Privacy
Declaration of data security and at the same time information of the data subjects pursuant to Article 13 and Article 14 of the EU General Data Protection Regulation
A) General information
1. Details of the responsible entity
Company: factory360 GmbH
Legal representative: Markus Meister
Address: Paul-Engel-Str., 92729 Weiherhammer
Email: info@factory360.world
2. Contact of the Data Protection Officer
Email: info@factory360.world
Email: info@factory360.world
Any data subject may contact our Data Protection Officer directly and at any time with any questions or suggestions regarding data protection.
B) Collection of general data and information
Affected data:
Personal data is only collected if provided on a voluntary basis, no other personal data is collected. Any processing of your personal data that goes beyond the scope of the statutory permissions will only take place on the basis of your explicit consent.
Processing purpose: Implementation of contracts
Recipients of personal data:
• Public authorities in the event of priority legislation
• External service providers or other contractors
• Other external bodies in so far as the data subject has given his consent or a transmission is permitted due to a prevailing interest.
Data transfer to a third country:
As part of contractual execution, processors could also be used outside the European Union, among others, e-mail providers.
Storage period of personal data:
The duration of data storage depends on the statutory storage requirements and is usually 10 years.
C) Specific information about the website
By registration on the website, data to our web server via internet browser is transmitted (for technical reasons). The following data is recorded during current connections for communication between the internet browser and our web server:
• date and time
• name of the requested file
• page from which the file was requested
• access status (file transferred, file not found, etc.)
• web browser and operating system
• complete IP address
• amount of data transferred
For technical reasons, a limited amount of data (so-called connection data) is collected with every access. This data is technically necessary to establish and execute a connection between the customer's end device and our servers. Furthermore, this data is required to maintain the session after a login and to prevent unauthorized access.
For reasons of technical security, particularly to defend against attempted attacks on our web server, this data is stored for a short time. It is not possible to identify individual persons from this data. After seven days at the latest, the data is anonymized by shortening the IP address at domain level so it is no longer possible to establish a link to the individual user. The data is also processed in an anonymized form for statistical purposes. The data is not passed on to third parties unless there is a statutory obligation to pass on the data, or if the transfer serves the aim of criminal prosecution.
1. Borlabs Cookie (Cookie-Consent-Tool)
1.1. Description of data processing
We use the cookie consent tool “Borlabs Cookie” from Borlabs GmbH (hereinafter referred to as “Borlabs”). When you access our website, Bor-labs Cookies displays a list of cookies divided into function groups in a pop-up window, explains the purpose of the cookie function groups and the individual cookies as well as their storage duration. You can activate the cookies divided into function groups by clicking on the corresponding box and give your consent to the use of the cookies, or give your consent to all cookies. Please note that the technical cookies are already stored when you enter our website and the corresponding field is preset.
1.2. Legal basis and purpose of data processing
The legal basis for the processing of personal data using cookies in Borlabs Cookies is Art. 6 (1) (f) GDPR to grant our legitimate interests in the best possible functionality and security of the website and a customer-friendly and effective design of the site visit. For this purpose, Borlabs uses technically cookies to save the content of the consent you have given for your next visit. We cannot offer some functions of our website without the use of cookies. For this it is necessary that the browser is recognized even after leaving the site.
1.3. Duration of storage / possibility of objection and removal
Cookies are stored on the user's device and transmitted by the user to our website. As a user, you therefore have full control over the use of cookies. You can deactivate or restrict the transmission of cookies by changing the corresponding settings in your internet browser. Cookies that have already been saved can be deleted at any time. This can also be done automatically. However, if you want to check or change your cookie settings, you can reset Borlabs Cookies by clearing your cache and reopening the website and then implement the appropriate settings with Borlabs Cookies. You can also click the button below to change your cookie settings. If you subsequently call up/load the website again, you will be asked again for your cookie consent.
