NAWIDA Logo
HOME
Digital Sales & E-Commerce Digital Performance Stabilization & Realignment Website Audit
PRAIDICT MARKET ANALYSIS
DEEN
LOGIN CONTACT
HOME
Digital Sales & E-Commerce Digital Performance Stabilization & Realignment Website Audit
PRAIDICT MARKET ANALYSIS
DEEN
LOGIN CONTACT

Privacy Policy

This English translation is provided for convenience only. The German version is legally binding.

In the following, we would like to explain what data we collect about you and what we do with this data. We also inform you about your data protection rights and explain who you can contact with questions about the protection of your data.

About us

Controller responsible for the processing of your data:

NAWIDA GmbH
Lindenstraße 11
36269 Philippsthal
[email protected]
030-91734590

Managing directors: Marc Fischer, Jan Tillmann

If you have any questions about this privacy policy, the processing of your data, your rights or other data protection matters, our data protection officer will be happy to help you.

Contact details of the data protection officer:

Xamit Bewertungsgesellschaft mbH
Monschauer Str. 12
40549 Düsseldorf
[email protected]

Scope

This privacy policy is addressed to:

  • our business customers, as well as

  • visitors to our websites nawida.de, app.praidict.de and app.fahrhalt.de.

Our pages contain links leading to the websites of other operators, to which this privacy policy does not apply.

Responsibility for the display of advertising banners, text advertising or advertising videos before or during embedded videos lies with the respective operator.

Do I have to provide my data?

When you visit our website, user data is stored automatically. Some of the data collected is necessary for the use of a website. In addition, we also process your data to safeguard our legitimate interests following a balancing of interests. This enables us to continuously improve the services offered to you. On the following pages you will find the background to our interests and whether or how you can object to the use of your data or deactivate its use yourself.

To use one of our offerings or to send an inquiry, you will be asked to provide your personal data. You can decide for yourself whether you wish to take advantage of these offerings and provide your data for this purpose. We also offer you services for which we only process your data if you have given us your consent. Consent is always given voluntarily. Consent, once given, can be withdrawn at any time.

Please note that if you provide information about other persons, you must first have obtained their consent and informed them about the purposes of the disclosure as set out in this privacy policy.

We also ask you to pass this information on to the persons you involve in the use of our services, such as family members or authorized representatives. Data processing on the website and in our app

We distinguish between different types of processing, which we describe below together with the legal basis for the processing. Tables describe the data processed for this purpose.

Origin of the data

In connection with your visit to our websites or the use of our apps, no data is collected from third parties.

We receive the data of contact persons at our business partners from the respective employer, unless the contact persons provide us with their data themselves.

As part of our advertising activities, we use so-called list owners, who make their own data (addresses) available to third parties for advertising purposes.

Data processing on the website and in our app

We distinguish between different types of processing, which we describe below together with the legal basis for the processing. Tables describe the data processed for this purpose.

Service provision

In order for you to be able to visit and use our website, your data must be collected. We process this data to safeguard our legitimate interest in providing a functioning website (Art. 6 (1) (f) GDPR).

Data security

Every access to our online offering is stored in a log file and analyzed. We process this data for data security purposes. The processing is carried out to safeguard our legitimate interest in being able to ensure data security (Art. 6 (1) (f) GDPR).

Processing of inquiries

We process the data you provide to us when you have a question or concern. This also includes, for example, the data you send to us by email. The processing of your data is necessary so that we can handle your inquiry. It is carried out to safeguard our legitimate interest in answering your questions and concerns (Art. 6 (1) (f) GDPR).

Optimization of the online offering incl. profiling

We are constantly improving our website in order to offer you optimal user guidance. We use your data to evaluate the usability, functionality and attractiveness of our website as well as user behavior. For this purpose, your data is aggregated into statistics without any personal reference. This enables us to fix errors, optimize the user experience, and further develop our website and our marketing activities. Your visit data is not linked to your name or other personal details (if you provide them to us).

The processing is based on your consent (Art. 6 (1) (a) GDPR).

Information about cookies

Where we use cookies that are necessary for the operation of the website, the processing is based on our legitimate interest (Art. 6 (1) (f) GDPR) in a functioning provision of the website. Otherwise, cookies are only set if you have given us your consent (Art. 6 (1) (a) GDPR).

