1. General Information
In this privacy policy, we, Cito Transport Technologies GmbH (hereinafter referred to as Cito), inform you about the processing of personal data when using our website and services.
Personal data is information that relates to an identified or identifiable individual. This primarily includes details that allow conclusions to be drawn about your identity, such as your name, telephone number, address, or email address. Statistical data that we collect, for example, when you visit our website and which cannot be linked to you personally, does not fall under the definition of personal data.
You can print or save this privacy policy using your browser's standard functionality.
The contact person and controller responsible for the processing of your personal data when visiting this website, as defined by the EU General Data Protection Regulation (GDPR), is
Cito Transport Technologies GmbH, c/o Mindspace, Hausvogteiplatz 12, 10117 Berlin.
- Phone: +49 302 332 634 00
- Email: dataprivacy@cito.ai
For all questions regarding data protection in connection with our services or the use of our website, you can also contact our Data Protection Officer at any time. They can be reached at the postal address above as well as at the email address provided previously (subject: "Attn: Data Protection Officer").
2. Data processing when visiting the Cito website
Every time you use our website, we collect the access data that your browser automatically transmits to enable you to visit the website. This access data includes, in particular:
- IP address of the requesting device,
- Date and time of the request,
- Address of the website accessed and the referring website,
- Information about the browser and operating system used,
- Online identifiers (e.g., device IDs, session IDs).
The processing of this access data is necessary to enable you to visit the website and to ensure the long-term functionality and security of our systems. For the purposes described above, the access data is also temporarily stored in internal log files in order to generate statistics on the use of our website, to further develop our website with regard to the usage habits of our visitors (e.g., if the proportion of mobile devices used to access the pages increases), and to maintain our website for administrative purposes in general. This data is processed in accordance with Article 6 (1) (f) GDPR based on our legitimate interest in being able to display the website to you properly.
The information stored in the log files does not allow for any direct conclusions to be drawn about your person – in particular, we only store IP addresses in a shortened, anonymized form. The log files are stored for 7 days and archived after subsequent anonymization.
3. Data processing when contacting us
You have various options for getting in touch with us. For example, you can contact us by phone or email. In this context, we process data exclusively for the purpose of communicating with you. The legal basis is Art. 6 (1) (b) GDPR, insofar as the processing is required to answer your inquiry or to initiate or execute a transport contract. Insofar as data processing is carried out for advertising purposes, for example to keep you informed about the development of our services, Art. 6 (1) (f) GDPR is the legal basis for the processing.
3.1 Data processing during the application process at Cito
We process your personal application data in accordance with the provisions of the EU GDPR and the German Federal Data Protection Act (BDSG), insofar as this is necessary for the decision regarding the establishment of an employment relationship with us. We process the data that we receive from you by post or email in the course of establishing contact or your application, or that you have made available or transmitted to us via social networks used for professional networking and professional self-presentation (e.g., LinkedIn). By sending or making your data available, you provide us with your express consent to do so. You may revoke this consent at any time.
Your data will be stored for a period of 90 days beyond the conclusion of the application process. This is generally done to fulfill legal obligations or to defend against potential claims arising from statutory provisions. Subsequently, we are required to delete or anonymize your data. In this case, the data will only be available to us as metadata without any direct personal reference for statistical analysis (e.g., the proportion of female vs. male applicants, the number of applications per period, etc.).
The legal basis for processing this data is Art. 88 GDPR in conjunction with Section 26 BDSG-new, as well as, where applicable, Art. 6(1)(b) GDPR for the initiation or performance of contractual relationships. Furthermore, we may process your personal data if this is necessary to fulfill legal obligations (Art. 6(1)(c) GDPR) or to defend against legal claims asserted against us. In the further course of the application process, this may include pre-employment screenings (background checks) to verify the information you provided during the application process.
The data submitted as part of your application is transmitted via TLS encryption and stored in a database. This database is operated by Personio GmbH, which provides human resources and applicant management software (https://www.personio.de/impressum/). In this context, Personio acts as our data processor in accordance with Art. 28 GDPR. The basis for this processing is a data processing agreement between us as the controller and Personio.
If an employment relationship is established between you and us, we may continue to process the personal data already received from you for the purposes of the employment relationship in accordance with Art. 88 GDPR in conjunction with Section 26 of the German Federal Data Protection Act (BDSG-new), insofar as this is necessary for the performance or termination of the employment relationship or for the exercise or fulfillment of the rights and obligations of the employees' representative body resulting from a law, a collective agreement, or a works or service agreement. There is no intention to transfer the data to a third country.
For our contract management, we use the service "Fynk" (fynk GmbH, Molkereistraße 7/16, 1020 Vienna, Austria) for the automated creation and signing of contracts.
For this purpose, we process your first and last name, email address, IP address, digital signature, and other personal data contained in the contracts, such as your address. The email address is required to send the documents to be signed.
We rely on our legitimate interest under Art. 6(1)(f) GDPR as the legal basis for this, in order to optimize our internal processes.
Your data is only accessible internally to the relevant individuals and departments (e.g., management, legal department, human resources) and is stored for as long as is necessary to fulfill the stated purpose.
3.2 Scheduling a product demonstration via Demodesk
Those interested in our product can book an appointment for a product demonstration with one of our team members via Demodesk (Demodesk GmbH, Brienner Straße 45a-d, 80333 Munich). For this purpose, the following data is processed by Demodesk:
- User IP address
- Date and time of contact
- Date and time of the appointment
- Email
- Name
- Phone number
- Company name
Further information on the processing of personal data by Demodesk can be found here.
3.3 Data processing for customer communication via email
On our website, you have the option to subscribe to our newsletter to receive regular updates about our company, discount codes, and information about blog posts or whitepapers.
We collect your contact details (first name, last name, email address) for this purpose. We use the features provided by Inxmail (see section 3.5.2) to send the newsletter.
The purpose of the data processing is to send information about Cito services to our potential and existing customers.
The legal basis for this is your consent in accordance with Art. 6 (1) sentence 1 (a) GDPR. Your email address will be processed for these purposes until you unsubscribe from the newsletter.
You can unsubscribe from the newsletter at any time and withdraw your consent to receive it in the future. Each newsletter contains a link for this purpose. If you are an existing customer, you can adjust the corresponding settings in your profile.
3.4 Direct marketing
If you are an existing customer, we will send you information about services similar to those you have already ordered from us, as well as information regarding software updates or changes to our platform.
We collect your contact details (first name, last name, email address) for this purpose. We use the features provided by Inxmail (see section 3.5.2) for distribution.
The purpose of the data processing is to send information about Cito services to our existing customers.
