1. Introductory information
1.1 General information
The websites https://investify.de, https://investify.lu and https://investify.com are operated by:
investify S.A., 46, Grand Rue, 6630 Wasserbillig, Luxembourg, registered with the Luxembourg Register Court (RCS Luxembourg) under the register number B 200777. The data collecting body (responsible person) is Investify S.A., 46, Grand Rue, 6630 Wasserbillig. For detailed data protection information (Art. 13 Data Protection Basic Regulation) please click here:
1.2 External Data Protection Officer
The investify data protection officer can be reached at the following address:
Herr Rechtsanwalt Dr. Karsten Kinast, LL.M.
KINAST Rechtsanwaltsgesellschaft mbH
1.3 Principles of data processing
Personal data is all information that relates to an identified or identifiable natural person. This includes information such as your name, age, address, telephone number, date of birth, e-mail address, IP address or user behavior. Information where we cannot (or only with a disproportionate effort) establish a connection to your person, e.g. by anonymising the information, is not personal data. The processing of personal data (e.g. the collection, retrieval, use, storage or transmission) always requires a legal basis or your consent. Processed personal data will be deleted as soon as the purpose of the processing has been achieved and there is no longer any legally prescribed obligation to keep records. If we process your personal data for the provision of certain offers, we will inform you in the following about the specific procedures, the scope and purpose of data processing, the legal basis for processing and the respective storage period.
2. Collection, processing and use of personal data through investify
investify offers its users services via its own Internet portal, a smartphone app and related electronic services. The core of the offer comprises individual asset management and in-depth information on investment issues.
2.1 Provision and use of the website
When you access and use our website, we collect personal data that your browser automatically transmits to our server. This information is temporarily stored in a so-called log file. When you use our website, we collect the following data, which is technically necessary for us to display our website and to ensure its stability and security:
- IP-address of the requesting computer
- Date and time of access
- Name and URL of the retrieved file
- Website from which the access takes place (referrer-URL)
- The browser used ans, if applicable, the operating system of your computer, as well as the name of your access provider
- Use of your data from the contact form: The personal data you provide us with in the context of this contact request will only be used to answer your request or contact you and for the related technical administration. The data is stored in HubSpot.
Art. 6 para. 1 lit. f DSGVO serves as the legal basis for the data processing mentioned above. The processing of the above-mentioned data is necessary for the provision of a website and thus serves to protect a legitimate interest of our company. As soon as the aforementioned data is no longer required to display the website, it will be deleted. The collection of the data for the provision of the website and the storage of the data in log files is absolutely necessary for the operation of the website. There is therefore no possibility of objection on the part of the user. Further storage may be carried out in individual cases if this is required by law.
You can delete specific cookies or all cookies via the browser settings. Information and instructions on how to delete cookies or block their storage in advance can be found on the following pages of the browser providers:
Other cookie management tools are provided by the following third parties:
Many browsers also support so-called "do-not-track functions", which prevent your user data from being "tracked" and stored by websites. If this function is activated, the browser informs advertising networks, websites and applications that you do not wish to be tracked on the basis of behavior-based advertising and similar. Depending on your browser, you can find information about this function here:
2.1.2 Use of the Google Maps Places API
Type and purpose of processing: Within the scope of registration we use the offer of Google Places. The Google Places API is operated by Google LLC, 1600 Amphitheatre Parkway, Mount Rain View, CA 94043, USA (hereinafter "Google"). This enables us to ensure the address data quality of the registrations, offer an auto-completion service and avoid incorrect entries. In the course of the verification of this contact and / or address data Google receives the IP address. Further information about data processing by Google can be found in the Google data protection information. There you can also change your personal data protection settings in the data protection centre.
You can find detailed instructions on how to manage your own data in connection with Google products here: http://dataliberation.org.
Legal basis: The legal basis for this data processing is Art. 6 I f) DSGVO, as the IP address is required to be able to supply this content. In this processing, our cooperation with Google is based on a contract on joint responsibility in accordance with Art. 26 DSGVO, which can be accessed here. Further information on data processing by Google can be found in the Google data protection guidelines at
Recipient: By visiting the website, Google receives information that you have called up the corresponding subpage of our website. This happens regardless of whether Google provides a user account through which you are logged in or whether no user account is available. If you are logged in at Google, your data will be assigned directly to your account. If you do not want the assignment in your profile at Google, you have to log out before activating the button at Google. Google stores your data as user profiles and uses them for the purposes of advertising, market research and/or demand-oriented design of its website. Such an evaluation is carried out in particular (even for users who are not logged in) to provide need-based advertising and to inform other users of the social network about your activities on our website. You have a right of objection to the creation of these user profiles, whereby you must contact Google to exercise this right.
