Privacy Policy
September 2024
Wir (i.e. the company that provides you with this privacy notice or named in the imprint as the operator of this site) take the protection of your personal data seriously. This privacy notice describes how we collect and record your personal data, use, disclose, transfer, and store them (“process”). The personal data collected depends on the context of your interactions with us, the products, services, and features obtained from us, your location, and residence, as well as applicable law.
1. Processing of personal data in connection with your use of our websites, applications, and online services Data categories and purpose of processing
As part of your use of our external and internal websites, applications, or online services (each an “Online Offering”), we process the following categories of personal data:
- Your contact information, such as first and last name, business address, business phone number, business mobile number, and business email address,
- Organisation information, including position and company name,
- Further personal data that you provide in contact and other forms of an online offer,
- Information you provide in a support request, survey, comment, or forum post,
- Information collected automatically when using an online offer, such as your device and user ID, information about your operating system, pages and services you have used and visited during your visit, as well as the date and time of a user request.
We process your personal data for the following purposes:
- To enable you to use the services and functions of the online offers, including creating and administering your online account, within updates, security, and error correction measures,
- To provide customer support and to improve and develop our online offers,
- To charge for the use of an online offer, to determine your identity and enable user authentication,
- To handle your request or instruction,
- To process your order and make related information and offers accessible to you,
- To contact you with information and offers regarding our products and services and to send you further marketing information or contact you as part of customer satisfaction surveys,
- To enforce our terms of use, assert legal claims or defend them, and to avert and prevent fraudulent and similar actions, including attacks on our IT infrastructure.
Online offers provided by your company
In some cases, our online offers are provided to you by the company you are employed with. When you use an online offer provided by your company, the processing of personal data, which is entered into the content of the online offer by you or your company, takes place on behalf and according to the instructions of your company as part of a data processing contract between your company and us. In this case, your company is the data controller. If you have questions about personal data that we process as a data processor for your company, please contact your company.
2. Processing of personal data in connection with your use of our marketplaces Data categories and purpose of processing
As part of your use of our marketplaces (each a “Marketplace”), we process the following categories of personal data:
- Your contact information, such as first and last name, business address, business phone number, business mobile number, and business email address,
- Organisation information, including position and company name,
- Payment data, such as information necessary for processing payment transactions or fraud prevention, including credit card details and card verification numbers,
- Further personal data that you provide in contact and other forms of a marketplace,
- Information you provide in a support request, survey, comment, or forum post;
- Information legally required in the context of compliance and export control screenings, such as date of birth,
nationality, residence, identification numbers, information on relevant legal proceedings and other legal disputes,
- Information automatically collected in the context of using a marketplace, such as your device and user ID,
information about your operating system, pages and services you have used and visited during your visit, and
date and time of a user request.
We process your personal data for the following purposes:
- Communicate with you about our services and products, e.g., to process your inquiries or provide technical information about products,
- Planning, executing, and managing the (contractual) business relationship, e.g., to process orders of products and services, collect payments for accounting and billing, and perform deliveries, maintenance, or repairs,
- Contacting you with information and offers regarding our products and services and conducting further marketing activities and customer satisfaction surveys,
- Maintaining and protecting the security of our products and services as well as our websites, preventing and detecting security risks, fraudulent activities, or other criminal or malicious actions,
- Complying with legal requirements (e.g., tax and commercial retention obligations), existing obligations to conduct compliance screenings (to prevent economic crime or money laundering), and our policies and industry standards,
- Settling disputes, enforcing existing contracts, and asserting, exercising, and defending legal claims.
3. Processing personal data of business partners Data categories and purpose of processing
As part of cooperation with business partners, we process personal data from end users and contact persons at customers, prospects, distributors, suppliers, and partners (each a “Business Partner”):
- Contact information, such as first and last names, business address, business phone number, business mobile number, and business email address,
- Organisation information, including position and company name,
- Payment data, such as information necessary for processing payment transactions or fraud prevention, including credit card details and card verification numbers,
- Further information required for processing in the framework of a project or handling a contractual relationship with us or volunteered by business partners, e.g., in the context of made orders, inquiries or project details,
- Personal data collected from publicly available sources (including company- or job-related social networks and websites), information databases, or obtained from credit reporting agencies,
- Information legally required in the context of compliance and export control screenings, such as date of birth,
nationality, residence, identification numbers, information on relevant legal proceedings and other legal disputes involving business partners.
