We, CUREosity GmbH, are pleased about your interest in our website and would like to make your stay on it as pleasant as possible. The protection of your privacy is very important to us.
Below we inform you about the handling of your personal data and your rights in this regard.
A. Verantwortliche Stelle / Datenschutzbeauftragte
For the processing of your personal data in connection with our website, we are "controller" within the meaning of Art. 4 No. 7 GDPR.
You can contact us as follows:
Tel.: +49 211 822 046 - 26
You can contact our data protection officer by email to firstname.lastname@example.org.
The web service Pathmonk is used on this website. Pathmonk captures information about the user's device, their IP address, geographic location, language settings, which website a user has come to our websites from and user interactions such as mouse movements, clicks and keyboard input. In providing its services, Pathmonk collects personal data from users who visit our websites. Pathmonk uses this personal information to draw conclusions about the user's personal preferences and to personalize the user's web experience, for example by displaying Micro-Experiences. If you contact us by using our contact forms or Micro-Experiences, Pathmonk will store the information you provide us with (your name and email address or telephone number) to respond to your query. We will erase the data we collected on this basis when it is no longer required or we will restrict the processing where we have to comply with statutory retention requirements. You can find Pathmonk’s privacy statement by following this link.
We host our website at Wix.com Ltd, 40 Namal Tel Aviv St, Tel Aviv 6350671, Israel (hereinafter "WIX").
WIX is a tool for creating and hosting websites. When you visit our website, WIX is used to analyze user behavior, visitor sources, the region of website visitors and visitor numbers. WIX stores cookies on your browser, which are necessary for the display of the website and to ensure security (necessary cookies).
The data collected through WIX may be stored on various servers around the world. The servers of WIX are located in the USA, among other places.
For details, please refer to the data protection declaration of WIX: https://de.wix.com/about/privacy.
According to WIX, data transfer to the USA and other third countries is based on the standard contractual clauses of the EU Commission or comparable guarantees according to Art. 46 DSGVO. Details can be found here: https://de.wix.com/about/privacy-dpa-users.
The use of WIX is based on Art. 6 para. 1 lit. f DSGVO. We have a legitimate interest in the most reliable presentation of our website. Insofar as a corresponding consent has been requested, the processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a DSGVO and § 25 para. 1 TTDSG, insofar as the consent includes the storage of cookies or access to information in the user's terminal device (e.g. device fingerprinting) as defined by the TTDSG. The consent can be revoked at any time.
Data processing agreement
We have concluded an order processing agreement (AVV) with the above-mentioned provider. This is a contract required by data protection law, which ensures that this provider only processes the personal data of our website visitors in accordance with our instructions and in compliance with the GDPR.
WIX Plugin "vcita"
For appointments we use the WIX plugin "vcita".
Vcita a tool for creating and hosting websites. When you visit our website, Vcita is used to analyze user behavior, visitor sources, region of website visitors and visitor numbers. Vcita stores cookies on your browser, which are necessary for the display of the website and to ensure security (necessary cookies).
The data collected through Vcita may be stored on various servers around the world. Vcita's servers are located in the USA, among other places.
According to Vcita, data transfer to the USA and other third countries is based on the standard contractual clauses of the EU Commission or comparable guarantees according to Art. 46 DSGVO. Details can be found here: https://www.vcita.com/wp-
The use of Vcita is based on Art. 6 (1) lit. f DSGVO. We have a legitimate interest in ensuring that our website is presented as reliably as possible. Insofar as a corresponding consent has been requested, the processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a DSGVO and § 25 para. 1 TTDSG, insofar as the consent includes the storage of cookies or access to information in the user's terminal device (e.g. device fingerprinting) as defined by the TTDSG. The consent can be revoked at any time.
B. Nature and scope of data processing
I. Processing of access data
You can browse our website without having to provide any personal information. We only store access data in so-called server log files. This also includes your IP address. This can be a personal data, because under certain circumstances it is possible to find out the identity of the owner of the Internet access used by additional information from the respective Internet provider. This data is evaluated by us exclusively for the purpose of secure and trouble-free operation of the website and stored for a period of seven days.
The processing of the IP address is based on our legitimate interest within the meaning of Art. 6 para. 1 lit. f) GDPR, as this enables communication between our server and your terminal device.
II. Data processing for handling your requests
We process the personal data that you provide to us when you contact us, in particular by email or via our contact form.
