PRIVACY POLICY
A. Data Controller / Data protection requests
We appreciate your interest in our website and would like to make your user experience as pleasant as possible. It is equally important for us to protect your privacy to the greatest possible extent.
Below we inform you about the handling of your personal data and your rights in this regard.
Responsible for the processing of your personal data in connection with the use of this website (hereinafter also referred to as "website") is
CUREosity GmbH
Hansaallee 299
40549 Düsseldorf
Phone: +49 211 8220466
E-mail: info@cureosity.de
You can also send data protection inquiries by email to the following address: datenschutz@cureosity.de
This privacy policy applies to this website operated by us. If offers from other providers ("third-party offers") are accessible from our website, our privacy policy does not apply to these third-party offers. In this case, we are also data controller for the processing of your personal data in the context of such third-party offers within the meaning of Art. 4 no. 7 GDPR. Art. 4 No. 7 GDPR.
B. Nature and scope of the processing of your personal data
I. Processing of access data, hosting
Type and scope of processing
You can visit our website without having to provide any personal information. We only store access data in so-called server log files. In addition to the browser type, operating system, referrer URL, pages visited, date and time of access, this also includes your IP address.
This may in principle be personal data because, under certain conditions, it is possible to use it to find out the identity of the owner of the Internet access used by providing information from the respective Internet provider.
Processing purpose
The server log file data is processed by us exclusively for the purpose of secure and trouble-free operation of the website.
Legal basis
The IP address is processed on the basis of our legitimate interest within the meaning of Art. Art. 6 para. 1 lit. f) GDPR to provide you with a secure website and to enable communication between our server and your end device.
Recipient
We host the content of our website with the provider
Webflow Inc. is certified under the EU-US Privacy Framework. Webflow's privacy policy can be viewed at https://webflow.com/legal/privacy.
The content of our blog is provided by
Wix.com Ltd. exclusively stores on servers in the European Union . Wix's privacy policy can be viewed at https://de.wix.com/about/privacy.
Storage duration
The log file data is deleted after seven days .
II Processing to answer your inquiries
Type and scope of processing
We process the personal data that you voluntarily provide to us when contacting us, in particular by email, when using our contact form or when making an inquiry by telephone. We also process your IP address when you submit the contact form.
Processing purpose
This data will only be processed for this correspondence with you and for the purpose for which you have provided us with the data in the context of this communication, e.g. to process your request or to contact you at your request.
Legal basis
The processing takes place on the basis of your consent, Art. 6 para. 1 lit. a) GDPR. You can withdraw your consent to the processing of your personal data at any time with effect for the future.
Insofar as the processing is necessary to fulfill a contract with you or to carry out pre-contractual measures at your request, the legal basis is Art. 6 para. 1 lit. b) GDPR.
The legal basis for processing your IP address is our legitimate interest in enabling communication between our server and your end device.
Storage duration
After your request has been fully processed, your data will be blocked for further use and deleted after any existing retention periods have expired, unless you have expressly consented to further use of your data or we otherwise have a right to store it.
III. Processing of applicant data
Type and scope of processing
On our website, we offer you the opportunity to apply for a job with us. In doing so, we process the data that you provide to us during the application process.
If you do not provide us with this data (in particular name, contact details, information on professional qualifications), we will not be able to process your application.
Processing purpose
Your data will only be used for the purpose of deciding whether to establish an employment relationship with you and will only be forwarded internally to the responsible contact persons who will decide whether to fill the position you have applied for. If you do not apply for a specific vacancy (unsolicited application), we will use your data for all vacancies that match your requirements at the time of application.
Legal basis
We are authorized to process this data in accordance with Art. 88 GDPR in conjunction with Section 26 (1) sentence 1 BDSG (Bundesdatenschutzgesetz – Federal Data Protection Act).
Storage duration
If your application is rejected, we will delete your data after the application process has been completed and a retention period of 6 months has expired. Your data will only be stored beyond this period if you have given your express consent. In this case, your data will be deleted by us after 2 years at the latest, unless you request us to delete it beforehand.
IV. Newsletter
Type and scope of processing
We offer a newsletter on our website in which we provide regular information about our products and services.
As a subscriber, in addition to the actual newsletter, you may also be informed about circumstances relevant to the newsletter service (e.g. changes to the newsletter offer or technical reasons). Such information will also be sent to the email address you have provided.
