Privacy policy
Last updated: September 2026
This English translation is provided for convenience only. The German version at /de/datenschutz/ is legally binding and prevails in the event of any discrepancy.
General
As the operator of this website and as a company, we come into contact with your personal data. This means all data that says something about you and by which you can be identified. In this privacy policy, we would like to explain to you in what way, for what purpose and on what legal basis we process your data.
The party responsible for the processing of data on this website and within our company is:
Thorit GmbH
Jakob-Degen-Straße 1
71034 Böblingen
Phone: +49 7031 3097426
Email: info@thorit.de
General Notes
SSL and TLS Encryption
When you enter your data on web pages or send emails over the internet, you must always expect that unauthorised third parties may access your data. There is no complete protection against such access. However, we do everything we can to protect your data as best as possible and to close security gaps wherever possible.
An important protective mechanism is the SSL or TLS encryption of our website, which ensures that data you transmit to us cannot be read by third parties. You can recognise the encryption by the padlock icon in front of the internet address you entered in your browser and by the fact that our internet address begins with https:// and not with http://.
How long do we store your data?
In some places in this privacy policy, we inform you how long we, or the companies that process your data on our behalf, store your data. If no such information is given, we store your data until the purpose of the data processing ceases to apply, you object to the data processing, or you withdraw your consent to the data processing.
In the event of an objection or withdrawal, however, we may continue to process your data if at least one of the following conditions is met:
We have compelling legitimate grounds for continuing the data processing that override your interests, rights and freedoms (only in the case of an objection to the data processing; if the objection is directed against direct marketing, we cannot assert any legitimate grounds).
The data processing is necessary to assert, exercise or defend legal claims (does not apply if your objection is directed against direct marketing).
We are legally obliged to retain your data.
In this case, we will delete your data as soon as the condition(s) cease(s) to apply.
Data Transfers to Third Countries
On our website we use tools from companies that transfer your data to the USA and store and, where applicable, further process it there. This matters to you primarily because your data does not enjoy the same protection in the USA as it does within the EU, where the General Data Protection Regulation applies. Under certain conditions, US companies are obliged to disclose personal data to security authorities.
On 10 July 2023, with the adequacy decision on the EU-US Data Privacy Framework, the European Commission determined that the USA offers an adequate level of data protection for companies certified under that framework. Where the US providers we use are certified, we base the transfer on that decision pursuant to Art. 45 GDPR. You can check whether a company is certified in the public list at https://www.dataprivacyframework.gov/list.
Where a provider is not certified or processes data in other third countries, we base the transfer on the standard contractual clauses of the European Commission pursuant to Art. 46(2)(c) GDPR. The basis that applies is stated for each individual service in this policy.
Data Protection Officer
We have appointed a data protection officer for our company:
PRIVE by Legaltrust GmbH
Lietzenburger Str. 94
10719 Berlin
Phone: 030 / 223 89 993
Email: datenschutz@prive.eu
Your Rights
Objecting to the Data Processing
IF YOU READ IN THIS PRIVACY POLICY THAT WE HAVE LEGITIMATE INTERESTS IN THE PROCESSING OF YOUR DATA AND THEREFORE RELY ON ART. 6(1) SENTENCE 1(F) GDPR, YOU HAVE THE RIGHT UNDER ART. 21 GDPR TO OBJECT TO THIS. THIS ALSO APPLIES TO PROFILING CARRIED OUT ON THE BASIS OF THE PROVISION MENTIONED. THIS REQUIRES THAT YOU STATE REASONS FOR THE OBJECTION THAT ARISE FROM YOUR PARTICULAR SITUATION. NO REASONS ARE REQUIRED IF THE OBJECTION IS DIRECTED AGAINST THE USE OF YOUR DATA FOR DIRECT MARKETING.
THE CONSEQUENCE OF THE OBJECTION IS THAT WE MAY NO LONGER PROCESS YOUR DATA. THIS DOES NOT APPLY IF ONE OF THE FOLLOWING CONDITIONS IS MET:
- WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING THAT OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS.
- THE PROCESSING SERVES TO ASSERT, EXERCISE OR DEFEND LEGAL CLAIMS.
THE EXCEPTIONS DO NOT APPLY IF YOUR OBJECTION IS DIRECTED AGAINST DIRECT MARKETING OR AGAINST PROFILING CONNECTED WITH IT.
Further Rights
Withdrawal of Your Consent to Data Processing
Many data processing operations are based on your consent. You give this, for example, by ticking a corresponding box on online forms before sending the form, or by allowing certain cookies when you visit our website. You can withdraw your consent at any time without giving reasons (Art. 7(3) GDPR). From the time of withdrawal, we may no longer process your data. The only exception: we are legally obliged to retain the data for a certain period of time. Such retention periods exist in particular in tax and commercial law.
Right to Lodge a Complaint with the Competent Supervisory Authority
If you believe that we are in breach of the General Data Protection Regulation (GDPR), you have the right under Art. 77 GDPR to lodge a complaint with a supervisory authority. You may contact a supervisory authority in the member state of your habitual residence, your place of work, or the place where the alleged infringement occurred. The right to lodge a complaint exists alongside any administrative or judicial remedies.
Right to Data Portability
Data that we process automatically on the basis of your consent or in performance of a contract must be handed over to you or to a third party in a common machine-readable format if you request this. We can only transfer the data to another controller insofar as this is technically feasible.
