Data Assessment Solutions

Legal

Privacy Policy

This English version is a translation provided for convenience. The legally binding version is the German original at data-assessment.com/datenschutz.

1. Scope

We take the protection of your personal data very seriously and treat your personal data confidentially and in accordance with the statutory data protection provisions and this privacy policy. With this document we inform you about the nature, scope and purpose of the personal data we collect, use and process. This privacy policy also explains the rights you are entitled to. It applies to all websites, applications, services and tools of Data Assessment Solutions GmbH (together the “Services”) that refer to it, regardless of how you access or use those Services, including access from mobile devices.

Persons under the age of 16 are not permitted to use our contact and registration forms under Art. 8 GDPR unless their legal guardians have given legally effective consent to the data processing. We also point out that our offering is aimed exclusively at business customers.

The controller within the meaning of the General Data Protection Regulation (GDPR), of other data protection laws applicable in the member states of the European Union and of other provisions with a data protection character is Data Assessment Solutions GmbH, Misburger Str. 81b, 30625 Hannover, Germany, phone: +49 511 47402330, email: , website: www.data-assessment.com. The data protection officer of the company is Dr. Stephan Glaschak (email: ).

2. Which personal data do we collect and what is it used for?

Definition

Personal data is information about an identified or identifiable natural person. An identifiable natural person is a person who can be identified directly or indirectly by reference to an attribute. Such an attribute can be a name, an identification number, location data or an online identifier, or specific information about the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. Data that is anonymized or aggregated and can no longer be used to identify a specific natural person, whether in combination with other data or otherwise, does not count as personal data.

Website

You can use our website without providing personal data. Each time a page is called up, however, our internet service provider records a range of general data and information that is temporarily stored in the log files of the web server. This can include the browser types and versions used, the operating system of the accessing system, the website from which an accessing system reaches our website (the referrer), the subpages accessed on our website, the date and time of access, an internet protocol address (IP address), the internet service provider of the accessing system and other similar data and information that serves to avert danger in the event of attacks on our information technology systems.

When processing this general data and information, we draw no conclusions about the data subject. Rather, this information is needed to deliver the content of our website correctly and to provide law enforcement authorities with the information required for prosecution in the event of a cyberattack. The anonymous data of the server log files is stored separately from any personal data provided by a data subject.

Our website is hosted on Microsoft Azure (Microsoft Ireland Operations Ltd., One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland). The log data described above is generated at Microsoft as our processor; the processing takes place on the basis of a data processing agreement under Art. 28 GDPR.

Products

Data Assessment Solutions GmbH is a German provider of software solutions and related services for automating back office tasks. Our solutions, for example assistants for meetings, incoming invoices, orders or absences, take over recurring processes in our customers’ existing systems, in particular in Microsoft 365 (such as Outlook, Teams and SharePoint) and connected business systems.

The solutions are set up for each customer and run in that customer’s IT environment. The data processed in the course of this (for example emails, documents, appointments, call recordings and transcripts) remains in the customer’s leading systems in principle and is not passed on to third parties.

The customer is the controller within the meaning of Art. 4(7) GDPR for the personal data processed within the solutions they use (for example data of their employees and business partners). It is the customer’s responsibility to obtain any necessary declarations of consent from the data subjects and to inform them of their rights and obligations under data protection law.

Where we process personal data on behalf of the customer during setup, operation, maintenance or support, this takes place on the basis of a data processing agreement under Art. 28 GDPR. In doing so we process only the data required to provide the contractually agreed services; the legal basis is performance of the contract under Art. 6(1)(b) GDPR.

For our skill and resource management solution decídalo we provide a separate privacy policy on the decídalo website (www.decidalo.com).

Contact form, email inquiries

If you send us inquiries via the contact form on our website, by email or in any other way, your details including the contact data you provide will be stored by us in order to process the inquiry and in case of follow-up questions. You always provide these details voluntarily. We do not pass your data on without your consent. Please note that data transmission over the internet, for example when communicating by email, can have security gaps. Complete protection of data against access by third parties is therefore not possible.

To prevent automated and abusive submissions (spam) we check form entries with the Cloudflare Turnstile service (see the section “Cloudflare Turnstile”); your IP address is processed in the course of this. Your inquiry is technically delivered to our mailbox through Microsoft Azure Communication Services (Microsoft Ireland Operations Ltd.) acting as a processor bound by our instructions. Your inquiry is not stored in a database; the data is transmitted to us by email only and stored there in order to process your inquiry. The legal basis is Art. 6(1)(b) or Art. 6(1)(f) GDPR.