We process personal data for the following purposes:
- Communicating with business partners about products, services, and projects, e.g., to process business partner inquiries or provide technical information about products,
- Planning, executing, and managing the (contractual) business relationship between the business partner and us, e.g., to process orders of products and services, collect payments, for accounting and billing, and perform deliveries, maintenance, or repairs,
- Creating a personal profile with business-related information about interactions between you and us to offer you and the company you work for relevant information and suitable offers to services and products, and improve our personal communication with you,
- Conducting market analysis, sweepstakes, competitions, or similar actions and events,
- Contacting with information and offers regarding our products and services and conducting further marketing activities and customer satisfaction surveys,
- Maintaining and protecting the security of our products and services as well as our websites, preventing and detecting security risks, fraudulent activities, or other criminal or malicious actions,
- Complying with legal requirements (e.g., tax and commercial retention obligations), existing obligations to conduct compliance screenings (to prevent economic crime or money laundering), and our policies and industry standards,
- Settling disputes, enforcing existing contracts, and asserting, exercising, and defending legal claims.
4. Processing of personal data for customer satisfaction surveys and direct marketing
Within the limits of applicable law, we may use your contact data for direct marketing purposes (e.g., trade fair invitations, newsletters with information and offers regarding our products and services) and for conducting customer satisfaction surveys, also via email. You have the right to object to the use of your contact data for these purposes at any time by sending an email to contact@nova-search, or by using the opt-out option in the message you have received.
5. Processing of personal data in connection with your application
If you apply for a vacancy with us, we process your personal data as described in the privacy policy of the nova-search recruiting portal or the application platform you are using.
6. Transfer and disclosure of personal data
We only transfer your personal data as described below:
Companies and distribution partners
To the extent and for the purpose necessary for conducting our business relationship with you, we transfer your personal data to our companies and other third parties (e.g., distribution partners and agents). For example, we supply certain products and services only through local business partners, and in this case, we transfer your personal data to our respective local companies or other distribution partners who handle the business relationship with you.
Transactions on our marketplaces
Through our marketplaces, we also provide products, services, and offers from our companies and other third parties. We transfer personal data of our customers in connection with these transactions to the respective company and/or other third parties.
Service providers
We engage companies and other companies to perform tasks on our behalf, such as manufacturers, service providers, IT services, or payment processing. These companies and other companies process personal data solely for the purpose of the commissioned products and services.
Other third parties
We transfer personal data in connection with the fulfillment of legal obligations or the establishment, exercise, or defense of rights or claims to other third parties (e.g., for court and arbitration proceedings, to regulatory, law enforcement, and government authorities, lawyers, and consultants). Recipients of your personal data may be located outside the country where you reside. Personal data that you publish via online offerings (e.g., in chat rooms or forums) can be accessible to other registered users of the respective online offering worldwide.
7. Retention periods
Unless an explicit retention period is specified at the time of collection (e.g., as part of a consent declaration), your personal data is deleted when it is no longer needed to fulfill the purpose of storage, unless legal retention periods (e.g., commercial and tax retention periods) oppose deletion.
8. Your rights
According to applicable data protection law, you may have the right to:
- Request confirmation as to whether we process personal data about you and access to the personal data we process about you,
- Request correction of inaccurate personal data,
- Request the deletion of personal data we process about you,
- Request restriction of processing of personal data,
- Request portability of personal data you actively provided to us,
- Object to the processing of personal data for reasons arising from your particular situation, or
- Withdraw a declared consent.
9. Data security
We take appropriate technical and organizational measures to protect personal data from accidental or unlawful destruction, use, or alteration, as well as unauthorized disclosure or unauthorized access.
10. Contact
Our data protection organisation assists with all questions regarding data protection. Complaints can also be made to our data protection organisation, and you may exercise the rights mentioned in this privacy notice.
