live sessions, recordings, and attendee interaction (presentations, polls).
During participation, Banzai collects in-session data (screen, clicks, movements, device/browser data, chat content). We analyze attendee engagement:
- Registration/channel sources (Meta, etc.),
- Attendance/no-shows,
- Participation duration,
- Login/logout timestamps,
- Real-time engagement (clicks, downloads, chat activity).
Data is stored and analyzed to tailor webinars to preferences.
Banzai processes data per Art. 6(1)(a) GDPR with your consent. Revoke via info@oraylis.de. Data is deleted immediately.
We have a data processing agreement (Art. 28(3) GDPR) with Banzai, including Standard Contractual Clauses for US transfers. Banzai seeks EU-U.S. Data Privacy Framework certification. Until certified, US data transfers lack equivalent protection. Privacy policy: https://www.banzai.io/legal/privacy-policy.
Use of LinkedIn Conversion API
For marketing/analytics, we use LinkedIn Conversion API (LinkedIn Ltd., Ireland). When you interact with our website (e.g., newsletter signup, whitepaper download, webinar registration), data is recorded in our CRM, pseudonymized (SHA-256 hashing), and matched with LinkedIn profiles. Data is deleted after 180 days; aggregated reports remain.
With consent (via banner), LinkedIn Insight Tag tracks website usage (see §5 > LinkedIn Insight Tag). Pseudonymized usage data is merged with ad platform data.
Details: https://www.linkedin.com/help/lms/answer/a1686124?lang=de-DE and LinkedIn Ads Terms (https://de.linkedin.com/legal/sas-terms?).
LinkedIn members may see our company updates. Legal basis: consent (Art. 6(1)(a) GDPR) via banner/form submissions. Object via info@oraylis.de. Data is deleted unless legally retained.
Data may transfer outside the EU (e.g., US servers). LinkedIn’s Data Privacy Framework certification ensures equivalent protection. Contracts guarantee GDPR compliance (Art. 45, 46 GDPR).
LinkedIn’s privacy policy: https://de.linkedin.com/legal/privacy-policy?#choices-oblig.
You can apply for open positions via our website or send us your unsolicited application. Please only use the application platform provided for this purpose. We can then guarantee that your application will only be processed by the appropriately authorized persons in our company.
For the automated processing of your application, we process the following data from you:
- First name, last name, e-mail and, if applicable, address/city, date of birth, title, telephone number, citizenship, and, if applicable, other data relevant to the position (e.g. driver’s license).
- Data from your motivation letter and CV, in particular information on professional experience and education, skills (e.g. Photoshop, MS Office), qualifications, awards and language skills
- Application photo, references, letters of recommendation, other documents you may upload
- We store the written, electronic communication that takes place between you and us. Furthermore, we process comments that are written about you in the course of your application process.
The data is stored for the purpose of processing your application and establishing an employment relationship Art. 6 para. 1 lit. b DSGVO. After receipt, your application will first be pre-sorted by the HR department and, if you are interested, forwarded to the relevant managers of the specialist department. If you receive a rejection, your documents will be deleted/destroyed in the specialist departments. For reasons of verifiability (contractual obligations, if applicable, personnel service providers, proof with regard to possible claims based on the General Equal Treatment Act), your data will be stored for a maximum of 12 months and then deleted. If we store your application for a longer period of time in order to contact you again at a later date about career prospects with our company, this will only happen if you give us your consent to do so (Art. 6 Para. 1 lit. a DSGVO). You can revoke your consent to data processing at any time and without giving reasons with effect for the future by sending us an e-mail to info@oraylis.de.
We use the e-recruiting system “Onlyfy” (Onlyfy International GmbH, Mariahilfer Straße 17, 1060 Vienna) to receive and process applications, so your data is hosted in the systems of Onlyyfy. An agreement on order processing according to Art. 28 para. 3 DSGVO is available.
In order to provide its services, Onlyfy commissions further subcontractors for the provision of IT services. In such a case, Onlyfy contractually obligates the order processors to comply with the applicable data protection provisions. For more information on the purpose and scope of data collection and its processing by Onlyfy, please refer to the privacy policy of Onlyfy International GmbH: https://onlyfy.io/de/datenschutzerklaerung/.
To generate applicants, we also use Mobile Funnel from Software perspective. You can find all information about this in § 3 “Use of Mobile Funnel”.
