Privacy Policy
Last updated: 19 August 2026
1. Data protection at a glance
1.1 General information
The following notes give you a simple overview of what happens to your personal data when you visit our website. Personal data is any data by which you can be personally identified.
We take the protection of your personal data seriously. We treat your personal data confidentially and in accordance with statutory data protection provisions and this privacy policy. We maintain current technical measures to ensure data security, in particular to protect your personal data against risks during transmission and against access by third parties. These are adapted in line with the state of the art.
When you use this website, various personal data is collected. This privacy policy explains which data we collect, what we use it for and on what basis. Please note that data transmission over the internet (e.g. when communicating by email) can have security gaps. Complete protection of data against access by third parties is not possible.
Without personal data we cannot fulfil your wishes, look after you as a contractual partner or send you information about our travel programmes. We of course only collect the data necessary for this. We do not use automated decision-making, including profiling, within the meaning of Art. 22 GDPR.
1.2 Controller
Data processing on this website is carried out by:
Natucate GmbH
Jakobstr. 181-183
52064 Aachen
Germany
Phone: +49 241 - 91 99 43 57
Email: info@natucate.com
Managing Director: Daniel Kaul
Commercial register: Aachen Local Court, HRB 18550
VAT ID: DE291921934
The controller is the natural or legal person who alone or jointly with others determines the purposes and means of processing personal data (e.g. names, email addresses).
1.3 Data protection contact
For questions about the processing of your data and to exercise your rights, please contact Daniel Kaul at datenschutz@natucate.de.
1.4 How do we collect your data?
Some data is collected because you provide it to us. This may be data you enter into a contact form, for example. We process the personal data you provide in accordance with the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG) in order to perform the travel contract or to take steps at your request prior to entering into a contract. In line with the law and the principle of data minimisation, we generally only collect data needed to provide that particular service.
Other data is collected automatically by our IT systems when you visit the website. This is mainly technical data (e.g. browser, operating system or time of access). This data is collected automatically as soon as you enter our website.
1.5 What do we use your data for?
Some data is collected to ensure the website is provided without errors. Other data may be used, with your consent, to analyse how you use the site. We also process your personal data to perform the travel contract or to prepare an offer.
To perform a travel contract we process the following personal data: name, address and other contact details (phone number, email address), date of birth, gender and, depending on the destination, nationality and passport details.
We mainly process personal data for the following purposes:
• customer and supplier management
• applicant management
• travel arrangement and organisation
• booking administration and processing
• operation of our website and apps
• communication (analogue and digital)
• sending company information (only with your consent)
• sending our newsletter (only with your consent)
• meeting legal requirements (tax law etc.)
• archiving data to secure it and meet documentation obligations
• disclosure in the context of official or court proceedings
2. Your rights
2.1 Access, rectification, erasure and restriction
Within the applicable statutory provisions you have the right at any time to free information about your stored personal data, its origin and recipients and the purpose of processing under Art. 15 GDPR. You further have the right to rectification under Art. 16 GDPR, to erasure under Art. 17 GDPR and to restriction of processing under Art. 18 GDPR. For this and for other questions about personal data you can contact us at any time at datenschutz@natucate.de.
2.2 Right to data portability
You have the right to have data that we process automatically on the basis of your consent or in performance of a contract handed over to you or to a third party in a common, machine-readable format. If you request direct transfer of the data to another controller, this will only be done where technically feasible.
2.3 Withdrawal of your consent
Many processing operations are only possible with your express consent. You can withdraw consent already given at any time. An informal message by email to us (datenschutz@natucate.de) is sufficient. The lawfulness of processing carried out before withdrawal remains unaffected.
2.4 Right to object
Processing based on legitimate interests: Where we process your data on the basis of Art. 6(1)(f) GDPR, you have the right under Art. 21(1) GDPR to object at any time, on grounds relating to your particular situation, to that processing. We will then stop processing your data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.
Direct marketing: Where your data is processed for direct marketing purposes, you have the right under Art. 21(2) GDPR to object at any time and without giving reasons. This also applies to profiling insofar as it is related to direct marketing. Following your objection we will no longer process your data for these purposes.
An informal message to datenschutz@natucate.de is sufficient in both cases.
2.5 Right to lodge a complaint with the supervisory authority
In the event of breaches of data protection law you have the right to lodge a complaint with a supervisory authority. The authority responsible for us is:
State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia
Kavalleriestraße 2-4
40213 Düsseldorf
Germany
https://www.ldi.nrw.de
You may also contact the supervisory authority at your place of residence or at the place of the alleged infringement.
