Privacy Policy
Thank you for your interest in our services.
Codex Systems Ltd, known here as dueto or dueto.io (“We”, “Us” or “Our”), respects your privacy and is committed to protect it through our compliance with this policy.
Below you will find details of the information that will be collected during your use of our web site (www.dueto.io).
Users may be subject to different protection standards and broader standards may therefore apply to some. In order to learn more about the protection criteria, Users can refer to the applicability section.
We may update this privacy policy from time to time to reflect new technologies and/or due to changes in the law. Relevant Changes will be brought to your attention in an appropriate manner.
Table of Contents
B. General information on data processing
2. Data processing when you are based in the EU/EEA/UK
a. Legal Basis for the Processing of Personal Data
b. Rights under the GDPR and where applicable UK GDPR
4. Recipients, third country transfer, linked third party websites
C. Data Collection and processing of User data when using our website
1. Third-Party Single Sign-On Service
2. Demo versions of our services
9. Cookies and integrated third-party offers
10. Statistics, Web-Analytics, Advertising based on Tracking and Retargeting – Use of Cookies
A. Definitions
Personal data (Article 4 No. 1 GDPR and where applicable UK GDPR)
Means any information relating to an identified or identifiable natural person ("data subject"). An identifiable person is one who can be identified, directly or indirectly, particularly by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that person. Identifiability can also be given by linking such information or additional knowledge. The form or embodiment of the information does not matter (e.g., photos, video, or audio recordings can contain personal data).
Processing (Article 4 No. 2 GDPR and where applicable UK GDPR)
It means any operation or set of operations performed on personal data, whether or not by automated means. This includes collection (i.e., procurement), recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment, combination, restriction, erasure, or destruction of personal data as well as the alteration of a purpose or objective originally underlying data processing.
Data Processor (Article 4 No. 8 GDPR and where applicable UK GDPR)
The natural or legal person, public authority, agency or other body which processes personal data on behalf of the Controller, as described in this privacy policy.
Data Controller (Article 4 No. 7 GDPR and where applicable UK GDPR)
The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data, including the security measures concerning the operation and use of dueto.io. The Data Controller, unless otherwise specified, is the Owner of dueto.io.
European Union (EU) and the United Kingdom (UK)
Unless otherwise specified, all references made within this document to the European Union (EU) include all current member states of the European Union and the European Economic Area (EEA). References to the United Kingdom (UK) apply separately where the UK General Data Protection Regulation (UK GDPR) or other applicable UK data protection laws govern the processing of personal data.
B. General information on data processing
1. Data Controller
The controller under data protection law is the entity that decides on the purposes and means of the processing of personal data. We are responsible for the technical setup, administration and distribution of the website.
Please do not hesitate to contact us if you have any questions about privacy policy, the information we hold about you, or if you wish to exercise any of your privacy rights.
The controller for the website www.dueto.io, in accordance with Article 4 (7) EU General Data Protection Regulation (“GDPR”) and, where applicable UK GDPR, is:
Codex Systems Ltd.,
4 HaRechev St., Tel Aviv–Yafo,
Israel 6777804,
represented by Adv. Eliav Boaron
The data controller is established in Israel. The European Commission has adopted an adequacy decision pursuant to Article 45 GDPR and where applicable UK GDPR, for Israel (commercial/private sector), recognising that personal data transferred to Israel benefits from an adequate level of protection. Where personal data is transferred to the controller in Israel, such transfers are therefore based on this adequacy decision, where applicable.
Our EU/UK representatives can be contacted in addition or instead of the controller by supervisory authorities and data subjects, on all issues related to processing and for the purposes of ensuring compliance with EU/UK data protection laws, as follows:
Rickert Rechtsanwaltsgesellschaft mbH
- Codex –
Colmantstraße 15
53115 Bonn, Germany
Rickert Services Ltd UK
- Codex –
PO Box 1487
Peterborough
PE1 9XX
United Kingdom
art-27-rep-codex@rickert-services.uk
2. Data processing when you are based in the EU/EEA/UK
a. Legal Basis for the Processing of Personal Data
We process your personal data when you are a user of our website. We only process data where we have a legal basis to do so. We specify the legal basis in the data processing sections, but generally we may process your personal data if one of the following conditions applies:
-
The data subject’s consent for the processing of personal data, Article 6 (1) (a), Article 7 GDPR and where applicable UK GDPR.
-
Processing personal data as a necessity for the fulfilment (performance) of a contract in return for payment or free of charge, Article 6 (1) (b) GDPR and where applicable UK GDPR. This shall also apply to processing operations necessary for the implementation of pre-contractual measures.
-
The processing is necessary for the fulfilment of a legal obligation to which we are subject, Article 6 (1) (c) GDPR and where applicable UK GDPR.