Cookies
Cookies are small text files that are placed on your computer by a web server. When you visit the website again, it can recognize your web browser through the cookie. Cookies cannot execute programs or transmit viruses to your computer. They serve to make the internet offering more user-friendly and effective overall.
There are different types of cookies, whose scope and functionality we would now like to explain:
- There are so-called temporary or transient cookies, which are automatically deleted when you close the browser. These include session cookies, among others. These store a so-called session ID, which allows various requests from your browser to be assigned to a common session. This enables your computer to be recognized when you return to our website. The session cookies are deleted when you log out or close your web browser.
- Furthermore, there are permanent or persistent cookies, which remain stored after closing the browser but are automatically deleted after a specified period. The duration varies depending on the cookie, although we would like to point out that you can delete the cookies at any time using the security settings of your web browser.
- Third-party cookies are cookies that are offered by providers other than the controller operating the online service.
We also use Mobile Funnel (hereinafter: Funnel) for the technical implementation of various forms. Through the use of this tool, cookies are also set, about which you can find more information in § 3 (section on the use of Mobile Funnel). The use of cookies is based on Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG, only in the case that you have given us your consent through the selection in our consent banner. If you have not consented, no data processing takes place.
Detailed information about the cookies and pixels we use can be obtained by clicking on the “Privacy Settings” button integrated in the footer of our website and thus calling up the consent banner. You can then view detailed information about the individual tools under the right-hand item “Services”.
Legal Basis for Use
The use of certain cookies is necessary to ensure the functionality and security of our site (Art. 6(1)(f) GDPR, legitimate interest). When you visit our site for the first time, you will be informed via our consent banner which technically necessary cookies are strictly required for the operation of the site. Via the consent banner, you can also make a selection as to which technically non-essential cookies are used based on your visit to our site.
The implementation of this selection via the consent banner we use requires the use of a cookie that is stored on your device for a period of one year, unless you delete it beforehand through your browser settings. Through the use of a consent banner, the following data is processed:
- Date and time of the visit
- Browser information
- Information about consents
- Device information
- The IP address of the requesting device.
The legal basis is our legitimate interest (Art. 6(1)(f) GDPR) in maintaining proof of the cookie selection you have made and fulfilling our accountability obligation under Art. 5(2) GDPR.
If you consent via the consent banner that technically non-essential cookies (usually for the implementation of tracking and remarketing tools) are set, the processing of your personal data is based on your consent (Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG)
Use of Google reCAPTCHA
We use Google reCAPTCHA on our website, a service of Google Ireland Limited with its registered office at Gordon House, Barrow Street, Dublin 4, Ireland. Google reCAPTCHA attempts to distinguish whether a particular action is performed by a human or by a computer program or “bot”. During the verification by Google reCAPTCHA, the following personal data, among others, is transmitted to Google:
- The page that integrates Google reCAPTCHA
- Your IP address
- Your browser’s language setting
- Information about screen and window resolution
- The time zone
- Installation of browser plugins
Additionally, Google reCAPTCHA checks whether a cookie has already been set in your browser. If this is not the case, a cookie is set by Google reCAPTCHA.
Furthermore, we would like to inform you that Google Fonts is a component of the Google reCAPTCHA tool and is loaded as a necessary sub-function within this service.
For details about the collection and storage of your personal data as well as the type, scope, and purpose of their use by Google reCAPTCHA, please refer to Google’s privacy policy: https://policies.google.com/technologies/partner-sites?hl=de.
Use of Google Analytics for Web Analysis
We use Google Analytics on our website, a service of Google Ireland Limited with its registered office at Gordon House, Barrow Street, Dublin 4, Ireland. This is a web-based analysis tool with which we can analyze the use of our website and make our web presence more interest-appropriate. During your visit to our website, Google Analytics places a cookie on your device with which your browser can be recognized and your behavior analyzed. When subpages of our website are accessed, the following personal data is collected by Google Analytics, among others:
- Your IP address
- The subpage accessed and time of access
- The source of your visit (i.e., via which website you came to us)
- Technical information (information about browser, internet provider, device, and screen resolution)
- The achievement of “website goals” (e.g., contact requests, newsletter registrations)
The use of Google Analytics is based on your consent according to Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG only in the case that you have given us your consent through the selection in our cookie banner. We would like to inform you that you can revoke your consent at any time according to Art. 7(3) GDPR with effect for the future without stating reasons by clicking on the “Privacy Settings” button integrated in the footer of our website and thus calling up the consent banner. Using the banner, you can then make a new selection. Alternatively, Google provides a deactivation add-on that can be installed on common internet browsers. The link to the deactivation add-on can be found at: https://tools.google.com/dlpage/gaoptout?hl=de. This add-on ensures that information about your visit to our website is not transmitted to Google Analytics.