Registration for events

For individual events we offer registration forms on our website. We process the data entered there (for example name, email address, company and optional details) exclusively in order to organize and run the event in question. Your registration is transmitted to our organizing team by email and you receive a confirmation by email; it is not stored in a database. The technical delivery likewise takes place through Microsoft Azure Communication Services.

To prevent automated submissions we use a form field that is invisible to humans as well as a limit on the number of requests per IP address; your IP address is processed briefly for this purpose. The legal basis is Art. 6(1)(b) or Art. 6(1)(f) GDPR.

Customers

Within an existing contract we also use personal data to fulfill the contract concluded with you, to provide you with our Services and to meet our legal obligations. This includes, for example, payment processing and account administration, operating, assessing and improving our Services, safeguarding our Services and keeping them functional, contacting you in the course of performing the contract, and other customer service measures. We may contact you for these reasons by email, telephone or post.

Application process

We process the personal data of applicants in order to handle application procedures. Processing usually takes place electronically, for example when someone sends application documents to us by email. If we conclude an employment contract, the data submitted is stored for the purpose of handling the employment relationship in compliance with the statutory provisions.

3. Do we share personal data?

Data is only passed on to third parties without your consent if we are legally obliged to do so or if it is necessary to perform the contract and serves our legitimate interests, provided your rights and freedoms do not override them. We have introduced appropriate control mechanisms to reconcile our interests with your rights. We may pass your personal data on to the following third parties and for the following purposes:

External service providers

We pass personal data on to external service providers who support us in our business operations, who provide technical, sales, financial or logistical services for us, or who support us in preventing, detecting, containing and investigating potentially unlawful acts, in complying with our legal obligations, in enforcing our terms and conditions, in defending legal claims, in debt collection, in partner and bonus programs and in other business transactions.

When we pass personal data on to external providers, this happens solely on the basis of an agreement that limits the processing of that personal data by the external provider to the purposes required to fulfill their contractual obligations towards us. The external provider is obliged to take appropriate security measures with regard to this data. External providers are in no way entitled to pass personal data on.

Government authorities

We pass personal data on to law enforcement authorities, government agencies or third parties authorized by law on the basis of a request for information or in connection with an investigation or the suspicion of a criminal offense, an unlawful act or another act that may result in legal liability for us, for you or for other users. In such cases we only disclose the data that in our assessment is relevant to the investigation or the request for information, such as name, place, postal code, telephone number, email address or IP address.

Transfers to third countries

Processing of personal data in a third country by us or on our behalf only takes place within the limits permitted by law and by contract and where the special requirements of Art. 44 et seq. GDPR are met. This means that processing then takes place, for example, on the basis of special safeguards such as an officially recognized finding of a level of data protection equivalent to that of the EU, or in compliance with officially recognized special contractual obligations (the standard contractual clauses of the EU Commission), supported by an individual risk assessment.

Legal successors, group companies

In the event of a merger with another company or an acquisition by another company we may pass information on to that company in accordance with our data protection principles. Should such an event occur, we will require the newly merged company to comply with the statutory data protection provisions regarding your personal data. Should your personal data be collected, used, passed on or stored for any purposes not mentioned in this document, you will be informed in advance about the processing of your data for these new purposes.

4. How long do we keep personal data?

Personal data is stored on the basis of the applicable statutory retention periods. Once a period expires, the corresponding data is deleted, provided that a) the data is no longer required to perform the contract, b) you have not explicitly agreed to an extended retention period and c) no other legitimate interests of our company prevent deletion. Another legitimate interest in this sense could arise, for example, from the burden of proof in proceedings under the German General Equal Treatment Act (AGG) in connection with application procedures.

5. Do we use cookies or tracking technologies?

No cookies, no tracking

This website does not set cookies. We use neither statistics nor marketing cookies, we do not embed analytics or advertising services and we do not create usage profiles. A cookie banner or consent is therefore not required.

When the pages are called up, only the technically necessary access data is processed, which our hosting provider records in server log files. You can find details in point 2 of this privacy policy.

