DE/EN

Privacy policy

We are delighted about the visit of our website. We would like to inform you below about the processing of your personal data on our website.

 

Controller
Rollout Solutions GmbH
Gangolfstr. 6
88048 Friedrichshafen

Tel.: 07544-95195-30
E-Mail: datenschutz@rolllout-solutions.de

Terms

The special terms used in this privacy policy are to be understood as legally defined in Art.4 GDPR. The terms "user" and "website visitor" are used synonymously in our privacy policy.

Recipient of data 

Recipients of data are named in our privacy policy under the respective category/heading. 

Categories of data subjects

The categories of data subjects are website visitors and other users of online services.

General information on data processing on the website

Automated data processing (log files etc.)

Our website can be visited without actively providing personal information about the user. However, every time our website is accessed, we automatically store access data (server log files), such as the name of the internet service provider, the operating system used, the website the user visited us from, the date and duration of the visit and the name of the file accessed, as well the IP address of the device used (for security reasons, such as to recognise attacks on our website). This data is stored in anonymized form for up to 8 weeks. This data is not merged with other data sources. We process and use the data for the following purposes: provision of the website, prevention and detection of errors/malfunctions, and the abuse of the website.

Data categories: Meta and communication data (e.g. IP address, date and time of access, time, type of HTTP request, website from which access is made (referrer URL), browser used and, if applicable, operating system of the accessing computer (user agent))

Purpose of the processing: Prevention and detection of errors/malfunctions, detection of abuse of the website

Legal basis: Legitimate interest according to Art. 6 para. 1 lit. f) GDPR

Legitimate interests: Fraud prevention to detect abuse of the website

 

Required cookies (functionality, opt-out links, etc.)

We use cookies on our website to enable the use of the basic functions on our website and to provide the service requested by the user. Cookies are a standard Internet technology for storing and retrieving information for website users. Cookies represent information and/or data that can be stored on the user's end device, for example. With classic cookie technology, the user's browser is instructed to store certain information on the user's device when a specific website is accessed.

Strictly required cookies are used to provide a digital service expressly requested by the user, e.g:

  • Cookies for error analysis and security purposes
  • Cookies for storing logins
  • Cookies for storing data in online forms if the form extends over several pages
  • Cookies for saving (language) settings
  • Cookies to store articles in the shopping basket by users to complete the purchase
  • Cookies for storing consent or withdrawal (opt-in, opt-out)

Some of the cookies used (session cookies) are erased after the end of the browser session, i.e. after closing the browser. 

Cookies can be erased by users afterwards to remove data that the website has stored on the user's computer.

The data processing described may also relate to information that is not personal but constitutes information within the meaning of the TDDDG. In these cases, this information may be necessary for the use of an expressly requested service and may therefore be stored in accordance with § 25 TDDDG. 

Opt-Out:

Firefox: https://support.mozilla.org/de/kb/wie-verhindere-ich-dass-websites-mich-verfolgen

Google Chrome: https://support.google.com/chrome/answer/95647?hl=de

Microsoft Edge: https://support.microsoft.com/de-de/microsoft-edge/inprivate-browsen-in-microsoft-edge-cd2c9a48-0bc4-b98e-5e46-ac40c84e27e2

Opera: https://help.opera.com/en/latest/security-and-privacy/

Safari: https://support.apple.com/de-de/HT201265

Legal basis:  Legitimate interests (Art. 6 para. 1 lit. f) GDPR in conjunction with § 25 para. 2 no. 2 TDDDG), consent (Art. 6 para. 1 lit. a) GDPR in conjunction with § 25 para. 1 TDDDG

Legitimate interests: Storage of opt-in preferences, ensuring the functionality of the website, maintaining user status across the entire website

 

Storage and processing of not required information and data

Beyond the required scope, user data may be processed by cookies, similar technologies or application-related technologies, e.g. for the purpose of (cross-website) tracking or personalized advertising etc.. Data may be transmitted to third-party providers. The storage and further processing of user data that is not necessary to provide the digital service, is then carried out on the basis of consent within the meaning of Art. 6 para. 1 lit. a) GDPR (if applicable in conjunction with § 25 para. 1 sentence 2 TDDDG).

