Privacy Policy
1. Privacy at a Glance
General Information
The following notices provide a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can be used to personally identify you. For detailed information on the subject of data protection, please refer to our privacy policy listed below this text.
Data Collection on This Website
Who is responsible for data collection on this website?
Data processing on this website is carried out by the website operator. You can find their contact details in the section 'Notice on the responsible party' in this privacy policy.
How do we collect your data?
Your data is collected in part by you providing it to us. This may be data that you enter in a contact form, for example.
Other data is collected automatically or with your consent when you visit the website by our IT systems. This is primarily technical data (e.g. internet browser, operating system, or time of page access). This data is collected automatically as soon as you enter this website.
What do we use your data for?
Some of the data is collected to ensure the error-free provision of the website. Other data may be used to analyse your user behaviour.
What rights do you have regarding your data?
You have the right at any time to obtain information free of charge about the origin, recipient, and purpose of your stored personal data. You also have the right to request the correction or deletion of this data. If you have given consent to data processing, you can revoke this consent at any time for the future. You also have the right, under certain circumstances, to request the restriction of the processing of your personal data. Furthermore, you have the right to lodge a complaint with the competent supervisory authority.
2. Data Controller
The data controller for data processing on this website is:
HaiSoTec GmbH
Freihofstraße 4
72401 Haigerloch
Deutschland
Telefon: 07474/319968-0
E-Mail: info@haisotec.de
The data controller is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data (e.g. names, e-mail addresses, etc.).
3. Data Collection on This Website
Contact Form
If you send us enquiries via the contact form, your details from the enquiry form, including the contact details you provide there, will be stored by us for the purpose of processing the enquiry and in case of follow-up questions.
The processing of this data is based on Art. 6(1)(b) GDPR if your enquiry is related to the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective handling of enquiries addressed to us (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR) if this has been requested.
The data you enter in the contact form will remain with us until you request deletion, revoke your consent to storage, or the purpose for data storage no longer applies (e.g. after your enquiry has been fully processed). Mandatory statutory provisions — in particular retention periods — remain unaffected.
Server Log Files
The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:
- Browser type and browser version
- Operating system used
- Referrer URL
- Hostname of the accessing computer
- Time of the server request
- IP address
This data is not merged with other data sources.
The collection of this data is based on Art. 6(1)(f) GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimisation of their website — for this purpose, the server log files must be collected.
4. Firebase Hosting, Cloud Functions & Cloud Storage (Google Cloud Platform)
This website uses services from Firebase, a platform for developing web applications by Google LLC (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland).
We use Firebase for hosting the website, Cloud Functions and Cloud Run services for server-side processing (among other things for contact form enquiries and sending emails), the Firestore database for storing content, and Google Cloud Storage for uploaded files. The following data may be processed in this context:
- IP address
- Browser information
- Timestamp of access
- Data from the contact form (name, e-mail, telephone, company, message)
- Content stored in Firestore (e.g. enquiries, registrations, applications) and files held in Cloud Storage (e.g. uploaded documents)
Usage is based on Art. 6(1)(f) GDPR. We have a legitimate interest in a reliable presentation and secure provision of our website.
Google is certified under the EU-US Data Privacy Framework. Further information on data protection at Firebase can be found at:
A data processing agreement pursuant to Art. 28 GDPR is in place with Google. Our Cloud Functions and server-side rendering run in the europe-west3 region (Frankfurt am Main). Transfers to third countries, in particular to the USA, cannot be entirely ruled out; they are based on the European Commission’s adequacy decision on the EU-US Data Privacy Framework, under which Google is certified.
5. Firebase Authentication
For protected areas of our website (e.g. reseller portal, administration area), we use Firebase Authentication, an authentication service provided by Google. This service enables secure login and management of user accounts.
The following data may be processed:
- E-mail address
- Password (encrypted/hashed)
- Login timestamps and login history
- IP address at login
Processing is based on Art. 6(1)(b) GDPR (performance of a contract) for registered users, as well as Art. 6(1)(f) GDPR (legitimate interest) in securing protected areas.
6. Reseller Registration and Document Upload
If you register as a sales partner via our reseller portal, we collect the information required to review and initiate the partnership. The data is stored in our Firestore database; documents you upload are held in Google Cloud Storage (Firebase Storage).
