DATA PROTECTION

Privacy policy

It is a matter of course for us to respect your personal rights. This also applies to the handling of personal data when you visit and use this website. Therefore, we act in accordance with the applicable data protection law. In the following, you will learn how we handle your personal data and, in particular, which data we process for which purposes and what rights you are entitled to.

1. scope of application

1.1 This data protection declaration applies to the use of the websites offered by AMERIA AG, which you can access at www.ameria.de (hereinafter referred to as "AMERIA websites"). This data protection declaration does not apply to other websites of AMERIA AG or to the websites of other service providers to which the AMERIA websites refer via a link.

1.2 The responsible party within the meaning of the EU General Data Protection Regulation (GDPR) is: AMERIA AG
Palo-Alto-Platz 1
69124 Heidelberg
Germany
info@ameria.de
www.ameria.de

2. personal data

Personal data is any information relating to an identified or identifiable natural person. The basic personal data is your name. In addition, however, your gender, date of birth, address, occupation, e-mail address and IP address, for example, are also considered personal data. Non-personal data, on the other hand, is data with which it is impossible to determine your actual identity or at least requires considerable effort. This includes, for example, the aforementioned information if we receive it anonymously or under a pseudonym and therefore cannot assign it to a natural person.

3. principle of anonymity

When using the AMERIA websites, you remain anonymous to us as long as you do not voluntarily provide us with personal data by writing to us via our contact form or sending us an unsolicited application.

4. provision of personal data

4.1 The provision of personal data is neither legally nor contractually required for the use of the AMERIA websites and is also not necessary for the conclusion of a contract. You are not obliged to provide personal data. However, you will not be able to visit the AMERIA websites without the transmission of the IP address used by you.

4.2 Contacting us via our contact form and the unsolicited application require the provision or collection of the data described in more detail in sections 6 and 7. If you do not provide us with this data, you will not be able to use the contact form or the unsolicited application option.

5 Processing of personal data

5.1 When using the AMERIA websites, the following data is stored for organisational and technical reasons: the names of the pages accessed, the browser and operating system used, the date and time of access, search engines used, names of downloaded files and your IP address. We evaluate this technical data anonymously and for statistical purposes only, in order to be able to constantly optimise our internet presence and make our internet offers even more attractive. This anonymous data is stored separately from personal information on secure systems and does not allow any conclusions to be drawn about an individual person. The IP address is stored for one week, after which it is automatically deleted.

5.2 Apart from that, we only process your personal data if you voluntarily provide it to us and this is permitted by law or you have consented to it. We use the personal data you provide exclusively for the purposes notified in this data protection declaration or expressly agreed with you.

5.3 We commission various service providers to support us in the provision, operation and maintenance of our IT systems, including the AMERIA websites. These include, for example, hardware and software suppliers, Google Inc (for the web analytics service Google Analytics, see clause 12, and the spam protection service reCAPTCHA, see clause 14), hosting providers or data centres. If such service providers act on our behalf, it is possible that they will have access to your personal data as recipients. However, these service providers are then also contractually obliged to comply with data protection via a so-called order processing agreement; the legal provisions on data protection also apply to our service providers anyway.

5.4 Your personal data will not be passed on, sold or otherwise transferred to third parties. Something else only applies if this is necessary for the processing of the notified or agreed purposes and is permitted under applicable data protection law without consent, you have expressly consented or we are legally obliged to do so. Clause 5.3 remains unaffected, of course, and applies independently of this clause 5.4.

5.5 The personal data provided by you on the AMERIA websites or collected by us will not be used for automated decision-making.

6 Contact form

6.1 If you contact us via the contact form, you consent to us processing your message with the contact details you have provided for the purposes of responding and contacting you. You can also provide a pseudonym (i.e. an invented name) as your name. Your consent and our legitimate interest in being able to contact users of the AMERIA websites electronically form the legal basis for the processing (Art. 6 para. 1 lit. a and f DSGVO).

6.2 To protect us against spam and abuse, we use a reCAPTCHA query that you must confirm and execute before you can send us a message via the contact form. You can find more information on reCAPTCHA and the data protection implications in section 14.

6.3 For the purpose of contacting us via the contact form, you have submitted the following declaration of consent: "Yes, I give my consent that my data entered above as well as my message may be processed by AMERIA AG for the purpose of processing, contacting and replying. In this context, I agree to the
data protection declaration. I may revoke this consent at any time with effect for the future."

6.4 We will only process the data you provide via the contact form in order to process your message and reply to you. As long as we have received your contact details provided via the contact form only for the purpose of processing, contacting and replying to your message, we will not use these personal data for any other purpose. Apart from cases in which we are legally obliged to do so, we also do not pass on your contact data to third parties in this case.

