Privacy Policy
Information obligations pursuant to Art. 12 et seq. EU-GDPR
Name and address of the controller
Your contact as controller within the meaning of the European General Data Protection Regulation (“EU-GDPR”), other national data protection laws of the Member States and other data protection provisions is:
ICS IT Projects GmbH Konrad-Zuse-Ring 26 68163 Mannheim Germany
ICS IT Projects GmbH (hereinafter “ICS IT Projects” or “publisher”) is a company of the ICS Group. The ICS Group provides consulting, software, technology and services for the digitization of business processes.
Our products, solutions and services offer high value to our customers. The basis for this is a trust-based relationship with customers, suppliers, partners and a trustworthy handling of data of prospects, employees and other stakeholders.
In order to provide our services, it is partly necessary to collect and process personal data. ICS IT Projects takes the protection of personal data very seriously and strictly complies with statutory regulations – currently in particular the General Data Protection Regulation (GDPR) 2016/679 and, additionally in Germany, the Federal Data Protection Act (BDSG).
Personal data is only collected, processed and used by ICS IT Projects to the extent necessary.
The following statement provides you with an overview of how we ensure data protection and what type of data is collected for which purpose.
1) Scope & notice regarding children
This Privacy Policy applies to all websites and digital services operated by ICS IT Projects, including all related content, features, tools, products and services (“Services”).
Our Services are not directed at children under the age of 16. We do not knowingly collect personal data from children under the age of 16, unless this is required in the context of an application or employment relationship.
If we become aware that we have processed personal data of a child without the required consent of the parents or guardians, we will delete such data without undue delay.
2) Collection & processing of personal data
2.1) General
We collect and process data about you in the following cases, for example:
- when you contact us directly, e.g. via our website, by contacting our customer service / hotline and you are interested in our products and services or have any other request;
- when you register as a participant / visitor for ICS IT Projects professional events such as trade shows and conferences and/or voluntarily provide us with your contact details at such events;
- when you purchase or request products and services directly from us;
- when you respond to our direct marketing activities, e.g. by submitting a response card from a mailing campaign;
- when affiliated companies (pursuant to Sec. 15 German Stock Corporation Act – AktG) and individual business partners lawfully transfer data about you to us;
- when you provide us with data in the context of recruitment and application processes (online / offline).
We do not disclose your data to third parties without your consent, unless:
- we are obliged to do so by law or by binding official or court order,
- the data transfer is legally permissible and required, e.g. for fraud prevention,
- affiliated companies (pursuant to Sec. 15 AktG) must be involved in order to process your request.
2.2) Processing by external processors
To provide our Services we use carefully selected external service providers who process personal data on our behalf. We have concluded data processing agreements pursuant to Art. 28 GDPR with all processors.
We ensure that the processing of personal data is carried out exclusively in accordance with our instructions and is protected by appropriate technical and organizational measures (TOMs).
As a rule, processing takes place within the European Union (EU) or the European Economic Area (EEA). If data is exceptionally transferred to a third country (e.g. the USA), this is only done on the basis of appropriate safeguards, such as the EU Standard Contractual Clauses (SCC) or equivalent legal instruments.
Examples of processors we use within the EU include:
- hosting and IT service providers (e.g. servers located in the EU),
- CRM systems (e.g. Zoho CRM, location: Netherlands),
- logistics and shipping partners within the EU.
2.3) Processing in the customer database
We store and use contact data and information received (such as business communication history) from customers and prospects for the purpose of handling or initiating the business relationship. Processing is based on Art. 6 (1) (b) GDPR (performance of a contract) and/or Art. 6 (1) (f) GDPR (legitimate interest in efficient customer management).
Personal data is collected and stored exclusively in accordance with the provisions of the General Data Protection Regulation (GDPR 2016/679) and the Federal Data Protection Act (BDSG) as applicable in Germany.
We and our affiliated companies (pursuant to Sec. 15 AktG) use Zoho CRM as our customer database. The service provider is Zoho Corporation B.V., Beneluxlaan 4B, 3527 HT Utrecht, Netherlands (“Zoho”). Data is stored on Zoho servers located in the Netherlands / in the EU. We and our affiliated companies have concluded a data processing agreement with Zoho.
