Privacy Policy - What are Complymarket's privacy policy.

1. General information and principles of data processing

  1. We are pleased that you are visiting our website. The protection of your privacy and the protection of your personal data when using our website is an important concern for us.

  2. According to Art. 4 No. 1 GDPR, personal data is any information relating to an identified or identifiable natural person. This includes, for example, information such as your first and last name, your address, your telephone number, your e-mail address, but also your IP address.

  3. Data for which no reference to your person can be established, such as anonymized information, is not personal data. Processing (e.g. collection, storage, retrieval, querying, use, transmission, deletion or destruction) according to Art. 4 No. 2 GDPR always requires your consent or another legal basis. Processed personal data must be deleted as soon as the purpose of the processing has been achieved and there are no longer any legally prescribed retention obligations to fulfil.

  4. Here you can find information about the handling of your personal data when visiting our website. To provide the functions and services of our website, it is necessary that we collect personal data about you.

  5. Below you will also find information on the type and scope of the respective data processing, the purpose and the corresponding legal basis as well as the respective storage period.

  6. This privacy policy only applies to this website. It does not apply to third-party websites to which we merely refer by means of a hyperlink. We cannot accept any responsibility for the confidential handling of your personal data on these third-party websites, as we have no influence on whether they comply with the statutory data protection provisions. Please inform yourself about the handling of your personal data by third parties directly on their websites.

2. Responsible entity

Responsible for the processing of personal data on this website is (see imprint):

ComplyMarket UG (haftungsbeschränkt) Tal 44

80331, Munich Germany

+491637819457

info@complymarket.com

3. Data Protection Officer

You can also contact our data protection officer at any time with questions about data protection:

ComplyMarket UG (haftungsbeschränkt)

Dr. Mohamed Kassem

Tal 44

80331, Munich

Germany

Phone: +491637819457

E-mail: info@complymarket.com

4. Provision and use of the website / server log files

Type and scope of data processing

If you use this website without transmitting data to us in any other way (e.g. by registering or using the contact form), we collect technically necessary data in the form of log data (so-called log files), which are automatically transmitted to our server by your device, including:

  • IP address
  • Date and time of the request
  • URL of the retrieved subpage
  • URL of the page from which the forwarding to our page took place (so-called referrer URL)
  • Access status/HTTP status code
  • Browser software type, language and version
  • Operating system

Purpose and legal basis of the data processing

This processing is technically necessary in order to display our website to you. We also use the data to ensure the security and stability of our website.

The legal basis for the processing is Art. 6 para. 1 lit. f) GDPR. The processing of the aforementioned data is necessary for the provision of our website and thus serves to protect a legitimate interest of our company.

c) Storage period

As soon as the aforementioned personal data is no longer required to display the website, it is deleted. This is the case at the latest seven days after visiting our website. The collection of data for the provision of the website and the storage of the data in log files is necessary for the operation of the website. Consequently, there is no possibility for the user to object to this aspect. Further storage may take place in individual cases if this is required by law.

5. Data collection for the implementation of pre-contractual measures and for the fulfillment of the contract with you

Type and scope of data processing

In the pre-contractual period and upon conclusion of the contract, we collect personal data about you. This concerns, for example, first and last name, address, e-mail address, telephone number or bank details.

Purpose and legal basis of the data processing

We collect and process this data exclusively for the purpose of fulfilling the contract with you or fulfilling pre-contractual obligations.

The legal basis for this is Art. 6 para. 1 lit b) GDPR. If you have also given your consent, the additional legal basis is Art. 6 para. 1 lit. a) GDPR.

Storage period

The data is deleted as soon as it is no longer required for the purpose of its processing. In addition, there may be legal obligations to retain data for up to 10 years, for example, obligations to retain data under commercial or tax law in accordance with the German Commercial Code (HGB) or the German Fiscal Code (AO). If such retention obligations exist, we will block or delete your data upon expiration of these legal retention periods.

6. Recruiting Privacy Statement

ComplyMarket is dedicated to safeguarding the privacy of all job applicants, and we have formulated a privacy statement to specify the processing and use of your employment application data.