We cannot rule out that personal data may be transmitted outside the legal territory of the European Union, e.g., to servers located in the USA. Google is certified under the Data Privacy Framework and guarantees an equivalent level of data protection in the event of a possible data transfer to the USA. Furthermore, we have concluded agreements with Google regarding data processing. Through these agreements, Google ensures that they process the data in accordance with the GDPR and guarantee the protection of the rights of the data subject (Art. 45, 46 GDPR).
For details about the collection and storage of your personal data as well as the type, scope, and purpose of their use by Google Analytics, please refer to Google’s privacy policy: https://policies.google.com/technologies/partner-sites?hl=de.
Google Ads
For the promotion of our website, we use Google Ads (Google Ireland Limited with its registered office at Gordon House, Barrow Street, Dublin 4, Ireland). Google Ads is an internet advertising service that allows advertisers to place ads both in Google’s search engine results and in the Google advertising network. Google Ads enables an advertiser to predefine certain keywords that will cause an ad to appear in Google’s search engine results only when the user retrieves a keyword-relevant search result with the search engine. In the Google advertising network, the ads are distributed via an automatic algorithm and in compliance with the predefined keywords on thematically relevant websites.
If a data subject accesses our website via a Google ad, a so-called conversion cookie is placed on the data subject’s IT system by Google. The purpose of Google Ads is to promote our website by displaying interest-relevant advertising on third-party websites and in the search engine results of Google and to display third-party advertising on our website. A conversion cookie loses its validity after 30 days and does not serve to identify the data subject. Via the conversion cookie, it can be tracked whether certain subpages of our website have been accessed, provided the cookie has not yet expired. Through the conversion cookie, both we and Google can track how a data subject who came to our website via an AdWords ad behaved, e.g., whether they ordered a newsletter or not.
The data and information collected through the use of the conversion cookie are used by Google to create visit statistics for our website. These visit statistics are in turn used by us to determine the total number of users who were referred to us via Ads ads, i.e., to determine the success or failure of the respective Ads ad and to optimize our AdWords ads for the future or to make our web presence more interest-appropriate. The use of Google AdWords is based on your consent according to Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG only in the case that you have given us your consent through the selection in our cookie banner. You can revoke your consent at any time according to Art. 7(3) GDPR with effect for the future without stating reasons by clicking on the “Privacy Settings” button integrated in the footer of our website and thus calling up the consent banner. Using the banner, you can then make a new selection. Additionally, you can object to interest-based advertising by Google by calling up www.google.de/settings/ads in the internet browser you use and making the desired settings there.
We cannot rule out that personal data may be transmitted outside the legal territory of the European Union, e.g., to servers located in the USA. Google is certified under the Data Privacy Framework and guarantees an equivalent level of data protection in the event of a possible data transfer to the USA. Furthermore, we have concluded agreements with Google regarding data processing. Through these agreements, Google ensures that they process the data in accordance with the GDPR and guarantee the protection of the rights of the data subject (Art. 45, 46 GDPR).
For details about the collection and storage of your personal data as well as the type, scope, and purpose of their use by Google Ads, please refer to Google’s privacy policy: https://policies.google.com/technologies/partner-sites?hl=de.
Google Tag Manager
We use Google Tag Manager on our website, a service of Google Ireland Limited with its registered office at Gordon House, Barrow Street, Dublin 4, Ireland. This is an organizational tool with which we can manage our analysis tags via an interface. In doing so, Google Tag Manager collects data on our website and forwards it to our connected analysis tools. The connected analysis tools store and evaluate this data. Google Tag Manager itself does not set cookies and does not store personal data. The organizational tool only collects data about how individual tags are used.
The use of Google Tag Manager is based on Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG only in the case that you have given us your consent through the selection in our cookie banner. You can revoke your consent at any time according to Art. 7(3) GDPR with effect for the future without stating reasons by clicking on the “Privacy Settings” button integrated in the footer of our website and thus calling up the consent banner. Using the banner, you can then make a new selection.