Right to Information, Erasure and Rectification of Data
Under Art. 15 GDPR, you have the right to receive, free of charge, information about which personal data we have stored about you, where the data comes from, to whom we transmit the data and for what purpose it is stored. If the data is incorrect, you have a right to rectification (Art. 16 GDPR); under the conditions of Art. 17 GDPR, you may request that we delete the data. Submit a data protection request
Right to Restriction of Processing
In certain situations, you may, under Art. 18 GDPR, require us to restrict the processing of your data. Except for storage, the data may then only be processed as follows:
- with your consent
- to assert, exercise or defend legal claims
- to protect the rights of another natural or legal person
- for reasons of important public interest of the European Union or of a member state
The right to restriction of processing exists in the following situations:
- You have disputed the accuracy of the personal data stored with us and we need time to verify this. Here, the right exists for the duration of the verification.
- The processing of your personal data is unlawful or was unlawful in the past. Here, the right exists as an alternative to erasure of the data.
- We no longer need your personal data, but you need it to exercise, defend or assert legal claims. Here, the right exists as an alternative to erasure of the data.
- You have lodged an objection under Art. 21(1) GDPR and your interests and ours must now be weighed against each other. Here, the right exists for as long as the outcome of that balancing exercise has not yet been determined.
Hosting and Content Delivery Networks (CDN)
External Hosting
Who processes your data?
Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, 1855 Luxembourg, Luxembourg
Has a data processing agreement been concluded with the host?
Yes
Where can you find further information about data protection at Amazon Web Services?
https://aws.amazon.com/privacy/
On what basis do we transfer your data to third countries?
The website is stored exclusively in the Frankfurt am Main region. Delivery via the Amazon CloudFront content delivery network may also take place from locations outside the EU; the standard contractual clauses of the European Commission apply in that case (https://aws.amazon.com/compliance/gdpr-center/).
How do we process your data?
This is a static website. It is stored in Amazon S3 object storage in the Frankfurt am Main region and delivered via the Amazon CloudFront content delivery network, which caches the pages at locations around the world.
When a page is requested, CloudFront processes the connection data technically required for delivery. In particular, these are:
- your IP address
- the address requested and the referrer URL
- the date and time of the request
- browser type and version
- the operating system used
We have not enabled access logs (server log files) for this connection data. We do not evaluate it and do not combine it with other data. The website contains no database and no user accounts; form entries are not stored on the web server but processed by the service providers named under "Contact and enquiry forms".
On what legal basis do we process your data?
Since we use our website to address potential customers and maintain contact with existing ones, the processing by our host serves the initiation and performance of a contract and is therefore based on Art. 6(1)(b) GDPR. In addition, we have a legitimate interest as a company in providing a professional online presence that meets the necessary requirements for security, speed and efficiency. To that extent, we also process your data on the basis of Art. 6(1)(f) GDPR.
Data Collection on This Website
Use of Cookies
Our website places cookies on your device. These are small text files that serve various purposes. Some cookies are technically necessary for the website to function at all (necessary cookies). Others are required to carry out certain actions or functions on the site (functional cookies). For example, without cookies it would not be possible to use the benefits of a shopping basket in an online shop. Yet other cookies serve to analyse user behaviour or to optimise advertising measures. When we use third-party services on our website, e.g. to process payments, these companies may also leave cookies on your device when you access the website (so-called third-party cookies).
How do we process your data?
Session cookies are only stored on your device for the duration of a session. As soon as you close your browser, they disappear automatically. Persistent cookies, on the other hand, remain on your device unless you delete them yourself. This can, for example, mean that your user behaviour is analysed on an ongoing basis. You can use the settings in your browser to influence how it handles cookies:
- Do you want to be informed when cookies are set?
- Do you want to exclude cookies generally or for certain cases?
- Do you want cookies to be deleted automatically when you close your browser?
If you deactivate or do not allow cookies, the functionality of the website may be limited.
How long an individual cookie is stored depends on the service concerned and ranges from the duration of your visit to several months. The lifetime of each cookie is listed per service in the cookie settings and can be viewed there at any time. You can also delete cookies that have been set in your browser at any time.
If we use cookies from other companies or for analysis purposes, we will inform you of this within this privacy policy. We also ask for your consent in this regard when you access our website.
On what legal basis do we process your data?
Cookies that are strictly necessary for the operation of the website are stored on the basis of Section 25(2) no. 2 TDDDG; the subsequent processing of the data they contain is based on our legitimate interest in a technically faultless online offering pursuant to Art. 6(1)(f) GDPR. For all other cookies — in particular functional cookies as well as analytics and advertising cookies — we obtain your consent; the legal basis is then Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG. You can withdraw this consent at any time with effect for the future.
Cookie Consent with Usercentrics
What is Usercentrics?
Consent management platform (CMP) for obtaining, processing and forwarding GDPR-compliant consents
Who processes your data?
Usercentrics GmbH, Rosental 4, 80331 Munich, Germany
Has a data processing agreement been concluded with Usercentrics?
Yes
Where can you find further information about data protection at Usercentrics?
https://usercentrics.com/de/datenschutzerklaerung/
How do we process your data?