The job listing you applied to specifies the ComplyMarket company responsible for the processing of your personal information. The personal data we process includes the information you provided as part of the application process, such as your name, contact information, qualifications, references, documentation, and login credentials. We may also obtain personal data from publicly accessible sources, including career networks.

Your personal data will be processed in compliance with legal requirements and will serve the purpose of personnel recruiting. The primary legal basis for processing is Art. 6, 1 b) GDPR, in conjunction with Art. 88, Para. 1 GDPR, and Section 26 Para. 1 BDSG. Additionally, we may utilize statistical techniques together with data from internal sources to enhance our recruitment processes, optimize performance management, develop HR strategies, plan compensation, improve organizational culture, drive innovation, and manage HR operations. The primary legal basis for this is Art. 6, 1 f) GDPR.

In cases where special categories of personal data, such as information about severe disabilities, are processed, we do so on the basis of Art. 9, Para. 2 b) GDPR in conjunction with Section 26 Para. 3 BDSG. To comply with legal requirements, we may use data analytics methods to identify the disability classification.

Your personal data will be accessible to the managers of the specialist department responsible for filling the vacancy, the personnel selection employees, and the HR division in charge. Data analysts may also process your data for statistical purposes. We may also use service providers to fulfill our contractual and legal obligations and for data processing.

Your application data will remain active throughout the selection process. If your application is unsuccessful, we will delete your personal information, such as your name and contact information, three months after the selection process is over. The remaining portions of your application will be stored for statistical purposes for an additional period of 12 months and then deleted.

If you are successful in your application, we will further process your personal data for the purposes of the employment relationship. As an applicant, you have the right to request information about the personal data stored on you, have any inaccurate personal data corrected, request deletion of personal data, restrict processing of personal data, request that the data you provided electronically be issued to you, object to data processing, and file a complaint with the Data Protection Officer or a supervisory authority if you believe we are in breach of the General Data Protection Regulation or other laws through the processing of personal data relating to you.

We require all applicants to provide accurate and truthful information. Providing false information can result in termination of any employment relationship.

If you have any questions or concerns regarding the processing of your personal data, please contact our Data Protection Officer at info@ComplyMarket.com.

7. Online Store

On our website there is an online store which can be used for product orders.

Type and scope of data processing

Our data collection is limited to the following data:

  • First and last name
  • Address
  • Phone number
  • E-mail address
  • Payment data (e.g. IBAN, EC card/credit card number)
  • Product name
  • If applicable, content of a personal message
  • List of products, components and materials
  • Compliance evidence

In addition, we collect any other personal data provided by you in the course of using the order form.

b) Purpose and legal basis of the data processing

The purpose of data processing is the proper handling of your order in our online store.

The legal basis for this is Art. 6 para. 1 lit. b) GDPR. The processing of the data serves the fulfillment of a contract or is necessary for the implementation of a pre-contractual measure, which takes place upon your request.

c) Storage period

The data will be deleted as soon as they are no longer needed to achieve the purpose of the processing.

In addition, there may be legal storage obligations of up to 10 years, for example, storage obligations under commercial or tax law in accordance with the German Commercial Code (HGB) or the German Fiscal Code (AO). If such retention obligations exist, we will block or delete your order data upon expiration of these retention periods.

8. Compliance evidence

Type and scope of data processing

On our website under https://complymarket.com/ you can send us the compliance data of your articles.

Purpose and legal basis of the data processing

The legal basis for this is Art. 6 para. 1 lit. b) GDPR. The processing of the data serves the fulfillment of a contract or is necessary for the implementation of a pre-contractual measure, which takes place upon your request.

Storage period

The data you provide will be stored by us for as long as is necessary to process your order and then deleted. Legal retention periods of up to 10 years (e.g. according to the German Commercial Code or Fiscal Code) remain unaffected.

9. Registration option

Type and scope of data processing

On our website you can register for a customer account with our online store. When you register, we collect and store the data that you enter in the registration form under [https://complymarket.com/register (e.g. first name, last name, address, date of birth, e-mail address, telephone number). After registration, you are free to change the personal data provided during registration at any time or to have your customer account deleted.

Purpose and legal basis of the data processing

By registering, you can save your delivery and payment details in our online store, so that you do not have to enter them again for future orders. [Please check description of content / purpose of the customer account and add if necessary].