Our data protection organisation can be contacted at datenschutz@nova.search.
Our data protection organisation is always committed to addressing and remedying your inquiries and complaints. However, in addition to contacting the data protection organisation, you always have the option to contact the competent data protection supervisory authority.
11. Processing of personal data in the scope of the EU General Data Protection Regulation
This section applies if your personal data is processed by one of our companies located in the European Economic Area.
Controller responsible for data processing Online offers
The company named in the imprint of the online offer is the controller responsible for data processing as defined by the GDPR for the processing activities described in this privacy notice.
Marketplaces
The company specified on the marketplace as the operator of the marketplace is the data processing controller.
Personal data of business partners in our customer relationship systems
Contact information of business partners is shared with other companies as part of your business relationship with us. We and these companies are jointly responsible for protecting your personal data (Art. 26 GDPR). To ensure that you can easily and reliably exercise your data protection rights within this joint responsibility, we agreed with these companies that you can exercise your rights, as described in section 6, not only with the respective company but also centrally with Nova Search GmbH. Contact us at: datenschutz@nova.search.de.
Legal basis for processing
The GDPR obliges nova-search to inform you about the legal basis of data processing. Unless explicitly stated otherwise upon collection, the legal basis for data processing is:
- The execution and fulfillment of a contract with you (Article 6 (1) (b) GDPR) (“Contract performance"),
- Compliance with legal obligations to which we are subject (Article 6 (1) (c) GDPR) (“Compliance with legal obligations"), or
- Protecting our legitimate interests (Article 6 (1) (f) GDPR) (“Legitimate interest in processing").
Our legitimate interest lies in processing your personal data for the purpose of:
(i) Offering and operating the online offers and
(ii) Initiating, executing, and managing our business relationship.
As specified in the table below, if our legitimate interest in processing is indicated as the legal basis for the processing of your personal data, we believe that your interests, fundamental rights, and freedoms are sufficiently considered because:
(i) We regularly review the processing activities and background processes described in this privacy notice,
(ii) We consider the protection of your personal data in our processes, including the Binding Corporate Rules for the Protection of Personal Data (nova-search Binding Corporate Rules),
(iii) We ensure the transparency of our processing activities, and
(iv) You have the previously mentioned rights regarding our processing activities.
If you want more information regarding the balancing of interests described, please contact our data protection organisation at datenschutz@nova-search.de.
In the event you have expressly consented to the processing of your personal data in an individual case, this consent is the legal basis for processing (Article 6 (1) (a) GDPR) (“Consent").
Processing personal data related to the use of our online offerings - Purpose and legal basis
- Enabling the use of the services and functions of the online offerings, including creating and administering your online account, within updates, security, and error correction measures, to provide customer support, and to improve and develop our online offerings
- Contract performance (Article 6 (1) (b) GDPR)
- Legitimate interest in processing (Article 6 (1) (f) GDPR)
- Billing for the use of an online offer
- Contract performance (Article 6 (1) (b) GDPR)
- Legitimate interest in processing (Article 6 (1) (f) GDPR)
- Determining identity and user authentication
- Contract performance (Article 6 (1) (b) GDPR)
- Legitimate interest in processing (Article 6 (1) (f) GDPR)
- Processing your request or instruction
- Contract performance (Article 6 (1) (b) GDPR)
- Legitimate interest in processing (Article 6 (1) (f) GDPR)
- Processing your order and offering related information and offers
- Contract performance (Article 6 (1) (b) GDPR)
- Legitimate interest in processing (Article 6 (1) (f) GDPR)
- Sending marketing information or contacting within the context of customer satisfaction surveys, as described in section 3
- Consent, if granted voluntarily (Article 6 (1) (a) GDPR)
- Legitimate interest in processing (Article 6 (1) (f) GDPR)
- Enforcing our terms of use, asserting and defending legal claims, preventing and averting fraudulent and similar actions, including attacks on our IT infrastructure
- Compliance with legal obligations (Article 6 (1) (c) GDPR)
- Legitimate interest in processing (Article 6 (1) (f) GDPR)
