top of page

Data protection

§ 1 General information about the collection of your personal data

(1) With this privacy policy, we inform you about which of your personal data is collected, processed, and stored when using the website. Personal data is individual information about the personal or factual circumstances of a specific or identifiable natural person. This includes, for example, information such as your first and last name, address, email address, or your user behavior when using the website.

(2) The controller within the meaning of the BDSG and pursuant to Art. 4 No. 7 EU General Data Protection Regulation (GDPR) is CT23 GmbH, Lilienthalallee 7, 80807 Munich, Germany, Email: info@ct-23.com (see our imprint). You can reach our data protection officer at the email address: datenschutz@ct-23.com.

§ 2 Your rights

(1) You can assert the following rights regarding your personal data against us: Right to access (Art. 15 GDPR), rectification (Art. 16 GDPR) or erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR), objection to processing (Art. 21 GDPR); see also the following note on the right of objection under Art. 21 GDPR; right to withdraw a given consent at any time without affecting the lawfulness of processing based on consent before its withdrawal, if the data processing is based on consent according to Art. 6 para. 1 lit. a or Art. 9 para. 2 lit. a GDPR; right to data portability (Art. 20 GDPR).

Note on the right of objection under Art. 21 GDPR
You have the right to object at any time, for reasons arising from your particular situation, to the processing of your personal data that is based on Art. 6 para. 1 lit. e or f GDPR (Art. 21 para. 1 GDPR). If we process your personal data for direct marketing purposes according to Art. 6 para. 1 f GDPR, you have the right to object to this processing at any time without giving reasons (Art. 21 para. 2 GDPR). We will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or the processing is for the establishment, exercise, or defense of legal claims. The right of objection can be exercised informally, for example by post or email to the contact details provided in the imprint or in § 1 para. 2 of this privacy policy.

(2) You also have the right to lodge a complaint with a data protection supervisory authority regarding our processing of your personal data (Art. 77 GDPR). The competent supervisory authority is the Bavarian Data Protection Authority, Promenade 27, 91522 Ansbach, Germany, Phone: +49 (0) 981 53 1300, Fax: +49 (0) 981 53 98 1300, Email: poststelle@lda.bayern.de.

§ 3 Collection, processing, and use of personal data during purely informational use

(1) If you visit our website without providing any personal information, we do not know who you are. In this case, we only receive communication data via your browser without specific personal reference. We collect the following data in this case: IP address, date and time of the request, access status/HTTP status code, amount of data transferred, browser, operating system and its interface, language and version of browser software, website from which the request comes, content of the request, time zone difference to GMT. This is done to the extent that it is technically necessary to enable access to our website and to provide the services and features you use on our website, to analyze, tailor, and improve our services, content, and advertisements, and to ensure stability and security. The legal basis is Art. 6 para. 1 sentence 1 lit. f GDPR. The data is stored for a period of 6 months and then automatically deleted.

(2) Furthermore, cookies are stored on your computer when you use the website. Cookies are small text files that are stored on your hard drive associated with the browser you use and through which certain information is transmitted to the entity that sets the cookie (in this case, us). A cookie typically contains the domain name it originated from, the "lifetime" of the cookie, and a value, usually a randomly generated unique number. Cookies cannot run programs or transmit viruses to your computer. The purpose of using cookies is to make our website more user-friendly and effective overall. Some elements of our website require that the calling browser be recognized even after a page change.

(3) The following cookies are used on our website:
Transient cookies (session cookies)
Session cookies are temporary cookies that remain in the browser's cookie file until the user leaves the website, i.e., they are automatically deleted after the end of the browser session or after closing your browser. They store a session ID that can be used to assign various requests from your browser to the session and are essential to enable the use of the website.
Persistent cookies in connection with Google Analytics, as described below. Persistent cookies are automatically deleted after a specified period, which can vary depending on the cookie. You can delete the cookies at any time in your browser's security settings.

(4) You can configure your browser settings to be informed about the setting of cookies and to decide individually whether to accept them, or to exclude the acceptance of cookies for specific cases or in general. If you do not accept cookies, the functionality of our website may be limited.

(5) This stored information is kept separate from any other data provided to us. In particular, the cookie data is not linked with your other data, if such data is provided.

§ 4 Collection of personal data during personalized use; in particular, contact form and applications

(1) In addition to purely informational use of our website, we offer various services that you can use if interested. For this, you generally need to provide additional personal data that we use to provide the respective service. If additional voluntary information is possible, it is marked accordingly. We only collect, process, and use those personal data that are necessary for your use of the website, to respond to a request, and/or to fulfill a contract concluded with us, or that you provide voluntarily. These include especially the following inventory and usage data, which may be transmitted via forms on our website: first and last name (including salutation, title, first name, last name), name of the company/institution, address, and email address.

(2) If you contact us via email or a contact form, we store the data you provide in order to answer your questions and for follow-up questions. A valid email address is required so we know who the request came from and to be able to respond. Additional information may be provided voluntarily. Your inquiries are stored for one year after the response. If these are business letters under commercial or tax law, we retain the correspondence for the legally prescribed periods (usually six years).

§ 5 Transmission of personal data to third parties

(1) We use external service providers or other services, specifically hosting providers, statistics and analytics services, as well as IT maintenance and development service providers.