If you request to receive the email newsletter we offer on our website, we will process your email address and any data you voluntarily provide to us when registering for the newsletter.
If you do not provide us with your email address , we will not be able to send you our newsletter.
We use the "double opt-in" procedure to check that a registration has actually been made by the owner of the registered email address. For this purpose, you will receive a confirmation email from us after submitting your email address, in which you must confirm your registration for the newsletter by clicking on a link. Only after this confirmation will your email address be added to the newsletter distribution list. As proof for us, we log the registration for the newsletter, the sending of the confirmation email and the receipt of the requested confirmation. The time of registration and confirmation as well as your IP address are also stored.
Processing purpose
The purpose of processing your email address is to send you newsletters by email. We process further data in order to be able to address you personally in the newsletter.
The processing of further data upon registration serves to document and verify your registration.
Legal basis
The legal basis for sending the newsletter is your consent in accordance with Art. 6 para. 1 lit. a) GDPR. You can withdraw your consent at any time with effect for the future.
The legal basis for the logging of the aforementioned data is our legitimate interest pursuant to Art. 6 para. 1 lit. f) GDPR in being able to prove your consent in case of doubt. This type of processing is common on the Internet and can therefore be expected, so that your interests, fundamental rights and freedoms do not outweigh our legitimate interest.
Recipient
The newsletter is sent via our service provider BREVO. You can view their privacy policy at https://www.brevo.com/en/legal/privacypolicy/ .
Storage duration
The data will be stored for the duration of the subscription to our newsletter and deleted after unsubscribing from the newsletter unless statutory retention periods require longer storage. Data that is also stored by us for other purposes remains unaffected by this.
If you unsubscribe from our newsletter mailing list, we may store your email address in a so-called blacklist if this is necessary to prevent future mailings.
The data from the blacklist will only be used for this purpose and will not be merged with other data. This serves both your and our legitimate interest in complying with the legal requirements when sending newsletters and not sending unsolicited newsletters. The legal basis therefore arises from Art. 6 para. 1 lit. f) GDPR.
Storage in the blacklist is not limited in time.
V. Appointments
Type and scope of processing
We provide you with a tool on our website that you can use to book consultation appointments with us. For this purpose, we process the data you provide during the booking process at. We also process your IP address when you submit the booking form.
Processing purpose
The processing serves to prepare and carry out the consultation appointment and to be able to contact you (in advance) if necessary.
Legal basis
The legal basis for the processing of your data is your consent in accordance with Art. 6 para. 1 lit. a) GDPR. You can withdraw your consent at any time with effect for the future.
Insofar as the processing is necessary to fulfill a contract with you or to carry out pre-contractual measures at your request, the legal basis is Art. 6 para. 1 lit. b) GDPR.
The legal basis for processing your IP address is our legitimate interest in enabling communication between our server and your end device.
Recipient
The booking form is provided by our service provider meetergo GmbH. You can view their privacy policy at https://meetergo.com/datenschutz/.
An alternative booking form is provided by Microsoft. You can view its privacy policy at https://learn.microsoft.com/en-us/microsoft-365/bookings/bookings-faq?view=o365-worldwide#datenschutz
Storage duration
The data entered when booking will be stored in accordance with the statutory retention periods and deleted at the latest when these expire.
VI. General information on cookies
We use so-called cookies on our website. Cookies are data records that are stored on your end device by the Internet browser. A cookie contains, for example, a string of characters that enables your browser to be uniquely identified when you return to the website. Cookies cannot execute programs or transfer viruses to your computer.
Cookies can be stored on your end device either temporarily for the duration of a session ("session cookies") or permanently ("permanent cookies").
Session cookies are automatically deleted immediately after the end of your visit to our website. Permanent cookies, on the other hand, remain stored on your end device until you delete them yourself or they are automatically deleted by your internet browser.
Cookies may also originate directly from us ("first-party cookies") or from third-party companies ("third-party cookies"). Third-party cookies enable, for example, the integration of certain services from third-party companies within websites.
Cookies have various functions. For example, they may be technically necessary to ensure certain functionalities of a website (e.g. the shopping cart function). Other cookies are not required in this way and are used, for example, to evaluate user behavior or for advertising purposes.
