PRIVACY POLICY

This privacy policy informs you about the nature, scope and purpose of the processing of personal data (hereinafter referred to as ‘data’) in connection with the use of our online services. This includes all associated web pages, functions and content. For the data protection terms used – such as ‘processing’ or ‘controller’ – please refer to the definitions in Article 4 of the General Data Protection Regulation (GDPR).

Person in charge

The e-learning application “OSIANTO” is provided by
30 doradus media design gmbh
Niederstr. 29
40789 Monheim am Rhein, Germany
Telephone: +49 (0)2173 109267-0
Email: info@osianto.de
Managing Director: Jürgen Osterberg

Types of data processed

  • Master data (e.g. names, addresses)
  • Contact details (e.g. email addresses, telephone numbers)
  • Content data (e.g. text entries)
  • Contract details (e.g. subject matter of the contract, term, services used)
  • Billing details (e.g. invoice details, payment status)
  • Usage data (e.g. websites visited, times of access, interest in content)
  • Meta and communication data (e.g. device information, IP addresses)

Categories of data subjects

Data processing affects visitors to and users of our online services – whom we shall hereinafter collectively refer to as ‘users’ – as well as our customers, prospective customers, contractual and business partners, including the contact persons named therein.

Purposes of processing

  • Provision of the online service, including all features and content
  • Processing contact requests and communicating with users
  • The provision of our contractual and pre-contractual services, as well as customer administration and customer care
  • Implementation of security measures to ensure data protection
  • Measuring reach and evaluating the effectiveness of our marketing activities
  • Identifying the business environment from which a request is made, in order to identify potential customers for our services
  • Marketing, advertising and market research

Relevant legal bases

We process personal data on the following legal grounds:

  • Consent (Article 6(1)(a) of the GDPR): Where you give us your explicit consent to process your data. You may withdraw such consent at any time.
  • Performance of a contract (Article 6(1)(b) of the GDPR): Where processing is necessary for the performance of a contract to which you are a party or in order to take steps at your request prior to entering into a contract.
  • Legal obligation (Article 6(1)(c) of the GDPR): Where we are legally obliged to process data.
  • Legitimate interests (Article 6(1)(f) of the GDPR): For example, to ensure IT security or to prevent misuse. In such cases, we ensure that your rights and freedoms are not unduly compromised.

Section 25 of the Telecommunications and Digital Services Data Protection Act (TDDDG) also applies to the storage of and access to information on your device – in particular via cookies. Under this provision, your consent is required unless such storage is strictly necessary to provide a service you have expressly requested.

Safety measures

In accordance with Article 32 of the GDPR, we implement appropriate technical and organisational measures to ensure a level of protection appropriate to the risk posed to the rights and freedoms of data subjects. In doing so, we take into account the state of the art, the costs of implementation, the nature and scope of the processing, and the likelihood and severity of the risks.

The measures taken include, in particular, ensuring the confidentiality, integrity and availability of data, protection against unauthorised access, and procedures that enable us to safeguard data subjects’ rights, delete data and respond to security threats. The website is accessed exclusively via an encrypted connection (TLS); you can recognise this by the ‘https’ in your browser’s address bar.

Furthermore, we take the protection of personal data into account right from the stage of selecting hardware, software and processes, and implement the principle of data protection by design as well as privacy-friendly default settings in accordance with Article 25 of the GDPR.

Cooperation with data processors and third parties

Where we disclose personal data to other individuals or organisations as part of our data processing activities, this is done exclusively on the basis of a legal authorisation – for example, because it is necessary for the performance of a contract, you have given your consent, there is a legal obligation to do so, or it is based on our legitimate interests (e.g. when using our hosting provider).

Where we engage third parties to process personal data, this is done on the basis of a data processing agreement in accordance with Article 28 of the GDPR.

Transfers to third countries

In connection with our online services, personal data is transferred to countries outside the European Union (EU) or the European Economic Area (EEA) in two instances:

  • Google reCAPTCHA to protect our forms from misuse. Data is transferred to Google LLC in the USA as part of this process; this takes place regardless of your selection in the cookie banner.
  • GoToWebinar when you take part in one of our webinars. When you follow the access link, your device will connect to the servers of GoTo Technologies USA, LLC in the USA. We do not pass on the details you provide on the registration form.

Both recipients are certified under the EU-US Data Privacy Framework; an adequacy decision by the European Commission is in place for transfers to certified US companies. Further details, including the relevant legal basis, can be found in the sections ‘Protection against abuse with Google reCAPTCHA’ and ‘Webinars with GoToWebinar’.

Should such a transfer become necessary in individual cases, it will take place exclusively in accordance with the specific requirements set out in Articles 44 et seq. of the GDPR. This means that processing will only take place on the basis of appropriate safeguards – such as an adequacy decision by the European Commission or the standard contractual clauses approved by the European Commission.

