Transparency Statement for Suppliers
Basic information
Data subjects
This privacy statement is directed at all persons who can be classified as potential, active, or former suppliers. This applies regardless of whether the service is provided for remuneration or free of charge. All references to persons refer to all genders and the associated linguistic forms, in particular diverse, female, male. Every reference to a person is to be understood with the addition "(m/f/d)".
Controller
The controller for the processing described here is: Adbaker GmbH, Kalscheurener Str. 19A, 50354 Hürth, mail@adbaker.de, T: +49 (0) 221 99983680, e-mail: mail@adbaker.de, represented by the managing director Simon Mader.
Rights
(1) With regard to the data stored about their person, data subjects have the following rights: the right of access, the right to rectification of inaccurate data, the right to erasure of data for which there is no longer any reason for retention, the right to restriction of processing, and the right to data portability. Furthermore, they have the right to lodge a complaint with the supervisory authority responsible for the controller.
(2) Insofar as the processing is based on the consent of the data subjects, the data subjects may revoke their consent at any time with effect for the future; for example, by informal message to one of the above-mentioned contact channels (Controller).
(3) Insofar as the processing is based on the pursuit of a legitimate interest, i.e. on Article 6 (1) sentence 1 lit. f GDPR, the data subjects may object to the processing at any time; for example, by informal message to one of the above-mentioned contact channels (Controller). If the objection is justified, the processing will be terminated. If the legitimate interest lies in direct marketing, the objection is always justified.
Transfer to countries outside the European Union
(1) If personal data is transferred to bodies outside the European Union, the controller must communicate supplementary safeguards pursuant to Article 44 et seq. GDPR.
(2) If the controller refers in the following privacy statement to a so-called adequacy decision, this means that the receiving body is located in a country, territory, or specific sector for which the EU Commission has decided that it offers an adequate level of data protection. The safeguard then follows from Article 45 GDPR.
(3) If the controller refers in the following privacy statement to the so-called EU Standard Contractual Clauses, this means that the receiving body has contractually committed itself to respecting the EU data protection principles, and this on the basis of the so-called EU Standard Contractual Clauses. The safeguard then follows from Article 45 GDPR.
(4) If the controller refers in the following privacy statement to so-called binding corporate rules, this means that the competent supervisory authority has approved the transfer. The safeguard then follows from Article 47 GDPR.
(5) If the controller refers in the following privacy statement to the fact that the data subjects have expressly consented to the transfer to a country outside the European Union, this means that they nevertheless consent to the transfer in full knowledge of all associated risks. The safeguard then follows from Article 49 (1) lit. a GDPR. In this context, we point out the following risks: In the USA, the Republic of India, and the Russian Federation, no data protection law comparable to the GDPR has been codified. The state authorities there have granted themselves extensive data access, whereby the principle of proportionality regulated in the EU is not applied. Furthermore, there is no effective legal protection for EU citizens in these countries.
(6) The above notices are provided only as a precaution. They apply only if and insofar as reference is made to them in the following privacy statement.
Further notices
(1) Automated decision-making, including profiling, does not take place.
(2) A legal obligation to process exists only insofar as reference is made below to Article 6 (1) sentence 1 lit. c GDPR.
Processing of data in the initiation phase.
(1) The controller receives the data from the initial contact. The legal basis is Article 6 (1) sentence 1 lit. b GDPR. According to this, the processing is permissible even without consent, as it serves the initiation, performance, and/or termination of a contractual relationship. In this case, the data will be deleted as soon as the respective purpose has been fulfilled, unless other legal bases and reasons for retention prevent this.
(2) In this phase of processing, the controller uses the following third-party providers, which it has commissioned pursuant to Article 28 GDPR:
- An external tax consultancy firm is entrusted with the bookkeeping. Insofar as data is processed there, this does not constitute processing on behalf (cf. DSK Short Paper 13), but a data transfer, which in turn is justified by Article 6 (1) sentence 1 lit. f GDPR.