The legal basis for this is our legitimate interest in accordance with Art. 6 (1) sentence 1 (f) GDPR. Your email address will be processed for these purposes until you unsubscribe from receiving this information.
You can unsubscribe from this information at any time and object to future use. Each email contains a link for this purpose. If you are an existing customer, you can adjust the corresponding settings in your profile.
As part of our existing business relationships, we occasionally send small gifts to our contacts at companies. The legal basis for this is our legitimate interest in accordance with Art. 6 (1) (f) GDPR in conjunction with Section 7 of the German Act Against Unfair Competition (UWG). You may, of course, object to this at any time.
3.5 Data processing with Sendgrid
We use SendGrid, an email delivery service for customer information and automated communication with you via our platform, such as sending transport status notifications. You can manage granular settings for receiving notifications within the platform.
In doing so, we process your first and last name, email address, IP address, click rates, and details regarding the opening of emails.
We rely on our legitimate interest pursuant to Art. 6(1) sentence 1(f) GDPR as the legal basis for this.
Your data will only be stored for as long as is necessary to fulfill the stated purpose.
The service is provided by Twilio Inc., based in Redwood City, California, USA. Consequently, your data is also processed directly in the USA, among other locations. The data processing terms, which comply with the Standard Contractual Clauses, can be found here. Twilio Inc. is also a participant in the Data Privacy Framework.
3.6 Data processing with Inxmail
Through Inxmail GmbH (Wentzingerstraße 17, 79106 Freiburg), we use a Salesforce integration to automate our marketing activities for the purpose of sending newsletters, product updates, and targeted marketing campaigns. We also use the tool to analyze open and click rates to measure effectiveness and improve our marketing campaigns.
The following personal data is processed: first name, last name, email address, IP address, click rates, and details regarding the opening of emails.
We rely on our legitimate interest pursuant to Art. 6(1) sentence 1(f) GDPR as the legal basis for this. Your data will only be stored for as long as is necessary to fulfill the stated purpose.
3.7 Data processing with Microsoft Forms
We offer a self-assessment as part of our webinars. To conduct and evaluate the assessment, we process the personal data you provide in the form (name, company, email address) as well as data generated in connection with the technical provision of the service.
Processing is carried out for the purpose of conducting the self-assessment and providing individual results. The legal basis is Art. 6(1)(b) GDPR (performance of pre-contractual measures) or Art. 6(1)(f) GDPR; our legitimate interest lies in providing and evaluating the self-assessment for our webinar participants.
If you consent to receiving marketing emails, we will also use your email address to send you information about our products, services, and offers in the field of AI and transport technology. In this context, we analyze your usage behavior within the emails (open and click rates) to optimize our content. The legal basis is your consent pursuant to Art. 6(1)(a) GDPR. This consent is agreed upon as a contractual consideration for the free provision of the assessment results.
The data will be deleted after 24 months.
For the self-assessment, we use Microsoft Forms, a service provided by Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. Microsoft processes the data on our behalf based on a data processing agreement in accordance with Art. 28 GDPR. Data processing generally takes place within the EU/EEA. However, it cannot be ruled out that access from the USA may occur in the context of support and maintenance. In such cases, the transfer is based on the EU-U.S. Data Privacy Framework or EU Standard Contractual Clauses.
3.8 Webinars with Microsoft Teams
We conduct webinars using Microsoft products (including Microsoft Teams and Microsoft Forms; provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland).
In this context, we process the personal data you provide in the registration form (first name, last name, company, position, email address, telephone number) as well as event-related metadata (e.g., time of registration, participation/attendance, entry and exit times, and technical log data).
Processing is carried out for the purpose of planning, registering, conducting, and following up on the webinar (including sending login details and organizational communication). The legal basis is Art. 6 (1) (b) GDPR (performance of the participation contract or pre-contractual measures) or Art. 6 (1) (f) GDPR; our legitimate interest lies in the efficient conduct of information events.
By submitting your registration, you consent to receiving marketing and product information via email. The legal basis is Art. 6 (1) (a) GDPR in conjunction with Section 7 of the German Act Against Unfair Competition (UWG). Consent is voluntary and can be withdrawn at any time with future effect; every newsletter contains an unsubscribe link.
Data processing generally takes place within the EU/EEA. However, it cannot be ruled out that access from the USA may occur during support and maintenance. In such cases, the transfer is based on the EU-US Data Privacy Framework or EU Standard Contractual Clauses.
After the webinar, participant data is imported into our CRM, Salesforce (Salesforce Ireland Limited; affiliated companies of Salesforce, Inc., USA), to manage customer relationships and—provided consent has been given—to send marketing emails. Salesforce acts as a data processor; any transfers to third countries are based on EU Standard Contractual Clauses; Salesforce is also a participant in the EU-US Data Privacy Framework.
Registration and attendance data for the webinar will be deleted after 24 months. Contact data stored for marketing purposes (including proof of your consent) will be processed until you withdraw your consent or unsubscribe from the newsletter; we retain proof of consent given or withdrawn in accordance with statutory limitation periods.
4. Use of cookies
4.1 Use of functional cookies
Some of our services require the use of cookies. A cookie is a small text file that is saved on your device by your browser. Cookies are not used to run programs or load viruses onto your computer. The primary purpose of our own cookies is to provide you with a tailored experience and to make using our services as efficient as possible.
Most browsers are set to accept cookies by default. However, you can adjust your browser settings to reject cookies or to require your consent before they are saved. If you reject cookies, some of our services may not function properly.
We use our own cookies, in particular:
- to save your language settings
- to note that information placed on our website has been displayed to you, so that it is not shown again the next time you visit the site.
This allows us to provide you with a more comfortable and personalized experience on our website. These services are based on our aforementioned legitimate interests; the legal basis is Art. 6 (1) (f) GDPR.
4.2 Use of cookies and similar technologies for analysis, tracking, and retargeting purposes
To improve our website, we use cookies and similar technologies (e.g., web beacons) for the statistical recording and analysis of general usage behavior based on access data. We also use analysis services to evaluate the performance of our various marketing channels.
The legal basis for the data processing described in the following section is Art. 6(1)(f) GDPR, based on our legitimate interest in the needs-based design and continuous optimization of our website and our marketing activities.
In the following list of the technologies we use, you will also find information on how to object to our analysis measures using an opt-out cookie. Please note that if you delete all cookies in your browser folder or subsequently use a different browser and/or profile, you will need to set an opt-out cookie again.
4.3 Matomo
We use the analysis tool Matomo, provided by InnoCraft Ltd., 150 Willis St, 6011 Wellington, New Zealand, on our website to analyze user behavior.
