fortiss data privacy policy

Data Protection Policy

Responsible party with respect to data protection policies, particularly in terms of the EU General Data Protection Regulation (GDPR), is:

fortiss GmbH
State Research Institute of the Free State of Bavaria for software-intensive systems
Guerickestrasse 25
80805 Munich
Germany
Phone: +49 89 3603522 0
Fax: +49 89 3603522 50
E-mail: info@fortiss.org

 

Your rights

You can exercise the following rights at any time using the contact details provided for our data protection officer:

  • Information about your data stored by us and its processing (Art. 15 GDPR),
  • Correction of incorrect personal data (Art. 16 GDPR),
  • Erasure of your data stored by us (Art. 17 GDPR),
  • Restriction of data processing if we are not yet allowed to delete your data due to legal obligations (Art. 18 GDPR)
  • Objection to the processing of your data by us (Art. 21 GDPR) and
  • data portability if you have consented to the data processing or have concluded a contract with us (Art. 20 GDPR).

If you have given us your consent, you can revoke it at any time with effect for the future. You can lodge a complaint with a supervisory authority at any time, e.g. with the competent supervisory authority in the federal state of your place of residence or with the authority responsible for us as the controller.

A list of supervisory authorities (for the non-public sector) with addresses can be found at: https://www.bfdi.bund.de/DE/Service/Anschriften/Laender/Laender-node.html.


The Bavarian State Office for Data Protection Supervision is responsible for fortiss GmbH:

Promenade 18
91522 Ansbach
Postal address:
P.O. Box 1349,
91504 Ansbach
Telephone: 0981/180093-0
E-mail: poststelle@lda.bayern.de

Collection of general information when visiting our website

Nature and purpose of processing:

When you access our website, i.e. if you do not register or otherwise transmit information, information of a general nature is automatically collected. This information (server log files) includes, for example, the type of web browser, the operating system used, the domain name of your internet service provider, your IP address and similar.

They are processed for the following purposes in particular:

  • Ensuring a smooth connection to the website,
  • Ensuring the smooth use of our website,
  • Analysing system security and stability and
  • To optimise our website.

We do not use your data to draw conclusions about your person. Information of this kind may be statistically evaluated by us in anonymised form in order to optimise our website and the technology behind it.

Legal basis and legitimate interest:

Processing is carried out in accordance with Art. 6 para. 1 lit. f GDPR on the basis of our legitimate interest in improving the stability and functionality of our website.

Recipient:

The recipient of the data is STRATO AG, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany, which acts as a processor for the operation of our website.

Third country transfer:

Please refer to the lists of the individual display, tracking, remarketing and web analysis providers for more information.

Storage period:

The data is deleted as soon as it is no longer required for the purpose for which it was collected. This is generally the case for the data used to provide the website when the respective session has ended.

Provision prescribed or required:

The provision of the aforementioned personal data is not required by law or contract. However, without this data, the service and functionality of our website cannot be guaranteed. In addition, individual services may not be available or may be restricted.

Cookies

Like many other websites, we also use so-called "cookies". Cookies are small text files that are stored on your end device (laptop, tablet, smartphone, etc.) when you visit our website.

You can delete individual cookies or the entire cookie inventory. You will also receive information and instructions on how to delete these cookies or block their storage in advance. Depending on your browser provider, you will find the necessary information under the following links:

Storage duration and cookies used:

If you allow us to use cookies through your browser settings or consent, the following cookies may be used on our websites:

www.fortiss.org

Name
Purpose
Expiry
Type
Provider
cookieConsent
Saves your consent to the use of cookies.                               
1 Year
HTML
Website
m2c_accepted_hosts
Saves your consent to the integration of external content           
1 Year
HTML
Webseite
_pk_id
Used to store a few details about the user such as the univque visitor ID.
13 Months
HTML
Matomo
_pk_ref
Used to store the information of the user's website of origin.       
6 Months
HTML
Matomo
_pk_ses
Short-term cookie to store temporary data of the visit              
30 Minutes
HTML
Matomo
_pk_cvar
Short-term cookie to store temporary data of the visit              
30 Minutes
HTML
Matomo
_pk_hsr
Short-term cookie to store temporary data of the visit              
30 Minutes
HTML
Matomo


recruitment.fortiss.org

Name
Purpose
Expiry
Type
Provider
cookieconsent_status   
Saves your consent to the use of cookies.                                       
1 Year
HTML
REXX
_pk_ses.632.6e9a       
Short-term cookie to store temporary data of the visit.                                                                                    
30 Minutes
 
REXX
_pk_id.632.6e9a         
Used to store a few details about the user such as the unique visitor ID.                                       
13 Months
 
REXX
sid
Saves an anonymous visitor ID to assign requests sot the same session.                                                                           
60 Minutes
HTML
REXX

 

Technically necessary cookies

Type and purpose of processing:

We use cookies to make our website more user-friendly. Some elements of our website require that the accessing browser can be identified even after a page change.