As a rule, you can set your browser in a way that you are informed about the setting of cookies, the setting of cookies is excluded for certain cases or in general, or you only allow the setting of cookies in individual cases. You can also delete stored cookies in your browser settings.
Without cookies, however, the functionality of our website may be limited.
Type and scope of processing, purpose of processing and storage period
We use the following cookies on our website:
Legal basis
Cookies that are technically required to carry out the electronic communication process and to provide certain functions (e.g. for language settings) are used on the basis of Art. 6 para. 1 lit. f) GDPR. In this respect, you and we have a concurrent interest in the provision of a secure and fully functional website.
All other cookies that are not technically necessary are set exclusively on the basis of your consent, § 25 para. 1 TTDSG and - insofar as personal data is processed - Art. 6 para. 1 lit. a) GDPR. You can withdraw your consent at any time with effect for the future.
VII. YouTube
Type and scope of processing
We may also embed videos from the YouTube website on our website.
The operator is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
If we embed YouTube videos (alternatively, the embedded videos can also be stored directly on our server), we use YouTube exclusively in the "Extended data protection mode" . According to YouTube, this mode means that YouTube does not store any information about visitors to this website before they watch the video. However, the transfer of data to YouTube partners is not necessarily excluded by the "Extended data protection mode". This means that YouTube can establish a connection to the Google DoubleClick network regardless of whether you watch a video.
As soon as you start a YouTube video on this website, a connection to the YouTube servers is established. This tells the YouTube server which of our pages you have visited. If you are logged into your YouTube account, you also enable YouTube to assign your surfing behavior directly to your personal profile. You can prevent this by logging out of your YouTube account beforehand.
Furthermore, YouTube may store various cookies on your end device after starting a video or use comparable recognition technologies (e.g. device fingerprinting). In this way, YouTube can obtain information about you. This information is used, among other things, to record video statistics, improve user-friendliness and prevent fraud attempts. If necessary, further data processing operations may be triggered after the start of a YouTube video, over which we have no influence.
You can find more information about data protection at YouTube in their privacy policy at: https://policies.google.com/privacy?hl=de.
Processing purpose
The purpose of the processing is to be able to show you the corresponding YouTube videos.
Legal basis
YouTube videos are used exclusively on the basis of your consent, which you give when you click on the "play button" of a video, Art. 6 para. 1 lit. a) GDPR. You can withdraw your consent at any time with effect for the future.
Recipient
The recipient of the data is Google Ireland Limited.
If personal data is also transferred to the USA, the company is certified in accordance with the "EU-US Data Privacy Framework".
VIII. Google Maps
We also use the Google Maps service. This allows us to show you interactive maps directly on the website and enables you to use the map function conveniently.
Type and scope of processing
When you visit the website, Google receives the information that you have accessed the corresponding subpage of our website. In addition, the above-mentioned basic data such as IP address and time stamp are transmitted. This occurs regardless of whether Google provides a user account through which you are logged in or whether no user account exists. If you are logged in to Google, your data will be assigned directly to your account.
If you do not wish to be associated with your Google profile, you must log out before activating it. Google stores your data as usage profiles and uses them for the purposes of advertising, market research and/or the needs-based design of its website. Such an evaluation is carried out in particular (even for users who are not logged in) to provide needs-based advertising.
The information collected is stored on Google servers, including in the USA. Google LLC is certified under the EU-US Data Privacy Framework.
Further information on the purpose and scope of data collection and its processing by the plug-in provider can be found at www.google.de/intl/de/policies/privacy.
Processing purpose
The purpose of processing is to be able to show you maps with locations or routes.
Legal basis
The use of Google Maps is based exclusively on your consent, Art. 6 para. 1 lit. a) GDPR. You can revoke this at any time with effect for the future.
IX. Google Analytics
Type and scope of processing
We use Google Analytics on our website, a web analytics service provided by Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
In addition to cookies, Google Analytics can also use so-called web beacons (invisible graphics). These web beacons can be used to analyze information such as visitor traffic on websites. The information generated by cookies and web beacons about the use of our website (including your IP address) is transmitted to a Google server, possibly in the USA or other third countries, and stored there.
Google provides detailed information on the processed data at https://www.google.com/intl/de/policies/privacy/#infocollect and at https://privacy.google.com/businesses/adsservices/.