Cookies and your consent

‘Cookies’ are small files that are stored on your device and may contain various types of information. Temporary cookies (also known as ‘session cookies’) are deleted as soon as you close your browser. Persistent cookies, however, remain stored.

The first time you visit this website, a pop-up window will appear asking you to decide whether we may analyse your visit for statistical purposes and, in doing so, determine the business environment from which the access is taking place. No audience measurement will take place without your consent, and no cookies will be set for this purpose. We describe below which cookies are set regardless of this.

Regardless of your decision, we store your selection in a cookie – otherwise we would have to ask you again every time you visit the page. A cookie also remembers which language version of the website you have selected. This storage is strictly necessary for the operation of the website and, pursuant to Section 25(2)(2) of the TDDDG, does not require consent. Further strictly necessary cookies are set when someone logs into the website’s administration panel. Also, regardless of your selection, cookies from the Google reCAPTCHA service are set when you access pages containing forms; details and our legal position on this can be found in the section ‘Protection against misuse with Google reCAPTCHA’.

We list in detail which cookies are set, along with their names, purposes and retention periods, in our Cookie Policy. This overview is automatically kept up to date.

Withdrawal of your consent

You may withdraw your consent at any time with future effect – just as easily as you gave it. To do so, open the cookie settings via the relevant link at the bottom of the page and change your selection. Any audience measurement cookies that have already been set will be deleted and the measurement will cease. Your right to withdraw consent is set out in Article 7(3) of the GDPR.

Collection of access data and log files

We, or our hosting provider, collect data on every access to the server on which this service is hosted (so-called server log files) on the basis of our legitimate interests pursuant to Article 6(1)(f) of the GDPR. The access data includes the name of the webpage accessed, the file, the date and time of access, the amount of data transferred, confirmation of a successful access, the browser type and version, the operating system, the previously visited page, the IP address and the requesting provider.

For security reasons (e.g. to investigate cases of misuse or fraud), log file information is stored for a maximum of seven days and then deleted. Data that needs to be retained for evidential purposes remains stored until the incident in question has been fully resolved.

The website is hosted in a data centre in Germany. A contract has been entered into with the hosting provider regarding processing on behalf of the controller in accordance with Article 28 of the GDPR.

Measuring reach with Matomo

Provided you have given your consent, we analyse the use of this website using the Matomo analytics software. Matomo is open-source software which we operate on our own server environment at metrics.30doradus.de; this, like this website, is hosted by our hosting provider, with whom – as described above – we have a contract for processing on our behalf in accordance with Article 28 of the GDPR. No other external analytics service provider that accesses the collected data or analyses it independently is involved; the data does not leave our own sphere of responsibility.

In particular, the following data is processed: the pages accessed and the duration of the visit, the time of access, the previously visited page or the search term used, external links clicked on, details of the browser, operating system and screen resolution, the approximate country of origin, and your IP address.

Why we use this – and what it means for you

We use this analysis for two purposes. Firstly, to understand what content is in demand and where our website could be improved. Secondly, to identify the locations from which our website is accessed, and to identify potential customers for our services on that basis.

To make this possible, we store your IP address in its full, untruncated form. In the case of a business internet connection, this often allows us to identify the company from which the access originated. Where necessary, we carry out this identification ourselves on a case-by-case basis, for example by consulting publicly available directories. We do not use an automated process or a specialist service provider for this purpose.

Pseudonymous user profiles may be created from the processed data. We use this information exclusively for our own purposes – to improve our online offering and to target potential customers directly. This data is not passed on to or sold to third parties.

Legal basis and retention period

The legal basis for both the storage of cookies on your device and their subsequent processing is exclusively your consent in accordance with Section 25(1) of the TDDDG in conjunction with Article 6(1)(a) of the GDPR. Without your consent, Matomo will not be loaded and no data will be collected.

Please refer to our Cookie Policy for details of how long the cookies we use are stored. The logs containing usage data are automatically deleted after six months at the latest.

Evaluation of offline advertising campaigns

Where we send out printed promotional material, such as postcards, these may contain a QR code with a web address. This address redirects to a page on our website and contains an identifier that enables us to attribute the visit to the relevant promotional campaign.

The sole purpose is to measure performance: we would like to know how many people have found their way to us via a particular advertising medium. Data processing takes place as part of the audience measurement described above using Matomo and, therefore, only if you have given your consent. If you access the website without consenting to audience measurement, no data will be linked; in that case, only the information contained in the server log files will apply.

Fonts

We use the ‘Roboto’ font to ensure a consistent presentation of text. The font files are stored locally on our own server and are delivered from there. When these fonts are delivered, no connection is made to servers operated by Google or any other third party, and no personal data is transferred to third parties. This is to be distinguished from the reCAPTCHA service described below, which establishes its own connections to Google on form pages.