-
The processing is necessary to safeguard a legitimate interest of our company or a third party and if the interests, fundamental rights, and fundamental freedoms of the data subject do not outweigh the above-mentioned interests, Article 6 (1) (f) GDPR and where applicable UK GDPR.
b. Rights under the GDPR and where applicable UK GDPR
You are entitled to exercise the following free rights against anyone responsible for processing your personal data:
-
Right to withdraw your consent (Article 7 (3) GDPR) and where applicable UK GDPR;
-
Right of access by the data subject (Article 15 GDPR and where applicable UK GDPR
-
Right to rectification and erasure (Article 16 and Article 17 GDPR and where applicable UK GDPR
-
Right to restriction of processing on the processing of your personal data (Article 18 GDPR and where applicable UK GDPR);
-
Right to data portability (Article 20 GDPR/ and where applicable UK GDPR);
-
Right to object to the processing of your personal data at any time for reasons relating to your special situation (Article 21 GDPR and where applicable UK GDPR)
Should you wish to contact us by e-mail, please use an address used to access our system so that we can identify you.
You also have the right to lodge a complaint with a competent supervisory authority, Article 77 GDPR and where applicable UK GDPR.
3. Third country transfer
As the controller is established in Israel, personal data may be transferred to and processed in Israel.
The European Commission has recognised Israel (commercial/private sector) as providing an adequate level of protection pursuant to Article 45 GDPR. For transfers from the United Kingdom, the UK adequacy regulations recognise Israel as providing an adequate level of protection, where applicable.
Where we process personal data in a third country (i.e. outside the European Union (EU), the European Economic Area (EEA) or, where applicable, the United Kingdom (UK)), or where such processing takes place in connection with the use of third-party services or the disclosure or transfer of personal data to other persons, authorities or companies, we do so only in accordance with the applicable legal requirements under Articles 44–49 GDPR and, where applicable, the UK GDPR.
This includes, in particular:
-
Personal data may be transferred to countries or territories for which the European Commission (or, where applicable, the UK Government) has adopted an adequacy decision pursuant to Article 45 GDPR and/or the UK GDPR, including Israel (commercial/private sector), where applicable.
-
Where no adequacy decision exists, transfers are carried out only if appropriate safeguards are in place, in particular by entering into the European Commission's Standard Contractual Clauses pursuant to Article 46 GDPR (and, where applicable, the UK International Data Transfer Addendum or UK International Data Transfer Agreement), or where another transfer mechanism under Articles 44–49 GDPR and, where applicable, the UK GDPR applies, such as approved certification mechanisms or binding corporate rules.
As part of the EU-U.S. Data Privacy Framework, the European Commission has recognised that personal data may be transferred to U.S. organisations certified under the EU-U.S. Data Privacy Framework, as these organisations are deemed to provide an adequate level of protection within the meaning of Article 45 GDPR. For transfers from the UK, the UK Extension to the EU-U.S. Data Privacy Framework (UK-US Data Bridge) may apply where the recipient is appropriately certified.
The European Commission's adequacy decision of 10 July 2023 and the list of certified organisations, together with further information on the Data Privacy Framework, are available at: https\://www.dataprivacyframework.gov/. We inform you of the use of certified service providers in the relevant sections of this privacy notice.
Our data protection requirements apply to all processors, including our service providers. These processors support us in the provision of our website and our services. They have been carefully selected, are contractually bound in accordance with Article 28 GDPR, act only on our documented instructions, are regularly monitored, and do not process personal data for their own purposes.
4. Recipients, third country transfer, linked third party websites
Some personal data may be accessible to our authorised employees (such as administration, sales, marketing, legal, and IT) to the extent necessary for the performance of their duties.
We may also disclose personal data to carefully selected third parties, including hosting and cloud service providers, IT and security service providers, payment service providers, telecommunications providers, professional advisers (such as accountants, auditors and legal counsel), banks, and public authorities where required by law or where necessary to establish, exercise or defend legal claims.
We use third-party services to ensure our website is functional, secure, visually appealing, and continuously optimized.
Where personal data is transferred to recipients located outside the EU, the EEA or, where applicable, the UK, such transfers are carried out only in accordance with the requirements set out in Section 3 ("Third country transfer").
Links to third-party websites may be provided for your convenience. These websites are operated by independent controllers. Please review their privacy policies before disclosing personal data, as we are not responsible for the privacy practices or data processing activities of such third parties.
Where third parties act as our processors, they process personal data solely on our documented instructions, are contractually bound in accordance with Article 28 GDPR, have been carefully selected and are subject to appropriate oversight. They do not process personal data for their own purposes.