- Processing personal data related to your use of our marketplaces and from business partners
- Communication regarding products, services, and projects, e.g., to process business partner inquiries or provide technical information about products
- Contract performance (Article 6 (1) (b) GDPR)
- Legitimate interest in processing (Article 6 (1) (f) GDPR)
- Planning, executing, and managing the (contractual) business relationship between us, e.g., to process orders of products and services, collect payments, for accounting and billing, and perform deliveries, maintenance, or repairs
- Contract performance (Article 6 (1) (b) GDPR)
- Compliance with legal obligations (Article 6 (1) (c) GDPR)
- Creating a personal profile with business-related information about interactions between you and us to offer you and the company you work for relevant information and suitable offers to services and products and improve our personal communication with you
- Legitimate interest in processing (Article 6 (1) (f) GDPR)
- Conducting market analysis, sweepstakes, competitions, or similar actions and events
- Consent, if granted voluntarily (Article 6 (1) (a) GDPR)
- Legitimate interest in processing (Article 6 (1) (f) GDPR)
- Conducting customer satisfaction surveys and direct marketing as described in section 4
- Consent, if granted voluntarily (Article 6 (1) (a) GDPR)
- Legitimate interest in processing (Article 6 (1) (f) GDPR)
- Maintaining and protecting the security of our products and services as well as our websites, preventing and detecting security risks, fraudulent activities, or other criminal or malicious actions
- Legitimate interest in processing (Article 6 (1) (f) GDPR)
- Complying with legal requirements (e.g., tax and commercial retention obligations), existing obligations to conduct compliance screenings (to prevent economic crime or money laundering), and our policies and industry standards
- Compliance with legal obligations (Article 6 (1) (c) GDPR)
- Legitimate interest in processing (Article 6 (1) (f) GDPR)
- Settling disputes, enforcing existing contracts, and asserting, exercising, and defending legal claims
- Compliance with legal obligations (Article 6 (1) (c) GDPR)
- Legitimate interest in processing (Article 6 (1) (f) GDPR)
- Processing your contact details for direct marketing purposes (e.g., trade fair invitations, newsletters with additional information and offers regarding our products and services) and conducting customer satisfaction surveys
- Consent, if granted voluntarily (Article 6 (1) (a) GDPR)
- Legitimate interest in processing (Article 6 (1) (f) GDPR)
International data transfers
When transferring your personal data to a recipient located outside the European Economic Area, we ensure your data is adequately protected in accordance with the GDPR. In this context, if legally required, we take the following measures:
- We only transfer your personal data to companies in such countries if these have implemented Binding Corporate Rules for the Protection of Personal Data (Binding Corporate Rules, "BCR").
- Personal data is only transferred to non-group external recipients in such countries if these have
(i) concluded EU Standard Contractual Clauses with us or
(ii) introduced Binding Corporate Rules.
Further information and a copy of the implemented measures can be obtained at datenschutz@nova-search.de.
The relevant data protection authority
Our data protection organisation supports all questions related to data protection. In addition to contacting our data protection organisation, you always have the option to contact the relevant data protection supervisory authority.
An overview of national and international data protection authorities can be found here.
12. Processing of personal data within the scope of Swiss data protection law
Any affected data subject has the right to enforce their rights in court or to file a complaint with the relevant data protection authority. The relevant data protection authority of Switzerland is the Federal Data Protection and Information Commissioner (http://www.edoeb.admin.ch).
13. Additional information for users of online offerings and business partners in the USA Do Not Track
Our online offerings do not recognize so-called "Do Not Track" settings of your web browser.
For further information regarding the "Do Not Track" functionality, please visit the help pages of your web browser.
Use by children
Our online offerings are not directed at children under the age of 13. Unless legally required, we do not knowingly collect personal data from children under the age of 13 without the consent of their guardians. We collect and transfer personal data of children only to the extent legally permitted, to obtain the consent of the guardians, or to protect the child.
Your rights in certain US states
Under the laws of some US states, residents of these states have additional rights concerning their personal data. Further information can be found here.
