This text explains what types of personal data concerning you (also referred to herein as “data”) Dussmann processes for which purposes and in what scope. This Data Protection and Privacy Statement applies to all processing of personal data by Dussmann, both within the scope of performance of services and, in particular, on Dussmann websites, in mobile applications and within external online sites such as Dussmann social media profiles (collectively referred to as “online services”).
It is important to note that Dussmann is not merely a single company. It is a group of companies consisting of Dussmann Stiftung & Co. KGaA and its affiliates. A list of these affiliates can be viewed here. Not every one of these affiliates does in fact offer online services or process your data. For ease of reference, the “Controller” section notes which company is responsible for processing your data. This means that where the text below refers to “us” or “we”, this means the responsible company of the Dussmann Group that is mentioned in the “Controller” section.
Please check back regularly to familiarize yourself with the content of our Data Protection and Privacy Statement. We adjust the text promptly as required by changes in the data processing we perform. We will let you know if and when these changes require any participatory action on your part (such as consent) or another form of individual notification is necessary.
Where we state the addresses and contact information of companies and organizations in this Data Protection and Privacy Statement, please note that these addresses may change over time and should be verified before you contact us.
Kursana GmbH
Schützenstrasse 25
10117 Berlin
Germany
E-mail: kursana @dussmann.de
Phone: +49 30 2025 2000
Dussmann Stiftung & Co. KGaA
Data Protection Officer
Friedrichstrasse 90
10117 Berlin
Germany
E-mail: datenschutz @dussmanngroup.com
Phone: +49 30 2025 0
The overview below summarizes the types of data we process and the purposes of processing thereof and indicates the data subjects.
Relevant legal bases pursuant to the GDPR: This section provides an overview of the legal bases under the GDPR on which we process personal data. Please note that in addition to the provisions of the GDPR, national data protection and privacy specifications may apply in your or our country of residence or domicile. Should more-specific legal bases be relevant in the individual case, we will notify you of these in the Data Protection and Privacy Statement.
National data protection regulations in Germany: In addition to the data protection regulations stipulated by the GDPR, there are national regulations governing data protection and privacy in Germany. This particularly includes German Federal Data Protection Act (BDSG). In particular, the BDSG contains special provisions relating to the rights of access to information, of erasure, and to object; the processing of special categories of personal data; processing for other purposes; transfers; and automated decision-making in individual cases, including profiling. Furthermore, state data protection laws at the level of the individual states may also apply.
In accordance with the legal specifications and taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, we implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk.
These measures include but are not limited to ensuring the confidentiality, integrity, and availability of data by controlling physical and electronic access to the data and the data access concerning them, along with the entry, communication, and separation thereof and ensuring the availability of the data. We have also established procedures that ensure that the rights of data subjects are upheld, data are erased, and there is a response to any risk to the data. Furthermore, we take protecting personal data into account in the early stages of developing and/or selecting hardware, software, and procedures in keeping with the principle of data protection by design and by default.
Safeguarding online connections through TLS/SSL encryption technology (HTTPS): To protect the user data transferred via our online services against unauthorized access, we rely on TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the Internet. These technologies encrypt the information transferred between the website or app and the user’s browser (or between two servers), which protects the data against unauthorized access. TLS, a further developed and more-secure version of SSL, ensures that all data transmissions meet the very highest standards of security. If a website is safeguarded by an SSL/TLS certificate, “HTTPS” is displayed in the URL. This serves as an indicator for users that their data are being transferred securely and with encryption.
Within the scope of our processing of personal data, it is possible that these data will be transferred or disclosed to other bodies, companies, legally independent organizational units, persons, or entities. Recipients of these data may include, for example, service providers commissioned to perform IT tasks or providers of services and content incorporated into a website. In such cases, we observe the legal specifications and, in particular, enter into relevant contracts and/or agreements that serve to protect your data with the recipients of your data.