Optimization and billing of advertising measures incl. profiling

We process your data for the optimization and billing of advertising measures and to enable us to re-address visitors to our website, for which purpose marketing cookies are also set (if you consent to this). This assigns you a unique user ID, which is used to identify your subsequent visits. We do not link your visit data to your name or other personal details (if you provide them to us).

We also use your data to have suitable advertising displayed by our partners on other sites even after you have left our website. Furthermore, we use services of LinkedIn Ireland Unlimited Company (hereinafter "LinkedIn"). The data collected is passed on to LinkedIn for the purpose stated above. LinkedIn takes previous usage behavior into account and assigns the transmitted information to your respective personal user account (if you have one). When you visit the LinkedIn network, personalized, interest-based ads are displayed to you in this network.

The processing is based on your consent (Art. 6 (1) (a) GDPR).

Display of videos

In order to use the videos embedded on our website, the specified data must be processed. Your data is only processed for the display of videos and passed on to the service provider Google Ireland Ltd (hereinafter "Google") once you have given your consent by activating the video service (Art. 6 (1) (a) GDPR). As a result, Google learns that our website was accessed via your IP address. The data may also be used by Google to analyze user behavior and for market research and marketing purposes. Access to this data from, or storage of this data in, countries with a level of data protection that differs from that of the EU cannot be ruled out. You can find more information on the handling of user data in Google's privacy policy: https://www.google.de/intl/de/policies/privacy/.

Information about cookies

Where we use cookies that are necessary for the operation of the website, the processing is based on our legitimate interest (Art. 6 (1) (f) GDPR) in a functioning provision of the website. Otherwise, cookies are only set if you have given us your consent (Art. 6 (1) (a) GDPR).

Further information about the specific processing purposes, the names and lifetimes of cookies, the partners used, the data recipients and the option to change your consent can be found in our consent manager. There you will also find links to the privacy information of our partners and can withdraw or change your consent via the Co logo at the bottom right of the screen.

Processed data

Data

Service provision

Data security

Processing of inquiries

Optimization of the online offering incl. profiling

Optimization and billing of advertising measures incl. profiling

IP address

X

X

x

Name of the file retrieved

X

Volume of data transferred

X

Web page accessed

X

X

x

Referrer URL (the previously visited web page)

X

X

x

End device

X

x

User agent sent by your browser

X

X

X

x

Cookies (see Information about cookies)

X

x

Date and time of access

X

X

X

X

x

Date and time of the last user activity (for session timeout)

X

Click ID

X

x

Operating system

X

x

Session duration

X

x

Information about the browser used (type, version, resolution (inner window size), language)

X

X

Screen format, screen resolution incl. color depth

X

x

Status code

X

X

X

x

Page path

X

X

X

x

JavaScript on/off

X

Requested resources

x

Metadata: title tag and description

x

UTM parameters (source, medium, campaign, content, duration)

x

Salutation, name

X

Contact details (email address, address, telephone, fax)

X

Subject, topic, concern

X

Content of the message

X

Time of receipt of the message/registration

X

Processing of customer data

This section explains what data we process, for which purposes, and on which legal basis the processing within the customer relationship is based. Tables describe the data processed for this purpose.

Inquiries, support and customer account

We process your data within the business relationship for the following purposes: to create your customer data in our customer database, for the registration and provision of a customer account with login, for the operation of various security measures for your customer account, for the handling of inquiries and orders, arranging individual appointments, cancellations, returns or complaints, for complaint management, and for coordination in the course of providing our services. The legal basis for the processing of your data for these purposes is the initiation or performance of a contract (Art. 6 (1) (b) GDPR) if you are the direct contracting party; otherwise, the processing is carried out to safeguard our legitimate interest in the performance of the contract and the contractual obligations with your employer or client (Art. 6 (1) (f) GDPR).

In order to support you as a customer holistically and to advise you in the best possible way, we further process your data in order to make suggestions to you on our platform with specific reference to your projects and your needs. The processing of your data for these purposes is carried out to safeguard our legitimate interest in the performance of the contract with you or your employer (Art. 6 (1) (f) GDPR).