Storage duration: We do not collect any personal data through the integration of Google Maps.
Third country transfer: Google processes your data in the USA and is subject to the EU-US Privacy Shield
The investify website uses HubSpot for its online marketing activities. HubSpot is a
US-American software company with a European subsidiary in Ireland. Contact: HubSpot, 2nd Floor 30 North Wall Quay, Dublin 1, Ireland, Phone: +353 1 5187500, is an integrated software solution that covers various aspects of our online marketing:
- E-mail marketing (newsletters and automated mailings, e.g. to provide downloads)
- Social Media Publishing & Reporting
- Reporting (including traffic sources, access, conversions, target group segmentation, analysis of user habits on the website, call-to-action analysis)
- Contact management (e.g. user segmentation & CRM)
- Landing Pages
- Contact forms
- Cookie Consent / Consent to cookie use
- Display of the content is partly done via the CDN Cloudflare
2.1.4 Newsletter dispatch via Hubspot
Hubspot is a service that can be used to organize and analyze the sending of newsletters, among other tasks. If you enter data for the purpose of subscribing to the newsletter (e.g. e-mail address), this data is stored on Hubspot's servers. Hubspot allows us to analyze our newsletter campaigns. When you open an email sent through Hubspot, we can determine whether a newsletter message was sent, opened and, if so, which links were clicked. Technical information is also collected: time of access, browser type and operating system. This information is used exclusively for statistical analysis of newsletter campaigns. The results of these analyses can be used to better adapt future newsletters to the interests of our subscribers. The data is evaluated anonymously. If you do not wish to receive an analysis from Hubspot you can unsubscribe the newsletter. For this purpose we provide a link in every newsletter message.
If you do not want HubSpot to collect cookies in general, you can prevent the storage of cookies at any time by your browser settings accordingly or by using the following opt-out link: http://www.investify.com/hubspot-opt-out
2.1.5 Hubspot Live-Chat (GGF)
To improve the user experience on our website, we also use HubSpot's live chat service "Messages" (round chat icon at the bottom right of the screen) to send and receive messages on some sub-pages. If you agree and use this function, the following data will be transmitted to HubSpot's servers:
- Content of all sent and received chat messages
- Context informationen (e.g. page on which the chat was used)
- Optional: user´s e-mail address (if provided by the user via chat function)
The legal basis for the use of the Hubspot chat is Art. 6 I a) DSGVO. The user explicitly gives his consent before his data is stored. HubSpot is certified under the "EU - U.S. Privacy Shield Framework" and is subject to the TRUSTe Privacy Seal and the "U.S. - Swiss Safe Harbor" framework.
2.1.6 CDN Cloudflare
You can prevent the collection and processing of your data by CloudFlare by deactivating the execution of script code in your browser or by installing a script blocker in your browser, which you can find here for example:
2.1.7 CDN CloudFront and S3
Our website uses the Content Delivery Network (CDN) Cloudfront and S3. These hosting services are provided by Amazon Web Services Inc, 410 Terry Avenue North, Seattle, WA
98109-5210. Cloudfront and S3 CDN make content from our website available on various Amazon Web Services (AWS) servers distributed worldwide. This reduces the loading time of the website, provides a higher reliability and increased protection against data loss. The content integrated on this website, such as images and videos, is obtained from the cloudfront / S3 CDN when the page is accessed. Through this access, information about your use of our website (such as your IP address) is transferred to Amazon servers in other EU countries and stored there. This already happens when you use the website with these servers. The use of Amazon Web Services and the Amazon CDN Cloudfront and S3 is in the interest of a higher reliability, increased protection against data loss and a better loading speed of the website. This represents a legitimate interest in the sense of Art. 6 para. 1 lit. f DSGVO. You can find out more about the data protection measures of Amazon Web Services at: https://aws.amazon.com/de/data-protection/
2.1.8 CDN Fastly
Our website uses the Content Delivery Network (CDN) Fastly to deliver content. The CDN Fastly is operated by Fastly Inc, General Counsel 475 Brannan St, Suite 300 San Francisco, CA 94107. The Fastly CDN makes content from our website available on various servers distributed worldwide. This shortens the loading time of the website, provides a higher reliability and increased protection against data loss. The contents of this website, such as images and videos, are obtained from the Fastly CDN when the page is called up. This retrieval transfers information about your use of our website (e.g. your IP address) to Fastly servers in other EU countries and stores it there. This is already done when you use the website with this content. The use of Fastly Web Services and the CDN Fastly is in the interest of greater reliability, increased protection against data loss and better loading speed of the website. This constitutes a legitimate interest in the sense of Art. 6 Para. 1 lit. f DSGVO. The current data protection declaration of fastly can be found here: https://www.fastly.com/privacy.