2.6 Objection to advertising emails
We hereby object to the use of contact data published under our legal notice obligations for sending unsolicited advertising and information material. We expressly reserve the right to take legal action in the event of unsolicited advertising being sent, for example by spam email.
3. Data collection on our website
3.1 Cookies and consent management
Our website uses cookies. Cookies do no harm to your device and contain no viruses. Cookies are small text files stored on your device by your browser.
We use a cookie consent tool (CookieConsent v3) together with Google Consent Mode V2. On your first visit you are informed about the use of cookies and can give or refuse your consent. Scripts requiring consent are technically blocked and only loaded once you have agreed. You can adjust your cookie settings at any time via the cookie link in the footer.
Strictly necessary cookies are set without consent. The legal basis is Section 25(2) no. 2 TDDDG (the German act on data protection in telecommunications and digital services) and Art. 6(1)(f) GDPR. These include storing your cookie choice, your session and your language selection.
All other cookies (e.g. analytics or marketing cookies) are only set with your express consent under Section 25(1) TDDDG and Art. 6(1)(a) GDPR.
A full list of the cookies in use, with provider, purpose and storage period, is available in the cookie settings.
3.2 Server log files
Each time our website is accessed, our system automatically collects and stores information in server log files that your browser transmits to us. These are:
• browser type and version
• operating system used
• referrer URL
• host name of the accessing device
• time of the server request
• IP address
The IP address is personal data. We process this data to make the website technically available and to ensure its security. This data is not combined with other data sources.
The legal basis for the processing is Art. 6(1)(f) GDPR. Our legitimate interest is the secure and uninterrupted operation of the website.
Storage period: 30 days
3.3 Hosting
Provider: DigitalOcean, LLC, 105 Edgeview Drive, Suite 425, Broomfield, CO 80021, USA
Purpose: providing and operating our website
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure and reliable operation)
Storage period: see server log files
Server location: Frankfurt am Main, Germany
Third country transfer: USA (EU-U.S. Data Privacy Framework, EU Standard Contractual Clauses)
Privacy notice: https://www.digitalocean.com/legal/privacy-policy
Data processing agreement: https://www.digitalocean.com/legal/data-processing-agreement
DigitalOcean processes all data arising technically when the website is accessed on our behalf, in particular the server log data listed in section 3.2. The provider does not analyse this data for its own purposes. As part of hosting, your data does not leave the European Union.
Note: As a US company, DigitalOcean is subject to the CLOUD Act. Government access to data can therefore not be entirely ruled out, even with servers located in the European Union.
3.4 Image delivery
We deliver images on our website through imgproxy, an open-source application running on our own servers in Frankfurt. It adapts images in size and format to your device. No data is transmitted to third parties in this process.
3.5 Search function
For the search on our website we use Meilisearch, an open-source search engine that also runs on our own servers in Frankfurt. Your search queries are not transmitted to third parties.
3.6 SSL and TLS encryption
For security reasons and to protect the transmission of confidential content, this site uses SSL or TLS encryption. You can recognise an encrypted connection by the browser address bar changing from "http://" to "https://" and by the padlock symbol in your browser bar. When SSL or TLS encryption is active, the data you send us cannot be read by third parties.
3.7 Contact and booking form
If you send us enquiries or bookings through a contact form, your details from the enquiry form including the contact data you provide there are stored by us in order to process the enquiry and in case of follow-up questions. We do not pass this data on without your consent.
The processing of data entered into the contact or booking form is based on Art. 6(1)(b) GDPR (entering into and performing a contract) and Art. 6(1)(f) GDPR (legitimate interest in handling enquiries).
To respond personally to messages and questions we need, among other things: first and last name, email address, phone number, street and house number, postcode, city and country.
To perform a travel contract we additionally process: date of birth, gender and, depending on the destination, nationality and passport details. Emergency contact details and project-specific information may also be collected.
Where information about your health is required, for example allergies, medication or pre-existing conditions, we process this exclusively on the basis of your explicit consent under Art. 9(2)(a) GDPR.
The data collected in connection with the trip is used exclusively to carry out the stay abroad, to provide all contractually owed services and to look after you as a customer.
4. Disclosure of personal data
4.1 Disclosure to third parties
Where we transfer personal data to a processor, you have the right to be informed about the appropriate safeguards relating to that transfer.