We use Matomo with the "AnonymizeIP" extension. The web server truncates every IP address before it is stored in the log file. This means that only anonymized data is analyzed. You as a user are not identifiable to us, and it is not possible to draw conclusions about individual persons.
Processing is based on your consent in accordance with Art. 6(1)(a) GDPR. Measuring user behavior on our website allows us to adapt and improve user-friendliness and our online presence.
The data is hosted in a European data center. Any potential transfer of your data to the provider in New Zealand is covered by an adequacy decision of the EU Commission pursuant to Art. 45 GDPR.
Further information on Matomo can be found here: Matomo Privacy Policy
4.4 Use of Google Tag Manager
We use Google Tag Manager from Google. "Google" is a group of companies consisting of Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland, as well as Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, and other affiliated companies of Google LLC.
We have entered into a data processing agreement with Google. Google Tag Manager is an auxiliary service that only processes personal data for technically necessary purposes. The tool triggers the loading of other components, which may in turn collect data. Google Tag Manager does not access this data.
For more information about Google Tag Manager, please refer to Google's privacy policy.
Please note that due to U.S. law, U.S. intelligence agencies may potentially gain access to personal data that is inevitably exchanged with Google when using this tool, as required by the Internet Protocol.
Further information on this can be found in the Google Privacy Policy.
4.5 LinkedIn Insight Tag
We use the LinkedIn Insight Tag on our website. It enables us to generate campaign reports and can provide information about our website visitors. This allows us to track conversions and target our website visitors with more personalized advertising. The LinkedIn Insight Tag can create a unique LinkedIn browser cookie in a visitor's browser and allows us to collect the following data for this cookie: URL, referrer URL, IP address, device and browser characteristics (User Agent), and timestamps. IP addresses are truncated or hashed. Direct member identifiers are removed within seven days to pseudonymize the data. These remaining pseudonymized data are then deleted within 180 days. You can find more information here and in the LinkedIn Privacy Policy.
The legal basis for this is your consent in accordance with Article 6(1)(a) of the GDPR.
5. Google Maps form
We provide an input form that allows you to display the location of an address on a map, for example for route planning. The underlying map software is provided by Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland ("Google"). Only when you submit the form is your input, along with your IP address and the URL of the page where the form is located, transmitted to Google. By using this form, you consent to the collection, processing, and use of this data by Google and its representatives. Google Maps Terms of Service. Google Privacy Policy.
Please note that, due to the Cloud Act, U.S. intelligence agencies may potentially gain access to personal data that is inevitably exchanged with Google when using this tool, as required by the Internet Protocol.
6. Data processing in the context of social media
6.1 Use of Facebook and Instagram
When you visit our Facebook and Instagram pages, certain personal data about you is processed. Social networks can comprehensively analyze your user behavior when you interact with content there (e.g., using a "like" button). This data is stored by Meta, the operator of these platforms, as user profiles and may be used for advertising and market research purposes. Since we have no influence over the processing of your personal data by Meta, we are unable to make binding statements regarding the purpose and scope of this processing.
When you visit our Facebook or Instagram account, we process your interactions with our social media page (e.g., your name, messages, posts, comments, likes, shared posts) as well as your publicly visible profile data (e.g., username, biography, and profile picture).
The purpose of our data processing on Facebook and Instagram is to inform our customers about offers, products, promotions, and news, as well as to interact with visitors to our social media presence. This constitutes a legitimate interest within the meaning of Art. 6(1)(f) GDPR. The personal data we collect and process is used exclusively for communication with you and for maintaining our social media presence.
Meta Leads: If you are interested in becoming our transport partner, we will process the following personal data from you: name, phone number, email, company name, region/city, vehicle model, licenses. We use this data exclusively to determine whether you are suitable as a transport partner and for subsequent contact. This constitutes a legitimate interest within the meaning of Art. 6(1)(f) GDPR.
As the operator of this page, we cannot rule out the transmission and processing of personal data to third countries, such as the USA, and the associated potential risks for users. Insofar as Meta, as the provider of Facebook and Instagram, decides alone on the purposes and means of data processing, Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, is the sole controller for the processing. In the addendum for controllers pursuant to Art. 26 GDPR, Meta has stipulated that it is responsible for the processing of Insights data: https://www.facebook.com/legal/terms/page_controller_addendum
You can find more information in Meta's privacy policy:
https://www.facebook.com/privacy/policy
6.2 Use of TikTok
We maintain a presence on the TikTok platform, which is provided by TikTok Technology Limited, The Sorting Office, Ropemaker Place Dublin 2, Dublin, D02 HD23, Ireland. Please note that you use this platform and its functions at your own risk. This applies in particular to interactive functions (e.g., commenting, sharing, rating). We have disabled the TikTok Analytics function.
The processing serves the creation and publication of video content about Cito with the primary goal of employer branding. Through these videos, we aim to present Cito as an attractive employer in order to attract qualified professionals and strengthen our corporate image.
Please note that applications are accepted exclusively via our official application email address hr@cito.ai. For data protection reasons, we ask that you refrain from submitting applications via platforms such as TikTok.
TikTok processes the data of its service users (e.g., personal information, IP address, etc.) and may use it for business purposes. We have no influence over data collection and further processing by TikTok. Furthermore, we cannot determine the extent to which, the location at which, and the duration for which the data is stored, the extent to which TikTok complies with existing deletion obligations, what analyses and links are made with the data, and to whom and to which countries the data is transferred. For more information on data processing by TikTok, please refer to TikTok's privacy policy: https://www.tiktok.com/legal/page/eea/privacy-policy/en
7. Data Disclosure
Data collected by us is generally only disclosed if:
- the disclosure is necessary under Art. 6(1)(f) GDPR for the establishment, exercise, or defense of legal claims, and there is no reason to assume that you have an overriding interest in the non-disclosure of your data that requires protection
- we are legally obligated to disclose the data under Art. 6(1)(c) GDPR, or
- this is legally permissible and necessary under Art. 6(1)(b) GDPR for the performance of a contract with you or for taking steps at your request prior to entering into a contract
Some data processing may be carried out by our service providers. In addition to the service providers mentioned in this privacy policy, this may include, in particular, data centers that host our website and databases, IT service providers that maintain our systems, and consulting firms. If we pass data on to our service providers, they may only use the data to fulfill their tasks. These service providers have been carefully selected and commissioned by us. They are contractually bound by our instructions, have appropriate technical and organizational measures in place to protect the rights of the data subjects, and are regularly monitored by us.
Furthermore, data may be disclosed in connection with official inquiries, court orders, and legal proceedings if required for legal prosecution or enforcement.
