Data protection
Privacy Policy
1. General Privacy Information
We at GONICUS are pleased that you are visiting our website and want you to feel safe and comfortable while using it. We take the protection of your personal data very seriously and handle it confidentially and in accordance with the legal requirements of the General Data Protection Regulation (GDPR). This privacy policy is intended to inform you about the scope and purpose of the collection and processing of personal data.
Please note that internet-based data transmission may have security vulnerabilities. A complete protection of data against access by third parties is not possible. If you have any questions or suggestions regarding our data protection practices, feel free to contact us at any time.
2. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
GONICUS GmbH
Möhnestrasse 55
59755 Arnsberg
Phone: +49 (0) 29 32 / 9 16 - 0
E-Mail: info@gonicus.de
Represented by Managing Directors: Stefan Grote, Dipl.-Volkswirt Rainer Lülsdorf und Lars Scheiter
Data Protection Officer:
Mr. Johann Böhmer
Phone: +49 (0) 221 / 9977 699
E-Mail: datenschutz@gonicus.de
3. Technical Aspects
This website uses SSL or TLS encryption to ensure secure data processing and to protect the transmission of confidential content—such as inquiries you send to us as the site operator. You can recognize an encrypted connection by the fact that the address bar of your browser switches from “http://” to “https://” and displays a padlock symbol.
When SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.
4. Collection and Storage of Personal Data, and the Nature and Purpose of Their Use
a) When Visiting the Website
When you access our website, the browser on your device automatically sends information to the server hosting our website. This information is temporarily stored in what is known as a log file. The following information is collected without any action on your part and is stored until it is automatically deleted:
-
IP address of the requesting device,
-
Date and time of access,
-
Name and URL of the requested file,
-
Website from which access is made (referrer URL),
-
Browser used and, if applicable, the operating system of your device, as well as the name of your access provider.
This data is processed for the following purposes:
-
Ensuring a smooth connection to the website,
-
Ensuring comfortable use of our website,
-
Evaluating system security and stability, and
-
For additional administrative purposes.
The legal basis for data processing is Article 6(1)(f) GDPR. Our legitimate interest arises from the purposes listed above. Under no circumstances do we use the collected data to draw conclusions about your identity.
5. Web Analytics Using Matomo
a) Nature and Purpose of Processing
This website uses Matomo (formerly Piwik), an open-source software for the statistical analysis of website visits and for the continuous improvement of our offering. The provider of the Matomo software is InnoCraft Ltd., 150 Willis St, 6011 Wellington, New Zealand. Matomo does not use cookies on this website. Accordingly, providing a cookie-consent tool is not required. The IP address is anonymized immediately after processing and before storage. For more information on Matomo’s privacy settings, please see: https://matomo.org/docs/privacy/.
b) Legal Basis for Processing
Data processing is carried out on the basis of our legitimate interests pursuant to Art. 6(1)(f) GDPR.
e) Storage Periods
The data will be deleted as soon as they are no longer required for our record-keeping purposes. In our case, this occurs after the following period: 3 months.
f) Statutory / Contractual Requirement
The provision of your personal data for web analytics is neither legally nor contractually required, nor necessary for the conclusion of a contract. You can use our website without transmitting your (anonymized) data; you will not incur any disadvantages as a result.
g) Data Transfer to Third Countries
Although Matomo is based in New Zealand, all data are hosted on our own servers located in Germany and transferred into our own databases using Matomo. Therefore, processing does not take place outside the European Union (EU) or the European Economic Area (EEA).
6.1 Online Presence on Facebook:
a) Nature and Purpose of Processing
We are pleased that you are interested in our presence on Facebook. Below we provide an overview of the data collected, used, and stored by us on this platform.
Social networks can usually analyze your user behavior extensively when you visit their websites or websites with integrated social media content (e.g., Like buttons or advertising banners). Visiting our social media presence on Facebook triggers various data protection–relevant processing operations. Specifically:
If you are logged into your Facebook account while visiting our page, Facebook may associate your visit with your user account. However, your personal data may also be collected if you are not logged in or do not have a Facebook account—for example, via cookies stored on your device or by recording your IP address.