The legal basis for the processing is your consent according to Art. 6 para. 1 lit. a) GDPR. If your registration serves the preparation of a contract conclusion, Art. 6 para. 1 lit. b) GDPR is an additional legal basis.

Storage period

The data collected during registration will be stored by us for as long as you are registered on our website and will then be deleted. Legal retention periods of up to 10 years (e.g. according to the German Commercial Code or the German Fiscal Code) remain unaffected.

10. Contact form

Type and scope of data processing

On our website, you can contact us via a form provided. During the process of sending your request via the contact form, reference is made to this data protection declaration in order to obtain your consent.

If you make use of the contact form under https://complymarket.com/contact-us, the following personal data of you can be processed:

  • Customer number
  • Title
  • First name
  • Last name
  • Title
  • Address
  • Postal code
  • Location
  • Country
  • E-mail address
  • Phone number
  • Subject
  • Message content

When using the contact form, your personal data will not be passed on to third parties.

Purpose and legal basis of the data processing

The purpose of processing your contact information is to respond to your inquiry.

The legal basis for the processing is your consent according to Art. 6 para. 1 lit. a) GDPR, which you can revoke at any time for the future.

Storage period

The data you enter in the contact form will remain with us until you request us to delete it, revoke your consent to store it, or the purpose for storing the data no longer applies (e.g. after we have completed processing your request).

Mandatory legal provisions - in particular retention periods according to the German Commercial Code (HGB) or the German Fiscal Code (AO) - remain unaffected.

11. Contact options by e-mail

Type and scope of data processing

  • You can contact us by e-mail. Our data collection is limited to the e-mail address of the e-mail account you use to contact us, the metadata (time stamp, additional recipients) and the personal data you provide as you wish when contacting us.
  • Please note that e-mails are usually sent unencrypted and thus access of a third party can not be excluded. You can also contact us by mail at any time.

Purpose and legal basis of the data processing

The purpose of the data processing is responding to your request. The legal basis for this is Art. 6 para. 1 lit. f) GDPR. We have a legitimate interest in processing the above-mentioned personal data to handle your request.

Storage period

The duration of the storage of the above data depends on the background of your contact. Your personal data will be deleted regularly if the purpose of the communication no longer applies and storage is no longer required due to legal retention obligations. This may be the case if we have completed processing your request.

12. Application possibility

Type and scope of data processing

You can apply to us by e-mail. When you apply, we collect and store the data that you send us by e-mail (see also No. 10 of this privacy policy).

Purpose and legal basis of the data processing

We use your data only for the purpose of processing your application. Your data will not be passed on to third parties. The legal basis for the processing is Art. 88 para. 1 GDPR in conjunction with § 26 para. 1 of the German Data Protection Act (BDSG). If, in the event of a rejection, the legal basis is Art. 6 para. 1 lit. a) GDPR, if you give us permission to continue to store your data so that we can return to your application in the future.

Storage period

If we are unable to offer you a position, we will store your data for a maximum of six months after the end of the application process, taking into account § 61b para. 1 of the German Labour Courts Act (ArbGG) in conjunction with § 15 of the German General Act on Equal Treatment (AGG). The start of the period is the receipt of the rejection letter.

If you have given us consent to include you in our applicant pool, we will store your data for a maximum of two years.

Data transfer

Your data will only be disclosed to the departments involved in the decision-making process (responsible HR or specialist departments, management).

In addition, we may be obliged by law, administrative or court order to disclose your data to public authorities (e.g. public prosecutor's office, police, supervisory authorities, tax office, social security institutions, etc.).

Other data recipients may be those entities for which you have given us your consent to transfer data.

13. Newsletter

Type and scope of data processing

On our website, you can subscribe to a free regular e-mail newsletter. In order to send you the newsletter, we require your e-mail address.

In connection with sending the newsletter, your data is passed on to our newsletter service provider. Any further disclosure to third parties does not take place.

We use the so-called double opt-in procedure. This means that we will only send you an e-mail newsletter if you have expressly confirmed that you consent to the sending of the newsletter. For this purpose, we will send you a confirmation e-mail in which you will be asked to confirm that you would like to receive future newsletters from us by clicking on a corresponding link.

