Privacy Policy

I. General information

We collect various types of data on our websites. Some data is collected automatically when you use our services, for example through the use of so-called cookies. This automatically collected data is mostly of a general nature and primarily includes information regarding the duration and location of access.

In addition, with your consent, we collect personal data and data that you voluntarily provide when you wish to use certain services. It is possible to use our website without providing personal data, but the scope of use may be significantly limited in some cases.

You decide whether to consent to the use of various purposes and service providers the first time you visit our website. With the exception of processing that is absolutely necessary for the operation of the website, it is up to you to determine which data processing you permit.

Due to numerous regulatory changes, a comprehensive body of data protection regulations has emerged in recent years. While these regulations are intended to ensure data security and strengthen user rights, they have also generated a flood of relevant terms. To make the following detailed explanations regarding collected data, legal regulations, and rights more accessible, we have briefly summarized the most important of these terms below.

Definitions

In our privacy policy, we use terms that are used in the GDPR and defined therein. To help you understand what these terms mean, we would like to explain the most important ones.

Processor

A data processor is a natural or legal person, public authority, agency, or other body that processes personal data on behalf of the data controller in accordance with its instructions.

Consent banner

As a user, you have the option to give your consent to processing activities that require consent and to revoke this consent in the future. You make this decision via the so-called consent banner, which is automatically displayed when you first visit our websites and provides you with the most important information regarding data processing.

Cookies

Cookies are text files that contain data from visited websites or domains and are stored by a browser on users’ devices. A cookie primarily serves to store information about a user during or after their visit to an online service. The stored information may include, for example, language settings on a website, login status, a shopping cart, or video interactions. The term “cookies” also encompasses other technologies that perform the same functions as cookies (e.g., when user information is stored using pseudonymous online identifiers, also known as “user IDs”). Cookies are used to make websites more user-friendly. Since cookies are stored on the user’s computer, you have control over them. You can adjust settings in your web browser to manage the use and storage of cookies. However, disabling cookies will in most cases result in limited functionality of our website.

Third Party

A third party is a natural or legal person, public authority, agency, or other body, other than the data subject, the controller, the processor, and the persons who, under the direct authority of the controller or the processor, are authorized to process the personal data.

Consent

Consent is an expression of self-determination under data protection law. It is the freely given, specific, informed, and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her. Consent given may be withdrawn at any time with effect for the future.

Recipient

A recipient is a natural or legal person, public authority, agency, or other body to whom personal data is disclosed, regardless of whether it is a third party or not. However, public authorities that may receive personal data in the course of a specific investigative mandate under Union law or the law of the Member States are not considered recipients.

Personal data

Personal data means any information relating to an identified or identifiable natural person (hereinafter referred to as the “data subject”). A natural person is considered identifiable if they can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. IP address or cookies) or to one or more specific characteristics that express the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.

Pseudonymization

Pseudonymization is the processing of personal data in such a way that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that this additional information is kept separately and is subject to technical and organizational measures that ensure the personal data is not attributed to an identified or identifiable natural person.

Telecommunications and Telemedia Data Protection Act (TDDDG)

The TDDDG is a law designed to protect the integrity of the end device and, thereby, the privacy of users. The legal basis for storing and retrieving information on the end user’s device is consent, pursuant to Section 25(1), sentence 1 of the TDDDG. This consent is requested when the website is accessed.

Pursuant to Section 25(2)(2) of the TDDDG, consent is not required if the storage of information on the end user’s terminal device or access to information already stored on the end user’s terminal device is absolutely necessary for the provider of a telemedia service to provide a telemedia service expressly requested by the user. You can see in the cookie settings which cookies are classified as strictly necessary (often referred to as “technically necessary cookies”), and therefore fall under the exception in Section 25(2) of the TDDDG and thus do not require consent.

Please note that the legal basis for the subsequent processing of personal data is derived from the GDPR. The relevant legal bases for the processing of personal data on this website are provided later in this privacy notice.

Processing

Processing refers to any operation or set of operations performed on personal data, whether or not by automated means. This essentially includes any handling of personal data, such as the collection, storage, modification, use, transmission, dissemination, erasure, or destruction of personal data.