An updated list of our processors and categories of recipients is available upon request, subject to our legal obligations and the protection of confidential information.
5. Data security
We use technical and organizational measures to protect personal data from accidental or unauthorized access, loss, or manipulation. We regularly review and update our technical and organisational security measures to ensure an appropriate level of protection.
6. Children
Our website is not intended for children. We do not knowingly collect personal data from children unless permitted by applicable law. Where processing is based on consent, we process personal data of children only where the applicable legal requirements regarding the age of consent have been met, including, where required, the consent of the holder of parental responsibility.
7. Automated decision making
We do not use automated decision-making within the meaning of Article 22 GDPR and, where applicable, UK GDPR that produces legal effects concerning you or similarly significantly affects you. However, we may use profiling techniques for analytics, statistical purposes and to improve our services. Such profiling does not result in automated decisions producing legal or similarly significant effects.
8. Retention periods
In line with Articles 17 and 18 GDPR and where applicable UK GDPR, we delete or restrict processing of data when it is no longer needed for its intended purpose. Server log files are generally deleted after 12 months, unless required a longer period under applicable law. Data may be retained longer where required for security purposes, legal obligations or the establishment, exercise or defence of legal claims. Data may be retained beyond this period only if required for lawful reasons or legal retention obligations, such as tax and company law documentation.
C. Data Collection and processing of User data when using our website
The data collected by us is either directly or indirectly provided by you. The information is either automatically collected in the course of the user’s view of our website. We collect and process the following User data.
Information collected automatically when you visit our website:
-
the date and time of accessing one of our Internet pages; -
-
your browser type;
-
the browser settings;
-
the operating system used;
-
the last page you visited;
-
the amount of data transferred and the access status (file transferred, file not found, etc.) and;
-
your IP address (which may be shortened or pseudonymised where technically possible).
Information additionally provided by you, through contact form:
-
first name and last name;
-
your Company’s size /employees;
-
company Name / website;
-
email address;
-
phone number.
-
selected appointment date and time;
-
time zone;
-
information voluntarily provided in the booking form;
-
email addresses of additional guests, where provided.
Information additionally provided by you, during the account sign-up
-
first and last name;
-
email address;
-
user role / permission level;
-
password / authentication credentials;
-
profile image, where provided;
-
phone number, where provided;
-
job title, where provided;
-
time zone;
-
data communicated while using the service.
The personal data is stored on our systems and on the servers of our hosting service provider acting on our behalf. Our website is hosted on Google Cloud Platform (GCP), provided by Google Cloud EMEA Limited and/or Google LLC. Google Cloud acts as our processor and processes personal data only on our documented instructions pursuant to Article 28 GDPR and, where applicable, UK GDPR. Personal data processed in connection with the hosting of the website may therefore be stored and processed on GCP infrastructure in accordance with applicable data protection laws and appropriate safeguards where international data transfers occur.
We do not store server log data together with other personal data unless this is necessary for security purposes or the investigation of technical incidents. Temporary storage of the IP address by the system is necessary to enable the delivery of the website to your device. The temporary processing of your IP address is technically necessary to enable communication between your device and our website. We do not evaluate this data on a personal basis, particularly not for profiling or marketing purposes. Unless otherwise described in this Privacy Policy, we do not use server log data to identify individual users or for marketing purposes.
The processing of the aforementioned data is technically necessary for the operation, stability and security of our website and is carried out on the basis of our legitimate interests pursuant to Article 6 (1) (f) GDPR and UK GDPR where applicable. We store server log files, including shortened or pseudonymised IP addresses where technically possible, for a period of 30 days, in order to ensure the security and integrity of our IT systems, detect attacks and prevent misuse.
The storage and hosting of our website is provided through Google Cloud Platform (GCP). Google Cloud acts as our hosting infrastructure provider and processes personal data solely on our documented instructions and in accordance with a data processing agreement concluded pursuant to Article 28 GDPR and UK GDPR where applicable. The hosting provider may process personal data, including inventory data, contact data, content data, contract data, usage data, metadata and communication data, solely on our behalf for the purpose of hosting, maintaining and operating the website. The processing is based on our legitimate interest in the secure and efficient provision of our website pursuant to Article 6 (1) (f) GDPR and UK GDPR, where applicable.
Further information on each type of personal data collected is provided in the relevant sections of this Privacy Policy or by specific explanatory text displayed prior to the collection of the relevant personal data
Please do not hesitate to contact us if you have any questions about privacy policy, the information we hold about you, or if you wish to exercise any of your privacy rights.
