Privacy Policy & Terms and Conditions: Global E-Invoice Cloud

Privacy Policy & Terms and Conditions:
Global E-Invoice Cloud

Softway AG

Industriestrasse 17
96114 Hirschaid, Germany
Tel: +49 9543 8238-0
Fax: +49 9543 8238-23
www.softway.de
dsb@softway.de

We appreciate your visit to our website. On this page, you will find our privacy policy and the general terms and conditions for Global E-Invoice Cloud.

Your privacy and the associated protection of personal data are important to us. That is why we conduct our business in accordance with the applicable legal provisions on data protection and data security. It is very important to us that you feel secure with us. For this reason, we and our data protection officer ensure compliance with data protection regulations.

Privacy Policy

Contents

I. Softway AG Privacy Policy

1. preliminary remark
2. definitions
3 Responsible party and general information
4. use of the website

4.1 Log files
4.2 Consent management with OneTrust
4.3 Use of newsletters
4.4 Communication via email, online form, fax, telephone, or postal mail

5. integration of third-party services and content

5.1 General
5.2 Social media plugins / social share plugins
5.3 Google Analytics
5.4 Google Tag Manager
5.5 Google Ads
5.6 Use of YouTube
5.7 Use of Facebook
5.8 Use of Instagram
5.9 Use of Xing
5.10 Use of Linkedin
5.11 Use of reCAPTCHA
5.12 Use of Hubspot
5.13 Use of the Microsoft Teams video conferencing system
5.14 Use of the Zoom video conferencing system
5.15 Use of SalesViewer® technology

6. categories of recipients of your data

6.1 Within SOFTWAY
6.2 Outside SOFTWAY
6.3 Processors
6.4 Links to other websites and applications

7. transfers to third countries

7.1 SOFTWAY International
7.2 Transfer bases

8. duration of data use/storage

8.1 General
8.2 Cookies
8.3 Deletion of data
8.4 User account data

9. data security/secure data transmission

10. rights of data subjects

10.1 Right of access
10.2 Right to rectification
10.3 Right to erasure
10.4 Right to restriction of processing
10.5 Right to data portability
10.6 Right to withdraw consent
10.7 Right to object
10.8 Automated individual decision-making, including profiling
10.9 Right to lodge a complaint/supervisory authority
10.10 Scope of your obligation to transfer data

11. updating your data
12. storage
13. transfer of business
14. data protection officer
15. changes to the privacy policy

II SOFTWAY privacy policy for Facebook

1. jointly responsible for processing
2. data processing with Facebook

2.1 Operation of a Facebook fan page
2.2 Use of Facebook Insights
2.3 Further information

3. rights of data subjects
4. data protection officer

III SOFTWAY privacy policy for Instagram

1. responsible party

1.1 Instagram
1.2 SOFTWAY
1.3 Jointly responsible for processing

2. data processing with Instagram

2.1 Operation of an Instagram company profile
2.2 Use of Instagram Insights

3. further information
4. rights of data subjects
5. data protection officer

IV SOFTWAY privacy policy for YouTube

1. responsible party

1.1 Google
1.2 SOFTWAY
1.3 Jointly responsible for processing

2. data processing with YouTube

2.1 Operation of a YouTube channel
2.2 Use of YouTube on the SOFTWAY website
2.3 Use of YouTube Analytics
2.4 Further information

3. rights of data subjects
4. data protection officer

V. SOFTWAY privacy policy for Xing

1. responsible party

1.1 New Work
1.2 SOFTWAY
1.3 Jointly responsible for processing

2. data processing with Xing

2.1 Operation of a Xing company profile
2.2 Use of Xing analysis functions
2.3 Further information

3. rights of data subjects
4. data protection officer

VI SOFTWAY privacy policy for LinkedIn

1. jointly responsible for processing
2. data processing with LinkedIn

2.1. Operating a LinkedIn company profile
2.2 Use of Page Insights
2.3 Further information

3. rights of data subjects
4. Data protection officer

VII SOFTWAY privacy policy for reCAPTCHA

VIII SOFTWAY Privacy Policy for Hubspot

IX. SOFTWAY privacy policy for the use of the Microsoft Teams video conferencing system

1. responsible party
2. Purposes of processing
3. What data is processed?
4. to what extent do we process your data?
5 Legal basis for data processing
6. recipients/categories of recipients of personal data
7. data processing outside the EEA countries
8. data protection officer
9. your rights as a data subject
10. data deletion
11. changes to this privacy policy

X. SOFTWAY privacy policy for the use of the Zoom video conferencing system

1. responsible party
2. Purposes of processing
3. What data is processed?
4. to what extent do we process your data?
5 Legal basis for data processing
6. recipients/categories of recipients of personal data
7. data processing outside the EEA countries
8. data protection officer
9. your rights as a data subject
10. data deletion
11. changes to this privacy policy

XI. Privacy policy for applications to SOFTWAY

1. responsible party
2. data collection
3. type and purposes of processing personal data
4. legal basis
5. your rights

5.1 Right to information
5.2 Right to correction or deletion
5.3 Right to restriction of processing
5.4 Right to data portability
5.5 Right to object to processing

6. retention period
7. objection or revocation of your consent to the processing of your data

I. Privacy Policy of SOFTWAY AG

1. preliminary note

We appreciate your visit to the website of SOFTWAY AG (hereinafter referred to as “SOFTWAY”).
Your privacy and the protection of personal data are of great importance to us.
Please read the following information carefully. For any questions, you may contact SOFTWAY directly or reach out to our Data Protection Officer.

For readability purposes, the masculine form (e.g., employee instead of employee(s) of all genders) is used throughout this Privacy Policy. Unless explicitly stated otherwise, all gender identities are, of course, included.

2. definitions

Data protection is a complex topic. To facilitate your understanding of this Privacy Policy, we provide the following definitions of key terms used herein.

  • “Processor”:
    As defined in Article 28 of the General Data Protection Regulation (GDPR), a processor is a service provider that processes personal data on behalf of and according to the instructions of the controller.
    The processor does not own or have any independent interest in the data. Before engaging such a service provider, SOFTWAY concludes a dedicated data processing agreement (DPA) and ensures appropriate measures for the protection of your personal data.

  • “Cookies”:
    Cookies are small text files stored on your device (e.g., computer, smartphone) that save certain settings or information for exchange with our systems via your browser.
    A cookie typically contains the name of the visited website, its lifetime, and an alphanumeric identifier.
    Cookies enable systems to recognize a user’s device and make preset configurations immediately available.

  • “Third Party”:
    Any natural or legal person or entity other than the data subject, the controller, the processor, or persons authorized to process personal data under the direct authority of the controller or processor (cf. Art. 4 No. 10 GDPR).
    Consequently, a processor acting under Article 28 GDPR is not considered a third party.

  • “IP Address”:
    A numerical identifier assigned to a specific IT device or network.
    Similar to a postal address, an IP address enables the correct routing of data to its intended recipient.

  • “Personal Data”:
    Any information relating to an identified or identifiable natural person (Art. 4 No. 1 GDPR).

  • “Controller”:
    As defined in Art. 4 No. 7 GDPR, a controller is any natural or legal person which, alone or jointly with others, determines the purposes and means of processing personal data (in this case: the website operator).

3 Controller and General Information

SOFTWAY AG is committed to the responsible collection, processing, and use of personal data, and to full compliance with the applicable data protection laws of Germany, the European Union, and other jurisdictions where SOFTWAY operates.

We are dedicated to ensuring the security and confidentiality of personal data through necessary and appropriate technical and organizational measures (TOMs) in the course of our business activities.

Controller (as per Art. 4 No. 7 GDPR):
SOFTWAY AG
Industriestraße 17
D-96114 Hirschaid, Germany
Phone: +49 (0) 9543 8238-0
Fax: +49 (0) 9543 8238-23
Email: dsb@softway.de

SOFTWAY AG bears full responsibility for the processing of personal data, whether performed by the company itself or by its designated processors.
If another entity acts as the controller within the meaning of Art. 4 No. 7 GDPR, this will be explicitly indicated unless it is obvious from context.

SOFTWAY continuously reviews, updates, and enhances its data protection processes to ensure the highest level of compliance with applicable laws.

4. use of the website

Beyond the provision of information, our website offers various services that you may use if interested.
To provide such services, we may require additional personal data, which will be processed solely for the specified purpose as described below.

4.1 Server log files

Each time you access our website or retrieve a file, certain data are automatically logged (“log data”).
These data are technically necessary to provide you with the website and ensure its functionality.

The following information is typically transmitted by your browser to our web server and recorded:

  • IP address

  • Date and time of the request

  • Time zone difference from Greenwich Mean Time (GMT)

  • Requested page or resource

  • Access status / HTTP status code

  • Volume of data transferred

  • Referrer URL (website from which the request originated)

  • Browser type and version

  • Browser language

  • Operating system and user interface

We process these data to ensure website functionality and to make your visit as user-friendly as possible.
We reserve the right to analyze log data on a case-by-case basis for data security reasons.
No individual profiling is conducted, and the data are not combined with other data sources.

Legal basis: Article 6 (1) (f) GDPR – our legitimate interest lies in providing a secure, user-friendly, and technically reliable website.

4.2 Consent management via OneTrust

Related web resources: cookielaw.org

For managing user consent, we use the Consent Management Platform (CMP) provided by
OneTrust Ltd, 82 St. John Street, Farringdon, London EC1M 4JN, UK (“OneTrust”).

The platform enables the administration of your consent preferences for both cookie-based and non-cookie-based technologies, as well as external services.
If you decline consent for a specific service, the CMP ensures that your personal data are not processed in relation to that service.

You may withdraw or modify your consents at any time with future effect by adjusting your settings within the consent manager, accessible here: Cookie Settings.

Legal basis: Article 6 (1) (f) GDPR – our legitimate interest is to provide a user-friendly website experience, to analyze and optimize technical functionality, and to comply with data protection obligations.

Personal data transferred to OneTrust (UK) are safeguarded under Standard Contractual Clauses (SCCs) and a Data Processing Agreement (DPA) concluded with OneTrust.
Furthermore, under the EU Commission’s adequacy decision (28 June 2021), the UK is recognized as a country ensuring an adequate level of data protection under Article 45 GDPR.

For more information on OneTrust’s privacy practices, please visit:
https://www.onetrust.de/datenschutzerklaerung.

In addition, our detailed Cookie Policy (types, purposes, duration, and recipients) is available at:
https://www.softway.de/cookie-richtlinie

4.3 Newsletter Subscription

If you subscribe to our newsletter, which provides information about our latest offerings and relevant company updates, we will collect and process the following personal data as mandatory fields:

  • Email address

  • Salutation

  • First name

  • Last name

Additional information that is separately marked as optional may be provided to allow us to address you personally.
Your personal data will be used exclusively for distributing the newsletter and for statistical analyses to evaluate and optimize system performance.
Your data will not be disclosed to third parties or used for any other purpose.

To ensure that newsletter registrations are genuine and intentional, we employ a double opt-in procedure.
This means that after your initial subscription, you will receive a confirmation email containing a link to finalize your registration.
If you do not confirm your registration within 48 hours, a reminder will be sent, and after 7 days your data will be locked and permanently deleted within 4 weeks.

We also store the IP addresses and timestamps of your registration and confirmation to be able to verify your consent and to prevent misuse of your personal data.

Legal basis: Article 6 (1) (a) GDPR – your consent.
You may withdraw your consent at any time with future effect by clicking the “unsubscribe” link included in each newsletter or by sending an informal notice to
datenschutz@softway.com, by fax, or by post.
No additional costs beyond standard transmission charges apply.

4.4 Communication via Email, Online Form, Fax, Telephone, or Postal Mail

4.4.1 Contact via Email, Fax, Telephone, or Postal Mail

When you contact us by email, fax, telephone, or postal mail, we process your data solely for the purpose of handling and responding to your inquiry.
Your data will not be passed on to third parties.
Your personal data will be deleted once your request has been processed, provided there is no legal requirement to retain the data (e.g., statutory retention periods).

Legal basis: Article 6 (1) (f) GDPR – our legitimate interest lies in adequately processing and responding to your request.
If your request is related to pre-contractual or contractual activities, the alternative legal basis is Article 6 (1) (b) GDPR.

4.4.2 Contact via Online Form

When contacting us through an online form provided on our website, we collect and store the personal data you enter in the form fields for the specific purpose of handling your request.
These may include: salutation, first and last name, company name, address, postal code, city, email address, position, comments, telephone number, and possibly a customer ID.

Your data will be used exclusively for processing and responding to your inquiry.
No data will be transferred to third parties.
Your data will be deleted once the purpose of storage no longer applies or upon your request, unless legal obligations require longer retention.

Legal basis: Article 6 (1) (f) GDPR – our legitimate interest lies in adequately processing and responding to your inquiry.
If your request serves to initiate or prepare a contractual relationship, the alternative legal basis is Article 6 (1) (b) GDPR.

5. integration of third-party services and content

5.1 General Information

If you grant consent through our Consent Manager, third-party content such as videos, maps, or graphics from external websites may be embedded within our online offerings.
This requires the respective providers to process certain data (e.g., IP address, browser and device data, visited webpages, date and time of access, and possibly additional data from cookies or non-cookie-based technologies).

The IP address is essential for delivering such content to your browser.
We make every effort to include only content from providers who use your IP address solely for content delivery.
However, we have no control over whether such providers also use it for statistical or analytical purposes.
If we are aware of such processing, we will inform you accordingly.

5.2 Social media plugins / social share plugins

Social plugins / social share plugins used: AddThis

We use social plugins, such as AddThis, that allow you to bookmark or share content with other users.
These plugins enable interaction with social networks and help us make our offerings more engaging.
However, we have no influence over the data collected and processed by these providers, nor do we know the full scope or purpose of data processing or storage duration.

Typically, plugin providers use such data to create cross-device usage profiles for advertising, market research, and personalized website design.
This may occur even if you do not have an account with the provider or are not logged in.
If you are logged in, the data may be directly associated with your existing account and shared with your contacts.