1.4. Collection of general data and information
The website of the factory360 GmbH collects a series of general data and information when a data subject or automated system calls up the website. This general data and information is stored in the server log files. The following data can be recorded, which serve to avert danger in the event of attacks on our information technology systems:
• browser types and versions used
• the operating system used by the accessing system
• the website from which an accessing system reaches our website (so-called referrer)
• the sub-websites which are accessed via an accessing system on our website
• the date and time of access to the website
• an internet protocol address (IP address)
• the internet service provider of the accessing system
• other similar data and information
• browser types and versions used
• the operating system used by the accessing system
• the website from which an accessing system reaches our website (so-called referrer)
• the sub-websites which are accessed via an accessing system on our website
• the date and time of access to the website
• an internet protocol address (IP address)
• the internet service provider of the accessing system
• other similar data and information
When using these general data and information, factory360 does not draw any conclusions about the data subject. Rather, this information are needed to (1) deliver the content of our website correctly, (2) optimize the content of our website as well as its advertisement, (3) ensure the long-term viability of our information technology systems and website technology, and (4) provide law enforcement authorities with the information necessary for criminal prosecution in case of a cyber-attacks. Therefore, the factory360 analyzes anonymously collected data and information statistically, with the aim of increasing the data protection and data security of our enterprise, and to ensure an optimal level of protection for the personal data we process. The anonymous data of the server log files are stored separately from all personal data provided by a data subject.
2. Contact via website
A contact form is available on our website, which can be used to contact us electronically. If a person uses this option, the data entered in the respective input mask will be transmitted to us and stored, in particular:
• Salutation*
• First name
• Surname*
• Company name
• Email*
• Telephone number
• Subject*
• Message*
The details marked with * are mandatory details that we consider essential for checking and answering an inquiry and without the contact form cannot be used.
At the time of sending your message via one contact form, the following data is stored:
• the IP address of the user
• the date and time of registration
Alternatively, it is possible to contact us via provided e-mail address. In this case, the user's personal data transmitted via e-mail will be stored.
The legal basis for storage is your consent or a contractual basis, i.e. Art. 6 para. 1 lit. a) and b) GDPR.
The data will be deleted as soon as it is no longer required to achieve the purpose for which it was collected.
3. Usage of the factory360 cloud login
3.1. Description of data processing
After completing a registration process, we offer customers the opportunity to use specific software via login area on our website. The following personal data is provided by the customer for this purpose:
• Salutation
• Surname
• First name
• e-mail address
• Company name
The access data required for login (e-mail address and password) are stored when a user account is created. To complete the registration process, the customer will receive an activation link to the e-mail address he provided, which must be confirmed via click. Alternatively, the customer can copy the link and call it up via address line of the web browser.
For technical reasons, a limited amount of data (so-called connection data) is collected with every access. This data is technically necessary to establish and execute a connection between the customer's end device and our servers. Furthermore, this data is required to maintain the session after a login and to prevent unauthorized access. As part of each registration process and the use of the customer portal, we or the hosting service provider store the following data:
• IP address and the time of the respective user action (timestamp)
• Internet service provider
• Web browser and operating system used or the respective version information
• language settings
• referrer URL
• name of the website accessed
• IP address and the time of the respective user action (timestamp)
• Internet service provider
• Web browser and operating system used or the respective version information
• language settings
• referrer URL
• name of the website accessed
After logging into the user account, a cookie is set, which is required to maintain and protect the session. For access to the user account, confirmation if the cookie in the web browser is required.
3.2. Legal basis and purpose of data processing
The legal basis for the processing of the data processed in the course of the registration and use of the user account is Art. 6 para. 1 lit. b GDPR due to the intended conclusion or execution of a contract.
3.3. Duration of storage / possibility of objection and removal
The data is deleted as soon as it is no longer required to achieve the purpose for which it was collected. For the personal data from the registration input screen, this is usually the case when the respective usage process has ended.
All personal data will be deleted at the latest if no legal requirements necessitate longer storage (e.g. statutory warranty periods).
4. Google Analytics 4
Based on your consent, we use Google Analytics, a web analytics service provided by Google Inc (hereinafter "Google"). Consent is given by setting the appropriate option in the cookie banner. Google uses cookies. The information regarding the online behavior of the data subject generated by the cookie is usually transmitted to a Google server in the USA and stored there.
Google will use this information on our behalf to evaluate the use of our online offer, to compile reports on the activities within this online offer and to provide us with other services related to the use of this online offer and the Internet. Therefore, pseudonymous usage profiles of the users can be created from the processed data.
