decídalo

Legal

Privacy Policy

This English version is a translation provided for convenience. The legally binding version is the German original at decidalo.com/datenschutz.

1. Scope

We take the protection of your personal data very seriously and treat your personal data confidentially and in accordance with the statutory data protection provisions and this privacy policy. With this document we inform you about the nature, scope and purpose of the personal data we collect, use and process. This privacy policy also explains the rights you are entitled to. It applies to all websites, applications, services and tools of Data Assessment Solutions GmbH (together the “Services”) that refer to it, regardless of how you access or use those Services, including access from mobile devices.

Persons under the age of 16 are not permitted to use this website on the basis of consent to the storage of cookies under Art. 8 GDPR unless their legal guardians have given legally effective consent to the data processing. The same applies to the use of our contact form and to newsletter subscriptions by persons under 16. We also point out that our offering is aimed exclusively at business customers.

The controller within the meaning of the General Data Protection Regulation (GDPR), of other data protection laws applicable in the member states of the European Union and of other provisions with a data protection character is Data Assessment Solutions GmbH, Misburger Str. 81b, 30625 Hannover, Germany, phone: +49 511 47402330, email: , website: www.data-assessment.com. The data protection officer of the company is Dr. Stephan Glaschak (email: ).

2. Which personal data do we collect and what is it used for?

Definition

Personal data is information about an identified or identifiable natural person. An identifiable natural person is a person who can be identified directly or indirectly by reference to an attribute. Such an attribute can be a name, an identification number, location data or an online identifier, or specific information about the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. Data that is anonymized or aggregated and can no longer be used to identify a specific natural person, whether in combination with other data or otherwise, does not count as personal data.

Website

You can use our website without providing personal data. Each time a page is called up, however, our internet service provider records a range of general data and information that is temporarily stored in the log files of the web server. This can include the browser types and versions used, the operating system of the accessing system, the website from which an accessing system reaches our website (the referrer), the subpages accessed on our website, the date and time of access, an internet protocol address (IP address), the internet service provider of the accessing system and other similar data and information that serves to avert danger in the event of attacks on our information technology systems.

When processing this general data and information, we draw no conclusions about the data subject. Rather, this information is needed to deliver the content of our website correctly and to provide law enforcement authorities with the information required for prosecution in the event of a cyberattack. The anonymous data of the server log files is stored separately from any personal data provided by a data subject.

Products

Data Assessment Solutions GmbH is a German provider of software solutions and related services. With decídalo we offer a SaaS industry solution for IT services and consulting companies. Alongside comprehensive skill and CV management for a company’s own employees, the software provides a way to manage reference projects. Its resource management also covers the staffing process through to time recording and supplies various aggregated views.

decídalo also offers integrations with Microsoft 365 and other cloud platforms. This makes it possible to take skills from existing documents, emails, external databases or chats, to link them to an existing decídalo license as required, and to enrich and analyze them with skills, projects and skill demands through Azure OpenAI Services.

In providing our SaaS application we collect and process only the data that is strictly necessary to operate the platform. The legal basis is the provision of contractually agreed services, authorization and access control and, where agreed, the provision of service and maintenance work as part of performing the contract under Art. 6(1)(b) GDPR.

The customer is the controller within the meaning of Art. 4(7) GDPR with regard to the use of our SaaS applications, that is, the collection, processing and use of their users’ data as well as the collection, processing and use of personal data within the decídalo account for which they are responsible. The skill profiles of a customer’s own employees are a central component of the database connected to decídalo. It is the customer’s responsibility to obtain any necessary declarations of consent from the data subjects and to inform them of their rights and obligations under data protection law.

The data records collected with decídalo are stored in the Azure cloud and are not passed on to third parties. Only the account owner, the users authorized by the account owner and our support department have access to the database. The data records of an account are irretrievably deleted when the respective contractual relationship ends.

Contact form and email inquiries

If you send us inquiries via the contact form on our website, by email or in any other way, your details including the contact data you provide will be stored by us in order to process the inquiry and in case of follow-up questions. You always provide these details voluntarily. We do not pass your data on without your consent. Please note that data transmission over the internet, for example when communicating by email, can have security gaps. Complete protection of data against access by third parties is therefore not possible.