5.5 Six (6) months after sending the reply, we will delete the data you submitted via the contact form, unless we are legally obliged to retain it for a longer period or we still need your personal data to implement or process an existing contractual relationship or for verification purposes. In such cases, we delete the relevant data after the statutory retention period has expired or as soon as we no longer need the data for the implementation or processing of an existing contractual relationship or for verification purposes.

6.6 You can revoke your consent for the future at any time (contact details see Clause 17 below). After revocation, your contact data will be stored for as long as and to the extent that we are obliged to do so within the scope of statutory retention obligations or we still need your personal data for the implementation or processing of an existing contractual relationship or for verification purposes.

6.6 You can revoke your consent for the future at any time (contact details see Clause 17 below). After revocation, your contact data will be stored for as long as and to the extent that we are obliged to do so within the scope of statutory retention obligations or we still need your personal data for the implementation or processing of an existing contractual relationship or for verification purposes.

7 Unsolicited application

7.1 If you contact us via our unsolicited application form, you consent to us processing your contact and application data, including any CV you may have sent, for the purposes of processing your application and contacting you. Your consent and our legitimate interest in receiving applications and contacting applicants form the legal basis for the processing (Art. 6 para. 1 lit. a and f DSGVO).

7.2 To protect us against spam and misuse, we use a reCAPTCHA query that you must confirm and execute before you can send us your unsolicited application via the associated form. For more information on reCAPTCHA and the data protection implications, please refer to section 14.

7.3 For the purpose of contacting us via our unsolicited application form, you have submitted the following declaration of consent: "Yes, I give my consent that my contact details entered above and my application documents sent may be processed by AMERIA AG for the purpose of processing my application, contacting me and responding to me. In this context, I agree to the data protection declaration. I can revoke this consent at any time with effect for the future.

7.4 We will only process the contact and application data you provide via the unsolicited application in order to process your application and respond to you. As long as we have received your contact and application data that you provide to us via the unsolicited application only for the purpose of processing, contacting and responding to your application, we will not use this personal data for any other purpose. Apart from cases in which we are legally obliged to do so, we will not pass on your contact and application data to third parties in this case.

7.5 If your application is successful and you enter into an employment relationship with us, we will transfer the contact and application data you submitted via the unsolicited application to our personnel management and your personnel file. In the event of a rejection, we will delete your contact and application data three (3) months after sending the rejection to you, unless we are legally obliged to store it for a longer period, you consent to a longer storage period (we will then ask you for this consent separately) or we still need your contact and application data for the implementation or processing of an existing contractual relationship or for verification purposes. In such cases, we delete the relevant data after the expiry of the statutory retention period or the period agreed with you in the context of the consent or as soon as we no longer need the data for the implementation or processing of an existing contractual relationship or for verification purposes.

7.6 As long as your application does not result in an employment relationship with us, you can revoke your consent at any time for the future (for contact details see Clause 17 below). After revocation, your contact and application data will be stored for as long as and to the extent that we are obliged to do so within the scope of statutory retention obligations or we still need your personal data for the implementation or processing of an existing contractual relationship or for verification purposes.

8 Revocation of consent

8.1 Within the framework of the legal provisions, you have the possibility to revoke your consent to the processing of your personal data for the future at any time. To do so, please contact the address listed below in Section 17 named below

8.2 We would like to point out that the processing of your personal data, which we have carried out on the basis of your consent until your revocation, is not affected by the revocation and remains lawful.

9 Right to information, correction, deletion, restriction of processing, objection and data portability

9.1 Within the framework of the legal provisions, you have the right to receive information from us about your personal data processed by us and to assert the right to rectification, deletion, restriction of processing, objection to processing and data portability. For the exact conditions under which you are entitled to the aforementioned rights, please refer to Articles 15 to 21 DSGVO and Sections 34, 35 and 37 of the German Federal Data Protection Act (BDSG). If you wish to exercise one or more of the aforementioned rights, please also contact the contact persons listed in section 17.

10 Right of appeal

10.1 Within the framework of the legal provisions, you have the right to contact the competent supervisory authority with complaints regarding data protection. The competent authority for us is the State Commissioner for Data Protection and Freedom of Information of Baden-W├╝rttemberg, which you can reach together with the supervisory authority via the website https://www.baden-wuerttemberg.datenschutz.de/.