When using social plugins, requests to external servers (potentially located in non-EU countries) may occur, meaning data such as your IP address, browser and device information, visited webpages, and timestamps may be processed outside the EU.
We explicitly inform you that such transfers may involve data movement to countries considered insecure from a data-protection perspective.

Legal basis: Article 6 (1) (a) GDPR – your consent.
You may withdraw your consent at any time with future effect via the Consent Manager.

5.2.1 AddThis bookmarking

Related web resources: addthis.com

We use a social plugin from AddThis, provided by Oracle America, Inc., 500 Oracle Parkway, Redwood Shores, CA 94065, USA.
The plugin transmits your data (e.g., IP address) to Oracle and, if applicable, to the selected social network or bookmarking service.
According to our knowledge, Oracle receives information about which of our pages you have visited.

If you wish to object to data collection and storage by Oracle, you can do so by setting an opt-out cookie here:
https://datacloudoptout.oracle.com/#optout

Further details:
AddThis Terms of Service | Oracle AddThis Privacy Policy

5.3 Google Analytics

Related web resources: google.com, google-analytics.com

We use Google Analytics, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”).

The purpose is to analyze and continuously improve the use of our website and to make it more user-friendly.
Google Analytics collects data on user behavior (e.g., visited pages, interactions) via cookies.
The data are generally transferred to Google servers in the USA and stored there.
We have activated IP anonymization so that Google truncates your IP address within the EU/EEA before transfer.

Google processes online identifiers (including cookie IDs) and device identifiers.
On our behalf, Google uses these data to evaluate website usage and compile reports on user activities.
The IP address transmitted by your browser is not merged with other Google data.
We have entered into a Data Processing Agreement (DPA) with Google.

The EU-U.S. Data Privacy Framework (2023) ensures an adequate level of data protection for certified U.S. entities per Art. 45 GDPR.

Legal basis: Article 6 (1) (a) GDPR – your consent.
You may withdraw it at any time via the Consent Manager or install the opt-out browser plugin here:
https://tools.google.com/dlpage/gaoptout?hl=en

Further information:
Google Analytics Terms | Google Partner Sites Policy

5.4 Google Tag Manager

Related web resources: google.com, googletagmanager.com

We use Google Tag Manager (by Google Ireland Limited) to manage website tags via a user interface.
The Tag Manager itself does not set cookies or collect personal data.
However, Google may process IP addresses and online identifiers for operational purposes.
Any deactivation you apply at domain or cookie level will also apply to tags implemented through Tag Manager.

Data may be transferred to the USA under Standard Contractual Clauses and the EU-U.S. Data Privacy Framework.

Legal basis: Article 6 (1) (a) GDPR – your consent.
You may withdraw it at any time via the Consent Manager.

More information:
https://www.google.com/intl/en/tagmanager/use-policy.html | https://policies.google.com/privacy

5.5 Google Ads

Related web resources: google.com, ads.google.com

We use Google Ads (Google Ireland Limited) for advertising and performance analysis.
This service may display personalized or non-personalized ads based on user data collected via cookies (e.g., IP address, device info, location, search terms).

Data are processed under SCCs and the EU-U.S. Data Privacy Framework.
Legal basis: Article 6 (1) (a) GDPR – consent.
Users may withdraw consent at any time via the Consent Manager.

Data retention: log data 9 months; cookie information 18 months (max.).

Further information:
https://policies.google.com/privacy | https://policies.google.com/technologies/cookies | https://safety.google/privacy/privacy-controls/

5.6 Use of YouTube

Information on data protection regarding the use of YouTube can be found here.

5.7 Use of Facebook

Information on data protection regarding the use of Facebook can be found here.

5.8 Use of Instagram

Information on data protection regarding the use of Instagram can be found here.

5.9 Use of Xing

Information on data protection regarding the use of Xing can be found here.

5.10 Use of LinkedIn

Information on data protection when using LinkedIn can be found here.

5.11 Use of reCAPTCHA

Information on data protection when using reCAPTCHA can be found here.

5.12 Use of Hubspot

Information on data protection regarding the use of Hubspot can be found here.

5.13 Use of the Microsoft Teams video conferencing system

Information on data protection regarding the use of Microsoft Teams can be found here.

5.14 Use of the Zoom video conferencing system

Information on data protection regarding the use of Zoom can be found here.

5.15 Use of SalesViewer® technology

On this website, data is collected and stored for marketing, market research, and optimization purposes using SalesViewer® technology from SalesViewer® GmbH on the basis of the legitimate interests of the website operator (Art. 6 (1) (f) GDPR).

For this purpose, a JavaScript-based code is used to collect company-related data and information about its use. The data collected using this technology is encrypted using a non-reversible one-way function (known as hashing). The data is immediately pseudonymized and is not used to personally identify visitors to this website.

The data stored within the scope of Salesviewer is deleted as soon as it is no longer required for its intended purpose and there are no legal retention obligations that prevent deletion. You can object to the collection and storage of data at any time with future effect by clicking on this link https://www.salesviewer.com/opt-out to prevent SalesViewer® from collecting data on this website in the future. An opt-out cookie for this website will be stored on your device. If you delete your cookies in this browser, you will need to click on this link again.

Further information on SalesViewer’s data protection can be found at https://www.salesviewer.com/de/plattform/datenschutz/.

6 Categories of Data Recipients

6.1 Within SOFTWAY

Only authorized departments and employees who need access to fulfill their duties may process your personal data.

6.2 Outside SOFTWAY

We disclose personal data to external recipients only where legally permitted or required and only to the extent necessary.
Categories of recipients include:

  1. Payment service providers

  2. External providers for invoice dispatch

  3. Logistics companies

  4. Auditors

  5. Consultants and legal advisors

  6. IT service providers

  7. Telecommunication providers

  8. Collection agencies and law firms for claim enforcement

  9. Marketing and advertising service providers

Transfers are based on:

  • Your consent (Art. 6 (1)(a) GDPR), which may be withdrawn at any time;

  • Contractual necessity (Art. 6 (1)(b) GDPR); or

  • Legal obligation (Art. 6 (1)(c) GDPR).

6.3 Processors (Data Processors)

Where we engage external processors to perform tasks on our behalf, we enter into a legally binding Data Processing Agreement (DPA) to ensure compliance with GDPR requirements and that such processors act solely under our instructions.

6.4 Links to External Websites and Applications

Our website may contain links to third-party websites or applications that are not operated by SOFTWAY.
We are not responsible for their data protection practices.

Users should review the respective privacy statements before using such sites or services.

7. transfers to third countries

7.1 SOFTWAY International

SOFTWAY operates globally. Like many international organizations, SOFTWAY centralizes certain aspects of customer administration, data management, and data storage within the European Union (EU). Cross-border projects may require access to personal data by SOFTWAY entities located in different countries.

Consequently, your personal data may be transferred outside your country of origin – including to countries both inside and outside the European Economic Area (EEA).
Such access may be granted within the SOFTWAY Group on a global basis.

SOFTWAY ensures that all necessary legal and technical safeguards are in place to maintain the integrity and confidentiality of personal data transferred within the SOFTWAY internal data exchange network, particularly for data originating from within the EEA.

The same level of protection applies throughout all SOFTWAY entities, regardless of processing location.

In addition, your personal data may be processed by service providers acting on SOFTWAY’s behalf who may also be located outside the EEA.
Further details are provided under section 6.3 “Processors.”

7.2 Legal Basis for Data Transfers

Transfers of personal data to third countries – i.e., countries outside the EU or EEA – are conducted only if:

  1. An adequacy decision has been issued by the European Commission under Article 45 GDPR;

  2. A specific derogation applies under Article 49 GDPR (for isolated cases);

  3. A legal obligation requires the transfer;

  4. You have explicitly consented to such transfer (consent may be withdrawn at any time through the Consent Manager); or

  5. Standard Contractual Clauses (SCCs) combined with additional technical and organizational safeguards have been implemented.

8 Duration of Data Use and Retention

8.1 General retention

We process your personal data for as long as is necessary to maintain our business relationship, which includes handling inquiries, initiating contracts (pre-contractual stage), and fulfilling contractual obligations.

We are also subject to statutory retention and documentation obligations, for instance under the German Commercial Code (HGB) and the Fiscal Code (AO), which may require data retention for up to ten (10) years following the termination of the business relationship or the pre-contractual relationship.

In some cases, longer retention periods may apply (e.g., under the German Civil Code, §§195 ff. BGB), particularly for legal claims or defense purposes, where limitation periods may extend up to thirty (30) years.

8.2 Cookies

You may revoke or delete cookies at any time by adjusting your preferences within our Consent Manager or directly in your browser settings.

A list of cookies used on our website, including purpose and duration, is available at:https://www.softway.de/cookie-richtlinie.

8.3 Data deletion

Personal data are deleted when they are no longer necessary for fulfilling contractual or legal obligations or when processing is otherwise no longer justified.
In cases where continued limited processing is required to meet residual obligations, your data may be stored and used for a period compatible with such purposes, even after the business relationship has ended.

9. data security / secure data transmission

Please note that data transmission over the internet (e.g., via email) may involve security risks. While we implement extensive technical and organizational measures (TOMs) to protect your personal data from unauthorized access, alteration, loss, or destruction, absolute security cannot be guaranteed.

Our IT systems – including the website – are protected through access controls, encryption, and other safeguards to prevent unauthorized access and data breaches.

Personal data transmitted to us online are protected using Secure Socket Layer (SSL) encryption (256-bit).
For security purposes, your IP address, along with the date and time of your visit, may also be logged.

10. data subject rights

Under the General Data Protection Regulation (GDPR), you have the following rights as a data subject.
You may exercise these rights at any time by contacting our external Data Protection Officer:

Brands Consulting | Data Protection & Consulting
Mr. Bernhard Brands
Auf dem Hahn 11
D-56412 Niedererbach (Westerwald), Germany
Website: www.brands-consulting.eu
Email: softway@rlp.brands-consulting.eu

10.1 Right of access (Art. 15 GDPR)

You have the right to request confirmation as to whether we process your personal data.
If so, you may obtain detailed information about the nature, purpose, and categories of data processed, as well as recipients, storage periods, and other relevant processing details.

10.2 Right to rectification (Art. 16 GDPR)

You have the right to request the correction of inaccurate or incomplete personal data concerning you, unless you are able to make such changes directly yourself.

10.3 Right to Erasure (“Right to be Forgotten”) (Art. 17 GDPR)

You have the right to request the immediate deletion of your personal data where the legal grounds apply, for example:

  • when the data are no longer necessary for the purposes for which they were collected,

  • when you withdraw your consent and no other legal basis applies, or

  • when processing is unlawful.

The right to erasure does not apply if processing is required for:

  • exercising freedom of expression and information,

  • compliance with a legal obligation (e.g., statutory retention periods), or

  • the establishment, exercise, or defense of legal claims.

10.4 Right to Restriction of Processing (Art. 18 GDPR)

You may request that we restrict processing of your data where one of the conditions set out in Article 18 GDPR applies (e.g., if you contest the accuracy of your data or object to processing).

10.5 Right to data portability (Art. 20 GDPR)

You have the right to receive personal data that you have provided to us in a structured, commonly used, and machine-readable format and to transmit those data to another controller where technically feasible.

10.6 Right to Withdraw Consent (Art. 7(3) GDPR)

You may withdraw your consent to data processing at any time with effect for the future. Such withdrawal does not affect the lawfulness of processing based on consent before its withdrawal. No additional costs beyond basic transmission rates apply.

10.7 Right to object (Art. 21 GDPR)

You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data based on Article 6(1)(e) or (f) GDPR.
If you object, we will stop processing your data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the processing is necessary for the establishment, exercise, or defense of legal claims.

10.8 Automated Decision-Making, Including Profiling (Art. 22 GDPR)

We do not conduct any automated decision-making or profiling that would have legal or significant effects on you.

10.9 Right to Lodge a Complaint (Art. 77 GDPR)

You have the right to lodge a complaint with a supervisory authority if you believe that your personal data are being processed unlawfully.
The competent authority for SOFTWAY AG is:

Bavarian State Office for Data Protection Supervision (BayLDA)
Promenade 18
91522 Ansbach, Germany
Mailing address: P.O. Box 1349, 91504 Ansbach
Phone: +49 (0) 981 180093-0
Fax: +49 (0) 981 180093-800
Email: poststelle@lda.bayern.de

However, we recommend contacting our Data Protection Officer first, who will handle your request in confidence.

10.10 Obligation to Provide Personal Data

In general, you are not legally required to provide your personal data to us.
However, failure to do so may mean we are unable to offer certain website functions, respond to inquiries, or enter into a contractual relationship with you.

11 Updating Your Data

SOFTWAY is committed to upholding the data protection principles set out in Article 5 of the GDPR, including the accuracy of personal data.
We therefore rely on your cooperation to help keep your personal information up to date.

Please inform us promptly of any changes to your contact or personal details.
You may contact your designated SOFTWAY representative directly or update your personal information through your user account on our website at
https://www.softway.de.

You may also contact our Data Protection Officer directly for assistance (see Section 14 below).

12. retention of personal data

SOFTWAY retains your personal data only for as long as is necessary to fulfill the purposes outlined under “Collected Data and Processing Purposes,” unless a longer retention period is required by law or permitted for legitimate business reasons.

Data are deleted as soon as:

  • the purpose of processing ceases to apply,

  • you exercise your right to erasure, or

  • continued storage would otherwise be unlawful.

In certain cases, SOFTWAY may be legally obliged to retain specific data for longer periods – for example, to establish, exercise, or defend legal rights, or to ensure compliance with applicable record-keeping laws.

Where possible and appropriate, SOFTWAY anonymizes personal data through deletion, substitution, or masking of personal identifiers to prevent identification.

13. business transfer

In the event that SOFTWAY, or a part of its business (including its websites), is sold, merged, or otherwise transferred, your personal data may be shared or transferred to the acquiring entity, co-owner, or operator of the relevant business segment or website.

Personal data may also be disclosed or transferred in connection with corporate mergers, consolidations, restructurings, stock or asset sales, or similar transactions – including during due diligence reviews.
In all such cases, this Privacy Policy will continue to apply with respect to the use and disclosure of your personal data.

