Website Privacy Policy

In the following, we inform you about the processing of your personal data by us and the claims and rights to which you are entitled under data protection regulations, in particular the European General Data Protection Regulation (GDPR).

This privacy policy informs you about the nature, scope, and purpose of the processing of personal data within our website (hereinafter “Website”). This privacy policy applies regardless of the domains, platforms, and devices used (e.g., desktop, mobile, etc.).

Personal data within the meaning of the GDPR is all data that can be related to you personally, e.g., name, address, email addresses, user behavior. Which data is processed in detail and in what way it is used depends largely on the services requested from us.

We use various other terms in our privacy policy within the meaning of the GDPR. These include terms such as processing, restriction of processing, profiling, pseudonymization, controller, processor, recipient, third party, consent, supervisory authority, and international organization. You can find the corresponding definitions for these terms in Art. 4 GDPR.

1. Who is responsible for data processing and who can I contact?


The Controller is:

Laika Communications GmbH

Oranienburger Straße 27

10117 Berlin Germany

info@laika.berlin

You can reach our Data Protection Officer at:

ALPHATECH Consulting GmbH

Yanick Röhricht

Taunusstraße 11

65183 Wiesbaden

Germany

datenschutz@ihredomain.de

www.alphatech-consulting.de

2. What sources and data do we use?


We process personal data that we receive from you in the context of using our website, when you contact us, and, if applicable, in the context of an existing or prospective business relationship.

In the case of purely informational use of our website, i.e., if you do not actively transmit information to us, we only process the personal data that your browser transmits to our server. When you visit our website, we collect the following access data, which is technically necessary for us to display our website to you and to ensure stability and security:

  • IP address
  • Date and time of the request
  • Time zone difference to Greenwich Mean Time (GMT)
  • Content of the request (i.e., name of the specifically accessed webpage)
  • Access status/HTTP status code
  • Amount of data transferred in each case
  • Referrer URL (previously visited page)
  • Operating system and its interface
  • Language and version, as well as the type of browser software
  • Message about successful retrieval

Furthermore, we process personal data when you contact us, especially via email or when booking an appointment. This particularly includes: first name, last name, email address, and any data you send us as a message (hereinafter referred to as “Contact Data”). Depending on the type of request, the provision of further data may be necessary.

Please note that we cannot guarantee complete data security when communicating via email, so we recommend using regular mail for information with high confidentiality requirements.

3. What do we process your data for (purpose of processing) and on what legal basis?


We process personal data in accordance with the provisions of the European General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG) for the following purposes and based on the following legal bases:

3.1 Data processing based on your consent

If you have given us consent to process personal data for specific purposes, in particular for contacting us (e.g., via our web forms), for sending newsletters, or for promotional approaches via phone or email (direct marketing), the lawfulness of this processing is based on your consent under Art. 6 (1) sentence 1 lit. a GDPR. Granted consent can be withdrawn at any time. Please note that the withdrawal is only effective for the future. Processing that occurred before the withdrawal is not affected. The withdrawal can be made to us at any time using the contact details mentioned above.

3.2 Data processing for the performance of pre-contractual measures upon the person’s request

When contacting us (e.g., via web form, phone, or email), your details are processed to handle and manage the contact request in accordance with Art. 6 (1) sentence 1 lit. b GDPR.

3.3 Data processing to fulfill legal obligations

Insofar as processing your personal data is necessary to fulfill a legal obligation to which we are subject, the data processing is based on Art. 6 (1) sentence 1 lit. c GDPR.

3.4 Processing for the purposes of our legitimate interests or those of third parties

We may process your personal data to protect the legitimate interests of us or third parties. We pursue the following legitimate interests in particular:

  • Ensuring IT security, in particular the security of the website;
  • Improving the website in terms of structure and content;
  • Asserting legal claims and defense in legal disputes.