 

Consent Management Platforms (Consent Management)

We use a consent management procedure on our online offering in order to be able to prove, store and manage the consent granted by our website visitors in accordance with the requirements of the GDPR. 

The consent management platform used helps us to identify all cookies and tracking technologies and to control them based on the consent status. At the same time, visitors to our website can use the consent management service we have integrated to manage the consents and preferences granted (optional setting of cookies and other technologies that are not required) or revoke consent at any time using the button. 

The status of the consent is stored on the server and/or in a cookie (so-called opt-in cookie) or a comparable technology in order to be able to assign the consent to a user or their device. The time of the declaration of consent is also recorded.

Data categories: Consent data (consent ID and number, time consent was given, opt-in or opt-out), meta and communication data (e.g. device information, IP addresses)

Purposes of processing: Fulfillment of accountability, consent management

Legal basis: Legal obligation (Art. 6 para. 1 lit. c) GDPR in conjunction with Art. 7 GDPR) 
Manage consent/revocation

Website support and consulting, web agency

We have commissioned a web agency to provide support and advice for services and applications on our website. This agency supports us in all activities related to the design and functionality of our website. In this context, the web agency selected by us receives the access data for our website in order to make necessary adjustments and changes, such as the design of forms or other programming activities.

The web agency also helps us set up the Brevo newsletter system and manage and administer Google Ads and Bing Ads.

Access to personal data, such as data from forms or log data of website visitors, cannot be ruled out. The web agency therefore acts as a processor for us and only acts on our instructions. Data is not processed for any other purpose. 

Data categories: Usage data (e.g. access times), Meta and communication data (e.g. device information, IP addresses), Contact data (e.g. email address), Content data (e.g. text information)

Purposes of processing: Support for web analysis and optimization, analysis of user behavior on the website (website interaction) for web optimization and reach measurement, checking the utilization of the website

Legal basis: Legitimate interests (Art. 6 para. 1 lit. f) GDPR)

Legitimate interests: Ensuring proper functionality, providing support for website optimization and search engine visibility, efficiently managing and evaluating online advertising campaigns, and assisting with targeted communication with prospects and customers.

 

Web agency

Recipient:  ALPENBLICKDREI Werbeagentur GmbH 

Third country transfer: Does not take place.

Privacy policy: https://www.alpenblickdrei.com/datenschutz/ 

 

Web analysis and optimization

We use procedures on our website to analyze user behavior and measure reach. For this purpose, information about the behaviour, interests or demographic information of visitors is collected to determine whether and where our website needs to be optimized or adapted (e.g. forms on the website, improved placement of buttons or call-to-action buttons, etc.). 

We can also measure the click and scroll behavior of website visitors. Among other things, this helps us to recognize at what time our website, its functions or content are most frequented. 

This data is collected through the use of certain technologies (e.g. cookies). The cookies are stored on users' end devices as part of client-side tracking when they visit our website.

We take precautions to protect the identity of our website visitors. We do not process any clear data of website visitors for the purpose of web analyses and optimization. 

Website visitors get an ID (identification code) when they visit the website so that they can be recognized when they return. The IDs and associated information are stored in user profiles. In addition, the IP addresses of website visitors are anonymized and the storage duration of cookies is reduced. 

Data categories: Usage data (e.g. websites visited, interest in content, access times), demographic characteristics (age, gender), meta and communication data (e.g. device information, anonymized IP addresses, location data), contact data (e.g. e-mail address), content data (e.g. text details)

Purposes of processing: Checking the status of target achievement (success control) of all online activities: Analysis of user behavior on the website (website interaction) for web optimization and reach measurement, checking the utilization of the website, lead evaluation, sales increase, budget control

Legal basis: Consent (Art. 6 para. 1 lit. a) GDPR); legitimate interests (Art. 6 para. 1 lit. f) GDPR )

Legitimate interests: Optimizing the website for better user-friendliness and improved discoverability.