Payment processing

We process your payment information for the purpose of payment processing. For this purpose, your data is forwarded to our payment service provider Stripe (Stripe Payments Europe Limited). The legal basis for the processing of your data for these purposes is the performance of the contract (Art. 6 (1) (b) GDPR).

Information and advertising purposes

We process your personal data for the purpose of advertising our own products and services. In order to be able to inform you about content that also matches your interests, we create a customer profile about you. Advertising contact takes place by post, by email or by telephone. In addition, we process your data to measure the success of our newsletters and to be able to optimize future newsletters.

The processing of your data for the creation of profiles is carried out to safeguard our legitimate interests in the targeted advertising of our products and services (Art. 6 (1) (f) GDPR). Postal advertising about our products and services is carried out to safeguard our legitimate interest in sales promotion. Advertising about our products and services by telephone and email, as well as the measurement of success and optimization of emails, is based on the consent you have given (Art. 6 (1) (a) GDPR). If no consent has been given, we base advertising by email on a statutory permission (Art. 6 (1) (c) GDPR in conjunction with Section 7 (3) UWG (German Act Against Unfair Competition)); telephone contact, however, on Art. 6 (1) (c) GDPR in conjunction with Section 7 (2) No. 2 UWG if you are a business customer.

In connection with the use of customer data from list owners for advertising purposes, we are jointly responsible for the processing together with the list owners we use. List owners make their data available to us for advertising purposes (see section "Origin of the data").

We have contractually agreed with the list owners we use who assumes which data protection obligations. Accordingly, you can assert your rights (see section "Your rights") against us or the list owners. If we receive corresponding requests from you that concern the joint data processing, we will forward your request to the responsible list owner.

List owners are responsible for the following processing purposes:

  • Processing of personal data for the purpose of direct marketing

We are responsible for the following processing purposes:

  • Use of the list owners' data for advertising purposes on the basis of the jointly concluded contract

The privacy information of the list owners we use and the contact details for asserting your rights can be found below:

https://schober.de/datenschutz/

www.personalleiter.today/datenschutz

Processed data

Data

Inquiries, support and customer account

Payment processing

Information and advertising purposes

Salutation, name

X

X

X

Username, password

X

Contact details (email address, address, telephone, fax)

X

X

X

Subject, topic, concern

X

X

Content of the message or from our online contact flows

X

X

Time of receipt of the message/registration

X

X

Order details, order date and number

X

X

Receivables and incoming payments

X

Conditions

X

X

Date and time of the report

X

Contract term

X

Appointments

X

Status

X

X

X

Planned activities

X

Advertising consent given

X

Company key figures

X

Register court

X

Tax number

X

VAT ID

X

Date of incorporation

X

Legal form

X

Name and contact details of persons authorized to issue instructions

X

Contact details of the data protection contact person

X

Reporting address for security incidents

X

Profile picture

X

History of browser sessions

X

Authentication service used, one-time password

X

Time lock after failed logins

X

Use of our platform (pages viewed and products used)

X

Search terms used, saved searches

X

Evaluations, analysis results

X

Links and content clicked

X

Time of logout

X

Location (country, region, city (geolocation))

X

Device used

X

German Whistleblower Protection Act (HinSchG)

We process your data to fulfill our obligations under the German Whistleblower Protection Act (Hinweisgeberschutzgesetz, HinSchG). Under this act, we are obliged to receive and examine reports of (suspected) violations of the law. As part of the investigation of the reported cases, reporting persons or persons named may be interviewed by us. Information and statements may be passed on to other affected bodies or authorities or used in court proceedings. Whether disclosure is necessary and legally permitted is examined separately in each individual case.

We receive the report from the respective whistleblower. Where applicable, the report is supplemented by the reporting office receiving it.

The processing of your data for the purpose of investigating a reported case is carried out to safeguard our legitimate interest in investigating violations of legal provisions or internal rules.

Other processing purposes

In addition, the data mentioned above is used for the following purposes on the basis of a balancing of interests (Art. 6 (1) (f) GDPR). The interests are named below:

  1. As it is in our interest to ensure the security of our systems, we regularly carry out security and effectiveness tests, in the course of which your data mentioned above may be processed.