8. Data processing when using our web and app services
The data listed below is stored and, if necessary, processed by or on behalf of Cito in addition to the data already mentioned when using the services or registering for one of the services.
8.1 Data provided by customers when booking the transport of goods
This includes customer profile data and transport details when booking a shipment. Cito collects data when users utilize the services of the Cito platform. In the final step, a user account is created and the following data is collected:
- Company name
- Company address
- First and last name
- Phone number
- Industry
- Email address
- VAT ID
- Billing address (including the first and last name to appear on the invoice)
The data may also be collected when updating the user account.
Cito collects data when users of a Cito account place a transport order, until the transport order has been fully processed within Cito. This includes the following data:
- Recipient's name
- Delivery address
- Recipient's phone number
At the customer's request, this data can be saved in the online address book provided by Cito. The data will not be shared with third parties. When using the online account, the customer is obligated to keep their account access credentials secure. They must ensure that no unauthorized third party gains access to the password. The customer is obligated to keep the password confidential and, if possible, to change it immediately or have it changed by Cito if they suspect that unauthorized third parties have gained knowledge of it. The customer is liable to Cito for any damages resulting from a breach of these obligations.
8.2 Data collected from the carrier
Cito collects data when carriers create or update an account for their company or as an individual carrier with Cito. This includes the following data:
- Company name
- Company address
- First and last name (of the person opening the account)
- Phone number
- Vehicle type including license plate
- Email address
- VAT ID number
- Tax number
- Copy of business registration
- Bank details such as IBAN and BIC
Furthermore, Cito stores copies of driver's licenses and other government-issued identification documents, such as national ID cards, which may contain document numbers, date of birth, gender, and a photo. This also includes vehicle or insurance information for carriers, such as commercial transport insurance and the vehicle's inspection certificate (TÜV). In addition, data from the standard certificate of good conduct is collected, as well as proof of a valid employment contract if required (for minimum wage and social security verification). Other documents necessary for contract fulfillment may also be collected. Please refer to the General Terms and Conditions for Carriers for further details.
Additionally, Cito collects information that users provide when they contact Cito customer service.
8.3 Data generated by the carrier when using our services via the Cito app
To use the Cito app, you must grant permission for location access, motion detection, and push notifications. When "Work Mode" is activated, the carrier's location data is tracked. Cito collects this data when the Cito app is running in the foreground (app open and on screen) or in the background (app open but not on screen) of the mobile device.
8.4 Location data (carriers)
Cito collects precise or approximate location data from carriers' mobile devices. Cito collects this data from the moment the "Work Mode" is active. The carrier's location data is made available to the customer via the platform from the time the transport is accepted until it is delivered.
8.5 Communication between carriers, customers, and Cito
For communication with carriers, transport partners, and customers, we use the tool Intercom (Intercom R&D Unlimited Company, 18–21 St. Stephen’s Green, Dublin 2, Ireland) to enable direct and efficient communication between users (partners, carriers, and drivers) and our operations team.
Intercom is used as a central platform for processing communication inquiries. It consolidates various communication channels—such as in-app chat messages, WhatsApp Business, emails, and other incoming requests—to make them available for processing. In particular, an integrated interface enables the exchange of messages between our internal team and registered drivers within the Cito app. Users can use the chat window to ask questions about deliveries, orders, or issues, for example.
When using the chat function and other communication channels, personal data such as name or company name, phone number, email address, message content (e.g., delivery inquiries or problem descriptions), metadata (e.g., timestamps), technical data (e.g., IP address, device information), and associated delivery, order, or purchase information are processed.
The purpose of data processing is to facilitate efficient and centralized communication with carriers, drivers, transport partners, and customers. The personal data we collect and process is used exclusively to handle your inquiry and manage our business relationship.
Processing is based on our legitimate interest pursuant to Art. 6(1)(f) GDPR to ensure fast, transparent, and structured communication.
Chat and ticket histories are stored only for as long as is necessary to fulfill the stated purpose, provided there are no statutory retention obligations or a need for further storage to resolve outstanding inquiries.
8.6 Transaction data
Cito collects transaction data related to the use of the services, including the type of services requested or provided, order details, delivery information, the date and time the service was provided, the amount charged, distance traveled, and payment method.
8.7 Usage data
Cito collects data on how users interact with the services. This includes data such as access dates and times, app features or pages viewed, app crashes and other system activity, browser type, and third-party sites or services used before interacting with the services. In some cases, Cito collects this data through cookies, pixels, tags, and similar tracking technologies that create and maintain unique identifiers. To learn more about these technologies, please read our Cookie Notice.
In addition, when using the app for carriers, photos related to the transport may be transmitted and collected by the carrier. To confirm pickup and delivery by the carrier, the signatures of the customer and the recipient are also collected in the Cito app.
8.7.1 Amplitude
With Amplitude (Amplitude, Inc., 201 Third Street, Suite 200, San Francisco, CA 94103), we use an analytics service that allows us to analyze user behavior on our platform in order to improve our product.
In our Cito app, we collect user behavior exclusively with your consent in order to continuously improve our product. This involves processing technical information about the device and operating system, various identification features for recognition, network and connection data such as IP address and mobile carrier, as well as language settings.
For this purpose, we collect the session ID, IP address, B, and the associated user behavior.
We rely on our legitimate interest pursuant to Art. 6(1)(f) GDPR as the legal basis for this. The data is used exclusively to improve our platform.
Amplitude processes personal data in the USA. Please note that, according to the European Court of Justice, there is currently no adequate level of data protection for data transfers to the USA. This may involve various risks to the legality and security of data processing. Amplitude uses EU Standard Contractual Clauses (SCCs) as the basis for data processing. You can find these in the corresponding DPA.
Further information about the provider itself can be found in Amplitude's Privacy Policy.
8.7.2 Device data
Cito may collect data about the devices used to access Cito services, including hardware models, device IP addresses, operating systems and versions, software, preferred languages, unique device identifiers, advertising identifiers, serial numbers, device motion data, and mobile network data.
8.8 Collection of data from other sources
Cito also collects data from other sources and may combine this collected data with other data in its possession. This includes:
- User feedback, such as reviews or customer satisfaction surveys commissioned by Cito, feedback, or compliments
- Insurance, vehicle, or financial service providers for carriers
- publicly accessible sources
- Marketing service providers
8.9 Data processing by AI-supported systems
We use AI-supported systems to optimize our processes and efficiently provide our contractually agreed services. Business inquiries and communications submitted to us by our customers or transport service providers may be processed automatically by our systems—particularly for the automated handling of incoming messages, the improvement of quote generation, and the support of precise matching between customers and transport service providers.