This serves to ensure that only you, as the owner of the specified e-mail address, can subscribe to the newsletter. Your confirmation must be made promptly after receipt of the confirmation email, otherwise your newsletter registration will be automatically deleted from our database.

When you subscribe to the newsletter, we collect and store the data you enter in the newsletter form (e.g. first name, last name, e-mail address).

When you register for the newsletter, we also store your IP address assigned by the Internet service provider (ISP) as well as the date and time of registration in order to be able to trace any possible misuse of your e-mail address at a later date. For the confirmation e-mail sent for control purposes (double opt-in), we also store the date and time of the click on the confirmation link and the IP address assigned by the Internet service provider (ISP).

Purpose and legal basis of the data processing

The data collected by us when you register for the newsletter will be used exclusively for the purpose of addressing you in an advertising manner by way of the newsletter.

The processing of your e-mail address for sending the newsletter is based, in accordance with Art. 6 para. 1 lit. a) GDPR and § 7 para. 2 No. 3 of the German Act against Unfair Competition (UWG), on the declaration of consent that you have given voluntarily and that can be revoked at any time with effect for the future.

In addition, the processing according to Art. 6 para. 1 lit. f) GDPR is based on our legitimate interest to document the proof of the required consent.

Storage period

Your e-mail address will be stored as long as you have subscribed to the newsletter. After unsubscribing from the newsletter, your e-mail address will be deleted unless you have consented to further use of your data or there is another legal basis for processing.

14. Cookies use

We use cookies. Cookies are small files that are placed on your computer and stored by your browser. Some functions of our website cannot be offered without the use of technically necessary cookies. Other cookies, on the other hand, enable us to perform various analyses. For example, some cookies can recognize the browser you are using when you visit our website again and transmit various information to us. We use cookies to facilitate and improve the use of our website. Among other things, cookies enable us to make our website more user-friendly and effective for you by, for example, tracking your use of our website and determining your preferred settings (e.g. country and language settings). If third parties process information via cookies, they collect the information directly from your browser. Cookies do not cause any damage to your end device. They cannot execute programs or contain viruses. Various types of cookies are used on our website, the type and function of which we would like to explain below.

Temporary cookies / session cookies

Our website uses so-called temporary cookies or session cookies, which are automatically deleted as soon as you close your browser. With the help of this type of cookie, it is possible to record your session ID. This makes it possible to assign various requests from your browser to a common session and to recognize your device during subsequent visits to the website. These session cookies expire at the end of the session.

Persistent cookies

So-called persistent cookies are used on our website. Persistent cookies are cookies that are stored in your browser for a longer period of time and can transmit information. The respective storage period differs depending on the cookie. You can also manually delete permanent cookies via your browser settings.

Legal basis and storage period

Based on the purposes described, the legal basis for the processing of personal data using cookies is Art. 6 para. 1 lit. f) GDPR. If you have given us your consent to the use of cookies in a consent tool ("cookie banner") issued by us on the website, the legal basis is Art. 6 para. 1 lit. a) GDPR.

As soon as the data transmitted to us via the cookies is no longer required for the purposes described above, this information is deleted. Further storage may take place in individual cases if this is required by law.

Browser settings configuration

Most web browsers are preset to accept cookies automatically. However, you can configure your respective browser so that it only accepts certain cookies or none at all. However, we would like to point out that you may then no longer be able to use all the functions of our website.

You can also delete cookies already stored in your browser via your browser settings. Furthermore, it is possible to set your browser to notify you before cookies are stored. Since the various browsers may differ in their respective modes of operation, we ask you to refer to the respective help menu of your browser for the corresponding configuration options.

Disabling the use of cookies may require the storage of a permanent cookie on your computer. If you delete this cookie, you must then set it again for it to take effect.

For more information on configuring cookie settings in the respective browsers, please see:

Cookie categories

We use the following categories of cookies:

Necessary cookies

Necessary cookies ensure functions without which our website cannot be used as intended. These essential cookies serve, for example, to ensure that logged-in users always remain logged in when accessing various sub-pages. They are so-called first-party cookies, which are only set and used by us. Cookies may also be used to store the contents of your shopping cart until the order process is completed. These cookies do not require your consent. You can disable cookies in your browser at any time.