 

Matomo

Recipient: SEO-Küche Internet Marketing GmbH & Co. KG, Fraunhoferstraße 6, 83059 Kolbermoor

Third country transfer: Does not take place.

Privacy policy: https://www.seo-kueche.de/datenschutzrichtlinien/

 

Microsoft Advertising Web Analytics 

Recipient: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA

Third country transfer: Based on the adequacy decision of the European Commission for the country USA 

Privacy policy: privacy.microsoft.com/de-de/privacystatement

 

Google Tag Manager

Recipient: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irland

Third country transfer:  Based on the adequacy decision of the European Commission for the country USA

Privacy policy: policies.google.com/privacy

 

Online marketing 

Search Engine Marketing (advertising in search engines)

We use search engine marketing methods. Search engine marketing includes all measures that are suitable for improving the visibility of our website in the organic or non-organic search results of search engines, increasing our reach and through there increasing traffic (visitor traffic) to our website. We can also use search engine marketing to generate new prospects (leads). The search engine provider sells us advertising space on the search engine results page or on websites of partners of the search engine providers.

The ads can therefore be displayed on various external platforms or websites. The ads are displayed to users in the form of text, display or video ads. 

We create a campaign for search engine advertising via our tracking tool and store various dimensions to be collected by the search engine provider, e.g. user location, device information and target groups (demographic characteristics). This enables us to gain further insights into the interests in our content/products and, if necessary, to recognize trends.

The process is implemented using a cookie or similar technology. When a visitor visits our website or searches for a specific keyword within the search engine used (e.g. Google), a cookie or similar technology is set on the website visitor's end device. This data may include, for example, user locations and device information, which is transmitted to the search engine provider's server. The search engine provider aggregates this data and makes it available to us automatically in the form of a statistical analysis via a dashboard in our account with the search engine provider.

The statistics provide us with information about which of our ads were clicked on, how often and at what prices, and if our marketing measures led to a event (e.g. downloading a PDF or playing a video) or a conversion (e.g. purchase of a product or registration on our website). The evaluation serves to analyze the success of our online activities. Each click on our ad incurs costs, which are then recorded in our tracking tool via a platform or website. The recording is used for budget and success control. We cannot identify individual users on the basis of this information.

Note: 

Website visitor data (e.g. name and e-mail address) can be assigned directly if they are logged into their account with the search engine provider. If assignment via the profile is not desired, the website visitor must log out of the search engine provider before visiting our website.

Data categories: User and interaction data (e.g. websites visited, interest in content, access times), meta and communication data (e.g. device information, anonymized IP addresses), location data if applicable, contact data (e.g. email addresses)

Purposes of processing: Increase in sales and reach, conversion measurement, target group formation, identification of trends for the development of marketing strategies

Legal basis: Consent (Art. 6 para. 1 lit. a) GDPR)

 

Google Double Click

Recipient: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irland

Third country transfer: Based on the adequacy decision of the European Commission for the country USA

Privacy policy: https://policies.google.com/privacy?hl=en-US

 

Google Ads

Recipient: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irland

Third country transfer: Based on the adequacy decision of the European Commission for the country USA

Privacy policy: policies.google.com/privacy

 

Presence on social media

We have a company profile on social networks and career platforms to increase our visibility among potential customers and interested parties and to make our company visible to the public.

Social networks help us to increase our reach and actively promote interaction and communication with users. Social media activity and communication is very important in attracting new customers and employees. Social media and the website can be used to share relevant information about our company, publish events and communicate important short-term announcements and job postings. They also help us to communicate quickly and easily with users.

Social media platform operators create user profiles based on user behavior, for example by listing interests (likes, shares). These are used to adapt advertisements to the interests of target groups. When users are active on social media channels, cookies or other technologies are regularly stored on users' end devices, in some cases regardless of whether they are registered users of the social network.

Insights (statistics)

The data evaluated from the social media platform operators is provided to us in the form of anonymized statistics, which means that it no longer contains any personal data of users. We can use the statistics to see, for example, how often and at what time our social media profile was visited. It is currently not possible for fan page operators to deactivate this function. We therefore have no influence on the extent to which data is processed by social media platforms.

