Privacy Policy

1 Data Protection at a Glance

1.1 General Information

We appreciate your interest in our website. The protection of your personal data during your visit to our website is a top priority for the management of OIT.One GmbH. The following information provides an overview of how we process your personal data and your rights under data protection laws. Personal data refers to any information that can be linked to you personally, such as your name, address, email addresses, and user behavior.

If a data subject wishes to use specific services offered by our company via our website, the processing of personal data may be necessary. If the processing of personal data is necessary and there is no legal basis for such processing, we generally obtain the data subject’s consent. Such processing is always carried out in accordance with the EU General Data Protection Regulation (GDPR) and in compliance with the country-specific data protection regulations applicable to OIT.One GmbH.

As the data controller, OIT.One GmbH has implemented technical and organizational measures to ensure the most comprehensive possible protection of the personal data processed through this website against loss, destruction, unauthorized access, alteration, or disclosure of your data by unauthorized persons. This includes the use of SSL or TLS encryption on this site for security reasons and to protect the transmission of confidential content, such as orders or inquiries that you send to us as the site operator. You can recognize an encrypted connection by the fact that the browser’s address bar changes from „http://“ to „https://“ and by the lock icon in your browser’s address bar. When SSL or TLS encryption is enabled, the data you transmit to us cannot be read by third parties.

Nevertheless, due to fundamental security vulnerabilities in Internet-based data transmissions, absolute protection cannot be guaranteed.

1.2 Data Controller

The data controller pursuant to Article 4(7) of the GDPR and the applicable state-specific data protection regulations is:

OIT.One GmbH

Poppenbütteler Weg 142b | 22399 Hamburg

+49 40 / 2396802 – 44 | info@oit.one

Please send general questions regarding data protection at OIT.One GmbH to Datenschutz(at)oit.one.

You can contact our Data Protection Officer by mail at the address listed above, with the note “Data Protection Officer,” or by email at: Datenschutzbeauftragter(at)oit.one.

In exceptional cases, email delivery may be disrupted for technical or operational reasons. Please ensure that time-sensitive messages are also sent by mail or fax. Please keep in mind that email communication is fundamentally insecure, as there is a risk that third parties may intercept or tamper with messages. Confidential data should never be sent unencrypted via email.

1.3 How do we collect your data?

Your data is collected, in part, when you provide it to us. This may include, for example, data you enter into a contact form.

Other data is collected by our IT systems automatically or with your consent when you visit the website. This primarily consists of technical data (e.g., internet browser, operating system, or the time the page was accessed). This data is collected automatically as soon as you access this website.

1.4 What do we use your data for?

Some of the data is collected to ensure that the website functions properly. Other data may be used to analyze your user behavior.

1.5 Who receives my data?

Unless otherwise specified in the detailed descriptions of the offers, access to your data within our company is limited to those departments that require it to fulfill our contractual and legal obligations or to pursue our legitimate interests. We will only disclose information about you outside the company if legal or regulatory disclosure requirements permit or require it, the disclosure is necessary for the processing and thus the fulfillment of the contract or, at your request, for the implementation of precontractual measures; we have your consent; or we are authorized to provide the information.

If we use third-party service providers for specific functions of our services, these providers have been carefully selected and commissioned by us, are bound by our instructions, and are regularly monitored. Your personal data may be processed on the basis of data processing agreements pursuant to Article 28 of the GDPR, and we ensure that the processing of personal data complies with the provisions of the GDPR. In this case, the categories of recipients are our service providers for website hosting, website management, and online marketing.

1.6 General Information on the Legal Basis for Data Processing on This Website

If you have consented to the processing of your data, we process your personal data on the basis of Article 6(1)(a) of the GDPR or Article 9(2)(a) of the GDPR, provided that special categories of data as defined in Article 9(1) of the GDPR are processed. In the event of explicit consent to the transfer of personal data to third countries, data processing is also carried out on the basis of Article 49(1)(a) of the GDPR. If you have consented to the storage of cookies or to access to information on your device (e.g., via device fingerprinting), data processing is additionally based on Section 25(1) of the German Teleservices Data Protection Act (TTDSG). You may revoke your consent at any time. If your data is necessary for the performance of a contract or for taking steps prior to entering into a contract, we process your data based on Article 6(1)(b) of the GDPR. Furthermore, we process your data if it is necessary to comply with a legal obligation, based on Article 6(1)(c) of the GDPR. Data processing may also be carried out on the basis of our legitimate interest pursuant to Article 6(1)(f) of the GDPR. Information regarding the applicable legal bases in each individual case is provided in the following paragraphs of this Privacy Notice.