1. Third-Party Single Sign-On Service
Users can log in to our website using third-party services instead of registering directly. You must already be registered with the third-party provider to do this. Thus, registering on our website is not necessary. You will find the relevant provider symbols on the registration or login page, and you can then select the provider you want to use. You will then be redirected to the third-party provider's site, where you can enter your login credentials. This will result in some of your profile data being transmitted to us from the third-party provider. You can find out which information is transmitted in the third-party provider's privacy policy. We never receive the password you use with the third-party provider. Depending on the provider and your settings, we may receive your name, email address and a unique user identifier. We never receive your password used with the third-party provider. This information will then be combined with the data listed under section d, provided you choose to provide it. The use of third-party single sign-on services is based on our legitimate interest in providing users with a convenient and secure authentication option pursuant to Article 6 (1) (f) GDPR and where applicable UK GDPR. Where required by applicable law, processing is based on your consent pursuant to Article 6 (1) (a), Article 7 GDPR and where applicable UK GDPR.
We use the following service in accordance with the privacy policy. Further information about the data protection assessment of our cooperation can be found in the linked privacy policy.
You can also find out how to exercise your rights with the third-party provider.
LinkedIn Single Sign-On: LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland. https://www.linkedin.com/legal/privacy-policy
2. Demo versions of our services
If you request or use a demonstration version (demo) of our products or services, we will process the personal data you provide (e.g. name, company, business contact details and the information provided as part of your enquiry) in order to process your enquiry, grant you access to the demo, run the demo, provide technical support and communicate with you in connection with the demo and a potential business relationship and ensure the stability and performance of the services.
Whilst you are using the demo, we also process technical information and usage data to the extent necessary to provide the demo, ensure IT security, analyse errors, prevent misuse and improve our products and services. This may include, in particular, your IP address, device and browser information, timestamps, log data and information about your use of the demo.
The processing is carried out for the purpose of taking pre-contractual measures at your request in accordance with Article 6 (1) (b) GDPR and where applicable UK GDPR. Insofar as the processing serves to ensure the security of our systems, to administer the demo, to analyse errors or to further develop our products and services, it is carried out on the basis of our legitimate interest in accordance with Article 6 (1) (f) GDPR and where applicable UK GDPR. Where personal data is transferred to the controller established in Israel, the transfer is based on the European Commission's adequacy decision pursuant to Article 45 GDPR (commercial/private sector) and, where applicable, the UK adequacy regulations for Israel. Where personal data is transferred to recipients in other third countries, this is done exclusively in compliance with the legal requirements and using appropriate safeguards, in particular the European Commission’s Standard Contractual Clauses or other permissible transfer mechanisms.
We store your personal data only for as long as is necessary for the purpose of conducting the demo, establishing a business relationship, complying with statutory retention obligations, or for the establishment, exercise or defence of legal claims.
3. Calendly
We use the Calendly tool to schedule and manage appointments for product demonstrations (demos) of our products and services. Calendly is a service provided by Calendly, LLC, BB&T Tower, 271 17th St NW, Atlanta, GA 30363, USA. When you book a demo appointment, we process the personal data you provide (such as your name, email address, company name and preferred appointment time) for the purpose of organizing and conducting the requested product demonstration and communicating with you in connection with your request. Your personal data is processed for the purpose of taking pre-contractual measures or for the performance of the contractual relationship with you in accordance with Article 6 (1) (b) GDPR and where applicable UK GDPR. Where the use of Calendly in individual cases does not serve the purpose of entering into or performing a contract, processing is carried out on the basis of your consent in accordance with Article 6 (1) (a), Article 7 GDPR and where applicable UK GDPR.
When using Calendly, the following personal data in particular is processed: first name, surname, email address, telephone number and the information you voluntarily provide in the booking form, including, where applicable, any uploaded documents or images.
We use the data you provide exclusively for the planning, execution and follow-up of the agreed appointment. It will be deleted as soon as it is no longer required for these purposes and provided that no statutory retention obligations prevent its deletion.
Calendly is used on the basis of a data processing agreement in accordance with Article 28 GDPR and where applicable UK GDPR. Calendly acts solely on our instructions and processes personal data exclusively for the purpose of providing the appointment scheduling service.
Calendly LLC is certified under the EU-U.S. Data Privacy Framework. Where personal data is transferred to the United States, the transfer is based on the EU-U.S. Data Privacy Framework pursuant to Article 45 GDPR where Calendly is certified. Where applicable, the UK Extension to the EU-U.S. Data Privacy Framework may apply for UK transfers. Where the Data Privacy Framework does not apply, appropriate safeguards such as Standard Contractual Clauses may be used. Further information on data protection at Calendly can be found at https\://calendly.com/pages/privacy.