We cannot rule out that personal data may be transmitted outside the legal territory of the European Union, e.g., to servers located in the USA. Google is certified under the Data Privacy Framework and guarantees an equivalent level of data protection in the event of a possible data transfer to the USA. Furthermore, we have concluded agreements with Google regarding data processing. Through these agreements, Google ensures that they process the data in accordance with the GDPR and guarantee the protection of the rights of the data subject (Art. 45, 46 GDPR).
Further information about Google Tag Manager can be found at https://support.google.com/tagmanager/answer/9323295?hl=de. For details about the collection and storage of your personal data as well as the type, scope, and purpose of their use through the use of Google Tag Manager, please refer to Google’s privacy policy: https://policies.google.com/privacy.
Hotjar
We use Hotjar on our website. This is a web analysis service of Hotjar Limited, Level 2, St. Julian’s Business Centre 3, Elia Zammit Street, St. Julian’s STJ 1000, Malta. With Hotjar, we can record and evaluate your user behavior on our website, in particular your mouse behavior (movement, clicks). Your visit to our website is anonymized. Furthermore, only information about the operating system, your internet browser, incoming or outgoing referrals (so-called links), geographical origin, and the device used is evaluated and processed for statistical purposes.
The use of Hotjar is based on Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG only in the case that you have given us your consent through the selection in our consent banner. If you have not consented, no data processing takes place.
You can revoke your consent at any time according to Art. 7(3) GDPR with effect for the future without stating reasons by clicking on the “Privacy Settings” button integrated in the footer of our website and thus calling up the consent banner. Using the banner, you can then make a new selection.
For details about the collection and storage of your personal data as well as the type, scope, and purpose of their use by Hotjar, please refer to Hotjar’s privacy policy: https://hotjar.com/privacy.
Hubspot Pixel
Furthermore, we use the analysis function of the CRM software Hubspot we use (see also § 3) on our website. Through the use of Hubspot, pixels are stored locally on your device and thus enable an analysis of the use of the website, in particular the use of the contact forms integrated on our site. For this purpose, data such as your IP address, geographical location, type of browser, duration of visit, and pages accessed are collected and analyzed by Hubspot.
The use of the Hubspot Pixel is based on your consent according to Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG only in the case that you have given us your consent through the selection in our cookie banner. You can revoke your consent at any time according to Art. 7(3) GDPR with effect for the future without stating reasons by clicking on the “Privacy Settings” button integrated in the footer of our website and thus calling up the consent banner. Using the banner, you can then make a new selection.
We cannot rule out that personal data may be transmitted outside the legal territory of the European Union, e.g., to servers located in the USA. Hubspot is certified under the Data Privacy Framework and guarantees an equivalent level of data protection in the event of a possible data transfer to the USA. Furthermore, we have concluded a Data Protection Addendum with Hubspot. Through these agreements, Hubspot ensures that the data is processed in accordance with the GDPR and that the protection of the rights of the data subject is guaranteed (Art. 45, 46 GDPR).
Facebook Pixel
On our website, the so-called “Facebook Pixel” of the provider Facebook (Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland) is used.
This is a code that we have implemented on our website. When you visit our website, this code establishes a connection with Facebook’s servers to track your behavior on our website. Among other things, the following personal data is collected by the Facebook Pixel:
- Your IP address
- Device information (device ID, device type, and your operating system)
Facebook uses this personal data to identify visitors to our website and to assign their actions to a Facebook user account as well as to display personalized advertising and create interest-based user profiles. The individual data processing operations and their scope are not necessarily traceable for us. The collected data remains anonymous and invisible to us and is only usable for us in the context of measuring the effectiveness of advertising placements.
The use of the Facebook Pixel is based on Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG only in the case that you have given us your consent through the selection in our consent banner. If you have not consented, no data processing takes place.
You can revoke your consent at any time according to Art. 7(3) GDPR with effect for the future without stating reasons by clicking on the “Privacy Settings” button integrated in the footer of our website and thus calling up the consent banner. Using the banner, you can then make a new selection.
We cannot rule out that personal data may be transmitted outside the legal territory of the European Union, e.g., to servers located in the USA. Meta is certified under the Data Privacy Framework and guarantees an equivalent level of data protection in the event of a possible data transfer to the USA. Furthermore, Facebook ensures within the framework of contractual agreements that they process the data in accordance with the GDPR and guarantee the protection of the rights of the data subject (Art. 45, 46 GDPR).
For details about the collection and storage of your personal data as well as the type, scope, and purpose of their use by the Facebook Pixel, please refer to Facebook’s privacy policy: https://de-de.facebook.com/privacy/policy/?entry_point=data_policy_redirect&entry=0.