We use the consent management platform Usercentrics to obtain your consent to the storage of cookies on your device and to document it in a data-protection-compliant manner. When you visit our website and close the Usercentrics cookie banner requesting consent, the following data is transmitted to the company:
- Your consent(s) or the withdrawal of your consent(s)
- Your IP address
- Information about your browser
- Information about your device
- the time of your visit to the website
Usercentrics also stores a cookie in your browser in order to be able to link the consents given, or their withdrawal, to your browser. All data collected is stored until the cookies are no longer needed, you delete the Usercentrics cookie, or you ask us to delete the data. This does not apply if we are legally obliged to retain the data.
How can you withdraw your consent?
You can change or fully withdraw your consent at any time with effect for the future. To do so, open the cookie settings of this website. There you can change your selection; services embedded via Google Tag Manager are released or blocked together with it. Alternatively, delete the cookies set by Usercentrics in your browser — you will then be asked for your consent again the next time you visit the website. Withdrawal does not affect the lawfulness of the processing carried out up to that point.
On what legal basis do we process your data?
We are legally obliged to obtain the consent of our website visitors for the use of certain cookies. To fulfil this obligation, we use Usercentrics. The legal basis for the data processing is therefore Art. 6(1)(c) GDPR.
Contact and Enquiry Forms
This website provides forms through which you can send us an enquiry or request a whitepaper. The forms are provided by HubSpot and embedded in our pages. The data you enter is transmitted directly to HubSpot and stored there in our CRM; details about this service provider can be found in the "HubSpot" section.
Which data do we process?
In the contact form we collect first and last name, business email address and telephone number as mandatory information, as well as company name, your message and your preferred language as optional information. In the whitepaper download form we collect first and last name, business email address and preferred language. We also process the time of submission and the technical data arising when the form is loaded.
The forms contain checkboxes with which you consent to receiving emails about our services and offers. We document your decision on this together with the time it was given. In the contact form, agreeing to receive emails from our sales team is a prerequisite for submission; without the fields marked as mandatory and this checkbox, you cannot submit the form. You are welcome to write to us informally by email at hello@thorit.de instead.
How do we process your data?
We store your information in order to handle your enquiry, including any follow-up questions, and to provide you with the content you requested. We use the contact details you provide to respond; this includes contacting you by telephone where you have supplied a telephone number. Beyond the service providers named in this policy, we do not pass the data on to third parties.
How long do we store your data?
We delete your data as soon as one of the following applies:
- Your enquiry has been fully dealt with and there is no further business contact.
- You ask us to delete the data.
- You withdraw your consent to storage.
This does not apply where we are legally obliged to retain the data; retention periods under commercial and tax law can be up to ten years.
On what legal basis do we process your data?
Where your enquiry relates to an existing or prospective contractual relationship – in particular where you request a quotation or information about our services – we process your data to answer the enquiry on the basis of Art. 6(1)(b) GDPR. In all other cases, we have a legitimate interest in dealing effectively with enquiries addressed to us; the legal basis is then Art. 6(1)(f) GDPR.
Sending emails about our services and offers that go beyond answering your enquiry is based on your consent pursuant to Art. 6(1)(a) GDPR. You can withdraw this consent at any time with effect for the future, in particular via the unsubscribe link in each of these emails.
Enquiries by Email, Telephone or Fax
You can send us a message by email or fax, or call us.
How do we process your data?
We store your message as well as the contact details you provide yourself or the transmitted telephone number, in order to be able to process your enquiry, including any follow-up questions. We do not pass your data on to other persons without your consent.
How long do we store your data?
We delete your data as soon as one of the following applies:
- Your enquiry has been conclusively processed.
- You ask us to delete the data.
- You withdraw your consent to the storage.
This does not apply if we are legally obliged to retain the data.
On what legal basis do we process your data?
If your enquiry is related to our contractual relationship or serves to carry out pre-contractual measures, we process your data on the basis of Art. 6(1)(b) GDPR. In all other cases, it is our legitimate interest to process enquiries addressed to us effectively. The legal basis for the data processing is therefore Art. 6(1)(f) GDPR. If you have consented to the storage of your data, Art. 6(1)(a) GDPR is the legal basis. In this case, you can withdraw your consent at any time with effect for the future.
HubSpot
What is HubSpot?
Platform for customer relationship management (CRM), i.e. managing customer relationships across marketing, sales and service
Who processes your data?
HubSpot Ireland Limited, Ground Floor, Two Dockland Central, Guild Street, Dublin 1, D01 K2C5, Ireland, and HubSpot, Inc., 2 Canal Park, Cambridge, MA 02141, USA
Has a data processing agreement been concluded with HubSpot?
Yes
Where can you find further information about data protection at HubSpot?
https://legal.hubspot.com/privacy-policy
On what basis do we transfer your data to the USA?
The data is stored in HubSpot's EU data centre in Germany. Where data is transferred to the USA, this takes place on the basis of the EU-US Data Privacy Framework and the standard contractual clauses of the European Commission (https://www.hubspot.com/data-privacy/gdpr).
How do we process your data?
We use the HubSpot CRM to record, organise and analyse customer interactions across various channels. We evaluate the personal data collected and use it to communicate with existing and potential customers and for marketing purposes.
HubSpot also provides the forms on this website and, subject to your consent, sets cookies that allow your visit to be recognised and assigned to your record in the CRM. This involves processing your IP address, the pages you view, the time you spend on them and details of your browser and operating system.