You may request information about your stored data in the customer database at any time and may also request its rectification or deletion.
Further information about data protection at Zoho CRM can be found at: https://www.zoho.com/de/crm/gdpr/. Information on security measures at Zoho CRM can be found at: https://www.zoho.com/security.html.
2.4) Processing in the workflow management system
For certain business processes (e.g. ticket management, support requests, workflow automation) we use the collaboration platform ServiceNow. Provider is ServiceNow Netherlands B.V., Hoogoorddreef 54D, 1101 BE Amsterdam, Netherlands. The parent company is ServiceNow, Inc., 2225 Lawson Lane, Santa Clara, CA 95054, USA.
In the course of using this platform, in particular the following personal data may be processed:
- master data (e.g. first and last name, company, e-mail address, telephone number),
- communication content (e.g. support requests, ticket history, attachments),
- usage data (e.g. time of the request, IP address, log files).
Processing takes place exclusively for the purpose of dealing with support requests, providing our services and optimizing internal processes. The legal basis is Art. 6 (1) (b) GDPR (performance of a contract) where processing is required to handle your request. In addition, processing is based on our legitimate interests pursuant to Art. 6 (1) (f) GDPR in efficient and secure handling of support and business processes.
ServiceNow generally stores data on servers within the EU/EEA. A transfer to third countries (in particular the USA) cannot be ruled out in individual cases. Where such transfer occurs, it is based on the EU Standard Contractual Clauses pursuant to Art. 46 GDPR.
Further information on data protection at ServiceNow is available at: https://www.servicenow.com/privacy-statement.html.
2.5) Categories of personal data
Depending on how you use our Services, we process in particular the following categories of personal data:
- Contact details: name, address, billing and delivery address, telephone number, e-mail address;
- Financial data: payment information, transaction details, payment confirmations;
- Account information: username, passwords, settings, security questions;
- Transaction information: items viewed, ordered, returned or cancelled, order history;
- Communication data: contents of inquiries, support contacts, feedback;
- Device information: device type, browser, IP address, unique identifiers;
- Usage information: interactions with our websites, services and shops.
3) Data collection when using our website and digital services
3.1) General
When you visit our website, personal data is generally processed only to the extent necessary to provide a functional website and our content and services. Where personal data (e.g. name, address or e-mail address) is collected on our pages, this is always done on a voluntary basis. Your data is transmitted using SSL/TLS encryption.
Your data is processed in accordance with European and German data protection law (GDPR and BDSG) as well as our internal policies.
Personal data is in particular used for the purpose of processing orders and dealing with your inquiries. Depending on the type and content of your request, your data may be passed on to affiliated companies (pursuant to Sec. 15 AktG) insofar as this is necessary for processing.
3.2) Website hosting & FTP services
Our website is hosted by IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany. When you access our website, IONOS automatically records information in server log files. This includes:
- IP address of the requesting device,
- date and time of access,
- address of the page / file accessed,
- referrer URL (previously visited page),
- browser type and version,
- operating system used.
Log files are used to ensure operational security and system security and to defend against attacks. The legal basis for this processing is our legitimate interest pursuant to Art. 6 (1) (f) GDPR.
We also use FTP and SFTP servers (File Transfer Protocol) provided by IONOS SE for uploading, managing and exchanging files. When accessing the FTP server, log files are generated for technical reasons, including:
- IP address of the requesting device,
- username used (FTP login),
- date and time of access,
- files accessed or transferred,
- server status messages (e.g. successful / failed login attempts).
Processing this data is necessary to ensure operation and security of the file server, to reconstruct access (e.g. for error analysis or misuse prevention) and to enable authorized users to securely exchange files.
The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in secure and stable operation of the FTP service) and Art. 6 (1) (b) GDPR (performance of a contract) where file exchange occurs in the context of contractual relationships.
We have concluded a data processing agreement pursuant to Art. 28 GDPR with IONOS, which ensures compliant processing. Further details can be found in the IONOS privacy notice: https://www.ionos.de/terms-gtc/datenschutzerklaerung/.