1.7 Retention Period

Unless a more specific retention period is stated in this Privacy Policy, we will retain your personal data until the purpose for which it was collected no longer applies. If you submit a valid request for erasure or revoke your consent to data processing, your data will be erased, provided we have no other legally permissible grounds for storing your personal data (e.g., retention periods under tax or commercial law); in the latter case, the data will be deleted once these grounds no longer apply.

2 Your Rights

2.1 Access, Correction, and Deletion

In accordance with applicable legal provisions, you have the right at any time to receive, free of charge, information about your stored personal data, its source and recipients, and the purpose of data processing, as well as the right to have this data corrected or deleted, if applicable. You may contact us at any time regarding this matter or with any other questions about personal data.

2.2 Right to Restriction of Processing

You have the right to request that the processing of your personal data be restricted. You may contact us at any time to do so. The right to restrict processing applies in the following cases:

  • If you dispute the accuracy of your personal data stored by us, we generally need time to verify this. For the duration of the verification process, you have the right to request that the processing of your personal data be restricted.
  • If the processing of your personal data was or is unlawful, you may request that the processing of your data be restricted instead of having it erased.
  • If we no longer need your personal data, but you need it to exercise, defend, or assert legal claims, you have the right to request that the processing of your personal data be restricted instead of being erased.
  • If you have filed an objection under Article 21(1) of the GDPR, a balancing of your interests against ours must be conducted. As long as it has not yet been determined whose interests prevail, you have the right to request that the processing of your personal data be restricted.

If you have restricted the processing of your personal data, such data—other than for storage purposes—may be processed only with your consent or for the purpose of asserting, exercise, or defense of legal claims; to protect the rights of another natural or legal person; or for reasons of a substantial public interest of the European Union or a Member State.

2.3 Right to Data Portability

You have the right to have data that we process automatically—based on your consent or in fulfillment of a contract—provided to you or to a third party in a commonly used, machine-readable format. If you request the direct transfer of the data to another data controller, this will only be done to the extent that it is technically feasible.

2.4 Right to Object to Data Collection in Specific Cases and to Direct Marketing (Art. 21 GDPR)

IF DATA PROCESSING IS BASED ON ART. 6(1)( E OR F OF THE GDPR, YOU HAVE THE RIGHT AT ANY TIME, FOR REASONS RELATED TO YOUR PARTICULAR SITUATION, to object to the processing of your personal data; this also applies to profiling based on these provisions. PLEASE REFER TO THIS PRIVACY NOTICE FOR THE SPECIFIC LEGAL BASIS ON WHICH PROCESSING IS BASED. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR PERSONAL DATA, UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING THAT OVERRIDE YOUR INTERESTS, RIGHTS, AND FREEDOMS, OR THE PROCESSING IS NECESSARY FOR THE ESTABLISHMENT, EXERCISE, OR DEFENSE OF LEGAL CLAIMS (OBJECTION PURSUANT TO ART. 21(1) OF THE GDPR).

IF YOUR PERSONAL DATA IS PROCESSED FOR DIRECT MARKETING PURPOSES, THEN YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF YOUR PERSONAL DATA FOR THE PURPOSE OF SUCH MARKETING; THIS ALSO APPLIES TO PROFILING, TO THE EXTENT THAT IT IS RELATED TO SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL NO LONGER BE USED FOR DIRECT MARKETING PURPOSES (OBJECTION PURSUANT TO ART. 21(2) OF THE GDPR).

2.5 Withdrawal of Your Consent to Data Processing

Many data processing operations are only possible with your explicit consent. You may revoke any consent you have already given at any time. The lawfulness of the data processing carried out prior to the revocation remains unaffected by the revocation.