Controller

The controller is the natural or legal person, public authority, agency, or other body that, alone or jointly with others, determines the purposes and means of the processing of personal data. The controller must ensure the lawfulness of data processing through the implementation of technical and organizational measures that are regularly reviewed

Data transfer outside the EU

The GDPR ensures a uniformly high level of data protection within the European Union. When selecting our service providers, we therefore rely on European partners whenever possible if your personal data is to be processed. Only in exceptional cases will we have data processed outside the European Union in connection with the use of third-party services.

We only permit the processing of your data in a third country if the specific requirements of Articles 44 et seq. of the GDPR are met. This means that the processing of your data may then only take place on the basis of specific safeguards, such as the EU Commission’s official recognition of a level of data protection equivalent to that of the EU, or compliance with officially recognized specific contractual obligations, known as “Standard Data Protection Clauses.”

II. Data Automatically Collected When Using Our Website

If you only use the website for information purposes, i.e. if you do not When using the website for informational purposes only—that is, if you do not register or otherwise provide us with information—we collect only the personal data that your browser transmits to our server. This data will not be combined with other data sources without your consent.

When you visit our website, we collect the following data, which is technically necessary for us to display our website to you and to ensure its stability and security:

– Your IP address,

– Date and time of the request,

– The directory protection user,

– The pages accessed,

– logs,

– The status code,

– The amount of data transferred,

– The referrer URL (last visited website),

– The user agent (browser),

– The hostname accessed.

The temporary storage of the IP address by our system is necessary to enable the website to be delivered to the user’s computer. For this purpose, the user’s IP address must remain stored for the duration of the session.

The temporary storage and processing of this so-called server log data is absolutely necessary to ensure functionality and technical security, in particular to prevent and defend against attacks or attempts to cause damage, and is carried out based on our legitimate interest pursuant to Art. 6(1)(f) GDPR.

The data we store is automatically deleted after 30 days.

III. Your (Data Subject) Rights

Under the EU General Data Protection Regulation, you, as a data subject, have various rights that you can exercise by contactingsupport@conreri.de . These are outlined below:

Right of access

You may request confirmation from us as to whether personal data concerning you is being processed by us. If such processing is taking place, you may request the following information from us:

– the purposes for which the personal data is processed;

– the categories of personal data being processed;

– the recipients or categories of recipients to whom your personal data has been or will be disclosed;

– the planned duration of the storage of your personal data or, if specific details cannot be provided, the criteria for determining the storage period;

– the existence of a right to rectification or erasure of your personal data, a right to restrict processing by the controller, or a right to object to such processing;

– the existence of a right to lodge a complaint with a supervisory authority

– all available information regarding the origin of the data, if the personal data is not collected from the data subject;

– the existence of automated decision-making, including profiling, pursuant to Article 22(1) and (4) of the GDPR and—at least in these cases—meaningful information regarding the logic involved, as well as the significance and intended consequences of such processing for the data subject.

In addition, you have the right to request information regarding whether your personal data is transferred to a third country or to an international organization. In this context, you may request to be informed of the appropriate safeguards pursuant to Article 46 of the GDPR in connection with the transfer.

You also have the right to request that we rectify or complete your personal data if it is inaccurate or incompleteete.

Right to lodge a complaint with the supervisory authority

If you believe that the processing of your personal data violates the GDPR, you have the right to lodge a complaint with the supervisory authority responsible for us:

State Commissioner for Data Protection and Freedom of Information, North Rhine-Westphalia

Kavalleriestr. 2-4

40213 Düsseldorf

Tel.: 0211/38424-0

Email:poststelle@ldi.nrw.de

The supervisory authority to which the complaint was submitted will inform you of the status and outcome of the complaint, including the possibility of a judicial remedy under Article 78 of the GDPR.

Right to restriction of processing

You may request the restriction of the processing of your personal data under the following conditions:

– if you contest the accuracy of your personal data for a period that allows the controller to verify the accuracy of the personal data;

– the processing is unlawful and you oppose the erasure of the personal data and instead request the restriction of the use of the personal data;

– we no longer need the personal data for the purposes of processing, but you need it to assert, exercise, or defend legal claims; or

– if you have objected to the processing pursuant to Art. 21(1) GDPR and it has not yet been determined whether our legitimate grounds override your grounds.

If the processing of your personal data has been restricted, such data may, apart from storage, be processed only with your consent or for the establishment, exercise, or defense of legal claims or to protect the rights of another natural or legal person or for reasons of an important public interest of the Union or of a Member State. If processing has been restricted in accordance with the above conditions, we will notify you before the restriction is lifted.