3.3) E-mail communication
For sending and receiving e-mails we use Microsoft 365 (Outlook) provided by Microsoft Ireland Operations Limited. To ensure IT security (spam, phishing and malware protection) we additionally use security / filter services from Cisco (Cisco Systems).
In the context of e-mail communication we process in particular: sender / recipient address, names, technical header and protocol data, timestamps, IP addresses as well as contents of messages and attachments.
The legal basis is Art. 6 (1) (b) GDPR (communication for contract performance and processing of inquiries) and, where not directly contract-related, Art. 6 (1) (f) GDPR (legitimate interest in efficient communication).
E-mails are usually transmitted in transit with TLS encryption (if supported by the recipient server). Incoming and outgoing messages are automatically scanned for malware, spam and phishing.
A transfer of personal data to third countries, in particular to the USA, may occur (e.g. in the context of support or security services). In such cases, appropriate safeguards are in place, including participation of service providers in the EU-US Data Privacy Framework (DPF) and/or conclusion of EU Standard Contractual Clauses (SCCs). We will provide further details upon request.
We have concluded data processing agreements (Art. 28 GDPR) with Microsoft and, where applicable, with Cisco. Further information can be found in the Microsoft Privacy Statement: https://www.microsoft.com/de-de/privacy/privacystatement.
3.4) Cookies
We are currently not using any cookies of our own on this contact and information website. However, our hosting provider may set technically necessary cookies to ensure the proper operation and security of the website. We do not use any additional cookies (e.g. for analytics or marketing).
3.5) Links to other websites and third-party applications
To interact with other websites where you are a registered user (e.g. Facebook, etc.), we may provide links or integrate third-party applications. We may also provide general links to websites of other providers. The use of such links and applications is governed by the providers of these sites and is subject to their privacy policies. ICS IT Projects is not responsible for the privacy practices or content of these sites.
3.6) Microsoft Office services “Bookings” and “Teams”
We use Microsoft Bookings and Microsoft Teams, provided by Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. The parent company is Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA.
Microsoft Bookings enables simple and user-friendly appointment scheduling (e.g. consulting, support, sales). Microsoft Teams enables online meetings, video conferences and chats. When using these services, the following data is processed:
- Microsoft Bookings: name, e-mail address, if applicable telephone number, appointment details (date, time, purpose), any further optional information you provide;
- Microsoft Teams: account information (name, e-mail, profile picture), communication content (chats, files, shared content), metadata (IP address, device information, connection data).
Data is processed solely for the purpose of scheduling, managing and holding appointments and for communication with you. The legal basis is Art. 6 (1) (b) GDPR where processing is required for performing (pre-)contractual measures (e.g. appointment scheduling, meetings) and Art. 6 (1) (f) GDPR where we have a legitimate interest in an efficient and secure communication and booking solution.
We may pass on your data to affiliated companies (pursuant to Sec. 15 AktG) and, where necessary, other third parties to the extent required for preparing and/or holding an appointment with you. In all other respects, data is only passed on if we are legally obliged to do so.
We and our affiliated companies take appropriate technical and organizational measures to protect your personal data against unauthorized access, loss or misuse. This includes encryption of data transfers, access restrictions and regular reviews of our security measures. Other third parties to whom we transfer personal data are contractually obliged to implement adequate data protection measures.
Data is stored for as long as required for the respective appointment or communication purpose, or as long as statutory retention periods apply. Where a subsequent business relationship arises, statutory retention obligations apply. Data is only passed on to third parties if this is necessary for fulfilling the appointment or required by law.
Microsoft stores most customer data from the EU in European data centers. However, it cannot be ruled out that personal data may be transferred to third countries (in particular the USA) in certain cases, for example for support and maintenance purposes. For such transfers, Microsoft uses the EU Standard Contractual Clauses (Art. 46 (2) (c) GDPR) and additional safeguards where appropriate. For the USA, an adequacy decision (EU-US Data Privacy Framework) has existed since 10 July 2023. Microsoft is certified under this framework.
Further information can be found in the Microsoft Privacy Statement: https://privacy.microsoft.com/de-de/privacystatement and in Microsoft’s security information: https://www.microsoft.com/de-de/microsoft-365/business/data-security-privacy-germany.