11 Use of cookies

11.1 We use so-called cookies on the AMERIA websites. These are small text files that are stored on your end device (PC, smartphone, tablet, etc.). Some of the cookies we use are deleted from your drive (hard disk, solid-state disk, flash memory, etc.) at the end of the browser session (so-called session cookies). Other cookies remain on your terminal device and enable us to recognise your terminal device on your next visit (so-called permanent cookies). We also use cookies from third-party providers that allow them to process personal data from you and possibly merge the information obtained with other data that these third-party providers have already stored about you or collected from you during your use of the third-party services.

11.2 As soon as you visit the AMERIA websites, the following cookies are set:

-PHPSESSIONID: This is a cookie generated by WordPress (which is the software we use to manage the AMERIA websites). The cookie serves as a general identifier used to maintain user session variables. It contains a randomly generated number that is assigned to your browser during the browsing session. When the browser session is terminated, the cookie is deleted.

- qtrans_front_language: The cookie stores the selection of the language in which the Ameria web pages should be displayed (German / English). Personal data is not stored in the cookie.

- __ga, _gat_gtag_UA_670379_1 and _gid: The cookies used by Google Analytics and their meaning are described at https://support.google.com/analytics/answer/6004245?hl=de and https://developers.google.com/analytics/devguides/collection/analyticsjs/cookie-usage.

11.4 The content of the cookies is encrypted (exception: qtrans_front_language) to prevent third parties from gaining unauthorised access to the data contained therein.

11.5 The legal basis for our use of cookies is our legitimate interest in designing our web presence on the AMERIA websites in line with requirements (Art. 6 para. 1 lit. f DSGVO).

11.6 In the security settings of your browser, you can view and delete the stored cookies at any time and restrict or prohibit the acceptance of cookies.

11.7 When using third-party services on the AMERIA websites (e.g. reCAPTCHA) or when you click on a link, third-party cookies may be used without our explicit warning. In the security settings of your browser, you can also view and delete these stored cookies at any time and restrict or prohibit the acceptance of cookies.

12. use of Google Analytics

12.1 As described in more detail in sections 12.2 ff. below, we use the online service Google Analytics of the US company Google Inc. on the AMERIA websites. Google Analytics analyses the data traffic on the AMERIA websites and collects various data about you and your user behaviour on the AMERIA websites (e.g. which web browser you use to surf, where you come from, which language setting you use, which search engines you use, date and time of your visit to the AMERIA websites, how long you stay on which page). Your IP address is only collected anonymously; for details, see sections 12.3 and 12.6. Our use of Google Analytics is for the purpose of tracking user behaviour on the AMERIA websites and thus better understanding it, so that we can optimise our website and provide users with a better service. The legal basis for our use of Google Analytics is our legitimate interest in using our web presence on the AMERIA websites for marketing purposes and optimising it in line with requirements (Art. 6 (1) lit. f DSGVO). We delete the user data collected with Google Analytics on a regular basis.

12.2 The AMERIA websites use functions of the web analysis service Google Analytics. The provider is Google Inc. 1600 Amphitheatre Parkway Mountain View, CA 94043, USA. Google Analytics uses so-called "cookies". These are text files that are stored on your computer and enable an analysis of your use of the AMERIA websites (see also section 11). The information generated by the cookie about your use of these AMERIA websites is generally transmitted to a Google server in the USA and stored there.

12.3 In the case of activation of IP anonymisation, which we use on the AMERIA websites (see also section 12.6), your IP address will, however, be truncated beforehand by Google within member states of the European Union or in other contracting states to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. On behalf of the operator of this AMERIA website, Google will use this information for the purpose of evaluating your use of the AMERIA website, compiling reports on website activity and providing other services relating to website activity and internet usage to the website operator. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.

12.4 You may refuse the use of cookies by selecting the appropriate settings on your browser, however please note that if you do this you may not be able to use the full functionality of this AMERIA website. You can also prevent the collection of data generated by the cookie and related to your use of the AMERIA websites (including your IP address) by Google and the processing of this data by Google by downloading and installing the browser plugin available at the following link: http://tools.google.com/dlpage/gaoptout?hl=de.

12.5 You can also prevent the collection of data by Google Analytics that you create on the AMERIA websites and that is stored in the cookie by activating the link below. An opt-out cookie will be stored on your computer, which will prevent the future collection of your data when you visit the AMERIA websites (however, this will not apply to other websites you visit and other browsers you use on the same computer): Deactivate Google Analytics. This alternative is particularly suitable for mobile devices. If you choose to do so, do not delete the opt-out cookie. Otherwise, you will lose the protection offered by this opt-out cookie until you install it again.