Protection against misuse with Google reCAPTCHA

On the forms on this website, we use the ‘reCAPTCHA’ service to determine whether an entry has been made by a human or, in a malicious manner, by automated, machine-based processing. The provider is Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. We use the ‘invisible’ version of reCAPTCHA, which generally operates in the background without requiring any active interaction (e.g. clicking on image fields).

In the process, information such as the IP address, details of the browser, operating system and language settings, as well as the time spent on the page and mouse movements, is transmitted to Google and analysed there. This data is collected as soon as the form page loads, regardless of whether the form is actually submitted.

Legal basis

When reCAPTCHA is loaded, cookies are also stored on your device, including one named “_grecaptcha”. These cookies are stored regardless of your selection in the cookie banner. We assume that, pursuant to Section 25(2)(2) of the TDDDG, this does not require separate consent, as it is strictly necessary to provide you with the form you have accessed in a functional state and protected against abusive automated use; this protection must take effect as soon as the page loads, as automated access cannot otherwise be reliably detected. This legal assessment is not uniformly interpreted in case law and legal literature; in some cases, prior consent is instead considered necessary for invisible reCAPTCHA.

We base the subsequent processing of the data collected in this way on our legitimate interest (Article 6(1)(f) of the GDPR) in maintaining a secure and fully functional website and in protecting our forms from spam, misuse and automated attacks. You may object to this processing on grounds relating to your particular situation, in accordance with Article 21(1) of the GDPR; please send your objection to info@osianto.de. As reCAPTCHA is loaded as soon as you access a form page, the only way to prevent future data transmission is to avoid accessing these pages and to contact us by email or telephone instead (see above for contact details).

Transfer to the USA

Google LLC is certified under the EU-US Data Privacy Framework. An adequacy decision has been issued by the European Commission regarding transfers to certified US companies, meaning that such transfers are permitted on this basis for as long as this decision remains in force.

Further information on reCAPTCHA can be found in Google’s Privacy Policy and Terms of Service.

Contact details and forms

When you contact us – for example, via the contact form, by email or by telephone – we process your details in order to handle and deal with your enquiry in accordance with Article 6(1)(b) of the GDPR, insofar as this relates to the initiation or performance of a contract; in all other cases, we process your details on the basis of our legitimate interest in responding to enquiries, in accordance with Article 6(1)(f) of the GDPR.

On our website, we provide the following forms in particular:

  • Request demo access – to get in touch, discuss your requirements and then set up access
  • Webinar registration – to organise and facilitate your participation, and to send you the login details

You can download the white paper available on our website straight away. You do not need to log in, register or provide any personal details to do so.

We require the information marked with an asterisk (*) in the forms in order to process your enquiry; without it, we are unable to process your enquiry. All other information is provided on a voluntary basis. There is no legal or contractual obligation to provide your data.

We use the information collected in this way to fulfil the purpose for which it was requested. The form entries are sent to us by email and stored in our email inbox. We do not use a separate customer management, ticketing or enquiry management system for this purpose; nor is the information processed automatically.

We delete enquiries as soon as they are no longer required. We review their necessity every two years; in addition, the statutory archiving obligations apply.

Webinars with GoToWebinar

We use the ‘GoToWebinar’ service to run our webinars. The provider is GoTo Technologies USA, LLC (USA); for data protection enquiries, GoTo can be contacted at: Attn: Legal and Privacy Team, The Reflector, 10 Hanover Quay, Dublin 2, D02 R573, Ireland.

We do not pass on the details you provide on the registration form to GoTo; they remain in our email inbox. We simply send you an access link. Only when you follow this link will your device connect to GoTo’s servers. GoToWebinar processes the name you enter yourself when joining, your IP address, details of your device and connection, the time and duration of your participation, and your contributions in the chat or Q&A section. Whether audio or video of you is transmitted depends on whether you activate your microphone or camera. Registration with GoTo is not required to participate; you decide for yourself what name to use when joining.

The legal basis is Article 6(1)(b) of the GDPR, as the processing is necessary to enable you to take part in the webinar you have requested.

A contract for processing on behalf of the data controller has been entered into with GoTo in accordance with Article 28 of the GDPR. For data transfers to the USA, GoTo relies on the certification of GoTo Technologies USA, LLC under the EU-US Data Privacy Framework and, in addition, on the Standard Contractual Clauses approved by the European Commission. Further details regarding processing by GoTo can be found in GoTo’s privacy policy.

Business-Related processing

In addition, we process contractual data (e.g. subject matter of the contract, term, customer category) and billing data (e.g. invoice details and payment status) relating to our customers, prospective customers and business partners in order to provide contractual services, ensure service and customer care, and carry out marketing, advertising and market research. The legal basis is Article 6(1)(b) of the GDPR, insofar as the processing serves to fulfil or enter into a contract; Article 6(1)(c) of the GDPR, insofar as we fulfil retention and record-keeping obligations under commercial and tax law; and Article 6(1)(f) of the GDPR for service provision, customer care and our own direct marketing.