3.7) Surveys
We and our affiliated companies (pursuant to Sec. 15 AktG) use the service Zoho Survey, provided by Zoho Corporation B.V. (Zoho), Beneluxlaan 4B, 3527 HT Utrecht, Netherlands, to conduct surveys. Data is stored on Zoho servers in the Netherlands / EU. We have concluded a data processing agreement (Art. 28 GDPR) with Zoho, ensuring compliance with European data protection standards. ICS IT Projects is responsible for data processing towards you.
Participation in surveys is always voluntary, as is answering individual questions. As a rule, our surveys are conducted anonymously; no personal data is collected and no conclusions can be drawn about the responding person.
If a survey optionally allows you to provide personal details (e.g. name, e-mail address), this is done based on your voluntary decision.
Processing is carried out exclusively for internal market research, optimization of our products and services and – in individual cases – for contacting you if you voluntarily provide personal data (e.g. name, e-mail address). The legal basis for anonymous surveys is Art. 6 (1) (f) GDPR (legitimate interest in market research and optimization), and Art. 6 (1) (a) GDPR (consent) if you voluntarily provide personal data (e.g. for being contacted). If you have voluntarily provided personal data within a survey, you may request access to, rectification or deletion of such data at any time.
Information on Zoho’s privacy policy is available at: https://www.zoho.com/privacy.html. Information on security measures at Zoho Survey is available at: https://www.zoho.com/security.html.
4) Use of personal data
4.1) General
We use the data you provide to perform and process your order and to respond to your inquiry, as well as to initiate and maintain the business relationship.
Where necessary and legally permissible, we may use your data prior to concluding a contract and, if necessary, during the business relationship for contract management and for credit checks or obtaining information. For this purpose, we use selected service providers and credit agencies, and information on payment behavior and creditworthiness may be obtained in the form of score values based on mathematical-statistical procedures.
We assure you that we will not transfer your personal data to third parties unless we are legally entitled or obliged to do so or you have given your prior consent. We may disclose your personal data in connection with ongoing or future legal proceedings, for example to establish, exercise or defend legal claims (including disclosure of information to third parties for the purpose of fraud prevention and reduction of credit risk).
We may transfer your personal data to affiliated companies (pursuant to Sec. 15 AktG) where this is necessary to process your request.
4.2) Recruitment / application process
We inform you that we and our affiliated companies (pursuant to Sec. 15 AktG) collect and use your personal data in connection with recruitment (online and offline).
Where we use service providers to perform and process data processing operations, contractual relationships are based on the GDPR.
For receiving and managing applications and thus for the purpose of potentially establishing an employment relationship, we and our affiliated companies use the recruiting tool “Zoho Recruit”.
This service is provided by Zoho Corporation B.V., Beneluxlaan 4B, 3527 HT Utrecht, Netherlands (“Zoho”). Data is stored on Zoho servers in the Netherlands / EU.
Zoho’s Privacy Policy is available at: https://www.zoho.com/de/privacy.html.
Further information on security at Zoho Recruit is available at: https://www.zoho.com/security.html.
ICS IT Projects is responsible for processing towards you.
If you apply to us, the following applies: Zoho collects, on our behalf, the following data from you: salutation, first and last name, contact details and other data from your application. ICS IT Projects and its affiliated companies can then access an internal, protected area of Zoho Recruit, view your applicant data and use / process it for documenting the recruitment process and for communication with you.
The legal basis for processing applicant data is Art. 88 (1) GDPR in conjunction with Sec. 26 (1) BDSG. The service relationship between Zoho and ICS IT Projects and its affiliated companies is based on Art. 28 GDPR (data processing agreement).
Applications from young people from the age of 16 (e.g. for apprenticeships, student internships or working student positions) are expressly welcome. In this context, we process the personal data you provide solely for the purpose of conducting the application process (Art. 6 (1) (b) GDPR in conjunction with Sec. 26 BDSG).
ICS IT Projects and its affiliated companies store applicant data in Zoho Recruit in accordance with statutory retention periods. After expiry of these periods, applicant data is deleted in a secure and data protection-compliant manner. In addition, applicants have the right to request deletion of their data at any time.