We use Google Analytics to display ads placed within Google's advertising services and those of its partners only to users who have shown an interest in our online offering or who have certain characteristics (e.g. interests in certain topics or products determined on the basis of the websites visited), which we transmit to Google (so-called "Remarketing Audiences" or "Google Analytics Audiences"). With the help of Remarketing Audiences, we also want to ensure that our ads correspond to the potential interest of users and do not have a harassing effect.
We only use Google Analytics with IP anonymization. This means that the IP address of the user is shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases the full IP address will be transferred to a Google server in the USA and shortened there.
The IP address transmitted by the user's browser is not merged with other data from Google. Users can prevent the storage of cookies by setting their browser software accordingly; users can also prevent the collection of data generated by the cookie and related to their use of the online offer to Google as well as the processing of this data by Google by downloading and installing the browser plugin available at the following link:
• https://tools.google.com/dlpage/gaoptout
More information about Google’s use of data, settings and objection options can be found on Google’s websites:
• www.google.com/intl/de/policies/privacy/partners (How we use data from websites or apps on or in which our services are used)
• www.google.com/policies/technologies/ads (How Google uses cookies in ads)
• www.google.de/settings/ads (Personalized Advertising Settings)
• www.google.com/policies/privacy (Google Privacy Policy)
5. Google Tag Manager
Furthermore, we may use "Google Tag Manager" (if consent for this has been obtained) to integrate and manage Google analysis and marketing services on our website.
For more information on the use of data for marketing purposes by Google, please refer to the overview page: www.google.com/policies/technologies/ads, Google's privacy policy is available at www.google.com/policies/privacy.
If you want to object to interest-based advertising by Google marketing services, you can use the settings and opt-out options provided by Google: www.google.com/ads/preferences.
6. Google Signals
As an extension to Google Analytics 4, Google Signals will be used on this website to generate cross-device reports. If you have activated personalized ads and have linked your devices to your Google account, Google can analyze your usage behavior across devices and create database models, including cross-device conversions, subject to your consent to the use of Google Analytics in accordance with Art. 6 para. 1 lit. a GDPR. We only receive statistics from Google. If you wish to stop the cross-device analysis, you can deactivate the “Personalized advertising” function in the settings of your Google account. For this follow the instructions on page:
• https://support.google.com/ads/answer/2662922?hl=de
You can find more information about Google Signals at the following link:
• https://support.google.com/analytics/answer/7532985?hl=de
• https://support.google.com/ads/answer/2662922?hl=de
You can find more information about Google Signals at the following link:
• https://support.google.com/analytics/answer/7532985?hl=de
7. UserIDs
As an extension to Google Analytics 4, the “UserIDs” function will be used on this website. If you have agreed to the use of Google Analytics 4 in accordance with Art. 6 para. 1 lit. a GDPR, have set up an account on this website and log in with this account on different devices, your activities, including conversions, can be analyzed across devices.
Data transfers to the USA are based on the EU-US Data Privacy Framework.
8. Google AdWords
The controller has integrated Google AdWords on this website. Google AdWords is a service for Internet advertising that allows placing ads in the results of Google search engine and Google advertising network. Google AdWords allows an advertiser to define specific keywords in advance, that help to only display ads in Google search results when the user uses the search engine to retrieve a keyword-relevant search result. In the Google advertising network, the ads are distributed to relevant web pages with the help of an automatic algorithm considering the previously defined keywords.
Provider of Google AdWords is Google Inc., located at 1600 Amphitheatre Pkwy, Mountain View, CA 94043-1351, UNITED STATES.
The purpose of Google AdWords is to promote our website by displaying relevant advertising on third-party websites and results of Google search engine, as well as a display of third-party advertising on our website.
If a data subject accesses our website via a Google ad, Google will store a conversion cookie on the data subject's information technology system. A conversion cookie loses its validity after 30 days and is not used to identify the data subject. If the cookie has not expired yet, the conversion cookie is used to check whether certain sub-pages, e.g., the shopping cart from an online store system, have been called up on our website. Through the conversion cookie, both Google and the controller can track whether a person who has called up an AdWords ad on our website has generated a sale, i.e., has made or cancelled a purchase of goods.