  2. Should a security incident ("personal data breach") occur in our company in which your data is affected, we are obliged to report the case to the data protection supervisory authority responsible for us (Art. 33 GDPR). As it is our legitimate interest to comply with this statutory reporting obligation as quickly as possible, data relating to you may be processed in the course of investigating the security incident in question. The reports of these security incidents to data protection supervisory authorities do not contain any of your personal data.

  3. We carry out audits, internal reviews and other control measures (e.g. monitoring by the data protection officer), as it is our legitimate interest to comply with legal requirements, to create transparency about our business processes, to continuously optimize these processes, and to prevent and detect actions that are damaging to the business. In doing so, documents or files containing your personal data may be processed.

  4. We carry out internal and external audits to obtain and maintain certifications as well as to meet customer requirements and quality standards. Furthermore, our customers or funding bodies carry out their own audits. Here, too, documents and files containing personal data may be processed.

  5. We process your data for the purposes of managing our company, for identifying and tracking financial risks, for bundling sales activities, and for fulfilling (contractual) obligations towards our customers. For this purpose, the processed data is evaluated in reports. The processing is carried out to safeguard our legitimate interests in corporate and sales management as well as in the fulfillment of our obligations towards our customers.

  6. To comply with our obligations under tax law, we use tax advisors. We also engage statutory auditors in order to comply with our obligation under commercial law to have the annual financial statements audited in accordance with Section 316 (1) HGB (German Commercial Code). Furthermore, it is in our interest to cooperate with tax auditors of the tax authorities and to demonstrate proper invoicing and annual financial statements. Documents examined in this context, such as receipts and invoices, may contain your personal data.

  7. As it is in our interest to resolve legal disputes, in such a case we process your data for that specific purpose. It is also in our interest, in the event of legal disputes, to retain evidence until all relevant statutory limitation periods pursuant to Sections 195 et seq. BGB (German Civil Code) have expired. For this purpose, we retain the corresponding data about you in accordance with these limitation periods. The deletion periods cannot be predicted in general terms, as they result from the respective subject matter of the dispute and the corresponding statutory limitation period, which can be up to 30 years. The standard limitation period is 3 years.

  8. Furthermore, it is in our interest to follow up on suspected cases and, in the event of a concrete suspicion of a criminal offense, to hand over relevant information to law enforcement authorities.

  9. We process your data for testing IT systems and software products as well as for carrying out migrations. The processing is carried out in fulfillment of our legitimate interest in verifying the correctness of new products or the correctness and completeness of migrations.

  10. Mistakes can happen to anyone and can occur in any operational process. So that we can optimize these processes and reduce our error rate, we process the data available in our company in order to identify sources of error. This processing is carried out to safeguard our legitimate interest in improving our processes.

Deletion periods

Data processed for the purpose of data security is deleted after 7 days.

Browser sessions are stored in your customer account for a period of 30 days.

Data processed to answer inquiries is deleted as soon as the inquiry has been conclusively dealt with.

Data processed to optimize our websites is deleted after two years.

Data processed for the optimization and billing of our advertising measures is deleted after two years.

Measures derived from reports under the HinSchG and their investigation contain no personal reference, which is why they are not subject to any deletion period. The documentation of a report is deleted 3 years after conclusion of the procedure at the reporting office. In all other respects, the deletion of your data is suspended if it is required for the assertion, defense and exercise of legal claims or in the context of official or court proceedings.

In all other respects, we process your data for as long as it is required for the fulfillment of the respective purposes stated. Where statutory retention periods exist, deletion only takes place after these periods have expired. To safeguard our legal positions and the associated preservation of evidence, retention may be necessary until the expiry of limitation periods pursuant to Sections 195 et seq. BGB. Your data will be deleted as soon as the respective processing purpose has been fulfilled.

Information about automated individual decision-making

No automated individual decision-making takes place.

Which bodies receive your data?

The following list shows which bodies receive your data ("data recipients"). You can read which data is specifically involved in the corresponding chapters of this policy. Your data is disclosed in some cases on the basis of legal or contractual obligations. In other cases, we use selected agents and service providers who act for us as processors (pursuant to Art. 28 GDPR) and may be given access to your data to the extent necessary in each case. Processors are subject to numerous contractual obligations and, in particular, may only process your personal data on our instructions and exclusively for the fulfillment of the orders received from us.