4. Contact, CRM
Depending on the nature of your enquiry, we process your personal data either for the purpose of taking steps at your request prior to entering into a contract or for the performance of a contract pursuant to Article 6 (1) (b) GDPR and where applicable UK GDPR, or on the basis of our legitimate interest in responding to general enquiries pursuant to Article 6 (1) (f) GDPR and where applicable UK GDPR. Where you have given your explicit consent processing of your personal data, processing is based on Article 6 (1) (a), Article 7 GDPR and where applicable UK GDPR. We use your contact details solely to respond to your enquiry and communicate with you regarding your request.
When you contact us via our form, we need the following data to answer your request and so that we can address you personally and assign your request:
-
Company Name,
-
First and last name,
-
Work e-mail-address,
-
Telephone-number.
After your enquiry has been completed, we will delete your personal data unless further storage is required by law or necessary for the establishment, exercise or defence of legal claims.
Where a business relationship exists or is reasonably expected based on previous communications, we may store your contact details in our customer relationship management ("CRM") system. The legal basis for this processing is our legitimate interest pursuant to Article 6 (1) (f) GDPR and, where applicable, the UK GDPR in efficiently managing customer and prospective customer relationships.
Personal data stored in the CRM system is reviewed every two years at the end of the relevant calendar year to determine whether continued retention is necessary. If continued storage is no longer required and no statutory retention obligations apply, the personal data will be deleted.
GoodWord processes personal data on our behalf as a processor. We have therefore concluded a data processing agreement in accordance with Article 28 GDPR and, where applicable, the UK GDPR.
Where GoodWord or its sub-processors process personal data outside the EU, the EEA or, where applicable, the UK, such transfers take place only in accordance with the safeguards described in Section 3 ("Third country transfer"). This includes, where applicable, transfers to organisations certified under the EU-U.S. Data Privacy Framework pursuant to Article 45 GDPR or, where required, the use of the European Commission's Standard Contractual Clauses and other appropriate safeguards.
5. Comment function
We offer you the opportunity to comment on some of our blog posts. The personal data processed includes your name, the content of your comment and your email address.
Where the comment function provides for publication, your name (or the name you choose to display) and the content of your comment will be publicly visible. Your email address will be used solely for the administration of the comments feature and will not be published or disclosed to other users.
In addition, we store the categories of data listed under ‘Log files’ in order to ensure the security of our systems, prevent misuse of the comments feature and, where necessary, to assert or defend legal claims.
The legal basis for the processing and publication of your comment is your consent in accordance with Article 6 (1) (a), Article 7 GDPR and where applicable UK GDPR. The processing of technical data generated in connection with the use of the comment function (in particular log files) is carried out on the basis of our legitimate interests pursuant to Article 6 (1) (f) GDPR and where applicable UK GDPR, for the purposes of ensuring the security and integrity of our systems, preventing misuse of the comments feature, and establishing, exercising or defending legal claims.
If you wish to withdraw your consent to the publication of a comment, please contact us using the contact details provided in this Privacy Policy. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal. Upon receipt of your request, we will remove the published comment unless continued storage is required by law or is necessary for the establishment, exercise or defence of legal claims.
6. Application
We process the personal data you provide to us during the application process for the purpose of managing application-related activities, which include the organisation and conduct of interviews and tests for applicants, as well as the analysis and assessment of the results of these interviews, and as otherwise required in the context of the application and recruitment process. The legal basis for processing applicant data is Article 6 (1) (b) GDPR and, where applicable, the UK GDPR, insofar as the processing is necessary to take steps prior to entering into an employment relationship. Where German employment law applies, Section 26 (1) German BDSG constitutes the relevant legal basis for processing personal data for purposes related to the establishment of an employment relationship.
Furthermore, we process your data where we require it to fulfil legal obligations (Article 6 (1) (c) GDPR and where applicable UK GDPR or for the purpose of defending or asserting legal claims, in particular to defend against claims under the German General Equal Treatment Act (AGG), where German law applies – as a legitimate interest on the basis of Article 6 (1) (f) GDPR and where applicable UK GDPR against us.
Mandatory information is marked accordingly in the application form. As part of the application process, we generally process the following personal data provided by you:
-
Applicant’s basic details (name, address, contact details, job advertisement, current position if applicable),
-
Information on qualifications (cover letter, CV, previous employment, professional qualifications),
-
(Employment) references and other certificates.
You may also provide further, voluntary information:
-
Application photograph,
-
where applicable, details regarding status as a person with a severe disability,
-
Contact details such as first and last name; email address and telephone number; CV/resume and information contained therein, such as employment history, education, skills and professional qualifications; LinkedIn profile URL, where provided; the position/job for which you are applying; responses to application or screening questions defined by the employer; and personal notes as part of the application process;
-
other information provided voluntarily.
