Privacy Policy
1. General Information on Data Processing: Data Protection; Scope of Data Processing; Your Rights; Profiling and automated decision making; Data Security; Data Processing outside the EU; Contacting us
1.1 Data Protection
Data controller is CdC3 GmbH, Geschäftsanschrift: Greifswalder Str. 208, 10405 Berlin, registered with the commercial register at local court of Charlottenburg under HRB 221095 B, represented by Fabian Heinrich, email: info@mercanis.com, ("we/us" or "Mercanis"). We have appointed a data protection officer who can be reached at datenschutzbeauftragter@datenschutzexperte.de.
PROLIANCE GmbH
www.datenschutzexperte.de
Leopoldstr. 21
80802 München
datenschutzbeauftragter@datenschutzexperte.de
1.2 Scope of Data Processing
Personal data are any information relating to an identified or identifiable natural person. Applicable legal provisions are in particular those of the regulation (EU) 2016 We as well as our external service partners process your data for the purpose of providing the Website and services, including providing hard- and software through such external service partners. You provide data if this is necessary for the aforementioned purposes.
In the event you refrain from providing such data you may face legal disadvantages, for example, limited or no possibility of using our Website or no answer to your email send to us.
1.3 Your Rights
In accordance with the statutory provisions, you as the data subject have the following rights:
(a) the right to access,
(b) the right to rectification or erasure,
(c) the right to restriction of processing,
(d) the right to data portability,
(e) If you have provided us with your personal data on the basis of a consent, you could withdraw the consent at any time with effect for the future,
(f) You may object to the processing of your personal data, if your personal data are processed for direct marketing purposes and/or on the basis of legitimate interests pursuant to Art. 6 (1) f GDPR insofar as there are reasons for this arising from your particular situation.
To exercise these rights named above you may contact us at any, for example via email to datenschutzbeauftragter@datenschutzexperte.de. You have also the right to lodge a complaint with a supervisory authority at your choice (for example: Berliner Beauftragte für Datenschutz und Informationsfreiheit
https://www.datenschutz-berlin.de/kontakt.html).
An overview of the Data Protection Authorities may be found here: https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links
/anschriften_links-node.html or http://ec.europa.eu/newsroom/article29/item-detail.cfm?item_id=612080
1.4 Storing and Deleting data
The data are deleted if you withdraw your consent and/or such data are no longer necessary for the purpose of processing. The log files and IP addresses of website visitors, which we process as described below, are deleted within 30 days. Data are also stored as set forth in this privacy policy. Furthermore, we store your data if we are obliged to do so in accordance with legal retention periods (e.g. German Commercial Code (HGB) or German Fiscal Code (AO)) (legal basis: Art. 6 (1) c. GDPR). We may also store your data to enforce, exercise and defense legal claims (legal basis: Art. 6 (1) f. GDPR) with our legitimate interest that may be, for example, in the assertion of legal claims and defense in legal disputes. Criteria for storing data are the respective interests of you or us for storing such data for example considering economic and technical restrictions, the time periods offered by third party providers engaged by us etc.
1.5 Profiling and automated decision making
We do not use automated decision-making including profiling when processing data concerning our Website or Platform except as set forth herein. However, our third party providers may carry out such profiling in individual cases. We will inform you about such fact if possible. Profiling means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.
You have the right not to be subject to a decision based solely on automated processing, including profiling, which has legal effect on you or substantially impairs you in a similar manner.
1.6 Data Security
For a best possible security of user data our service through the Website is provided via a secured SSL connection between your server and the browser. That means that the data shall be transferred in encrypted form. We have implemented suitable technical and organizational measures.
1.7 Data Processing by Third Parties / Data Processing outside the EU
We may use third party service providers that process your data for the purposes named in this privacy policy. We process your personal data by using third party providers in the EU and the USA, whereas data protection standards applicable in the EU are ensured. A list of the data processors processing data outside the EU and corresponding information is available by request via email to datenschutzbeauftragter@datenschutzexperte.de.
1.8 Contact Us
If you send us an e-mail or contact us in another way, your details in this online form or request, including the contact data, name, email address and other data provided respectively, are processed by us in order to deal with your inquiry or to be able to contact you at a later time for follow up questions. These data are processed only on the basis of your consent (legal basis Art. 6 (1) a. GDPR) or on the basis of an initiating or existing business relationship with us (legal basis Art. 6 (1) b. GDPR or TMG).