LinkedIn Insight Tag
On our website, we use the LinkedIn Insight Tag of LinkedIn Corporation and the associated conversion tracking technology as well as the retargeting function of LinkedIn Ireland Unlimited Company with its registered office at Wilton Place, Dublin 2, Ireland. During your visit to our website, the LinkedIn Insight Tag places a cookie on your device with which LinkedIn members can be identified and their behavior analyzed. Among other things, the following personal data is collected by the LinkedIn Insight Tag:
- Your IP address
- Referrer URL and URL
- Time of access
- Technical information (information about browser, internet provider, device, and screen resolution)
This data is encrypted and anonymized within seven days. The anonymized data is deleted within 90 days. We do not receive any personal data from LinkedIn. The individual data processing operations and their scope are not necessarily traceable for us. We can only see summarized reports about the website’s target audience and ad performance in order to achieve a target group-appropriate improvement of the user experience when visiting our website.
If you are logged into your LinkedIn account during an online session, LinkedIn assigns your visit to our website to your personal user account. In addition, the use of the LinkedIn Insight Tag enables retargeting of visitors to our website. Based on this retargeting, we can address visitors to our website with advertising outside our website.
The use of the LinkedIn Insight Tag is based on Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG only in the case that you have given us your consent through the selection in our consent banner. If you have not consented, no data processing takes place.
You can revoke your consent at any time according to Art. 7(3) GDPR with effect for the future without stating reasons by clicking on the “Privacy Settings” button integrated in the footer of our website and thus calling up the consent banner. Using the banner, you can then make a new selection. Additionally, we recommend that you log out of your LinkedIn account, delete your cookies in the browser settings, and restart the browser. Alternatively, you can object to the collection by the LinkedIn Insight Tag by adjusting your advertising settings in your LinkedIn profile accordingly. In this regard, you can use the following link to disable the use of the LinkedIn Insight Tag and the use of interest-based advertising on LinkedIn: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
We cannot rule out that personal data may be transmitted outside the legal territory of the European Union, e.g., to servers located in the USA. LinkedIn is certified under the Data Privacy Framework and guarantees an equivalent level of data protection in the event of a possible data transfer to the USA. Furthermore, LinkedIn ensures within the framework of contractual agreements that the data is processed in accordance with the GDPR and that the protection of the rights of the data subject is guaranteed (Art. 45, 46 GDPR).
For details about the collection and storage of your personal data as well as the type, scope, and purpose of their use by the LinkedIn Insight Tag, please refer to LinkedIn’s privacy policy. There you will also find further information about your rights and setting options to protect your privacy https://de.linkedin.com/legal/privacy-policy?#choices-oblig.
Zapier
We use Zapier on our website, a service of Zapier Inc. with its registered office at 548 Market St #62411, San Francisco, California 94104, USA. Zapier is a web service with which we can link actions between different tools and thus synchronize the applications with each other. During the use of Zapier, the following personal data, among others, can be collected:
- Names,
- Email addresses,
- IP address,
- Details about the website visit
The use of Zapier is based on Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG only in the case that you have given us your consent through the selection in our consent banner. If you have not consented, Zapier will not be used.
You can revoke your consent at any time according to Art. 7(3) GDPR with effect for the future without stating reasons by clicking on the “Privacy Settings” button integrated in the footer of our website and thus calling up the consent banner. Using the banner, you can then make a new selection.
The personal data transmitted to Zapier is used solely for technical processing and for the administration of our services.
Zapier is certified under the Data Privacy Framework and guarantees an equivalent level of data protection in the event of a possible data transfer to the USA
For details about the collection and storage of your personal data as well as the type, scope, and purpose of their use by Zapier, please refer to Zapier’s privacy policy: https://zapier.com/privacy.
Surfer SEO
We use the analysis tool Surfer SEO, a service of Surfer Sp. z o.o., Plac Solny 14/3, 50-062 Wrocław, Poland. With Surfer SEO, we are shown anomalies on our website and are supported in using the right keywords to optimize our texts as best as possible for search engines.
The use of Surfer SEO is based on Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG only in the case that you have given us your consent through the selection in our consent banner. If you have not consented, Zapier will not be used.
You can revoke your consent at any time according to Art. 7(3) GDPR with effect for the future without stating reasons by clicking on the “Privacy Settings” button integrated in the footer of our website and thus calling up the consent banner. Using the banner, you can then make a new selection.