2.1.9 Embedded YouTube videos
Google processes your data in the USA and is subject to the EU-US Privacy Shield
Legal basis: Legal basis for the integration of YouTube and the associated data transfer to Google constitutes a legitimate interest (Article 6(1)(f) DSGVO) Recipients: Calling YouTube automatically triggers a connection to Google. Storage period and withdrawal of consent: Who has deactivated the storage of cookies for the Google ad program, will not have to expect such cookies when watching YouTube videos. YouTube also stores non-personalized usage information in other cookies. If you want to prevent this, you must block the storage of cookies in the browser. Further information on data protection at "YouTube" can be found in the provider's data protection declaration at:
Third country transfer: Google processes your data in the USA and is subject to the EU-US Privacy Shield:
Parts of the Internet portal and the smartphone app are reserved for registered users or asset management clients. An e-mail address is required for registration. In order to be able to make a professional assessment of the financial situation, investify collects and stores various personal data on the user's financial situation, risk tolerance and willingness to delegate, as well as on the level of education, experience and knowledge of financial products and investments in general.
In order to conclude an asset management agreement and the necessary account and custody agreement, the following personal data will be collected by investify and in part by the appointed service provider IDnow (IDnow GmbH, Fürstenstraße 15, 80333 Munich, Germany), forwarded to Baader Bank (Baader Bank AG, Weihenstephaner Straße 4, 85716 Unterschleissheim, Germany) for the purpose of opening an account and custody account and stored by investify for the purpose of processing the agreement (as an example): Name, title, date and place of birth, nationality, marital status, e-mail address, address, telephone number(s), details of tax liability). During the personal identification conversation (video chat), photos and/or video recordings of the identification document and of the client are taken and stored. In addition, a sound recording of the conversation is made and stored. The information available on the identification document is checked and in particular the type of identification document, its ID number and date of issue, and the issuing authority. A reference account must be specified for the subsequent transfer of funds. Due to the requirements of the Money Laundering Act and other legal regulations, information on the origin of the funds as well as on the status as a politically exposed person will continue to be requested.
As a registered user, you will receive a personal copy of the basic information on securities from Banken-Verlag (Bank-Verlag GmbH, Wendelinstraße 1, 50933 Köln). For the personalization of this document we will transfer your full name to a server of the Banken-Verlag to receive a personalized PDF document. The Banken-Verlag does not store this personal data, but uses it exclusively for the one-time generation of the document. This data is only passed on or transmitted to third parties if this is necessary for the purpose of processing the contract or if you have given your prior consent. We would like to point out that data transmission over the Internet (e.g. when communicating by e-mail or other digital services) may have security gaps and data may be transmitted via network nodes in several countries. A complete protection of data against access by third parties is not possible. According to Art. 6 Para. 1 lit. b DSGVO, the processing of the personal data presented (cf. § 4 2. a.) serves to fulfil the asset management contract or to carry out pre-contractual measures. Due to legal regulations, investify will store the personal data for 5 years after the end of the business relationship. As a user you have the possibility to cancel the registration at any time. You can have the data stored about you changed at any time. To do so, please send an e-mail to: Investify S.A., 46, Grand Rue, 6630 Wasserbillig, Luxemburg, E-Mail: datenschutz(at)investify.com
However, if the processed data is necessary for the fulfilment of a contract or for the implementation of pre-contractual measures, an early deletion of the data is only possible if this does not conflict with contractual or legal obligations.