On what legal basis do we process your data?
We have a legitimate interest in managing customers and communicating with them as efficiently as possible. The processing of data submitted through the forms is therefore based on Art. 6(1)(f) GDPR, unless it already serves the initiation of a contract under Art. 6(1)(b) GDPR. The setting of cookies and the associated analysis of your usage behaviour take place exclusively on the basis of your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG. You can withdraw your consent at any time with effect for the future.
ProvenExpert
What is ProvenExpert?
Online service for collecting and publishing customer reviews
Who processes your data?
Expert Systems AG, Quedlinburger Str. 1, 10589 Berlin, Germany
Has a data processing agreement been concluded with ProvenExpert?
Yes
Where can you find further information about data protection at ProvenExpert?
https://www.provenexpert.com/en-us/privacy-policy/
How do we process your data?
We use ProvenExpert to collect feedback from our customers and to publish the reviews they submit. This involves processing the contact details of the person invited to leave a review and the information they provide in the review itself.
This website does not embed a review seal or any other ProvenExpert content. Simply visiting this website therefore transmits no data to ProvenExpert.
On what legal basis do we process your data?
We have a legitimate interest in measuring the quality of our services and presenting it in a comprehensible way. The processing is therefore based on Art. 6(1)(f) GDPR. If you have consented to the processing, we process your data exclusively on the basis of Art. 6(1)(a) GDPR. You can withdraw your consent at any time with effect for the future.
Analytics Tools and Advertising
We use the following tools to analyse the behaviour of our website visitors and to show them advertising.
The services listed below map your behaviour on this website into pseudonymous user profiles and deliver advertising to you on that basis. This constitutes profiling within the meaning of Art. 4(4) GDPR. It does not involve any decision based solely on automated processing which produces legal effects or similarly significantly affects you within the meaning of Art. 22 GDPR. All services in this section are loaded only after you have given your consent.
Google Tag Manager
What is Google Tag Manager?
Tag management system for embedding tracking codes and conversion pixels, provided by Google Ireland Ltd.
Who processes your data?
Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland
Where can you find further information about data protection at Google Tag Manager?
https://policies.google.com/privacy
On what basis do we transfer your data to the USA?
Google LLC is certified under the EU-US Data Privacy Framework; the standard contractual clauses of the European Commission apply in addition (https://privacy.google.com/businesses/compliance)
How do we process your data?
We use Google Tag Manager. The tool helps us to embed, manage and deploy tracking codes and conversion pixels on our website. Google Tag Manager itself does not create user profiles, does not place cookies on your device, and does not analyse your behaviour as a user. However, it does record your IP address and transmits it to Google's servers in the USA.
On what legal basis do we process your data?
We use Google Tag Manager to embed and manage the services used on this website. Storing information on your device and accessing it requires your consent. The service is therefore used exclusively on the basis of your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG. You can withdraw your consent at any time with effect for the future; without it, the service is not loaded.
Google Analytics
What is Google Analytics?
Tool for analysing user behaviour, provided by Google Ireland Ltd. We use the Google Analytics 4 version.
Who processes your data?
Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland
Has a data processing agreement been concluded with Google Analytics?
Yes
Where can you find further information about data protection at Google Analytics?
https://support.google.com/analytics/answer/6004245?hl=de
On what basis do we transfer your data to the USA?
Google LLC is certified under the EU-US Data Privacy Framework; the standard contractual clauses of the European Commission apply in addition (https://privacy.google.com/businesses/compliance)
How can you prevent the data collection?
Among other things, with a browser plugin: https://tools.google.com/dlpage/gaoptout?hl=de
How do we process your data?
We are always interested in optimising our website for our visitors and placing advertising optimally. Google Analytics helps us with this — a tool that analyses user behaviour and thus provides us with the necessary data basis for adjustments. Through the tool, we receive information about the origin of our visitors, their page views and the time they spend on the pages, as well as the operating system they use.
Standard Processing
To collect the data, Google Analytics uses cookies, device fingerprinting or other technologies for recognising users. The data is transmitted to Google's servers in the USA and, using the IP address also collected, combined into a profile that can be attributed to you or your device.
You can prevent Google from processing your data by installing a browser plugin provided by Google itself: https://tools.google.com/dlpage/gaoptout?hl=de.
Truncation of the IP Address
In Google Analytics 4, your IP address is not stored. It is truncated on arrival at servers within the EU or the EEA and evaluated only for a rough determination of location. This truncation is part of the service and cannot be switched on or off.
Demographic Characteristics
We use the "demographic characteristics" function of Google Analytics in order to be able to show visitors to our website advertisements matching their interests within the Google advertising network. As a result, reports can be generated that contain information on the age, gender and interests of our page visitors. This data comes from Google's interest-based advertising as well as from visitor data provided by third-party providers. It is not possible to attribute the collected data to specific individuals.
You can deactivate this function in the settings of your Google account.
How long do we store your data?
Data stored at user and event level that is linked to cookies, user identifiers (e.g. user IDs) or advertising IDs is, according to Google's own information, deleted or anonymised by Google after 26 months (see https://support.google.com/analytics/answer/7667196?hl=de).
On what legal basis do we process your data?
We have an interest in analysing user behaviour in order to improve our online offering. Storing information on your device and accessing it requires your consent. The service is therefore used exclusively on the basis of your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG. You can withdraw your consent at any time with effect for the future; without it, the service is not loaded.