For details about the collection and storage of your personal data as well as the type, scope, and purpose of their use by Surfer SEO, please refer to Surfer SEO’s privacy policy: https://surferseo.com/privacy-policy/.
Social Plug Ins
Through the use of the plug-ins named below, we offer you the opportunity to interact with social networks and other users so that we can improve our offer and make it more interesting for you as a user. The legal basis for the use of the plug-ins is Art. 6 para. 1 p. 1 lit. f DS-GVO. We use the so-called Shariff solution. This means that when you visit our site, no personal data is initially passed on to the providers of the plug-ins. You can identify the provider of the plug-in by marking the box with its initial letter or logo. We give you the opportunity to communicate directly with the provider of the plug-in via the button. Only when you click on the marked box and thereby activate it, does the plug-in provider receive the information that you have accessed the corresponding website of our online offer
You have the option of interacting with the social network by clicking on the button. Please note that even without interaction on your part, your data will be collected by the provider of the social network. To the best of our knowledge, we inform you as follows:
By using the plug-in, the plug-in provider receives the information that you have accessed the corresponding website of our online offer. In addition, the IP address, the date and time of the request; the time zone difference to Greenwich Mean Time; the content of the request (specific page); the access status/HTTP status code; the respective amount of data transferred; the website from which the request comes, the browser; the operating system and its interface and the language as well as the version of the browser software are transmitted.
According to the providers, the IP address is anonymised immediately after collection. By activating the plug-in, your personal data may be transmitted to the respective plug-in provider and stored there (in the case of US providers, in the USA). Since the plug-in provider collects the data in particular via cookies, we recommend that you delete all cookies via your browser’s security settings before clicking on the greyed-out box.
The plug-in provider stores the data collected about you as a usage profile and uses it for the purposes of advertising, market research and/or designing its website to meet your needs. Such an evaluation is carried out in particular (also for users who are not logged in) for the display of needs-based advertising and to inform other users of the social network about your activities on our website. You have the right to object to the creation of these user profiles, whereby you must contact the respective plug-in provider to exercise this right.
The data transfer takes place regardless of whether you have an account with the plug-in provider and are logged in there. If you are logged in to the plug-in provider, your data collected from us will be directly assigned to your account with the plug-in provider. If you click the activated button and, for example, link to the page, the plug-in provider also saves this information in your user account and shares it publicly with your contacts. We recommend that you log out regularly after using a social network, but especially before activating the button, as this will help you to avoid an assignment to your profile with the plug-in provider.
We have no influence on the data collected and data processing procedures, nor are we aware of the full extent of the data collection, the purposes of the processing, the storage periods. We also have no information on the deletion of the collected data by the plug-in provider.
Further information on the purpose and scope of the data collection and its processing by the plug-in provider can be found in the data protection declarations of these providers communicated below. There you will also receive further information on your rights in this regard and setting options for protecting your privacy.
Facebook privacy policy
http://www.facebook.com/policy.php; further information on data collection: http://www.facebook.com/help/186325668085084, http://www.facebook.com/about/privacy/your-info-on-other#applications and http://www.facebook.com/about/privacy/your-info#everyoneinfo. Facebook has submitted to the EU-US Privacy Shield, https://www.privacyshield.gov/EU-US-Framework.
Privacy policy Twitter
Twitter, Inc, 1355 Market St, Suite 900, San Francisco, California 94103, USA; https://twitter.com/privacy. Twitter has submitted to the EU-US Privacy Shield, https://www.privacyshield.gov/EU-US-Framework.
Privacy policy LinkedIn
LinkedIn Corporation, 2029 Stierlin Court, Mountain View, California 94043, USA; http://www.linkedin.com/legal/privacy-policy. LinkedIn hat sich dem EU-US-Privacy-Shield unterworfen, https://www.privacyshield.gov/EU-US-Framework.
Privacy policy Xing
Xing AG, Gänsemarkt 43, 20354 Hamburg, DE; http://www.xing.com/privacy.
Integration of widgets from the providers kununu and glassdoor
We have integrated so-called “widgets” from the providers kununu and glassdoor on our careers page. The integration of these widgets means that if the overall rating of our company changes in these forums, this change is automatically adjusted on our website.