The following data is processed:
- Company data: company name, legal form, VAT identification number, address, country and website
- Company contact details: invoicing email address and telephone number
- Contact person details: first and last name, email address, telephone number and role within the company
- The email address used for subsequent sign-in (see section 5)
- The proof of business registration you upload (e.g. trade licence or commercial register extract)
- Time of registration and the approval status of your application
Uploaded documents are not publicly accessible — access requires being signed in, and the storage path is not published. Your application is reviewed by the members of staff responsible for it.
Processing is based on Art. 6(1)(b) GDPR (performance of pre-contractual measures and of the partner agreement). Verifying the proof of business registration additionally serves our legitimate interest in preventing fraudulent registrations (Art. 6(1)(f) GDPR).
If no partnership is established, we delete the registration data including the uploaded document no later than six months after the review is concluded. Where a partnership exists, the periods set out in section 17 apply.
7. Google Tag Manager
This website uses Google Tag Manager (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). Tag Manager is an administration tool that lets us integrate and control the services used on this website — such as analytics and conversion tags — from one place.
Tag Manager itself sets no cookies and creates no user profiles of its own. It does, however, load a script from a Google server on every page view. In doing so your IP address is transmitted to Google, because it is technically required for delivery.
The container is loaded on every page. Whether the services it manages actually collect data depends on your choice in the cookie banner: we use Google Consent Mode v2, which defaults to "denied". Without your consent, no analytics or advertising cookies are set through Tag Manager. You can change your choice at any time via the cookie banner.
The legal basis for loading the container is Art. 6(1)(f) GDPR (legitimate interest in a consistent and maintainable technical integration of our website services). The analytics and advertising services triggered through Tag Manager are based on your consent under Art. 6(1)(a) GDPR (see sections 8 and 9).
Further information can be found in the Google Tag Manager terms of service and in Google’s privacy policy:
8. Firebase Analytics / Google Analytics
This website uses Firebase Analytics (linked with Google Analytics), a web analytics service provided by Google. We use Google Consent Mode v2: the Google tag loads on every page but defaults to 'consent denied' mode. In this mode no cookies are set; Google only receives aggregated, cookieless signals without a client ID and without personal identifiers, used for statistical reach modelling (legal basis: Art. 6(1)(f) GDPR — legitimate interest in anonymous measurement). Only after your express consent via the cookie banner are cookies set and full analytics data collected.
When analytics is enabled, the following data may be processed:
- Page views and time spent on pages
- Device and browser information
- Approximate location (based on IP address, which is subsequently anonymised)
- Interactions with the website (e.g. clicks, form submissions)
Processing is based on your consent pursuant to Art. 6(1)(a) GDPR. You can revoke your consent at any time via the cookie banner. Data already collected will remain stored until it expires automatically.
Further information on data protection at Google Analytics can be found at:
9. Google Ads Conversion Tracking
We use Google Ads conversion tracking (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) to measure the effectiveness of our online advertising. As with Firebase Analytics, we use Google Consent Mode v2. Without your consent, no cookies are set and no GCLID-based attribution is performed; Google only receives an aggregated, cookieless signal when the confirmation page /kontakt/danke is loaded, used for statistical modelling of anonymous conversion rates (legal basis: Art. 6(1)(f) GDPR — legitimate interest in anonymous measurement). Only after your express consent is full conversion attribution via the Google Click ID (GCLID) performed.
If you click on one of our Google ads and subsequently submit a request via the contact form, the following data may be transmitted to Google:
- A unique click identifier (Google Click ID / GCLID) set when the ad is clicked
- Timestamp of the conversion (contact-form submission)
- Device and browser information
- The fact that the confirmation page /kontakt/danke was loaded
No contents of the contact form (name, email, message) are transmitted to Google. Google Ads only receives the information that a conversion occurred and the click identifier required to attribute it to the ad. This data is evaluated by Google in pseudonymous form.
Processing is based on your consent pursuant to Art. 6(1)(a) GDPR. You can revoke your consent at any time via the cookie banner. Further information on data protection at Google Ads can be found at:
10. Consent Record (Cookie Banner)
When you make a choice via our cookie banner (Accept all, Decline, or save individual categories), we log this choice in our Firestore database to fulfil our obligation to demonstrate consent under Art. 7(1) GDPR.
The following data is stored:
- Timestamp of your choice (server-side)
- Your choice per category (analytics / advertising — each allowed or denied)
- Banner version (to link the applicable disclosure text)
- Your browser language (e.g. "de-DE") and user-agent string (browser and device information)
We do not store your IP address or any direct user identifier in this log. The records cannot easily be linked to you personally; they serve solely as statistical proof of consent vis-à-vis supervisory authorities.