  • Auditors

  • Call centers

  • Data protection officer

  • Service providers for the display of videos

  • Service providers for the optimization and billing of advertising measures

  • Service providers for the destruction of data carriers

  • Service providers for individual appointment scheduling

  • Service providers for mail dispatch

  • Service providers for the optimization of our online presence

  • The recipient's email provider (for communication by email)

  • Tax authorities

  • IT service providers

  • Lawyers, law enforcement authorities, public prosecutor's office, courts, opposing lawyers, State or Federal Criminal Police Office (in the event of legal disputes and concrete suspicion of a criminal offense)

  • Tax advisors

  • Telecommunications service providers (when we communicate by telephone)

  • Postal service providers (for written communication)

  • Statutory auditors

  • Payment service providers and banks

Data recipients in non-EU countries

The following service providers we use in the EU have affiliated companies or subcontractors outside the EU who may access your data: IT service providers, service providers for the display of videos, service providers for the optimization and billing of advertising measures, service providers for the optimization of our online presence. The EU Commission determines which non-EU/EEA countries (third countries) have an adequate level of data protection. The affiliated companies or subcontractors of our IT service providers have either submitted to the so-called Data Privacy Framework (Decision No. C(2923) 4745 final of 10.07.2023), insofar as they are based in the USA; otherwise, our IT service providers are responsible for the use of EU standard contractual clauses in accordance with Commission Decision No. (EU) 2021/914. A template of these EU standard contractual clauses can be found on the websites of the EU Commissioner for Justice and in the Official Journal of the EU.

Your rights

You have the statutory right to:

  • Access to the personal data stored about you (Art. 15 GDPR)

  • Rectification and completion of the data we hold about you (Art. 16 GDPR)

  • Erasure (Art. 17 GDPR)

  • Restriction of processing (Art. 18 GDPR)

  • Data portability (Art. 20 GDPR)

  • Withdrawal of consent given (Art. 7 GDPR) with effect for the future. The lawfulness of the processing of the data carried out up to the time of withdrawal remains unaffected.

  • You also have the right to present your own point of view and to contest a decision based on automated processing (Art. 22 GDPR).

______________________________________________________________

  • You have the right to object to the processing of your data to safeguard our legitimate interests or the legitimate interests of third parties (Art. 21 GDPR) – you have the right to object to such processing at any time on grounds relating to your particular situation; this also applies to profiling based on these provisions within the meaning of Art. 4 (4) GDPR.

  • Objection to direct marketing – You have the right to object at any time and without stating reasons to the processing of your data for the purpose of direct marketing.

______________________________________________________________

To exercise these rights, you can contact us in particular via the contact details given above.

You also have the statutory right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR).

SOCIAL MEDIA PRIVACY POLICY

In the following, we would like to explain what data we collect about you when you visit our presence on social media or professional networks and what we do with this data. We also inform you about your data protection rights and explain who you can contact with questions about the protection of your data.

About us

Controller responsible for the processing of your data:

NAWIDA GmbH
Lindenstraße 11
36269 Philippsthal
[email protected]
+49 30-91734590

Managing directors: Marc Fischer, Jan Tillmann

If you have any questions about this privacy policy, the processing of your data, your rights or other data protection matters, our data protection officer will be happy to help you.

Contact details of the data protection officer:

Xamit Bewertungsgesellschaft mbH
Monschauer Str. 12
40549 Düsseldorf
[email protected]

Scope

This privacy policy applies to the following presences on social media, professional networks and video portals:

  • https://www.youtube.com/channel/UCiWCgRJgscqo-LjQWxllbTg

  • https://www.youtube.com/channel/UCRMI1AUIYA3K97loJ4yqjmw

  • https://www.instagram.com/nawida_gmbh

  • https://www.linkedin.com/showcase/praidict

  • https://www.linkedin.com/showcase/contentscoring

  • https://www.linkedin.com/showcase/fahrhalt-app

  • https://www.linkedin.com/showcase/nawida-hr/about

  • https://www.linkedin.com/company/nawida-gmbh

and is addressed to the visitors of these presences, insofar as postings by us or by visitors, the writing and answering of direct messages, and the commissioning and management of advertising measures are concerned. The respective operator is responsible for the other processing operations on the platform.