The purpose of using technically necessary cookies is to simplify the use of websites for users. Some functions of our website cannot be offered without the use of cookies. For these, it is necessary for the browser to be recognised even after a page change.

We require cookies for the following applications:

  • Consent to the use of cookies
  • Processing of applications
  • Integration of YouTube videos

Legal basis and legitimate interest:

Processing is carried out in accordance with Art. 6 para. 1 lit. f GDPR on the basis of our legitimate interest in improving the stability and functionality of our website.

Recipient:

The recipient of the data is rexx Systems GmbH, Süderstraße 75-79, 20097 Hamburg, which acts as a processor for the operation of our career website.

Provision prescribed or required:

The provision of the aforementioned personal data is neither legally nor contractually required. However, without this data, the service and functionality of our website cannot be guaranteed. In addition, individual services may not be available or may be restricted.

Objection

Please read the information on your right to object under Art. 21 GDPR below.

 

Cookies that are not technically necessary

We also use cookies in order to better customise the offer on our website to the interests of our visitors or to generally improve it on the basis of statistical analyses.

Please refer to the information below on the display, tracking, remarketing and web analysis technologies used to find out which providers set cookies.

Legal basis:

The legal basis for this processing is your consent in each case, Art. 6 para. 1 lit. a GDPR.

Recipients:

For further recipients, please refer to the information below on the display, tracking, remarketing and web analysis technologies used.

Third country transfer:

For information on this, please refer to the listings of the individual display, tracking, remarketing and web analysis providers.

Provision prescribed or required:

Of course, you can also view our website without cookies. Web browsers are regularly set to accept cookies. In general, you can deactivate the use of cookies at any time via your browser settings (see Revocation of consent).

Please note that individual functions of our website may not work if you have deactivated the use of cookies.

Revocation of consent:

You can withdraw your consent at any time via our cookie consent tool.

Profiling:

To what extent we analyse the behaviour of website visitors with pseudonymised user profiles, please refer to the information below on the display, tracking, remarketing and web analysis technologies used.

Applications via our website

Type and purpose of processing:

Personal data that we need exclusively to process your application will only be stored if you provide it to us voluntarily as part of your application. Your personal information and data will be collected and stored with the utmost care and integrity and will only be used for the intended purpose. The provisions of the Federal Data Protection Act are observed. We only collect the data that is necessary in the course of your application to fortiss GmbH. However, other technically necessary data, such as the IP address, cookies, etc., are required for the use of the service and the functionality of the website and are stored by the data processor.

You agree to the processing and transmission of your data exclusively for the application process.

Legal basis:

The data entered during registration is processed on the basis of the user's consent (Art. 6 para. 1 lit. a GDPR).

Recipient:

The recipient of the data is rexx Systems GmbH, Süderstraße 75-79, 20097 Hamburg, which acts as a processor for the operation of our career website.

Storage period:

The data is deleted as soon as it is no longer required for the purpose for which it was collected. Further information on data protection at rexx Systems GmbH can be found in the provider's privacy policy at: www.rexx-systems.com/datenschutz/

Provision prescribed or required:

The provision of your personal data is voluntary, solely on the basis of your consent. Without the provision of your personal data, we cannot grant you access to the content we offer.

Registration on our website

Type and purpose of processing:

To register for an event on our website, we require some personal data (salutation, title, first name, surname, company (optional), e-mail address), which is transmitted to us via an input mask. Your registration is required for the provision of certain content and services on our website. For this purpose, we use the CRM software from Salesforce, Inc. Salesforce Tower, 415 Mission Street, 3rd Floor, San Francisco, CA 94105, United States. This software instance is operated in a Telekom data centre in Germany.

Legal basis:

The data entered during registration is processed on the basis of the user's consent (Art. 6 para. 1 lit. a GDPR).

Recipient:

The recipient of the data is curexus GmbH, Nordostpark 3, D - 90411 Nuremberg, in order to carry out maintenance and support for the Saleforce software instance as a processor.

Storage period:

Data will only be processed in this context for as long as the corresponding consent is available.

Provision prescribed or required:

The provision of your personal data is voluntary, solely on the basis of your consent. Without the provision of your personal data, we cannot grant you access to the content we offer.

Newsletter

Type and purpose of processing:

For the delivery of our newsletter, we collect personal data that is transmitted to us via an input mask. For this purpose, we use the CRM software of Salesforce, Inc. Salesforce Tower, 415 Mission Street, 3rd Floor, San Francisco, CA 94105, United States, whose software instance is operated in a Telekom data centre in Germany in accordance with the Data Processing Agreement.

We require a valid e-mail address for effective registration. You will then receive a confirmation of registration.

Legal basis:

On the basis of your expressly granted consent (Art. 6 para. 1 lit. a GDPR), we will regularly send you our newsletter or comparable information by e-mail to the e-mail address you have provided.

You can revoke your consent to the storage of your personal data and its use for sending the newsletter at any time with effect for the future. There is a corresponding link in every newsletter. You can also unsubscribe directly on this website at any time or inform us of your cancellation using the contact option provided at the end of this data protection notice.