Processing is based on our legitimate interest pursuant to Art. 6(1)(f) GDPR in efficient business operations and the technical advancement of our services. In doing so, we ensure that the interests, fundamental rights, and freedoms of the data subjects are appropriately protected. Processing only occurs to the extent necessary for the stated purposes.
Where necessary for system training or the further development of the AI technology used, content may be processed in pseudonymized form. Actual anonymization only occurs if re-identification can be ruled out with reasonable effort. Any transfer to external service providers takes place exclusively in compliance with applicable data protection regulations and on the basis of appropriate contractual agreements.
To carry out the described processing activities, we use the following external service providers (data processors):
- Langfuse GmbH, Gethsemanestr. 4, 10437 Berlin, Germany, supports us in the analysis and logging of AI queries as well as in the management and optimization of our LLM application.
- Triple AI GmbH, Dolziger Straße 7, 10247 Berlin, Germany, performs software development tasks in connection with our AI application.
- OpenAI Ireland Ltd, 1st Floor, The Liffey Trust Centre, 117-126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland, processes the provided content to offer generative AI features (e.g., text processing) embedded in our application. Processing takes place on servers within the EU, provided this is technically feasible and contractually agreed upon.
Data subjects have the right to object at any time, on grounds relating to their particular situation, to the processing of their personal data which is based on Art. 6(1)(f) GDPR (Art. 21 GDPR). If an objection is raised, we will no longer process the personal data in question unless we can demonstrate compelling legitimate grounds for the processing.
There is no exclusively automated decision-making within the meaning of Art. 22 GDPR that produces legal effects concerning natural persons or similarly significantly affects them. Should this change in an individual case, affected persons will be informed separately, and the legally required protective measures will be implemented.
9. Payment data
For payment services, we use the provider Adyen N.V., PO Box 10095, 1001 EB, Amsterdam, Netherlands.
Credit card payments are handled by our service provider. We do not have access to this data ourselves. For the processing of the payment, the respective payment data is processed by Adyen. The legal basis for this is our legitimate interest pursuant to Art. 6 (1) sentence 1 (f) GDPR.
Providing your payment details when paying by credit card is necessary for the conclusion or performance of the contract. If you choose one of these payment methods and do not provide the payment details, it will not be possible to conclude or perform the contract.
We retain transaction confirmations for a maximum of 10 years after the completion of the respective transaction in order to fulfill our tax, business, and other legal obligations.
10. Contract data
For our contract management, we use the service "Fynk" (fynk GmbH, Molkereistraße 7/16, 1020 Vienna, Austria) for the automated creation and signing of contracts.
For this purpose, we process your first and last name, email address, IP address, digital signature, and other personal data contained in the contracts, such as your address. The email address is required to send the documents to be signed.
The legal basis for this is our legitimate interest pursuant to Art. 6 (1) sentence 1 (f) GDPR, in order to optimize our internal processes.
11. Sanctions list screenings
To comply with our export control obligations, we use the tool OpenSanctions (OpenSanctions Datenbanken GmbH, Schonensche Str. 43, 13189 Berlin). This software is used to perform sanctions list screenings of our contractual partners during registration and at regular intervals.
When contractual partners provide individual data, the following personal data is processed: company name and company address.
Purpose of data processing:
Data processing is carried out for the legally required sanctions list screening as part of export control. It enables us to identify potential risks and meet legal requirements for combating sanctions violations.
Legal basis:
The processing of personal data is based on our legitimate interest in accordance with Art. 6 (1) (f) GDPR. Our legitimate interest lies in fulfilling legal requirements for export control and preventing violations of sanctions regulations.
Storage period:
The data is deleted after the sanctions list screening is completed. If necessary, a re-screening is carried out at regular intervals.
12. Use of personal data
Cito collects and uses data to provide reliable and convenient deliveries. Cito also uses the collected data to:
- for customer satisfaction surveys
- for customer support
- for research and development
- to send marketing and non-marketing communications to users
- in connection with legal proceedings
Cito does not sell user personal data or share it with third parties for their direct marketing purposes, unless users have provided their consent. Cito does not sell user personal data or share it with third parties for their direct marketing purposes, unless users have provided their consent.
13. Purposes of data processing
Cito uses the collected data for purposes including:
13.1 Provision of services and features
Cito uses the data collected to provide, personalize, maintain, and improve products and services. This includes using the data to:
- Creating and updating user accounts
- Verifying the identity, background, and eligibility of carriers to work
- Facilitating transportation
- Processing payments for services
- Offering, obtaining, providing, or facilitating insurance, vehicle, billing, or financing solutions in connection with Cito services
- Tracking and sharing delivery status
- Performing internal operations necessary to provide our services, including troubleshooting software bugs and operational issues, conducting data analysis, testing, and research, and monitoring and analyzing usage and activity trends.
13.2 Security and protection
Cito uses personal data to ensure the security and integrity of its services and users. This includes:
- Vetting carriers before authorizing their use of Cito services and at subsequent intervals, including conducting background checks where permitted by law, to prevent the use of services by unsafe carriers.
- Using device, location, profile, usage, and other data to prevent, detect, and combat fraud or unsafe activities.
13.3 Customer Support
Cito uses the collected information to provide customer support, including:
- Forwarding inquiries to the appropriate customer support representative
- Investigating and addressing user concerns
- Monitoring and improving customer support responses and processes
- Generating billing summaries upon customer request
14. Storage Period
In principle, Cito only stores personal data for as long as is necessary to fulfill the (pre-)contractual or legal obligations for which Cito collected the data. Thereafter, the data will be deleted without undue delay, unless Cito still requires the data until the expiry of the statutory limitation period for evidentiary purposes regarding civil claims or due to statutory retention obligations.
The legal basis is generally Art. 6(1)(b) GDPR, as the processing is necessary for the performance of a contract and to provide proof of correct service delivery, in which you are (indirectly) involved. Furthermore, data processing is carried out to fulfill legal obligations in accordance with Art. 6(1)(c) GDPR in connection with contract fulfillment.
15. Your Rights
You have the right to request information about our processing of your personal data at any time. As part of this process, we will explain how your data is processed and provide you with an overview of the data we have stored about you.
If any data stored by us is incorrect or no longer up to date, you have the right to have it corrected. You can change all relevant information yourself via the profile settings on the marketplace.
You may also request the deletion of your data. If deletion is exceptionally not possible due to other legal requirements, the data will be restricted so that it is only available for that specific legal purpose. Depending on the sales organization's settings, details of your user profile may be stored until the respective processes have been assigned to new users within that sales organization.
You may also request the restriction of the processing of your data, for example, if you believe that the data we have stored is incorrect. You also have the right to data portability, which means that we will provide you with a digital copy of the personal data you have provided upon request.