If we transfer your personal data as part of a business transaction, processing will occur on the following legal basis:

  • Article 6 (1)(f) GDPR (Legitimate Interest): SOFTWAY’s legitimate interest in developing its business and structuring its corporate organization to meet operational needs.

14 Data Protection Officer

If you wish to exercise any of your rights as a data subject (see Section 10) or have any questions about the processing of your personal data, please contact our external Data Protection Officer:

Brands Consulting | Data Protection & Consulting
Mr. Bernhard Brands
Auf dem Hahn 11
D-56412 Niedererbach (Westerwald), Germany
Website: www.brands-consulting.eu
Email: softway@rlp.brands-consulting.eu

All data protection requests will be handled confidentially and in accordance with the applicable legal requirements.

15 Amendments to This Privacy Policy

Technological developments, changes in legal requirements, or adjustments to our internal processes may require updates to this Privacy Policy.

SOFTWAY reserves the right to amend this Privacy Policy at any time, with effect for the future.
The most recent version of this Policy is always available on our website.

We therefore recommend visiting this page regularly to stay informed of any changes to the applicable data protection provisions.

Effective Date: August 26, 2023

II. SOFTWAY’s data protection information for Facebook

We use the Facebook fan page of the provider MetaPlatforms Ireland Ltd at https://www.facebook.com/SoftwayAG (“Facebook”) to inform you about our offers and to communicate with you. We would like to point out that your data may be processed outside the European Union (EU). The processing of personal data outside the EU entails fundamental risks with regard to the enforcement of the rights of those affected and the preservation of the general protection objectives of data protection.

1. the following are jointly responsible for processing:

Meta Platforms Ireland Ltd.
4 Grand Canal Square
Dublin 2
Ireland
imprint@support.instagram.com
Fax: +1 650 543 5340

and

Softway AG
Industriestrasse 17
D-96114 Hirschaid
Telephone: +49(0) 9543 8238-0
Fax: +49 (0) 9543 8238-23
Email: dsb@softway.de

Facebook assumes primary responsibility for processing the Insights data and fulfilling the obligations arising from the GDPR. This includes the fulfillment of (1) necessary information obligations, (2) data subject rights that can be asserted against Facebook, (3) reporting obligations in the event of data protection violations and (4) ensuring appropriate technical and organizational measures for secure processing.

Of course, you can also assert your request for information or other rights against us. In this case, we will be happy to forward your concern to Facebook, as Facebook has access to the relevant user data and can take measures in accordance with your user rights.

2. data processing with Facebook
2.1 Operation of a Facebook fan page

We use our Facebook fan page to provide you with news about our offers and to get in touch with you. For example, if you comment on our posts, we process the content of your comment and, if necessary, other data that you provide to us or that is transmitted through your Facebook activity. Depending on the privacy settings of your user profile, we may also have access to further information about your user profile and your Facebook activities (e.g. posts and “likes”). Every time you visit our Facebook fan page, your personal data (e.g. IP address; browser data; operating system and device; websites visited; date and time of access, etc.) are processed by Facebook and cookies are set. However, we have no influence on the data collected and the data processing, nor are we aware of the full extent of the data collection, the purposes of the processing, the storage periods or the deletion of the collected data. This enables Facebook to use your data to create usage profiles across devices for the purposes of advertising, market research and/or the needs-based design of their websites. Such use may occur even if you do not have a Facebook account or are not logged in there. If you are logged in to Facebook, your data will be assigned directly to your existing Facebook account and, if necessary, publicly shared with your contacts.

Our legal basis for processing is Article 6 (1) (f) GDPR. Our legitimate interest lies in external representation and communication with you.

2.2 Use of Facebook Insights

The processing of personal data when using Facebook takes place with Facebook Insights and also includes processing purposes for market research, advertising and the collection of statistical data. For example, Usage profiles can be created based on your usage behavior and your resulting interests.

The usage profiles can in turn be used, for example to place advertisements inside and outside of Facebook that presumably match your interests. Cookies are usually stored on your device to record your user behavior, your preferences and interests and to create and store usage profiles. The purpose of Facebook is to show you tailored advertising inside and outside of Facebook. Furthermore, data can also be stored in the usage profiles regardless of the device you use (especially if you are a member of Facebook and logged in to it). However, even if you do not have a Facebook profile or are not logged into it when you visit our fan page, Facebook can assign this data to a user profile. Cookies remain on your device until you delete them.

Data from Facebook Insights is only available to us in anonymized form, so that we can only analyze the general user behavior of visitors to our fan page. However, this does not allow us to draw conclusions about individual users.

Our legal basis for processing is Article 6 (1) (f) GDPR. Our legitimate interest lies in analyzing the reach and effectiveness of our Facebook activities in order to optimize our online offering.

2.3 Further information

For a detailed description of the respective processing, the objection options (opt-out) and legal bases, we refer to the following linked information on Facebook’s data protection:

– Information about Facebook Insights:
https://www.facebook.com/business/pages/manage#page_insights
– Shared responsibility agreement with Facebook:
https://www.facebook.com/legal/terms/page_controller_addendum
– Data protection declaration:
https://www.facebook.com/about/privacy
– Opt-out option:
https://www.facebook.com/help/568137493302217/

Legal basis for processing:
https://www.facebook.com/about/privacy/legal_base
and
https://de-de.facebook.com/policy.php

3. rights of those affected

We would like to point out your data subject rights in accordance with Art. 13 ff. GDPR. In particular, you have a right to information (Article 15 GDPR), a right to rectification (Article 16 GDPR), a right to erasure (Article 17 GDPR), a right to restriction of processing (Article 18 GDPR), a right to data portability (Article 20 GDPR) and a right to object to processing (Article 21 GDPR). We also ensure your rights according to Art. 22 GDPR. You or your data in our area of responsibility are therefore not
the subject of decisions that are based exclusively on automated processing – including profiling. You also have the right to lodge a complaint with a supervisory authority at any time (Article 77 GDPR). In addition, you have the right to revoke your consent with effect for the future (Art. 7 Para. 3 GDPR).

4. data protection officer

If you would like information about the processing of your personal data in connection with Facebook or would like to assert your data subject rights in this context, we would like to point out that the most effective way to do this is to address your request directly to Facebook. You can contact Facebook’s data protection officer via the link https://www.facebook.com/help/contact/540977946302970.

If you would like to exercise your data subject rights with us, please contact our data protection officer at the email address softway@brands-consulting.eu and describe your specific concern to us in as much detail as possible. We will be happy to forward your concern to Facebook, as Facebook has access to the relevant user data and can take measures in accordance with your user rights.

Further information on data protection can be found in the data protection declaration of the SOFTWAY website.

As of: August 26, 2023

III SOFTWAY data protection information for Instagram

We use the Instagram company profile of the provider Meta PlatformsIreland Ltd under softway_ag (“Facebook”) to inform you about our offers with photos and videos. We would like to point out that your data may be processed outside the European Union (EU). The processing of personal data outside the EU entails fundamental risks with regard to the enforcement of the rights of those affected and the preservation of the general protection objectives of data protection

1. responsible person
1.1 Instagram

Responsible for the processing of your data, insofar as it is processed exclusively by Instagram, is:

Meta Platforms Ireland Ltd.
4 Grand Canal Square
Dublin 2
Ireland
impressum@support.instagram.com
Fax: +1 650543 5340

1.2 SOFTWAY

Responsible for the processing of your data, insofar as it is processed exclusively by SOFTWAY, is:

Softway AG
Industriestrasse 17
D-96114 Hirschaid
Telephone: +49(0) 9543 8238-0
Fax: +49 (0) 9543 8238-23
Email: dsb@softway.de

1.3 Jointly responsible for processing

To the extent that your transmitted data is processed jointly by Facebook and SOFTWAY and both decide on the purposes and means of processing, Facebook and SOFTWAY are jointly responsible within the meaning of Art. 26 GDPR. By operating our Instagram company profile, we enable Facebook to process your data, which is made available to us in the form of statistics via the Instagram Insights analysis service.

For this reason – in conjunction with the ruling of the European Court of Justice of June 5, 2018 (ref.: C-210/16) on the existence of joint responsibility for the operation of a Facebook fan page and the use of Facebook’s own analysis service – we also assume joint responsibility for our Instagram company profile and the use of Instagram Insights. However, Facebook currently does not provide an agreement on joint responsibility in accordance with Art. 26 GDPR, in which the data protection obligations of each person responsible can be defined and differentiated from one another.

(https://www.facebook.com/legal/terms/page_controller_addendum).

2. data processing with Instagram
2.1 Operating an Instagram company profile

We use our Instagram company profile to provide you with news about our offers and to get in touch with you. For example, if you comment on our posts, we process the content of your comment and, if necessary, other data that you provide to us or that is transmitted during your Instagram activity. Depending on the privacy settings of your user profile, we may also have access to further information about your user profile and your Instagram activities (e.g. “likes”).

Every time you access our Instagram company profile, your personal data (e.g. IP address; browser data; operating system and device; websites visited; date and time of access, etc.) are processed by Facebook and cookies are set. However, we have no influence on the data collected and the data processing, nor are we aware of the full extent of the data collection, the purposes of the processing, the storage periods or the deletion of the collected data. This enables Facebook to use your data to create cross-device usage profiles for the purposes of advertising, market research and/or the needs-based design of their websites. Such use may occur even if you do not have an Instagram account or are not logged in there. If you are logged in to Instagram, your data will be assigned directly to your existing Instagramprofile and, if necessary, shared publicly with your contacts.

Our legal basis for processing is Article 6 (1) (f) GDPR. Our legitimate interest lies in external representation and communication with you.

2.2 Use of Instagram Insights

The processing of personal data when using Instagram takes place with Instagram Insights and also in cludes processing purposes for market research, advertising and the collection of statistical data. The usage profiles can in turn be used, for example to place advertisements inside and outside of Instagram or Facebook that presumably correspond to your interests. To record your user behavior and to create and store usage profiles, cookies are usually stored on your device. For example, Usage profiles can be created based on your usage behavior for certain posts, stories, IGTV videos, Reels, live videos and your resulting interests. Furthermore, data can also be stored in the usage profiles regardless of the device you use (especially if you are a member of Instagram or Facebook and logged in on these platforms). However, even if you do not have an Instagram profile or are not logged in when you visit our company profile, Facebook can assign this data to a user profile. Cookies remain on your device until you delete them.

Data from Instagram Insights is only available to us in anonymized form, so that we can only analyze the general user behavior of visitors to our Instagram profile. However, this does not allow any conclusions to be drawn about individual users. Our legal basis for processing is Article 6 (1) (f) GDPR. Our legitimate interest lies in analyzing the reach and effectiveness of our Instagram activities in order to optimize our online offering.

3. more information

For a detailed description of the respective processing, the objection options (opt-out) and legal bases, we refer to the following linked information on data protection from Instagram and Facebook:

Information about Instagram Insights:
https://www.facebook.com/help/instagram/788388387972460

Data protection declaration:
https://www.facebook.com/about/privacy and https://help.instagram.com/519522125107875/?helpref=hc_fnav&bc[0]=Instagram help area&bc[1]=Guidelines%20and%20Messages

Opt-out and customization options:
https://www.facebook.com/help/instagram/2885653514995517?locale=de
and
https://help.instagram.com/615366948510230

Legal basis for processing:
https://www.facebook.com/about/privacy/legal_bases
and
https://de-de.facebook.com/policy.php

4. rights of those affected

We would like to point out your data subject rights in accordance with Art. 13 ff. GDPR. In particular, you have a right to information (Article 15 GDPR), a right to rectification (Article 16 GDPR), a right to erasure (Article 17 GDPR), a right to restriction of processing (Article 18 GDPR), a right to data portability (Article 20 GDPR) and a right to object to processing (Article 21 GDPR). We also ensure your rights according to Art. 22 GDPR. You or your data in our area of responsibility are therefore not
the subject of decisions that are based exclusively on automated processing – including profiling. You also have the right to lodge a complaint with a supervisory authority at any time (Article 77 GDPR). In addition, you have the right to revoke your consent with effect for the future (Art. 7 Para. 3 GDPR).

5. data protection officer

If you would like information about the processing of your personal data in connection with Instagram or Facebook or would like to assert your data subject rights in this context, we would like to point out that the most effective way to do this is to address your request directly to Facebook. You can contact Facebook’s data protection officer using the link https://www.facebook.com/help/contact/540977946302970.

If you would like to exercise your data subject rights with us, please contact our data protection officer at the email address softway@brands-consulting.eu and describe your specific concern to us in as much detail as possible. We will be happy to forward your concern to Facebook, as Facebook has access to the relevant user data and can take measures in accordance with your user rights.

As of: August 26, 2023

IV SOFTWAY’s data protection information for YouTube

We use the YouTube channel of the provider Google Ireland Limited (“Google”) at https://www.youtube.com/@softwayag and would like to point out that your data may be processed outside the European Union (EU). The processing of personal data outside the EU entails fundamental risks with regard to the enforcement of the rights of those affected and the preservation of the general protection objectives of data protection.

1. responsible person
1.1 Google

This data protection declaration applies in addition to our existing data protection declaration, in which you will receive all specific information about how we process your personal data in principle and as part of your website visit.

Responsible for the processing of your data, to the extent that it is processed exclusively by Google, is:

Google Ireland Limited
Gordon House, Barrow Street
Dublin 4
Ireland
Telephone: +353 1 543 1000
Fax: +353 1 686 5660
Email: support-deutschland@google.com

1.2 SOFTWAY

Responsible for the processing of your data, insofar as it is processed exclusively by SOFTWAY, is:

Softway AG
Industriestrasse 17
D-96114 Hirschaid
Telephone: +49(0) 9543 8238-0
Fax: +49 (0) 9543 8238-23
Email: dsb@softway.de

1.3 Jointly responsible for processing

To the extent that your transmitted data is processed jointly by Google and SOFTWAY and both decide on the purposes and means of processing, Google and SOFTWAY are jointly responsible within the meaning of Art. 26 GDPR. By operating our YouTube channel, we enable Google to process your data, which is made available to us in the form of statistics via the YouTubeAnalytics analysis service. For this reason – in conjunction with the judgment of the European Court of Justice of June 5, 2018 (ref.: C-210/16) on the existence of joint responsibility for the operation of a Facebook fan page and the use C-210/16 on the existence of joint responsibility for the operation of a Facebook fan page and the use of Facebook’s own analysis service – we also assume joint responsibility for our YouTube channel and the use of YouTube Analytics. However, Google does not currently provide an agreement on joint responsibility in accordance with Art. 26 GDPR, in which the data protection obligations of each person
responsible can be determined and differentiated from one another.