Recipient:

The recipient of the data is curexus GmbH, Nordostpark 3, D - 90411 Nuremberg, in order to carry out maintenance and support for the Saleforce software instance as a processor.

Storage period:

The data will only be processed in this context for as long as the corresponding consent is available. After that, it will be deleted.

Provision prescribed or required:

The provision of your personal data is voluntary, solely on the basis of your consent. Unfortunately, we cannot send you our newsletter without your consent.

Revocation of consent:

You can revoke your consent to the storage of your personal data and its use for sending the newsletter at any time with effect for the future. You can unsubscribe via the link contained in every e-mail or by contacting the data protection officer listed below or the person responsible for data protection.

Use of Matomo

If you have given your consent, Matomo (formerly Piwik), an open source software for the statistical analysis of visitor access, is used on this website. The provider of the Matomo software is InnoCraft Ltd, 150 Willis St, 6011 Wellington, New Zealand.

Matomo places a cookie (a text file) on your end device with which your browser can be recognised. If subpages of our website are accessed, the following information is stored

  • the user's IP address, shortened by the last two bytes (anonymised)
  • the subpage accessed and the time of access
  • the page from which the user came to our website (referrer)
  • which browser with which plugins, which operating system and which screen resolution is used
  • the time spent on the website
  • the pages that are accessed from the accessed subpage

Matomo is used for the purpose of improving the quality of our website and its content. This enables us to find out how the website is used and to constantly optimise our offering.

By anonymising the IP address by six digits, we take into account the website visitor's interest in the protection of personal data. The data is not used to personally identify the user of the website and is not merged with other data. The information generated by the cookie about your use of this website is not passed on to third parties.

Revocation of consent:

You can revoke your consent to the storage and analysis of your data by Matomo at any time via the link below. An opt-out cookie will then be stored on your device, which is valid for two years. As a result, Matomo will not collect any session data. Please note, however, that the opt-out cookie will be deleted if you delete all cookies.

You can find more information on the privacy settings of the Matomo software at the following link: https://matomo.org/docs/privacy/.

You can also prevent the use of cookies by setting your browser software accordingly; however, we would like to point out that in this case you may not be able to use all functions of this website to their full extent.

Embedded YouTube videos

We embed YouTube videos on our website. The operator of the corresponding plugins is YouTube, LLC, 901 Cherry Ave, San Bruno, CA 94066, USA (hereinafter referred to as "YouTube"). YouTube, LLC is a subsidiary of Google LLC, 1600 Amphitheatre Pkwy, Mountain View, CA 94043, USA (hereinafter referred to as "Google"). When you visit a page with the YouTube plugin, a connection to YouTube servers is established. YouTube is informed which pages you visit. If you are logged into your YouTube account, YouTube can assign your surfing behaviour to you personally. You can prevent this by logging out of your YouTube account beforehand.

If a YouTube video is started, the provider uses cookies that collect information about user behaviour.

Further information on the purpose and scope of data collection and its processing by YouTube can be found in the provider's privacy policy, where you will also find further information on your rights in this regard and setting options to protect your privacy (https://policies.google.com/privacy).

Revocation of consent:

The provider does not currently offer the option of simply opting out or blocking data transmission. If you wish to prevent your activities on our website from being tracked, please revoke your consent for the corresponding cookie category or all technically unnecessary cookies and data transmissions in the cookie consent tool. In this case, however, you may not be able to use our website or may only be able to use it to a limited extent.

SSL encryption

To protect the security of your data during transmission, we use state-of-the-art encryption methods (e.g. SSL) via HTTPS.

Information about your right to object in accordance with Art. 21 GDPR

Right to object on a case-by-case basis

You have the right to object, on grounds relating to your particular situation, at any time to processing of personal data concerning you which is based on point (f) of Art. 6 (1) GDPR (data processing on the basis of a balancing of interests); this also applies to profiling based on this provision within the meaning of Art. 4 No. 4 GDPR.

If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.

Recipient of an objection

Data protection officer of fortiss GmbH
c/o activeMind AG
Potsdamer Str. 3, 80802 Munich, Germany
Phone: +49 (0)89 - 91 92 94 900
datenschutzbeauftragter@fortiss.org

Changes to our privacy policy

We reserve the right to amend this privacy policy so that it always complies with current legal requirements or to implement changes to our services in the privacy policy, e.g. when introducing new services. The new privacy policy will then apply to your next visit.

Questions for the data protection officer

If you have any questions about data protection, please send us an email or contact the person responsible for data protection in our organisation directly:

Data Protection Officer of fortiss GmbH
c/o activeMind AG
Potsdamer Str. 3, 80802 Munich
Phone: +49 (0)89 - 91 92 94 900
datenschutzbeauftragter@fortiss.org

The privacy policy was created with the help of activeMind AG, the experts for external data protection officers (version #2020-09-30).