Data transfers within the corporate group: We may transfer personal data to other companies within our corporate group or grant them access to these data. Where such disclosures take place for administrative purposes, the disclosure of the data is based on our legitimate entrepreneurial and business administration interests or takes place to the extent necessary to fulfill our contract-related obligations or where the data subject has given consent or the disclosure is permitted by law.
Data processing in third countries: Where we process data in a third country (i.e., outside the European Union (EU) or European Economic Area (EEA)) or the processing takes place within the scope of our utilization of third-party services or of the disclosure or transfer of data to other persons or entities, bodies, or companies, this takes place solely in compliance with the legal specifications. Where the level of data protection in the third country has been acknowledged by an adequacy decision (Article 45 GDPR), this decision serves as the basis for the data transfer. In all other respects, data transfers take place only if the level of data protection has been safeguarded through other means, particularly standard contractual clauses (point (c) of Article 46(2) GDPR), express consent has been granted, or the transfer is required based on the provisions of a contract or by law (Article 49(1) GDPR). In all other respects, we communicate to you the bases for the third-country transfer in the case of the individual third-country providers; the adequacy decisions take precedence as bases. For information on third-country transfers and existing adequacy decisions, please consult the information provided by the European Commission: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en.
Transatlantic EU–U.S. data privacy framework: Within the scope of the Data Privacy Framework (DPF), the European Commission acknowledged the level of data protection provided by certain companies based in the United States as secure under the adequacy decision dated July 10, 2023. The list of certified companies and further information relating to the DPF is available from the U.S. Department of Commerce website at https://www.dataprivacyframework.gov/.
We erase personal data that we process in accordance with the statutory provisions once the underlying consent has been withdrawn or there are no further legal bases for the processing thereof. This applies to cases in which the original purpose of processing ceases to apply or the data are no longer required. Exceptions to this provision apply if statutory obligations or particular interests require that the data be retained or archived for a longer period.
In particular, data that must be retained for reasons of commercial or tax law or whose storage is necessary in order to pursue legal claims or protect the rights of other natural persons or legal entities must be archived accordingly.
We process data that are no longer retained for the originally intended purpose, but rather based on legal specifications or other reasons, exclusively on the bases that justify the retention thereof.
Should you wish your data to be erased or withdraw consent to data processing, the data will be erased as soon as possible unless there is an obligation to store them.
Further information on processing operations, procedures, and services:
Rights of data subjects under the GDPR: As a data subject, you have various rights under the GDPR, particularly based on Articles 15 through 21 GDPR:
We process the data of other parties to contracts with us and our business partners, such as clients and prospective clients (collectively “other parties to contracts”), within the scope of contractual and similar legal relationships and associated measures and with an eye to communications with other parties to contracts (or as part of steps prior to entering into contracts), for example to respond to inquiries.
We use these data to comply with our contractual obligations. These include but are not limited to the obligations to perform the agreed services, any obligations of updating, and obligations to effect a cure or remedy a situation in the case of warranty claims and other disruptions in performance. Beyond that, we use the data to safeguard our rights and for the purposes of the administrative tasks associated with these obligations and of company organization. We also process the data on the basis of our legitimate interests both in the proper and economical management of our business and in security measures to protect the other parties to contracts with us and our business operations against abuse, jeopardization of their data, secrets, information, and rights (e.g., relating to the involvement of telecommunication, transportation, and other supporting services as well as subcontractors, banks, tax advisors and legal counsel, payment service providers or fiscal authorities). Within the scope of applicable law, we share the data of other parties to contracts with us with third parties only to the extent that this is necessary for the aforementioned purposes or to fulfill statutory obligations. Other parties to contracts with us are informed of further forms of processing, such as for marketing purposes, within the scope of this Data Protection and Privacy Statement.
We notify the other parties to contracts of which data are necessary for the aforementioned purposes before or at the time of collection of the data, e.g., in online forms, through special designation (e.g., colors) or symbols (e.g., asterisk or similar) or in person.