Where your application contains special categories of personal data (for example, information relating to health, religion or ethnic origin), we process such data only where this is necessary to exercise rights or comply with obligations in the field of employment and social security law pursuant to Article 9 (2) (b) GDPR and, where applicable, the UK GDPR. Where German employment law applies, Section 26 (3) German BDSG constitutes the applicable national legal basis.
During the application process, we will use all the information you provide to progress your application and to assess whether we can offer you a position with us. We are also required to fulfil our legal obligations as an employer. The provision of the personal data requested in the application process is necessary for us to assess your application and conduct the recruitment process. Failure to provide information required for the assessment of your application may result in us being unable to consider your application.
We will use your contact details solely to get in touch with you and to keep you informed about the progress of the application process. We will use any other information contained in your application documents exclusively to assess your suitability for the post in question.
The data in the database is used to contact applicants should a vacancy arise that appears to be of interest to them. We will include your application data in this database if you give your consent to this during the application process. You may withdraw your consent at any time by contacting info@dueto.io. The legal basis for processing data in the database is Article 6 (1) (a), Article 7 GDPR and where applicable UK GDPR. You may withdraw your consent at any time with effect for the future. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
Generally, we process and store your data only for as long as is necessary for the purpose described above or as long as we are required to retain the data due to legal obligations. In the event that, following the application process, an employment, apprenticeship, work placement or other employment relationship is established, the data will initially continue to be stored and transferred to the personnel file.
Unless statutory retention obligations require longer storage, unsuccessful applications will be deleted six months after completion of the recruitment process, unless continued retention is necessary for the establishment, exercise or defence of legal claims.
We will inform you separately about the retention period for your personal data in the event that an employment relationship is established. Following the rejection of your application, if you wish to be considered for future recruitment processes, we will store your application documents in the talent pool on the basis of your consent, in accordance with Article 6 (1) (a), Article 7 GDPR and where applicable UK GDPR, and Section 26 (2) German BDSG. In this case, we will obtain your consent separately. Consent is entirely voluntary and does not affect your current application. Your application documents will initially be retained for a further 12 months from the date you give your consent, provided that longer retention is not necessary to defend legal claims. A further 12-month extension of the retention period requires your renewed consent.
7. Newsletter
Your personal data is used to send you newsletters related to the services you have subscribed to via e-mail. We use third-party services to send you these newsletters.
We use SendGrid, a service provided by Twilio Inc., 889 Winslow St, Redwood City, CA, 94063, USA. Twilio acts as our processor pursuant to Article 28 GDPR and where applicable UK GDPR and processes personal data solely on our documented instructions.
By registering on the mailing list or for the newsletter, you need to sign up to the newsletter with your e-mail address. To verify that the owner of the e-mail address has given consent, we use a double opt-in procedure. After submitting your e-mail address via our subscription form, you will receive a confirmation e-mail asking you to confirm your subscription. You must click the confirmation link contained in this e-mail to complete your subscription. If you do not confirm your subscription, you will not receive any newsletters from us. We analyse the performance of our newsletter campaigns. Each time an email is opened, a file contained within it (known as a web beacon) connects to our newsletter server. This allows us to determine whether the newsletter has been opened and which link, if any, have been clicked on.
Technical information is also recorded, such as the time of retrieval, IP address, browser type and operating system. Where the use of web beacons or similar technologies involves storing information on or accessing information from a user's end device, this is carried out on the basis of your consent pursuant to Section 25 German Telecommunications Digital Services Data Protection Act (TDDDG), where applicable.
The information is evaluated primarily on an aggregated basis to measure the effectiveness of our newsletter campaigns and improve future communications. It is used exclusively for the statistical analysis of newsletter campaigns. The results of these analyses can be used to adapt future newsletters to better suit the interests of recipients. If you do not want your data to be analysed, you must unsubscribe from the newsletter.
The legal basis for sending newsletters and, where applicable, analysing newsletter interactions is your consent pursuant to Article 6 (1) (a), Article 7 GDPR and, where applicable, the UK GDPR. Where newsletter tracking involves storing or accessing information on your end device, the legal basis is also your consent pursuant to German Section 25 TDDDG, where applicable. Your data will be stored and processed in an electronic newsletter system for the duration of your subscription. You may withdraw your consent at any time with effect for the future by using the unsubscribe link contained in every newsletter or by contacting us using the contact details provided in this Privacy Policy. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal. Following your withdrawal, your personal data will no longer be processed for newsletter distribution or newsletter tracking unless another legal basis permits further processing.
