pib.Pro

Privacy Policy

Privacy at a Glance

Your data is in good hands with us. Helping you stay informed, this Privacy Notice explains how we handle your personal data and your rights under the European General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG). The controller responsible for data processing is isento robotics GmbH (hereinafter referred to as “we”, “us”, “our” or “isento”).

This Privacy Notice consists of two parts:

  • In Part A, you will find general information regarding data protection at isento, your legal rights, and our Data Protection Officer’s contact details.
  • Part B addresses specific categories of individuals and explains in detail which personal data we collect and how we process it. This applies to you in your role as:
    • a. Visitors to our websites,
    • b. Customers who use our services or purchase our products,
    • c. Contact persons at B2B customers whose employees use our services,
    • d. Job applicants seeking employment with our company,
    • e. Newsletter subscribers whom we keep informed on a regular basis, and
    • f. Visitors to our social media pages.

A. General Information

1. Our Contact Details

If you have any questions, suggestions, or requests regarding this Privacy Notice or if you wish to exercise your rights as a data subject, please contact us at:

isento robotics GmbH
it-systems & services
Ostendstraße 242
DE-90482 Nuremberg, Germany
Phone: +49 911 21 77 38 70
Email: info@isento.de
Web: www.isento-robotics.de

Authorized representative managing directors:
Dr. Shota Okujava, Dr. Jürgen Baier

How can you contact our Data Protection Officer?

You may contact our company Data Protection Officer using the following details:

Jörg ter Beek
Cortina Consult GmbH
Hafenweg 24, 48155 Münster, Germany
Web: www.cortina-consult.com
Email: datenschutzbeauftragter@isento.de

The term “personal data” refers to any information relating to an identified or identifiable natural person. We process personal data in accordance with the applicable data protection laws, in particular the GDPR and the BDSG. We process personal data only where a valid legal basis exists:

  • on the basis of your consent (Art. 6(1)(a) GDPR),
  • where necessary for the performance of a contract to which you are a party or in order to take steps at your request prior to entering into a contract (Art. 6(1)(b) GDPR),
  • where necessary for compliance with a legal obligation (Art. 6(1)(c) GDPR),
  • or where necessary for the purposes of our legitimate interests or those of a third party, provided that such interests are not overridden by your interests, fundamental rights or freedoms requiring the protection of personal data (Art. 6(1)(f) GDPR).

If you apply for a position within our company, we also process your personal data for the purpose of deciding whether to establish an employment relationship in accordance with Section 26(1) sentence 1 BDSG.

3. Your Rights

You remain in control of your personal data! As a data subject, you have the right to exercise the following rights under applicable data protection laws:

  • Right of access (Art. 15 GDPR, Section 34 BDSG): Pursuant to Art. 15 GDPR and Section 34 BDSG, you have the right to obtain confirmation as to whether we process personal data concerning you and, where that is the case, access to such data.
  • Right to rectification (Art. 16 GDPR): Pursuant to Art. 16 GDPR, you have the right to request the rectification of inaccurate personal data concerning you.
  • Right to erasure (Art. 17 GDPR, Section 35 BDSG): Pursuant to Art. 17 GDPR and Section 35 BDSG, you have the right to request the deletion of your personal data.
  • Right to restriction of processing (Art. 18 GDPR): Pursuant to Art. 18 GDPR, you have the right to request restriction of the processing of your personal data.
  • Right to data portability (Art. 20 GDPR): Pursuant to Art. 20 GDPR, you have the right to receive personal data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format and to transmit those data to another controller.
  • Right to withdraw consent (Art. 7(3) GDPR): Where processing is based on your consent, you may withdraw that consent at any time pursuant to Art. 7(3) GDPR. Withdrawal of consent does not affect the lawfulness of processing carried out prior to such withdrawal.
  • Right to lodge a complaint with a supervisory authority (Art. 77 GDPR): Pursuant to Art. 77 GDPR, you have the right to lodge a complaint with a supervisory authority if you believe that the processing of your personal data infringes applicable data protection laws.
  • Right to object (Art. 21 GDPR): Pursuant to Art. 21(1) GDPR, you have the right to object, on grounds relating to your particular situation, to the processing of your personal data where such processing is based on Art. 6(1)(e) or Art. 6(1)(f) GDPR. Where we process your personal data for direct marketing purposes, you have the right to object to such processing at any time pursuant to Art. 21(2) and (3) GDPR.

Where you exercise your rights under Arts. 15 to 22 GDPR, we process the personal data you provide for the purpose of fulfilling your request and documenting compliance with our legal obligations. Data stored for the preparation and provision of information requests will be processed solely for that purpose and for data protection compliance purposes. Processing will otherwise be restricted in accordance with Art. 18 GDPR. This processing is based on Art. 6(1)(c) GDPR in conjunction with Arts. 15 to 22 GDPR and Section 34(2) BDSG.