For inquiries via our contact form, this is obligatory your name, your e-mail address and such data that result from your message to us. Voluntary additional information is possible regarding your telephone number and address as well as the subject.
This data is only processed for correspondence with you and for the purpose for which you have provided us with the data in the context of this communication, such as to process your inquiry or to contact you at your request. In this case, the processing of personal data is carried out with your consent and is permissible pursuant to Art. 6 para. 1 lit. a) GDPR. As far as the processing is necessary for the performance of a contract with you or for the implementation of pre-contractual measures upon your request, the legal basis is Art. 6 para. 1 lit. b) GDPR.
When you submit the form, we also process your IP address. The legal basis for this is our legitimate interest within the meaning of Art. 6 para. 1 lit. f) GDPR to enable communication between our server and your terminal device.
After your request has been completely dealt with, your data will be deleted unless you have expressly consented to further use of your data or we are required by law to retain it.
III. Processing of applicant data
On our website we offer you the possibility to apply for a job with us by email ("email@example.com").
In doing so, we process the data that you yourself provide to us in the course of the application process. This involves at least:
Name and first name
Other information and documents, such as cover letter, curriculum vitae, and certificates
Your data will only be used to decide whether to establish an employment relationship with you and will only be forwarded internally to the relevant contact persons who will decide on filling the position you have applied for. If you do not apply for a specific job posting (unsolicited application), we will use your data for all vacancies that match your requirements at the time of application.
We are entitled to this data processing pursuant to Art. 88 GDPR in conjunction with § 26 para. 1 sentence 1 of the Federal German Data Protection Act (BDSG). The processing of your email address is based on our legitimate interest within the meaning of Art. 6 para. 1 lit. f) GDPR to offer you the opportunity to apply and to be able to contact you at any time. Your legitimate interests do not conflict with this.
We delete your data after completion of the application process and a retention period of 6 months. Any storage beyond this period will only take place if you have given your express consent. In this case, your data will be deleted by us after 2 years, unless you request us to delete it beforehand.
Cookies are text files that contain data from visited websites or domains and are stored by a browser on your terminal device. A cookie is primarily used to store certain information about a user, such as language settings or a log-in status, during or after a users' visit within an online offer.
You can withdraw your consent at any time with effect for the future.
V. Social Plugins
On our website, we use so-called social plugins of third-party platforms named below to enable the sharing of posts and videos:
service provider: Facebook Ireland Ltd, Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland; parent company: Facebook, 1 Hacker Way, Menlo Park, CA 94025, USA
service provider: Twitter International Company, One Cumberland Place, Fenian Street, Dublin 2 D02 AX07, Ireland; parent company: Twitter Inc, 1355 Market Street, Suite 900, San Francisco, CA 94103, USA
service provider: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Irland
Dienstanbieter: New Work SE, Am Strandkai 1, 20457 Hamburg, Deutschland
In order to increase the protection of your data when visiting our website, the plugins are integrated into the site using the so-called ["2-click solution" / "Shariff solution" ]. This integration ensures that when you call up a page of our website that contains such plugins, no connection is yet established with the servers of the respective providers. Only when you activate the plugins and thus give your consent to the transmission of data, does your browser establish a direct connection to the servers of the activated providers. The content of the respective plugin is then transmitted directly to your browser by the associated provider and integrated into the page. By integrating the plugins, the providers receive the information that your browser has called up the corresponding page of our website, even if you do not have a profile with the corresponding provider or are not currently logged in to the service of the respective provider. This information (including your IP address) is transmitted by your browser directly to a server of the respective provider, possibly in non-EU countries, and stored there.
If you are logged in to one of the providers' services, the providers can directly assign your visit to our website to your profile/account of the respective provider. If you interact with the plugins, for example by clicking the "Like" button or the "Tweet" button, the corresponding information is also transmitted directly to a server of the providers and stored there. The information will also be published on the social network or on your social media account and displayed there to your contacts. If you do not want the providers to directly assign the data collected via our website to your profile/account in the respective service, you must log out of the corresponding service before activating the plugins.
The purpose and scope of the data collection and the further processing and use of the data by the providers, as well as your rights in this regard and setting options for protecting your privacy, can be found in the providers' data protection notices.
The legal basis for this type of processing is your consent within the meaning of Art. 6 para. 1 lit. a) GDPR.