3.5 Direct marketing to existing customers

If you have provided us with your email address when purchasing goods or services, we reserve the right to regularly send you offers for similar goods or services to those already purchased from our range via email. We do not need to obtain separate consent from you for this in accordance with Sec. 7 (3) UWG (German Act Against Unfair Competition). Data processing in this regard is based on our legitimate interest in personalized direct advertising under Art. 6 (1) sentence 1 lit. f GDPR in conjunction with Sec. 7 (3) UWG. If you initially objected to the use of your email address for this purpose, we will not send you emails. You have the right to object to the use of your email address for the aforementioned advertising purpose at any time with effect for the future, e.g., by clicking on the unsubscribe link at the end of our emails or by notifying us via the contact options mentioned above. You will only incur transmission costs according to the basic rates. In the event of an objection, we will stop using your email address for direct marketing purposes.

3.6 Execution of application procedures

When you contact us (via Kununu, Xing, LinkedIn, or email) regarding an application, we process your data to review your suitability for the position (or other open positions in our company, if applicable) and to carry out the application process, Art. 6 (1) sentence 1 lit. b GDPR. Upon receipt, your application data will be reviewed by the HR department. Suitable applications will then be forwarded internally to the department heads responsible for the open position, who decide on the next steps. Within the company, only those persons who need access to your data for the proper execution of our application process will generally have access to it. For data processing that is not strictly necessary for carrying out the application process, we obtain your consent under Art. 6 (1) sentence 1 lit. a GDPR.

3.7 Storing data on your terminal device or accessing data on your terminal device

We use cookies and similar technologies on our website. We store information on your device because this is absolutely necessary to make our website available to you, Sec. 25 (2) No. 2 TDDDG. Data processing is carried out to protect our legitimate interest under Art. 6 (1) sentence 1 lit. f GDPR in the best possible functionality of the website. When you visit our website for the first time, you will also be asked whether you consent to the setting of non-technically necessary cookies and the use of comparable technologies. Data collection and storage, as well as any subsequent data processing, only take place based on your explicit consent, Sec. 25 (1) TDDDG, Art. 6 (1) sentence 1 lit. a GDPR. If personal data is also processed by individual cookies or similar technologies, processing generally occurs under Art. 6 (1) sentence 1 lit. f GDPR to safeguard our legitimate interests (e.g., best possible functionality and a user-friendly visit), or under Art. 6 (1) sentence 1 lit. a GDPR based on your consent. For further information, see “Cookies and similar technologies”.

4. Who receives my data?


Within our company, access to your data is given to those departments that need it to fulfill our contractual and legal obligations.

Processors deployed by us (Art. 28 GDPR) may also receive data for the above-mentioned purposes. These are companies in the IT services and software categories. If we pass data on to our service providers, they may only use the data to fulfill their tasks. Service providers have been carefully selected and commissioned by us. They are contractually bound to our instructions, have implemented appropriate technical and organizational measures to protect the rights of data subjects, guarantee an adequate level of data protection, and are regularly monitored by us.

Data transfer to third parties who are not processors only occurs within the framework of legal requirements. We only pass user data on to third parties if this is necessary, e.g., on the basis of Art. 6 (1) sentence 1 lit. b GDPR for contractual purposes, on the basis of legitimate interests under Art. 6 (1) sentence 1 lit. f GDPR for the economic and effective operation of our business, or if you have consented to the data transfer. In the case of purely informational use of the website, we generally do not pass any data on to third parties.

5. How long will my data be stored?


5.1 Access data

For security reasons (e.g., to investigate misuse or fraud), log file information is stored for a maximum of 30 days and then deleted (see Section 2 above). Data whose further retention is necessary for evidentiary purposes is exempt from deletion until the final clarification of the respective incident.

5.2 (Pre-)contractual measures

Where necessary, we process and store your personal data for the duration of our business relationship, which includes the initiation of a contract via contact form or email.

5.3 Applicant data

In the event of a rejection, applicant data is deleted after 6 months. If you are not hired, but your application remains of interest to us, we will keep your application on file for future vacancies provided we have your explicit written consent. The data will be deleted at the latest after two years or upon withdrawal of your consent. If we fill the advertised position with you, your data will be stored in our HR management system.

5.4 Statutory retention obligations

Furthermore, we are subject to various retention and documentation obligations, which arise inter alia from the German Commercial Code (HGB) and the German Fiscal Code (AO). The retention and documentation periods specified there are six to ten years.