2. data processing with YouTube
2.1 Operating a YouTube channel

We use our YouTube channel to inform you about our offerings and to get in touch with you. For example, if you comment on our posts, we process the content of your comment and, if applicable, other data that you provide to us or that is transmitted during your YouTube activity. Depending on the privacy settings of your user profile, we may also have access to additional information from your user profile and your YouTube activities (e.g., posts and “liked videos”).

Every time you visit our YouTube channel, your personal data (e.g., IP address; browser data; operating system and device; websites visited; date and time of visit, etc.) is processed by Google and cookies are set. However, we have no influence on the data collected and the data processing, nor are we aware of the full extent of the data collection, the purposes of the processing, the storage periods, or the deletion of the data collected. This enables Google to use your data to create cross-device usage profiles for the purposes of advertising, market research, and/or the needs-based design of its websites. Such use may also occur if you do not have a YouTube or Google account or are not logged in there. If you are logged in to YouTube or Google, your data will be directly associated with your existing YouTube or Google account and, if applicable, shared publicly with your contacts.

Our legal basis for processing is Art. 6 (1) lit. f GDPR. Our legitimate interest lies in our public image and communication with you.

2.2 Use of YouTube on the SOFTWAY website

The SOFTWAY website embeds YouTube videos from Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”), which can be played directly from our website. These YouTube videos are all embedded in “extended privacy mode,” which means that no data about you as a user is transferred to YouTube if you do not play the videos. Your data is only transferred when you play the videos.

2.3 Use of YouTube Analytics

The processing of personal data in connection with the operation of our YouTube channel takes place using YouTube Analytics and also includes processing purposes for market research, advertising, and the collection of statistical data. The usage profiles can in turn be used, for example, to place advertisements within and outside the Google advertising network that are presumed to correspond to your interests. Cookies are usually stored on your device to record your user behavior and to create and store usage profiles. For example, usage profiles can be created based on your usage behavior for certain videos and comments. Furthermore, data can also be stored in the usage profiles independently of the devices you use (especially if you have a YouTube or Google account and are logged in to these platforms). However, even if you do not have a YouTube or Google account or are not logged in to it during your visit to our YouTube channel, Google can still assign this data to a user profile. Cookies remain on your device until you delete them.

Data from YouTube Analytics is only available to us in anonymized form, which means that we can only analyze the general user behavior of visitors to our YouTube channel. However, this does not allow us to draw any conclusions about individual users.

Our legal basis for processing is Art. 6 (1) lit. f GDPR. Our legitimate interest lies in analyzing the reach and effectiveness of our YouTube activities in order to optimize our online offering.

2.4 Further information

For a detailed description of the respective processing, we refer to the data protection information from YouTube and Google linked below:

– Information about YouTube Analytics:
https://developers.google.com/youtube/analytics
and
https://support.google.com/youtube/topic/9257532?hl=en&ref_topic=9257610
– Terms of use:
https://www.youtube.com/static?gl=DE&template=terms&hl=de
-Privacy policy:
https://policies.google.com/privacy
and
https://kids.youtube.com/t/privacynotice
– Use of cookies:
https://policies.google.com/technologies/cookies?hl=de&gl=de
– Opt-out and customization options:
https://support.google.com/youtube/answer/9487666?hl=de
and
https://www.youtube.com/intl/de_be/howyoutubeworks/user-settings/ad-settings/
– Data protection assistance / privacy settings for YouTube:
https://support.google.com/youtube/answer/9315727?hl=de&ref_topic=9386940
and
https://support.google.com/policies/answer/9581826?p=privpol_privts&hl=de&visit_id=637217551183067910-377434558&rd=1

3. rights of those affected

We would like to draw your attention to your rights as a data subject within the meaning of Art. 13 et seq. GDPR. In particular, you have a right to information (Art. 15 GDPR), a right to rectification (Art. 16 GDPR), a right to erasure (Art. 17 GDPR), a right to restriction of processing (Art. 18 GDPR), a right to data portability (Art. 20 GDPR), and a right to object to processing (Art. 21 GDPR). We also ensure your rights under Art. 22 GDPR. You and your data within our area of responsibility are therefore not subject to decisions based solely on automated processing, including profiling. In addition, you have the right to lodge a complaint with a supervisory authority at any time (Art. 77 GDPR). Furthermore, you have the right to withdraw your consent with effect for the future (Art. 7 (3) GDPR).

4. data protection officer

If you would like information about the processing of your personal data in connection with YouTube or Google, or if you wish to assert your rights as a data subject in this context, we would like to point out that this is most effectively done by contacting Google directly. You can contact Google’s data protection officer at https://support.google.com/policies/contact/general_privacy_form.

If you wish to exercise your rights as a data subject vis-à-vis us, please contact our data protection officer at softway@brands-consulting.eu and describe your specific request in as much detail as possible. We will be happy to forward your request to Google, as Google has access to the relevant user data and can take measures in accordance with your user rights.

Further information on data protection can be found in the privacy policy on the SOFTWAY website.

As of: July 28, 2023

V. SOFTWAY Privacy Notice for Xing

This privacy notice applies in addition to our existing privacy policy, where you can find all specific information on how we generally process your personal data and during your visit to our website.

We use a Xing company profile provided by New Work SE (“New Work”) at https://www.xing.com/pages/softwayag and point out that your data may be processed outside the European Union (EU). The processing of personal data outside the EU carries inherent risks regarding the enforcement of data subject rights and the safeguarding of general data protection objectives.

1st controller
1.1 New Work

Responsible for processing your data, insofar as it is processed exclusively by New Work:

New Work SE
Dammtorstraße 30
20354 Hamburg
Germany
Phone: +49 40 419 131-0
Fax: +49 40 419 131-11
E-mail: info@xing.com

1.2 SOFTWAY

Responsible for processing your data, insofar as it is processed exclusively by SOFTWAY:

Softway AG
Industriestrasse 17
D-96114 Hirschaid
Phone: +49(0) 9543 8238-0
Fax: +49 (0) 9543 8238-23
E-mail: dsb@softway.de

1.3 Joint controllership

If your transmitted data is processed jointly by New Work and SOFTWAY, and both determine the purposes and means of processing, New Work and SOFTWAY are joint controllers according to Art. 26 GDPR. By operating our Xing company profile, we enable New Work to process your data, which is provided to us via analytics functions (e.g., click paths) in the form of statistics. Therefore-and in connection with the European Court of Justice ruling of June 5, 2018 (Ref.: C-210/16) on the existence of joint responsibility for operating a Facebook fan page and using Facebook’s analytics service-we analogously assume joint responsibility for our Xing company profile and the use of analytics features. However, New Work currently does not provide an agreement on joint responsibility under Art. 26 GDPR, in which the data protection obligations of each controller are defined and distinguished.

2. data processing with Xing
2.1 Operation of a Xing Company Profile

We use our Xing company profile to inform you about news regarding our offerings and to get in touch with you. For example, if you comment on our posts, we process the content of your comment and, if applicable, other data you provide or that is transmitted during your Xing activity. Depending on the privacy settings of your user profile, additional information from your user profile and Xing activities (e.g., posts) may be accessible to us.

Every time you access our Xing company profile, your personal data (e.g., IP address; browser data; operating system and device; pages visited; date and time of access, etc.) is processed by New Work and cookies are set. We have no influence over the data collected and its processing, nor are we fully aware of the scope of data collection, purposes of processing, retention periods, or deletion of the collected data. This enables New Work to create cross-device usage profiles for advertising, market research, and/or tailored website design. Such use may occur even if you do not have a Xing account or are not logged in. If you are logged into Xing, your data is directly linked to your existing Xing account and may be publicly shared with your contacts.

Our legal basis for processing is Art. 6(1)(f) GDPR. Our legitimate interest lies in public representation and communication with you.

2.2 Use of Xing Analytics Functions

The processing of personal data in the context of operating our Xing company profile takes place with analytics functions (e.g., click path) and also includes purposes such as market research and statistical data collection. These data may be used, for instance, to identify valuable business contacts or potential employees. To record your user behavior and to create and store usage profiles, cookies are generally stored on your device. For example, usage profiles can be created based on your behavior regarding certain comments and the interests derived from them. Furthermore, data can be stored in usage profiles independently of the devices you use (especially if you have a Xing account and are logged in to the platform). However, even if you do not have a Xing profile or are not logged in during your visit to our company profile, Xing can assign these data to a user profile. Cookies remain on your device until you delete them.

Data from Xing analytics functions is only available to us in anonymized form, so we can only analyze the general user behavior of visitors to our Xing company profile. Identification of individual users is not possible.

Our legal basis for processing is Art. 6(1)(f) GDPR. Our legitimate interest lies in analyzing the reach and effectiveness of our Xing activities to optimize our online offering.

2.3 Further information

For a detailed description of each processing activity, please refer to the following linked New Work privacy notices:

– Terms of Use:
https://www.xing.com/terms

– Privacy Policy:
https://privacy.xing.com/de/datenschutzerklaerung
and
https://privacy.xing.com/de/datenschutzerklaerung/druckversion

– Use of Cookies:
https://faq.xing.com/de/sicherheit/was-sind-cookies-und-warum-brauche-ich-sie-beim-einloggen

3. data subject rights

We draw your attention to your rights as a data subject under Art. 13 et seq. GDPR. In particular, you have the right to access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR), data portability (Art. 20 GDPR), and to object to processing (Art. 21 GDPR). We also ensure your rights under Art. 22 GDPR. Your data within our area of responsibility is not subject to decisions based solely on automated processing-including profiling. Furthermore, you have the right to lodge a complaint with a supervisory authority at any time (Art. 77 GDPR). You also have the right to withdraw consent with future effect (Art. 7(3) GDPR).

4. data protection officer

If you wish to obtain information about the processing of your personal data in connection with Xing or exercise your data subject rights, we point out that it is most effective to direct your request to New Work. You can contact New Work’s Data Protection Officer at Datenschutzbeauftragter@xing.com.

If you wish to exercise your rights towards us, please contact our Data Protection Officer at softway@brands-consulting.eu and describe your specific request as detailed as possible. We will gladly forward your request to New Work, as New Work has access to the relevant user data and can take actions according to your user rights.

Further privacy information can be found in the SOFTWAY website privacy policy.

As of: 26.08.2023

VI SOFTWAY Privacy Notice for LinkedIn

This privacy notice applies in addition to our existing privacy policy, where you can find all specific information on how we generally process your personal data and during your visit to our website.

We use a LinkedIn company profile provided by LinkedIn Ireland Unlimited Company (“LinkedIn”) at https://www.linkedin.com/company/softway/ and point out that your data may be processed outside the European Union (EU). The processing of personal data outside the EU carries inherent risks regarding the enforcement of data subject rights and the safeguarding of general data protection objectives.

1. joint controllers

LinkedIn Ireland Unlimited Company
Wilton Place,
Dublin 2, Ireland

and

Softway AG
Industriestrasse 17
D-96114 Hirschaid
Phone: +49(0) 9543 8238-0
Fax: +49 (0) 9543 8238-23
E-mail: dsb@softway.de

For the processing of Page Insights data, LinkedIn assumes responsibility for fulfilling GDPR obligations. This includes (1) necessary information duties, (2) data subject rights enforceable against LinkedIn, (3) notification duties in case of data breaches, and (4) ensuring appropriate technical and organizational measures for secure processing.

You may, of course, also assert your right of access or other rights with us. In such cases, we will gladly forward your request to LinkedIn, as LinkedIn has access to the relevant user data and can take actions according to your user rights.

2. data processing with LinkedIn
2.1 Operation of a LinkedIn Company Profile

We use our LinkedIn company profile to inform you about news regarding our offerings and to get in touch with you. For example, if you comment on our posts, we process the content of your comment and, if applicable, other data you provide or that is transmitted during your LinkedIn activity. Depending on the privacy settings of your user profile, additional information from your user profile and LinkedIn activities (e.g., posts) may be accessible to us.

Every time you access our LinkedIn company profile, your personal data (e.g., IP address; browser data; operating system and device; pages visited; date and time of access, etc.) is processed by LinkedIn and cookies are set. We have no influence over the data collected and its processing, nor are we fully aware of the scope of data collection, purposes of processing, retention periods, or deletion of the collected data. This enables LinkedIn to create cross-device usage profiles for advertising, market research, and/or tailored website design. Such use may occur even if you do not have a LinkedIn account or are not logged in. If you are logged into LinkedIn, your data is directly linked to your existing LinkedIn profile and may be publicly shared with your contacts.

Our legal basis for processing is Art. 6(1)(f) GDPR. Our legitimate interest lies in public representation and communication with you.

2.2 Use of Page Insights

The processing of personal data in connection with operating our LinkedIn company profile takes place using the Page Insights analytics service and also includes purposes such as market research, advertising, and statistical data collection. These data may be used, for instance, to identify valuable business contacts or potential employees. To record your user behavior and to create and store usage profiles, cookies are generally stored on your device. For example, usage profiles can be created based on your behavior regarding certain posts and the interests derived from them. Furthermore, data can be stored in usage profiles independently of the devices you use (especially if you are a LinkedIn member and logged in to the platform). However, even if you do not have a LinkedIn profile or are not logged in during your visit to our company profile, LinkedIn can assign these data to a user profile. Cookies remain on your device until you delete them.

Data from Page Insights is only available to us in anonymized form, so we can only analyze the general user behavior of visitors to our LinkedIn company profile. Identification of individual users is not possible.

Our legal basis for processing is Art. 6(1)(f) GDPR. Our legitimate interest lies in analyzing the reach and effectiveness of our LinkedIn activities to optimize our online offering.