Privacy Policy
September 2024
Wir (i.e. the company that provides you with this privacy notice or named in the imprint as the operator of this site) take the protection of your personal data seriously. This privacy notice describes how we collect and record your personal data, use, disclose, transfer, and store them (“process”). The personal data collected depends on the context of your interactions with us, the products, services, and features obtained from us, your location, and residence, as well as applicable law.
1. Processing of personal data in connection with your use of our websites, applications, and online services Data categories and purpose of processing
As part of your use of our external and internal websites, applications, or online services (each an “Online Offering”), we process the following categories of personal data:
- Your contact information, such as first and last name, business address, business phone number, business mobile number, and business email address,
- Organisation information, including position and company name,
- Further personal data that you provide in contact and other forms of an online offer,
- Information you provide in a support request, survey, comment, or forum post,
- Information collected automatically when using an online offer, such as your device and user ID, information about your operating system, pages and services you have used and visited during your visit, as well as the date and time of a user request.
We process your personal data for the following purposes:
- To enable you to use the services and functions of the online offers, including creating and administering your online account, within updates, security, and error correction measures,
- To provide customer support and to improve and develop our online offers,
- To charge for the use of an online offer, to determine your identity and enable user authentication,
- To handle your request or instruction,
- To process your order and make related information and offers accessible to you,
- To contact you with information and offers regarding our products and services and to send you further marketing information or contact you as part of customer satisfaction surveys,
- To enforce our terms of use, assert legal claims or defend them, and to avert and prevent fraudulent and similar actions, including attacks on our IT infrastructure.
Online offers provided by your company
In some cases, our online offers are provided to you by the company you are employed with. When you use an online offer provided by your company, the processing of personal data, which is entered into the content of the online offer by you or your company, takes place on behalf and according to the instructions of your company as part of a data processing contract between your company and us. In this case, your company is the data controller. If you have questions about personal data that we process as a data processor for your company, please contact your company.
2. Processing of personal data in connection with your use of our marketplaces Data categories and purpose of processing
As part of your use of our marketplaces (each a “Marketplace”), we process the following categories of personal data:
- Your contact information, such as first and last name, business address, business phone number, business mobile number, and business email address,
- Organisation information, including position and company name,
- Payment data, such as information necessary for processing payment transactions or fraud prevention, including credit card details and card verification numbers,
- Further personal data that you provide in contact and other forms of a marketplace,
- Information you provide in a support request, survey, comment, or forum post;
- Information legally required in the context of compliance and export control screenings, such as date of birth,
nationality, residence, identification numbers, information on relevant legal proceedings and other legal disputes,
- Information automatically collected in the context of using a marketplace, such as your device and user ID,
information about your operating system, pages and services you have used and visited during your visit, and
date and time of a user request.
We process your personal data for the following purposes:
- Communicate with you about our services and products, e.g., to process your inquiries or provide technical information about products,
- Planning, executing, and managing the (contractual) business relationship, e.g., to process orders of products and services, collect payments for accounting and billing, and perform deliveries, maintenance, or repairs,
- Contacting you with information and offers regarding our products and services and conducting further marketing activities and customer satisfaction surveys,
- Maintaining and protecting the security of our products and services as well as our websites, preventing and detecting security risks, fraudulent activities, or other criminal or malicious actions,
- Complying with legal requirements (e.g., tax and commercial retention obligations), existing obligations to conduct compliance screenings (to prevent economic crime or money laundering), and our policies and industry standards,
- Settling disputes, enforcing existing contracts, and asserting, exercising, and defending legal claims.
3. Processing personal data of business partners Data categories and purpose of processing
As part of cooperation with business partners, we process personal data from end users and contact persons at customers, prospects, distributors, suppliers, and partners (each a “Business Partner”):
- Contact information, such as first and last names, business address, business phone number, business mobile number, and business email address,
- Organisation information, including position and company name,
- Payment data, such as information necessary for processing payment transactions or fraud prevention, including credit card details and card verification numbers,
- Further information required for processing in the framework of a project or handling a contractual relationship with us or volunteered by business partners, e.g., in the context of made orders, inquiries or project details,
- Personal data collected from publicly available sources (including company- or job-related social networks and websites), information databases, or obtained from credit reporting agencies,
- Information legally required in the context of compliance and export control screenings, such as date of birth,
nationality, residence, identification numbers, information on relevant legal proceedings and other legal disputes involving business partners.