Personal data of service recipients and clients, including clients or business partners and further third parties, are processed within the scope of contractual and similar legal relationships and steps prior to entering into a contract, such as preparations for business relationships. This data processing supports and facilitates business administration processes in areas such as customer management, sales, payment transactions, accounting, and project management.
The data collected serve to fulfill contractual obligations and streamline operational processes. This includes the settlement of business transactions, management of customer relationships, optimization of sales strategies, and ensuring internal accounting and financial processes. The data also support the safeguarding of the controller’s rights and are conducive to administrative tasks and to the company's organization.
Personal data may be disclosed to third parties to the extent that this is necessary in order to fulfill the aforementioned purposes or statutory obligations. The data are erased when statutory retention time limits expire or the purpose of processing ceases to apply. This also includes data that must be stored for longer based on the evidentiary obligations of tax law and other laws.
Further information on processing operations, procedures, and services:
Where we perform in advance or enter into comparable financial risks (e.g., in the case of orders for payment subsequent to invoicing), we reserve the right to obtain an identity and credit check from service providers that specialize in this area (credit bureaus or agencies) for the purpose of assessing the credit risk on the basis of mathematical and statistical methods in order to safeguard our legitimate interests.
We process the information received from the credit bureaus or agencies concerning the statistical likelihood of default of payment within the scope of an appropriate decision at our discretion regarding the establishment, performance, and termination of the contractual relationship. We reserve the right to decline to offer payment subsequent to invoicing or another form of advance performance if the result of the credit check is negative.
The decision regarding whether we perform in advance is made in keeping with the legal specifications based solely on an automated decision made in the individual case by our software based on the information received from the credit bureau or agency.
Where we obtain express consent from other parties to contracts with us, the legal basis for the credit check and the transfer of the client’s data to the credit bureaus or agencies is consent. If no consent is obtained, the credit check is performed on the basis of our legitimate interest in minimizing the risk of default on our claims to payment.
Further information on processing operations, procedures, and services:
We process user data to be able to provide them with our online services. To this end, we process the user’s IP address, which is necessary in order to transfer the content and features of our online services to the user’s browser or device.
Further information on processing operations, procedures, and services:
Collection of access data and log files: Access to our online services is logged in the form of “server log files”. Server log files may include the address and name of the websites and files retrieved, date and time of retrieval, volumes of data transferred, report of successful retrieval, browser type and version, the user’s operating system, referrer URL (the page visited beforehand) and typically IP addresses and the requesting provider. The server log files may be used, first, for security purposes, e.g., to prevent overloading of servers (particularly in the case of distributed denial-of-service (DDoS) attacks) and, second, to ensure server capacity utilization and stability; legal bases: legitimate interests (point (f) of Article 6(1) GDPR). Erasure of data: Log file information is stored for a maximum period of 30 days, after which it is erased or anonymized. Data that must be retained for a longer period for evidentiary purposes are exempt from erasure until the relevant incident has been clarified on a final basis.
Cookies are small text files or other storage notes that store information on devices and read it out from there. This is done, for example, to store the log-in status for a user account, the contents of a shopping cart in an online store, or the content retrieved or features of an online service that are used. Cookies can also be used in relation to various matters, such as for purposes of the functionality, security, and convenience of online services and to prepare analyses of user streams.
Information on consent: We use cookies in accordance with the legal provisions. Therefore, we obtain advance consent from users except where consent is not required by law. In particular, permission is not necessary if storing and reading out the information, including through the use of cookies, is strictly necessary in order to provide users with a tele-media service (meaning our online services) that they have expressly requested. The fact that they are giving consent and that it can be withdrawn is communicated clearly to them in a form that includes the information on the relevant cookie usage.
Information on legal bases for purposes of data protection and privacy law: The legal basis for purposes of data protection and privacy law on which we process users’ personal data using cookies depends on whether we ask users for consent. If users accept, the legal basis for the use of their data is their stated consent. Otherwise, the data used via cookies are processed on the basis of our legitimate interests (e.g., in the cost-effective operation of our online services and improvement of the usability thereof) or, if this takes place within the scope of fulfillment of our contractual obligations, if the use of cookies is necessary in order to comply with our contractual obligations. We provide information on the purposes for which we use cookies elsewhere in this Data Protection and Privacy Statement or within the scope of our consent and processing procedures.