We only use Google Analytics with IP anonymization ("anonymize IP") activated. This means that your IP address will be shortened by Google within member states of the European Union or within the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and truncated there.
Furthermore, we have concluded a data processing agreement with Google for the use of Google Analytics. Google processes the data on our behalf in order to evaluate the use of our website or to compile reports on website activity for us.
You can prevent Google from processing your data by downloading and installing the browser plug-in available at https://tools.google.com/dlpage/gaoptout?hl=de.
Further information can be found in Google's privacy policy: https://support.google.com/analytics/answer/6004245?hl=de.
Processing purpose
By integrating Google Analytics, we pursue the purpose of analyzing user behavior on our website and being able to react to it. This enables us to continuously improve our offering and tailor it to the interests of users.
Legal basis
The legal basis for the processing is exclusively your consent (§ 25 TTDSG [Telekommunikation- Telemedien- Datenschutzgesetz – Federal Telecommunications-Telemedia Data Protection Act] or Art. 6 para. 1 lit. a) GDPR). You can withdraw your consent at any time with effect for the future. You can also deactivate the settings for personalized advertising at https://support.google.com/ads/answer/2662922?hl=de.
X. Social media (plugins)
Type and scope of processing
We may use social media plugins on our website.
We will only regularly link to our social media channels. Occasionally, however, we may also embed posts in social media channels in our website or enable the sharing of posts. The embedding takes place via the service provider Flockler (https://flockler.com/de), whose privacy policy can be viewed at https://flockler.com/privacy-policy. In these cases, Flockler establishes a connection to the social media accounts and replicates the respective view.
Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland
Website: https://www.facebook.com
Privacy policy: https://www.facebook.com/about/privacy
Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland
Website: https://www.instagram.com/
Privacy policy: https://privacycenter.instagram.com/policy/?entry_point=ig_help_center_data_policy_redirect
Service provider: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland
Website: https://www.linkedin.com
Privacy policy: https://www.linkedin.com/legal/privacy-policy
YouTube
Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Website: https://www.youtube.com/
Privacy policy: https://policies.google.com/privacy?hl=de
Processing purpose
This serves to present our social media activities and increase their reach.
Legal basis
If social media plugins are used, they are integrated into the page using the so-called "2-click solution" or the "Sharrif solution". This integration ensures that no connection is established with the servers of the respective providers when a page of our website containing such plugins is accessed. Your browser only establishes a direct connection to the servers of the activated providers when you activate the plugins and thus give your consent to data transmission. The content of the respective plugin is then transmitted directly to your browser by the corresponding provider and integrated into the page. By integrating the plugins, the providers receive the information that your browser has accessed the corresponding page of our website, even if you do not have a profile with the corresponding provider or are not currently logged in to the service of the respective provider. This information (including your IP address) is transmitted directly from your browser to a server of the respective provider, possibly in a non-EU country, and stored there.
If you are logged in to one of the providers' services, the providers can directly associate your visit to our website with your profile/account with the respective provider. If you interact with the plugins, for example by clicking the "Like" button, the corresponding information is also transmitted directly to a server of the provider and stored there. The information is also published on the social network or on your social media account and displayed to your contacts there. If you do not want the providers to assign the data collected via our website directly to your profile/account in the respective service, you must log out of the respective service before activating the plugins.
The legal basis for this type of processing is therefore your consent within the meaning of Art. 6 para. 1 lit. a) GDPR. You can withdraw your consent at any time with effect for the future.
Receiver
Recipients may be the respective service providers of the social network.
XI Other tools
In addition to the aforementioned tools, we use
(i) FoxBase, a service of FoxBase GmbH.
Among other things, FoxBase provides information on which areas of our website are particularly clicked on. This enables us to address customers in a more targeted manner.
FoxBase is used exclusively on the basis of your consent. You can withdraw your consent at any time with effect for the future.
The recipient of the data may be FoxBase. Their privacy policy can be viewed at https://www.foxbase.de/de/datenschutz/.
(ii) Pathmonk, the Pathmonk web service provided by Pathmonk GmbH.
Pathmonk collects information about the device you are using, your IP address, geographical location, language settings, the website from which you came to our websites and user interactions such as mouse movements, clicks and keystrokes.
Pathmonk uses this data to draw conclusions about the user's personal preferences and to personalize the user's web experience, e.g. by displaying micro-experiences. If you contact us via our contact forms or micro-experiences, Pathmonk stores the information you provide (your name and email address or telephone number) in order to respond to your inquiry.