We process personal data for the following purposes:
- Communicating with business partners about products, services, and projects, e.g., to process business partner inquiries or provide technical information about products,
- Planning, executing, and managing the (contractual) business relationship between the business partner and us, e.g., to process orders of products and services, collect payments, for accounting and billing, and perform deliveries, maintenance, or repairs,
- Creating a personal profile with business-related information about interactions between you and us to offer you and the company you work for relevant information and suitable offers to services and products, and improve our personal communication with you,
- Conducting market analysis, sweepstakes, competitions, or similar actions and events,
- Contacting with information and offers regarding our products and services and conducting further marketing activities and customer satisfaction surveys,
- Maintaining and protecting the security of our products and services as well as our websites, preventing and detecting security risks, fraudulent activities, or other criminal or malicious actions,
- Complying with legal requirements (e.g., tax and commercial retention obligations), existing obligations to conduct compliance screenings (to prevent economic crime or money laundering), and our policies and industry standards,
- Settling disputes, enforcing existing contracts, and asserting, exercising, and defending legal claims.
4. Processing of personal data for customer satisfaction surveys and direct marketing
Within the limits of applicable law, we may use your contact data for direct marketing purposes (e.g., trade fair invitations, newsletters with information and offers regarding our products and services) and for conducting customer satisfaction surveys, also via email. You have the right to object to the use of your contact data for these purposes at any time by sending an email to contact@nova-search, or by using the opt-out option in the message you have received.
5. Processing of personal data in connection with your application
If you apply for a vacancy with us, we process your personal data as described in the privacy policy of the nova-search recruiting portal or the application platform you are using.
6. Transfer and disclosure of personal data
We only transfer your personal data as described below:
Companies and distribution partners
To the extent and for the purpose necessary for conducting our business relationship with you, we transfer your personal data to our companies and other third parties (e.g., distribution partners and agents). For example, we supply certain products and services only through local business partners, and in this case, we transfer your personal data to our respective local companies or other distribution partners who handle the business relationship with you.
Transactions on our marketplaces
Through our marketplaces, we also provide products, services, and offers from our companies and other third parties. We transfer personal data of our customers in connection with these transactions to the respective company and/or other third parties.
Service providers
We engage companies and other companies to perform tasks on our behalf, such as manufacturers, service providers, IT services, or payment processing. These companies and other companies process personal data solely for the purpose of the commissioned products and services.
Other third parties
We transfer personal data in connection with the fulfillment of legal obligations or the establishment, exercise, or defense of rights or claims to other third parties (e.g., for court and arbitration proceedings, to regulatory, law enforcement, and government authorities, lawyers, and consultants). Recipients of your personal data may be located outside the country where you reside. Personal data that you publish via online offerings (e.g., in chat rooms or forums) can be accessible to other registered users of the respective online offering worldwide.
7. Retention periods
Unless an explicit retention period is specified at the time of collection (e.g., as part of a consent declaration), your personal data is deleted when it is no longer needed to fulfill the purpose of storage, unless legal retention periods (e.g., commercial and tax retention periods) oppose deletion.
8. Your rights
According to applicable data protection law, you may have the right to:
- Request confirmation as to whether we process personal data about you and access to the personal data we process about you,
- Request correction of inaccurate personal data,
- Request the deletion of personal data we process about you,
- Request restriction of processing of personal data,
- Request portability of personal data you actively provided to us,
- Object to the processing of personal data for reasons arising from your particular situation, or
- Withdraw a declared consent.
9. Data security
We take appropriate technical and organizational measures to protect personal data from accidental or unlawful destruction, use, or alteration, as well as unauthorized disclosure or unauthorized access.
10. Contact
Our data protection organisation assists with all questions regarding data protection. Complaints can also be made to our data protection organisation, and you may exercise the rights mentioned in this privacy notice.