Functional cookies

Functional cookies allow us to extend the functionality of our site to show you additional useful information or to optimize the presentation of our site. The data collected using such cookies may vary depending on the purpose of the cookie and are listed directly with the respective consent tool used.

Statistics cookies

Statistics cookies can be used to collect information about the use of a website in order to improve its attractiveness, content and functionality. This concerns, for example, the length of time spent on the page, the sub-pages accessed and the functions used (click path).

Marketing cookies

Marketing cookies can be used to display interest-based advertising to visitors of the website and to measure the effectiveness of advertising campaigns. With the help of these cookies, visitors can be recognized on other websites and personalized ads can be displayed to them there.

15. Google Maps

Type and scope of data processing

We integrate the online maps of the service Google Maps. Google Maps is a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, Tel: +353 1 543 1000, Fax: +353 1 686 5660 , E-Mail: support-deutschland@google.com ("Google").

This allows us to show you interactive maps directly on our website and enables you to use the map function comfortably.

If you use the Google Maps component integrated on our website, Google stores a cookie on your device via your Internet browser and processes the following data:

  • Information about the operating system,
  • Information about the browser type and version used,
  • Information about your Internet service provider,
  • Your IP address,
  • Date and time of access,
  • Websites from which you have accessed our website,
  • Web pages that you access via our website.

This occurs regardless of whether you are logged into a Google user account. If you are logged in to Google, there is the possibility of an allocation of your data to your account by Google. If you do not want the assignment to your profile at Google, please log out of your Google account.

Purpose and legal basis of the data processing

Google stores your data as usage profiles and uses them for the purposes of advertising, market research and/or demand-oriented design of its website.

Such an evaluation is carried out in particular (even for users who are not logged in) for the provision of personalized advertising.

We use Google Maps to show you online maps on our website, especially for directions.

The legal basis for the processing is your consent in accordance with Art. 6 para. 1 a) GDPR.

Storage period

The stored data will be deleted by us as soon as they are no longer required for the purposes presented.

Right of objection

You have the right to object to the creation of user profiles. This must be addressed to Google.

You can prevent the transmission of data to Google by deactivating JavaScript in your browser settings. In this case, however, you will not be able to use Google Maps on our website.

More information about Google's terms of use:

https://policies.google.com/terms?gl=DE&hl=de

More information in the additional terms of use of Google Maps:

www.google.com/intl/de_US/help/terms_maps.html

For more information, please see Google's privacy policy:

http://www.google.de/intl/de/policies/privacy/

16. Google reCAPTCHA

Type and scope of data processing

We use reCAPTCHA, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, Tel: +353 1 543 1000, Fax: +353 1 686 5660, Email: support-deutschland@google.com ("Google").

Through this service, Google can determine from which website a request is sent as well as from which IP address you use the so-called reCAPTCHA input box.

In addition to your IP address, other information may be collected by Google that is necessary for offering and guaranteeing this service.

For more information about Google's privacy policy, please visit http://www.google.de/intl/de/privacy.

Purpose and legal basis of the data processing

The purpose of using Google reCAPTCHA is to ensure data security when submitting forms. This serves primarily to distinguish whether the input is made by a natural person or abusively by machine and automated processing.

The legal basis is Art. 6 para. 1 lit. f) DSGVO. Our legitimate interest lies in the security of our website and in the defense against unwanted, automated access in the form of spam.

Storage period

The stored data will be deleted by us as soon as they are no longer required for the purposes mentioned above.

Right of objection

You may refuse the use of cookies by selecting the appropriate settings on your browser, however please note that if you do this you may not be able to use the full functionality of this website.

17. Data transmission

We will only share your personal information with third parties if:

  • you have given your express consent for this in individual cases in accordance with Art. 6 para. 1 lit. a) GDPR;
  • this is legally permissible and necessary according to Art. 6 para. 1 lit. b) GDPR for the fulfillment of a contractual relationship with you or the implementation of pre-contractual measures (e.g. to payment, shipping, delivery or collection service providers);
  • in accordance with Art. 6 para. 1 lit. c) GDPR, there is a legal obligation for the disclosure (e.g. to authorities, social insurance carriers, health insurance companies, supervisory authorities and law enforcement agencies);
  • the disclosure is necessary in accordance with Art. 6 para. 1 lit. f) GDPR for the protection of legitimate business interests, as well as for the assertion, exercise or defense of legal claims and there is no reason to assume that you have an overriding interest in the non-disclosure of your data (e.g. to debt collection service providers);
  • we use external service providers (so-called order processors) for processing in accordance with Art. 28 GDPR, who process data according to our instructions and are obliged to handle your data with care (e.g. in the areas of IT or marketing).