Facebook can use the collected data to create user profiles that include your preferences and interests. This enables interest-based advertising to be displayed both within and outside of Facebook. If you have a Facebook account, this advertising can appear across all devices on which you are or have been logged in.
Please also note that we cannot track all processing activities carried out by Facebook. Additional processing may be conducted by Facebook independently. For details, please consult Facebook’s Terms of Use and Privacy Policy.
b) Legal Basis for Processing
Processing is carried out on the basis of Article 6(1)(f) GDPR, based on our legitimate interest in maintaining contact with customers. Facebook’s own data processing and analytics may rely on different legal bases, which Facebook must indicate (e.g., consent under Article 6(1)(a) GDPR).
c) Categories of Data
Please refer to Facebook’s privacy policy for details on which data is collected and how it is used:
Facebook: http://www.facebook.com/policy.php
e) Retention Period
Once the purpose has been fulfilled and our use of Facebook ends, the data collected in connection with this presence will be deleted.
f) Statutory / Contractual Requirement
The provision of your personal data is voluntary. However, without this data, we may not be able to grant you access to certain content or services.
g) Data Transfer to Third Countries
Processing does not occur outside the European Union (EU) or the European Economic Area (EEA).
6.2 Online Presence on LinkedIn
a) Nature and Purpose of Processing
We appreciate your interest in our presence on LinkedIn and would like to provide an overview of what data we collect, use, and store in this context.
Social networks typically analyze your user behavior extensively when you visit their websites or sites with integrated social media elements (e.g., Like buttons or ads). Visiting our LinkedIn profile triggers several data protection–relevant processing operations. Specifically:
If you are logged into your LinkedIn account when visiting our page, LinkedIn can associate your visit with your user account. However, your personal data may also be collected if you are not logged in or do not have a LinkedIn account. This data collection may occur, for example, via cookies stored on your device or by recording your IP address. Using this data, LinkedIn can create user profiles that reflect your interests and preferences. This enables interest-based advertising within and outside of LinkedIn. If you have a LinkedIn account, such advertising can be shown across all devices where you are or were logged in. Please also note that we cannot track all data processing operations on LinkedIn. LinkedIn may perform additional processing independently. For more information, please consult LinkedIn’s terms and privacy policy.
b) Legal Basis for Processingc
Processing is based on Article 6(1)(f) GDPR and our legitimate interest in maintaining communication channels with our clients. LinkedIn’s analytics and processing may rely on different legal bases, which LinkedIn is responsible for specifying (e.g., consent under Article 6(1)(a) GDPR).
c) Categories of Data
For details on which data is collected and how it is used, please refer to LinkedIn’s privacy policy: LinkedIn: https://www.linkedin.com/legal/privacy-policy
e) Retention Period
After the purpose has ceased to exist and our use of LinkedIn has ended, all data collected in connection with this presence will be deleted.
f) Statutory / Contractual Requirement
Providing your personal data is voluntary. Without providing it, however, we may not be able to offer you access to certain content or services.
g) Data Transfer to Third Countries
Processing does not take place outside the European Union (EU) or the European Economic Area (EEA).
6.3 Online Presence on Xing
a) Nature and Purpose of Processing
Thank you for your interest in our presence on Xing. Below, we provide an overview of the data collected, used, and stored via this platform.
Social networks generally allow for comprehensive analysis of your user behavior when you visit their websites or websites with embedded social media content (e.g., Like buttons or banners). By visiting our Xing profile, various data protection–relevant processing operations may be triggered. Specifically:
If you are logged into your Xing account while visiting our profile, Xing can associate this visit with your personal user account. However, your personal data may also be collected if you are not logged in or do not have a Xing account. This can occur through cookies stored on your device or by collecting your IP address.
The data collected in this way can be used by Xing to create user profiles that reflect your preferences and interests. This enables interest-based advertising to be displayed both within and outside of Xing. If you have a Xing account, such advertising can be shown across all devices where you are or were logged in.