2.3 Further information

For a detailed description of each processing activity, please refer to the following linked LinkedIn privacy notices:

– Joint Controller Addendum with LinkedIn:
https://legal.linkedin.com/pages-joint-controller-addendum

– Terms of Use:
https://legal.linkedin.com/linkedin-pages-terms

– Privacy Policy:
https://de.linkedin.com/legal/privacy-policy?

– Cookie Policy:
https://www.linkedin.com/legal/cookie-policy

– Opt-out options:
https://www.linkedin.com/psettings/guest-controls

– Safety Center:
https://safety.linkedin.com/

– Help Center “Data and Privacy”:
https://www.linkedin.com/help/linkedin/topic/104742?trk=hc-hp-recommendedTopics

3. data subject rights

We draw your attention to your rights as a data subject under Art. 13 et seq. GDPR. In particular, you have the right to access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR), data portability (Art. 20 GDPR), and to object to processing (Art. 21 GDPR). We also ensure your rights under Art. 22 GDPR. Your data within our area of responsibility is not subject to decisions based solely on automated processing-including profiling. Furthermore, you have the right to lodge a complaint with a supervisory authority at any time (Art. 77 GDPR). You also have the right to withdraw consent with future effect (Art. 7(3) GDPR).

4. data protection officer

If you wish to obtain information about the processing of your personal data in connection with LinkedIn or exercise your data subject rights, we point out that it is most effective to direct your request to LinkedIn. You can contact LinkedIn’s Data Protection Officer via https://www.linkedin.com/help/linkedin/ask/TSO-DPO.

If you wish to exercise your rights towards us, please contact our Data Protection Officer at softway@brands-consulting.eu and describe your specific request as detailed as possible. We will gladly forward your request to LinkedIn, as LinkedIn has access to the relevant user data and can take actions according to your user rights.

Further privacy information can be found in the SOFTWAY website privacy policy.

As of: 26.08.2023

VII SOFTWAY Privacy Notice for Google reCAPTCHA

This privacy notice applies in addition to our existing privacy policy, where you can find all specific information on how we generally process your personal data and during your visit to our website.

SOFTWAY aims to protect you and its own homepage. To achieve this, SOFTWAY uses reCAPTCHA from Google Inc.

With reCAPTCHA, SOFTWAY can determine whether our homepage is actually being used by humans and not by robots or malware. Google reCAPTCHA is a captcha service designed to protect websites from spam software and abuse by non-human visitors. When using reCAPTCHA, data is transmitted to Google to determine whether the user is truly a human.

reCAPTCHA collects personal data from users to verify that usage is genuinely by humans.

Within the European region, Google Ireland Limited, located at Gordon House, Barrow Street Dublin 4, Ireland, is responsible for Google services.

The IP address and other data required by Google for the use of the reCAPTCHA service are sent to Google. It is standard practice for IP addresses within the EU or other contracting states of the European Economic Area Agreement to be shortened before these data are forwarded to servers in the USA.

The IP address is not combined with other Google data unless you are logged in with an existing Google account while using reCAPTCHA.

reCAPTCHA first checks whether Google cookies from other Google services are present. Then reCAPTCHA sets an additional cookie in the browser and takes an inventory of the respective browser window.

Below are examples of data that, according to current knowledge, are processed by Google. Please note that this list is not exhaustive:

 

– IP address

– Cookies

– Information about the operating system

– Mouse and keyboard usage

– Date

– Language settings

– Screen resolution

– All Javascript objects

 

The following cookies are used by reCAPTCHA:

Name Purpose Deletion Value
ANID Advertising 270 days U7j1v3dZa3316859514920xgZFmiqWppRWKOr
1P_JAR Collects statistics on website usage and measures conversions. Also used to display relevant ads and prevent repeated display of the same ad. 30 days

 

2019-5-14-12
CONSENT Stores the user’s consent status for different Google services. Also used for security to check users, prevent credential fraud, and protect user data from unauthorized attacks. Not clearly defined YES+AT.de+20150628-20-0
DP Used by Google Analytics for personalized advertising. Collects information anonymously and distinguishes users. 10 minutes gEAABBCjJMXcI0dSAAAANbqc331685951492-4
NID Used to customize ads.  

80 days

0WmuWqy331685951492zILzqV_nmt3sDXwPeM5Q
IDE Recognizes and forwards user actions on the homepage in connection with advertising. Stored under the domain doubleclick.net by DoubleClick. 12 months WqTUmlnmv_qXyi_DGNPLESKnRNrpgXoy1K-pAZtAkMbHI-331685951492-8

 

This list is based on the Google reCAPTCHA demo version at [https://www.google.com/recaptcha/api2/demo](https://www.google.com/recaptcha/api2/demo).

The listed cookies require a unique identifier for tracking purposes.

This list does not claim to be exhaustive.

If you do not want data to be transmitted to Google, you must log out completely from Google and delete all Google cookies before visiting our website or using the reCAPTCHA software.

Data is automatically transmitted to Google as soon as our site is accessed. To delete this data, you must contact Google support at https://support.google.com/?hl=de&tid=331685951492.

By using our website, you consent to Google LLC and its representatives automatically collecting, processing, and using data.

When using this tool, data may also be stored and processed outside the EU. Most third countries are considered unsafe under current European data protection law. Data may not be transferred, stored, or processed in unsafe third countries unless suitable guarantees (such as EU standard contractual clauses) exist.

If consent has been given for the use of Google reCAPTCHA, the legal basis for the corresponding data processing is this consent. According to Art. 6(1)(a) GDPR (consent), this consent serves as the legal basis for processing personal data as may occur when Google reCAPTCHA collects data.

SOFTWAY also has a legitimate interest in using Google reCAPTCHA to improve and secure our online service. The legal basis is Art. 6(1)(f) GDPR.

Google processes your data, among other places, in the USA.

The information generated by the cookies may be transferred to and stored on a server in the USA. The USA is considered a third country from a data protection perspective, but the EU Commission has issued an adequacy decision, as explained above. This means the USA is certified as having a level of data protection comparable to that of the EU/EEA.

Further information about reCAPTCHA can be found at https://developers.google.com/recaptcha/ and https://www.google.com/intl/de/policies/privacy/.

VIII SOFTWAY Privacy Notice for HubSpot

On this website, we use the HubSpot service for various purposes, a software company from the USA with a branch in Ireland. HubSpot contact details:

– HubSpot (European Headquarters), 2nd Floor 30 North Wall Quay, Dublin 1, Ireland, Phone: +353 1 5187500

– HubSpot, Inc, 25 First Street, 2nd Floor Cambridge, MA 02141 USA, Phone: +1 888 482 7768

On our website https://www.softway.de/ and our landing pages under the subdomain https://formulare.softway.de/, we use tracking tools from HubSpot, Inc., 25 First Street, 2nd Floor, Cambridge, MA 02141 USA. We use HubSpot to analyze website usage, compile reports on activities within this web offering, and provide related services, as well as to improve user-friendliness. Primarily, HubSpot is used to record and analyze website visitors’ actions (e.g., click behavior) via cookies.

The legal basis for processing the described data, insofar as they are personal, is your consent, Art. 6(1)(a) GDPR.

You may withdraw your consent at any time with future effect under Art. 7(3) GDPR by adjusting the settings in our cookie consent tool or by deleting and blocking cookies in your browser. If you have difficulties implementing this, please feel free to contact us or our appointed data protection officer.

If you enter data into a HubSpot form on our website https://www.softway.de/ or under the subdomain https://formulare.softway.de/ and

  1. consent to the creation of a customer account or
  2. consent to receiving advertising,

this results in the use of HubSpot and data being transmitted to our service provider HubSpot in the USA. The branch of HubSpot Inc. responsible for Europe is the one listed above and located in Ireland. An adequate level of protection is ensured by the conclusion of an EU standard contract plus a Data Processing Agreement (DPA) with the service provider. Further information on HubSpot Inc.’s privacy policy can be found here: https://legal.hubspot.com/de/privacy-policy.

SOFTWAY Privacy Notice for the Use of the Microsoft Teams Video Conferencing System

We would like to inform you about how we process your personal data when using the video conferencing tool “Microsoft Teams” (hereinafter referred to as “Teams”). The application offers various features, including chats, audio and video calls, file sharing, and collaborative document editing.

“Teams” is generally part of Microsoft Office 365, now known as Microsoft 365, but can also be used via the web-based version in your browser. Some features may not be available in the browser version. If you participate as an external attendee in an online meeting, the host will send you a link via email to log in. You will then need to provide your name or a pseudonym and, if necessary, your email address to register for the online meeting.

Please ensure that any personal data you do not wish to exchange via “Teams” is redacted or otherwise made unrecognizable beforehand. This is particularly important if you share your screen or provide data or documents via the service.

Further information on the processing of your data when using “Teams” can be found at:

https://privacy.microsoft.com/de-de/privacystatement

https://news.microsoft.com/de-de/datenschutz-und-sicherheit-in-microsoft-teams-nutzer

1st controller

The controller for the processing of personal data directly related to the conduct of Teams video conferences is:

Softway AG
Industriestrasse 17
D-96114 Hirschaid | Germany
Phone: +49 9543 8238-0 | Fax: +49 9543 8238-23
www.softway.de | Email: dsb@softway.de

Please note that the provider “Microsoft Corporation – One Microsoft Way, Redmond, WA 98052 – 6399, USA” (hereinafter: “Microsoft”) is responsible for data processing on its website. “Teams” can be used in the following ways:

– Installation and use of the desktop application

– Use via your web browser (requires login to your own Microsoft account)

– Mobile app

– As a component of other Microsoft products (e.g., Outlook, SharePoint)

2. purpose of processing

We use the “Teams” tool to conduct teleconferences, online meetings, video conferences, and/or webinars (“online meetings”) with customers, business partners, and employees.

3. what data is processed?

Microsoft Teams is a cloud-based service. Various types of personal data are processed in the provision of the service.

The following personal data is processed:

– Content of your meetings, chats, voicemails, shared files, recordings, and transcriptions

– Profile data shared within your company, such as your email address, profile picture (optional), and phone number

– A detailed history of your phone calls, enabling you to search your own call records later

– Call quality data: System administrators have access to call details and data to diagnose issues related to poor call quality and service usage

– Support/feedback data: Information related to troubleshooting tickets or feedback sent to Microsoft

– Diagnostic data regarding service usage: These personal data enable Microsoft to provide the service (troubleshoot, secure and update the product, monitor performance) and perform a range of internal business operations (e.g., revenue determination, metric development, usage analysis, product and capacity planning)

4. scope of data processing

We will inform you in advance and request your consent if we wish to record an “online meeting.” If necessary, we will log chat content to document session results; this is generally not required.

Occasionally, questions from participants asked during a webinar are logged for later review.

“Teams” stores personal data as long as necessary to provide the service. All copies of data are deleted within 30 days if the user stops using “Teams” or deletes their personal data. Personal data is deleted 90 to 180 days after discontinuing the use of “Teams.” Retention of call recordings for billing purposes may be required for a certain period due to regional or national laws. If we request Microsoft to retain user data to comply with a legal obligation, Microsoft will comply and adhere to the laws of the respective country.

We do not make decisions without human involvement; automated decision-making within the meaning of Art. 22 GDPR does not take place.

5 Legal Basis for Data Processing

The legal basis for data processing is § 26 German Federal Data Protection Act (BDSG) if and to the extent that personal data of Softway AG employees are processed. If personal data in connection with the use of “Teams” is not required for the initiation, execution, or termination of the employment relationship but is essential for the use of Teams, Art. 6(1)(f) GDPR is the legal basis. Our legitimate interest lies in ensuring the effective conduct of “online meetings.”

If “online meetings” are conducted within the scope of contractual relationships, Art. 6(1)(b) GDPR is the legal basis for data processing. If there is no contractual relationship, Art. 6(1)(f) GDPR is the legal basis, with our interest also being the effective conduct of “online meetings” or “webinars.”

6 Recipients / Categories of Recipients of Personal Data

To enable efficient communication and collaboration, participation in “online meetings” requires the processing of personal data. We respect our users’ right to privacy and will not disclose personal data to third parties unless required by law or explicitly consented to by the user. Please note, however, that “online meetings” are often a means of exchanging information with customers, prospects, or third parties. In such cases, limited disclosure of personal data may be necessary for effective collaboration.

We obtain the video conferencing tool “Teams” from “Microsoft,” which necessarily becomes aware of the data mentioned above. We have concluded a data processing agreement (DPA) with Microsoft. Therefore, Microsoft is not considered a “third party.” We remain responsible for the protection of your data.

Where “Teams” processes personal data in connection with Microsoft’s legitimate business activities, Microsoft is an independent data controller and is responsible for compliance with all applicable laws and controller obligations.

7 Data Processing Outside EEA Countries

Microsoft provides its service from the USA. However, the company offers customers the option to store their data in the region where they are located. We have specified the desired storage location within the EU when setting up our Teams account. Therefore, data processing generally does not occur outside the European Union (EU). Please note that the availability of certain “Teams” features and services may depend on the region. Some features may not be available in all regions.

Please note that Microsoft has implemented strict privacy and security measures to ensure the confidentiality and security of customer data, regardless of where the data is stored.

Microsoft states that various types of data traffic are encrypted to ensure the security and confidentiality of data when using “Teams.” Server-to-server and client-to-server traffic, such as chat, is encrypted with TLS. Media streams, such as audio and video sharing, are also encrypted with TLS. Enhanced client-to-client encryption, such as end-to-end encrypted calls, uses SRTP/DTLS.

Despite all settings and configurations, we cannot rule out the possibility that data may be transmitted to internet servers outside the EU. On July 10, 2023, the European Commission adopted an adequacy decision for the EU-U.S. Data Privacy Framework (DPF) pursuant to Art. 45(3) GDPR. Since then, the adequacy decision can be used for the transfer of personal data to certain organizations in the USA. The data recipient must be a member of the DPF. Microsoft Corporation is a member. You can verify this yourself at https://www.dataprivacyframework.gov/list.

8. data protection officer

We have appointed a data protection officer:

Brands Consulting | Data Protection & Consulting
Owner: Bernhard Brands
Auf dem Hahn 11
D-56412 Niedererbach

You are currently viewing a placeholder content from Standard. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.