4. Where Do We Process Your Data?

As a general principle, we process your data on servers located within the European Union and protected by state-of-the-art security measures. To provide our services, we engage external service providers who may receive personal data on our behalf. Certain processing activities may involve the transfer of personal data to countries outside the scope of the GDPR (“third countries”). Such transfers take place only where legally permitted:

  • Where the European Commission has determined that a third country ensures an adequate level of data protection through an adequacy decision (Art. 45 GDPR). This applies to all transfers to countries listed here:
    International dimension of data protection
  • If no adequacy decision exists, personal data will only be transferred where appropriate safeguards under Art. 46 GDPR are in place (in particular the EU Standard Contractual Clauses – SCCs) or where one of the derogations under Art. 49 GDPR applies. You have the right to obtain a copy of these clauses upon request.
  • Where you expressly consent to the transfer of personal data to a third country, such transfer is carried out on the basis of Art. 49(1)(a) GDPR.

5. To Whom and Why Do We Disclose Your Personal Data?

In order to provide our services and operate our business efficiently, we engage various external service providers and, where necessary, disclose personal data to them. Where additional categories of recipients apply to specific groups of data subjects, these are described in Part B:

  • Hosting providers: We do not operate our own servers. Instead, we engage certified hosting providers to host our administrative systems and CRM platform.
  • IT service providers and SaaS vendors: We use various service providers acting as processors to support the provision, operation and maintenance of our services.
  • Affiliated companies: isento robotics GmbH and affiliated companies of the isento group (such as isento GmbH and isento eCommerce solutions GmbH) work with cross-company teams. As a result, personal data may be shared with affiliated companies where necessary.
  • Public authorities: To comply with legal obligations, court orders or other lawful requests from governmental authorities.
  • Other service providers: Where necessary, personal data may be disclosed to postal and delivery service providers, banking institutions, tax advisors, auditors, financial authorities and document destruction service providers.

6. How Long Do We Store Your Data?

Unless otherwise specified in this Privacy Notice, we retain personal data only for as long as necessary to fulfil the relevant processing purpose or to comply with contractual or statutory obligations. Statutory retention obligations may arise in particular under commercial and tax legislation. From the end of the calendar year in which the data were collected, we generally retain personal data contained in accounting records for ten (10) years and personal data contained in commercial correspondence and contracts for six (6) years. Furthermore, we may retain data relating to documented consents, complaints, warranty claims, legal claims and defences for the duration of the applicable statutory limitation periods. Personal data processed for marketing purposes will be deleted if you object to processing for such purposes.

7. How Do We Use Cookies and Other Tracking Technologies?

We use cookies and similar technologies on our websites and in connection with the provision of our services. Further information about our use of these technologies is available through our Cookie Banner, also referred to as a Consent Management Platform (CMP). The Cookie Banner can be accessed when you first visit our website, via a link in the website footer or via a consent badge displayed on the edge of the website. The Cookie Banner also allows you to manage your preferences and to accept or reject specific categories of cookies and similar technologies.

B. Specific Information – How and Why We Process Your Data

1. Website Visitors

Contact Forms & Direct Inquiries

  • What data do we collect? Information you provide through contact forms about yourself or the company for which you work, such as your name, email address and telephone number.
  • Why do we process this data?
    • Customer acquisition and business development;
    • Support and communication, including responding to enquiries.
  • Legal Basis: Art. 6(1)(a) GDPR.

Device & Server Log Files

  • What data do we collect? Pseudonymous technical information relating to your device and browser, server log files, network connection and IP address.
  • Why do we process this data? Ensuring the security, availability and stability of our services, including detecting and preventing attacks.
  • Legal Basis: Art. 6(1)(f) GDPR.

Website Behavior & Analytics

  • What data do we collect? Information about your use of our website, including your IP address and user identifiers, including identifiers assigned by third-party providers where you have given consent through the Cookie Banner.
  • Why do we process this data?
    • Analytics and measurement of website reach to improve our websites, increase customer satisfaction and identify errors;
    • Conversion tracking and performance measurement;
    • Remarketing and personalised advertising for customer acquisition.
  • Legal Basis: Art. 6(1)(a) GDPR.

2. Customers

Contract and Account Details

  • What data do we collect? Information provided when entering into a contract, such as your name, postal address, email address, payment information and billing information.
  • Why do we process this data?
    • Provision of services, payment processing, customer account administration;
    • Support and communication, including responding to enquiries (Legal Basis: Art. 6(1)(b) GDPR);
    • Non-marketing communications concerning technical, security-related and contractual matters (e.g. fraud alerts, account restrictions or contract amendments), product updates, feature announcements and marketing of similar products and services (Legal Basis: Art. 6(1)(f) GDPR);
    • Conducting customer satisfaction and product surveys (Legal Basis: Art. 6(1)(a) GDPR);
    • Compliance with statutory obligations and retention requirements (Legal Basis: Art. 6(1)(c) GDPR).