Please note that we cannot track all processing activities carried out by Xing. Xing may carry out additional processing. For details, please consult Xing’s terms of use and privacy policy.
b) Legal Basis for Processing
Processing is based on Article 6(1)(f) GDPR, reflecting our legitimate interest in maintaining contact with customers. Xing’s data processing may be based on different legal grounds, which Xing must specify (e.g., consent under Article 6(1)(a) GDPR).
c) Categories of Data
To learn which specific data is collected and how it is used, please refer to Xing’s privacy policy: Xing: https://www.xing.com/privacy
e) Retention Period
Once the intended purpose has ended and our use of Xing has been discontinued, any data collected in this context will be deleted.
f) Statutory / Contractual Requirement
The provision of your personal data is voluntary. Without providing it, we may be unable to offer access to certain content or services.
g) Data Transfer to Third Countries
Processing does not occur outside the European Union (EU) or the European Economic Area (EEA).
6.4 Online Presence on X (formerly Twitter)
a) Nature and Purpose of Processing
We appreciate your interest in our presence on X (formerly Twitter). In the following, we outline what data is collected, used, and stored when interacting with our presence on this platform.
Social networks typically analyze user behavior extensively when you visit their websites or websites with integrated social media content (e.g., Like buttons or advertising banners). Visiting our social media profile on X may trigger various data protection–relevant processing operations. Specifically:
If you are logged into your X account while visiting our profile, X can associate the visit with your user account. However, your personal data may also be collected if you are not logged in or do not have an account on X. This may happen, for example, through cookies stored on your device or by capturing your IP address.
X can use this data to create user profiles that include your preferences and interests. As a result, you may be shown interest-based advertising on and off the platform. If you have an account on X, such advertising can be displayed across all devices where you are or were logged in.
Please be aware that we cannot monitor all data processing operations carried out by X. X may process data independently. For details, please refer to X’s terms of use and privacy policy.
b) Legal Basis for Processing
Processing is based on Article 6(1)(f) GDPR, reflecting our legitimate interest in staying in contact with clients and other stakeholders. X’s internal processing may rely on other legal bases, which X is responsible for disclosing (e.g., consent under Article 6(1)(a) GDPR).
c) Categories of Data
To find out which data is collected and how it is used, please consult X’s privacy policy: X: https://x.com/de/privacy
e) Retention Period
Once the purpose of use has ended and we discontinue our presence on X, any associated data will be deleted.
f) Statutory / Contractual Requirement
Providing your personal data is voluntary. Without it, we may be unable to provide access to specific content or services.
g) Data Transfer to Third Countries
Processing does not take place outside the European Union (EU) or the European Economic Area (EEA).
6.5 Online Presence on YouTube
a) Nature and Purpose of Processing
We appreciate your interest in our presence on YouTube. The following information outlines what data is collected, used, and stored in the context of our activity on this platform.
Social networks can typically conduct extensive analysis of your user behavior when you visit their websites or websites with integrated social media content (e.g., Like buttons or advertising banners). By visiting our YouTube presence, various data protection–relevant processing operations may occur. Specifically:
If you are logged into your YouTube account while visiting our profile, YouTube can associate this visit with your user account. Your personal data may also be collected even if you are not logged in or do not have a YouTube account—e.g., via cookies stored on your device or by logging your IP address.
YouTube may use this data to create user profiles based on your preferences and interests. This can result in interest-based advertising being displayed both within and outside of YouTube. If you have a YouTube account, such advertising may be shown on all devices on which you are or were logged in.
