Data Protection Statement
Data protection statement of turingpoint GmbH from Hamburg
Controller
turingpoint GmbH
Neuer Wall 80
20354 Hamburg
Email: [email protected]
Managing Directors: Jan Kahmen, Till Oberbeckmann
Imprint: turingpoint.de/en/company/legal-disclosure/
Overview of Data Processing
What Data We Process
We only process personal data to the extent necessary for providing our website and services. This includes:
- Master and contact data (e.g. name, address, email, phone number)
- Usage data (e.g. pages visited, access times)
- Content data (e.g. form entries)
- Technical data (e.g. IP address, browser type, operating system)
- Contract data (e.g. subject matter, term, customer category)
- Payment data (e.g. bank details, invoices)
Data Subjects
Visitors to our website, customers, business partners, applicants, and interested parties.
Purposes
- Provision and operation of our website
- Processing inquiries and communication
- Provision of contractual services
- Security and abuse prevention
- Analysis and optimization of our offering
- Compliance with legal obligations
Legal Bases
Our data processing is based on the following legal bases under the GDPR:
- Consent (Art. 6(1)(a)): When you have given your explicit consent, e.g. for analytics tools.
- Contract performance (Art. 6(1)(b)): Where processing is necessary for the performance of a contract or pre-contractual measures.
- Legal obligation (Art. 6(1)(c)): Where legal obligations require processing, e.g. tax retention requirements.
- Legitimate interests (Art. 6(1)(f)): Where processing is necessary for our legitimate interests, e.g. the secure operation of our website.
Processing of special categories of data (Art. 9(1) GDPR) only takes place under the conditions of Art. 9(2) GDPR.
Your Rights
As a data subject, you have the following rights:
- Access (Art. 15 GDPR): You may request information about your data stored with us.
- Rectification (Art. 16 GDPR): You may request correction of inaccurate data.
- Erasure (Art. 17 GDPR): You may request deletion of your data, provided no statutory retention obligations apply.
- Restriction (Art. 18 GDPR): You may request restriction of processing.
- Data portability (Art. 20 GDPR): You may receive your data in a commonly used, machine-readable format.
- Objection (Art. 21 GDPR): You may object to the processing of your data based on Art. 6(1)(e) or (f) GDPR at any time. This also applies to profiling based on these provisions. If your data is processed for direct marketing, you may object at any time.
- Withdrawal: You may withdraw any consent given at any time with effect for the future.
- Complaint: You have the right to lodge a complaint with a data protection supervisory authority.
Data Security
We employ technical and organizational measures to adequately protect your data. These include encryption of data transmission, access controls, and regular review of our security measures. We take data protection into account from the design stage of our systems (Privacy by Design).
Processors and Third Parties
Where we engage service providers as processors, this is done on the basis of appropriate contracts pursuant to Art. 28 GDPR. Within our group of companies, data may be shared for administrative purposes as a legitimate interest. Details on individual services can be found in the following sections.
Data Transfers to Third Countries
Some of our service providers are based outside the EU/EEA, particularly in the USA. Transfers are made on the basis of adequacy decisions, EU Standard Contractual Clauses (SCCs), or certifications under the EU-US Data Privacy Framework (DPF). Further details can be found under the respective services.
Cookies
This website does not set any cookies of its own. Embedded third-party services (e.g. embedded videos) may set cookies. You can manage or delete cookies at any time in your browser settings.
Hosting and Infrastructure
Cloudflare Pages
Our website is hosted via Cloudflare Pages. The provider is Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. As a Content Delivery Network (CDN), Cloudflare ensures the delivery of our website and processes technical access data (e.g. IP address, browser type) in the process. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a secure and performant website). Cloudflare is certified under the EU-US DPF and additionally employs SCCs. Privacy policy: https://www.cloudflare.com/security-policy
Communication and Contact
Contact Form and Email
When you contact us via the contact form or email, we process your information to handle your inquiry. Legal basis: Art. 6(1)(b) GDPR (pre-contractual/contractual measures) or Art. 6(1)(f) GDPR (legitimate interest in processing inquiries). Your data may be stored in a CRM system. Inquiries are deleted once they are no longer needed. Necessity is reviewed every two years.