5.5 Statutes of limitation

Finally, the storage period is also judged according to the statutory limitation periods, which, for example, according to Sections 195 et seq. of the German Civil Code (BGB), are generally 3 years, but in certain cases up to thirty years, with the standard limitation period being three years. If you exercise your rights as a data subject, we will store the information provided to you in this regard until the expiry of the statutory limitation period under Sec. 31 (2) No. 1 OWiG, Sec. 41 (1) BDSG, Art. 83 (5) lit. b GDPR for 3 years. This period may be extended if the statutory limitation period is interrupted (e.g., through inquiries from supervisory authorities).

5.6 Further storage periods

Information on further storage periods can be found in the following paragraphs.

6. Will data be transferred to a third country or an international organization?


The provided data is processed within the European Union and in the USA. In the case of a data transfer to the USA, we ensure that the data recipients are certified under the EU-U.S. Data Privacy Framework or that we agree on EU Standard Contractual Clauses with recipients without certification. If we base the data transfer on the EU Standard Contractual Clauses, we will implement additional security measures to protect your data and achieve an adequate level of protection. You have the possibility to obtain or view a copy of the EU Standard Contractual Clauses. If necessary, we will ask for your explicit consent for the data transfer to the USA.

7. What are my data protection rights?


Every data subject has:

  • The right of access under Art. 15 GDPR (i.e., you have the right to request information about your personal data stored by us at any time).
  • The right to rectification under Art. 16 GDPR (i.e., if your personal data is inaccurate or incomplete, you can request correction).
  • The right to erasure under Art. 17 GDPR and the right to restriction of processing under Art. 18 GDPR (i.e., you may have the right to request deletion or restriction if, for example, there is no longer a legitimate business purpose and statutory retention obligations do not require further storage).
  • The right to data portability under Art. 20 GDPR (i.e., you may have the right to receive the personal data you provided to us in a structured, commonly used, and machine-readable format and transmit it to another controller without hindrance).

Furthermore, you can generally withdraw given consent at any time with effect for the future.

You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR in conjunction with Sec. 19 BDSG). You can find your competent supervisory authority at: https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html. We would appreciate it if we could address your concerns before you approach the supervisory authority, so we ask you to contact us with your complaint first.

Additionally, we would like to point out your right to object under Art. 21 GDPR:

Information on your right to object under Art. 21 GDPR

You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is based on Art. 6 (1) sentence 1 lit. e GDPR (data processing in the public interest) and Art. 6 (1) sentence 1 lit. f GDPR (data processing based on a balancing of interests); this also applies to profiling based on these provisions within the meaning of Art. 4 No. 4 GDPR.

If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or the processing serves the establishment, exercise, or defense of legal claims.

In individual cases, we process your personal data for direct marketing purposes. You have the right to object at any time to the processing of personal data concerning you for such marketing; this also applies to profiling to the extent that it is related to such direct marketing. If you object to processing for direct marketing purposes, we will no longer process your personal data for these purposes.

The objection can be made informally to us via the contact details mentioned above, and no costs other than the transmission costs according to basic rates will be incurred.

8. Is there automated decision-making in individual cases including profiling?


When accessing our website or when contacting us via form or email, we generally do not use fully automated decision-making under Article 22 GDPR. Should we use these procedures in individual cases, we will inform you separately if this is required by law. We do not process your data automatically with the aim of evaluating certain personal aspects (profiling).

9. Is there an obligation for me to provide data?


When visiting our website, you must provide the personal data that is technically necessary or required for IT security reasons to use our website. If you do not provide this data, you cannot use our website. When contacting us via form or email, you only need to provide the personal data necessary to process your request. Otherwise, we cannot process your request.

If your inquiry is aimed at concluding a contract or if the provision of data is required in the context of initiating a contract, failure to provide data may result in us being unable to render the intended service.

10. Cookies and similar technologies


10.1 General

We and service providers deployed by us process personal data on this website and use cookies and similar technologies, such as web storage, in this context. These technologies can store information on your device or access information stored on your device (so-called client-based tracking).

Cookies are stored in the browser on the user’s terminal device. They contain information that is saved in connection with a visited page. The cookie is either sent from the web server to the browser or generated in the browser by a script (JavaScript). Upon later, renewed visits to this page, the web server can read this cookie information directly or transmit it via a website script back to the server. When cookies are set, they generally collect and process specific user information on an individual scale, such as browser and location data and IP address values. Some of these cookies are essential for the functioning of our website, while others help us improve our website by giving us insights into how you use it.