Duration of storage: With regard to the duration of storage, a distinction is made between the following types of cookies:
General information on withdrawal of consent and objections (opting out): Users can withdraw the consent they have given at any time and can also object to the processing of their data in accordance with the legal specifications, including using their browser’s privacy settings.
Further information on processing operations, procedures, and services:
Usercentrics: Consent management: procedure for obtaining, logging, managing and withdrawing consent, particularly to the use of cookies and similar technologies used to store, retrieve, and process information on users’ devices; service provider: Usercentrics GmbH, Sendlinger Strasse 7, 80331 Munich, Germany; website: https://usercentrics.com/. Privacy policy: https://usercentrics.com/privacy-policy/.
When people contact us (e.g., by mail, contact form, e-mail, phone, or via social media) and in the context of existing user and business relationships, the information provided by the inquiring persons is processed to the extent necessary to respond to the contact inquiries and any requested measures.
We use platforms and applications from other providers (collectively “conference platforms”) for purposes of holding video and audio conferences, webinars, and other types of video and audio meetings (collectively “conferences”). We observe the legal specifications in selecting conference platforms and their services.
Data processed by conference platforms: In the context of participation in a conference, the conference platforms process the personal data of participants as mentioned below. The scope of the processing depends on factors including which data are specifically required in the context of a concrete conference (e.g., provision of login information or real names) and which optional information is provided by participants. In addition to processing to hold the conference, the participants’ data may also be processed by the conference platforms for security purposes or to optimize services. The data processed include personal information (first name, last name), contact information (e-mail address, phone number), login information (login codes or passwords), profile pictures, information about the person’s professional position/title or role, the IP address of the Internet access, information on participants’ devices, operating system, browser, and technical and language settings, information on content-related communication procedures, i.e., entries in chats and audio and video data, along with the use of other available features (such as surveys or polls). The content of the communications is encrypted to the extent provided in technical terms by the conference providers. If the participants are registered with the conference platforms as users, then additional data may be processed as agreed with the relevant conference provider.
Logging and recordings: If text entries, results of participation (e.g., in surveys or polls) and video or audio recordings are logged, this is communicated transparently to the participants in advance, and they are asked to consent where necessary.
Data protection measures of participants: With regard to the details of the processing of your data by the conference platforms, please note the latter’s data protection and privacy information and select the security and data protection and privacy settings that are optimal for you within the scope of the conference platform settings. Furthermore, please ensure data protection and privacy in the background of your images or recordings for the duration of a videoconference (e.g., by notifying others with whom you live, closing doors, and using any available technical features to blur your background). Links to conference rooms and login information must not be disclosed to unauthorized third parties.
Information on legal bases: Where we also process users’ data in addition to the conference platforms and request consent from users to the use of the conference platforms or certain features (e.g., consent to the recording of conferences), the legal basis of processing is this consent. Furthermore, our processing may be necessary in order to fulfill our contractual obligations (e.g., in participant lists, in the case of processing of the results of discussions or meetings, etc.). In all other respects, user data are processed on the basis of our legitimate interests in efficient and secure communication with the other parties to communications with us.
Further information on processing operations, procedures, and services:
Web analysis (also known as “reach measurement”) serves to analyze the visitor streams to our online services and may encompass behavior, interests, or demographic information on visitors, such as age or gender, as pseudonymized values. We can use reach analysis to see, for example, the time at which our online services or their features or content are used most frequently or to invite people to use them again. It is also possible for us to track which areas require optimization.
In addition to Web analysis, we may also use test methods to test and optimize aspects such as different versions of our online services or their components.