On our website you have the possibility to subscribe to a free newsletter. With the newsletter we inform you about us and our offers. In order to send you the newsletter regularly, we need the following information from you:
- e-mail address
When you register for the newsletter, we save your IP address and the date of registration. This storage serves only as proof in the event that a third party misuses an e-mail address and registers to receive the newsletter without the knowledge of the entitled person.
Your data will not be passed on to third parties in connection with the newsletter dispatch. We use the so-called double opt-in procedure for sending out newsletters, i.e. we will only send you the newsletter if you first confirm your registration via a confirmation e-mail sent to you for this purpose using the link contained in the e-mail. Thus, we would like to make sure that only you yourself, as the owner of the e-mail address provided, can subscribe to the newsletter. Your confirmation must be sent promptly after receipt of the confirmation e-mail, otherwise your newsletter registration will be automatically deleted from our database.
The processing of your e-mail address, for the purpose of sending the newsletter, is based on your declaration of consent in accordance with Art. 6 para. 1 letter a DSGVO. Your e-mail address will be stored the same way you have subscribed to the newsletter. After you have unsubscribed from the newsletter, your e-mail address will be deleted. A further storage can take place in individual cases, if this is required by law.
3.1 Use of own cookies
Various types of cookies are used on our website, the type and function of which are explained in detail below.
Our website uses transient cookies that are automatically deleted when you close your browser. We use transient cookies for tracking and analysis of user activity in connection with various partners. This type of cookie makes it possible to record your session ID. This allows us to assign different requests from your browser to a common session and enables us to recognize your device during later visits to the website within a session.
Persistent cookies are used on our website. Persistent cookies are cookies that are stored in your browser over a longer period of time and transmit information to us. We use persistent cookies for tracking and analysis of user activities in connection with various partners. The respective storage period varies depending on the cookie. You can delete persistent cookies independently via your browser settings. We use the following cookies:
- Partner-Cookie to assign new customers to a partner
- Data on the current visitor session
- Data on visitor history (actual customer)
- ID for cross-session visitor recognition
- Storage of the selected language of (this cookie is currently not actively used)
3.2 Market research
Your user data will be used anonymously for the purposes of market research and demand-oriented product design.
For this purpose, we summarize your accrued and specified data in user profiles and evaluate them for the aforementioned purposes. This is only done internally and only for the aforementioned purposes.
4. Tracking and analysis tools
We use tracking and analysis tools to ensure that our website is continuously optimised and designed to meet your needs. With the help of tracking measures, we are also able to statistically record the use of our website by visitors and to further develop our online offer for you with the help of the insights gained. Based on these interests, the use of the tracking and analysis tools described below is justified in accordance with Art. 6 para. 1 sentence 1 lit. f DSGVO. The following description of the tracking and analysis tools also shows the respective processing purposes and the processed data.
4.1. Use of the Google Tag Manager
The investify website and app use the Google Tag Manager from Google (Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA). Google Tag Manager is a solution that allows marketers to manage website tags through one interface. The Tag Ma- nager tool itself (which implements the tags) is a cookie-less domain. The tool triggers other tags, which in turn may collect data. Google Tag Manager does not access this data. If deactivation has been made at the domain or cookie level, it will remain for all tracking tags implemented with Google Tag Manager.
4.2 Use of Google Analytics
The investify website and app uses Google Analytics, a web analytics service provided by Google (Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA). Google Analytics uses so-called cookies, text files which are stored on your computer/end device and which enable an analysis of the use of the website or the app. The information generated by the cookie about your use of this website or app is usually transferred to a Google server in the USA and stored there. However, on this website or app, your IP address is first shortened by Google within member states of the European Union or in other states that are party to the Agreement on the European Economic Area.
The information generated by these cookies, for example about time, place and frequency of your use of this website, is usually transferred to a Google server in the USA and stored there. When using Google Analytics, it is not excluded that the cookies set by Google Analytics may also collect other personal data in addition to the IP address. We would like to point out that Google may transfer this information to third parties if this is legally required or if third parties process this data on behalf of Google.