Google Ads
What is Google Ads?
Online advertising programme provided by Google Ireland Ltd.
Who processes your data?
Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland
Where can you find further information about data protection at Google Ads?
https://policies.google.com/privacy?hl=de&gl=de
On what basis do we transfer your data to the USA?
Google LLC is certified under the EU-US Data Privacy Framework; the standard contractual clauses of the European Commission apply in addition (https://privacy.google.com/businesses/compliance)
How do we process your data?
We use Google Ads. Google's advertising programme allows us to display advertisements in the Google search engine or on third-party websites when visitors to our website enter certain search terms in Google (keyword targeting). Furthermore, based on the user data available at Google (e.g. location data and interests), we can place targeted advertisements (audience targeting). We evaluate the collected data quantitatively, for example by analysing which search terms led to the display of our advertisements and how many advertisements led to corresponding clicks.
On what legal basis do we process your data?
We have an interest in placing and evaluating advertisements. Storing information on your device and accessing it requires your consent. The service is therefore used exclusively on the basis of your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG. You can withdraw your consent at any time with effect for the future; without it, the service is not loaded.
Google Conversion Tracking
What is Google Conversion Tracking?
Tool for analysing user behaviour, provided by Google Ireland Ltd.
Who processes your data?
Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland
Where can you find further information about data protection at Google Conversion Tracking?
https://www.google.de/intl/de/policies/privacy/
On what basis do we transfer your data to the USA?
Google LLC is certified under the EU-US Data Privacy Framework; the standard contractual clauses of the European Commission apply in addition (https://privacy.google.com/businesses/compliance)
How do we process your data?
We are always interested in optimising our website for users and placing advertising optimally. For this purpose, we also use Google's Conversion Tracking. With its help, we can record whether and how often visitors to our website have clicked on certain buttons and which products were viewed and purchased particularly frequently (conversion statistics) . In the course of collecting and storing the data, we do not receive any information that would enable us to personally identify individual visitors. Google itself uses cookies or comparable recognition technologies for identification.
On what legal basis do we process your data?
We have an interest in measuring the success of our advertisements. Storing information on your device and accessing it requires your consent. The service is therefore used exclusively on the basis of your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG. You can withdraw your consent at any time with effect for the future; without it, the service is not loaded.
Google DoubleClick
What is Google DoubleClick?
Tool for personalised advertising, provided by Google Ireland Ltd.
Who processes your data?
Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland
Where can you find further information about data protection at Google DoubleClick?
https://www.google.de/intl/de/policies/privacy/ and https://policies.google.com/technologies/ads
On what basis do we transfer your data to the USA?
Google LLC is certified under the EU-US Data Privacy Framework; the standard contractual clauses of the European Commission apply in addition (https://privacy.google.com/businesses/compliance)
How can you prevent the data processing?
By objecting to personalised advertising in your Google account or on the page https://www.google.com/settings/ads/onweb/
How do we process your data?
We use DoubleClick in order to show you advertising tailored to your interests throughout the entire Google advertising network. The advertisements appear, for example, in Google search results or in advertising banners connected to DoubleClick. In order to display the appropriate advertising to you, Google DoubleClick must be able to recognise you. For this reason, the tool places cookies on your computer or uses other recognition technologies, such as device fingerprinting. Google creates pseudonymous user profiles from the data collected.
On what legal basis do we process your data?
We have an interest in targeted advertising measures. Storing information on your device and accessing it requires your consent. The service is therefore used exclusively on the basis of your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG. You can withdraw your consent at any time with effect for the future; without it, the service is not loaded.
Meta Pixel (Facebook Pixel)
What is the Meta Pixel?
Tool for analysing user behaviour that measures the effectiveness of advertising on Facebook and Instagram and enables user-based advertising to be delivered on those platforms
Who processes your data?
Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland
In what capacity does Meta process your data?
For the collection of data via the pixel and its transmission to Meta, we are joint controllers with Meta within the meaning of Art. 26 GDPR; we have concluded Meta's Controller Addendum for this purpose. Meta is the sole controller for the subsequent processing. Pursuant to Art. 26(2) GDPR we inform you of the essence of the arrangement: Meta provides the information required under Art. 13 and 14 GDPR in its privacy policy and is the contact point for exercising your data subject rights in respect of the data stored at Meta; you may also assert your rights against us, and we will forward the request. The addendum is available at https://www.facebook.com/legal/controller_addendum.
Where can you find further information about data protection at Meta?
https://www.facebook.com/privacy/policy/
On what basis do we transfer your data to the USA and other third countries?
Meta is certified under the EU-US Data Privacy Framework and additionally complies with the standard contractual clauses of the European Commission (see https://www.facebook.com/legal/EU_data_transfer_addendum and https://www.facebook.com/help/566994660333381)
How can you prevent the data processing?
If you have a Facebook account: deactivate the remarketing function "Custom Audiences" in the ad settings (https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen).
If you do not have a Facebook account: deactivate usage-based advertising from Facebook on the website of the European Interactive Digital Advertising Alliance: http://www.youronlinechoices.com/de/praferenzmanagement/.
How do we process your data?