More Information

Email: softway@rlp.brands-consulting.eu

9 Your Rights as a Data Subject

If you wish to exercise your rights as a data subject, please let us know. In connection with data processing, you are generally entitled to the following rights under Art. 12 et seq. GDPR:

Right to access, rectification, objection, erasure, blocking (restriction of processing), and the right to data portability. In addition, we guarantee your rights under Art. 22 GDPR. Your data must not be subject to decisions based solely on automated processing – including profiling.

You have the right to lodge a complaint with a supervisory authority if you believe that your personal data is not being processed lawfully (our competent supervisory authority is: Der Bayerische Landesbeauftragte für den Datenschutz (BayLfD); Wagmüllerstraße 18, 80538 Munich; Email: poststelle@datenschutz-bayern.de).

10. data deletion

Personal data for which further storage is not necessary will generally be deleted. Necessity may exist, in particular, if the data is still required to fulfill contractual obligations, to verify, grant, or defend warranty and, if applicable, guarantee claims and other civil law claims. Where statutory retention obligations exist, your data will be deleted when the respective retention period expires (usually 6 to 10 years according to HGB and AO).

11 Changes to this Privacy Notice

These privacy provisions are subject to change if data processing operations or other developments (e.g., case law) occur. The current version can be found on this website.

Status: January 2024

SOFTWAY Privacy Notice for the Use of the Zoom Video Conferencing System

We would like to inform you about how we process your personal data when using the video conferencing tool “Zoom.” The application offers various features, including chats, audio and video calls, file sharing, and collaborative document editing.

1st controller

The controller for the processing of personal data directly related to the conduct of Zoom video conferences is:

Softway AG
Industriestrasse 17
D-96114 Hirschaid | Germany

Phone: +49 9543 8238-0 | Fax: +49 9543 8238-23
https://www.softway.de | Email: dsb@softway.de

Please note that the provider “Zoom Video Communication, Inc.” based in the USA is responsible for data processing on its website. To use Zoom, you only need to download the software, which may require visiting the Zoom website. With the meeting ID and, if applicable, other access data, you can also use the Zoom app directly. If you do not wish to use the app, you can use Zoom’s basic functions in your browser.

2. purpose of processing

We use “Zoom” to conduct teleconferences, online meetings, video conferences, and/or webinars (“online meetings”) with customers, business partners, and employees.

3. what data is processed?

When you use “Zoom,” various types of data are processed. The type and scope of the data also depend on the information you provide before or during your participation in an online conference.

The following personal data is processed:

– User information:

First name, last name, phone (optional), email address, password (if applicable), profile picture (optional), department (optional)

– Session metadata:

Information collected during a Zoom meeting, e.g., host, meeting ID, meeting title, hash code of the meeting password, meeting settings, actual start time, actual end time, scheduled time, scheduled duration, settings for recurring meetings (type and duration), host’s time zone, actual meeting duration, participant count, participant list, participant email addresses (if registered), dial-in numbers, participant IP addresses, chat data, names of participants, content of chat messages sent during the meeting, device/hardware information

– Recordings (optional):

MP4 file containing all video, audio, and presentation recordings, as well as M4A file containing audio recordings only. The online meeting chat is saved as a text file.

– If you dial in by phone:

Information such as incoming and outgoing phone numbers, country name, and start/end time of the connection is stored. Additional connection data, such as the device’s IP address, may also be stored.

– Text, audio, and video data:

During an online meeting, text, audio, and video data may be processed. This enables functions such as chat, questions, or polls to be displayed and, if necessary, recorded. Displaying video and playing audio during the meeting is enabled by processing the data from your device’s microphone and camera. You can turn off or mute your camera and microphone at any time via the Zoom application. You must provide at least your name to participate in an “online meeting” or enter the “meeting room.”

4. scope of data processing

For our “online meetings” or “webinars,” we use the “Zoom” application. We will inform you in advance and request your consent if we wish to record a “Zoom session.” We will also notify you within the Zoom application if a session is being recorded. If necessary, we will log chat content to document session results; this is generally not required.

Occasionally, questions from participants asked during a session or webinar are logged for later review.

Zoom stores personal data for as long as necessary for the purposes described in this privacy statement, unless longer retention periods are required by applicable laws.

Criteria for determining retention periods include:

– The duration during which Zoom is in business with you and providing products and services (e.g., as long as you have a Zoom account or use Zoom products)

– Changes or deletion of information by account holders or users via their accounts

– Whether retention is legally required (e.g., certain laws require Zoom to retain records of your transactions for a specific period before deleting them)

– If retention is advisable in light of Zoom’s legal position (e.g., for contract fulfillment, dispute resolution, applicable statutes of limitations, court proceedings, or regulatory investigations)

We do not make decisions without human involvement; automated decision-making within the meaning of Art. 22 GDPR does not take place.

5 Legal Basis for Data Processing

The legal basis for data processing is § 26 German Federal Data Protection Act (BDSG) if and to the extent that personal data of Softway AG employees are processed. If personal data in connection with the use of “Zoom” is not required for the initiation, execution, or termination of the employment relationship but is essential for the use of Zoom, Art. 6(1)(f) GDPR is the legal basis. Our legitimate interest lies in ensuring the effective conduct of “online meetings” or “webinars.”

If “online meetings” or “webinars” are conducted within the scope of contractual relationships, Art. 6(1)(b) GDPR is the legal basis for data processing. If there is no contractual relationship, Art. 6(1)(f) GDPR is the legal basis, with our interest also being the effective conduct of “online meetings” or “webinars.”

6 Recipients / Categories of Recipients / Data Disclosure

To enable efficient communication and collaboration, participation in “online meetings” requires the processing of personal data. We respect our users’ right to privacy and will not disclose personal data to third parties unless required by law or explicitly consented to by the user. Please note, however, that “online meetings” are often a means of exchanging information with customers, prospects, or other third parties. In such cases, limited disclosure of personal data may be necessary for effective collaboration.

We obtain the video conferencing tool “Zoom” from “Zoom,” which necessarily becomes aware of the data mentioned above. We have concluded a data processing agreement (DPA) with Zoom and have chosen the EEA (European Economic Area) as the physical server location. Therefore, Zoom is not considered a “third party.” We remain responsible for the protection of your data.

Where “Zoom” processes personal data in connection with Zoom’s legitimate business activities, Zoom is an independent data controller and is responsible for compliance with all applicable laws and controller obligations.

We have integrated Zoom usage into the “HubSpot” tool. Therefore, we cannot rule out that data processed via Zoom may also be transferred to the “HubSpot” service. Further information on data processing via HubSpot can be found in the relevant section of the privacy policy. You can conveniently click [here](#) for more information.

7 Data Processing Outside EEA Countries

The video conferencing system provider “Zoom” provides its service from the USA. It cannot be ruled out that personal data may also be processed in the USA as a third country within the meaning of the GDPR. Our processor “Connect4Video” has concluded a sub-processing agreement with Zoom. Additionally, Zoom has been configured so that only data centers within the EEA are used for conducting “online meetings.”

Despite all settings and configurations, we cannot rule out the possibility that data may be transmitted to internet servers outside the EEA. On July 10, 2023, the European Commission adopted an adequacy decision for the EU-U.S. Data Privacy Framework (DPF) pursuant to Art. 45(3) GDPR. Since then, the adequacy decision can be used for the transfer of personal data to certain organizations in the USA. The data recipient must be a member of the DPF. Zoom is a member. You can verify this yourself at https://www.dataprivacyframework.gov/list.

8. data protection officer

We have appointed a data protection officer:

Brands Consulting | Data Protection & Consulting
Owner: Bernhard Brands
Auf dem Hahn 11
D-56412 Niedererbach

You are currently viewing a placeholder content from Standard. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.

More Information

Email: softway@rlp.brands-consulting.eu

9 Your Rights as a Data Subject

If you wish to exercise your rights as a data subject, please let us know. In connection with data processing, you are generally entitled to the following rights under Art. 12 et seq. GDPR:

Right to access, rectification, objection, erasure, blocking (restriction of processing), and the right to data portability. In addition, we guarantee your rights under Art. 22 GDPR. Your data must not be subject to decisions based solely on automated processing – including profiling.

You have the right to lodge a complaint with a supervisory authority if you believe that your personal data is not being processed lawfully (our competent supervisory authority is: Der Bayerische Landesbeauftragte für den Datenschutz (BayLfD); Wagmüllerstraße 18, 80538 Munich; Email: poststelle@datenschutz-bayern.de).

10. data deletion

Personal data for which further storage is not necessary will generally be deleted. Necessity may exist, in particular, if the data is still required to fulfill contractual obligations, to verify, grant, or defend warranty and, if applicable, guarantee claims and other civil law claims. Where statutory retention obligations exist, your data will be deleted when the respective retention period expires (usually 6 to 10 years according to HGB and AO).

11 Changes to this Privacy Notice

This privacy notice is subject to changes in data processing or other changes (e.g., case law). The current version can always be found here.

Status: January 2024

Privacy Policy for Applications to SOFTWAY

This privacy policy for applicants informs you about how Softway processes your personal data when you apply for a position advertised by us. It also informs you about your data protection rights, including the right to object to part of the processing carried out by Softway. For further information about your rights and how to exercise them, please see the section “Your Rights.”

This privacy policy applies in addition to our existing privacy policy, which provides all specific information about how we generally process your personal data and in the context of website visits or non-application-specific topics.

1st controller

The controller for the processing of personal data within the meaning of Art. 4(7) General Data Protection Regulation (GDPR) is:

Softway AG
Industriestrasse 17
D-96114 Hirschaid
Phone: +49(0) 9543 8238-0
Fax: +49 (0) 9543 8238-23
Email: dsb@softway.de

2. data collection

During the selection process, we collect and process the following categories of personal data:

– Contact data in your application profile (e.g., first and last name, country, email, phone number)

– Information from the application form (e.g., desired salary, your motivation, any information on disability – only if relevant to the advertised position)

– Application documents (e.g., CV, cover letter, data on professional development, qualifications, and language skills)

– Results from test procedures (e.g., personality tests, cognitive performance tests)

– References you provide to us

It is possible that we may also obtain the above data about you from other sources, including external business partners such as personnel service companies. We may also use data you have made public in professional social networks or that you have submitted to us via other websites or obtained from other publicly accessible sources (only if the data is relevant to your professional life). The reason for this is to verify the accuracy of the information you have provided in your application documents.

3 Nature and Purpose of Processing Personal Data

Your personal data will be processed exclusively for the following purposes:

– Initiation and establishment of the employment relationship

– To contact you if you are considered for an alternative position

– To contact you based on your unsolicited application

4. legal bases

We collect and process your personal data to offer advertised positions and to conduct the selection process. For certain positions, this includes your participation in a cognitive performance test or personality test.

The legal basis for the cognitive performance test is § 26(1) in conjunction with § 26(8) sentence 2 BDSG and § 22(1)(b) BDSG. Providing your personal data as part of the application process is voluntary. However, providing personal data is necessary for processing your application or concluding an employment contract with us. The legal basis for the personality test is your consent under § 26(2) BDSG. Participation in the personality test is voluntary.

If we obtain information from your public profile on professional social networks, we rely on our legitimate interest in forming a basis for deciding to establish an employment relationship with you. The legal basis is Art. 6(1)(f) GDPR in conjunction with Art. 9(2)(e) GDPR.

Furthermore, we may process personal data about you to the extent necessary to defend against legal claims asserted against us from the application process. The legal basis is Art. 6(1)(b) and (f) GDPR. The legitimate interest is, for example, the burden of proof in proceedings under the General Equal Treatment Act (AGG).

5. data recipients

We may transfer your personal data to affiliated companies to the extent permitted within the scope of the purposes and legal bases stated above. For data processing in our online application tool, Softway jointly determines the purposes and means of data processing. You can request the deletion of your profile, as described in the “Retention Period” section.

Otherwise, personal data may be processed on our behalf based on contracts under Art. 28 GDPR, particularly by providers of applicant management and selection systems. Personal data will not be transferred to third parties unless it relates to applicant management and selection or the purposes described in the section “Nature and Purpose of Processing Personal Data.”

Transfers may involve the transfer of personal data to recipients outside the European Union / European Economic Area. With these external service providers, standard contractual clauses have been concluded unless they are located in countries with an adequacy decision under Art. 45 GDPR.

Other recipients are listed in the section on general recipients.

In the event of a legal obligation, we reserve the right to disclose information about you if disclosure is required by law enforcement authorities or agencies acting lawfully. The legal basis is Art. 6(c) GDPR.

6. your rights
6.1. Right of Access

You have the right to access the personal data stored about you in our company. Please contact the controller named above or our data protection officer.

6.2. Right to Rectification or Erasure

You can correct your personal data by sending an email to bewerbung@softway.de. You may also request the erasure of your data under certain conditions.

6.3. Right to Restriction of Processing

Under certain conditions, you can request the restriction of the processing of your data, e.g., if the accuracy of your data is disputed and needs to be verified by us. You can adjust the visibility of your application profile at any time and disable your SMS notification settings.

6.4. Right to Data Portability

Under certain conditions, your data will be provided in a structured, commonly used, and machine-readable format.

6.5. Right to Object to Processing

You can object to the processing of your data based on our legitimate interests. You also have the right to lodge a complaint with a supervisory authority at any time.

7. retention period

We store your personal data for 6 months after a final rejection of your application. This is required for the burden of proof in proceedings under the General Equal Treatment Act (AGG). You can request the deletion or withdrawal of your application by contacting us at bewerbung@softway.de.

If your application is successful, we store your personal data for the entire duration of your employment in accordance with the privacy policy for employees, which we will provide to you upon acceptance of employment.

8 Objection or Withdrawal of Your Consent to Data Processing

If you have given consent to the processing of your data, you may withdraw it at any time. The withdrawal only affects the lawfulness of the processing of your personal data after receipt.

If we base the processing of your personal data on a balancing of interests, you may object to the processing. This is the case if the processing is not required to fulfill a contract with you. When exercising such an objection, please explain the reasons why we should not process your personal data as we have been doing. If your objection is justified, we will review the situation and either stop or adjust the data processing, or demonstrate our compelling legitimate grounds for continuing the processing.