Google will use the information generated by cookies on behalf of the operator of this website to evaluate your use of the website, to compile reports on website activity and to provide further services to the website operator in connection with the use of the website and the Internet. The IP address transmitted by your browser within the framework of Google Analytics is not merged with other Google data according to Google's own information. It cannot be ruled out that the cookies set by Google Analytics may collect further personal data in addition to the IP address. In order to prevent information on your use of the website from being collected by Google Analytics and transmitted to Google Analytics, you can download and install a plugin for your browser under the following link:
This plugin prevents information about your visit to the website from being transmitted to Google Analytics. Any other analysis is not prevented by this plugin.
Please note that you cannot use the browser plug-in described above when visiting our website via the browser of a mobile device (smartphone or tablet). When using a mobile device, you can prevent Google Analytics from recording your usage data by clicking on the following link: https://investify.com/app/opt-out/google-analytics
By clicking on this link, a so-called opt-out cookie is placed in your browser. This prevents information about your visit to the website from being transmitted to Google Analytics. Please note that the opt-out cookie is only valid for this browser and only for this domain. If you delete the cookies in this browser, the opt-out cookie will also be deleted. In order to continue to prevent Google Analytics from recording the cookie, you must click the link again. The use of the opt-out cookie is also possible as an alternative to the above plug-in when using the browser on your computer. In order to ensure the best possible protection of your personal data, Google Analytics on this website has been extended by the code "anonymizeIp". This code ensures that the last 8 bits of IP addresses are deleted and your IP address is thus recorded anonymously (so-called IP mas- king). Your IP address will be shortened by Google in principle even before it is transferred within member states of the European Union or in other signatory states of the Agreement on the European Economic Area and thus made anonymous. Only in exceptional cases will the full IP address be transferred to a Google server in the USA and shortened there. Further information on the use of data for advertising purposes by Google, setting and objection possibilities can be found on the websites of Google:
(“Data usage by Google when you use websites or apps of our partners“),
(“Use of data for advertising purposes“),
(“Manage information that Google uses to serve ads to you“) and
(“Determine which ads Google shows you“).
4.3 Google AdWords
We use the technology "Google AdWords"' and especially the conversion tracking. Google Conversion Tracking is an analysis service of Google Inc, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. When you click on an ad placed by Google, a conversion tracking cookie is placed on your PC. The cookies are valid for 30 days and are not used for personal identification. If you visit certain pages on our site, if the cookie hasn't expired, Google and we may know that you clicked on an ad and were directed to that page. Google AdWords customers each receive a different cookie. As a result, we don't have the ability to track cookies through the websites of our AdWords customers. The data collected using the conversion cookie is used to compile conversion statistics for AdWords customers who use conversion tracking. Customers are told the number of times they have clicked on their ad and been redirected to a page with a conversion tracking tag. However, they do not receive any information that can be used to personally identify users. The storage of 'conversion cookies' is based on Art. 6 para. 1 lit. f DSGVO. The website operator has a legitimate interest in the analysis of user behaviour in order to optimise both his website and his advertising. If you do not wish to participate in conversion tracking, you can prevent this by making the appropriate setting in your browser, e.g. by generally preventing the installation of cookies. You can also deactivate cookies for conversion tracking by setting your browser so that only cookies from the web address "googleadservices.com" are blocked. Alternatively, you can prevent Google AdWords from recording your usage data by clicking on the following link: https://investify.com/app/opt-out/google-adwords.
4.4. Google Analytics Remarketing
4.5 Google Charts
4.6 Use of Crashlytics
We use the Crashlytics service from Google (Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) to collect information about errors and crashes that may occur in our iOS and Android apps. This allows us to improve the stability and quality of our apps. We do not use any Crashlytics services that require personal data. The only non-personal information transmitted through our apps is stored on Crashlytics servers in the USA. For more information on data protection at Crashlytics, please visit https://try.crashlytics.com/terms/
4.7 Use of financeAds
To prevent information about your use of the website from being collected and transmitted to financeAds, you can download and install a plugin for your browser under the following link:
4.8. Use of Facebook
We use on this website the Facebook Pixel, Custom Audiences as well as the business tool of Facebook, a social media network of Facebook Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2 Ireland. The implemented code can evaluate the behaviour of visitors who came to our website from a Facebook advertisement.