Our data protection organisation can be contacted at datenschutz@nova.search.
Our data protection organisation is always committed to addressing and remedying your inquiries and complaints. However, in addition to contacting the data protection organisation, you always have the option to contact the competent data protection supervisory authority.
11. Processing of personal data in the scope of the EU General Data Protection Regulation
This section applies if your personal data is processed by one of our companies located in the European Economic Area.
Controller responsible for data processing Online offers
The company named in the imprint of the online offer is the controller responsible for data processing as defined by the GDPR for the processing activities described in this privacy notice.
Marketplaces
The company specified on the marketplace as the operator of the marketplace is the data processing controller.
Personal data of business partners in our customer relationship systems
Contact information of business partners is shared with other companies as part of your business relationship with us. We and these companies are jointly responsible for protecting your personal data (Art. 26 GDPR). To ensure that you can easily and reliably exercise your data protection rights within this joint responsibility, we agreed with these companies that you can exercise your rights, as described in section 6, not only with the respective company but also centrally with Nova Search GmbH. Contact us at: datenschutz@nova.search.de.
Legal basis for processing
The GDPR obliges nova-search to inform you about the legal basis of data processing. Unless explicitly stated otherwise upon collection, the legal basis for data processing is:
- The execution and fulfillment of a contract with you (Article 6 (1) (b) GDPR) (“Contract performance"),
- Compliance with legal obligations to which we are subject (Article 6 (1) (c) GDPR) (“Compliance with legal obligations"), or
- Protecting our legitimate interests (Article 6 (1) (f) GDPR) (“Legitimate interest in processing").
Our legitimate interest lies in processing your personal data for the purpose of:
(i) Offering and operating the online offers and
(ii) Initiating, executing, and managing our business relationship.
As specified in the table below, if our legitimate interest in processing is indicated as the legal basis for the processing of your personal data, we believe that your interests, fundamental rights, and freedoms are sufficiently considered because:
(i) We regularly review the processing activities and background processes described in this privacy notice,
(ii) We consider the protection of your personal data in our processes, including the Binding Corporate Rules for the Protection of Personal Data (nova-search Binding Corporate Rules),
(iii) We ensure the transparency of our processing activities, and
(iv) You have the previously mentioned rights regarding our processing activities.
If you want more information regarding the balancing of interests described, please contact our data protection organisation at datenschutz@nova-search.de.
In the event you have expressly consented to the processing of your personal data in an individual case, this consent is the legal basis for processing (Article 6 (1) (a) GDPR) (“Consent").
Processing personal data related to the use of our online offerings - Purpose and legal basis
- Enabling the use of the services and functions of the online offerings, including creating and administering your online account, within updates, security, and error correction measures, to provide customer support, and to improve and develop our online offerings
- Contract performance (Article 6 (1) (b) GDPR)
- Legitimate interest in processing (Article 6 (1) (f) GDPR)
- Billing for the use of an online offer
- Contract performance (Article 6 (1) (b) GDPR)
- Legitimate interest in processing (Article 6 (1) (f) GDPR)
- Determining identity and user authentication
- Contract performance (Article 6 (1) (b) GDPR)
- Legitimate interest in processing (Article 6 (1) (f) GDPR)
- Processing your request or instruction
- Contract performance (Article 6 (1) (b) GDPR)
- Legitimate interest in processing (Article 6 (1) (f) GDPR)
- Processing your order and offering related information and offers
- Contract performance (Article 6 (1) (b) GDPR)
- Legitimate interest in processing (Article 6 (1) (f) GDPR)
- Sending marketing information or contacting within the context of customer satisfaction surveys, as described in section 3
- Consent, if granted voluntarily (Article 6 (1) (a) GDPR)
- Legitimate interest in processing (Article 6 (1) (f) GDPR)
- Enforcing our terms of use, asserting and defending legal claims, preventing and averting fraudulent and similar actions, including attacks on our IT infrastructure
- Compliance with legal obligations (Article 6 (1) (c) GDPR)
- Legitimate interest in processing (Article 6 (1) (f) GDPR)