If ICS IT Projects and its affiliated companies wish to store applicant data in Zoho Recruit beyond the statutory retention periods (e.g. for a talent pool), this is done solely with the applicant’s express written consent. Such consent can be withdrawn at any time.
4.3) Credit checks and scoring
Where we provide services in advance (e.g. purchase on account), we may, to protect our legitimate interests, obtain credit information on the basis of mathematical-statistical procedures from Verband der Vereine Creditreform e.V., Hellersbergstraße 12, 41460 Neuss (and its local offices) and/or Allianz Trade Deutschland, branch of Allianz Trade SA (formerly Euler Hermes), Gasstr. 29, 22761 Hamburg.
For this purpose, we transmit the personal data required for a credit check to Creditreform (and its local offices) and/or Allianz Trade Deutschland. We use the information received on the statistical probability of default to make a balanced decision on the establishment, conduct or termination of the contractual relationship. The credit report may contain probability values (score values) calculated on the basis of scientifically recognized mathematical-statistical methods, which include address data. Your legitimate interests are taken into account in accordance with legal provisions.
4.4) Data security and retention
We implement technical and organizational measures pursuant to Art. 32 GDPR to protect your data against loss, manipulation or unauthorized access. This includes in particular SSL encryption, access restrictions, backups, firewalls and regular reviews of our security concepts. Nevertheless, no transmission or storage method can guarantee absolute security.
Personal data is stored only for as long as necessary for fulfilling the processing purpose or as long as statutory retention periods apply. After the purpose ceases to exist, the data is deleted. Examples of retention periods:
- contract and tax-relevant data: 6–10 years (under the German Commercial Code – HGB – and Fiscal Code – AO),
- applicant data: generally 6 months after completion of the recruitment process, longer storage only with consent (talent pool),
- log files and technical data: generally 14 days, no longer than 30 days.
5) Your rights under GDPR
Under the General Data Protection Regulation (GDPR), you have the right to obtain information on your stored data free of charge and, where applicable, the right to rectification, restriction of processing, erasure (“right to be forgotten”) and data portability.
We are obliged under Art. 12 and Art. 21 GDPR to provide information in writing, electronically or – on request – orally, depending on the circumstances of the case. You have a comprehensive right to object at any time (Art. 21 (2) GDPR). Any consent you have given remains effective until withdrawn. All our communication channels meet appropriate security requirements.
As a data subject you have in particular the following rights:
- Right of access (Art. 15 GDPR) & right to data portability (Art. 20 GDPR): you may request a copy of the personal data we hold about you. On request, we will provide it in a machine-readable format where technically feasible.
- Right to rectification (Art. 16 GDPR): you may have inaccurate data corrected or incomplete data completed.
- Right to erasure / “right to be forgotten” (Art. 17 GDPR): you may request the deletion of your personal data where no statutory retention obligations prevent this.
- Right to restriction of processing (Art. 18 GDPR) & right to object (Art. 21 GDPR): you may request restriction of processing or object to processing where particular reasons apply.
- Right to withdraw consent (Art. 7 (3) GDPR): where we process your data on the basis of consent, you may withdraw this consent at any time with effect for the future.
- Right to lodge a complaint (Art. 77 GDPR): you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, your place of work or the place of the alleged infringement. An overview of supervisory authorities is available at: https://edpb.europa.eu/about-edpb/about-edpb/members_en.
To exercise your rights, please contact us using the contact details provided at the end of this Privacy Policy. Where legally required, we reserve the right to verify your identity before processing your request.
6) Changes to this Privacy Policy
We reserve the right to amend or update this Privacy Policy at any time. Please review this page regularly for updates.
7) Further information / data protection contact
Your trust is important to us. We therefore remain at your disposal to answer questions regarding the processing of your personal data. If you would like information on your stored personal data or have questions that this Privacy Policy could not answer, or if you wish to receive more detailed information on a specific point, please contact our Data Protection Officer at any time: datenschutz@ics-it-projects.com.
Alternatively, you can reach us at the following address:
ICS IT Projects GmbH Data Protection Officer Konrad-Zuse-Ring 26 68163 Mannheim GermanyData protection inquiries are usually answered within a maximum of 30 days of receipt.
ICS IT Projects GmbH