Depending on where the social network is operated, user data may be processed outside the European Union or outside the European Economic Area. This may pose risks to users, as it makes it more difficult for them to enforce their rights.

Data categories:  User names (e.g. surname, first name), contact data (e.g. e-mail address), content data (e.g. text details, photographs, videos), usage and interaction data (e.g. websites visited, interests, likes, shares, access times), meta and communication data (e.g. device information, IP address, location data if applicable)

Purposes of the processing: Increasing reach, awareness-raising activities, rapid networking

Legal basis:  Legitimate interests (Art. 6 para. 1 lit. f) GDPR), consent (Art. 6 para. 1 lit. a) GDPR)

Legitimate interests: Interaction and communication on social media presence, profit increase, insights about target groups

 

LinkedIn

Recipient: LinkedIn Corporation, 1000 West Maude Avenue, Sunnyvale, CA 94085, USA

Third country transfer: Based on the adequacy decision of the European Commission for the country USA

Privacy policy: de.linkedin.com/legal/privacy-policy?

 

YouTube

Recipient: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irland

Third country transfer: Based on the adequacy decision of the European Commission for the country USA

Privacy policy:  https://policies.google.com/privacy?hl=en-US

 

Xing

Recipient: New Work SE, Dammtorstraße 30, 20354 Hamburg, Deutschland

Third country transfer: Does not take place.

Privacy policy: https://privacy.xing.com/de/datenschutzerklaerung

 

Newsletter and mass communication (with tracking)

On our online offering, users have the option of subscribing to our newsletter or to notifications on various channels (hereinafter referred to overall as ‘newsletters’). We only send newsletters to data subjects who have agreed to receive the newsletter, and within the framework of statutory provisions. We use a select service provider to send out our newsletter.

An email address must be provided to subscribe to our newsletter. If applicable, we collect extra data, such as your name to include a personal greeting in our newsletter.

Our newsletter is only sent after the ‘double opt-in procedure’ has been fully completed. If visitors to our online offering decide to receive our newsletter, they will receive a confirmation email that serves to prevent the fraudulent input of wrong email addresses and preclude a single, possibly accidental, click from causing the newsletter to be sent. The subscription to our newsletter can be ended at any time with future effect. An unsubscription (opt-out) link is given at the end of every newsletter.

In addition, we are obliged to provide proof that our subscribers actually want to receive the newsletter. To this end, we collect and store their IP address, along with the time of subscription and unsub-scription. 

Newsletter Tracking

Our newsletters are designed so that we can obtain findings about improvements, target groups or the reading behaviour of our subscribers. We are able to do this thanks to a 'web beacon’ or tracking pixel that reacts to interactions with the newsletter, such as looking at whether links are clicked on, whether the newsletter is opened at all, or at what time the newsletter is read. For technical reasons, we can associate this information with individual subscribers. 

Data categories: Master data (e.g. name, address), contact data (e.g. e-mail address, telephone number), meta and communication data (e.g. device information, IP address), usage data (e.g. interests, access times)

Purposes of processing: Marketing, increase in customer loyalty and new customer acquisition, analysis and evaluation of the success of the campaign

Legal basis: Consent (Art. 6 para. 1 lit. a) GDPR)

 

Brevo

Recipient:  Brevo GmbH, Köpenicker Str. 126, 10179 Berlin

Third country transfer: Does not take place.

Privacy policy:  https://www.brevo.com/de/legal/privacypolicy/

 

Advertising communication

We also use data provided to us for advertising purposes, for example, in the context of an order or commissioning of a service particularly to provide information on various channels about new products from us or in our portfolio of offerings. However, promotional contact from our side is only undertaken within the framework of the legal requirements, and once consent has been granted, insofar this is necessary. If the data subjects of our advertising do not want to receive it, they can inform us of this at any time with future effect. We are happy to acquiesce to their request. The unsubscribe button in our email can be used for this purpose.  Only those users who have not revoked to receiving our advertising in advance will receive it. 