When you visit our presence on the operator's platform or interact with it, the operator of the platform processes your personal data for its own purposes, which differ from those described in our privacy information. Further details can be found in the privacy information of the respective operator. If you contact us in the context of your rights listed below (see chapter "Your rights"), we will forward your request to the operator of this platform if your request relates to its activities.

This privacy information therefore does not apply to other domains of Meta Platforms Ireland Limited (hereinafter "Meta", responsible for the platforms Facebook and Instagram), LinkedIn Ireland Unlimited Company (hereinafter "LinkedIn"), Google Ireland Limited (hereinafter "Google", responsible for the platform YouTube) or domains of companies affiliated with these companies, or to the data processing carried out by these companies. For information on data processing by the operators mentioned, please refer to the corresponding privacy notices and terms of use of these operators.

Our page contains links leading to the websites of other operators, to which this privacy policy does not apply.

Responsibility for the display of advertising banners, text advertising or advertising videos before or during embedded videos lies with the respective operator.

Do I have to provide my data?

We offer you the opportunity to get in touch with us. It is up to you to decide freely whether you wish to make use of this option and provide your data. To process your inquiry, we process the personal data that you have sent to us, for example, by email or private message, posted on the timeline or communicated in a chat. The data you post on the timeline is publicly visible. Your data and details will be passed on to third parties if this is necessary for processing.

Please note that if you provide information about other persons, you must first have obtained their consent and informed them about the purposes of the disclosure as set out in this privacy policy.

We also ask you to pass this information on to the persons you involve in the use of our services, such as family members or authorized representatives.

Processing purposes, processed data and legal bases

Processing of inquiries and comments: We process your data that we receive through your comment or your message to us (including by email) or when you like, follow or similarly interact with our page. This includes the data that you provide to us yourself as well as the data that the social network or professional network displays to us as part of your public profile. The processing is based on our legitimate interest in answering your questions and concerns (Art. 6 (1) (f) GDPR).

Network maintenance: We process your data about your activities in order to expand our network, communicate with you, and analyze our market and target groups. The processing is carried out to safeguard our legitimate interest in improving our corporate and sales strategy (Art. 6 (1) (f) GDPR).

Processed data:

Data

Processing of inquiries and comments

Network maintenance

Salutation

x

x

First name and surname or username

x

x

Email address

x

x

Topic

x

x

Message and timestamp

x

x

Profile picture

x

x

Public profile/channel

x

x

Activities, postings within the network

x

Like or other reaction/interaction

x

x

In addition, the data mentioned above is used for the following purposes on the basis of a balancing of interests (Art. 6 (1) (f) GDPR). The interests are named below:

  1. Should a security incident occur in our company in which your data is affected, we are obliged to report the case to the data protection supervisory authority responsible for us (Art. 33 GDPR). As it is our legitimate interest to comply with this statutory reporting obligation as quickly as possible, data relating to you may be processed in the course of investigating the security incident in question. The reports of these security incidents to data protection supervisory authorities do not contain any of your personal data.

  2. As it is in our interest to ensure the security of our systems, we regularly carry out security and effectiveness tests, in the course of which your data mentioned above may be processed.

  3. As it is in our interest to resolve legal disputes, in such a case we process your data for that specific purpose. It is also in our interest, in the event of legal disputes, to retain evidence until all relevant statutory limitation periods pursuant to Sections 195 et seq. BGB have expired. For this purpose, we retain the corresponding data about you in accordance with these limitation periods. The deletion periods cannot be predicted in general terms, as they result from the respective subject matter of the dispute and the corresponding statutory limitation period, which can be up to 30 years. The standard limitation period is 3 years.

  4. Furthermore, it is in our interest to follow up on suspected cases and, in the event of a concrete suspicion of a criminal offense, to hand over relevant information to law enforcement authorities.

  5. We carry out audits, internal reviews and other control measures (e.g. monitoring by the data protection officer), as it is our legitimate interest to comply with legal requirements, to create transparency about our business processes, to continuously optimize these processes, and to prevent and detect actions that are damaging to the business. In doing so, documents or files containing your personal data may be processed.

Information about automated individual decision-making

No automated individual decision-making takes place.

Deletion periods (or storage duration)

  • Data processed to answer inquiries is deleted as soon as the inquiry has been conclusively dealt with.