Unless otherwise indicated below, profiles, meaning data compiled on a use operation, may be created for these purposes, and information may be stored in a browser or on a device and then retrieved. The information collected includes but is not limited to websites visited and elements used there, along with technical information such as the browser and computer system used and information on usage times. Where users have consented, either to us or the providers of the services used by us, to the collection of their location data, processing of location data is also possible.
Beyond that, users’ IP addresses are stored. However, we use an IP masking procedure (i.e., pseudonymization by truncating (shortening) the IP address) to protect users. In general, no real information pertaining to users (such as e-mail addresses or names) is stored in the context of Web analysis, A/B testing and optimization. Instead, this information is pseudonymized. This means that neither we nor the providers of the software used know the actual identity of the user. Instead, all that is known is the information stored in the users’ profiles for the purpose of the relevant operations.
Information on legal bases: Where we ask users for their consent to the use of third parties, the legal basis for data processing is consent. Otherwise, user data are processed on the basis of our legitimate interests (i.e., interest in efficient, cost-effective and user-friendly services). In this context, we would also like to point out the information on the use of cookies in this Data Protection and Privacy Statement.
Further information on processing operations, procedures, and services:
We maintain an online presence within social networks and, in this context, process user data to communicate with the users active there or offer information about us.
Please note that user data may be processed outside the European Union in this context. This may give rise to risks to users, as it could make enforcing user rights more difficult, for example.
Furthermore, user data are typically processed within social networks for market research and advertising purposes. In this way, for example, use profiles can be created based on a user’s usage behavior and the user interests it indicates. These profiles may in turn be used, for example, to serve ads that are likely to match users’ interests within and outside these networks. Therefore, cookies are typically stored on users’ computers, storing their usage behavior and interests. In addition, data may also be stored in the usage profiles independently of the devices used by the users (especially if users are members of the relevant platforms and are logged in there).
For a detailed discussion of the relevant forms of processing and the options for objecting (opting out), please see the data protection and privacy statements and policies and other information provided by the operators of the relevant networks.
Please note that requests for access to information and assertion of the rights of data subjects are also most effectively addressed to these providers. Only the latter have access to the user data in each case and can take relevant action and provide information directly. Should you still need help, feel free to contact us.
Further information on processing operations, procedures, and services:
Our online services incorporate functional and content elements obtained from the servers of their respective providers (“third-party providers”). These may include but are not limited to graphics, videos, and maps (collectively “content”).
Incorporation of these elements always presupposes that the third-party providers of this content process the IP addresses of users, as without these IP addresses, they would be unable to transmit the content to the users’ browsers. This means the IP address is required in order to present this content or these functions. We strive to use only content whose respective provider uses the IP address solely to deliver the content. Third-party providers may moreover use what are known as pixel tags (invisible graphics also known as Web beacons) for statistical or marketing purposes. These pixel tags allow for analysis of information such as user traffic to the pages of this website. This pseudonymized information can furthermore be stored in cookies on the user’s device and may include items such as technical information on the browser and operating system, referring websites, the time of the visit, and further information on the use of our online services. It may also be associated with such information from other sources.
Information on legal bases: Where we ask users for their consent to the use of third parties, the legal basis for data processing is permission. Otherwise, user data are processed on the basis of our legitimate interests (i.e., interest in efficient, cost-effective and user-friendly services). In this context, we would also like to point out the information on the use of cookies in this Data Protection and Privacy Statement.
Further information on processing operations, procedures, and services:
This section contains information on how we handle the data of persons who make reports (whistleblowers) and of other parties who are affected and involved within the scope of our whistleblower system. Our goal is to offer an uncomplicated and secure way to report potential misconduct by us, our employees, or our service providers, especially for actions that violate laws or ethical guidelines. We also ensure that reports and processed and handled appropriately.