When you call up the page, kununu or glassdoor receives the information that you have called up the corresponding sub-page of our website. In addition, the IP address, date, time, content (specific page) of the request; the access status/HTTP status code; the respective amount of data transferred; the website from which the request comes, the browser; the operating system and its interface and the language as well as the version of the browser software are transmitted. This takes place regardless of whether the provider of the respective widget provides a user account via which you are logged in or whether no user account exists. If you are logged in to the respective provider, your data will be directly assigned to your account. If you do not wish to have your data associated with your profile, you must log out before accessing the provider’s site. We assume that the respective provider uses the data received for the purposes of advertising, market research, creation of user profiles or similar, but we cannot provide you with any concrete information on this.
The provider Glassdoor Inc. is certified under the E.U.-U.S. Privacy Shield agreement and, according to its own statement, processes the data in the function of the data controller. Please contact the respective provider for further information on the purpose and scope of the processing of the data as well as your rights and settings options in this regard:
- Privacy policy kununu: kununu GmbH, Neutorgasse 4-8, Top 3.02, A-1010 Wien,
https://privacy.xing.com/de/datenschutzerklaerung - Privacy policy glassdoor: Glassdoor, Inc., 100 Shoreline Highway, Building A, Mill Valley, California, 94941, USA, https://www.glassdoor.com/about/privacy.htm, https://help.glassdoor.com/Privacy_Request/en_US
Integration of YouTube videos (extended data protection mode)
We have integrated YouTube videos into our online offer, which are stored on http://www.YouTube.com and can be played directly from our website. These are all integrated in “extended data protection mode”, i.e. no data about you as a user is transmitted to YouTube if you do not play the videos. Only when you play the videos will the data mentioned in paragraph 2 be transmitted. We have no influence on this data transmission.
By visiting the website, YouTube receives the information that you have accessed the corresponding sub-page of our website. In addition, the IP address, the date and time of the request; the time zone difference to Greenwich Mean Time; the content of the request (specific page); the access status/HTTP status code; the respective amount of data transferred; the website from which the request comes, the browser; the operating system and its interface and the language as well as the version of the browser software are transmitted. This takes place regardless of whether YouTube provides a user account via which you are logged in or whether no user account exists. If you are logged in to Google, your data will be directly assigned to your account. If you do not want your data to be associated with your YouTube profile, you must log out before activating the button. YouTube stores your data as usage profiles and uses them for the purposes of advertising, market research and/or designing its website in line with requirements. Such an evaluation is carried out in particular (even for users who are not logged in) to provide needs-based advertising and to inform other users of the social network about your activities on our website. You have the right to object to the creation of these user profiles, and you must contact YouTube to exercise this right.
For more information on the purpose and scope of data collection and its processing by YouTube, please see the privacy policy. There you will also find further information on your rights and setting options to protect your privacy: https://www.google.de/intl/de/policies/privacy. Google also processes your personal data in the USA and has submitted to the EU-US Privacy Shield, https://www.privacyshield.gov/EU-US-Framework.
Our company operates the following company presences in the social networks:
- YouTube
- kununu
- glassdoor
Joint responsibility and legal basis
As operators of these company presences, we jointly process personal data with the respective provider of the social network (joint responsibility pursuant to Art. 26 DS-GVO). By creating and publishing our company presences, we have accepted the terms of use of the respective social network, which regulate the conditions of use of the site and the resulting data processing.
The legal basis for the data processing is our legitimate interest (Art. 6 (1) lit. f DS-GVO) to present our company in common communication media and to offer applicants, interested parties and other persons a form of communication with our company that they prefer and that is common in today’s world.
We would like to point out that the use of social media by you, in particular the interactions with the networks such as posting and sharing, is at your own responsibility and that you can alternatively contact us via the contact form on the website or by mail/letter/phone.
Data processing during a visit to one of our company presences on social networks
According to our state of knowledge, we inform you as follows about the data processing that arises from the use of our appearances in social media.
When you visit one of our company websites on a social network, the provider of the social network receives information about you, your surfing and usage behaviour, your interactions and your respective location by collecting your IP address and using cookies, pixels and web beacons. From this information, the social network provider forms a user profile. We cannot exclude that data stored in the user profiles are stored across devices and/or that the user profile is linked to your data stored in the network.
The social network uses the information about you collected in this way to compile statistics about the use and user structure of the network and to place interest-based advertising within and outside the network. The advertising models of social networks also provide that the social networks transmit data about your usage behaviour to third parties (advertising partners) outside the network or receive data from them about your surfing/usage behaviour from outside the network.