We have commissioned a service provider to send out the advertising. This service provider acts exclusively on our instructions. The data will not be processed for other purposes. 

Data categories: Master data (e.g. name, address), contact data (e.g. e-mail address, telephone number if applicable) 

Purposes of the processing: Direct marketing 

Legal basis:  Consent (Art. 6 para. 1 lit. a) GDPR), legitimate interests (Art. 6 para. 1 lit. f) GDPR)

Legitimate interests: Customer loyalty and acquisition of new contacts or contractual partners, information about similar goods and services

 

Contact us

On our online offering, we offer the option of contacting us directly or requesting information via various contact options. We use a management tool/ our CRM-System for these enquiries so that we always have an overview of contact that has been made with us.

In the event of contact being made, we process the data of the person making the enquiry to the extent necessary for answering or handling their enquiry. Which data is processed depends on the way in which contact is made with us.

Data categories: Master data (e.g. name, address), contact data (e.g. email address, telephone number), content data (e.g. text input, photographs, videos), usage data (e.g. interests, access times), meta and communication data (e.g. device information, IP address).

Purposes of processing: Processing requests

Legal basis: Consent (Art. 6 para. 1 lit. a) GDPR), fulfillment or initiation of a contract (Art. 6 para. 1 lit. b) GDPR)

 

Microsoft Dynamics

Recipient: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA 

Third country transfer: Based on the adequacy decision of the European Commission for the country USA

Privacy policy: privacy.microsoft.com/de-de/privacystatement/

 

Downloads (whitepaper, product information)

On our online offering, visitors have the opportunity to download documents, so that we can provide them with recent or relevant information. In some cases, our visitors can download pdf files without being recorded by our system. No tracking or statistical analysis takes place.

In some cases, we collect personal data including IP-address via a form before the download and make the provision of our free services dependent on a subscription to our newsletter. In this case, consent is obtained via a double-opt-in procedure both for the processing of user data for the down-load and separately for the subscription to download-related mailings, which are freely withdrawable separately.

The download then takes place via a download link, which we provide to our users by e-mail.

Data categories: Meta and communication data (e.g. device information, IP addresses), usage data (e.g. access time)

Purposes of processing: Marketing, acquiring new customers, increasing sales

Legal basis: Consent (Art. 6 para. 1 lit. a) GDPR)

Online meetings, webinars, online events

We make use of the opportunity to hold online conferences, meetings and/or webinars. To do so, we use offerings provided by other carefully selected providers. When actively using offerings of this nature, data regarding the participants in the communication is processed and stored on the servers of the third-party services used, provided this data is necessary for the communication process. When selecting providers, we ensure that communication via the selected services is end-to-end encrypted. 

Data categories: Master data (e.g. surname, first name), contact data (e.g. e-mail address), content data (e.g. text input), meta and communication data (e.g. device information, IP addresses)

Purposes of processing: Processing of enquiries, increasing efficiency, promoting cross-company and cross-location cooperation

Legal basis: Consent (Art. 6 para. 1 lit. a) GDPR)

 

Microsoft Teams 

Recipient: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA

Third country transfer: Based on the adequacy decision of the European Commission for the country USA

Privacy policy: privacy.microsoft.com/de-de/privacystatement 

Further mandatory information on data processing 

Data transfer

We transfer the personal data of website visitors for internal purposes (e.g. for internal administration or to the HR department in order to comply with legal or contractual obligations). Internal data transfer or the disclosure of data only occurs to the extent necessary, under the pertinent data protection provisions.

It may be necessary for us to disclose personal data in order to perform contracts or to fulfill a legal obligation. If we are not receiving the personal data, it may not be possible to conclude the contract with the data subject. 

If your data is processed outside the EU/EEA, in third countries (e.g. USA), we ensure that the legal requirements of Art. 44 et seq. GDPR are fulfilled. We take additional measures to ensure the highest possible level of protection for the personal data of data subjects. The guarantee applicable to the transfer to third countries is specified in our privacy policy under the respective recipients. 