Right to erasure

You may request that we erase your personal data without undue delay, and we are obligated to erase such data without undue delay if any of the following grounds apply:

– Your personal data is no longer necessary for the purposes for which it was collected or otherwise processed;

– You withdraw your consent on which the processing was based pursuant to Art. 6(1)(a) or Art. 9(2)(a) of the GDPR, and there is no other legal basis for the processing;

– You object to the processing pursuant to Article 21(1) of the GDPR and there are no overriding legitimate grounds for the processing, or you object to the processing pursuant to Article 21(2) of the GDPR;

– Your personal data has been processed unlawfully;

– The erasure of your personal data is necessary for compliance with a legal obligation under Union law or the law of the Member States to which the controller is subject;

– Your personal data was collected in relation to information society services offered pursuant to Article 8(1) of the GDPR.

The right to erasure does not apply if the processing is necessary:

– to exercise the right to freedom of expression and information;

– to comply with a legal obligation which requires processing under Union or Member State law to which the controller is subject, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;

– for reasons of public interest in the area of public health pursuant to Article 9(2)(h) and (i) and Article 9(3) of the GDPR;

– for archiving purposes in the public interest, scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, insofar as the right referred to in section (a) is likely to render impossible or seriously impair the achievement of the objectives of such processing, or for the establishment, exercise, or defense of legal claims.

If you have exercised your right to rectification, erasure, or restriction of processing against us, we are obligated to notify all recipients to whom your personal data has been disclosed of such rectification, erasure, or restriction of processing, unless this proves impossible or involves disproportionate effort.

Right to Data Portability

You have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format. You also have the right to transmit this data to another controller without hindrance from us, provided that

– the processing is based on consent pursuant to Art. 6(1)(a) GDPR or Art. 9(2)(a) GDPR or on a contract pursuant to Art. 6(1)(b) GDPR and

– the processing is carried out by automated means.

In exercising this right, you also have the right to have your personal data transmitted directly by us to another controller, provided this is technically feasible. The freedoms and rights of other individuals must not be adversely affected by this. The right to data portability does not apply to the processing of personal data necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.

IV. Further data processing

Passing on to other proficiency testing organisers

Contact

You may contact us via the contact form or the provided email address. In this case, the user’s personal data transmitted via email or the contact form will be stored. The mandatory data processed via the contact form are:

– Your name,

– Your email address,

– Your company,

– Your phone number,

– Your address,

– Your message.

The following data is also stored when the message is sent:

– The user’s IP address,

– The user agent.

Your data will not be disclosed to third parties in this context; the data is used exclusively for the purpose of processing the communication.

The processing of personal data in this context serves solely to handle the contact request. The legal basis for processing the contact request and its handling is generally Article 6(1)(b) of the GDPR, and additionally Article 6(1)(f) of the GDPR.

Your data will be deleted as soon as it is no longer necessary to achieve the purpose for which it was collected. For personal data entered in the contact form and data sent via email, this is the case once the respective conversation with the user has ended. The conversation is considered ended when it can be inferred from the circumstances that the matter in question has been conclusively resolved.

Application Process

You have the option of applying to us via email or our applicant portal. In this context, the personal data you provide will be processed for the purpose of conducting the application process. The data that must be provided typically includes:

– Your first and last name,

– your email address,

– your application documents (in particular your resume and cover letter).

In addition, depending on the application, other personal data may be processed, such as:

– Your phone number,

– references, certificates, and proof of qualifications,

– details of your professional experience,

– salary expectations,

– earliest possible start date,

– and any other information you voluntarily provide.

Your data will not be disclosed to third parties under any circumstances. Within our company, only those individuals involved in the application process will have access to your data.

If we engage external service providers as part of the application process, this will be done exclusively in accordance with applicable data protection laws.

The processing of your personal data serves exclusively to conduct and manage the application process and to make a decision regarding the establishment of an employment relationship.

The legal basis for the processing of your personal data is Section 26(1) of the German Federal Data Protection Act ( ) and Article 6(1)(b) of the General Data Protection Regulation (GDPR). If you grant us consent to include you in a candidate pool, the processing is additionally based on Article 6(1)(a) of the GDPR.