Legal basis: Art. 6(1)(c) GDPR in conjunction with Art. 7(1) GDPR (legal obligation to demonstrate validly obtained consent). Records are automatically deleted 3 years after collection (limitation period pursuant to § 195 BGB).
11. Google reCAPTCHA v3
We use Google reCAPTCHA v3 (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) to protect our forms from automated requests (spam/bots). reCAPTCHA analyses the behaviour of website visitors based on various characteristics to distinguish between human users and automated programs.
The following data may be transmitted to Google:
- IP address
- Referrer URL
- Information about the operating system and browser
- Mouse movements, keyboard inputs, and time spent on the page
Usage is based on Art. 6(1)(f) GDPR. We have a legitimate interest in protecting our website from abusive automated use and spam.
Further information can be found in Google's privacy policy and terms of service:
12. Fonts (Locally Hosted)
This website uses the 'Orbitron' and 'IBM Plex Mono' fonts from Google Fonts. The fonts are installed locally on our server and are not loaded from external servers (e.g. Google servers). Therefore, no connection to Google servers is established, and no data is transmitted to Google.
Further information about Google Fonts can be found at:
13. Electronic Signature & IP Collection
On our website, we offer the ability to sign documents (e.g. quotations, contracts) electronically. To strengthen the evidentiary value of the electronic signature, additional data is collected during the signing process.
The following data is processed during the signature process:
- Your IP address (determined via the service ipify.org)
- Timestamp of the signature
- The signature data itself (digital image of the signature)
To determine your IP address, the external service ipify (https://www.ipify.org) is used. A request is sent to ipify's servers, whereby your IP address is transmitted to this service. The determined IP address is then stored in the signed document.
Processing is based on Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(f) GDPR (legitimate interest in the verifiability of electronic signatures).
14. Email Communication
If you contact us by e-mail or via the contact form, the information you provide (e-mail address, name, telephone number, message) will be stored by us for the purpose of processing the enquiry and in case of follow-up questions.
Processing is based on Art. 6(1)(b) GDPR if your enquiry is related to the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective handling of enquiries addressed to us (Art. 6(1)(f) GDPR).
The data will be deleted as soon as it is no longer required for the purpose of its collection or you request deletion.
15. Job Applications
On our careers page we invite applications by email to bewerbung@haisotec.de. We process incoming applications in order to carry out the recruitment procedure and store them in our internal applications area.
In doing so we process the data you provide, in particular:
- Contact details: name, email address, telephone number and postal address
- Application documents: cover letter, CV, references and other attachments
- Information on qualifications and career history
- Correspondence during the procedure and internal notes on its status
Application documents and correspondence are stored in our Firestore database and in Google Cloud Storage. Access is limited to the people involved in the recruitment procedure.
The legal basis is Section 26(1) BDSG in conjunction with Art. 88 GDPR and Art. 6(1)(b) GDPR (decision on entering into an employment relationship). If you voluntarily provide special categories of personal data — for example information on a disability — that processing is based on Section 26(3) BDSG.
If no employment relationship is entered into, we delete your application documents no later than six months after the procedure ends. This period accounts for the deadlines for asserting claims under the German General Equal Treatment Act (AGG). If we are to keep your documents beyond that for future positions, we obtain your separate consent under Art. 6(1)(a) GDPR, which you may withdraw at any time.
16. Browser Extension 'HaiSoTec Zeiterfassung'
For HaiSoTec Zeiterfassung, our time-tracking system, we offer a browser extension for Google Chrome and other Chromium browsers. It shows the running timer in the toolbar, lets you start, pause, resume and stop your own time tracking, and reminds you of the statutory break and of the end of the working day. The extension is not tied to a fixed address: it works exclusively with the time-tracking system whose address you enter yourself when you first start it. Until you have entered an address, the extension accesses no website at all.
In the storage of your browser profile, that is on your own device, the extension keeps:
- The address of the time-tracking system you connected to, together with its publicly available configuration document (customer, environment, Firebase configuration)
- The user ID and the display name or email address of the signed-in account — solely to display them in the extension window
- The existing sign-in (the access token of your time-tracking system) and an identifier for the extension session, which lets you revoke access from within the time-tracking system
- The point in time at which the connection was established
- The most recently retrieved timer state (status, start time, daily totals) — only for the duration of the browser session
- Which reminders have already been shown on the current day
The extension stores this information solely in your browser profile; it transmits none of it to any destination other than the time-tracking system you chose. It neither stores a password nor gets to see one: sign-in runs through the usual sign-in page of your time-tracking system in a separate browser window, and all the extension receives back is a one-time pairing code that it exchanges for an access token.