- The cloud tool "Google Workspace" and the downstream tool "Google Docs" of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4 (Ireland) are used, whereby data traffic with Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043 (USA) cannot be ruled out. The provider was commissioned pursuant to Article 28 GDPR. The use of this third-party provider is not precluded by the fact that it is based outside the EU. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.
- The project management tool "Asana" of Aana Inc., 1550 Bryant St #200, San Francisco, CA 94103, 6399 (USA) is used. The use of this third-party provider is not precluded by the fact that it is based outside the EU. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.
- The CRM tool "HubSpot" of HubSpot, Inc. (USA) is used, which was commissioned pursuant to Article 28 GDPR. The use of this third-party provider is not precluded by the fact that it is based outside the EU. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.
- In connection with automation, the interface tool "Zapier" of Zapier, Inc. (USA) is used, which was commissioned pursuant to Article 28 GDPR. Further details on the manner of processing by this third-party provider are described here: https://zapier.com/how-it-works. In short: With Zapier, the controller can connect applications so that supplier and prospect data can be exchanged automatically between the various applications. The processing is not precluded by the fact that the provider is based outside the European Union. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.
- The accounting tool "Lexoffice" of Haufe-Lexware GmbH & Co. KG, Munzinger Straße 9, 79111 Freiburg (Germany) is used. The provider was commissioned pursuant to Article 28 GDPR.
- The video communication tool "Loom" of Loom, Inc. (USA) is used, which was commissioned pursuant to Article 28 GDPR. The processing is not precluded by the fact that the provider is based outside the European Union. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.
- The project management tool "Slack" of Slack Technologies Limited (Ireland – EU) is used, which was commissioned pursuant to Article 28 GDPR. The processing is not precluded by the fact that it cannot be ruled out that Slack Technologies Inc. (USA) obtains access to the data. For it has committed itself in accordance with the EU Standard Contractual Clauses.
- The online fax service sipgate of sipgate GmbH (Germany) is used, in that fax messages are received and sent there in the context of contract-related communication.
- The feedback tool "Leapsome" of Leapsome GmbH (Germany) is used.
- The signature tool "PandaDoc" of Pandadoc, Inc. (USA) is used, which was commissioned pursuant to Article 28 GDPR. Further details on the manner of processing by this third-party provider are described here: https://www.pandadoc.com/de/electronic-signature-software/. The commissioning of this provider is also not precluded by the fact that it is based outside the European Union. For the processing of personal data takes place only if the data subjects consent to the associated data transfer to the USA (cf. Article 49 (1) lit. a GDPR). In this respect, the risk notices mentioned above (Basic information / Transfer to countries outside the European Union) are decisive.
- The platform tool "KAJABI" of Kajabi LLC (USA) is used, which was commissioned pursuant to Article 28 GDPR. The processing is not precluded by the fact that the provider is based outside the European Union. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.
- The chat software "Miro" of RealtimeBord, Inc. (USA) is used, which was commissioned pursuant to Article 28 GDPR. The processing is not precluded by the fact that the provider is based outside the European Union. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.
Processing of data in the phase of the active contractual relationship.
(1) The controller processes all data required for the performance of the contractual relationship, in particular for the fulfillment of its contractual obligations. The legal basis is Article 6 (1) sentence 1 lit. b GDPR. According to this, the processing is permissible even without consent, as it serves the initiation, performance, and/or termination of a contractual relationship.