The purpose of this is to better align our website with the interests of website visitors and to generate leads.
We use Pathmonk exclusively on the basis of your consent, Art. 6 para. 1 lit. a) GDPR. You can withdraw your consent at any time with effect for the future.
The recipient of the data may be Pathmonk GmbH. Their privacy policy can be viewed at https://pathmonk.com/wp-content/uploads/2023/11/privacypolicy_pathmonk_gmbh.pdf.
(iii) Meta Pixel, an analytics tool for measuring the effectiveness of Facebook advertising provided by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.
This pixel tracks user behavior on our website and links the information with the user data of our website visitors on Facebook.
We use meta pixels exclusively on the basis of your consent. You can withdraw your consent at any time with effect for the future.
The recipient of the data may be Facebook (Meta Platforms). Their privacy policy can be viewed at https://www.facebook.com/about/privacy.
C. Your rights
In connection with the processing of your personal data by us, you have the rights listed below.
The assertion of the following rights is generally free of charge for you.
However, in the case of manifestly unfounded or - especially in the case of frequent repetition - excessive requests regarding the rights under II. to VI. we may, in accordance with Art. 12 (5) GDPR, either
a. charge a reasonable fee, taking into account the administrative costs of providing the information or notification or implementing the requested measure, or
b. refuse to take action on the basis of the application.
To exercise your rights, please contact one of the addresses listed above.
I. Withdrawl of consents granted
You can withdraw any consent given to us at any time with effect for the future.
II Right of access
You have a right of access to the personal data stored about you. In addition, you are entitled to information about the information listed in Art. 15 GDPR.
III Rectification and deletion
You also have the right to rectification of inaccurate personal data and completion of incomplete personal data in accordance with Art. 16 GDPR and erasure of your personal data if the requirements of Art. 17 GDPR are met.
IV. Restriction of processing
Under the conditions of Art. 18 GDPR, you can restrict the processing of your personal data.
V. Data portability
Furthermore, you have the right to receive the personal data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format. You also have the right, insofar as this is technically feasible, for us to transfer this data to another controller on your instructions. The right to data portability only applies to personal data where the processing is based on consent pursuant to Art. 6 para. 1 lit. a) GDPR or on a contract pursuant to Art. 6 para. 1 lit. b) GDPR and the processing is carried out by automated means. The right to transfer data to another controller is excluded if this would adversely affect the rights and freedoms of other persons (e.g. personal data of third parties, our business and trade secrets or copyrights).
VI. RIGHT TO OBJECT
In accordance with Art. 21 GDPR, you have the right to object to the processing of your personal data at any time for reasons arising from your particular situation, insofar as this is done on the basis of Art. 6 para. 1 lit. e) or lit. f) GDPR. In the event of such an objection, we will no longer process this data unless we can prove that there are compelling legitimate grounds for the processing that outweigh your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims.
If we process your personal data for the purpose of direct marketing, you also have the right to object at any time to the processing of your personal data for the purpose of such marketing.
If you object to the processing of your personal data for the purpose of direct marketing, we will no longer process your personal data for this purpose. You can also exercise your right to object in particular by clicking on "Unsubscribe" in a relevant advertising email.
VII Right to lodge a complaint with a supervisory authority
If you are of the opinion that we are not properly fulfilling our data protection obligations, you can contact the supervisory authorities at any time.
You can contact the supervisory authority ultimately responsible for us as follows:
State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia
P.O. Box 20 04 44
40102 Düsseldorf
Germany
Phone: +49 211 384240
E-mail: poststelle@ldi.nrw.de
D. Obligation to provide data
There is no legal or contractual obligation to provide us with personal data. However, the provision of data that is absolutely necessary for the provision of the respective service (see above) is necessary if you wish to make use of these services.
E. Updating this privacy policy
From time to time, it may be necessary to update this privacy policy, for example due to new legal or regulatory requirements or new offers on our website. We will then inform you here. In general, we recommend that you visit this privacy policy regularly to check whether there have been any changes. You can tell whether changes have been made by the fact that the status indicated at the bottom of this document has been updated.
F. Printing and saving this privacy policy
You can print out and save this privacy policy directly, for example by using the print or save function in your browser.
Status: March 2024