Contractual services

We process the data of our contractual partners, prospective customers and other clients and customers (hereinafter collectively referred to as ‘contractual partners’) in accordance with Article 6(1)(b) of the GDPR in order to provide them with our contractual or pre-contractual services. The nature, scope and purpose of the processing depend on the underlying contractual relationship.

The data processed includes, in particular, master data (e.g. names and addresses), contact details (e.g. email addresses, telephone numbers), contract details (e.g. services used, contract terms, names of contact persons) and billing details.

Special categories of personal data are generally not processed, unless they form part of commissioned or contractual processing. In such cases, we base the processing on your explicit consent in accordance with Article 9(2)(a) of the GDPR. Disclosure to external individuals or organisations only takes place where this is required under the terms of a contract.

When you use our online services, we may store your IP address and the time at which the relevant user action took place. This data is stored on the basis of our legitimate interests and the users’ interest in protection against misuse and unauthorised use.

The data will be deleted as soon as it is no longer required to fulfil contractual or statutory obligations. The need to retain the data is reviewed every three years; otherwise, the statutory retention obligations apply.

Deletion of data

The data we process will be erased or its processing restricted in accordance with the provisions of Articles 17 and 18 of the GDPR. Unless expressly stated otherwise in this privacy policy, the data stored by us will be erased as soon as it is no longer required for the respective purpose and there are no statutory retention obligations preventing this.

Records are retained in accordance with statutory requirements, in particular for a period of ten years pursuant to section 147(3) in conjunction with section 147(1)(1) of the German Fiscal Code (AO) and section 257(4) in conjunction with section 257(1)(1) of the German Commercial Code (HGB) (books, records, inventories, annual accounts, management reports, as well as the working instructions and other organisational documents necessary for their understanding), for eight years in accordance with Section 147(3) in conjunction with Section 147(1)(4) of the German Fiscal Code (AO) and Section 257(4) in conjunction with Section 257(1)(4) of the German Commercial Code (HGB) (accounting vouchers); and for six years in accordance with Section 147(3) in conjunction with Section 147(1)(2), 3 and 5 of the German Fiscal Code (AO) and Section 257(4) in conjunction with paragraph 1, No. 2 and 3 of the German Commercial Code (HGB) (commercial or business correspondence received and sent, as well as other documents relevant for tax purposes).

Social media presence

We maintain profiles on social media platforms to communicate with customers, prospective customers and users who are active on these platforms, and to provide information about our services. This currently includes LinkedIn, Facebook, Instagram and X (formerly Twitter). On our website, we simply provide links to these profiles. No content or buttons from these networks are embedded; therefore, no data is transmitted to these providers simply by visiting our website. Data is only transferred once you actively click on such a link and thereby access the respective provider’s page.

When accessing the respective social media platforms, the terms and conditions and data processing policies of the respective operators apply. Unless otherwise stated, we process users’ data when they communicate with us via social media, for example by sending us messages. The legal basis is our legitimate interest in public image and communication pursuant to Article 6(1)(f) of the GDPR; in the case of pre-contractual arrangements, it is Article 6(1)(b) of the GDPR.

Rights of data subjects

You have the following rights in relation to your personal data:

  • Information regarding the data processed (Article 15 of the GDPR)
  • Rectification of inaccurate data or completion of incomplete data (Article 16 of the GDPR)
  • Erasure (Article 17 of the GDPR)
  • Restriction of processing (Article 18 of the GDPR)
  • Data portability (Article 20 of the GDPR)
  • Objection to processing based on a legitimate interest (Article 21 of the GDPR) – in particular, to processing for the purposes of direct marketing
  • Withdrawal of consent with effect for the future (Article 7(3) of the GDPR)

To exercise this right, simply send an informal message to info@osianto.de.

Right to lodge a complaint

Under Article 77 of the GDPR, you have the right to lodge a complaint with a supervisory authority. The competent authority for us is:

State Commissioner for Data Protection and Freedom of Information, North Rhine-Westphalia
Kavalleriestraße 2–4, 40213 Düsseldorf
www.ldi.nrw.de

No automated decisions in individual cases

No decision based solely on automated processing which produces legal effects concerning you or similarly significantly affects you (Article 22 of the GDPR) is made. The pseudonymous usage profiles generated as part of audience measurement do not lead to any such decision; the attribution of a visit to a specific company, as described above, is carried out manually on a case-by-case basis. Similarly, the assessment carried out by reCAPTCHA serves solely to detect automated access and has no legal effect on you.

Changes

We will update this statement if the legal situation or the processing carried out on this website changes. The version available here shall apply at any given time.

As at September 2026