Twilio acts as our processor and we have concluded a data processing agreement in accordance with Article 28 GDPR and, where applicable, the UK GDPR. Where personal data is transferred outside the EU, the EEA or, where applicable, the UK, such transfers are carried out in accordance with the safeguards described in Section 3 ("Third country transfer"). This includes, where applicable, transfers to organisations certified under the EU-U.S. Data Privacy Framework (including the UK Extension where applicable) or, where required, the use of the European Commission's Standard Contractual Clauses together with any supplementary measures required by applicable law
8. Social media
Where our website contains only links to our social media profiles, no personal data is transmitted to the respective provider merely by visiting our website. Such links do not constitute embedded social media content or social media plugins.
Where we embed social media content or functions that require the storage of or access to information on your end device (for example, through social media plugins or embedded content), such processing is carried out only on the basis of your consent pursuant to Article 6 (1) (a), Article 7 GDPR and, where applicable, the UK GDPR. Where required, consent is also obtained pursuant to German Section 25 TDDDG (where applicable), before information is stored on or accessed from your end device.
We also provide links to our profiles on various social networks. The integration takes place solely via a linked graphic or icon of the respective social network. Clicking on the relevant icon redirects you to the website of the respective social media provider. Only after you actively click on the icon will a connection to the servers of the respective provider be established.
If you access the social media platform while logged into your user account, the provider may associate your visit with your user account. If you interact with the platform, for example by using a "Like", "Share" or similar function, this information may also be linked to your account and, depending on your privacy settings, made publicly available. If you wish to prevent such association, you should log out of your social media account before visiting the respective platform.
We would like to point out that once you access the respective social media platform, the provider acts as an independent controller. We have no influence over or knowledge of the processing of personal data carried out by the respective provider. Please refer to the provider's privacy policy for further information.
The respective provider may process personal data, including your IP address, browser information, device information, the date and time of access and the pages visited, in accordance with its own privacy policy. Such processing may also take place in countries outside the EU, the EEA or, where applicable, the UK, including the United States.
Where the provider participates in the EU-U.S. Data Privacy Framework (and, where applicable, the UK Extension thereto), transfers are based on the adequacy decision adopted pursuant to Article 45 GDPR and, where applicable, the UK GDPR. Where no adequacy decision applies, transfers are carried out on the basis of the European Commission's Standard Contractual Clauses together with any supplementary safeguards required by applicable law.
The following social networks are integrated into our site via links:
a. X (formerly Twitter)
X Corp., Market Square, 1355 Market Street, Suite 900 San Francisco, CA 94103, USA.
Privacy Policy: https://x.com/privacy
b. Meta (formerly Facebook)
Meta Platforms Inc., 1601 Willow Road, Menlo Park, CA 94025, USA.
Privacy Policy: https://www.facebook.com/about/privacy/
c. LinkedIn
LinkedIn Corporation, 1000 W Maude Avenue, Sunnyvale, California 94085 USA.
Privacy Policy: https://www.linkedin.com/legal/privacy-policy
d. Instagram
Meta Platforms Inc., 1 Hacker Way, Menlo Park, CA 94025, USA.
Privacy Policy: https://privacycenter.instagram.com/policy/
9. Cookies and integrated third-party offers
Our website uses cookies and similar technologies, such as local storage and pixels. Cookies are small text files that are stored on your end device by your browser when you visit our website. They enable certain information to be stored and retrieved in order to ensure the proper functioning of the website, improve user experience and, where applicable, analyse website usage.
You can configure your browser settings to determine whether cookies may be stored on your end device. For example, you can disable the storage of cookies completely, restrict it to certain websites, or configure your browser to notify you before a cookie is stored. You may also delete cookies at any time using your browser settings. Please note that disabling or deleting cookies may affect the functionality and availability of certain features of our website.
Where cookies or similar technologies involve the storage of information on, or access to information stored on, your end device, such processing is carried out in accordance with German Section 25 TDDDG, where applicable. Any subsequent processing of personal data is carried out in accordance with the applicable provisions of the GDPR and, where applicable, the UK GDPR.
Technically necessary cookies and similar technologies are used where they are required to provide and operate our website securely and correctly. Where the use of such technologies requires the storage of or access to information on your end device, the legal basis is German Section 25 (2) TDDDG, where applicable. Where personal data are processed in connection with such technologies, the legal basis is our legitimate interest pursuant to Article 6 (1) (f) GDPR and, where applicable, the UK GDPR.
All other cookies and similar technologies are used only with your prior consent. Where consent is required, the storage of or access to information on your end device is based on German Section 25 (1) TDDDG, where applicable, and any subsequent processing of personal data is based on Article 6 (1) (a), Article 7 GDPR and, where applicable, the UK GDPR.
10. Statistics, Web-Analytics, Advertising based on Tracking and Retargeting - Use of Cookies
Occasionally, we and our service providers use cookies and similar technologies (e.g. pixel technologies, local storage or log file analysis) where this is necessary or where you have given your consent. Cookies are small text files that can be stored on your device when you visit our website. Various technologies can be used for tracking, such as pixel technology or log file analysis.
