Privacy policy

Thank you for visiting our website. The protection of your personal data is important to us. Personal
data are information about personal or factual circumstances of an identified or identifiable natural
person. This includes, for example, name, e-mail address, login data, etc.

As personal data enjoys special legal protection, we only collect it to the extent necessary for the
provision of our website and the provision of our services.

Our data protection practices comply with the statutory regulations, in particular those of the so
called ‘Bundesdatenschutzgesetz’ (BDSG), the General Data Protection Regulation (GDPR) and all
other relevant data protection regulations.

So that you know at all times how and which personal data we process, you will be informed below
about the individual processing purposes.

Controller within the meaning of Art. 4 para. 7 GDPR

The Controller for data processing is

m3connect GmbH
Pascalstraße 18
52076 Aachen

Phone: +49 241 980986 0
Mail: info@m3connect.de

CEO: Emilijo Dragas

Name and address of the data protection officer of m3connect GmbH:
Raphaela Weise
Pascalstraße 18
52076 Aachen

dsb@m3connect.de

Server log files

Our web server automatically collects and stores information in so-called server log files, which your
browser automatically transmits to us.
These are:

  • Browser type and browser version
  • Operating system used
  • Referrer URL
  • Host name of the accessing computer
  • The IP address of the retrieval device
  • Time of the server request

This data cannot be assigned to specific persons. This data is not merged with other data sources. We
reserve the right to check this data retrospectively if we become aware of specific indications of
unlawful use. The storage period for server log files is 3 months.

We process this data in accordance with Art. 6 para. 1 lit. f GDPR on the basis of legitimate interest.
Our legitimate interest is to ensure the achievement of the purpose described below.

  • Logging is carried out to maintain the compatibility of our website for as many visitors as
    possible and to combat misuse and troubleshooting. For this purpose, it is necessary to log
    the technical data of the accessing computer in order to be able to react as early as possible
    to display errors, attacks on our IT systems and/or errors in the functionality of our website.
    In addition, we use the data to optimize the website and to generally ensure the security of
    our IT systems.

The aforementioned technical data is deleted as soon as it is no longer required to ensure the
compatibility of the website for all visitors, but no later than 3 months after accessing our website.

Registration / Login

In order to use Conn4, you must be registered in advance. Registration is carried out exclusively by
m3connect. Independent registration is not possible. You will first be created as a user by m3connect
with your surname, first name and e-mail address. You will then receive a registration e-mail. This
gives you the opportunity to log in with your e-mail address. Once you have registered, you can log in
at any time via the Conn4 portal using your access data. It is also possible for you to register
authorized persons from your company in the portal.
Registration takes place on the basis of the contract pursuant to Art. 6 para. 1 lit. b GDPR, which we
have concluded with you in advance. Your data will not be passed on. We process this data for as
long as you use the service, and the contractual relationship exists.

Cookies

Technically necessary

We use cookies on this website. Cookies are text files that are stored in the Internet browser or by
the Internet browser on the user's computer system. When a user accesses a website, a cookie may
be stored on the user's operating system. This cookie contains a characteristic string of characters
that enables the browser to be uniquely identified when the website is called up again.

We use cookies to make our website more user-friendly. Some elements of our website require that
the accessing browser can be identified even after a page change.

The following data is stored and transmitted in the cookies:

  • Log-in information
  • Use of website functions

The purpose of using technically necessary cookies is to simplify the use of websites for users. Some
functions of our website cannot be offered without the use of cookies. For these, it is necessary for
the browser to be recognized even after a page change. These purposes also constitute our
legitimate interest in the processing of personal data in accordance with Art. 6 para. 1 lit. f GDPR.
The user data collected by technically necessary cookies is not used to create user profiles.
Cookies are stored on the user's computer and transmitted from there to our website. As a user, you
therefore have full control over the use of cookies. You can deactivate or restrict the transmission of
cookies by changing the settings in your Internet browser. Cookies that have already been saved can
be deleted at any time. This can also be done automatically. If cookies are deactivated for our
website, it may no longer be possible to use all functions of the website to their full extent.

Consent with consent banner

We use a consent banner on our website so that we can obtain your consent to the storage of
cookies on your end device or to the use of certain technologies and to document this in compliance
with data protection regulations.

When you visit our website, a connection is established
to our server in order to obtain your consent to the use of cookies and to be able to assign the
consents given or their revocation. Among other things, information about your IP address (masked),
the time and a consent key are processed. The data collected in this way is stored until the purpose
for data storage no longer applies. The consent banner is used to obtain the legally required consent
for the use of cookies. This is done in accordance with Art. 6 para. 1 lit. c GDPR.

Matomo

This website uses Matomo (formerly Piwik), an open source software for the statistical analysis of
visitor access. The provider of the Matomo software is InnoCraft Ltd, 150 Willis St, 6011 Wellington,
New Zealand. Matomo uses cookies that enable your use of the website to be analyzed. The
information generated by the cookie about your use of the website is stored on a server in Germany.
We have configured Matomo so that no profiling takes place.

We use Matomo to statistically evaluate visitor access in order to adapt and improve the content on
our website.