(2) Furthermore, the controller stores all tax and commercial law information (here, the invoice and delivery data) arising from the conduct of the data subjects. The legal basis is Article 6 (1) sentence 1 lit. c GDPR in conjunction with § 147 AO (German Fiscal Code), § 257 HGB (German Commercial Code). According to this, the processing is permissible even without your consent, as the controller in this case fulfills its legal obligation to retain the data in accordance with tax and commercial law provisions. Accordingly, there is an obligation:
- to retain data about the data subjects arising from books and records, inventories, annual financial statements, individual financial statements pursuant to § 325 (2a) HGB, consolidated financial statements, management reports and group management reports, opening balance sheets, accounting vouchers, documents pursuant to Article 15 (1) and Article 163 of the Union Customs Code, commercial books, as well as the work instructions and other organizational documents necessary for their understanding, for ten years, whereby the retention period generally begins at the end of the calendar year in which the relevant document was created (Article 6 (1) sentence 1 lit. c GDPR in conjunction with § 147 AO or in conjunction with § 257 HGB),
- to retain data about the data subjects arising from commercial or business letters received, from reproductions of the commercial or business letters received, as well as from other documents relevant for taxation, for six years, whereby the retention period generally begins at the end of the calendar year in which the relevant document was created (Article 6 (1) sentence 1 lit. c GDPR in conjunction with § 147 AO or in conjunction with § 257 HGB).
After expiry of the periods, all data will be deleted, unless other legal bases and reasons for retention prevent this. Data processed on the basis of consent will be deleted by the controller as soon as the consent is revoked (Article 6 (1) sentence 1 lit. c GDPR in conjunction with Article 5 (1) lit. e GDPR).
(3) The controller will use the name, the e-mail address, order-related communication content, and information on reading and click behavior to address the data subjects for advertising purposes. The advertising contact by e-mail comprises any statement made by the controller in the exercise of its specific trade with the aim of promoting the sale of its goods or the provision of its services. This includes in particular, but not exhaustively, regular and irregular newsletters, invitations, and offers for specific products and services. Furthermore, the advertising contact includes the controller being permitted to draw the data subjects' attention by e-mail to the free and paid products and services offered by its cooperation partners. In doing so, the data is not transferred to these cooperation partners. Rather, the controller merely recommends their products to the data subjects, whereby it can edit these messages itself. Here, Article 6 (1) sentence 1 lit. f GDPR is the legal basis. According to this, the controller may process the data of the data subjects for advertising purposes even without your consent. Its legitimate interest follows from the fact that a contractual relationship exists between it and the data subjects, from the fact that it has informed the data subjects about this in advance, and from the fact that the data subjects can object to processing for advertising purposes at any time and without giving reasons. In this context, the data subjects are advised that they may object to the use at any time, without incurring any costs other than the transmission costs according to the basic rates.
(4) In this phase of processing, the controller uses the following third-party providers, which it has commissioned pursuant to Article 28 GDPR:
- An external tax consultancy firm is entrusted with the bookkeeping. Insofar as data is processed there, this does not constitute processing on behalf (cf. DSK Short Paper 13), but a data transfer, which in turn is justified by Article 6 (1) sentence 1 lit. f GDPR.
- The cloud tool "Google Workspace" and the downstream tool "Google Docs" of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4 (Ireland) are used, whereby data traffic with Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043 (USA) cannot be ruled out. The provider was commissioned pursuant to Article 28 GDPR. The use of this third-party provider is not precluded by the fact that it is based outside the EU. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.
- The project management tool "Asana" of Aana Inc., 1550 Bryant St #200, San Francisco, CA 94103, 6399 (USA) is used. The use of this third-party provider is not precluded by the fact that it is based outside the EU. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.
- The CRM tool "HubSpot" of HubSpot, Inc. (USA) is used, which was commissioned pursuant to Article 28 GDPR. The use of this third-party provider is not precluded by the fact that it is based outside the EU. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.
- In connection with automation, the interface tool "Zapier" of Zapier, Inc. (USA) is used, which was commissioned pursuant to Article 28 GDPR. Further details on the manner of processing by this third-party provider are described here: https://zapier.com/how-it-works. In short: With Zapier, the controller can connect applications so that supplier and prospect data can be exchanged automatically between the various applications. The processing is not precluded by the fact that the provider is based outside the European Union. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.
- The accounting tool "Lexoffice" of Haufe-Lexware GmbH & Co. KG, Munzinger Straße 9, 79111 Freiburg (Germany) is used. The provider was commissioned pursuant to Article 28 GDPR.
- The video communication tool "Loom" of Loom, Inc. (USA) is used, which was commissioned pursuant to Article 28 GDPR. The processing is not precluded by the fact that the provider is based outside the European Union. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.