Your personal data is disclosed only within the applicable legal requirements, in particular those of competition and data protection law. Where necessary to provide the services we owe you (accommodation, meals, activities and excursions, support, and orientation days on site where applicable) or to meet legal obligations, your data is also passed to subcontractors or service providers performing the service in our name or on our behalf.
We have data processing agreements under Art. 28 GDPR in place with all processors, containing EU Standard Contractual Clauses.
4.2 Transfers abroad
We have to transfer data to the partners named above in order to organise all contractually owed services connected with the stay abroad. For the same purpose our partners may have to pass data on themselves. Our partners operate independently and are not part of Natucate GmbH. We therefore have no influence on their data processing.
Third countries are countries in which the GDPR does not directly apply. In principle this covers all countries outside the EU or the European Economic Area. We base such transfers on one of the following grounds:
• an adequacy decision of the European Commission under Art. 45 GDPR, for the USA under the EU-U.S. Data Privacy Framework (decision of 10 July 2023)
• EU Standard Contractual Clauses under Art. 46(2)(c) GDPR
• the necessity for the performance of a contract under Art. 49(1)(b) GDPR, in particular when transferring data to project partners on site
• your explicit consent under Art. 49(1)(a) GDPR
4.3 Storage of your data
In principle we store personal data only for as long as necessary to fulfil the contractual or legal obligations for which we collected it. We then delete the data without delay, unless we still need it until the statutory limitation period expires for evidentiary purposes in civil claims or because of statutory retention obligations.
We are subject to statutory documentation obligations arising from the German Commercial Code and the German Fiscal Code. The retention periods set out there are between two and ten years.
5. Form services
Jotform
Provider: Jotform Inc., 111 Pine Street, Suite 1815, San Francisco, CA 94111, USA
Purpose: online form tool for enquiries, bookings and surveys
Legal basis: Art. 6(1)(b) GDPR (pre-contractual steps) and Art. 6(1)(f) GDPR (legitimate interest)
Storage period: until the form data is deleted, otherwise in line with retention periods
Third country transfer: USA (EU-U.S. Data Privacy Framework, EU Standard Contractual Clauses)
Privacy notice: https://www.jotform.com/privacy/
6. Functional services
Pipedrive LeadBooster Chat
Provider: Pipedrive OÜ, Mustamäe tee 3a, 10615 Tallinn, Estonia
Purpose: chat function on our website for direct communication
Legal basis: Art. 6(1)(a) GDPR together with Section 25(1) TDDDG (consent)
Storage period: as long as required for business purposes, then in line with retention periods
Third country transfer: EU (Estonia)
Privacy notice: https://www.pipedrive.com/en/privacy
Note: If you use our chat function, the information you enter and technical data such as your IP address and browser identifier are transmitted to Pipedrive. The chat is only loaded after you have agreed in the cookie banner.
ProvenExpert
Provider: Expert Systems AG, Quedlinburger Straße 1, 10589 Berlin, Germany
Purpose: displaying our review seal
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in displaying customer reviews)
Storage period: no storage beyond the request
Third country transfer: none (Germany)
Privacy notice: https://www.provenexpert.com/de-de/datenschutzbestimmungen/
Note: Your IP address is transmitted to the provider when the seal is loaded.
jsDelivr
Provider: Prospect One, Kraków, Poland
Purpose: delivering our consent management tool through a content delivery network
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in technical operation). The service has to load before consent is given because it is what makes giving consent possible
Storage period: no storage beyond the request
Third country transfer: EU (Poland), delivery through globally distributed servers possible
Privacy notice: https://www.jsdelivr.com/terms/privacy-policy-jsdelivr-net
Google reCAPTCHA
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Purpose: bot protection for forms
Legal basis: Art. 6(1)(a) GDPR together with Section 25(1) TDDDG (consent)
Storage period: session up to 6 months
Third country transfer: USA (EU-U.S. Data Privacy Framework)
Privacy notice: https://policies.google.com/privacy
WhatsApp Business
Provider: Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland
Purpose: direct customer communication via WhatsApp
Legal basis: Art. 6(1)(a) GDPR (consent)
Storage period: 1 year
Third country transfer: USA (EU-U.S. Data Privacy Framework)
Privacy notice: https://www.whatsapp.com/legal/privacy-policy
7. Analytics services
Matomo
Provider: self-hosted on our own servers at matomo.natucate.com. No data is transmitted to third parties.