We use Facebook Pixel on our website. The analysis tool helps us learn more about the behaviour of visitors to our website after they have clicked on one of our advertisements on Facebook. This allows us to measure how effective our Facebook advertising is and to align future advertising measures with the insights gained. The data that Facebook collects via the pixel is anonymous to us as the operator of this website. We therefore cannot identify you as a visitor. However, the data is stored and processed by Facebook. Facebook uses the pixel to establish a connection to your Facebook account and also uses the data to place advertising itself both within and outside the network (see Facebook's data use policy). In the course of storage and processing, Facebook also transmits the data to the USA and other third countries.
If you have a Facebook account, you can deactivate the remarketing function "Custom Audiences" in the ad settings at https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen.
If you do not have a Facebook account, you have the option of deactivating usage-based advertising from Facebook on the website of the European Interactive Digital Advertising Alliance: http://www.youronlinechoices.com/de/praferenzmanagement/.
On what legal basis do we process your data?
We have an interest in effective advertising measures on social networks. Storing information on your device and accessing it requires your consent. The service is therefore used exclusively on the basis of your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG. You can withdraw your consent at any time with effect for the future; without it, the service is not loaded.
LinkedIn Insight Tag
What is LinkedIn Insight Tag?
Tool for analysing user behaviour, provided by LinkedIn Ireland Unlimited Company
Who processes your data?
LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland
In what capacity does LinkedIn process your data?
For the collection of data via the Insight Tag and its transmission to LinkedIn, we are joint controllers with LinkedIn within the meaning of Art. 26 GDPR. LinkedIn is the sole controller for the subsequent processing. Pursuant to Art. 26(2) GDPR we inform you of the essence of the arrangement: LinkedIn fulfils the information obligations under Art. 13 and 14 GDPR through its privacy policy and is the contact point for exercising your data subject rights in respect of the data stored at LinkedIn; you may also assert your rights against us. The arrangement forms part of the LinkedIn Ads Data Processing Agreement (https://www.linkedin.com/legal/l/dpa).
Where can you find further information about data protection at LinkedIn Insight Tag?
https://www.linkedin.com/legal/privacy-policy#choices-oblig
On what basis do we transfer your data to the USA?
LinkedIn Insight Tag complies with the standard contractual clauses of the European Commission (see https://www.linkedin.com/legal/l/dpa and https://www.linkedin.com/legal/l/eu-sccs)
How can you prevent the data processing?
By objecting to the analysis of your user behaviour and to targeted advertising by LinkedIn at the following link: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out. If you have a LinkedIn account, you can also make settings there regarding the use of your personal data for advertising purposes.
How do we process your data?
We use LinkedIn Insight Tag on our website. The analysis tool helps us learn more about the visitors to our website and adapt our online offering accordingly. If our visitors are registered with LinkedIn, we can use the tool to analyse, among other things, their professional details such as career level, company size, country, location, industry and job title. It is also possible to measure whether they make a purchase or carry out some other action (conversion measurement). This data is determined across devices. Finally, LinkedIn Insight Tag offers a retargeting function that we can use to show our visitors targeted advertising outside our website. LinkedIn assures that individual advertising recipients cannot be identified in the process.
In addition to the data mentioned, the analysis tool collects the following data about you when you visit our website: URL, referrer URL, IP address, device and browser characteristics, and the time of access. The IP addresses are shortened or pseudonymised. The latter occurs when you, as a LinkedIn member, are to be reached across devices.
The data collected by LinkedIn is anonymous to us as the operator of the website. We therefore cannot identify you as a visitor. However, LinkedIn will store your personal data on its servers in the USA and use it for its own advertising purposes.
You can prevent LinkedIn from linking the data collected on our website to your LinkedIn account by logging out of your account before continuing to browse the internet. You can also prevent the use of your data for advertising purposes through the corresponding settings in your account.
If you do not have a LinkedIn account, you can object to the analysis of your usage behaviour and to targeted advertising by LinkedIn at the following link: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
How long do we store your data?
LinkedIn deletes the direct identifiers of LinkedIn members after 7 days. The remaining pseudonymised data is deleted within 180 days.
On what legal basis do we process your data?
We have an interest in evaluating and optimising our advertising measures. Storing information on your device and accessing it requires your consent. The service is therefore used exclusively on the basis of your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG. You can withdraw your consent at any time with effect for the future; without it, the service is not loaded.
Hotjar
What is Hotjar?
Analytics service that records usage behaviour on websites and presents it graphically
Who processes your data?
Hotjar Ltd., Dragonara Business Centre, 5th Floor, Dragonara Road, Paceville St Julian's STJ 3141, Malta
Has a data processing agreement been concluded with Hotjar?
Yes
Where can you find further information about data protection at Hotjar?
https://www.hotjar.com/legal/policies/privacy/
On what basis do we transfer your data to third countries?
Hotjar processes the data within the European Union. Where sub-processors transfer data to third countries, this takes place on the basis of the standard contractual clauses of the European Commission.
How do we process your data?
We use Hotjar to understand how our website is used and where it can be improved. To do this, Hotjar records your behaviour on a page and presents it to us in aggregated form as a heatmap, or replays individual sessions as a sequence of movements. The following are recorded:
- mouse movements, clicks, scrolling behaviour and keystrokes outside input fields
- the pages viewed and the time spent on them
- screen size, browser type and version and the operating system used
- the country from which the visit originates
- a truncated IP address
Hotjar suppresses the contents of input fields by default, so the text you enter into forms does not appear in the recordings. The data is stored pseudonymously under a randomly assigned identifier; we do not combine it with other data and do not attribute it to you personally.