- The project management tool "Slack" of Slack Technologies Limited (Ireland – EU) is used, which was commissioned pursuant to Article 28 GDPR. The processing is not precluded by the fact that it cannot be ruled out that Slack Technologies Inc. (USA) obtains access to the data. For it has committed itself in accordance with the EU Standard Contractual Clauses.
- The online fax service sipgate of sipgate GmbH (Germany) is used, in that fax messages are received and sent there in the context of contract-related communication.
- The feedback tool "Leapsome" of Leapsome GmbH (Germany) is used.
- The signature tool "PandaDoc" of Pandadoc, Inc. (USA) is used, which was commissioned pursuant to Article 28 GDPR. Further details on the manner of processing by this third-party provider are described here: https://www.pandadoc.com/de/electronic-signature-software/. The commissioning of this provider is also not precluded by the fact that it is based outside the European Union. For the processing of personal data takes place only if the data subjects consent to the associated data transfer to the USA (cf. Article 49 (1) lit. a GDPR). In this respect, the risk notices mentioned above (Basic information / Transfer to countries outside the European Union) are decisive.
- The platform tool "KAJABI" of Kajabi LLC (USA) is used, which was commissioned pursuant to Article 28 GDPR. The processing is not precluded by the fact that the provider is based outside the European Union. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.
- The chat software "Miro" of RealtimeBord, Inc. (USA) is used, which was commissioned pursuant to Article 28 GDPR. The processing is not precluded by the fact that the provider is based outside the European Union. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.
Processing of data after the end of the contractual relationship.
(1) After the end of the contractual relationship, the controller retains the data. The legal basis is Article 6 (1) sentence 1 lit. c GDPR in conjunction with § 147 AO (German Fiscal Code), § 257 HGB (German Commercial Code). According to this, the processing is permissible even without consent, as the controller in this case fulfills its legal obligation to retain the data in accordance with statutory provisions. Accordingly, there is an obligation:
- to retain data about the data subjects arising from books and records, inventories, annual financial statements, individual financial statements pursuant to § 325 (2a) HGB, consolidated financial statements, management reports and group management reports, opening balance sheets, accounting vouchers, documents pursuant to Article 15 (1) and Article 163 of the Union Customs Code, commercial books, as well as the work instructions and other organizational documents necessary for their understanding, for ten years, whereby the retention period generally begins at the end of the calendar year in which the relevant document was created (Article 6 (1) sentence 1 lit. c GDPR in conjunction with § 147 AO or in conjunction with § 257 HGB),
- to retain data about the data subjects arising from commercial or business letters received, from reproductions of the commercial or business letters received, as well as from other documents relevant for taxation, for six years, whereby the retention period generally begins at the end of the calendar year in which the relevant document was created (Article 6 (1) sentence 1 lit. c GDPR in conjunction with § 147 AO or in conjunction with § 257 HGB).
After expiry of the periods, all data will be deleted, unless other legal bases and reasons for retention prevent this. Data processed on the basis of consent will be deleted by the controller as soon as the consent is revoked (Article 6 (1) sentence 1 lit. c GDPR in conjunction with Article 5 (1) lit. e GDPR).
(2) In this phase of processing, the controller uses the following third-party providers, which it has commissioned pursuant to Article 28 GDPR:
- An external tax consultancy firm is entrusted with the bookkeeping. Insofar as data is processed there, this does not constitute processing on behalf (cf. DSK Short Paper 13), but a data transfer, which in turn is justified by Article 6 (1) sentence 1 lit. f GDPR.
- The cloud tool "Google Workspace" and the downstream tool "Google Docs" of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4 (Ireland) are used, whereby data traffic with Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043 (USA) cannot be ruled out. The provider was commissioned pursuant to Article 28 GDPR. The use of this third-party provider is not precluded by the fact that it is based outside the EU. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.