2.6 Right to File a Complaint with the Competent Supervisory Authority

In the event of violations of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, their place of work, or the location of the alleged violation. The right to lodge a complaint is without prejudice to any other administrative or judicial remedies.

3 Data Collection on Our Website

3.1 Hosting

This website is hosted on our own server infrastructure, which is operated by OIT.One GmbH itself. We do not use an external hosting provider. The personal data collected on this website is stored and processed exclusively on our own servers. This may include, in particular, IP addresses, contact requests, metadata and communication data, contract data, contact information, names, website visits, and other data generated through a website.

The website is operated for the purpose of fulfilling our contractual obligations to our potential and existing customers (Art. 6(1)(b) GDPR) as well as in our legitimate interest in providing our online services in a secure, fast, efficient, and reliable manner (Art. 6(1)(f) GDPR). If consent has been requested, processing is based exclusively on Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG, to the extent that the consent covers the storage of cookies or access to information on the user’s device (e.g., device fingerprinting) within the meaning of the TDDDG. Consent may be revoked at any time with future effect.

Since we operate the servers ourselves, your data is not transferred to any external service provider as part of our hosting services. The servers are located in Germany.

3.2 Use of Server Log Files

The provider of this website automatically collects and stores information in what are known as server log files, which your browser automatically transmits to us. These include:

  • Browser Type and Browser Version
  • Operating system used
  • Referrer URL
  • Hostname of the connecting computer
  • Time of the server request
  • IP address

The legal basis for the temporary storage of data and log files is Article 6(1)(f) of the GDPR. As the website operator, we have a legitimate interest in ensuring the website connects without issues, in ensuring its technically error-free display and optimization, and in evaluating system security and stability. We use server log files for this purpose. However, the provider reserves the right to review the log data retrospectively if there are concrete indications giving rise to a legitimate suspicion of unlawful use.

3.3 Use of Cookies

„Cookies“ are small files that are stored on users' devices. Cookies can be used to store various types of information. This information may include, for example, language settings on a website or the point at which a video was paused.

Our website does not currently use cookies.

3.4 Contact Form

If you submit inquiries to us via the contact form, we will store the information you provide in the inquiry form—including the contact information you provide there—for the purpose of processing your inquiry and in case we have follow-up questions. We will not share this information without your consent.

The processing of this data is based on Article 6(1)(b) of the GDPR, provided that your inquiry is related to the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective handling of inquiries addressed to us (Article 6(1)(f) of the GDPR).

The data you enter in the contact form will remain with us until you request that we delete it, revoke your consent to its storage, or the purpose for storing the data no longer applies (e.g., after your inquiry has been processed). Mandatory legal provisions—in particular retention periods—remain unaffected.

3.5 Inquiries by email, phone, or fax

If you contact us by email, phone, or fax, we will store and process your inquiry—including all personal data contained therein (name, inquiry)—for the purpose of handling your request. We will not disclose this data without your consent.

This data is processed on the basis of Article 6(1)(b) of the GDPR, provided that your inquiry is related to the performance of a contract or is necessary for the implementation of precontractual measures. In all other cases, the processing is based on our legitimate interest in the effective handling of inquiries directed to us (Article 6(1)(f) of the GDPR).

The data you send us via contact requests will remain with us until you request that we delete it, revoke your consent to its storage, or the purpose for storing the data no longer applies (e.g., after your request has been processed). Mandatory legal provisions—in particular statutory retention periods—remain unaffected.

3.6 Customer Area

As part of the initial business setup, our service team will create an account for you in our online customer center. Here, you’ll find a complete overview of the services you’ve booked, tickets you’ve created, and other details regarding our collaboration. In your customer profile, you can update your personal information at any time and add additional details on a voluntary basis.

The data is processed for the purpose of entering into and performing contracts, in accordance with Article 6(1)(b) of the GDPR.

Upon termination of the business relationship, the account will be suspended after 30 days of inactivity and deleted after an additional 30 days, or upon request. Data subject to various retention and documentation requirements will be deleted only after the prescribed retention or documentation periods have expired.