To exercise the rights described here, you may contact us at any time using the contact details provided in the "Contact" section. This also applies if you wish to receive copies of safeguards as proof of an adequate level of data protection.
Furthermore, you have the right to object to data processing based on Art. 6(1)(e) or (f) GDPR or used for direct marketing. Finally, you have the right to lodge a complaint with the data protection supervisory authority responsible for us. You may exercise this right before a supervisory authority in the Member State of your habitual residence, your place of work, or the place of the alleged infringement. In Berlin, the competent supervisory authority is: Berlin Commissioner for Data Protection and Freedom of Information, Friedrichstr. 219, 10969 Berlin.
Right to Object
Where we process your data based on legitimate interests pursuant to Art. 6(1)(f) GDPR, you have the right under Art. 21 GDPR to object to the processing of your data by providing reasons relating to your particular situation that you believe outweigh our legitimate interests. If you object to data processing for direct marketing purposes, you have a general right to object, which we will implement without the need for you to specify any reasons.
If you wish to exercise your right to withdraw consent or object, a simple informal notification to the contact details provided above is sufficient.
16. Data Security
We maintain up-to-date technical measures to ensure data security, in particular to protect your personal data from risks during data transmission and from unauthorized access by third parties. These measures are adjusted in line with the current state of the art.
17. Changes
We update this privacy policy from time to time, for example, when we update our website or when legal or regulatory requirements change.
1. Data protection at a glance
General information
The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can be used to identify you personally. For detailed information on the subject of data protection, please refer to our privacy policy listed below this text.
Data collection on this website
Who is responsible for data collection on this website?
Data processing on this website is carried out by the website operator. You can find their contact details in the "Information on the Controller" section of this privacy policy.
How do we collect your data?
Some of your data is collected when you provide it to us. This may, for example, be data you enter into a contact form.
Other data is collected automatically or with your consent by our IT systems when you visit the website. This primarily includes technical data (e.g., internet browser, operating system, or the time the page was accessed). This data is collected automatically as soon as you enter this website.
What do we use your data for?
Some data is collected to ensure the website functions correctly. Other data may be used to analyze your user behavior. If contracts can be concluded or initiated via the website, the transmitted data will also be processed for contract offers, orders, or other inquiries.
What are your rights regarding your data?
You have the right to receive information about the origin, recipients, and purpose of your stored personal data at any time, free of charge. You also have the right to request the correction or deletion of this data. If you have provided consent for data processing, you may revoke this consent for the future at any time. Furthermore, you have the right to request the restriction of the processing of your personal data under certain circumstances. You also have the right to lodge a complaint with the competent supervisory authority.
You can contact us at any time with any further questions regarding data protection.
Analysis tools and third-party tools
When you visit this website, your browsing behavior may be statistically analyzed. This is primarily done using analysis tools.
Detailed information about these analysis tools can be found in the following privacy policy.
2. Hosting and Content Delivery Networks (CDN)
We host our website content with the following provider:
Webflow
The provider is Webflow, Inc., 398 11th Street, 2nd Floor, San Francisco, CA 94103, USA (hereinafter "Webflow"). When you visit our website, Webflow collects various log files, including your IP addresses.
Webflow is a tool for building and hosting websites. Webflow stores cookies or other recognition technologies that are necessary for the display of the site, for providing certain website functions, and for ensuring security (necessary cookies).
For details, please refer to Webflow's privacy policy: https://webflow.com/legal/eu-privacy-policy.
Webflow is used on the basis of Art. 6(1)(f) GDPR. We have a legitimate interest in ensuring our website is displayed as reliably as possible. If consent has been requested, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and § 25(1) TDDDG, insofar as the consent includes the storage of cookies or access to information on the user's device (e.g., device fingerprinting) within the meaning of the TDDDG. Consent can be revoked at any time.
Data transfer to the USA is based on the Standard Contractual Clauses of the European Commission. Details can be found here: https://webflow.com/legal/eu-privacy-policy.
The company is certified under the EU-U.S. Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. Further information can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/participant/6365.
Data Processing
We have entered into a data processing agreement (DPA) for the use of the aforementioned service. This is a contract required by data protection law, which ensures that the service processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.
Cloudflare
We use the service "Cloudflare." The provider is Cloudflare Inc., 101 Townsend St., San Francisco, CA 94107, USA (hereinafter "Cloudflare").
Cloudflare offers a globally distributed content delivery network with DNS. Technically, this involves routing the transfer of information between your browser and our website through Cloudflare's network. This enables Cloudflare to analyze traffic between your browser and our website and to act as a filter between our servers and potentially malicious traffic from the internet. In doing so, Cloudflare may also use cookies or other technologies to recognize internet users, which are used solely for the purposes described here.
The use of Cloudflare is based on our legitimate interest in providing our website as securely and error-free as possible (Art. 6(1)(f) GDPR).
Data transfer to the USA is based on the Standard Contractual Clauses of the European Commission. Details and further information regarding security and data protection at Cloudflare can be found here: https://www.cloudflare.com/privacypolicy/.
The company is certified under the EU-U.S. Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. Further information can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/participant/5666.
Data Processing
We have entered into a data processing agreement (DPA) for the use of the aforementioned service. This is a contract required by data protection law, which ensures that the service processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.
3. General Information and Mandatory Information
Privacy Policy
The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with statutory data protection regulations and this privacy policy.
When you use this website, various personal data are collected. Personal data is information that can be used to identify you personally. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this happens.
Please note that data transmission over the internet (e.g., when communicating via email) can have security vulnerabilities. Complete protection of data against access by third parties is not possible.
Information about the controller
The controller responsible for data processing on this website is:
Cito Transport Technologies GmbH
Cito Transport Technologies GmbH is registered in the commercial register of the Charlottenburg District Court (Berlin) under number HRB 231683 B.
CITO is neither willing nor obligated to participate in dispute resolution proceedings before a consumer arbitration board.
Managing Directors: Dr. Stock, Gregor; Shiromani, Sajeel
Registered office: Cito Transport Technologies GmbH, c/o Mindspace, Hausvogteiplatz 12, 10117 Berlin
Phone: 0800 693 6933
Email: kontakt@cito.ai
The controller is the natural or legal person who, alone or jointly with others, decides on the purposes and means of processing personal data (e.g., names, email addresses, etc.).
Storage duration
Unless a more specific storage period is stated in this privacy policy, your personal data will remain with us until the purpose for data processing no longer applies. If you assert a legitimate request for deletion or revoke your consent to data processing, your data will be deleted, provided we have no other legally permissible reasons for storing your personal data (e.g., tax or commercial retention periods); in the latter case, deletion will occur after these reasons cease to exist.