When transferring data to external recipients in third countries, i.e. outside the European Union (EU) or the contracting states to the Agreement on the European Economic Area (EEA), we ensure that these recipients treat your personal data with the same care as within the EU or the EEA. We only transfer personal data to third countries for which the EU Commission has confirmed an adequate level of protection or if we can ensure the careful handling of personal data through contractual agreements or other suitable guarantees.

18. Data security and backup measures

We are committed to protecting your privacy and treating your personal data confidentially. To this end, we take extensive technical and organizational security precautions, which are regularly reviewed and adapted to technological progress.

This includes, among other things, the use of recognized encryption methods (SSL or TLS). However, data disclosed in an unencrypted manner, for example by e-mail, may be read by third parties. We have no influence on this. It is the responsibility of the user to protect the data provided against misuse by using encryption or otherwise.

18. Changes to the privacy policy

We reserve the right to update this statement accordingly at any time if necessary.

20. Your legal rights

Below you can find your legal rights in relation to your personal data. Details can be found in Articles 7, 15-22 and 77 of the GDPR. You can also contact us as the controller (No. 2) or our data protection officer (No. 3) in this regard.

a) Right to revoke your data protection consent pursuant to Art. 7 para. 3 s. 1 GDPR

You may revoke your consent to the processing of your personal data at any time with effect for the future. However, the lawfulness of the processing carried out until the revocation is not affected by this.

b) Right to information according to Art. 15 GDPR

You have the right to request confirmation as to whether we are processing personal data concerning you. If this is the case, you have the right to obtain information about this personal data as well as further information, e.g. the purposes of processing, the categories of personal data processed, the recipients and the planned duration of storage or the criteria for determining the duration.

c) Right to rectification and completion according to Art. 16 GDPR

You have the right to request the correction of inaccurate data without undue delay. Taking into account the purposes of the processing, you have the right to request the completion of incomplete data.

d) Right to erasure ("right to be forgotten") according to Art. 17 GDPR

You have a right to erasure insofar as the processing is no longer necessary. This is the case, for example, if your data is no longer required for the original purposes, you have revoked your declaration of consent under data protection law or the data was processed unlawfully.

e) Right to restriction of processing according to Art. 18 GDPR

You have a right to restrict processing, e.g. if you believe that the personal data is incorrect.

f) Right to data portability according to Art. 20 GDPR

You have the right to receive the personal data concerning you that you have provided to us in a structured, common and machine-readable format.

g) Right of objection according to Art. 21 GDPR

You have the right to object at any time, on grounds relating to your particular situation, to the processing of certain personal data concerning you. In the event of direct marketing, you as the data subject have the right to object at any time to processing of personal data concerning you for the purposes of such marketing; this also applies to profiling insofar as it is related to such direct marketing.

h) Automated decision in individual cases including profiling according to Art. 22 GDPR

You have the right not to be subject to a decision based solely on automated processing - including profiling - except in the exceptional circumstances mentioned in Article 22 of the GDPR. Decision-making based exclusively on automated processing - including profiling - does not take place.

i) Complaint to a data protection supervisory authority pursuant to Art. 77 GDPR

In addition, you can lodge a complaint with a data protection supervisory authority at any time, for example if you believe that the data processing does not comply with data protection regulations.

Competent supervisory authority:

The competent supervisory authority for ComplyMarket UG (beschrankte gesellschaft) is The Bavarian State Commissioner for Data Protection:

P.O. Box 22 12 19 80502 Munich, or

Wagmüllerstr. 18

80538 Munich

Germany

Telephone: 089/21 26 72-0

Fax: 089/21 26 72-50

poststelle@datenschutz-bayern.de

Munich, March 2023