Cloudflare Turnstile

To protect our contact form against automated and abusive submissions (bots, spam) we use the service Turnstile provided by Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA). Turnstile checks whether a submission is made by a human. Technical information from your browser and your IP address are transmitted to Cloudflare and evaluated there. According to the provider, Turnstile is designed to minimize data and does not set cookies for tracking purposes; the data is not used for advertising. The processing is based on our legitimate interest in protecting our website against misuse and spam under Art. 6(1)(f) GDPR. Where personal data is transferred to the USA in this context, this takes place on the basis of the standard contractual clauses of the EU Commission. You can find further information in Cloudflare’s privacy policy at https://www.cloudflare.com/privacypolicy/.

6. Use of AI services in our solutions

Our solutions use AI models to analyze content such as emails, documents or call recordings, for example to read invoice data, summarize meetings or classify transactions. In this section we explain which data protection aspects are taken into account.

Data processing and transfer

Which AI services are used is agreed contractually with each customer. As a rule the processing takes place through AI services that the customer controls or has commissioned themselves, for example Azure OpenAI Services in the customer’s Azure tenant or the AI assistants used within the customer’s organization. Inputs and outputs are processed exclusively in order to provide the agreed functions and are not passed on to third parties.

No use for model training

The AI services used are selected and configured in such a way that inputs (for example documents and texts) and outputs (AI results) are not used to train the underlying models. For Azure OpenAI Services, Microsoft guarantees that customer inputs and AI outputs are available neither to other customers nor to OpenAI and are not used to improve the models.

Microsoft provides further information on data protection questions relating to the use of Azure OpenAI Services on the following pages: https://learn.microsoft.com/en-us/azure/ai-services/openai/faq and https://learn.microsoft.com/en-us/legal/cognitive-services/openai/data-privacy.

Legal basis for processing

Where we process personal data in this context on behalf of the customer, this takes place on the basis of a data processing agreement under Art. 28 GDPR; otherwise the legal basis is performance of the contract under Art. 6(1)(b) GDPR. The customer remains the controller for the personal data processed within their own workflows.

Data subject rights

In connection with the processing of your data for AI functions you have the right to information, rectification, erasure and objection. You can find further information about your rights in the general section “What choices and rights do you have” under point 7 of this privacy policy.

7. What choices and rights do you have regarding the processing of personal data?

Legal basis

Unless the legal basis is explicitly stated in an individual case, the following applies: the legal basis for obtaining consent is Art. 6(1)(a) and Art. 7 GDPR, the legal basis for processing in order to provide our services, carry out contractual measures and answer inquiries is Art. 6(1)(b) GDPR, the legal basis for processing in order to fulfill our legal obligations is Art. 6(1)(c) GDPR, and the legal basis for processing in order to safeguard our legitimate interests is Art. 6(1)(f) GDPR.

Rights

Under Art. 15 GDPR you also have the right to information about the nature, scope and purpose of the personal data stored, the right to rectification under Art. 16 GDPR, the right to erasure under Art. 17 GDPR, the right to restriction of processing under Art. 18 GDPR, the right to object under Art. 21 GDPR and the right to data portability under Art. 20 GDPR. The restrictions under Sections 34 and 35 of the German Federal Data Protection Act (BDSG) apply to the right to information and the right to erasure. In addition, you have the right to lodge a complaint with a data protection supervisory authority under Art. 77 GDPR in conjunction with Section 19 BDSG. Please contact us using the contact options given at the beginning if you would like to exercise your rights. On your request we will delete your personal data insofar as this is possible within your contractual relationship and in accordance with applicable law.

Consequences

If you ask us to stop processing your personal data in whole or in part, or if you withdraw your consent (where applicable) to the use or disclosure of your personal data for the purposes set out in this privacy policy, we may no longer be able to provide you with all Services. Please note that this does not automatically release you from payment obligations under existing contracts.

8. How do we protect your personal data?

Your personal data is protected by technical and organizational security measures in order to minimize the risks of loss, misuse, unauthorized access and unauthorized disclosure and alteration. For this purpose we use firewalls and data encryption, for example, but also physical access restrictions for our data processing facilities and authorization controls for data access. Subcontractors are obliged to comply with data protection provisions under Art. 28(4) GDPR.

We are happy to provide further information on request.

9. Other information

We may amend this privacy policy at any time by publishing the amended version on this website. If you have any further questions, we are happy to help.