Note: If you declare your consent, you also consent to your personal data being processed in the USA. According to the European Court of Justice, the level of data protection in the USA is inadequate compared to the European Union. In particular, there is a risk that US authorities may access your data. If you do not consent, your personal data will not be transferred to the USA. Once you have given your consent, you can withdraw it at any time with effect for the future.
VI. Embedded functions and content
On our website, we partly use the embedding function of the video platform YouTube to display content (such as videos).
service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC ("Google"), 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
If you browse a part of our website with YouTube content, a connection is established to the YouTube or Google servers. As a result, they receive your IP address and the information that you have visited our website if you play the YouTube videos. If you are logged into your YouTube account, this information can also be directly assigned to your personal profile. You can prevent this by logging out of your YouTube account beforehand.
However, we only integrate the videos via the so-called extended data protection mode , so that these cookies are only set by YouTube when you play the videos.
The legal basis for this is your consent within the meaning of Art. 6 para. 1 lit. a) GDPR.
Note: If you declare your consent to play a video, you also consent to your personal data being processed in the USA. According to the European Court of Justice, the level of data protection in the USA is inadequate compared to the European Union. In particular, there is a risk that US authorities may access your data. If you do not consent to the playing of the videos, your personal data will not be transferred to the USA. Once you have given your consent, you can withdraw it at any time with effect for the future.
We also integrate the maps of the Google Maps service of the provider Google.
The service provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
No cookies are set in the process.
C. Your rights
You have the following rights in connection with the processing of your personal data by us. The assertion of these rights is basically free of charge for you. To exercise your rights, please contact firstname.lastname@example.org.
However, in the case of manifestly unfounded or - especially in the case of frequent repetition - excessive requests, we may, in accordance with Art. 12 para. 5 GDPR, either
(i) charge a reasonable fee taking into account the administrative costs of providing the information or communication or taking the action requested; or
(ii) refuse to act on the request.
This does not apply to the exercise of your right of withdrawal.
I. Right of withdrawal
You can withdraw any consent given to us at any time with effect for the future.
II. Right of access
You have the right to obtain from us confirmation as to whether or not personal data concerning you are being processed, and, where that is the case, access to the personal data and the information listed in Art. 15 GDPR.
III Right to rectification and erasure
In addition, you have the right to have incorrect personal data rectified and incomplete personal data completed in accordance with Art. 16 GDPR and to have your personal data erased if the requirements of Art. 17 GDPR are met.
IV. Right to restriction of processing
You can restrict the processing of your personal data under the conditions set out in Art. 18 GDPR.
V. Right to data portability
In addition, you have the right to receive the personal data concerning you that you have provided to us in a structured, commonly used and machine-readable format. You also have the right, where technically feasible, to have us transmit this data to another controller on your instructions. The right to data transmission only applies to personal data where the processing is based on consent pursuant to Art. 6 para. 1 lit. a) GDPR or on a contract pursuant to Art. 6 para. 1 lit. b) GDPR and the processing is carried out by automated means. The right to data transmission to another controller shall be excluded if this would impair the rights and freedoms of other persons (e.g. personal data of third parties, our business and trade secrets or copyrights).
VI. Right to object
Pursuant to Art. 21 GDPR, you have the right to object at any time to the processing of your personal data on grounds relating to your particular situation, insofar as this is carried out on the basis of Art. 6 para. 1 lit. e) or lit. f) GDPR. In the event of such an objection, we will no longer process this data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or that the processing serves the purpose of establishing, exercising or defending legal claims.
E. Obligation to provide data
There is no statutory or contractual requirement to provide us with personal data. However, the provision of data that is absolutely necessary for the provision of the respective service is necessary if you wish to make use of these services.
F. Right to lodge a complaint
If you consider that we are not properly fulfilling our obligations under data protection law, you can contact the supervisory authorities at any time. You can address the respective state data protection commissioner responsible for us as follows:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
P.O. Box 20 04 44
Phone: +49 (0) 211/38424-0
Fax: +49 (0) 211/38424-10
From time to time, it may become necessary to update this data protection declaration, for example due to new legal or official requirements or new offers on our website. We will then inform you here. In general, we recommend that you call up this data protection declaration regularly to check whether there have been any changes. You can see whether changes have been made by the fact that the status indicated under this declaration has been updated.
As of: Juni 2021