The social networks provide advertisers with anonymised statistical data with their offers such as “Facebook Insights” or “LinkedIn Website Demographics”, e.g. information on page views, activities, proportion of men/women, professional position, company sector and much more (see https://www.facebook.com/iq/tools-resources/audience-insights and https://www.linkedin.com/help/lms/answer/82351). We have no influence on the data processing that takes place for this purpose, cannot prevent it and also do not have access to the underlying data.
We use these offers to better understand the structure of our users and their interests and to design our site accordingly. Furthermore, we and the providers of the social networks can better target advertising in this way because we learn, for example, information about the demographic and geographical distribution or about the gender of the users. In this way, we can recognise trends in our users from the statistics and show them more relevant content.
When using the services Facebook, Instagram, Twitter, YouTube, LinkedIn and glassdoor, data is transferred to the USA. These providers are certified under the Privacy Shield agreement and are obliged to comply with EU data protection standards.
Your rights as a data subject
From the terms of use, which we accepted when creating our company websites, it is regulated that you contact the respective provider of the social network regarding your rights as a data subject to information, objection, correction, restriction of processing, transferability and deletion, as only this provider has access to your data. You can find the information on the data protection of the providers here:
- Facebook (Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Irland): https://www.facebook.com/about/privacy/, https://www.facebook.com/settings?tab=ads und http://www.youronlinechoices.com,
- Instagram (Instagram LLC., 1601 Willow Road, Menlo Park, CA 94025, USA) http://instagram.com/about/legal/privacy, https://help.instagram.com/155833707900388
- Twitter (Twitter, Inc., 1355 Market St, Suite 900, San Francisco, California 94103, USA) https://twitter.com/privacy; https://twitter.com/personalization
- YouTube (Google Ireland Limited, Sitz in Gordon House, Barrow Street, Dublin 4, Irland) https://policies.google.com/privacy, https://adssettings.google.com/authenticated
- LinkedIn (LinkedIn Ireland, Wilton Place, Dublin 2, Irland) https://www.linkedin.com/legal/privacy-policy
- Xing (XING AG, Dammtorstraße 29-32, 20354 Hamburg, Deutschland) – Datenschutzerklärung/ Opt-Out: https://privacy.xing.com/de/datenschutzerklaerung.
- kununu (Kununu GmbH, Neutorgasse 4-8, Top 3.02, A-1010 Wien) https://privacy.xing.com/de/datenschutzerklaerung
- glassdoor (Glassdoor, Inc., 100 Shoreline Highway, Building A, Mill Valley, 94941, USA), https://www.glassdoor.com/about/privacy.htm, https://help.glassdoor.com/Privacy_Request/en_US
You have the following rights with regard to the functions of our website explained in the section “Information on data processing” and the purposes of data processing described there:
Right to information (Art. 15 DSGVO)
We must provide you with information as to whether we are processing data relating to you. In the case of such processing, we must, among other things, explain the purposes for which the processing takes place, which categories of personal data are processed, to whom data may be transferred and for how long the data will be stored.
Correction (Art. 16 DSGVO), objection (Art. 21 DSGVO), restriction of processing (Art. 18 DSGVO)
If you discover that we are processing personal data that is incorrect or incomplete, you may of course request rectification. You may also object to the processing for specific reasons and, if justified, request the restriction of processing.
Deletion (Art. 17 DSGVO) and data portability (Art. 20 DSGVO)
In the event that personal data is processed by us, inter alia, without justification or after the purpose has ceased to apply, you may request its erasure. Please note that deletion may not always be possible due to the existence of legal obligations to provide proof/retention. Furthermore, you have the right to receive from us all information that you have provided to us in a structured, common and machine-readable format. For a better understanding and easier readability of the personal rights, we have summarised them here in parts. If required, please inform yourself in the (original text: link to http://eur-lex.europa.eu/legal-con-tent/de/TXT/?uri=CELEX%3A32016R0679) or contact our data protection officer directly. You can exercise your data protection rights at any time and without incurring any costs. Please use the following contact option for your request: info@oraylis.de.
Right to complain to a supervisory authority
You have the right to contact the supervisory authority for data protection regarding compliance with data protection and to lodge a complaint in this regard. The authority responsible for us is:
North Rhine-Westphalia State Commissioner for Data Protection and Freedom of Information (LDI NRW).
Kavalleriestr. 2-4 | 40213 Düsseldorf
Telephone: 0211 384 24-0 | E-Mail: poststelle@ldi.nrw.de