Please note that we cannot track all processing operations conducted by YouTube. YouTube may carry out additional processing for which it is solely responsible. For further information, please refer to YouTube’s terms of service and privacy policy.
b) Legal Basis for Processing
Processing is based on Article 6(1)(f) GDPR, reflecting our legitimate interest in communicating with clients and prospects. YouTube’s internal processing may be based on other legal grounds, which are disclosed by YouTube (e.g., consent under Article 6(1)(a) GDPR).
c) Categories of Data
To learn which specific data is collected and how it is used, please refer to YouTube’s privacy policy: YouTube: https://policies.google.com/privacy
e) Retention Period
Once the purpose of the processing no longer applies and we discontinue our use of YouTube, all data collected in this context will be deleted.
f) Statutory / Contractual Requirement
Providing your personal data is voluntary. Without it, we may be unable to offer access to certain services or content.c
g) Data Transfer to Third Countries
Processing does not take place outside the European Union (EU) or the European Economic Area (EEA).
6.6 Online Presence on Instagram
a) Nature and Purpose of Processing
Thank you for your interest in our presence on Instagram. The following section provides an overview of what data is collected, used, and stored when interacting with our account on this platform.
Social networks generally allow for in-depth analysis of your user behavior when you visit their websites or websites that contain embedded social media content (e.g., Like buttons or advertising banners). By visiting our Instagram profile, various data protection–relevant processing operations may occur. Specifically:
If you are logged into your Instagram account while visiting our page, Instagram can associate this visit with your user profile. However, your personal data may also be collected if you are not logged in or do not have an Instagram account. This can happen via cookies stored on your device or through the collection of your IP address.
Instagram may use such data to create user profiles that reflect your interests and preferences. As a result, you may be shown interest-based advertising both within and beyond the Instagram platform. If you are or were logged into an Instagram account, such advertising may appear on all associated devices.
Please be aware that we are unable to monitor or control all processing activities conducted by Instagram. Additional processing operations may take place independently. For further information, please refer to Instagram’s privacy policy and terms of use.c
b) Legal Basis for Processing
Processing is carried out pursuant to Article 6(1)(f) GDPR and is based on our legitimate interest in maintaining communications with our clients and other interested parties. Instagram’s processing may be based on other legal grounds, such as consent under Article 6(1)(a) GDPR, which are subject to Instagram’s own responsibility.
c) Categories of Data
For detailed information on the data collected and its usage, please consult Instagram’s privacy policy: Instagram: https://privacycenter.instagram.com/policy
e) Retention Period
Once the intended purpose is fulfilled and our Instagram presence is discontinued, all data collected in this context will be deleted.
f) Statutory / Contractual Requirement
Providing your personal data is voluntary. However, if you choose not to provide such data, we may not be able to offer you access to certain content or services.
g) Data Transfer to Third Countries
Processing does not take place outside the European Union (EU) or the European Economic Area (EEA).
6.7 Online Presence on Kununu
a) Nature and Purpose of Processing
We appreciate your interest in our presence on Kununu. Below, we provide an overview of the data collected, used, and stored when interacting with our profile on this platform.
Social networks generally enable comprehensive tracking of your user behavior when you visit their websites or sites that contain embedded social media elements (e.g., Like buttons or advertising banners). Visiting our Kununu profile may therefore trigger several data protection–relevant processing operations. Specifically:
If you are logged into your Kununu account during your visit, Kununu can link your visit to your user account. However, your personal data may also be collected if you are not logged in or do not have a Kununu account. This may happen via cookies stored on your device or by capturing your IP address.
With this data, Kununu can generate user profiles that reflect your preferences and interests. This allows interest-based advertising to be displayed on and off the Kununu platform. If you use Kununu, such ads can be shown across all devices where you are or were logged in.
Please note that we cannot monitor or influence all processing activities carried out by Kununu. Additional operations may be performed independently by Kununu. For more information, refer to Kununu’s privacy terms and conditions.
b) Legal Basis for Processing
The processing is based on Article 6(1)(f) GDPR and reflects our legitimate interest in staying in contact with current and prospective employees or clients. Data processing carried out by Kununu may be subject to additional legal bases, which Kununu must provide (e.g., consent under Article 6(1)(a) GDPR).
c) Categories of Data
To find out which data is collected and how it is used, please consult Kununu’s privacy policy: Kununu: https://privacy.xing.com/de/datenschutzerklaerung
e) Retention Period
After the intended purpose has ended and our Kununu presence is deactivated, the data collected in this context will be deleted.
f) Statutory / Contractual Requirement
Providing your personal data is voluntary. However, without it, we may not be able to offer you access to certain services or features.
g) Data Transfer to Third Countries
Processing does not occur outside the European Union (EU) or the European Economic Area (EEA).