General Terms and Conditions for the Use of SaaS Offerings

1. definitions

SOFTWAY: Softway AG, Industriestraße 17, 96114 Hirschaid, Germany. Registered in the commercial register: Amtsgericht Bamberg HRB 4351 and its affiliated companies according to § 15 AktG.

SOFTWARE: The SaaS solutions provided to the CUSTOMER by SOFTWAY based on contracts. This refers exclusively to SOFTWARE provided by SOFTWAY as a Software as a Service (SaaS) solution. With SaaS software, the CUSTOMER accesses the SOFTWARE via a web browser, an interface designed for use, and the Internet. Hosting and general management of the SOFTWARE and associated systems are carried out by SOFTWAY.

CUSTOMER: The contractual partner of SOFTWAY regarding the acquisition or use of the SOFTWARE.

PARTIES: SOFTWAY and the CUSTOMER jointly.

UPDATES: Updates are adjustments to the SOFTWARE to ensure the service remains contractually compliant. These may include security updates, bug fixes, or UX element adjustments.

UPGRADES: Upgrades are changes to the SOFTWARE that go beyond maintaining the contractually owed scope of services. Upgrades include new features, expansion of existing features, and provision of further interaction possibilities with the existing SOFTWARE.

SLA: A Service Level Agreement (SLA) is a formal part of the contract between SOFTWAY and the CUSTOMER describing the services to be provided by SOFTWAY, the expected scope of service, and the metrics used to measure this performance. The SLA may differ depending on the SOFTWARE.

2. general

2.1. These General Terms and Conditions (GTC) apply to all contracts concluded between SOFTWAY and the CUSTOMER concerning the use of SaaS SOFTWARE. Different contractual conditions apply to contracts not related to SaaS products.

2.2. SOFTWAY’s offering is exclusively for entrepreneurs within the meaning of § 14 BGB (natural or legal persons or a legally capable partnership acting in the exercise of their commercial or independent professional activity when concluding a legal transaction).

2.3. SOFTWAY grants the CUSTOMER the use of the current version of the licensed SOFTWARE for the agreed number of authorized users via the Internet, e.g., access via a browser or via an API, according to the provisions for using the SOFTWARE in Section 4.

2.4. SOFTWAY does not owe adaptation to the individual needs or IT environment of the CUSTOMER unless specifically agreed. This applies particularly to adaptations necessary to support versions not marked as supported by SOFTWAY.

2.5. Any SOFTWARE does not replace legal or tax advice for the CUSTOMER and serves only to provide technical support. The (tax-)legal assessment of the use of the SOFTWARE is the responsibility of the CUSTOMER.

2.6. An increase in the scope of services is possible at any time. The CUSTOMER may request an increase in writing from SOFTWAY at any time. SOFTWAY will review the resulting costs and submit an additional offer, which the CUSTOMER can accept in writing.

3 Order of Contracts / Scope of Services

3.1. These GTC take precedence over other agreements regarding the SOFTWARE or the CUSTOMER’s GTC. In case of a conflict between properly included GTC and other conditions, the following order applies:

3.1.1. Specific order;

3.1.2. Data Processing Agreement (if available);

3.1.3. Description of services and special conditions of the SOFTWARE;

3.1.4. Existing SLA for the product, if any;

3.1.5. These General Terms and Conditions;

3.2. The specific scope of usable SOFTWARE functions depends on the booked service packages and modules. The owed scope of services results from the description of the individual booked packages and/or modules.

3.3. Whether and to what extent SOFTWAY provides maintenance and support services depends on further agreements with SOFTWAY, e.g., the SLA or specific license or usage conditions of the respective SOFTWARE.

4. customer’s rights of use

4.1. SOFTWAY grants the CUSTOMER a non-exclusive, non-transferable, and non-sublicensable right to use the SaaS SOLUTION during the contract term, limited to the contractually agreed scope. The scope of the CUSTOMER’s right of use is determined by the concluded contract and the criteria specified therein and is at least sufficient to achieve the contractually agreed purpose.

4.2. Under no circumstances is the CUSTOMER entitled to rent the acquired contractual software or otherwise make it available to third parties (e.g., by sublicensing), to publicly reproduce it via wired or wireless means, or to provide it to third parties for use, whether for payment or free of charge, e.g., via Application Service Providing or as “Software as a Service”.

4.3. Suggestions by the CUSTOMER for installation, further development, or expansion of the SOFTWARE do not affect the fee and do not establish co-authorship, even if they are incorporated into the SOFTWARE.

4.4. SOFTWAY is entitled to indicate the copyright within the SOFTWARE and to affix corresponding notices. These notices may not be removed or obscured by other technical measures without the consent of SOFTWAY or the respective provider.

4.5. The user interface of the respective SOFTWARE may not be altered by the CUSTOMER or a third party commissioned by the CUSTOMER beyond the configuration provided in the system. The CUSTOMER is not granted any editing rights beyond the system settings. Any copyright imitation, even of parts of the SOFTWARE, is prohibited.

4.6. The transfer of granted rights of use to third parties and/or multiple use, unless contractually regulated otherwise, is subject to a fee and requires the consent of SOFTWAY, provided no exhaustion has occurred. In all other cases, SOFTWAY is entitled to request information from the CUSTOMER about the scope of use by the third party.

4.7 The CUSTOMER grants SOFTWAY, free of charge, the non-exclusive, territorially unlimited, and temporally limited right for the duration of the respective contract to edit content provided or uploaded, such as company logos, files, etc., for contract fulfillment. This applies especially to the technical processing of files made available within the respective SOFTWARE and all other rights required for operating the SOFTWARE.

4.8. By uploading or transmitting data to SOFTWAY, the CUSTOMER confirms that they have sufficient rights to all transmitted files to grant SOFTWAY the rights specified above and that no conflicting third-party rights are known. In particular, the CUSTOMER confirms possessing the necessary licenses, rights, permissions, and authorizations to use all trademarks, trade secrets, copyrights, and other proprietary rights in all transmitted files and to authorize SOFTWAY to use them. The CUSTOMER also confirms having written consent, release, or authorization from every identifiable person to ensure SOFTWAY’s acceptance and use of uploads in the manner described above. The CUSTOMER is liable to SOFTWAY for damages arising from breaches of their obligations under the above provisions (Section 4) and indemnifies SOFTWAY against all related third-party claims.

5 SOFTWAY’s Obligations

5.1. SOFTWAY provides the licensed SOFTWARE, the necessary access to the SOFTWARE, storage space on the provided servers, and support services to the CUSTOMER in the contractually owed scope.

5.2. SOFTWAY will perform the SOFTWARE services with the diligence customary for a software provider and, in particular, comply with applicable legal, regulatory, technical, and professional standards in the development and delivery of services.

5.3. SOFTWAY will remedy software errors – as far as technically possible – without delay. A software error exists if the SOFTWARE does not fulfill the functions specified in the product description, delivers incorrect results, or otherwise does not operate properly, so that the use of the SOFTWARE is impossible or restricted. Details on error correction can be found in Section 14 of these General Terms and Conditions.

5.4. If SOFTWAY independently owes a backup service, SOFTWAY will provide this according to the respective conditions of the service description. If the SOFTWARE is operated on the CUSTOMER’s system, the CUSTOMER is responsible for the backup. Regarding services provided by SOFTWAY on SAP’s BTP platform, backup is performed by SAP according to SAP’s conditions. SOFTWAY has no influence on this (https://help.sap.com/docs/btp/sap-business-technology-platform/backups?locale=en-US).

5.5. SOFTWAY provides the CUSTOMER with user documentation within the SOFTWARE. The user documentation is accessible at all times during use and can be downloaded in a common format.

5.6. The elimination of minor defects is at SOFTWAY’s discretion.

5.7. Any statutory claims of the CUSTOMER against SOFTWAY remain unaffected by the provisions of this Section.

6 Other Rights and Obligations of the CUSTOMER

6.1. The CUSTOMER is solely responsible for the functionality of their Internet access, including transmission paths and their own IT systems. This applies especially to the connection of the SOFTWARE via BTP. The CUSTOMER must also ensure that all relevant firewall configurations (e.g., whitelisting) are made.

6.2. The CUSTOMER receives their own BTP subaccount within SOFTWAY’s BTP Global Account. There, the CUSTOMER can create, delete, and assign roles to further users. Regarding the use of the BTP platform, SAP’s terms of use apply additionally.

6.3. For the SOFTWARE, the computing power required for server-side use and the storage space necessary for operation are provided to the CUSTOMER in the contractually agreed scope. The system area assigned to the CUSTOMER is protected from third-party access. Logical separation as part of a multi-tenant system is always ensured. Physical separation of the CUSTOMER’s system areas from other CUSTOMERS is not owed.

6.4. SOFTWAY may make the use of the respective SOFTWARE, individual functions, or the extent to which individual functions of the SOFTWARE can be used dependent on certain requirements, such as verification of access data, usage duration, account type, payment history, or submission of certain proofs (e.g., identity proof, payment proof).

6.5. If data, accesses, or information of the CUSTOMER are required within the SOFTWARE, the CUSTOMER shall provide SOFTWAY with all data, documents, and accesses reasonably necessary for execution. The CUSTOMER is obliged to provide these promptly, correctly, and completely via the formats and channels provided by SOFTWAY after the first request. Specific requirements result from the respective contract or description of the SOFTWARE. Furthermore, the CUSTOMER will perform all cooperation necessary for the fulfillment of the contract in a reasonable manner.

6.6. The CUSTOMER is obliged to take appropriate measures to protect the SOFTWARE from unauthorized third-party access.

6.7. The CUSTOMER is responsible for backing up the results achieved with the SOFTWARE, unless expressly agreed otherwise or owed by SOFTWAY. The CUSTOMER must also keep their own systems up to date. This applies in particular to security measures associated with the system.

6.8. Use of a user account by multiple natural persons (account sharing) is not permitted unless otherwise provided in the contracts or GTC of the respective service description.

6.9. After setting up a user account, SOFTWAY provides the CUSTOMER with access data for identification and authentication of individual users. Unless otherwise agreed, the CUSTOMER and their employees are not permitted to pass these access data to third parties.

6.10. The CUSTOMER is responsible for managing their user database within the BTP environment and obliging their USERS to comply with these GTC.

6.11. The CUSTOMER undertakes not to convert the SOFTWARE provided by SOFTWAY into another code form or make changes to the code of the respective SOFTWARE unless permitted by law.

6.12. If the CUSTOMER fails to meet the obligations set out in this article at all, not on time, not correctly, or not completely, and this demonstrably results in additional effort for SOFTWAY, SOFTWAY is entitled to charge the CUSTOMER for the resulting additional costs if the CUSTOMER is at fault. In such cases, SOFTWAY is also entitled to suspend services requiring CUSTOMER cooperation.

7. provision of UPGRADES and UPDATES, Maintenance Work, and Availability

7.1. The SOFTWARE is adjusted by SOFTWAY through UPDATES and UPGRADES at its own discretion.

7.2. The CUSTOMER receives all UPDATES free of charge under these conditions.

7.3. UPGRADES may be offered free of charge or for a fee at SOFTWAY’s discretion. If SOFTWAY does not provide UPGRADES free of charge, SOFTWAY will inform the CUSTOMER of the price for unlocking the latest version. The CUSTOMER is not obliged to purchase UPGRADES. If the CUSTOMER decides not to license an upgrade under the offered conditions, the provisions of the existing contract remain unaffected. This also applies to the provision of free UPDATES.

7.4. The CUSTOMER has no right to versions with an older UPDATE status. If a SaaS solution in the version used by the CUSTOMER is no longer supported, e.g., only newer UPGRADE versions are supported, SOFTWAY will inform the CUSTOMER at least 6 months in advance about the discontinuation of version support.

7.5. Adjustments, changes, and additions to the SOFTWARE as well as measures for detecting and eliminating faults only lead to temporary interruption or impairment of availability if absolutely necessary for technical reasons. If SOFTWAY provides predictable maintenance windows for individual SOFTWARE components, SOFTWAY will inform the CUSTOMER about outages and maintenance windows.

7.6. The availability of the SOFTWARE is 99% on an annual average, including maintenance work, whereby availability may not be impaired or interrupted for more than two consecutive calendar days. Periods of insignificant disturbances are not considered in the calculation of availability.

7.7. Decisive is the availability of the SOFTWARE at the transfer point of the SOFTWAY data center or the BTP account point to the Internet. Availability is the CUSTOMER’s ability to use all essential functions of the licensed SOFTWARE.

7.8. SOFTWAY reserves the right to temporarily restrict its services regarding the SOFTWARE if necessary due to capacity limits, security or integrity of SOFTWAY’s servers, or to carry out technical measures, or if this serves the proper or improved provision of services. In these cases, SOFTWAY will take the legitimate interests of the CUSTOMER into account, e.g., by providing advance information.

8. individual services

8.1. If individual services such as interface programming, individual adaptations, additional software for evaluation and recording, automation services, or the transfer of existing data in relation to the SOFTWARE are commissioned, the following provisions apply additionally and subordinately to the special consulting conditions and any SLA.

8.2. All individual additional services by SOFTWAY are not contractually owed services within the scope of licensing the respective SOFTWARE, but require a separate – usually paid – additional agreement.

8.3. SOFTWAY will inform the CUSTOMER in good time about (impending) additional services. If SOFTWAY, with the prior consent of the CUSTOMER, provides services that go beyond the content or scope of an order, these services must be remunerated by the CUSTOMER according to the agreed rates, or, in the absence of such, according to SOFTWAY’s usual rates. Agreed additional services will be invoiced separately.

8.4. If the additional work leads to delays in the agreed services, SOFTWAY will inform the CUSTOMER about the expected delay.

9. open source software and third-party software

9.1. If the SOFTWARE provided by SOFTWAY contains code and computer programs from third parties, the respective license conditions of these apply unrestrictedly and in addition to the license conditions of the SOFTWARE, with the license conditions of the respective manufacturer taking precedence over these SOFTWARE license conditions in case of conflicts.