(2) We comply with all data protection regulations and bind our service providers to do the same, where necessary.

(3) Otherwise, we do not share your personal data unless, exceptionally, an authority is legally entitled to request the data, for example for law enforcement or public safety purposes.

(4) The aforementioned processing may also involve the transfer of data to recipients outside the European Union (see below, Google Analytics). The data transfer is carried out according to the principles of the so-called Privacy Shield (https://www.privacyshield.gov/welcome) or based on the so-called standard contractual clauses of the EU Commission (http://ec.europa.eu/justice/data-protection/international-transfers/transfer/index_en.htm).

§ 6 Use of Google Analytics

(1) This website uses Google Analytics if its use is enabled under the website's privacy settings (sub-item analytics cookies). This is a web analytics service provided by Google Inc. ("Google"). Google Analytics uses "cookies", text files stored on your computer that allow an analysis of your use of the website. The information generated by the cookie about your use of this website is usually transmitted to a Google server in the USA and stored there. If IP anonymization is activated on this website, your IP address will be truncated by Google within member states of the European Union or in other states party to the Agreement on the European Economic Area before being transmitted. Only in exceptional cases is the full IP address transmitted to a Google server in the USA and truncated there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, compile reports on website activity, and provide other services related to website and internet usage.

(2) The IP address transmitted by your browser within the scope of Google Analytics is not merged with other data from Google.

(3) You can prevent the storage of cookies by adjusting your browser software settings; however, please note that in this case, you may not be able to fully use all the features of this website. You can also prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) by Google as well as the processing of this data by Google by downloading and installing the browser plugin available at the following link:
http://tools.google.com/dlpage/gaoptout?hl=de
This sets an opt-out cookie that prevents future data collection when you visit this website. Please note that the opt-out cookie must be reset if all cookies are deleted. Opt-out cookies prevent future data collection when visiting this website. To prevent data collection across devices, the opt-out must be carried out on all systems used.

(4) This website uses Google Analytics with the extension “_anonymizeIp()”. As a result, IP addresses are processed in a truncated form, which excludes direct personal reference. If the data collected about you has a personal reference, this is immediately excluded, and the personal data is promptly deleted.

(5) We use Google Analytics to analyze and improve the use of our website. The legal basis for the use of Google Analytics is Art. 6 para. 1 sentence 1 lit. f GDPR. Furthermore, by using this website, you consent to the processing of data about you collected by Google in the manner and for the purposes described above. The personally identifiable data collected by Google linked to cookies, user ID, or advertising ID will be automatically deleted after 14 months.

(6) Information about the third-party provider: Google Dublin, Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland, Fax: +353 (1) 436 1001. Terms of use: http://www.google.com/analytics/terms/de.html, Privacy overview: http://www.google.com/intl/de/analytics/learn/privacy.html, Privacy policy: http://www.google.de/intl/de/policies/privacy. Google is subject to the EU-US Privacy Shield, https://www.privacyshield.gov/EU-US-Framework.

§ 7 LinkedIn

(1) Our company operates an online presence on LinkedIn. Provider is LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland.
This is a subsidiary of LinkedIn Corporation, 1000 W. Maude Avenue, Sunnyvale, CA 94085, USA.

(2) If its use is enabled under the privacy settings of the website (sub-item analytics cookies), it is possible that user data may be processed outside the European Union, specifically in the USA. This may make later access to user data more difficult. We ourselves do not have access to this user data; this is exclusively held by LinkedIn.
LinkedIn privacy policy: https://www.linkedin.com/legal/privacy-policy

§ 8 Protection of personal data

We take technical and organizational measures in accordance with the requirements of Art. 32 GDPR to protect the user's personal data. All our employees involved in processing personal data are obliged to maintain data confidentiality. Personal data is encrypted via HTTPS when transmitted to the website.

§ 9 Legal bases

In accordance with Art. 13 GDPR, we inform you of the legal bases for our data processing.
Where we obtain consent from the data subject for processing operations involving personal data, Art. 6 para. 1 lit. a GDPR serves as the legal basis.
When processing personal data necessary for the performance of a contract to which the data subject is party, Art. 6 para. 1 lit. b GDPR serves as the legal basis. This also applies to processing operations required for pre-contractual measures.
Where processing of personal data is necessary to fulfill a legal obligation to which our company is subject, Art. 6 para. 1 lit. c GDPR serves as the legal basis.
The legal basis for the temporary storage of data and log files is Art. 6 para. 1 lit. f GDPR.
The legal basis for processing personal data using technically necessary cookies is Art. 6 para. 1 lit. f GDPR.
If processing is necessary to safeguard a legitimate interest of our company or a third party, and this interest is not overridden by the interests or fundamental rights and freedoms of the data subject, Art. 6 para. 1 lit. f GDPR serves as the legal basis.

§ 10 No automated decision-making / no profiling

We do not carry out automated decision-making or profiling.

§ 11 Changes to this privacy policy

(1) If it becomes necessary to adapt or amend the content of this privacy policy, we reserve the right to do so. We will send the affected person the amended version before it comes into force and publish the updated privacy policy.

(2) You can prevent the storage of the cookies mentioned on your PC through appropriate settings in your internet browser. However, this may limit the usability of this website's content. By using this website, you consent to the processing of data collected about you by Google in the manner and for the purpose described above.

bottom of page