Newsletter

If you would like to receive our free newsletter, we need an email address from you; on initial registration the IP address of the computer used and the date and time of registration may also be stored. You can optionally provide your first and last name so that we can address you personally. No further data is collected. We use this data exclusively to send the newsletter and do not pass it on to third parties. You can withdraw the consent you have given to the storage of the data and the email address and to their use for sending the newsletter at any time, for example through the corresponding link in the newsletter.

Newsletter tracking

Our newsletters may contain tracking pixels. A tracking pixel is a miniature graphic embedded in emails that are sent in HTML format in order to enable log file recording and log file analysis. This allows a statistical evaluation of the success or failure of online marketing campaigns. Using the embedded tracking pixel, we can see whether and when an email was opened by the recipient and which links in the email were clicked. Personal data collected through the tracking pixels contained in the newsletters is stored and evaluated by us in anonymized form in order to optimize the newsletter distribution and to tailor the content of future newsletters even better to the interests of the recipients. This personal data is not passed on to third parties. Data subjects are entitled at any time to withdraw the separate declaration of consent given through the double opt-in procedure. After a withdrawal we delete this personal data. We automatically treat unsubscribing from the newsletter as a withdrawal.

Customers

Within an existing contract we also use personal data to fulfill the contract concluded with you, to provide you with our Services and to meet our legal obligations. This includes, for example, payment processing and account administration, operating, assessing and improving our Services, safeguarding our Services and keeping them functional, contacting you in the course of performing the contract, and other customer service measures. We may contact you for these reasons by email, telephone or post.

Application process

We process the personal data of applicants in order to handle application procedures. Processing usually takes place electronically, for example when someone sends application documents to us by email. If we conclude an employment contract, the data submitted is stored for the purpose of handling the employment relationship in compliance with the statutory provisions.

3. Do we share personal data?

Data is only passed on to third parties without your consent if we are legally obliged to do so or if it is necessary to perform the contract and serves our legitimate interests, provided your rights and freedoms do not override them. We have introduced appropriate control mechanisms to reconcile our interests with your rights. We may pass your personal data on to the following third parties and for the following purposes:

External service providers

We pass personal data on to external service providers who support us in our business operations, who provide technical, sales, financial or logistical services for us, or who support us in preventing, detecting, containing and investigating potentially unlawful acts, in complying with our legal obligations, in enforcing our terms and conditions, in defending legal claims, in debt collection, in partner and bonus programs and in other business transactions.

When we pass personal data on to external providers, this happens solely on the basis of an agreement that limits the processing of that personal data by the external provider to the purposes required to fulfill their contractual obligations towards us. The external provider is obliged to take appropriate security measures with regard to this data. External providers are in no way entitled to pass personal data on.

Government authorities

We pass personal data on to law enforcement authorities, government agencies or third parties authorized by law on the basis of a request for information or in connection with an investigation or the suspicion of a criminal offense, an unlawful act or another act that may result in legal liability for us, for you or for other users. In such cases we only disclose the data that in our assessment is relevant to the investigation or the request for information, such as name, place, postal code, telephone number, email address or IP address.

Transfers to third countries

Processing of personal data in a third country by us or on our behalf only takes place within the limits permitted by law and by contract and where the special requirements of Art. 44 et seq. GDPR are met. This means that processing then takes place, for example, on the basis of special safeguards such as an officially recognized finding of a level of data protection equivalent to that of the EU, or in compliance with officially recognized special contractual obligations (the standard contractual clauses of the EU Commission), supported by an individual risk assessment.

Legal successors, group companies

In the event of a merger with another company or an acquisition by another company we may pass information on to that company in accordance with our data protection principles. Should such an event occur, we will require the newly merged company to comply with the statutory data protection provisions regarding your personal data. Should your personal data be collected, used, passed on or stored for any purposes not mentioned in this document, you will be informed in advance about the processing of your data for these new purposes.

4. How long do we keep personal data?

Personal data is stored on the basis of the applicable statutory retention periods. Once a period expires, the corresponding data is deleted, provided that a) the data is no longer required to perform the contract, b) you have not explicitly agreed to an extended retention period and c) no other legitimate interests of our company prevent deletion. Another legitimate interest in this sense could arise, for example, from the burden of proof in proceedings under the German General Equal Treatment Act (AGG) in connection with application procedures.

5. How do we use cookies and tracking technologies?

Cookies

These web pages partly use cookies. Cookies do no harm to your computer and contain no viruses. Cookies help to make our offering more user-friendly, more effective and more secure. Cookies are small text files that are placed on your computer and stored by your browser. Most of the cookies we use are session cookies. They are deleted automatically at the end of your visit. Other cookies remain stored on your device until you delete them.