Purpose: web analytics, audience measurement, developing our offering
Legal basis: Art. 6(1)(a) GDPR together with Section 25(1) TDDDG (consent), as Matomo stores cookies on your device
Storage period: 14 months for raw data. Aggregated statistics without personal reference are kept beyond that.
Third country transfer: none
Note: IP anonymisation active
Opt-out: via the cookie settings in the footer
Note: With Matomo we record which pages are visited, which regions visits come from and how our content is used. Matomo sets two cookies named _pk_id and _pk_ses. The data collected does not leave our own infrastructure.
You can object to collection by Matomo at any time by deactivating the analytics cookies in the cookie settings in the footer.
Google Analytics 4
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Purpose: web analytics, user behaviour, website performance
Legal basis: Art. 6(1)(a) GDPR together with Section 25(1) TDDDG (consent)
Storage period: 14 months
Third country transfer: USA (EU-U.S. Data Privacy Framework)
Note: IP anonymisation active
Opt-out: https://tools.google.com/dlpage/gaoptout
Privacy notice: https://policies.google.com/privacy
8. Marketing and advertising
Google Ads and conversion tracking
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Purpose: online advertising with conversion tracking to measure advertising effectiveness
Legal basis: Art. 6(1)(a) GDPR together with Section 25(1) TDDDG (consent)
Storage period: 3 months (conversion cookies)
Third country transfer: USA (EU-U.S. Data Privacy Framework)
Privacy notice: https://policies.google.com/privacy
Note: As part of Google Ads, servers on the domain doubleclick.net are also contacted.
Google Tag Manager
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Purpose: tag management system for website tags and marketing services
Legal basis: Art. 6(1)(a) GDPR together with Section 25(1) TDDDG (consent)
Storage period: no data storage of its own
Third country transfer: USA (EU-U.S. Data Privacy Framework)
Privacy notice: https://www.google.com/intl/de/tagmanager/use-policy.html
Note: Tag Manager itself does not store cookies, but transmits your IP address to Google when loading and controls the delivery of the other services named here. It is therefore only loaded after you have agreed in the cookie banner.
Meta Pixel (Facebook and Instagram)
Provider: Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland
Purpose: conversion tracking, remarketing, custom audiences
Legal basis: Art. 6(1)(a) GDPR together with Section 25(1) TDDDG (consent)
Storage period: 3 months
Third country transfer: USA (EU-U.S. Data Privacy Framework)
Privacy notice: https://www.facebook.com/policy
Ad settings: https://www.facebook.com/settings?tab=ads
LinkedIn marketing services and Insight Tag
Provider: LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland
Purpose: B2B marketing, remarketing, conversion measurement, insight tags
Legal basis: Art. 6(1)(a) GDPR together with Section 25(1) TDDDG (consent)
Storage period: 3 months
Third country transfer: USA (EU Standard Contractual Clauses)
Privacy notice: https://www.linkedin.com/legal/privacy-policy
Opt-out: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out
Note: Data is processed pseudonymously. LinkedIn does not store your name or email address but processes the relevant data on a cookie basis within pseudonymous user profiles.
TikTok Pixel
Provider: TikTok Technology Limited, 10 Earlsfort Terrace, Dublin 2, Ireland
Purpose: retargeting, conversion tracking
Legal basis: Art. 6(1)(a) GDPR together with Section 25(1) TDDDG (consent)
Storage period: 13 months
Third country transfer: USA (EU-U.S. Data Privacy Framework)
Privacy notice: https://www.tiktok.com/legal/privacy-policy
9. External media and content
Vimeo
Provider: Vimeo Inc., 555 West 18th Street, New York, New York 10011, USA
Purpose: embedding videos, including a background video on our home page
Legal basis: Art. 6(1)(a) GDPR together with Section 25(1) TDDDG (consent)
Storage period: session up to 12 months
Third country transfer: USA (EU-U.S. Data Privacy Framework)
Privacy notice: https://vimeo.com/privacy
Note: When you open a page containing a Vimeo video, a connection to Vimeo's servers is established. Vimeo is told which of our pages you visited and receives your IP address. We have configured the embed so that Vimeo does not evaluate the data for its own advertising purposes ("Do Not Track" parameter). If you are logged in to your Vimeo account, Vimeo can attribute your browsing to your personal profile. You can prevent this by logging out beforehand.