6.8 Online Presence on Mastodon
a) Nature and Purpose of Processing
Thank you for your interest in our presence on Mastodon. Below, we provide an overview of what data is collected, used, and stored when engaging with our account on this platform.
Social networks generally allow for detailed analysis of user behavior when visiting their websites or sites with embedded content such as Like buttons or advertising banners. When you visit our Mastodon profile, various data protection–relevant processing activities may occur. Specifically:
If you are logged into your Mastodon account while visiting our page, Mastodon can associate the visit with your account. However, even if you are not logged in or do not have a Mastodon account, personal data may be collected—for example, through cookies stored on your device or by logging your IP address.
Mastodon may use this data to create user profiles that reflect your preferences and interests. Based on this, you may receive interest-based advertising both on and off the platform. If you use Mastodon across multiple devices, ads may be displayed consistently across all of them.
Please note that we cannot monitor or influence all processing operations conducted by Mastodon. Additional processing may occur independently. For full details, please refer to Mastodon’s terms of use and privacy policy.
b) Legal Basis for Processing
Processing is carried out under Article 6(1)(f) GDPR, based on our legitimate interest in maintaining communication with stakeholders. Mastodon’s own processing may rely on other legal grounds, such as consent under Article 6(1)(a) GDPR, which Mastodon must disclose.
c) Categories of Data
For information on which data is collected and how it is used, please refer to Mastodon’s privacy policy: Mastodon: https://mastodon.social/privacy-policy
e) Retention Period
Once the purpose of processing ends and our use of Mastodon is discontinued, the associated data will be deleted.
f) Statutory / Contractual Requirement
Providing your personal data is voluntary. Without it, we may not be able to provide access to certain content or features.
g) Data Transfer to Third Countries
Processing does not occur outside the European Union (EU) or the European Economic Area (EEA).
7. Data Security
he personal data of anyone who is in a contractual, pre-contractual, or any other relationship with our company deserves special protection. Our goal is to maintain a high standard of data protection at all times. For this reason, we continuously develop and improve our data protection and data security practices.
We are committed to safeguarding your privacy and treating your personal data confidentially. To prevent manipulation, loss, or misuse of the data we store, we have implemented extensive technical and organizational security measures. These are regularly reviewed and adjusted in line with technological developments. Among other things, we use established encryption technologies (such as SSL or TLS).
However, please note that due to the structure of the internet, data protection regulations and the aforementioned security measures may be circumvented by individuals or institutions outside our area of responsibility. For example, data sent unencrypted via email may be read by third parties. Unfortunately, we have no technical control over this.
It is therefore the responsibility of each user to protect their own data—provided to us—against misuse, for example by using encryption or other protective measures.
8. Data Subject Rights
WIf your personal data is being processed, you are considered a data subject under the General Data Protection Regulation (GDPR). As such, you have the following rights vis-à-vis the controller:
-
Right of access (Article 15 GDPR)
-
Right to rectification or erasure of personal data (Articles 16 and 17 GDPR)
-
Right to restriction of processing (Article 18 GDPR)
-
Right to notification regarding rectification or erasure of personal data or restriction of processing (Article 19 GDPR)
-
Right to data portability (Article 20 GDPR)
-
Right to object (Article 21 GDPR)
-
Right to withdraw consent that you have previously given. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal (Article 7(3) GDPR)
-
Right to lodge a complaint with a supervisory authority (Article 77 GDPR)
9. Our Right to Amend This Policy
Changes in legislation or internal company processes may make it necessary to adapt this privacy policy. We therefore encourage you to review this privacy policy regularly.
We reserve the right to amend this policy at any time in compliance with applicable data protection laws.