We use technically necessary cookies to ensure the technical operation and the basic functions of our website. The legal basis for this is our legitimate interest in the technically flawless operation and the smooth functioning of our website under Art. 6(1)(f) GDPR. With your consent, we also use cookies for marketing purposes. You will find the details in the section on Snitcher below.

You can prevent cookies from being set by our website and other websites at any time through the corresponding setting in the internet browser you use and thereby permanently object to cookies being set. You can also delete cookies that have already been set at any time through an internet browser or other software programs. This is possible in all common internet browsers. If you deactivate cookies, the functionality of this website may be limited.

We do not store your decision about visitor analytics in a cookie but in your browser’s local storage. This entry does not leave your device and is not transmitted to us. If you clear your browser’s website data, we will ask again on your next visit.

Snitcher

With your consent, this website uses the “Snitcher” service provided by Snitcher B.V., Oude Enghweg 2, 1217 JC Hilversum, Netherlands. Snitcher matches the IP address of your internet connection against a database of corporate networks and then shows us which organization a visit to our website comes from. The aim is not to identify individual people but to recognize which organizations take an interest in what we offer.

The data processed are your IP address, the pages you open, the time and duration of your visit, the referring page and technical details about your browser and device. Snitcher also stores an identifier on your device so that several visits can be linked to one another: a device identifier with a term of one year and a session identifier for 30 minutes, kept as a cookie and in your browser’s local storage.

The legal basis for storing and reading this identifier on your device is your consent under Section 25(1) TDDDG, and for the subsequent processing of the data your consent under Art. 6(1)(a) GDPR. Without your consent the service is not loaded at all: no data is transmitted to Snitcher and no information is stored on your device.

You can withdraw your consent at any time with effect for the future. To do so, click “Cookie settings” at the bottom of any page and choose “Decline”. This does not affect the lawfulness of the processing carried out up to the withdrawal.

Snitcher processes the data for us as a processor on the basis of a contract under Art. 28 GDPR. According to the provider, the data collected is processed and stored exclusively on servers in Frankfurt am Main and does not leave the European Union. Further information is available in Snitcher’s privacy policy at https://www.snitcher.com/privacy-policy.

Cloudflare Turnstile

To protect our contact form against automated and abusive submissions (bots, spam) we use the service Turnstile provided by Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA). Turnstile checks whether a submission is made by a human. Technical information from your browser and your IP address are transmitted to Cloudflare and evaluated there. According to the provider, Turnstile is designed to minimize data and does not set cookies for tracking purposes; the data is not used for advertising. The processing is based on our legitimate interest in protecting our website against misuse and spam under Art. 6(1)(f) GDPR. Where personal data is transferred to the USA in this context, this takes place on the basis of the standard contractual clauses of the EU Commission. You can find further information in Cloudflare’s privacy policy at https://www.cloudflare.com/privacypolicy/.

6. Use of Azure OpenAI Services for conversational AI in decídalo

In this section we would like to inform you how we use Azure OpenAI Services as part of our SaaS solutions. We attach great importance to the protection of your personal data and want to explain transparently how we integrate these services and which data protection aspects are taken into account.

Our SaaS solution decídalo uses Azure OpenAI Services in order to offer our customers high-quality conversational AI services based on Microsoft Azure. These services allow users to interact with an AI-driven application in order to carry out certain tasks or obtain information. Azure OpenAI works on the basis of the OpenAI GPT, Codex and DALL-E models, is operated by Microsoft Ireland Operations Ltd., One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland, and is provided within Azure.

Data processing and transfer

When the conversational AI services are used, text messages or inputs are sent to the Azure OpenAI Services. This data is processed on Microsoft Azure servers. In communication with the Azure OpenAI Services, certain data including the text entered may be transferred to Microsoft Azure in order to carry out the AI processing. Beyond this, no data is passed on to third parties.

Data storage and use

The OpenAI models implemented in our SaaS solution decídalo are stateless in principle, which means that no records of earlier interactions are kept; each interaction request is processed entirely on the basis of the information directly associated with it. Neither user inputs nor AI suggestions are stored in the model. The optionally available decídalo Teams Chat App uses an extended Azure OpenAI model that allows the customer to access an existing database by chat through a Microsoft Teams integration and to specify or refine chat inputs on the basis of earlier AI responses.