12.6 The code "anonymizeIP" has been added to Google Analytics on the AMERIA websites. The use of this code leads to an anonymous recording of your IP address through so-called IP masking. The last octet of your IP address is thereby set to zero. For IPv6 addresses, this affects the last 80 of the 128 bits. This still happens in the working memory before the data is written to the hard disk (see also https://support.google.com/analytics/answer/2763052).

12.7 Further information on the purpose and scope of data collection and processing by Google Analytics can be found in Google's privacy policy on the Google website. The following websites are known to us in this regard:

- https://policies.google.com/privacy?hl=de

- https://support.google.com/analytics/answer/6004245?hl=de

- http://www.google.com/analytics/terms/

13. use of social media links

We do not currently use social media plugins on the AMERIA websites. Nevertheless, we display social media links of the following social networks:

- Facebook, www.facebook.com

- instagram, www.instagram.com

- kununu, www.kununu.com

- LinkedIn, www.linkedin.com

- Twitter, www.twitter.com

- XING, www.xing.com

- YouTube, www.youtube.com

This is a link to our company presence in the corresponding social network; the link does not contain any further functions (unlike the Like button from Facebook, for example). When you click on a social media link on the AMERIA websites, only the corresponding linked website opens.

14. use of reCAPTCHA

14.1 We use the iframe (inline frame) reCAPTCHA on the AMERIA websites to render embedded content from the following provider:

- Google, https://www.google.com/recaptcha/intro/v3beta.html

14.2 The legal basis for our use of reCAPTCHA is our legitimate interest in making our contact form and the unsolicited application form on the AMERIA websites available only for human contact and to protect ourselves from spam and misuse (Art. 6 para. 1 lit. f DSGVO).

14.3 reCAPTCHA is an online service of the US company Google Inc. The provider is Google Inc. 1600 Amphitheatre Parkway Mountain View, CA 94043, USA. reCAPTCHA helps us to distinguish whether an entry on the AMERIA websites is made by a human being or fully automatically by a machine (in particular a so-called bot). Our use of reCAPTCHA is therefore for the purpose of ensuring that only humans contact us via our contact form and the speculative application form and that we do not fall victim to spamming or fake messages. For this purpose, reCAPTCHA collects various data about you and your user behaviour on the AMERIA websites (e.g. your IP address, plug-ins installed in the browser, browser language setting, screen and window resolution, execution time, time zone, number of click / keyboard / touch actions in the iframe of the captcha). reCAPTCHA determines from which website the captcha function is called up. It reads cookies already stored in your browser or stores a new one if there is no reCAPTCHA cookie (see also section 11). The information generated by such cookies about your use of these AMERIA websites is generally transmitted to a Google server in the USA and stored there.

14.4 Further information on the purpose and scope of data collection and processing by Google can be found in Google's privacy policy on their website. The following website is known to us in this regard:

- Google, https://policies.google.com/privacy?hl=de&gl=de

There you will also find further information on your rights in this regard and settings to protect your privacy.

15. web fonts

15.1 AMERIA websites use web fonts from Google, so-called Google Fonts, which require your browser to download the required web fonts into its cache. To do this, your browser establishes a connection to the servers of the web font provider and transmits the IP address used by your end device at that time. The provider of the web font thus learns that a user with your IP address is visiting our AMERIA websites. If your browser does not support the web fonts used by the AMERIA websites, the display is based on a standard font instead.

15.2 The legal basis for our use of web fonts is our legitimate interest in displaying texts and fonts of our web presence on the AMERIA websites correctly and independently of the system you are using in order to ensure a uniform, visually pleasing presentation of our AMERIA websites on the accessing end devices (Art. 6 para. 1 lit. f DSGVO).

16 IT security

We take various technical and organisational security measures to protect the integrity and confidentiality of your personal data. To this end, your personal data is encrypted during transmission using so-called Secure Socket Layer technology (SSL). This means that communication between your computer and the servers of the AMERIA websites takes place using a recognised encryption method, the latest version of which is considered secure (currently SSL version 3, 256 bit). If your browser supports SSL, the transmission of personal data is protected by this function. In this case, most browsers show you whether the security protocol is supported by means of a short dialogue box or a graphic symbol. You can find more information in the help function of your browser.

17. data protection contact details

17.1 If you wish to exercise your rights under data protection law, have any questions about this privacy policy or our privacy practices on the AMERIA websites, please contact: info@ameria.de.

17.2 You can contact our data protection officer by e-mail at datenschutz@ameria.de and by post at AMERIA AG, c/o Data Protection Officer, Palo-Alto-Platz 1, 69124 Heidelberg, Germany, and by telephone at +49 6221 3521 500.