On what legal basis do we process your data?
Hotjar is used exclusively on the basis of your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG. You can withdraw your consent at any time with effect for the future. Independently of this, you can object to being tracked by Hotjar on a per-device basis: https://www.hotjar.com/policies/do-not-track/
Microsoft Advertising
What is Microsoft Advertising?
Advertising network with conversion measurement and remarketing for the Bing search engine
Who processes your data?
Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland
Where can you find further information about data protection at Microsoft Advertising?
https://privacy.microsoft.com/privacystatement
On what basis do we transfer your data to the USA?
Microsoft is certified under the EU-US Data Privacy Framework; the standard contractual clauses of the European Commission apply in addition.
How do we process your data?
We use Microsoft Advertising Universal Event Tracking to measure which of our advertisements led to a visit or an enquiry, and to show you advertising on other websites that matches your interests. To do this, a cookie is set in your browser and details of the pages viewed, the origin of the visit and your IP address are transmitted to Microsoft.
On what legal basis do we process your data?
This service is used exclusively on the basis of your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG. You can withdraw your consent at any time with effect for the future.
AdRoll
What is AdRoll?
Platform for user-based advertising that delivers ads across a large number of connected advertising networks
Who processes your data?
NextRoll, Inc., 2300 Harrison Street, 2nd Floor, San Francisco, CA 94110, USA, and NextRoll Ireland Limited, Level 1, The Chase, Carmanhall Road, Sandyford, Dublin 18, Ireland
Has a data processing agreement been concluded with AdRoll?
Yes
Where can you find further information about data protection at AdRoll?
https://www.nextroll.com/privacy
On what basis do we transfer your data to the USA?
On the basis of the standard contractual clauses of the European Commission.
How do we process your data?
We use AdRoll to show visitors to our website advertising for our services on other websites. To do this, AdRoll sets cookies and processes your IP address, a device identifier, the pages you viewed and details of your browser.
AdRoll matches these identifiers with connected advertising networks so that the ads can also be delivered there. Your data may be transmitted to the following companies in the process: BIDSWITCH, Bombora, Eyeota, Index Exchange, OpenX, Outbrain, PubMatic, Taboola, Tapad, The Rubicon Project and TripleLift. Each of these companies is itself responsible for the processing within its own sphere of responsibility.
On what legal basis do we process your data?
This service is used exclusively on the basis of your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG. You can withdraw your consent at any time with effect for the future.
Plugins and Tools
Fonts
The fonts used on this website are stored on our own storage and loaded exclusively from there. When you visit the website, no connection is established to servers operated by Google or any other font provider, and no data is transmitted to them.
Audio and Video Conferencing
As a company, we are in contact with many people: customers, business partners, service providers, etc. For this exchange, alongside other means of communication, we also use so-called online conferencing tools. Information relevant to data protection concerning the provider(s) of the tools we use can be found at the end of this section. If you communicate with us via such a tool, not only we but, in particular, the provider of the respective tool also processes your personal data.
How do we process your data?
Online conferencing tools collect and store various personal data in order to enable participation in an online conference and its smooth execution. In addition to registration, conference and technical data, this also concerns certain communication content.
Registration data: your email address and/or telephone number and, where applicable, further data you provide when registering for the conference.
Conference data: start, end and duration of your participation in the conference, the number of participants and other metadata relating to the conference.
Technical data: IP address, MAC address, device ID, device type, operating system and version, client version, camera type, microphone or speaker, as well as the type of connection.
Communication content: cloud recordings, chat/instant messages, voicemails, uploaded photos and videos, files, whiteboards and other information shared while using the service.
Please refer to the privacy policies of the respective conferencing tool provider for details on the data processing.
How long do we store your data?
As your communication partner, we delete your data on our systems as soon as one of the following applies:
The purpose of the data processing ceases to apply.
You ask us to delete the data.
You withdraw your consent to the storage.
This does not apply if we are legally obliged to retain the data.
Cookies remain on your device until you delete them.
The providers of conferencing tools also store your data for their own purposes. Please ask the providers directly what this means for the duration of the storage of your data.
On what legal basis do we process your data?
If we are already contractually connected or if you wish to conclude a contract with us, we use conferencing tools to perform the contract or to inform you about our services or products. In this respect, the data processing is carried out on the basis of Art. 6(1)(b) GDPR. Otherwise, the use of conferencing tools serves simple and fast communication, without which we could not run our company efficiently. We therefore also have a legitimate interest in the data processing pursuant to Art. 6(1)(f) GDPR. A further legal basis may be your consent. Art. 6(1)(a) GDPR is applicable in this case. This basis ceases to apply for the future if you withdraw your consent.
Which Online Conferencing Tools Do We Use?
Microsoft Teams
What is Microsoft Teams?
Communication platform for collaboration in teams
Who processes your data?
Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland
Has a data processing agreement been concluded with Microsoft Teams?
Yes
Where can you find further information about data protection at Microsoft Teams?
https://privacy.microsoft.com/de-de/privacystatement
On what basis do we transfer your data to the USA?