This can be used to improve Facebook advertisements and this data is collected and stored by Facebook. The collected data cannot be viewed by us, but can only be used in the context of advertising campaigns. By using the Facebook pixel code, cookies are also set. By using the Facebook pixel, the visit to our website is communicated to Facebook so that visitors to Facebook can see suitable advertisements. If you have a Facebook account and are logged in, the visit is assigned to your user account. The data collected is anonymous to us, so we cannot draw any conclusions about the identity of the user. However, the data is stored and processed by Facebook, so that a connection to the respective user profile is possible and Facebook can use the data for its own advertising purposes, in accordance with the Facebook Data Usage Policy: https://www.facebook.com/about/privacy/
If you are a Facebook member and do not want Facebook to collect data about you via the pixel and link it with the membership data stored on Facebook, you can revoke your consent via the following opt-out link:
Please note that an opt-out is limited to the browser you are currently using and to the website domain you are currently visiting.
4.9. Use of etracker
The websites of cooperation partners use the analysis service etracker. The provider is etracker GmbH, Erste Brunnenstraße 1 20459 Hamburg Germany. User profiles can be created from the data under a pseudonym. Cookies are used to enable a statistical analysis of the use of these websites by their visitors, especially the forwarding to our website, as well as the display of usage-related content or advertising.
The data generated with etracker is processed and stored by etracker on behalf of the provider of this website exclusively in Germany and is therefore subject to the strict German and European data protection laws and standards. etracker has been independently tested, certified and awarded the ePrivacyseal data protection seal of approval. Data processing is carried out on the legal basis of Art. 6 Para. 1 lit f (legitimate interest) of the EU Data Protection Basic Regulation (EU-DSGVO). The legitimate interest is the optimization of the corresponding online offer of the cooperation partner. You can object to the collection and storage of data at any time with effect for the future. In order to object to the future collection and storage of your visitor data, you can obtain an opt-out cookie from etracker by clicking on the following link: https://investify.com/app/opt-out/etracker
By changing the settings in your Internet browser, you can deactivate or restrict the transmission of cookies. Already stored cookies can be deleted at any time. This can also be done automatically.
4.10 Hyperlinks to external websites
On our website there are so-called hyperlinks to websites of other providers. When activating these hyperlinks, you will be forwarded from our website directly to the website of the respective provider. You can recognize this by the change of the URL, among other things. We cannot assume any responsibility for the confidential handling of your data on these third-party websites, as we have no influence on whether these companies comply with the data protection regulations. Please inform yourself about the handling of your personal data by these companies directly on these websites.
5.1. Cooperation with service providers
investify falls back on service companies, in particular also on affiliated companies of investify. These companies are monitored by investify for their reliability in accordance with legal requirements and are subject to the order and instructions of investify with regard to the processing of customer data and its use. investify uses electronic systems and electronic means of communication, including telephone and e-mail, operated by service providers for internal and external communication with customers and other third parties. Communication contents and data including customer data are stored and processed in Luxembourg, in Germany and possibly in other countries of the European Union. For organisational reasons investify may also access this data from outside Germany and Luxembourg. This also includes the collection, processing and use of the data.
5.2. List of major service providers
The following service providers regularly process communication data, personal data or operate infrastructures on behalf of investify, which are indirectly used by investify to provide its services.
Software development, software testing, system administration, operation and monitoring of the workstationand server systems as well as implementation of data backup.
Baader Bank AG
Weihenstephaner Straße 4
Opening and maintenance of a securities account with clearing account, execution of securities and account transactions, mutual information about significant changes in master data and contract status.
Telekom Deutschland GmbH
Provision of electronic means of communication and internal server services.
Conducting video interviews with (potential) customers for identification purposes. For this purpose, comparison of personal master data with an identification document and recording of audio and video data.
noris network AG
Provision of a secure computer centre and the Internet infrastructure for server operation.
Am Birkenfeld 1
Provision of communication services.
POST Telecom S.A.
1 rue Emile Bian
Provision of electronic means of communication and internal server services.
Im Süsterfeld 6
Provision of a secure computer centre and the Internet infrastructure for server operation.
Consulting on IT security, implementation of IT security tests and security audits.
The protection of personal data is very important to us. Therefore, we provide the following information on the collection, processing and use of data in the context of online applications, in accordance with the relevant data protection regulations.