2. Visiting The Website
2.1 Visiting the Website
We (or the webspace provider) collect data on each visit to our website mercanis.com ("Website") (so-called Server log files), which include: Name of the Website visited, file, date and time of the visit, data amount transferred, information on a successful call, browser type as well as version, operating system of the user, referrer URL (the page visited before), IP address and the requesting provider as well as the following, if a mobile end device is being used:
country code, language, name of device, name of operating system and version
We use these server log files only for statistical evaluations for the purpose of optimizing our services and in order to guarantee the stability and operational security of the Website. When personal data (such as the IP-address) are stored the legal basis for this is Art. 6 (1) c. GDPR or Art. 6 (1) f. GDPR based on our legitimate interest of quality assurance or TMG.
2.2 Careers Section on our Website
We will also process your data through the careers section of the Website. Such data may include name, email, address and telephone number, gender, your career history, qualifications, country of residence, language skills and any other personal information you include in your interactions with us. We may also ask for additional information to assist us with our recruitment process and in the event you are offered a job an example would be date of birth, work documents. You may also share details of other people with us; for example, if somebody else referred the job to you (someone you know at Mercanis or otherwise). In those circumstances, you will need to check with that person that they are happy for you to share their personal information with us, and for us to use it in accordance with this privacy policy.
We process your personal data for fulfilling our contractual or pre contractual obligations (based on Art. 6 (1) b. GDPR) or -- as applicable -- for the purpose of the employment relationship with you (Section 26 BDSG), in particular, we use your data:
(a) to get in touch with you, communicate with you, update you and to facilitate your application,
(b) to offer an online-application system that is connected to our website,
(c) to respond to your questions or concerns,
(d) to carry out vetting of staff members (where required); this may involve our collection and use of sensitive personal information including information obtained from criminal background checks about offences or alleged offences and information relating to any proceedings for offences committed or allegedly committed,
(e) when necessary and for the purposes of our legitimate interests to maintain adequate records, we may collect and handle information related to medical information, ethnic origin or criminal records,
(f) to assist in any disputes, claims or investigations relating to your application, or
(g) to comply with our legal, regulatory and professional obligations.
We may also use your data with your explicit consent (based on Art. 6 (1) a. GDPR or Section 26 BDSG), for example to keep you informed about other opportunities if you wish us to do so. If you do not provide your personal data, you may face certain disadvantages, for example we will not be able to provide you with our recruiting processes or keep you informed about future opportunities.
We also use third party service providers for processing your career data. For job applications and the recruiting process we work together with the software recruiting service by Recruitee, Personio, LinkedIn Recruiter and process your data according to this privacy policy and as described in the Greenhouse’s Privacy Policy (http://www.greenhouse.io/privacy-policy) and on the basis of a Data Processing Agreement. Greenhouse may process your data outside the EU/EEA. Greenhouse is certified according to the EU-US agreement “Privacy Shield”. The “Privacy Shield” is an agreement between the European Union (EU) and the USA to ensure compliance with European data protection standards in the USA. Further information is available by request via email to datenschutzbeauftragter@datenschutzexperte.de.
A list of the data processors processing data (outside the EU) and corresponding information is available by request via email to datenschutzbeauftragter@datenschutzexperte.de.
With your explicit consent, we will keep your information in case any other opportunities become available which you might be interested in; we will only keep your information for a limited period and your details will be deleted on a general basis after 12 months of inactivity on your account latest. You may withdraw such consent with effect for the future at any time via email to datenschutzbeauftragter@datenschutzexperte.de.
3. Cookies And Third Party Providers On The Website
3.1 Cookies
Our Website uses so-called cookies. Cookies do not cause any harm to your device and do not contain any viruses. Cookies serve the purpose of making our service more user-friendly, more effective and safer. Cookies are small text files which are stored on your device and in your browser. Most of the cookies we use are so-called session cookies. After the end of the session these cookies will be deleted automatically. The session cookies are used in order to associate successive page requests with the individual users, who at the same time access our Website. Other cookies will be stored on your device until you delete them. These cookies enable us to recognize your browser during your next visit.
By clicking "I agree" in the cookie banner appearing on your screen when visiting mercanis.com for the first time you agree that all cookies set out in this clause will be set. This applies both to regular cookies and essential cookies; essential cookies are such cookies which are necessary to correctly display the Website and/or carry out its basic functionalities. If you, however, choose to not agree with our usage of those non-essential cookies – either by ignoring the banner or by clicking the top right "X" – only essential cookies will be set. Your decision will be stored in one cookie which is used to recognize your browser during your next visit, so you will not be asked again until you decide to delete this cookie. Please find information on how to opt-out in connection with cookies in general in the following paragraph and in particular in the respective subsection of this clause.