The data and information collected by the conversion cookie is used by Google to compile statistics for visits of our website. These statistics are used to determine the total number of users targeted through AdWords ads, to determine the success or failure of individual AdWords ads, and to optimize our AdWords ads in the future. Neither our company nor other Google AdWords advertisers receive information from Google to identify the data subject.
The conversion cookie stores personal information, e.g., the internet pages visited by the data subject. Whenever our websites are visited, personal data, including the IP address of the internet access, is transmitted to Google in the United States of America. This personal data is stored by Google in the United States of America. Google may disclose this personal data collected through the technical process to third parties.
The data subject can prevent the setting of cookies by our website, as already described above, at any time by an appropriate setting of the Internet browser used and thus permanently object to the setting of cookies. Such a setting of the Internet browser used would also prevent Google from setting a conversion cookie on the information technology system of the data subject. In addition, a cookie set by Google AdWords can be deleted at any time in the browser or other software programs.
The data subject has the option to object to Google's interest-based advertising, provided that prior consent has been given via the cookie banner. To do this, the data subject must call up the link www.google.de/settings/ads from each of the browsers used and make the desired settings.
Further information and the applicable Google privacy policy can be found at www.google.com/intl/en/policies/privacy.
9. Google Maps
This website uses Google Maps to display interactive maps and to provide directions. Google Maps is a map service provided by Google Inc, 1600 Amphitheatre Parkway, Mountain View, California 94043, USA. By using Google Maps, information about the use of this website, including your IP address and the (start) address entered as part of the route planner function, may be transmitted to Google in the USA. When you access a web page on our website that contains Google Maps, your browser establishes a direct connection with Google's servers. The map content is transmitted by Google directly to your browser, which integrates it into the website. We therefore have no influence on the scope of the data collected by Google in this way. According to our knowledge, these are at least the following data:
• internet address or URL of the website accessed
• Internetadresse oder URL der aufgerufenen Webseite,
• IP address
• (start) address entered as part of route planning.
We have no influence on the further processing and use of the data by Google and can therefore take no responsibility.
To activate Google Maps, we therefore require your agreement to display Google Maps.
The purpose and scope of the data collection and the further processing and use of the data by Google as well as your rights in this regard and setting options to protect your privacy can be found in Google's data protection information (https://policies.google.com/privacy?hl=de).
By using our website, you agree to the processing of data by Google Maps Route Planner.
10. YouTube
YouTube components are integrated on this website. The collection of personal data when embedding a YouTube video is not our responsibility.
YouTube is a web video portal that allows publishers of videos to post video clips free of charge as well as other users to view, rate and comment on them free of charge. YouTube allows the publication of all types of videos. That is why complete film and TV shows, but also music videos, trailers or videos made by the users themselves can be accessed via the web portal.
The operating company of YouTube is YouTube, LLC, 901 Cherry Ave, San Bruno, CA 94066, USA. YouTube, LLC is a subsidiary of Google Inc., 1600 Amphitheatre Pkwy, Mountain View, CA 94043-1351, USA.
Each time one of the individual pages of this website operated by the controller and including a YouTube component (YouTube video) has been called up by the data subject, the browser on the information technology system of the data subject will cause a download of the respective YouTube component from YouTube for representation. Further information on YouTube can be found at www.youtube.com/yt/about/de. Within the scope of this technical procedure, YouTube and Google get to know which specific subpage of our website was visited by the data subject.
If the data subject is logged in to YouTube at the same time, YouTube recognizes the specific subpage of our website containing a YouTube video which the data subject called up. This information is collected by YouTube and Google and assigned to the respective YouTube account of the data subject.
YouTube and Google receive information that the data subject has visited our website via the YouTube component, if the data subject is logged into YouTube at the same time. It is regardless if the data subject clicks on a YouTube video or not. If the data subject would like to avoid transmission of this information to YouTube and Google a log out of the YouTube account before accessing our website is necessary. Further information on collection, processing and usage of personal data by YouTube and Google can be found in the privacy policy published by YouTube: www.google.de/intl/de/policies/privacy.