Surveys and Feedback

  • What data do we collect? Feedback and information that you provide to us during surveys and interviews.
  • Why do we process this data? Improving our products and services, increasing customer satisfaction, identifying errors, and publishing testimonials or customer statements on our website and other marketing channels for promotional purposes.
  • Legal Basis: Art. 6(1)(a) GDPR.

3. Contact Persons at B2B Customers

  • What data do we collect? Information that you provide about yourself and the company for which you work, such as your name, email address and telephone number.
  • Why do we process this data?
    • Performance of the contract with your employer or organisation, account administration and invoicing, support and communication, responding to enquiries, non-marketing communications regarding product updates and new features (Legal Basis: Art. 6(1)(f) GDPR);
    • Conducting customer satisfaction and product surveys, marketing of products and services (Legal Basis: Art. 6(1)(a) GDPR);
    • Compliance with legal obligations and statutory retention requirements (Legal Basis: Art. 6(1)(c) GDPR).

4. Job Applicants

  • What data do we collect? Personal data provided by you during the application process or supplied by a recruitment agency acting on your behalf (CV, employment history, qualifications, professional experience, application documents).
  • Why do we process this data?
    • Assessing whether employment is possible; managing the recruitment process and taking steps prior to entering into an employment relationship (Legal Basis: Art. 6(1)(b) GDPR and Section 26 BDSG);
    • Compliance with statutory retention obligations or establishing, exercising or defending legal claims (Legal Basis: Art. 6(1)(c) GDPR);
    • Where you have given your consent, inclusion in our talent pool in order to contact you regarding future employment opportunities (Legal Basis: Art. 6(1)(a) GDPR).
  • Applicant History: Name and contact details obtained during the recruitment process to maintain records of previous applicants (Legal Basis: Art. 6(1)(f) GDPR).
  • Retention Periods for Applicants: If we are unable to offer you employment, we will generally retain the application documents you submitted for up to six (6) months following a rejection in order to respond to questions relating to your application and our decision. This does not apply where statutory provisions prevent deletion, where further storage is necessary for evidentiary purposes or where you have expressly consented to longer retention. We retain your name and contact details for three (3) years in order to maintain records of previous applicants.

5. Newsletter Subscribers

  • What data do we collect?
    • Name and contact details provided when subscribing to our newsletter.
    • Pseudonymous information regarding your interaction with our newsletters (click behaviour, open rate and opening time, time spent engaging with newsletter content).
  • Why do we process this data?
    • Sending promotional newsletters with information and updates about our products, promotions and events for sales promotion and customer acquisition purposes (Legal Basis for subscription/dispatch: Art. 6(1)(a) GDPR; Legal Basis for performance analysis and optimization: Art. 6(1)(f) GDPR).

6. Social Media Visitors

Social Media Providers

When you visit our social media pages (Facebook, Instagram, LinkedIn, YouTube), through which we present our company or individual products from our offering, certain information about you is processed by the respective platform provider:

Joint Controllership

The social media providers provide us with anonymised statistics and insights for our pages, which help us understand the types of actions that users take on our pages (“Page Insights”). These Page Insights are generated based on certain information about individuals who have visited our pages:

  • Facebook and Instagram:
    A Joint Controller Agreement is in place (Joint Controller Agreement). Data subject rights may also be exercised directly against Meta. Further information is available in Meta’s Privacy Policy.
  • LinkedIn:
    A Joint Controller Agreement is in place (Joint Controller Agreement). Data subject rights may be exercised against LinkedIn via the LinkedIn contact form. LinkedIn’s Data Protection Officer can be contacted via this link. We have agreed with LinkedIn that the Irish Data Protection Commission is the lead supervisory authority for the processing of Page Insights data. You may lodge a complaint with the Irish Data Protection Commission (www.dataprotection.ie) or with any other competent supervisory authority.
  • YouTube:
    Google’s Controller-to-Controller Data Protection Terms apply (Controller-to-Controller Data Protection Terms). Google’s privacy settings are available at myaccount.google.com.

Processing by isento robotics GmbH

We process information that you provide to us through our social media page on the relevant social media platform (such as username, contact details, or messages sent to us):

  • Support, communication and responding to enquiries:
    Legal Basis: Art. 6(1)(f) GDPR.
  • Competitions and giveaways:
    To identify winners and send prizes.
    Legal Basis: Art. 6(1)(b) GDPR.

← Home