With the following privacy policy we would like to inform you which types of your personal data (hereinafter also abbreviated as "data") we process for which purposes and in which scope. The privacy statement applies to all processing of personal data carried out by us, both in the context of providing our services and in particular on our websites, in mobile applications and within external online presences, such as our social media profiles (hereinafter collectively referred to as "online services").
The terms used are not gender-specific.
Last Update: 29 June 2023
reeeliance IM GmbH, Mariendorfer Damm 1, 12099 Berlin — see Imprint for full contact details.
In the following, you will find an overview of the legal basis of the GDPR on which we base the processing of personal data. Please note that in addition to the provisions of the GDPR, national data protection provisions of your or our country of residence or domicile may apply.
In addition to the GDPR, national regulations apply in Germany, in particular the Federal Data Protection Act (BDSG), which contains special provisions on rights of access, erasure, objection, processing of special categories of data, and automated individual decision-making including profiling. State-level data protection laws may also apply. These notices are also intended to satisfy the Swiss Data Protection Act (Swiss DPA) alongside the GDPR.
We take appropriate technical and organisational measures in accordance with the legal requirements, taking into account the state of the art, implementation cost, and the nature, scope, context and purposes of processing, to ensure a level of security appropriate to the risk — including safeguarding confidentiality, integrity and availability of data, controlling access, and ensuring erasure and rapid response to data threats. We use TLS encryption (https) to protect data transmitted via our online services.
In the context of processing personal data, data may be transferred to other places, companies or persons, or disclosed to them — for example service providers commissioned with IT tasks, or providers of embedded website services. Legal requirements are respected, and corresponding contracts protecting your data are concluded with recipients. We may also transfer personal data within our group of companies or organization for administrative purposes, based on legitimate business interests, contractual necessity, or consent.
If we process data in a third country (outside the EU/EEA), or in the context of third-party services or disclosure to other bodies, this only takes place in accordance with legal requirements — on the basis of special guarantees such as EU Commission standard contractual clauses, or recognised certifications / binding internal data protection regulations (Art. 44–49 GDPR).
Data processed by us is erased in accordance with statutory provisions as soon as processing is revoked or permissions no longer apply. Where data must be retained for other legally permissible purposes (e.g. commercial or tax retention obligations), processing is restricted to those purposes. Retention periods are generally ten years for tax-relevant documents and commercial books, and six years for received and sent commercial/business letters.
As a data subject, you are entitled to various rights under Articles 15–21 GDPR:
Cookies are small text files or other data records that store and read information on end devices, for purposes such as login status, shopping cart contents, or usage analytics. We obtain prior consent for cookies in accordance with statutory provisions, except where strictly necessary to provide a service explicitly requested by the user (essential cookies for display, security, load balancing, and stored preferences).
Temporary (session) cookies are deleted once you close your browser after leaving the site. Permanent cookies remain stored afterwards — for example to remember login status or preferred content — and unless stated otherwise, assume a storage duration of up to two years. You can revoke consent and object to processing at any time, and restrict cookies in your browser settings (which may limit functionality). Opt-out for online marketing cookies is also available via optout.aboutads.info and youronlinechoices.com.
Legal basis: Legitimate interests (Art. 6(1)(f) GDPR); Consent (Art. 6(1)(a) GDPR).
Cookie consent management: We use a cookie management solution (BorlabsCookie, hosted locally on our server, no data transfer to third parties) in which consent to cookies can be given, managed and revoked. A pseudonymous user identifier, timestamp and scope of consent, along with browser/system/device information, are stored for up to two years to document consent.
We process data of our contractual and business partners (customers and prospective customers) in the context of contractual and comparable legal relationships and associated communication — to fulfil contractual obligations, protect our rights, and for administrative and business management purposes, as well as security measures. We disclose such data to third parties only as necessary for these purposes or to comply with legal obligations (e.g. telecommunications, transport, subcontractors, banks, tax/legal advisors, payment providers, tax authorities).
Data is generally deleted after the expiry of statutory warranty obligations (typically 4 years) unless retained in a customer account or for legal archiving reasons — 10 years for tax-relevant documents, 6 years for commercial correspondence.
We process user data — including IP address — to provide our online services and transmit content to the user's browser or device, including server log files (address/name of pages and files accessed, date and time, data volumes, browser type and version, operating system, referrer URL, and IP address) for security purposes such as preventing server overload and DDoS attacks. Log file information is generally stored for a maximum of 30 days.
When contacting us (mail, contact form, email, phone or social media), the information of the inquiring person is processed to the extent necessary to respond to the request. This includes contact data, content data, usage data, and meta/communication/process data, on the basis of legitimate interests and/or contractual performance.
The application process requires applicants to provide the data necessary for assessment and selection — typically name, address, contact details and proof of qualifications. Applications may be submitted via online form (transmitted encrypted) or email (not necessarily encrypted end-to-end, and we accept no responsibility for the transmission path). Third-party applicant management and recruitment platforms may be used in compliance with legal requirements.
Special categories of data (Art. 9(1) GDPR, e.g. health data or disability status) requested during the application process are processed in accordance with Art. 9(2)(b)/(c)/(h) GDPR as applicable.
If an application is successful, data may be further processed for the employment relationship. If unsuccessful or withdrawn, applicant data is deleted — generally within six months, to allow us to answer follow-up questions and comply with equal treatment documentation duties. Travel expense invoices are archived per tax regulations. Admission to a talent pool is voluntary, based on consent, and revocable at any time.
We use internet-accessible software services ("cloud services" / "Software as a Service") on providers' servers for storage and management of content. This may include master data, contact data, and process/contract data of data subjects, as well as usage data and metadata processed by providers for security and service optimization.
Google Cloud Services & Google Cloud Storage: Cloud infrastructure, storage and application software services; Service provider: Google Cloud EMEA Limited, 70 Sir John Rogerson's Quay, Dublin 2, Ireland; Legal basis: Legitimate interests (Art. 6(1)(f) GDPR). See Google's website and privacy policy for further information, including data processing agreements and standard contractual clauses for international transfers.
Web analysis evaluates visitor traffic and may include pseudonymous behavioural, interest or demographic information, to recognise usage patterns and optimise our online services. IP addresses are masked (shortened) to protect users, and profiles are generally pseudonymous rather than tied to a real identity.
Google Analytics 4: Used to measure and analyse usage of our online services via a pseudonymous user identification number (no names or email addresses). Time of use, duration, referral sources, and technical device/browser information are stored; higher-level geographic metadata (city, region, country, continent) is derived from IP lookup. For EU users, all data is received and processed via EU domains and servers, IP addresses are not logged and are shortened by default, and sensitive data is deleted before collection. Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal basis: Legitimate interests (Art. 6(1)(f) GDPR). Opt-out available via the Google Analytics opt-out browser add-on or Google Ad Settings.