9.2. The CUSTOMER is obliged to comply with the terms of use of the respective third-party software.

9.3. SOFTWAY is entitled to replace third-party software integrated into the SOFTWARE, provided that functionality is not restricted. SOFTWAY will inform the CUSTOMER about the change. If this leads to deviating contractual regulations, SOFTWAY will grant the CUSTOMER a special right of termination.

9.4. The CUSTOMER may not integrate third-party software supplied by SOFTWAY into other computer programs and use it unless permitted by the underlying license conditions of the third-party software. Otherwise, the CUSTOMER may only use the delivered third-party software as part of the SOFTWARE. In this context, the CUSTOMER indemnifies SOFTWAY – upon first request – from all claims arising from a breach of this obligation.

10 Invoicing / Payments / Cancellation

10.1. The minimum contractual term and payment provisions are derived from the contract concluded between SOFTWAY and the CUSTOMER.

10.2. SOFTWAY is entitled to issue interim invoices at its reasonable discretion.

10.3. The contractually owed remuneration is due within 14 days after receipt of an invoice.

10.4. The payment method agreed between the CUSTOMER and SOFTWAY is payment by bank transfer to SOFTWAY’s business account, unless payment by direct debit is agreed. If direct debit is agreed, the CUSTOMER will provide SOFTWAY with a SEPA mandate upon first request.

10.5. From the due date of the remuneration, SOFTWAY is entitled to charge interest at the statutory rate for entrepreneurs according to § 288 para. 2 BGB in the applicable version.

10.6. If the payments made by the CUSTOMER are not sufficient to settle all debts, the oldest debt is settled, even if the CUSTOMER specifies otherwise. If interest and/or costs have already been incurred, payments not sufficient to settle the total debt will first be credited to the oldest costs, then to the oldest interest, and only then to the principal.

10.7. The withholding of payments due to disputed and not legally established counterclaims by SOFTWAY or offsetting with disputed or not legally established counterclaims by SOFTWAY is not permitted.

10.8. If SOFTWAY has not received payment within 30 days after the due date, SOFTWAY reserves the right, without prejudice to all other rights and remedies, to suspend the customer’s user accounts and access to all or part of the products or services. SOFTWAY is not obliged to provide the products or services in whole or in part as long as the relevant invoice(s) remain unpaid.

10.9. SOFTWAY may adjust the underlying annual price based on the price development for “Content: Data Processing, Hosting and Related Services” (Code: CPA08-6311) of the Federal Statistical Office (available at: https://www-genesis.destatis.de/) as of January 1 of each year. The relevant change is the change since the last adjustment or, for the first adjustment, the time of contract conclusion. SOFTWAY will announce the adjustment of the fee at least one month in advance.

10.10. SOFTWAY may also change the underlying price if the costs for providing the contractual service have changed due to a significant increase in SOFTWAY’s own procurement costs. This may occur, for example, with a short-term sharp increase in hosting, software, and license costs. The costs must have changed so that SOFTWAY would adjust the existing fee level by at least 5% if the existing contract were newly concluded. Upon request, SOFTWAY will provide further information, documents, and evidence necessary to review the fee change. SOFTWAY will inform the CUSTOMER of the adjustment of the fee based on procurement costs at least two months before it takes effect. If the CUSTOMER does not respond within 4 weeks of receipt of the adjustment notice, the new fee is deemed agreed. SOFTWAY will specifically point out the consequences of a lack of response and the related deadline in the written announcement of the fee adjustment.

10.11. Further provisions regarding remuneration, billing, notice periods, and contract terms are set out in the ORDER FORM and the special provisions for each SOFTWARE contained therein.

10.12. The CUSTOMER is obliged to provide SOFTWAY with their VAT identification number. If the CUSTOMER does not provide SOFTWAY with their VAT identification number, SOFTWAY is entitled to charge VAT on the invoice.

10.13. The CUSTOMER is obliged to provide SOFTWAY with all information necessary for proper invoicing. This includes, in particular, providing a ready-to-receive email address.

11. prices

11.1. All prices quoted by SOFTWAY are exclusive of VAT. All amounts and fees are payable in Euro.

11.2. The CUSTOMER pays SOFTWAY a fee based on the booked service package of the SOFTWARE. The fee is determined by the offer or the respective order confirmation and/or SOFTWAY price list detailing the services underlying the order.

12th Extraordinary Termination

12.1. Without prejudice to other rights or remedies, either party may terminate this agreement and/or any order form with immediate effect by written notice to the other party if:

– a party ceases operations (either entirely or if departments essential to the performance of this agreement are affected);

– a person (including a shareholder or holder of another security right) is appointed as administrator or insolvency administrator for the other party, or if the intention of such appointment is expressed or documents related to such appointment are filed with the court;

– proceedings are initiated leading to the dissolution of a party or resulting in its assets being distributed to its creditors, shareholders, or other employees (except in the case of a merger or restructuring);

– insolvency proceedings are opened over the assets of the other party or the opening of insolvency proceedings is rejected due to lack of assets.

12.2. Notwithstanding the provisions of Section 12, the CUSTOMER is only entitled to partially terminate this contract and/or an order form regarding future services from SOFTWAY or non-performance by SOFTWAY in the past. All services already provided by SOFTWAY at the time of partial or complete termination under this agreement and/or an order form cannot be revoked under any circumstances, and all invoices related to these services remain immediately due and payable at the time of termination. The modalities are set out in Section 10 of these General Terms and Conditions.

13. changes to these GTC

13.1. SOFTWAY is entitled to change these GTC with future effect if this is necessary for justified reasons, especially due to changes in the legal situation or supreme court rulings, technical changes or developments, changed organizational requirements for the operation of the SOFTWARE, gaps in these GTC, changed market conditions, or other comparable reasons, and the CUSTOMER is not unreasonably disadvantaged as a result.

13.2. For future changes, SOFTWAY will inform the CUSTOMER at least six weeks before they take effect in writing (e.g., by email) and indicate where the previous and new GTC can be viewed.

13.3. The changes are deemed approved and become effective if the CUSTOMER does not object to the change in writing (e.g., letter or email) within one month of receipt of the change notice, provided the change notice expressly points out this consequence.

13.4. If the change affects a material contractual provision, whose compliance is of particular importance for achieving the contract’s purpose (material contractual obligation or cardinal obligation), the change will only be made with the express consent of the CUSTOMER. A material contractual or cardinal obligation in the above sense is one whose fulfillment enables the proper execution of this contract and on whose compliance the CUSTOMER regularly relies and may rely; this includes, in particular, agreements regarding the remuneration payable to SOFTWAY.

14 Liability for Material and Legal Defects

14.1. SOFTWAY warrants that the contractually agreed condition will be maintained during the contract term and that no third-party rights oppose the contractual use of the SOFTWARE. SOFTWAY will remedy material and legal defects within a reasonable period. SOFTWAY may fulfill its obligation to rectify defects by providing UPDATES or workarounds with an automatic installation routine for download on its homepage and offering telephone support for resolving installation problems.

14.2. Technical data, specifications, and performance details in public statements by SOFTWAY, especially in advertising materials, are not specifications. The functionality of the SOFTWARE is determined by the description in the user documentation and the supplementary agreements. Otherwise, the licensed SOFTWARE must be suitable for the use intended by this contract and otherwise have the characteristics typical for SOFTWARE of the same type.

14.3. The CLIENT’s right to reduce the price or withdraw from the contract at their discretion after two unsuccessful attempts at rectification or replacement remains unaffected. In the case of only insignificant defects, there is no right of withdrawal.

14.4. The CUSTOMER is obliged to notify SOFTWAY of defects in the SOFTWARE in writing immediately upon discovery.

15. liability

15.1. The following provisions of this section of the General Terms and Conditions apply to claims by the CUSTOMER for damages or reimbursement of “useless expenses” (§ 284 BGB) against SOFTWAY. SOFTWAY’s liability under the Product Liability Act (§ 14 ProdHaftG) and guarantees given by SOFTWAY remain unaffected.

15.2. SOFTWAY is liable for all damages resulting from intentional or grossly negligent breach of duty by SOFTWAY, its employees, legal representatives, or vicarious agents according to the statutory provisions.

15.3. SOFTWAY is also liable for damages resulting from injury to life, body, or health caused by intentional, grossly negligent, or negligent breach of duty by SOFTWAY, its employees, legal representatives, or vicarious agents according to the statutory provisions.

15.4. For negligent breaches not covered by Section 15.3, SOFTWAY is only liable if SOFTWAY negligently breaches a material contractual obligation, i.e., an obligation whose fulfillment is of particular importance for achieving the contract’s purpose (material contractual obligation or cardinal obligation). In such cases, liability is limited to the typically foreseeable damage, i.e., damage that must typically be expected within the scope of the contract. A material contractual or cardinal obligation in the above sense is one whose fulfillment enables the proper execution of the contract and on whose compliance the CUSTOMER regularly relies and may rely.

15.5. In all other cases, SOFTWAY is not liable.

16 Confidentiality

16.1. SOFTWAY collects and uses the customer’s personal data only within the framework of applicable legal provisions. SOFTWAY will store and process data exclusively in compliance with legal requirements, especially the GDPR.

16.2. “Confidential information” means all information disclosed or made available by one PARTY to the other PARTY in connection with the contract in writing, orally, visually, or electronically and marked as “confidential” or whose confidential nature arises from the circumstances. This includes, in particular, object codes, documentation and other documents, business processes, business relationships, and know-how.

16.3. The PARTIES will maintain strict confidentiality regarding all confidential information disclosed to them in connection with this contract, especially business or trade secrets of the other contracting party, and will neither disclose nor otherwise exploit them. Disclosure of confidential information to employees of the respective contracting party and to third parties is only permitted if the disclosure is necessary for the proper fulfillment of contractual obligations by the respective employee or third party or if the third party is a person subject to professional confidentiality.

16.4. Confidential information does not include information that, in the reasonable judgment of a prudent merchant, is insignificant and therefore does not require secrecy. In case of doubt, the recipient is obliged to clarify the status of such information with the other PARTY. The other PARTY’s decision on the confidentiality of such information, made at its reasonable discretion, is then binding.

16.5. The confidentiality obligation does not apply if

– the relevant confidential information was publicly known at the time it was provided by a PARTY for reasons other than a breach of this agreement;

– the relevant confidential information becomes accessible to a PARTY from another source, provided the PARTY has reason to believe that this source is itself prevented from disclosing the confidential information by a statutory or contractual obligation;

– the PARTY has authorized the other PARTY to disclose certain confidential information to a third party with prior written consent;

– the confidential information was already lawfully in the possession of the other PARTY before being made accessible by the other PARTY; or

– the disclosing PARTY is obliged to disclose confidential information due to an order from a competent court, authority, or mandatory stock exchange regulation.

16.6. Mandatory law permitting or requiring the collection, use, or disclosure of confidential information by a party (e.g., § 5 GeschGehG, §§ 6 ff. HinSchG) remains unaffected.

16.7. The PARTIES undertake to agree with all employees deployed in connection with the execution of the contract on a provision of identical content as this clause.

16.8. If a PARTY is obliged to disclose confidential information due to a sovereign measure, e.g., a court or authority order or statutory reporting obligations, the confidentiality obligation shall only lapse to the extent necessary for compliance with the sovereign measure requiring disclosure. In this case, the PARTY subject to the sovereign measure is obliged to inform the other PARTY in writing immediately before disclosure and, in consultation with the other PARTY, to take all reasonable measures to reject disclosure requests and/or ensure the confidentiality of the information before disclosure.

16.9. The confidentiality obligation applies indefinitely beyond the term of this agreement.

17. support | contact person | escalation level

17.1. SOFTWAY will set up a support service for CUSTOMER inquiries regarding the SOFTWARE. Inquiries can be submitted via the support channels specified on the SOFTWAY website during the times indicated there.

17.2. Support requests are always processed in the order in which they are received.

17.3. To channel the necessary communication – especially in the event of service structure disruptions – the PARTIES will each designate a main contact (Key User) who can make binding declarations for the respective PARTY or obtain such declarations after being informed by the Key User of the other PARTY about a situation and the need for a decision via the support channels provided by SOFTWAY.

17.4. The CUSTOMER must follow the instructions provided by SOFTWAY when describing, isolating, identifying, and reporting errors.

17.5. The CUSTOMER must specify their fault reports and questions to the best of their knowledge and, if a Key User has been designated, submit them via the support channels communicated by SOFTWAY.

17.6. For SaaS SOLUTIONS, the CUSTOMER is solely responsible for creating the system requirements listed for the use of the respective SOFTWARE on the deployed IT systems, especially providing compatible browsers and installing any necessary plug-ins.

18 Final Provisions

18.1. The law of the Federal Republic of Germany applies, excluding the UN Convention on Contracts for the International Sale of Goods. If the CUSTOMER is a merchant, a legal entity under public law, or a special fund under public law, the exclusive place of jurisdiction for all disputes arising from this contract is SOFTWAY’s registered office in 96114 Hirschaid.

18.2. The same applies if the CUSTOMER is an entrepreneur and does not have a general place of jurisdiction in Germany or their residence or usual place of abode is unknown at the time of the action. SOFTWAY’s right to bring an action at another statutory place of jurisdiction remains unaffected.

18.3. If SOFTWAY provides translations of the German version of these GTC, the German version (available at [LINK]) is always decisive for the legal assessment of the content of the GTC. This applies especially if there are differences or contradictions between the German version and a translated version of these GTC.

18.4. SOFTWAY points out that the SOFTWARE may be subject to export and import restrictions. In particular, there may be licensing requirements, or the use of the SOFTWARE or related technologies abroad may be subject to restrictions. The CUSTOMER will – where applicable – comply with the relevant export and import control regulations of the Federal Republic of Germany, the European Union, and all other applicable regulations. SOFTWAY’s performance of the contract is subject to the condition that there are no obstacles due to national and international regulations of export and import law and no other legal regulations.

18.5. The CUSTOMER is not entitled to offset or withhold counterclaims arising from this contract unless the counterclaims are acknowledged in writing by SOFTWAY or have been legally established.

consultation