General information on the legal bases for data processing on this website
If you have consented to data processing, we process your personal data based on Art. 6(1)(a) GDPR or Art. 9(2)(a) GDPR, provided that special categories of data under Art. 9(1) GDPR are processed. In the event of explicit consent to the transfer of personal data to third countries, data processing also takes place based on Art. 49(1)(a) GDPR. If you have consented to the storage of cookies or access to information on your device (e.g., via device fingerprinting), data processing also takes place based on Section 25(1) TDDDG. Consent can be revoked at any time. If your data is required for the performance of a contract or for pre-contractual measures, we process your data based on Art. 6(1)(b) GDPR. Furthermore, we process your data if it is necessary to fulfill a legal obligation based on Art. 6(1)(c) GDPR. Data processing may also occur based on our legitimate interest under Art. 6(1)(f) GDPR. The specific legal bases applicable in each individual case are explained in the following sections of this privacy policy.
Recipients of personal data
We work with various external service providers as part of our business operations. In some cases, this requires the transfer of personal data to these external parties. We only share personal data with external parties when necessary for the performance of a contract, when we are legally obligated to do so (e.g., sharing data with tax authorities), when we have a legitimate interest in the transfer under Art. 6(1)(f) GDPR, or when another legal basis permits the transfer. When using data processors, we only share our customers' personal data based on a valid data processing agreement. In the case of joint processing, a joint processing agreement is concluded.
Revoking your consent to data processing
Many data processing operations are only possible with your express consent. You may revoke your consent at any time. The legality of the data processing carried out prior to the revocation remains unaffected by the revocation.
Right to object to data collection in special cases and to direct marketing (Art. 21 GDPR)
WHERE DATA PROCESSING IS BASED ON ART. 6(1)(E) OR (F) GDPR, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME, ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION, TO THE PROCESSING OF YOUR PERSONAL DATA; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE RESPECTIVE LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR PERSONAL DATA UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING WHICH OVERRIDE YOUR INTERESTS, RIGHTS, AND FREEDOMS, OR IF THE PROCESSING SERVES THE ESTABLISHMENT, EXERCISE, OR DEFENSE OF LEGAL CLAIMS (OBJECTION PURSUANT TO ART. 21(1) GDPR).
IF YOUR PERSONAL DATA IS PROCESSED FOR THE PURPOSE OF DIRECT MARKETING, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR THE PURPOSE OF SUCH MARKETING; THIS ALSO APPLIES TO PROFILING TO THE EXTENT THAT IT IS RELATED TO SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL SUBSEQUENTLY NO LONGER BE USED FOR THE PURPOSE OF DIRECT MARKETING (OBJECTION PURSUANT TO ART. 21(2) GDPR).
Right to lodge a complaint with the competent supervisory authority
In the event of violations of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work, or the place of the alleged infringement. The right to lodge a complaint is without prejudice to any other administrative or judicial remedies.
Right to data portability
You have the right to have data that we process automatically based on your consent or in fulfillment of a contract handed over to you or to a third party in a common, machine-readable format. If you request the direct transfer of the data to another controller, this will only be done to the extent that it is technically feasible.
Information, correction, and deletion
Within the framework of the applicable legal provisions, you have the right at any time to obtain free information about your stored personal data, its origin and recipients, and the purpose of the data processing, as well as a right to the correction or deletion of this data. You can contact us at any time regarding this or any other questions you may have about personal data.
Right to restriction of processing
You have the right to request the restriction of the processing of your personal data. You can contact us at any time to do so. The right to restriction of processing applies in the following cases:
- If you contest the accuracy of the personal data we have stored, we generally need time to verify it.to verify this. For the duration of this review, you have the right to request the restriction of the processing of your personal data.
- If the processinprocessing of your personal data was or is unlawful, you may request the restriction of data processing instead of deletion.
- If we no longer need your perno longer need your personal data, but you require it for the establishment, exercise, or defense of legal claims, you have the right to request the restriction of the processing of your personal data instead of its deletion.to request the data concerned.
- If you have filed an objection pursuant to Art. 21(1) GDPR, a balancing of your interests and our interests mustbe taken. As long as it is not yet determined whose interests prevail, you have the right to request the restriction of the processing of your personal data.
If you have restricted the processing of your personal data, this data—apart from its storage—may only be processed with your consent or for the establishment, exercise, or defense of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest of the European Union or a member state.
SSL or TLS encryption
For security reasons and to protect the transmission of confidential content, such as orders or inquiries that you send to us as the site operator, this site uses SSL or TLS encryption. You can recognize an encrypted connection by the fact that the browser's address line changes from "http://" to "https://" and by the lock symbol in your browser line.
When SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.
Objection to advertising emails
The use of contact data published within the scope of the legal notice obligation for the purpose of sending unsolicited advertising and information materials is hereby rejected. The operators of the pages expressly reserve the right to take legal action in the event of the unsolicited sending of advertising information, such as spam emails.
4. Data collection on this website
Cookies
Our websites use so-called "cookies." Cookies are small data packets that do not cause any damage to your device. They are stored on your device either temporarily for the duration of a session (session cookies) or permanently (permanent cookies). Session cookies are automatically deleted after your visit. Permanent cookies remain stored on your device until you delete them yourself or until they are automatically deleted by your web browser.
Cookies can be placed by us (first-party cookies) or by third-party companies (so-called third-party cookies). Third-party cookies enable the integration of certain services from third-party companies within websites (e.g., cookies for processing payment services).
Cookies have various functions. Many cookies are technically necessary because certain website functions would not work without them (e.g., the shopping cart function or the display of videos). Other cookies may be used to evaluate user behavior or for advertising purposes.
Cookies that are required to carry out the electronic communication process, to provide certain functions you have requested (e.g., for the shopping cart function), or to optimize the website (e.g., cookies to measure web traffic) (necessary cookies) are stored on the basis of Art. 6(1)(f) GDPR, unless another legal basis is specified. The website operator has a legitimate interest in storing necessary cookies for the technically error-free and optimized provision of its services. If consent to the storage of cookies and comparable recognition technologies has been requested, processing is based exclusively on this consent (Art. 6(1)(a) GDPR and § 25(1) TDDDG); consent can be revoked at any time.
You can configure your browser to notify you about the placement of cookies and only allow them in individual cases, exclude the acceptance of cookies for specific cases or in general, and activate the automatic deletion of cookies when closing the browser. If cookies are disabled, the functionality of this website may be limited.
If other cookies and services are used on this website, you can find details in this privacy policy.