6.1. Data collection
In the course of the online application, we collect and process the following personal application data of applicants: Surname, first name, address, telephone number, e-mail and all documents and data sent by applicants in the context of the application (application letter, curriculum vitae, references, certificates, etc.).
6.2 Purpose of data collection / transfer
The collection and processing of personal application data is exclusively for the purpose of filling the positions in our company. This data will only be forwarded to the investify internal offices and specialist departments responsible for the specific application procedure. The application data will not be used for any other purpose or passed on to third parties.
Legal basis: Art. 6 para. 1 b) DSGVO in connection with § 26 BDSG-New.
6.3 Period of retention of application data
Personal application data is automatically deleted three months after completion of the application process. This does not apply if legal regulations oppose deletion, if further storage is required for the purpose of providing evidence or if the applicant has expressly agreed to longer storage.
6.4 Storage for future job advertisements
If we are unable to offer a current vacancy, but are of the opinion, based on the applicant's profile, that the application might be interesting for future vacancies, we will store personal application data for a period of six months, unless the applicant expressly objects to such storage and use.
6.5 Data security
In order to protect the data collected in the context of your application from manipulation and unauthorized access, we have taken a number of technical and organizational precautions.
6.6 Right of information and revocation
Questions regarding the collection, processing or use of personal data or information, the correction or deletion of data, as well as the revocation of consents granted, can be addressed to our external data protection officer.
7. Further information and contacts
7.1. Rights of data subjects
The following rights result from the DSGVO for you as a person affected by the processing of personal data:
- According to Art. 15 DSGVO you can request information about your personal data processed by us. In particular, you can request information on the purposes of processing, the categories of personal data, the categories of recipients to whom your data has been or will be disclosed, the planned storage period, the existence of a right of correction, deletion, restriction of processing or objection, the existence of a right of appeal, the origin of your data, if not collected by us, on transfers to third countries or international organisations, as well as on the existence of automated decision making including profiling and, if applicable, meaningful information on the details thereof.
- In accordance with Art. 16 DSGVO, you can immediately request the correction of incorrect data or the completion of your personal data stored with us.
- In accordance with Art. 17 DSGVO, you can demand the deletion of your personal data stored with us, unless the processing is necessary to exercise the right to freedom of expression and information, to fulfil a legal obligation, for reasons of public interest or to assert, exercise or defend legal claims.
- In accordance with Art. 18 DSGVO, you can demand the restriction of the processing of your personal data if the accuracy of the data is disputed by you, the processing is unlawful, we no longer require the data and you refuse to solve it because you need it to assert, exercise or defend legal claims. You are also entitled to the right under Art. 18 DSGVO if you have lodged an objection to the processing in accordance with Art. 21 DSGVO.
- In accordance with Art. 20 DSGVO, you can request to receive the personal data you have provided us with in a structured, common and machine-readable format or you can request that it be transferred to another responsible party.
- According to Art. 7 para. 3 DSGVO you can revoke your consent at any time. As a result, we may no longer continue to process the data based on this consent in the future.
- According to Art. 77 DSGVO you have the right to appeal to a supervisory authority. As a rule, you can apply to the supervisory authority of your usual place of residence, your place of work or our company headquarters for this purpose.
7.2. Right of objection
If your personal data are processed on the basis of legitimate interests in accordance with Art. 6 para. 1 sentence 1 letter f DSGVO, you have the right to object to the processing of your personal data in accordance with Art. 21 DSGVO, if there are reasons for doing so arising from your particular situation or if the objection is directed against direct marketing. In the case of direct advertising, you have a general right of objection, which will be implemented by us without specifying a special situation.
7.3. Data security and security measures
We commit ourselves to protect your privacy and to treat your personal data confidentially. In order to avoid manipulation, loss or misuse of your data stored with us, we take extensive technical and organisational security measures which are regularly checked and adapted to technological progress. This includes the use of recognised encryption procedures (SSL or TLS). We would like to point out, however, that due to the structure of the Internet it is possible that the rules of data protection and the above-mentioned security measures may not be observed by other persons or institutions that are not within our area of responsibility. In particular, data disclosed in unencrypted form (e.g. when sent by e-mail) may be read by third parties. We have no technical influence on this. It is the responsibility of the user to protect the data provided by him/her against misuse by means of encryption or in any other way.
6.3.2019, Version 1.7.1