  • You can delete your public comments, "likes" and other reactions yourself at any time, provided the respective platform allows this.

  • To preserve evidence, we retain data within the framework of the statutory limitation provisions pursuant to Sections 195 et seq. BGB. The storage period of your data may therefore exceed the duration stated above. The statutory limitation periods can be up to 30 years. The standard limitation period is 3 years.

Origin of the data

No data is collected from third parties.

Which bodies receive your data?

The following list shows which bodies (or "data recipients") receive your data in which cases. You can read which data is specifically involved in the corresponding chapters of this policy. Your data is disclosed in some cases on the basis of legal or contractual obligations. In other cases, we use selected agents and service providers who act for us as processors (pursuant to Art. 28 GDPR) and may be given access to your data to the extent necessary in each case. Processors are subject to numerous contractual obligations and, in particular, may only process your personal data on our instructions and exclusively for the fulfillment of the orders received from us.

  • Auditors

  • Operator of the platform used

  • Data protection officer

  • Service providers for the destruction of data carriers

  • The recipient's email provider (for communication by email)

  • IT service providers

  • Lawyers, law enforcement authorities, public prosecutor's office, courts, opposing lawyers, State or Federal Criminal Police Office (in the event of legal disputes and concrete suspicion of a criminal offense)

  • Telecommunications service providers (when we communicate by telephone)

  • Postal service providers (for written communication)

Data recipients in non-EU countries

Our IT service providers in the EU have affiliated companies or subcontractors outside the EU who may access your data. The EU Commission determines which non-EU/EEA countries (third countries) have an adequate level of data protection. The affiliated companies or subcontractors of our IT service providers have either submitted to the so-called Data Privacy Framework (Decision No. C(2923) 4745 final of 10.07.2023), insofar as they are based in the USA; otherwise, our IT service providers are responsible for the use of EU standard contractual clauses in accordance with Commission Decision No. (EU) 2021/914. A template of these EU standard contractual clauses can be found on the websites of the EU Commissioner for Justice and in the Official Journal of the EU.

Your rights

You have the statutory right to:

  • Access to the personal data stored about you (Art. 15 GDPR)

  • Rectification and completion of the data we hold about you (Art. 16 GDPR)

  • Erasure (Art. 17 GDPR)

  • Restriction of processing (Art. 18 GDPR)

  • Data portability (Art. 20 GDPR)

  • Withdrawal of consent given (Art. 7 GDPR) with effect for the future. The lawfulness of the processing of the data carried out up to the time of withdrawal remains unaffected.

  • You also have the right to present your own point of view and to contest a decision based on automated processing (Art. 22 GDPR).

  • You have the right to object to the processing of your data to safeguard our legitimate interests or the legitimate interests of third parties (Art. 21 GDPR) – you have the right to object to such processing at any time on grounds relating to your particular situation; this also applies to profiling based on these provisions within the meaning of Art. 4 (4) GDPR.

  • Objection to direct marketing – You have the right to object at any time and without stating reasons to the processing of your data for the purpose of direct marketing.

To exercise these rights, you can contact us in particular via the contact details given above.

You also have the statutory right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR).

Services

  • Digital Sales & E-Commerce
  • Digital Performance
  • Stabilization & Realignment
  • Website Audit

Company

  • Imprint
  • Privacy Policy
  • Terms & Conditions
  • Grounding
BSFZ seal R&D 2026 - German Research Allowance Certification Office

Research that shapes the future. We develop innovative solutions that move mid-sized businesses forward.

Magazine (DE)

Knowledge & Insights

Digital Visibility

  • Vier Säulen der Online-Sichtbarkeit
  • Technisch saubere Frontends
  • Social SEO: Instagram & Co.

Digitalization

  • Digitalisierung im Mittelstand
  • Förderung „Digital Jetzt“
  • Glossar Digitalisierung & KI
  • PCI DSS 4.0

Artificial Intelligence

  • KI-Anwendungsbereiche
  • KI – Was jetzt wichtig ist
  • AI-Act & KI-Regulierung

Market Analysis

  • Methoden & Tools
  • User-Story: PRAIDICT

Digital Marketplaces

  • Spezialisierte Marktplätze

Copyright 2026 NAWIDA GmbH