YouTube
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Purpose: embedding videos
Legal basis: Art. 6(1)(a) GDPR together with Section 25(1) TDDDG (consent)
Storage period: session up to 6 months
Third country transfer: USA (EU-U.S. Data Privacy Framework)
Privacy notice: https://policies.google.com/privacy
Mapbox
Provider: Mapbox Inc., 740 15th Street NW, 5th Floor, Washington, DC 20005, USA
Purpose: interactive maps and map visualisation
Legal basis: Art. 6(1)(a) GDPR together with Section 25(1) TDDDG (consent)
Storage period: session up to 12 months
Third country transfer: USA (EU Standard Contractual Clauses under Art. 46(2)(c) GDPR)
Privacy notice: https://www.mapbox.com/legal/privacy
Note: When you open a page containing Mapbox maps, your browser establishes a direct connection to Mapbox's servers. The map content is delivered by Mapbox directly to your browser.
Instagram embeds
Provider: Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland
Purpose: embedding social media content
Legal basis: Art. 6(1)(a) GDPR together with Section 25(1) TDDDG (consent)
Storage period: session up to 1 year
Third country transfer: USA (EU-U.S. Data Privacy Framework)
Privacy notice: https://instagram.com/about/legal/privacy/
10. Newsletter and email marketing
MailChimp
Provider: The Rocket Science Group LLC d/b/a Mailchimp, a company of Intuit Inc., Atlanta, Georgia, USA
Purpose: newsletter delivery, email marketing
Legal basis: Art. 6(1)(a) GDPR (consent) or Section 7(3) UWG (the German Act Against Unfair Competition) for existing customers
Storage period: until you unsubscribe, consent records for three years beyond that
Third country transfer: USA (EU Standard Contractual Clauses under Art. 46(2)(c) GDPR)
Privacy notice: https://mailchimp.com/legal/privacy/
Unsubscribe: link in every newsletter or by email to datenschutz@natucate.de
To receive one of our newsletters we need a valid email address from you. To address you personally we also ask you to tell us your form of address and your name. These details are optional.
Double opt-in: After you sign up, we send you an email containing a confirmation link. Only once you click that link do we add you to the mailing list. This ensures that nobody can subscribe you without your knowledge.
Logging: To document your consent, we store the time of sign-up, the time of confirmation and the IP address used. We keep these records for the duration of your subscription and for three years after the end of the calendar year in which you unsubscribed. This period follows the standard limitation period under Sections 195 and 199 of the German Civil Code.
Performance measurement: Our newsletter contains tracking pixels and individualised links. These tell us whether and when an email was opened and which links were clicked. This analysis is covered by your consent.
11. Social networks and media
Natucate GmbH maintains online profiles within social networks and platforms in order to communicate with customers and users active there and to inform them about our services. No content from these networks is embedded in our website, we only link to our profiles.
Please note that data may be processed outside the European Union in this context. This can create risks for users, for example because enforcing their rights may be more difficult.
The processing of users' personal data takes place on the basis of our legitimate interest in effective information and communication under Art. 6(1)(f) GDPR. Where users are asked for consent by the platform providers, the legal basis is Art. 6(1)(a) and Art. 7 GDPR. Where we are joint controllers with the providers for page statistics, this takes place on the basis of Art. 26 GDPR.
For access requests and to exercise your rights, please note that these can most effectively be asserted with the providers. Only the providers have access to users' data. If you still need help, you can contact us.
We refer to the privacy notices of the respective providers:
• Facebook/Meta: https://www.facebook.com/about/privacy/
• Instagram: https://instagram.com/about/legal/privacy/
• YouTube/Google: https://policies.google.com/privacy
• LinkedIn: https://www.linkedin.com/legal/privacy-policy
12. Payment and accounting services
PayPal
Provider: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, 2449 Luxembourg, Luxembourg
Purpose: online payment processing
Legal basis: Art. 6(1)(b) GDPR (performance of a contract)
Storage period: in line with statutory retention periods (up to 10 years)
Third country transfer: EU (Luxembourg), transfer to the USA possible
Privacy notice: https://www.paypal.com/de/webapps/mpp/ua/privacy-full
Revolut
Provider: Revolut Ltd, 7 Westferry Circus, E14 4HD London, United Kingdom
Purpose: payment processing, business account
Legal basis: Art. 6(1)(b) GDPR (performance of a contract)
Storage period: in line with statutory retention periods
Third country transfer: United Kingdom (adequacy decision of the European Commission)
Privacy notice: https://www.revolut.com/legal/privacy/
DATEV
Provider: DATEV eG, Paumgartnerstraße 6-14, 90429 Nuremberg, Germany
Purpose: accounting, tax advice, payroll
Legal basis: Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(c) GDPR (legal obligation)
Storage period: in line with statutory retention periods (up to 10 years)
Third country transfer: EU (Germany)
Privacy notice: https://www.datev.de/web/de/berufsgruppenuebergreifend/ueber-datev/datenschutz-und-compliance
13. Systems we use internally
The following systems are not loaded when you visit our website and do not set cookies. We name them because they may process data you send us as part of an enquiry, a booking or an application. We have data processing agreements under Art. 28 GDPR in place with all of them.