You can adjust your browser to notify you, before you receive a cookie or to decide to accept cookies on a case-by-case basis, to completely or partly exclude all incoming cookies and to activate the deletion of cookies automatically when the browser is closed. You may manage many online advertisement cookies provided by companies via the American web page http://www.aboutads.info
/choices/ or the web page of the European Union http://www.youronlinechoices.com
/uk/your-ad-choices/. We would like to inform you that the usage and especially the convenience of usage without using any cookies may be limited.
In the event personal data are processed such processing is based on Art. 6 (1) a. GDPR.
3.2 Google Analytics
The service offered here uses Google Analytics, a web analytics tool offered by Google LLC, Mountain View, CA, USA ("Google"). This analysis service uses so-called "cookies". For analysis, text files will be stored on your device. The information stored in the corresponding files about the use of this website are generally transmitted and stored in Google server in the USA. As the IP anonymization is active on this Website, your IP address will be shortened by Google within the member states of the European Union (EU). This information will be used to evaluate your use of the services offered here and enable the operator of this website to analyze your website activity and provide other services associated with the website service. The IP address transmitted from your browser, as part of Google Analytics will not be merged with other data from Google.
Adjusting the settings of your browser Platform can prevent the use of cookies. In this case, it may be possible that the functions of the service offered here cannot be used in its entirety. Furthermore, it is possible to prevent the acquisition and processing of data generated by the "cookies" in relation to the use of this website, by downloading and installing the browser plugin available at the following link: https://tools.google.com
/dlpage/gaoptout
We point out that an automated decision making ("profiling") can take place when integrating Google and an existing Google account.
Opt-out: https://adssettings.google.com
/authenticated
3.3 Google Fonts
Our Website uses the "Google Fonts" service of Google LLC, Mountain View, CA, USA to integrate and display text on the Website. For this purpose Google may process your data (including the IP address) on servers located in the USA.
When the IP address is processed this is based on our legitimate interests of technical functionality of the Website based on Art. 6 (1) f. GDPR or TMG.
Google LLC is certified according to the "Privacy Shield" agreement between the European Union and the USA and guarantees compliance with applicable European data protection regulations (see: https://www.privacyshield.gov/). You can also find more information in Google's privacy policy: services.google.com/sitestats/en.html
3.4 Google Tag Manager
Our Website uses the Google Tag Manager by Google LLC, Mountain View, CA, USA. Google Tag Manager is a solution that allows marketers to manage website tags through a single interface. The tool Google Tag Manager itself (which implements the tags) is a cookieless domain and does not collect any personal data. The tool triggers other tags, which in turn may collect data. Google Tag Manager does not access this data. If deactivation has been made at the domain or cookie level, it will remain in effect for all tracking tags implemented with Google Tag Manager. You can also find more information in Google's privacy policy: services.google.com/sitestats
/en.html
3.5 Zapier
We use Zapier provided by Zapier, Inc. (548 Market St. #62411. San Francisco, CA 94104-5401) (“Zapier”), a web-based, application integration and data linking service. To show compliance with EU data protection standards Zapier is certified according to the EU-US-Privacy-Shield (see: https://www.privacyshield.gov). We have concluded a Data Processing Agreement (DPA) with Zapier. The legal basis for our use of Zapier is Art. 6 a. GDPR. For more information visit: zapier.com/privacy.
3.6 Integration of Services by Third Parties
When using this online service, contents of third parties, like for instance, links to Instagram, YouTube videos, map material provided by Google Map, RSS feeds or graphics are integrated from other websites. This always requires that the providers of this content ("Third Party Providers") use the IP address. Without this IP address these Third Party Providers would not be able to send the content to your browser. Consequently, the IP address is required in order to display the content. We make every effort to only use such content by Third Party Providers which use the IP address for the delivery of content only.
Such data are used in order to guarantee the stability and operational security of the websites of the Third Party Providers as well as for the purpose of optimizing our services via quality assurance. If the IP address is stored such processing is basedon Art. 6 (1) b., c. GDPR, Art. 6 (1) a. GDPR or TMG.
In the event of displayed content by Third Party Providers your data may be processed outside the EU.
3.7 HubSpot
We are using HubSpot, a marketing automation tool, which will trigger messages based of user action. The legal basis for our use of HubSpot is Article 6 (1) a. GDPR.