Proprietary Cookie Consent Tool (UniversalCookie)
Our website uses its own cookie consent tool to manage the consents granted. When you first visit the website, a modal window will appear to collect your choices regarding functional, analytical, and marketing cookies.
To maintain these settings, a technically necessary cookie is stored on your device (managed via the UniversalCookie library). Your preferences are recorded in this cookie for a maximum period of 180 days.
The legal basis for the use of this consent management system is Art. 6(1)(c) GDPR, in order to fulfill the legal obligation to obtain and document consent in a data-protection-compliant manner.
Jetboost
We use Jetboost (provider: Jetboost.io) on this website. Jetboost is a service for providing dynamic filter, search, and sorting functions within our Webflow website.
When using the filter and search functions, technically necessary queries are performed to correctly display the filtered content to you. Temporary session data may be processed during this process.
The use of Jetboost is based on our legitimate interest in providing our content in a user-friendly and efficient manner, in accordance with Art. 6(1)(f) GDPR.
Leadfeeder / Dealfront (Marketing & B2B Analytics)
If you have provided your consent for marketing cookies via our cookie banner, we use the service Leadfeeder (provided by Dealfront / Liid Media Oy, Mikonkatu 17, 00100 Helsinki, Finland) on our website.
Leadfeeder captures the IP addresses of website visitors and compares them against a company database to identify which companies (B2B) are visiting our website. In doing so, Leadfeeder collects data on browsing behavior (e.g., pages viewed, time spent, origin of the visit). Private IP addresses and visits by private individuals are filtered out or anonymized whenever possible.
Processing is carried out exclusively on the basis of your consent in accordance with Art. 6(1)(a) GDPR and Section 25(1) TDDDG. You can adjust or withdraw your consent at any time with future effect via our cookie settings.
Microsoft Bookings
You have the option to schedule appointments with us on our website. We use Microsoft Bookings for appointment scheduling. The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland, https://learn.microsoft.com/de-de/microsoft-365/bookings/?view=o365-worldwide.
To book an appointment, please enter the requested data and your preferred date into the provided form. The data entered is used for planning, conducting, and, if necessary, following up on the appointment. Appointment data is stored for us on the servers of Microsoft Bookings, whose privacy policy you can view here: https://privacy.microsoft.com/de-de/privacystatement.
The data you enter remains with us until you request its deletion, withdraw your consent for storage, or the purpose for data storage no longer applies. Mandatory legal provisions—especially retention periods—remain unaffected.
The legal basis for data processing is Art. 6(1)(f) GDPR. The website operator has a legitimate interest in making appointment scheduling as simple as possible for prospective and existing customers. If consent has been requested, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG, provided that the consent includes the storage of cookies or access to information on the user's device (e.g., for device fingerprinting) as defined by the TDDDG. Consent may be withdrawn at any time.
Data transfer to the USA is based on the European Commission's standard contractual clauses. Details can be found here: https://learn.microsoft.com/de-de/compliance/regulatory/offering-eu-model-clauses.
The company is certified under the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. Further information can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/participant/6474.
5. Social Media
LinkedIn
This website uses elements of the LinkedIn network. The provider is LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland.
Whenever you access a page on this website that contains LinkedIn elements, a connection to LinkedIn's servers is established. LinkedIn is informed that you have visited this website with your IP address. If you click the LinkedIn "Recommend" button while logged into your LinkedIn account, LinkedIn can associate your visit to this website with your user account. Please note that as the provider of these pages, we have no knowledge of the content of the transmitted data or its use by LinkedIn.
This service is used based on your consent in accordance with Art. 6(1)(a) GDPR and Section 25(1) TDDDG. You may withdraw your consent at any time.
Data transfer to the USA is based on the EU Commission's standard contractual clauses. Details can be found here: https://www.linkedin.com/help/linkedin/answer/a1343190/datenubertragung-aus-der-eu-dem-ewr-und-der-schweiz?lang=en
Further information can be found in LinkedIn's privacy policy at: https://www.linkedin.com/legal/privacy-policy.
The company is certified under the "EU-U.S. Data Privacy Framework" (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/5448.
6. Proprietary services
Handling of applicant data
We offer you the opportunity to apply for a position with us (e.g., via email, post, or our online application form). Below, we inform you about the scope, purpose, and use of your personal data collected during the application process. We assure you that the collection, processing, and use of your data are carried out in accordance with applicable data protection laws and all other legal provisions, and that your data will be treated as strictly confidential.
Scope and purpose of data collection
When you submit an application, we process the associated personal data (e.g., contact and communication details, application documents, notes from interviews, etc.) to the extent necessary to decide on the establishment of an employment relationship. The legal basis for this is Section 26 of the German Federal Data Protection Act (BDSG) (initiating an employment relationship), Art. 6(1)(b) GDPR (general contract initiation), and—if you have provided consent—Art. 6(1)(a) GDPR. Consent can be withdrawn at any time. Your personal data will only be shared within our company with individuals involved in processing your application.
If your application is successful, the data you submitted will be stored in our data processing systems for the purpose of carrying out the employment relationship, based on Section 26 of the German Federal Data Protection Act (BDSG) and Art. 6(1)(b) GDPR.
As part of the application process, we may conduct an internet search regarding your person. This primarily includes Google searches, LinkedIn, and Xing. The legal basis for this type of processing is our legitimate interest in obtaining a comprehensive impression of publicly available information about you in accordance with Art. 6(1)(f) GDPR.
Data retention period
If we are unable to offer you a position, if you decline an offer, or if you withdraw your application, we reserve the right to retain the data you submitted for up to 6 months after the conclusion of the application process (rejection or withdrawal) based on our legitimate interests (Art. 6(1)(f) GDPR). Subsequently, the data will be deleted and physical application documents destroyed. Retention serves primarily as evidence in the event of a legal dispute. If it is evident that the data will be required after the 6-month period (e.g., due to an impending or pending legal dispute), deletion will only take place once the purpose for further retention no longer applies.
Longer retention may also occur if you have provided appropriate consent (Art. 6(1)(a) GDPR) or if legal retention obligations prevent deletion.
Inclusion in the applicant pool
If we do not offer you a position, there may be an opportunity to include you in our applicant pool. If you are included, all documents and information from your application will be transferred to the applicant pool so that we can contact you regarding suitable vacancies.
Inclusion in the applicant pool is based exclusively on your explicit consent (Art. 6(1)(a) GDPR). Providing consent is voluntary and has no bearing on the current application process. You may withdraw your consent at any time. In such cases, data will be irrevocably deleted from the applicant pool, provided there are no legal retention requirements to the contrary.
Data in the applicant pool will be irrevocably deleted no later than two years after consent is granted.