Your personal data will be deleted as soon as it is no longer necessary to achieve the purpose for which it was collected. If no employment relationship is established, your application documents will generally be deleted no later than six months after the conclusion of the application process, provided that no legal retention obligations preclude this or you have expressly consented to longer storage.

Advertising via Email, Phone, and Mail

We use your contact information for advertising if you have consented to it (Art. 6(1)(a) GDPR), as well as for legally permissible direct marketing of our own and related products if you have provided this information during your order or registration (Art. 6(1)(f) GDPR in conjunction with § 7(3) UWG). If you no longer wish to receive advertising, you can withdraw your consent at any time or object to direct marketing

– by clicking the unsubscribe link at the bottom of the email, – by email tosupport@conreri.de

– in writing to our company address listed at the beginning (please include your name and contact information),

– or by phone using the number provided at the beginning.

Your personal data will be shared with our external and internal marketing and newsletter service providers, provided they assist us with data processing. We contractually require them not to use the data for their own purposes or to share it with others. We will not share your data with third parties for advertising purposes without your express consent. The data we process will be deleted as soon as it is no longer necessary for its intended purpose and there are no legal retention obligations preventing its deletion.

Disclosure of Personal Data to Proficiency Testing Organizers

In the context of using our platform and conducting proficiency tests, it may be necessary to transfer personal data to the respective proficiency test organizers. This is done exclusively to the extent necessary for the registration, conduct, evaluation, or processing of the respective proficiency test. In particular, the following personal data may be processed and transmitted to the respective interlaboratory test organizer:

– Name of the contact person,

– Email address,

– Phone number,

– Company name,

– Address,

– Laboratory or customer numbers,

– Details regarding booked interlaboratory tests and related organizational information.

The data is transmitted exclusively to the respective interlaboratory test organizer and only to the extent necessary for conducting the interlaboratory test in question. No further disclosure to third parties takes place unless there is a legal obligation to do so. The processing and transfer of personal data are carried out for the purpose of contract initiation and contract performance in accordance with Art. 6(1)(b) of the GDPR. To the extent that processing is necessary to safeguard legitimate interests, it is additionally based on Art. 6(1)(f) of the GDPR. Our legitimate interest lies in the efficient organization and conduct of interlaboratory tests as well as the fulfillment of the services commissioned by users.

Personal data is stored only for as long as is necessary for the conduct and processing of the respective interlaboratory test and to fulfill statutory retention obligations. Once the purpose of processing no longer applies and statutory retention periods have expired, the data is deleted, provided that no further statutory or contractual retention obligations exist.

Geo Targetly – Location-Based User Guidance

We use the Geo Targetly tool on this website to display the appropriate website version (e.g., DACH or international website) to visitors based on their approximate location. For this purpose, the IP address is processed to determine the country or region. Processing is carried out exclusively for the purpose of directing users to the website version relevant to them.

The legal basis for the processing is our legitimate interest pursuant to Art. 6(1)(f) GDPR. Geo Targetly is used as an external service provider within the framework of data processing on our behalf. Data processing takes place via globally distributed servers, so processing outside the EU/EEA cannot be completely ruled out. To the extent that personal data is transferred to third countries in this context, this is done on the basis of the EU Standard Contractual Clauses (SCCs) agreed upon with Geo Targetly.

In connection with the use of the tool, cookies or similar technologies may be used, for example, to control the repeated display of the notice. Unless technically necessary, access to information on your device is granted only on the basis of your consent pursuant to Section 25(1) of the German Telemedia Act (TDDDG). Technically necessary access is granted pursuant to Section 25(2) of the TDDDG.

Further information regarding your rights can be found in the other sections of this Privacy Policy.

V. Presence in the social media

We maintain a presence on “social media.” To the extent that we have control over the processing of your data, we ensure that applicable data protection regulations are complied with. Below you will find the most important information regarding data protection in relation to our corporate social media accounts.

In addition to us, the following entities are responsible for the company’s social media presence within the meaning of the EU General Data Protection Regulation (GDPR) and other data protection regulations:

– Meta Platforms (Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland),

– Instagram (Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland),

– Xing (New Work SE, Am Strandkai 1, 20457 Hamburg),

– LinkedIn (LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland).

You use these platforms and their features at your own risk. This applies in particular to the use of interactive features (e.g., commenting, sharing, rating). Please note that your personal data may be processed outside the European Union in this context.