11. LinkedIn
You can recognize the call from LinkedIn, LinkedIn, 2029 Stierlin Courtm, Mountain View, CA 94043 USA, by the "in" sign on a blue background. If you activate our "in" button as part of the 2-click solution, a connection is established with the LinkedIn server and the LinkedIn plugin is reloaded on the respective website. The content of the "in" button is transmitted by LinkedIn directly to your browser and integrated into the website. It is possible that your IP address will be transmitted to LinkedIn in the USA. For the purpose and scope of data collection and further processing and use of data by LinkedIn, as well as your rights and setting options for protecting your privacy, please refer to LinkedIn's privacy policy (www.linkedin.com/legal/privacy-policy). If you are a LinkedIn member and do not want LinkedIn to collect and store your data when using our website, you must log out of LinkedIn before visiting our website.
12. Restaurant NEWS app (only when using the app)
When using this app, your personal data that you have provided to us (name, e-mail and telephone number) are processed. We collect and process your data in the course of providing our services.
The data you send to us via contact requests will remain with us until you request us to delete it, revoke your consent to store it, or the purpose for storing the data no longer applies (e.g., after we have completed processing your request). Mandatory legal provisions - in particular legal retention periods - remain unaffected.
D) Information about other data processing procedure
1. Specific information for application procedure
Affected data: application details
Processing purpose: Implementation of application procedure
The provision of personal data is necessary for an application at factory 360. If the personal data is not provided, you cannot be considered for filling job vacancies.
If you do not agree to the further storage of your application data in the so-called talent pool, we will not be able to consider you for filling future job vacancies.
During an application process personal data like title, surname, first name as well as the contact details such as postal address, e-mail address and telephone numbers is stored in the database for applications. In addition to that, application documents such as cover letter, curriculum vitae, professional, educational, and training qualifications, as well as job references are recorded. This data is only stored, evaluated, processed, or forwarded internally due to your application. The personal information is only accessible to employees of the HR department and the persons responsible for the selection of applicants. The data may be processed for statistical purposes (e.g. reporting). However, in this case it is not possible to draw conclusions about individual persons. We process your personal data to carry out pre-contractual measures pursuant to Art. 6 para.1 lit.b GDPR.
Recipients of personal data:
Your data will not be disclosed to companies or persons outside factory 360 unless required by law, e.g.:
• Public authorities in the event of priority legislation
• External service providers or other contractors, e.g., for data processing and hosting.
• Other external bodies in so far as the data subject has given his consent or a transmission is permitted due to a customer or lead for e.g. acquisition of orders.
Data transfer to a third country: A transfer of data to a third country does not take place.
Storage period of personal data:
If you get an acceptance and join factory 360 as employee your application will be part of our personnel file. In case of a rejection your data will be stored for about 6 months after completion of the application process and deleted, if there are no other legitimate interests of the controller that prevent deletion. Other legitimate interest is e.g., to provide evidence in proceedings under the General Equal Treatment Act (AGG).
If you have consented that your application data can be stored in the application talent pool, we will use your data to fill future vacancies. If you have separately agreed to the storage of your personal data for the period after the end of the application process (talent pool), the data processing will be carried out in accordance with Art. 6 para.1 lit.a DSGVO for 12 months and after 12 month deleted, if there are no other legitimate interests of the controller that prevent deletion.
2. Specific information for the processing of customer data / prospective parties’ data
Affected data: Data communicated for contract execution; if necessary, additional data for processing on the basis of your express consent. Data communicated for contract execution; if necessary, additional data for processing based on your express consent.
Processing purpose: Contract execution, e.g, quotations, orders, order fulfillment and invoicing, quality assurance.
Recipients of personal data:
• Public authorities in the event of priority legislation, e.g., customs
• External service providers or other contractors, e.g., for data processing and hosting, for shipping, transport and logistics, service provider for printing and shipping of information
• Other external bodies in so far as the data subject has given his consent or a transmission is permitted due to a prevailing interest, e.g., for creditworthiness information for purchases on account, for the electronic dispatch of information, for quality assurance purposes.
Third-country transfers: As part of contractual execution, processors could also be used outside the European Union, among others, e-mail providers.
Duration of data storage: The duration of data storage depends on the statutory storage requirements and is usually 10 years.
3. Specific information on the processing of employee data
Affected data: Data communicated for contract execution; if necessary, additional data for processing on the basis of your express consent. Data communicated for contract execution; if necessary, additional data for processing based on your express consent.