With web storage, information is stored locally in your browser’s cache. The stored information is either automatically deleted after the browser window is closed (“Session Storage”) or remains so that it can be read again when you visit the website (“Local Storage”), provided you do not clear your browser cache (“Browser Data”).

You can individually prohibit the storage of cookies via your browser settings (the browser’s help page tells you how to manage cookie handling). Assistance with cookie management in common browsers can be found at the following addresses:

  • Mozilla Firefox: https://support.mozilla.org/en-US/kb/clear-cookies-and-site-data-firefox
  • Internet Explorer: https://support.microsoft.com/en-us/windows/delete-and-manage-cookies-168dab11-0753-043d-7c16-ede5947fc64d
  • Google Chrome: https://support.google.com/accounts/answer/61416?hl=en
  • Opera: http://www.opera.com/help
  • Safari: https://support.apple.com/en-us/HT201265
  • Microsoft Edge: https://support.microsoft.com/en-us/microsoft-edge/delete-cookies-in-microsoft-edge-63947406-40ac-c3b8-57b9-2a946a29ae09

Please note that deactivating cookies may lead to functional restrictions on this website.

11. Appointment scheduling via Google Calendar


You have the opportunity to arrange appointments with us via our website or as part of business communication. In doing so, we process the data you provide, in particular your first and last name and your email address. To organize and manage appointments, we use Google Calendar, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Processing is carried out to perform pre-contractual measures and to fulfill contractual obligations under Art. 6 (1) lit. b GDPR or on the basis of our legitimate interest in efficient appointment organization and communication under Art. 6 (1) lit. f GDPR.

12. Conducting video conferences via Google Meet


We use Google Meet to conduct online meetings and video conferences. When participating in a video conference, your name, email address, and technical connection data in particular may be processed. Furthermore, content provided or exchanged by participants during the conference may be processed. Processing is carried out to perform pre-contractual measures and fulfill contractual obligations under Art. 6 (1) lit. b GDPR or, insofar as the processing takes place within general business communication, on the basis of our legitimate interest in efficient appointment organization and communication under Art. 6 (1) lit. f GDPR. Insofar as personal data is transferred to third countries, in particular the USA, in connection with the use of Google Calendar or Google Meet, this is done on the basis of the EU-U.S. Data Privacy Framework and, where applicable, supplementary appropriate safeguards under Art. 44 et seq. GDPR. Further information on data processing by Google can be found in Google’s privacy policy: https://policies.google.com/privacy

13. Newsletter


If you register for our newsletter, we will use your email address to regularly send you information, insights, and news from Laika Communications.

The only mandatory information for sending the newsletter is your email address. When you register for the newsletter, we store the IP address entered by the Internet Service Provider (ISP) as well as the date and time of registration in order to be able to trace possible misuse of your email address at a later point in time. Our email newsletters are sent via Substack, Inc., 111 Sutter Street, 7th Floor, San Francisco, CA 94104 USA, which processes the information provided during newsletter registration for dispatch and statistical evaluation of the newsletters on our behalf. For statistical evaluation, the sent emails contain so-called web beacons. This makes it possible to determine whether a newsletter message was opened and which links, if any, were clicked. In addition, technical information is recorded (e.g., time of retrieval, IP address, and browser and device information like the operating system). This data serves exclusively for the statistical analysis of newsletter campaigns and is not used to personalize the newsletter. If you wish to revoke your consent to data processing for statistical evaluation purposes, you must unsubscribe from the newsletter.