Where cookies or similar technologies involve the storage of information on, or access to information stored on, your end device, this processing is carried out in accordance with German Section 25 TDDDG, where applicable. Any subsequent processing of personal data is carried out on the basis of the applicable provisions of the GDPR and, where applicable, the UK GDPR.
Consent is obtained via our cookie banner, which requires an active opt-in. Unless otherwise stated, the processing activities described in this section are based on your consent pursuant to Article 6 (1) (a), Article 7 GDPR and, where applicable, the UK GDPR. Where required, consent pursuant to German Section 25 TDDDG is also obtained. You may withdraw your consent at any time with effect for the future via the cookie settings available on our website.
Web-Analytics, Statistics
In order to ascertain the content of our website that is of most interest to you, we undertake continuous measurement of the number of visitors and the most viewed content. For this purpose, we process pseudonymised usage data including
-
the number of visitors to our website;
-
the duration and timing of visits;
-
the sequence of visits to different pages and website areas in order to optimize our website.
We also record the sequence of visits to different websites and product sites in order to optimize our website.
a. Web Analysis through Google Analytics 4
The use of Google Analytics 4 is based on your consent pursuant to Article 6 (1) (a), Article 7 GDPR and, where applicable, UK GDPR, as well as German Section 25 TDDDG where applicable. For the purposes of analysis and optimisation of our website, we use the service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, and Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. In Google Analytics 4, IP anonymisation is activated by default. Where applicable, Google truncates IP addresses within the EU or EEA before further processing. Only in exceptional cases may the full IP address be transmitted to Google servers in the United States and shortened there. According to Google, the IP address transmitted by your browser as part of Google Analytics 4 is not merged with other Google data.
The following data may be processed when you visit our website:
-
IP address (generally shortened/anonymised where applicable);
-
approximate location (country and city);
-
technical information such as browser type, internet service provider, device information and screen resolution;
-
usage behaviour on the website (pages visited, clicks and scrolling behaviour);
-
source of the visit (e.g. referring website or advertising medium);
-
session duration and interactions with website content;
-
clicked links and completed actions (such as conversions, where configured).
Google processes this information on our behalf to analyse your use of our website, compile reports on website activity and provide further services related to website and internet usage. Google Analytics 4 may use automated technologies, including machine learning, to analyse and model data.
The retention period for user-level data is configured in accordance with our settings in Google Analytics 4. Cookies used by Google Analytics 4 may remain stored for up to two years unless deleted earlier by you or your browser settings.
We have configured Google Analytics 4 as follows:
-
IP anonymisation enabled;
-
advertising features disabled;
-
personalised advertising disabled;
-
remarketing disabled;
-
Google Signals disabled;
-
data sharing with Google products and services and other optional Google services disabled.
We have concluded a data processing agreement with Google in accordance with Article 28 GDPR and, where applicable, the UK GDPR.
Where personal data is transferred to the United States, such transfers are carried out in accordance with the safeguards described in Section 3 ("Third country transfer"), including, where applicable, the EU-U.S. Data Privacy Framework pursuant to Article 45 GDPR and, where applicable, the UK GDPR, provided that the recipient is certified. Where no adequacy decision applies, appropriate safeguards such as the European Commission's Standard Contractual Clauses may be used.
Further information on Google Analytics 4 can be found at:
https://policies.google.com/privacy
b. Microsoft Clarity
We use the service Microsoft Clarity on our website (provided by Microsoft Corporation, One Microsoft Way, Redmond, WA 98052 USA).
We use Microsoft Clarity to analyse how visitors interact with our website, including through heatmaps and session recordings where enabled. The use of Microsoft Clarity is based on your consent pursuant to Article 6 (1) (a), Article 7 GDPR and, where applicable, UK GDPR, as well as German Section 25 TDDDG where applicable.
Information relating to usage and users, such as IP addresses, approximate location, times and frequencies of visits to our website, interaction data and technical information relating to your device, may be transferred to and stored on Microsoft servers. We use Microsoft Clarity with IP anonymisation enabled. This function enables Microsoft to truncate IP addresses within the EU or EEA.
We have concluded a data processing agreement with Microsoft in accordance with Article 28 GDPR and where applicable UK GDPR. Where personal data is transferred to the United States, such transfers are carried out in accordance with the safeguards described in Section 3 ("Third country transfer"), including the EU-U.S. Data Privacy Framework where applicable or other appropriate safeguards such as Standard Contractual Clauses.
Further information can be found here https://clarity.microsoft.com/privacy.
How Can You Contact Us?
Please contact us at info@dueto.io for further information, questions, or comments.
Last updated: September 9, 2026