Legal bases (Germany): Where we process data to comply with our statutory obligations under the German Whistleblower Protection Act (HinSchG), the legal basis of processing is point (c) of Article 6(1) GDPR and, in the case of special categories of personal data, point (g) of Article 9(2) GDPR and Sec. 22 of the German Federal Data Protection Act (BDSG), in each case in conjunction with Sec. 10 HinSchG. This relates to the obligation to establish and operate an internal whistleblowing body, compliance with the statutory obligations thereof and, in the case of use of the data collected as part of the reporting procedure, measures taken to verify the validity of a report, to take further action against the reported violation or to close the procedure.
Where we process data (particularly in the event that misconduct is found to have occurred) in the context of or to prepare for a legal defense, this takes place on the basis of our legitimate interests in legally compliant and ethical actions in accordance with point (f) of Article 6(1) GDPR.
Where you have given us your consent to the processing of personal data for specific purposes, the processing takes place on the basis thereof in accordance with point (a) of Article 6(1) GDPR and, in the case of special categories of personal data, point (a) of Article 9(2) GDPR. One example of this would be the disclosure of the whistleblower’s identity or making a verbatim record during a personal submitted report. Consent can be withdrawn at any time with effect for the future.
Types of data processed:
We may collect various types of data in the context of accepting and processing reports and when taking measures to verify the validity of a report, to take further action against the reported violation or to conclude the procedure. This include but are not limited to the data provided by a whistleblower, such as:
For purposes of reviewing the matter and next steps in the process, we moreover process the following personal data:
Special categories of personal data:
We may collect special types of personal data in the context of our activities, particularly where these data are disclosed by a whistleblower. This includes:
These data are processed only if they are relevant to the processing of the report in question and have been expressly provided by the whistleblower.
Please note that it is possible to make reports anonymously. To ensure that your data are secure when using our online services, we recommend that you access the services using your browser’s “incognito” or “private” mode. Follow these steps to open an incognito window: a) On a Windows PC: Open your browser and press Ctrl+Shift+N; b) On a Mac: Open your browser and press Command+Shift+N; c) On a mobile device: Use the tab menu to switch to private mode.
When you access our website in normal browsing mode, your browser automatically transmits certain information to our server, such as the browser type and version and the date and time of your access. This also includes your device’s IP address. These data are temporarily stored in a log file and automatically erased after 30 days at a maximum.
The processing of the IP address serves the technical and administrative purposes of connecting to our website. It ensures the security, stability, and functionality of the website and is an important component of the measures we take to ensure confidential whistleblowing.
The processing of the logged data is based on point (f) of Article 6(1) GDPR. Our legitimate interest in this case lies in the need for security and the necessity of establishing the technical prerequisites for smooth and disruption-free whistleblowing.
Provision of identity: You can make a report anonymously.
If you provide your name and contact information, your identity will be treated as strictly confidential. The only exceptions to this confidentiality are where we are obligated by law to disclose your identity. This may be necessary in order to protect or defend our rights or those of our employee, clients, suppliers, or business partners. Another exception applies if it is determined that the accusations were made with malicious intent.
Provision of data to third parties: We do not disclose data associated with the reports made to third parties except under certain circumstances. This takes place if and when either a) you have given us your express consent to this; or b) there is a legal obligation to disclose the data. These possible third parties include public authorities and government, regulatory, or tax authorities, if disclosure is necessary to comply with a legal or regulatory obligation. We may also engage the services of attorneys and other professional advisors within measures taken to verify the validity of a report, to take further action against the reported violation or to close the procedure.
Data retention and erasure: Personal data are processed only as long as is necessary in order to fulfill the purposes of processing as described above. If these data are no longer necessary for the purposes mentioned, erasure takes place. In certain situations, however, the data may be retained longer to fulfill the statutory requirements as long as this is necessary and proportionate. In such cases, the data are erased once they are no longer required for these purposes.
Technical and organizational measures: We have implemented the necessary contractual, technical, and organizational measures to ensure the security of all data processed by us. These data are processed exclusively for the stipulated purposes. Incoming reports are processed by persons authorized to do so, who receive access to the relevant reports and perform the subsequent review of the matter. Our employees are specially trained for the proper performance of the reviews of these matters and are obligated to maintain the strictest confidentiality.