Data collection takes place in accordance with Sec. 25 (1) TDDDG, and subsequent data processing according to Art. 6 (1) sentence 1 lit. a GDPR, provided you have expressly consented to the delivery of our newsletter via the double opt-in (DOI) procedure. This means we will only send you an email newsletter once you have explicitly confirmed that you consent to its delivery. We will send you a confirmation email asking you to click a link confirming that you wish to receive future newsletters. You can unsubscribe from the newsletter at any time using the link provided in the newsletter or by sending us a message via the contact options listed above. Once you have unsubscribed, your email address will be deleted from our newsletter mailing list immediately. Further information on data processing can be found in the privacy policy of Substack, Inc. at https://substack.com/privacy

14. External link to Google Maps


Our website contains a link to Google Maps, a map service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. By visiting our website, no personal data is transmitted to Google. A connection to Google’s servers is only established when you click the link. During this process, personal data, in particular your IP address, may be transmitted to Google. Further information on data processing by Google can be found at: https://policies.google.com/privacy

15. Our Social Media Presences


You can find our presences within social networks and platforms so that we can communicate with you there and inform you about our services. We point out that your data may also be processed outside the European Union when using social media networks or platforms, and that social network providers generally process data for market research and advertising purposes. User profiles can be created from user behavior and resulting interests. These profiles can in turn be used to place advertisements inside and outside the platforms that presumably correspond to users’ interests. For this purpose, cookies and similar technologies are often stored on the user’s device, capturing user behavior and interests. Other data may also be stored in these profiles, particularly if users are members of the respective platforms and logged in.

We merely link to our company profiles on the respective social networks on our website. Note, however, that clicking a link to social networks transfers data to their servers. If you are logged into the respective social network with your username and password at that time, the information that you visited our company profile from our website is transmitted there, and the respective provider can link this information to your user account.

We generally have no significant influence on data processing by social networks. However, we receive statistics from the providers regarding the use and visits of our social media profiles (e.g., data on views, interactions like likes and comments, as well as aggregated demographic and other information or statistics). Detailed information on the data used by providers can be found in their privacy policies linked below.

If we receive personal data from you via social networks (e.g., through a message) and process it solely ourselves, we act as the Controller for that data processing. In this case, you are entitled to the rights mentioned above in this privacy policy. You can direct your inquiries regarding data processing within our company profiles to us via the contact details provided above. Please consider carefully what personal data you share with us via social networks.

If the data transmitted by you via the social network is processed additionally or exclusively by the social network provider (Insights Data), both we and the respective provider are Joint Controllers under the GDPR. This data processing is governed by an agreement between joint controllers under Art. 26 GDPR. If you wish to assert rights against the social network provider in this regard, the easiest way is to contact the providers directly. The provider knows the details of the technical operation of the platform and the associated data processing, as well as the concrete purposes. Contact details can be found in their respective privacy policies linked below. We will also gladly support you in asserting your rights to the best of our ability.

The processing of users’ personal data is generally based on your consent under Art. 6 (1) sentence 1 lit. a GDPR. The legal basis is also Art. 6 (1) sentence 1 lit. b GDPR if we receive and process your data within a contract-related inquiry via our social media presence. The legal basis for linking to and operating our company profiles on social networks, including receiving statistics on their usage, is Art. 6 (1) sentence 1 lit. f GDPR, based on our legitimate interest in corporate communication on the respective networks.

For information on the specific processing operations and your respective opt-out options, please refer to the providers’ privacy policies linked below:

  • Facebook (Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland), Social Network – Privacy Policy: https://www.facebook.com/about/privacy/, Opt-Out: https://www.facebook.com/settings?tab=ads, Joint Controller Agreement: https://www.facebook.com/legal/terms/page_controller_addendum
  • Instagram (Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland), Online service for sharing photos and videos – Privacy Policy: https://help.instagram.com/519522125107875/?helpref=hc_fnav
  • LinkedIn (LinkedIn Ireland Unlimited Company Wilton Place, Dublin 2, Ireland), Social Network for maintaining and creating new business contacts – Privacy Policy: https://www.linkedin.com/legal/privacy-policy, Opt-Out: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out
  • TikTok Video portal for short video clips (TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland), Video portal with social network functions, Privacy Policy: https://www.tiktok.com/legal/privacy-policy
  • X (Twitter International Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07 Ireland), Microblogging service – Privacy Policy: https://twitter.com/en/privacy, Opt-Out: https://twitter.com/personalization
  • YouTube (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland), Video portal – Privacy Policy: https://policies.google.com/privacy, Opt-Out: https://adssettings.google.com/authenticated
  • Xing (XING AG, Dammtorstraße 29-32, 20354 Hamburg, Germany), Social Network for maintaining and creating new business contacts – Privacy Policy / Opt-Out: https://privacy.xing.com/en/privacy-policy