- Processing personal data related to your use of our marketplaces and from business partners
- Communication regarding products, services, and projects, e.g., to process business partner inquiries or provide technical information about products
- Contract performance (Article 6 (1) (b) GDPR)
- Legitimate interest in processing (Article 6 (1) (f) GDPR)
- Planning, executing, and managing the (contractual) business relationship between us, e.g., to process orders of products and services, collect payments, for accounting and billing, and perform deliveries, maintenance, or repairs
- Contract performance (Article 6 (1) (b) GDPR)
- Compliance with legal obligations (Article 6 (1) (c) GDPR)
- Creating a personal profile with business-related information about interactions between you and us to offer you and the company you work for relevant information and suitable offers to services and products and improve our personal communication with you
- Legitimate interest in processing (Article 6 (1) (f) GDPR)
- Conducting market analysis, sweepstakes, competitions, or similar actions and events
- Consent, if granted voluntarily (Article 6 (1) (a) GDPR)
- Legitimate interest in processing (Article 6 (1) (f) GDPR)
- Conducting customer satisfaction surveys and direct marketing as described in section 4
- Consent, if granted voluntarily (Article 6 (1) (a) GDPR)
- Legitimate interest in processing (Article 6 (1) (f) GDPR)
- Maintaining and protecting the security of our products and services as well as our websites, preventing and detecting security risks, fraudulent activities, or other criminal or malicious actions
- Legitimate interest in processing (Article 6 (1) (f) GDPR)
- Complying with legal requirements (e.g., tax and commercial retention obligations), existing obligations to conduct compliance screenings (to prevent economic crime or money laundering), and our policies and industry standards
- Compliance with legal obligations (Article 6 (1) (c) GDPR)
- Legitimate interest in processing (Article 6 (1) (f) GDPR)
- Settling disputes, enforcing existing contracts, and asserting, exercising, and defending legal claims
- Compliance with legal obligations (Article 6 (1) (c) GDPR)
- Legitimate interest in processing (Article 6 (1) (f) GDPR)
- Processing your contact details for direct marketing purposes (e.g., trade fair invitations, newsletters with additional information and offers regarding our products and services) and conducting customer satisfaction surveys
- Consent, if granted voluntarily (Article 6 (1) (a) GDPR)
- Legitimate interest in processing (Article 6 (1) (f) GDPR)
International data transfers
When transferring your personal data to a recipient located outside the European Economic Area, we ensure your data is adequately protected in accordance with the GDPR. In this context, if legally required, we take the following measures:
- We only transfer your personal data to companies in such countries if these have implemented Binding Corporate Rules for the Protection of Personal Data (Binding Corporate Rules, "BCR").
- Personal data is only transferred to non-group external recipients in such countries if these have
(i) concluded EU Standard Contractual Clauses with us or
(ii) introduced Binding Corporate Rules.
Further information and a copy of the implemented measures can be obtained at datenschutz@nova-search.de.
The relevant data protection authority
Our data protection organisation supports all questions related to data protection. In addition to contacting our data protection organisation, you always have the option to contact the relevant data protection supervisory authority.
An overview of national and international data protection authorities can be found here.
12. Processing of personal data within the scope of Swiss data protection law
Any affected data subject has the right to enforce their rights in court or to file a complaint with the relevant data protection authority. The relevant data protection authority of Switzerland is the Federal Data Protection and Information Commissioner (http://www.edoeb.admin.ch).
13. Additional information for users of online offerings and business partners in the USA Do Not Track
Our online offerings do not recognize so-called "Do Not Track" settings of your web browser.
For further information regarding the "Do Not Track" functionality, please visit the help pages of your web browser.
Use by children
Our online offerings are not directed at children under the age of 13. Unless legally required, we do not knowingly collect personal data from children under the age of 13 without the consent of their guardians. We collect and transfer personal data of children only to the extent legally permitted, to obtain the consent of the guardians, or to protect the child.
Your rights in certain US states
Under the laws of some US states, residents of these states have additional rights concerning their personal data. Further information can be found here.