- The project management tool "Asana" of Aana Inc., 1550 Bryant St #200, San Francisco, CA 94103, 6399 (USA) is used. The use of this third-party provider is not precluded by the fact that it is based outside the EU. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.
- The CRM tool "HubSpot" of HubSpot, Inc. (USA) is used, which was commissioned pursuant to Article 28 GDPR. The use of this third-party provider is not precluded by the fact that it is based outside the EU. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.
- In connection with automation, the interface tool "Zapier" of Zapier, Inc. (USA) is used, which was commissioned pursuant to Article 28 GDPR. Further details on the manner of processing by this third-party provider are described here: https://zapier.com/how-it-works. In short: With Zapier, the controller can connect applications so that supplier and prospect data can be exchanged automatically between the various applications. The processing is not precluded by the fact that the provider is based outside the European Union. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.
- The accounting tool "Lexoffice" of Haufe-Lexware GmbH & Co. KG, Munzinger Straße 9, 79111 Freiburg (Germany) is used. The provider was commissioned pursuant to Article 28 GDPR.
- The video communication tool "Loom" of Loom, Inc. (USA) is used, which was commissioned pursuant to Article 28 GDPR. The processing is not precluded by the fact that the provider is based outside the European Union. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.
- The project management tool "Slack" of Slack Technologies Limited (Ireland – EU) is used, which was commissioned pursuant to Article 28 GDPR. The processing is not precluded by the fact that it cannot be ruled out that Slack Technologies Inc. (USA) obtains access to the data. For it has committed itself in accordance with the EU Standard Contractual Clauses.
- The online fax service sipgate of sipgate GmbH (Germany) is used, in that fax messages are received and sent there in the context of contract-related communication.
- The feedback tool "Leapsome" of Leapsome GmbH (Germany) is used.
- The signature tool "PandaDoc" of Pandadoc, Inc. (USA) is used, which was commissioned pursuant to Article 28 GDPR. Further details on the manner of processing by this third-party provider are described here: https://www.pandadoc.com/de/electronic-signature-software/. The commissioning of this provider is also not precluded by the fact that it is based outside the European Union. For the processing of personal data takes place only if the data subjects consent to the associated data transfer to the USA (cf. Article 49 (1) lit. a GDPR). In this respect, the risk notices mentioned above (Basic information / Transfer to countries outside the European Union) are decisive.
- The platform tool "KAJABI" of Kajabi LLC (USA) is used, which was commissioned pursuant to Article 28 GDPR. The processing is not precluded by the fact that the provider is based outside the European Union. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.
- The chat software "Miro" of RealtimeBord, Inc. (USA) is used, which was commissioned pursuant to Article 28 GDPR. The processing is not precluded by the fact that the provider is based outside the European Union. For the provider has committed itself in accordance with the EU Standard Contractual Clauses.
Processing in the event of a sale of the company by way of spin-off or merger.
(1) There is the possibility that the controller's company or parts of it may undergo changes under company law. In this context, the controller has, among other things, the possibility of reorganizing itself by selling parts of the company (spin-off) or by combining with other companies (merger). In a spin-off, it continues to exist as a company and transfers part of its assets to one or more other, already existing or new legal entities. In a merger, it transfers its entire company to another legal entity, either already existing or to be newly founded.
(2) Regardless of which variant of the change under company law the controller chooses, there is the possibility that the data it stores will be transferred along with it to the respective new legal entity, possibly also for remuneration. There is even the possibility that this is the main reason for the change under company law and a significant, price-determining factor.
(3) However, the consent of the data subjects is not required for the transfer of data described in paragraph 2. For the data protection principle according to which any processing of personal data requires a legal basis is not applicable to this transfer. This legal principle, which derives from Article 5 (1) lit. a GDPR, requires processing of the data. What could be considered here is a disclosure by transmission, dissemination, or another form of making available. But the elements "transmission", "dissemination", as well as "making available in another form" all presuppose that the data leaves the controller and reaches a body outside the controller. And in the case of a spin-off or merger, the new legal entity would not be a third party within the meaning of Article 4 (10) GDPR with regard to the data.