Some functions require the interaction with the AI to be stored for a limited period. The data store in which customer requests (inputs) and AI responses (outputs) are stored is logically separated by customer on the Azure OpenAI resource in the customer’s Azure tenant (every request contains the resource ID of the individual user’s Azure OpenAI resource). The stored data is not passed on to third parties and is deleted automatically after 3 months.

Microsoft guarantees that all customer requests (inputs) and AI responses (outputs) as well as all real customer and training data are NOT available to other customers, are NOT available to OpenAI, are NOT used to improve OpenAI models, are NOT used to improve Microsoft or third-party products or services, and are NOT used to automatically improve Azure OpenAI models for use in our resources. Our individual Azure OpenAI models are available exclusively for use by us and our customers.

Legal basis for processing

Your data is processed in connection with the use of the conversational AI services under Art. 6(1)(f) GDPR on the basis of our legitimate interests in offering you an optimized and personalized user experience.

Security measures

We have implemented appropriate technical and organizational security measures to protect the confidentiality and integrity of your data. Microsoft Azure likewise applies strict security precautions to protect the data processed in connection with the conversational AI services.

The Azure OpenAI Services are controlled entirely by Microsoft and hosted in the Azure environment. The Azure services do NOT interact with other services operated by OpenAI (for example ChatGPT or the OpenAI API). The AI we use was trained with randomly generated test data. Neither existing nor future real customer data has been or will be used to train the AI model.

Data subject rights

In connection with the processing of your data for the conversational AI services you have the right to information, rectification, erasure and objection. You can find further information about your rights in the general section “What choices and rights do you have” under point 7 of this privacy policy.

Microsoft provides further information on data protection questions relating to the use of Azure OpenAI Services on the following pages: https://learn.microsoft.com/en-us/azure/ai-services/openai/faq and https://learn.microsoft.com/en-us/legal/cognitive-services/openai/data-privacy. Microsoft’s fundamental principles for responsibility in the development and use of AI are available at https://www.microsoft.com/en-us/ai/responsible-ai.

Contact

If you have questions or concerns about the use of the conversational AI services or about data processing within our SaaS solution, please feel free to contact our data protection team.

7. What choices and rights do you have regarding the processing of personal data?

Legal basis

Unless the legal basis is explicitly stated in an individual case, the following applies: the legal basis for obtaining consent is Art. 6(1)(a) and Art. 7 GDPR, the legal basis for processing in order to provide our services, carry out contractual measures and answer inquiries is Art. 6(1)(b) GDPR, the legal basis for processing in order to fulfill our legal obligations is Art. 6(1)(c) GDPR, and the legal basis for processing in order to safeguard our legitimate interests is Art. 6(1)(f) GDPR.

Newsletter

You have the right to withdraw your consent to receiving the newsletter at any time. Every newsletter contains a corresponding link for this purpose. You can also unsubscribe from the newsletter at any time directly by telephone, email or post.

Rights

Under Art. 15 GDPR you also have the right to information about the nature, scope and purpose of the personal data stored, the right to rectification under Art. 16 GDPR, the right to erasure under Art. 17 GDPR, the right to restriction of processing under Art. 18 GDPR, the right to object under Art. 21 GDPR and the right to data portability under Art. 20 GDPR. The restrictions under Sections 34 and 35 of the German Federal Data Protection Act (BDSG) apply to the right to information and the right to erasure. In addition, you have the right to lodge a complaint with a data protection supervisory authority under Art. 77 GDPR in conjunction with Section 19 BDSG. Please contact us using the contact options given at the beginning if you would like to exercise your rights. On your request we will delete your personal data insofar as this is possible within your contractual relationship and in accordance with applicable law.

Consequences

If you ask us to stop processing your personal data in whole or in part, or if you withdraw your consent (where applicable) to the use or disclosure of your personal data for the purposes set out in this privacy policy, we may no longer be able to provide you with all Services. Please note that this does not automatically release you from payment obligations under existing contracts.

8. How do we protect your personal data?

Your personal data is protected by technical and organizational security measures in order to minimize the risks of loss, misuse, unauthorized access and unauthorized disclosure and alteration. For this purpose we use firewalls and data encryption, for example, but also physical access restrictions for our data processing facilities and authorization controls for data access. Subcontractors are obliged to comply with data protection provisions under Art. 28(4) GDPR.

We are happy to provide further information on request.

9. Other information

We may amend this privacy policy at any time by publishing the amended version on this website. If you have any further questions, we are happy to help.