We also use your contact information to inform you about our products. The legal basis for this is Article 6(1), first sentence, letter f of the GDPR in conjunction with Section 7(3) of the UWG. You can disable this use for promotional purposes at any time in your customer account or contact us using the contact information provided in Section 1, Item 2.

3.7 Business Cloud

To exchange large volumes of data as part of business relationships, we offer our Business Cloud platform to business partners. You can obtain the necessary account information from our service team.

The data is processed for the purpose of fulfilling contracts, in accordance with Article 6(1)(b) of the GDPR.

Upon termination of the business relationship or upon request, the account will be deleted. Data subject to various retention and documentation requirements will not be deleted until the prescribed retention or documentation periods have expired.

3.8 Handling of Applicant Data

We offer you the opportunity to apply for a position with us (e.g., by email, mail, or through our online application form). Below, we provide information about the scope, purpose, and use of your personal data collected as part of the application process.

We assure you that the collection, processing, and use of your data are carried out in accordance with applicable data protection laws and all other legal requirements, and that your data will be treated with the strictest confidentiality.

3.8.1 Handling and Purpose of Data Collection

If you submit an application to us, we will process the associated personal data (e.g., contact and communication information, application documents, etc.) to the extent necessary to make a decision regarding the establishment of an employment relationship. The legal basis for this is Section 26 of the German Federal Data Protection Act (BDSG) (initiation of an employment relationship), Article 6(1)(b) of the GDPR (general pre-contractual processing), and—provided you have given your consent—Article 6(1)(a) of the GDPR. Consent may be revoked at any time, with effect for the future. Your personal data will be disclosed within our company exclusively to persons involved in processing your application.

If your application is successful, the data you submit will be stored in our data processing systems in accordance with Section 26 of the German Federal Data Protection Act (BDSG) and Article 6(1)(b) of the General Data Protection Regulation (GDPR) for the purpose of carrying out the employment relationship.

3.8.2 Data Retention Period

If we are unable to offer you a position, if you decline a job offer, or if you withdraw your application, we reserve the right to retain the data you have provided on the basis of our legitimate interests (Art. 6(1)(f) GDPR) for up to 6 months from the date of termination

of the application process (rejection or withdrawal of the application). The data will then be deleted and the physical application documents destroyed. The data is retained primarily for evidentiary purposes in the event of a legal dispute. If it becomes apparent that the data will be required after the 6-month period has expired (e.g., due to an impending or pending legal dispute), the data will not be deleted until the purpose for its continued retention no longer applies.

Data may also be retained for a longer period if you have provided the necessary consent (Art. 6(1)(a) GDPR) or if statutory retention requirements prevent its deletion. You may revoke your consent at any time, effective for the future.

4 Analytics Tools and Advertising

When you visit this website, your browsing behavior may be analyzed for statistical purposes. This is primarily done using so-called analytics tools. You can find detailed information about these analytics tools in the following section.

4.1 Matomo

This website uses the open-source web analytics service Matomo.

With the help of Matomo, we are able to collect and analyze data about how visitors use our website. This allows us, among other things, to determine when specific pages were viewed and which region the visitors are from. We also collect various log files (e.g., IP address, referrer, browsers, and operating systems used) and can track whether our website visitors perform certain actions (e.g., clicks, etc.).

The use of this analytics tool is based on Article 6(1)(f) of the GDPR. The website operator has a legitimate interest in analyzing user behavior in order to optimize both its website and its advertising.

Privacy-friendly settings:

IP Anonymization

We use IP anonymization when analyzing data with Matomo. This involves truncating your IP address before analysis, so that it can no longer be uniquely associated with you.

„Replace User ID with Pseudonym“ option“

The feature has been enabled and causes internal visitor identifiers to be replaced with a hash value.

Hosting

We host Matomo exclusively on our own servers, so all analytics data remains with us and is not shared with anyone else.

5 Changes to Our Privacy Policy

We reserve the right to update this Privacy Policy to ensure it always complies with current legal requirements or to reflect changes to our services, such as the introduction of new services. The updated Privacy Policy will then apply to your next visit.