We process your personal data based on our legitimate interests in effective information and communication pursuant to Art. 6(1)(f) GDPR.

Since we do not have full access to your personal data, you should contact the social media providers directly to exercise your data subject rights, as they have access to their users’ personal data and can take appropriate measures and provide information.

Should you nevertheless require assistance, we will of course try to support you

VI. Overview of Data Processing Procedures

This section lists the data processing procedures on this website. It also transparently outlines which services we use for this purpose.

Consent preferences with Borlabs Cookie

We have integrated the consent management tool “Borlabs Cookie” from Borlabs GmbH, Hamburger Str. 11, 22083 Hamburg, Germany, into our website.

Borlabs Cookie enables us to obtain, manage, and document website visitors’ consents to the storage of certain cookies and the use of certain technologies in compliance with data protection regulations.

In doing so, Borlabs Cookie stores information about the consents you have granted or revoked.

For this purpose, the following data, among others, is processed:

– Your consent decision or its revocation,

– Date and time of consent,

– Information about the browser you are using,

– Information about your device,

– a cookie ID or consent ID to associate your consent,

– the consent settings you have selected.

This data is processed to provide evidence of the legally required consents for the use of cookies and similar technologies, as well as to fulfill our data protection obligations.

The legal basis for the processing of personal data is Article 6(1)(c) of the GDPR in conjunction with Article 7(1) of the GDPR.

The stored consent data will be deleted as soon as it is no longer necessary to achieve the purpose for which it was collected and there are no legal retention obligations to the contrary.

For further information on data protection, please refer to Borlabs’ Privacy Policy:

– Privacy Policy: https://de.borlabs.io/datenschutz/

Web Analytics with Matomo

We use the open-source web analytics software “Matomo” on our website.

Matomo enables us to analyze the usage behavior of our website visitors in order to optimize our online offering in terms of both technology and content.

In particular, the following data may be processed:

– truncated or anonymized IP address,

– pages and content accessed,

– date and time of the page visit,

– referrer URL,

– browser and operating system used,

– device information,

– Usage and interaction data.

The information collected by Matomo is processed exclusively on our own servers or by our hosting provider and is not shared with third parties for marketing purposes.

The processing is carried out for the purpose of analyzing and optimizing our online offering.

If Matomo is used with consent or cookies are used, processing is based on Article 6(1)(a) of the GDPR. If used without cookies and with anonymized data, processing is based on our legitimate interest pursuant to Article 6(1)(f) of the GDPR in the statistical evaluation and optimization of our website.

The data is deleted or anonymized as soon as it is no longer necessary to achieve the purpose of processing.

For more information about Matomo, please visit:

– Privacy Policy: https://matomo.org/privacy-policy/

VII. Analysis, Tracking, and Third-Party Provider

In order to provide our digital services, deliver content to you on the website, ensure the security of the website, fix potential errors, and conduct analyses, we and our partners use certain cookies and similar technologies. To this end, we and our partners (“providers”) process personal data such as your IP address or ID and browser information. The legal basis for this processing is your voluntary consent, which may be revoked at any time, pursuant to Art. 6(1)(a) GDPR.

Some of our service providers process your data outside the European Union. We only permit the processing of your data in a third country if the specific requirements of Art. 44 et seq. GDPR are met. This means that the processing of your data may then only take place on the basis of specific safeguards, such as the EU Commission’s official recognition of a level of data protection equivalent to that of the EU, or compliance with officially recognized specific contractual obligations, known as “Standard Data Protection Clauses.”

Purposes of Data Processing

Within the scope of our website, we and our partners (“Providers”) pursue the purposes described below:

Essential: These cookies and similar technologies are used for activities that are strictly necessary to operate or provide the service you have requested. They do not require your consent and cannot be disabled.

Marketing: These cookies and similar technologies help us deliver personalized advertising or marketing content to you and measure its effectiveness.

External Media: Content from video platforms and social media platforms is blocked by default. If external services are accepted, manual consent is no longer required to access this content.

Information about the tools used for the purposes described can be found directly in our privacy settings.n on your rights can be found in the other sections of this privacy policy.

VIII. Privacy Settings

You can adjust and revoke your consent to data processing requiring consent, such as advertising tracking, at any time in the privacy settings.