Pipedrive (CRM)
Provider: Pipedrive OÜ, Mustamäe tee 3a, 10615 Tallinn, Estonia
Purpose: CRM system, customer relationship management, sales administration
Legal basis: Art. 6(1)(b) GDPR (entering into and performing a contract) and Art. 6(1)(f) GDPR (legitimate interest)
Storage period: as long as required for business purposes, then in line with retention periods
Third country transfer: EU (Estonia)
Privacy notice: https://www.pipedrive.com/en/privacy
Google Workspace
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Purpose: email, cloud storage, document editing
Legal basis: Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(f) GDPR (legitimate interest)
Storage period: as long as required for business purposes
Third country transfer: USA (EU-U.S. Data Privacy Framework)
Privacy notice: https://policies.google.com/privacy
pCloud
Provider: pCloud AG, Place de la Gare 6, 1003 Lausanne, Switzerland
Purpose: cloud storage for documents, files and backups
Legal basis: Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(f) GDPR (legitimate interest in secure data storage)
Storage period: as long as required for business purposes
Third country transfer: Switzerland (adequacy decision of the European Commission)
Privacy notice: https://www.pcloud.com/privacy_policy.html
Note: pCloud offers the option of choosing the storage location explicitly in the EU and of using client-side encryption (pCloud Crypto).
Zapier
Provider: Zapier Inc., 548 Market St #62411, San Francisco, California 94104, USA
Purpose: integration and automation of different tools
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in efficient organisation)
Storage period: in line with retention periods
Third country transfer: USA (EU-U.S. Data Privacy Framework, data processing agreement in place)
Privacy notice: https://www.zapier.com/privacy
Make (formerly Integromat)
Provider: Celonis SE (Make), Theresienstraße 6, 80333 Munich, Germany
Purpose: workflow automation and tool integration
Legal basis: Art. 6(1)(f) GDPR (legitimate interest)
Storage period: in line with retention periods
Third country transfer: EU (Germany)
Privacy notice: https://www.make.com/en/privacy-notice
14. Applications
We process applicant data only for the purpose and within the scope of the application procedure, in accordance with statutory requirements. Applicant data is processed to fulfil our pre-contractual and contractual obligations in the application procedure within the meaning of Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR, where processing becomes necessary for us in the context of legal proceedings (in Germany Section 26 BDSG additionally applies).
The application procedure requires applicants to provide us with their data. Where we offer an online form, the necessary applicant data is marked; otherwise it follows from the job description. This generally includes personal details, postal and contact addresses and the documents belonging to the application such as covering letter, CV and references.
If an application is successful, the data provided may be processed further by us for the purposes of the employment relationship. Otherwise we delete the data six months after the procedure has been concluded, unless longer storage is required or you have consented to it.
15. General information
15.1 EU-U.S. Data Privacy Framework
The US services named in this privacy policy are, where indicated, certified under the EU-U.S. Data Privacy Framework (adequacy decision of the European Commission of 10 July 2023). The list of participants can be viewed at https://www.dataprivacyframework.gov/list. We note that government access to data in the USA cannot be entirely ruled out.
15.2 Processing on our behalf
We have data processing agreements under Art. 28 GDPR in place with all processors, containing EU Standard Contractual Clauses where applicable.
15.3 Changes to this privacy policy
We reserve the right to change this privacy policy in order to adapt it to changes in the legal situation or to changes in our services or data processing. The current version is always available on this page. The date of the most recent change is shown at the top.
15.4 Managing cookie settings
You can adjust your cookie settings at any time via the cookie link in the footer, or contact us at datenschutz@natucate.de