Data processing 

Recipients of personal data may act as data processors. We have concluded "data processing agreements" with them in accordance with Art. 28 para. 3 GDPR. This means that the processors may only process your personal data on explicit instruction. Processors take adequate technical and organizational measures to process your data securely and in accordance with our instructions.

 

Storage period

In principle, we store the data of visitors to our online offering for as long as needed to render our service or to the extent that the European body issuing directives and regulations or another legislator stipulates in laws and regulations to which we are subject. In all other cases, we delete personal data once the purpose has been fulfilled, with the exception of data that we need to continue to store to comply with legal obligations (e.g. if retention periods under tax law and trade law require us to keep documents such as contracts and invoices for a certain period of time).

 

Automated decision-making (including profiling)

We do not use automated decision-making or profiling in accordance with Art. 22 GDPR.

Legal bases

The relevant legal bases are primarily arise from the GDPR. They are supplemented by national laws of the member states and can, if applicable, be applied alongside or in addition to the GDPR. 

Consent: Art. 6 para.1 lit. a) GDPR serves as the legal basis for data processing activities for which we have obtained consent for a specific processing purpose. 

Performance of a contract: Article 6 (1) (b) serves as the legal basis for processing re-quired to perform a contract to which the data subject is a contractual party or for taking steps prior to entering into a contract, at the request of the data subject.

Legal obligation: Article 6 (1) (c) GDPR is the legal basis for processing that is required to comply with a legal obligation.

Vital interests: Article 6 (1) (d) GDPR serves as the legal basis if the processing is necessary to protect the vital interests of the data subject or another natural person.

Public interest: Article 6 (1) (e) GDPR serves as the legal basis for processing that is necessary to perform a task in the public interest or to exercise public force that is transferred to the controller.

Legitimate interest: Article 6 (1) (f) GDPR serves as the legal basis for processing that is necessary to protect the legitimate interests of the controller or a third party, provided this is not out-weighed by the interests or fundamental rights and funda-mental freedoms of the data subject that require personal da-ta to be protected, particularly if the data subject is a child.

 

Rights of data subjects

Right to information: Pursuant to Art. 15 GDPR, data subjects have the right to request confirmation as to whether we are processing data concerning them. They can request information about this data as well as the further information listed in Art. 15 para. 1 GDPR and a copy of their data.

Right to rectification: Pursuant to article 16 GDPR, data subjects have the right to request that data relating to them, and that we process, be rectified or completed.

Right to erasure: Pursuant to article 17 GDPR, data subjects have the right to request that data relating to them be erased without delay. Alternatively, they can request that we restrict the processing of their data, pursuant to article 18 GDPR.

Right to data portability: Pursuant to article 20 GDPR, data subjects have the right to request that data made available to us by them be provided and transferred to another controller.

Right to lodge a complaint: In addition, data subjects have the right to lodge a complaint with the supervisory authority responsible for them, under ar-ticle 77 GDPR.

Right to object: If personal data is processed on the basis of legitimate inter-ests pursuant to article 6 (1) (1) (f) GDPR, under article 21 GDPR data subjects have the right to object to the processing of their personal data, provided there are reasons for this that arise from their particular situation or the objection relates to direct advertising. In the latter case, data subjects have a general right to object that is to be put into effect by us without a particular situation being stated.

 

Withdrawal of consent

Some data processing procedures can only be carried out with the express consent of the data subject. You have the option to withdraw any consent you have already given. All you need to do is send an email to: datenschutz@rollout-solutions.de. The consent of data processing operations on our online offer can be directly adjusted in our Consent Manager-Tool.

The legality of the data processing carried out up to the point of withdrawal shall remain unaffected by the withdrawal.

External links

Our website contains links to the online offerings of other providers. We would like to point out that we have no influence on the content of the linked websites and the compliance with data protection regulations by their providers.

Amendments

We reserve the right to amend this information on data protection, in compliance with the applicable data protection provisions, if changes are made to our online offering so that it complies with the legal requirements.

 

This privacy policy was drawn by 
DDSK GmbH
www.ddsk.de