Processing purpose: Contract execution within the scope of employment.
Recipients of personal data:
• Public authorities in the event of priority legislation, among others tax office, social insurance agency, employers' liability insurance association.
• External service providers or other contractors, among others data processing and hosting, payroll accounting, travel expense accounting, insurance benefits, vehicle use.
• Other external bodies in so far as the data subject has given his consent or a transmission is permitted due to a prevailing interest among others for order acquisition, insurance benefits.
Data transfer to a third country: As part of contractual execution, processors could also be used outside the European Union, among others, e-mail providers.
Storage period of personal data: The duration of data storage depends on the statutory storage requirements and is usually 10 years.
4. Specific information for the processing of supplier data
Affected data: Data communicated for contract execution; if necessary, additional data for processing on the basis of your express consent. Data communicated for contract execution; if necessary, additional data for processing based on your express consent.
Processing purpose: Contract execution, e.g., , purchase orders, quality assurance.
Recipients of personal data:
• Public authorities in the event of priority legislation, e.g., tax office, customs.
• External service providers or other contractors, e.g., for data processing and hosting, accounting, payment processing.
• Other external bodies in so far as the data subject has given his consent or a transmission is permitted due to a prevailing interest.
Third-country transfers: As part of contractual execution, processors could also be used outside the European Union, among others, e-mail providers.
Duration of data storage: The duration of data storage depends on the statutory storage requirements and is usually 10 years.
5. Specific information on the use of video conferencing/webinar software
Affected data: Data provided for the use of the video conferencing software or webinar software (first name, surname, e-mail address; optional sound transmission, image transmission and questions when using chat functions); To the technically necessary extent, data from your system is processed to establish the connection with the provider of the conference software.
Processing purpose: Conducting video conferences or webinars.
Recipients of personal data:
• Public authorities in the event of overriding legal provisions.
• External service providers or other contractors, e.g., for data processing and hosting.
• Other external bodies in so far as the data subject has given his consent or a transmission is permitted due to a prevailing interest.
Data transfer to a third country: Processors outside the European Union are used (here: United States of America); standard contractual clauses have been concluded with the service provider accordingly.
Storage period of personal data: Video conferences are only recorded with the prior documented consent of the participants. The technical data is deleted as soon as it is no longer required. The duration of data storage is determined by the statutory retention obligations and is generally 10 years.
6. Specific information for Customer Training
We hereby inform you about the nature, scope, and purpose of the collection and use of personal data within the framework of our customer training.
Within the scope of the customer training, we collect the following personal data:
• First name, last name
• Contact details (email address, telephone number)
• Company affiliation
• Position in the company
• Participation and performance data (e.g., attendance, test results)
The collected data will be processed for the following purposes:
• Conducting and organizing the training
• Issuance of participation certificates and certificates
• Evaluation and improvement of our training offer
• Communication within the framework of the training (e.g., sending informational materials)
The processing of your data is based on Art. 6(1)(b) GDPR and Art. 6(1)(a) GDPR.
Your personal data will be shared with our subsidiary, C4Trends GmbH. This company conducts the training on our behalf.
We retain your personal data only as long as necessary to fulfill the purposes for which it was collected or as required by law. Once your data is no longer needed for these purposes, it will be deleted.
7. Handling of business cards
By handing over or exchanging business cards, you provide us with personal data, such as phone number, e-mail address. We use this information exclusively to stay in contact with you. In addition, we may provide you with further information. 5 years after the purpose for which the data was collected has ceased to exist, we will delete your personal data. You have the right of information, deletion, or correction at any time.
Sie haben jederzeit das Recht auf Auskunft, Löschung oder Berichtigung.
E) Miscellaneous
1. Decision making
As a responsible company, we do not use automatic decision-making or profiling.
2. Right of complaint to the supervisory authority
In addition, you have the right for information, correction, or deletion or to restriction of processing or the exercise of your right to object to processing as well as the right to data portability at any time. You can contact us by e-mail or letter here in the legal notice.
The data subject may complain to the competent supervisory authority:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 27
91522 Ansbach
Phone: +49 (0) 981 53 1300
eMail: poststelle@lda.bayern.de