Email Dispatch via Resend
For sending emails from our contact form, we use Resend (Resend, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA). When you use our contact form, your entries (name, email, message) are transmitted to us via Resend. Resend acts as a processor pursuant to Art. 28 GDPR. Legal basis: Art. 6(1)(b) or (f) GDPR. Data transfer to the USA is based on SCCs. Privacy policy: https://resend.com/legal/privacy-policy
Appointment Booking
You can book appointments via our website (https://cal.turingpoint.de/till/sales). For this, we operate self-hosted scheduling software (cal.diy) in a data center of kyberio GmbH (Am Mittelfelde 29, 30519 Hannover, Germany). Your booking data is not transferred to Cal.com, Inc. (USA). When you book, we process the data you provide (e.g. name, email address, phone number, preferred appointment). Legal basis: Art. 6(1)(b) or (f) GDPR. kyberio GmbH acts as a processor pursuant to Art. 28 GDPR.
Embedded Third-Party Content
When embedding external content (e.g. videos, fonts), the transmission of your IP address to the respective provider is technically necessary. We endeavor to only use services that process your data in compliance with data protection law. Third-party providers may also use tracking technologies (e.g. pixel tags) for statistical purposes. Legal basis: Art. 6(1)(f) GDPR.
YouTube
We embed videos from YouTube (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). When playing a video, data may be transmitted to Google. Privacy policy: https://www.google.com/policies/privacy/. Opt-out: https://adssettings.google.com/authenticated
Social Media
We maintain company profiles on social networks to communicate with customers and interested parties. User data may also be processed outside the EU. Platform operators may create usage profiles and use cookies. Legal basis: Art. 6(1)(f) GDPR. Data subject rights can be exercised most effectively directly with the respective provider.
- LinkedIn (LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland) - Privacy policy: https://www.linkedin.com/legal/privacy-policy, Opt-out: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out
- Xing (XING SE, Dammtorstraße 30, 20354 Hamburg, Germany) - Privacy policy: https://privacy.xing.com/de/datenschutzerklaerung
- GitHub (GitHub, Inc., 88 Colin P. Kelly Jr St, San Francisco, CA 94107, USA) - Privacy policy: https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement
Job Applications
Applications can be submitted by email to [email protected] or by postal mail. Please note that emails on the internet are generally not encrypted end-to-end.
Legal basis: Art. 6(1)(b) GDPR (pre-contractual relationship). For special categories of data (Art. 9(1) GDPR), Art. 9(2)(b), (c), and (h) GDPR apply. In Germany, §§ 22, 26 BDSG additionally apply.
Applicant data is deleted no later than six months after an unsuccessful application, unless legitimate reasons for longer retention exist. Invoices for travel expense reimbursement are archived in accordance with tax law requirements.
Business Data Processing
In the course of our business activities, we process contract, payment, and contact data of our customers and business partners. Purposes: contract performance, customer care, accounting, office organization, and compliance with legal obligations. Legal bases: Art. 6(1)(b), (c), and (f) GDPR. Data is shared with tax advisors, auditors, and payment service providers as required. Business partner data is generally stored permanently based on our legitimate interests.
For business optimization, we analyze business data. Personal evaluations are deleted or anonymized upon contract termination, at the latest after two years. Overall business analyses are prepared anonymously wherever possible.
Data Deletion
We delete personal data once the processing purpose ceases to apply and no statutory retention obligations (e.g. under commercial or tax law) prevent deletion. Where such obligations exist, processing is restricted to retention only.
Currency of This Privacy Policy
We update this privacy policy as needed when changes to our data processing require it. If changes require your participation (e.g. renewed consent), we will inform you separately.