The following data is collected:

  • IP address
  • Date and time of the page visit
  • Actions per visit
  • Bounce rate
  • Average visit time
  • Country
  • Browser

We process this data on the basis of your consent in accordance with Art. 6 para. 1 lit. a GDPR in
conjunction with. § 25 para. 1 TTDSG.
This service may transfer the collected data to another country. Please note that this service may
transfer data outside the European Union and the European Economic Area and to a country that
does not offer an adequate level of data protection. Recipients of the data are technical service
providers who ensure the maintenance and operation of our website. They work for us as
contractors and corresponding contractual arrangements have been concluded.
The data is deleted as soon as it is no longer required for our recording purposes. In our case, this
happens automatically after 90 days. The IP address is anonymized immediately after processing and
before it is stored by truncating the last 2 bytes. You have the option of preventing the installation of
cookies by changing the settings of your browser software. We would like to point out that if you do
so, you may no longer be able to use all the functions of this website.
On the one hand, you can completely prevent the storage of cookies in your browser. However, this
means that you may no longer be able to use some functions of our website that require
identification. On the other hand, you can activate the "Do-not-track" setting in your browser. You
can adjust the cookie settings on our website at any time. To do this, you will find the "Change cookie
settings" button in the introduction.

You can find more information on the privacy settings of the Matomo software at the following link:
https://matomo.org/docs/privacy-how-to/

Your rights as a data subject

In particular, you have the following rights vis-à-vis us:

  • Right of access about your stored personal data in accordance with Art. 15 GDPR
  • Right to rectification if the stored data concerning you is incorrect, outdated or otherwise
    inaccurate in accordance with Art. 16 GDPR
  • Right to erasure if the storage is unlawful, the purpose for the processing has been fulfilled
    and the storage is no longer necessary or you have withdrawn your consent to the
    processing of certain personal data in accordance with Art. 17 GDPR
  • Right to restriction of processing if one of the conditions set out in Art. 18 para. 1 lit. a to d
    GDPR is met pursuant to Art. 18 GDPR
  • Right to data portability of the personal data concerning you that you have provided in
    accordance with Art. 20 GDPR
  • Right to lodge a complaint pursuant to Art. 77 GDPR

You can contact a supervisory authority at any time with a complaint, e.g. the competent supervisory
authority in the federal state of your place of residence or the authority responsible for us as the
controller.
A list of supervisory authorities (for the non-public sector) with addresses can be found at:
https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html

Objection and Withdrawal

Withdrawal of consent

If the processing of your personal data is based on consent, this consent can be withdrawn at any
time with effect for the future. No disadvantages arise from the revocation. The revocation
can be made either in writing by e-mail to dsb@m3connect.de, stating which consent you are
revoking. You can make changes to your consent at any time in relation to the cookie selection made
in the consent banner under "Cookie settings" (in the footer).

Right to object to Art. 21 GDPR

If the processing of your personal data is necessary for the performance of a task carried out in the
public interest pursuant to Art. 6 para. 1 lit. e GDPR or if your personal data is processed to safeguard
legitimate interests within the meaning of Art. 6 para. 1 lit. f GDPR, you have the right to object to
this processing pursuant to Art. 21 para. 1 GDPR on grounds relating to your particular situation.
This also applies to profiling based on this provision within the meaning of Art. 4 No. 4 GDPR.
If you object, we will no longer process your personal data unless we can demonstrate compelling
legitimate grounds for the processing which override your interests, rights and freedoms, or the
processing serves the establishment, exercise or defense of legal claims.

You can object to processing for direct marketing purposes in accordance with Art. 21 para. 2 GDPR
at any time with effect for the future without giving reasons. To exercise your right to object, simply
send an informal message to dsb@m3connect.de stating which data processing you object to.

SSL and TLS encryption

We use SSL or TLS encryption for our website for security reasons and to protect the transmission of
confidential content. You can recognize an encrypted connection by the fact that the address line of
the browser changes from "http://" to "https://" and by the lock symbol in your browser line.

Data security and data protection, communication by e-mail

When you contact us by email, your email signature is one of the ways in which personal data is
processed. As a rule, your name, address, e-mail address, telephone number, date and time are
recorded.

We need to collect this data in order to process your request. The legal basis for processing the data
is the legitimate interest in responding to your request in accordance with Art. 6 para. 1 lit. f GDPR.
Your data is protected by technical and organizational measures; this applies to the collection,
storage and processing so that it is not accessible to third parties. In the case of unencrypted
communication by e-mail, we cannot guarantee complete data security on the transmission path to
the IT systems, so we recommend encrypted communication or the postal service for information
with a high need for confidentiality.
In principle, no personal data is transferred to a third country. However, we use Microsoft services
(Temas, Outlook) for communication. A transfer can therefore not be completely ruled out. You can
find more information about Microsoft at:
https://privacy.microsoft.com/de-de/privacystatement or
https://www.microsoft.com/de-de/trust-center/privacy/gdpr-faqs?market=de.

The company is certified in accordance with the "EU-US Data Privacy Framework" (DPF). The DPF is
an agreement between the European Union and the USA, which guarantees compliance with
European data protection standards for data processing in the USA. Every company certified in
accordance with the DPF undertakes to comply with these data protection standards.

Further information on this can be obtained from the provider at the following link:
https://www.dataprivacyframework.gov/s/participant-search.

Changes to our privacy policy

We reserve the right to adapt this privacy policy so that it always complies with current legal
requirements or to implement changes to our services in the privacy policy, e.g. when introducing
new services. The new privacy policy will then apply to your next visit.