In operation, the extension communicates exclusively with the time-tracking system you specified and its Google Cloud services (googleapis.com, cloudfunctions.net). Once a minute it retrieves the signed-in account's time entries for the current day (start, end, entry type and duration) as well as the daily total; your clicks on start, pause, resume and stop are passed on to the time-tracking system. Whether an entry is permitted is decided by the time-tracking system — the extension books nothing on its own. Reminders are calculated on your device from the retrieved times; the notifications appear only there.
The extension contains no analytics, tracking or advertising functions. It reads neither your browsing history nor open tabs nor the content of other websites, and it passes no data to third parties. Fonts and icons are contained in the package and are not loaded from external servers.
The controller for the processing within the time-tracking system itself is its operator, as a rule your employer. The extension opens no separate connection to us: apart from the time-tracking system you entered yourself, it contacts no HaiSoTec GmbH server at all. Where we operate that time-tracking system on your employer's behalf, we process the data arising there solely as a processor under an agreement pursuant to Art. 28 GDPR. Installation and updates of the extension run through the Chrome Web Store; Google is responsible for the processing that takes place there.
The legal basis for storing and reading the information listed above on your terminal equipment is Section 25(2) no. 2 TDDDG, because it is strictly necessary for the function you have expressly requested; the subsequent processing is based on Art. 6(1)(b) GDPR (provision of the function you requested). You can disconnect at any time in the extension window and additionally revoke access in your time-tracking system under 'Verbundene Erweiterungen' (connected extensions). Removing the extension deletes all locally stored information listed above.
17. Retention Periods and Deletion
Unless an explicit period is stated in the preceding sections, we store personal data only for as long as is necessary for the respective purpose. In overview:
- Contact enquiries: until your enquiry has been dealt with conclusively; beyond that only where statutory retention obligations apply
- Job applications: six months after the procedure ends (see section 15)
- Reseller registrations without a contract: six months after the review is concluded (see section 6)
- Consent records: three years from collection (see section 10)
- Signature transactions and the associated evidence data: for the duration of the contractual relationship and the subsequent statutory retention periods
- Reseller portal accounts: until the account is deleted or the business relationship ends
- Browser extension: the information kept locally in your browser remains until you disconnect or remove the extension (see section 16)
Statutory retention obligations remain unaffected: commercial letters must be retained for six years under Section 257 HGB, accounting-relevant records for ten years under Section 147 AO. For the duration of those periods we restrict processing; once they expire, the data is deleted.
18. Your Rights
You have the following rights regarding your personal data:
Right of Access
You have the right to obtain information about your personal data processed by us (Art. 15 GDPR).
Right to Rectification
You have the right to request the rectification of inaccurate or the completion of your personal data stored by us (Art. 16 GDPR).
Right to Erasure
You have the right to request the erasure of your personal data stored by us, unless processing is necessary for exercising the right of freedom of expression and information, for compliance with a legal obligation, for reasons of public interest, or for the establishment, exercise, or defence of legal claims (Art. 17 GDPR).
Right to Restriction of Processing
You have the right to request the restriction of the processing of your personal data (Art. 18 GDPR).
Right to Data Portability
You have the right to receive your personal data that you have provided to us in a structured, commonly used, and machine-readable format and to transmit this data to another controller (Art. 20 GDPR).
Right to Object
You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you (Art. 21 GDPR).
Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority. As a rule, you may contact the supervisory authority of your usual place of residence or workplace or of our registered office.
The competent supervisory authority for data protection matters is the state data protection commissioner of the federal state in which our company is based.
19. SSL / TLS Encryption
This site uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content, such as enquiries you send to us as the site operator. You can recognise an encrypted connection by the fact that the address line of the browser changes from 'http://' to 'https://' and by the lock symbol in your browser bar.
When SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.
20. Changes to This Privacy Policy
We reserve the right to amend this privacy policy from time to time so that it always complies with current legal requirements or to implement changes to our services in the privacy policy, e.g. when introducing new services. The new privacy policy will then apply to your next visit.