Microsoft complies with the standard contractual clauses of the European Commission (https://docs.microsoft.com/en-us/compliance/regulatory/gdpr)
Data Processing in the Recruitment Process
If you apply to Thorit GmbH, we process your personal data to carry out the application procedure. Below, we provide you with comprehensive information on the nature, scope and purpose of this processing, as well as on the tools and service providers we use.
1. What Data Do We Process?
As part of your application, we process the following categories of personal data:
- master data such as first and last name, address and date of birth
- contact details such as email address and telephone number
- application documents such as cover letter, CV, references and certificates
- information about your education, career history and qualifications
- information you provide voluntarily, such as a portfolio or a profile on a professional network
- communication data from the application process as well as notes and assessments from interviews
- technical data arising when the job portal is loaded (see section 2)
2. Applicant Tracking System: Ashby (ATS)
| Who processes your data? | Ashby, Inc., 548 Market St PMB 24306, San Francisco, CA 94104, USA |
|---|---|
| Has a data processing agreement been concluded? | Yes |
| Data protection information | https://www.ashbyhq.com/privacy |
| Third-country transfer | On the basis of the EU standard contractual clauses pursuant to Art. 46(2)(c) GDPR |
We use Ashby as an applicant tracking system (ATS) to manage incoming applications, for internal communication about candidates and to coordinate the selection process. Ashby processes applicant data on our behalf as a processor pursuant to Art. 28 GDPR.
The job portal is embedded on our careers page as content provided by Ashby. When you open the careers page, the job listings are loaded directly from Ashby's servers; in doing so, your IP address and details of your browser and operating system are transmitted to Ashby. In this context, Ashby sets a cookie with a lifetime of 15 minutes that serves to identify your session.
2a. Reach and Error Analysis in the Job Portal (Datadog)
Within the job portal, Ashby uses the Datadog RUM service provided by Datadog, Inc., 620 8th Avenue, 45th Floor, New York, NY 10018, USA, in order to monitor the technical availability and correct operation of the portal. This records technical session data and your interactions with the portal. A proportion of sessions is recorded as a sequence of movements; entries in the fields of the application form may become visible in the process.
Data protection information from Datadog: https://www.datadoghq.com/legal/privacy/. Transfer to the USA takes place on the basis of the EU-US Data Privacy Framework and the standard contractual clauses of the European Commission.
The legal basis for storing information on your device and accessing it is your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG, which is obtained in the job portal. Where a session recording captures information from your application documents that may contain special categories of personal data within the meaning of Art. 9(1) GDPR, we base the processing on your explicit consent pursuant to Art. 9(2)(a) GDPR. You can withdraw your consent at any time with effect for the future.
2b. Protection Against Automated Access (reCAPTCHA)
The application form is protected by reCAPTCHA version 3 provided by Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland. Without a visible test, the service checks whether the input originates from a human being or from an automated program. To this end, your IP address, details of your browser and operating system and your behaviour on the page are transmitted to Google and evaluated there. reCAPTCHA is embedded by Ashby and is loaded only on the application form, not on the job overview.
Further information: https://policies.google.com/privacy. Storing information on your device and accessing it are necessary in order to protect the application form against automated access; the legal basis for this is Section 25(2) no. 2 TDDDG. The subsequent processing is based on our legitimate interest in preventing misuse pursuant to Art. 6(1)(f) GDPR.
3. Retention Period
Applicant data is generally deleted within 6 months of the conclusion of the application procedure. This period derives from the two-month period for asserting claims under Section 15(4) of the German General Equal Treatment Act (Allgemeines Gleichbehandlungsgesetz, AGG), the three-month limitation period for bringing an action under Section 61b(1) of the German Labour Court Act (Arbeitsgerichtsgesetz, ArbGG) and an allowance for service. It serves the purpose of allowing any claims under the AGG to be asserted or defended against.
4. No Fully Automated Individual Decisions (Art. 22 GDPR)
All decisions – in particular invitations to interviews, rejections and hiring decisions – are made by human recruiting staff. Profiling and any evaluation of your application based solely on automated processing do not take place.
Art. 22(1) GDPR, which provides for the right not to be subject to a decision based solely on automated processing, is thus fully complied with.
5. Legal Bases at a Glance
| Processing activity | Legal basis |
|---|---|
| Receiving and reviewing application documents | Art. 6(1)(b) GDPR in conjunction with Section 26(1) BDSG |
| Managing the process in the applicant tracking system | Art. 6(1)(b) GDPR in conjunction with Section 26(1) BDSG |
| Operating and securing the job portal | Art. 6(1)(f) GDPR (legitimate interest) |
| Retention after rejection (AGG period) | Art. 6(1)(f) GDPR (legitimate interest) |
6. Third-Country Transfer
Ashby, Inc. and Datadog, Inc. are based in the USA. Where personal data is transferred to the USA, this takes place on the basis of the EU standard contractual clauses pursuant to Art. 46(2)(c) GDPR or, where the company is certified, on the basis of the adequacy decision on the EU-US Data Privacy Framework.
7. Your Rights as an Applicant
In relation to the data processed about you in the application process, you have the same rights as any data subject, in particular the right of access, rectification, erasure, restriction of processing, data portability and objection, as well as the right to withdraw consent at any time and to lodge a complaint with a supervisory authority. Details can be found above under "Your Rights".
For data protection enquiries relating to the application process, please contact our data protection officer: datenschutz@prive.eu
Or use our data protection portal: Submit a data protection request