4. Data Processing On Our Social Media Pages
We operate pages on the following social media channels:
(a) Facebook: facebook.com or mobile app by Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA or Facebook Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland, please refer to privacy policy: https://www.facebook.com
/policy.php,
OptOut:
https://www.facebook.com/ads
/preferences or
https://www.facebook.com/settings;
(b) Instagram: instagram.com or mobile app by Facebook Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland, please refer to privacy policy: http://instagram.com/about
/legal/privacy/;
Opt-Out:
https://www.instagram.com
/accounts/
privacy_and_security/;
(c) Twitter: twitter.com or mobile app by Twitter Inc., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA, please also refer to privacy policy: https://twitter.com/en
/privacy, Opt-Out: https://twitter.com
/personalization;
(d) LinkedIn: linkedin.com or mobile app by LinkedIn Corporation, Legal Department -- Privacy, 1000 W. Maude Ave, Sunnyvale, CA 94085, USA / LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland, please also refer to: https://www.linkedin.com
/legal/privacy-policy, https://www.linkedin.com
/psettings/privacy
When you visit our social media pages, data is processed both by us and by the responsible social media provider as the responsible party. The respective provider of social media assumes the data protection obligations towards you as the user, such as information on data processing, and is the contact person for your rights. This follows from the fact that such provider has direct access to the relevant information on the social media page and the processing of your data. However, you are also welcome to contact us if this should become necessary and we will then forward the request to them.
When using Facebook, Instagram, Twitter or LinkedIn data may also be processed outside the EU. The US companies of Facebook/Instagram, Twitter and LinkedIn are certified in accordance with the EU-US Privacy Shield agreement, which guarantees compliance with data protection regulations in the EU. For more information please refer to: https://www.privacyshield.gov
4.1 Data Processing and Legal Basis
With our social media pages, we can communicate with you and provide you with interesting information. We may receive further data from you through your comments, shared images, messages and reactions, which we then process to answer or communicate with you. If you use social media on several end devices, a cross-device analysis of the data can take place. Furthermore, the providers of social media pages may also use cookies and tracking technologies to analyse and improve their services.
Data processing takes place with your consent or for the purpose of answering your enquiry (Art. 6 (1) a, b GDPR) or on the basis of legitimate interests in improving the services and presentation to the outside world (Art. 6 (1) f GDPR).
4.2 Facebook
Facebook and we use the Page Insights function to process statistical data from users of our Facebook pages (see also the agreement at: https://www.facebook.com
/legal/terms/
page_controller_addendum). This involves the processing of data in the form of so-called 'page insights', which are described in more detail at https://www.facebook.com
/business/a/page/page-insights.
Evaluations and statistics are generated in the form of page insights from the usage data of the Facebook pages, which support us in improving our marketing activities and our external presence. We may also learn about users and their behavior who interact with or use our Facebook Pages to display relevant content and develop features that may be of interest to them. These page statistics show us, for example, which people from certain target groups interact most with our Facebook Page or which content on the Facebook Page was visited, shared or licked when and how often. When classifying people into target groups, demographic data or data about the location of a person is also included in order to place targeted advertisements with these people. If you use Facebook on several end devices, a cross-device analysis of the data can take place. The data collected in this way is statistically processed and usually anonymous, i.e. we cannot establish any reference to the individual person.
Information on these page insights and data processing can be found, for example, in Facebook's data protection statement at https://www.facebook.com
/policy.php or at https://www.facebook.com
/business/a/page/page-insights.
Facebook also uses cookies and storage technologies. More information can be found here: https://www.facebook.com
/policies/cookies/
As a Facebook user, you can at any time influence how your user behavior is recorded when you visit Facebook pages. To do this, you can manage the settings for advertising preferences in your Facebook account or at https://www.facebook.com
/ads/preferences, or the Facebook settings in your account or at https://www.facebook.com
/settings. Facebook also provides opportunities to contact or exercise rights at https://www.facebook.com
/help/contact
/2061665240770586 or
https://www.facebook.com
/help/contact
/308592359910928.
4.3 Instagram
When using Instagram and you have an account there, Instagram can assign your activities to your profiles there. Instagram and we use the Instagram Insights function to process statistical data from users of our Instagram pages (see also for Facebook which is connected to the provider of Instagram the agreement at: https://www.facebook.com
/legal/terms
/page_controller_addendum). This involves the processing of data in the form of so-called 'Instagram Insights' which are described in more detail at https://help.instagram.com
/788388387972460?helpref=faq_content.
Evaluations and statistics are generated in the form of Instagram Insights from the usage data of the Instagram pages, which support us in improving our marketing activities and our external presence. Instagram Insights lets us learn more about our users and the performance of our content with you as audience. For this purpose Instagram provides us with statistics on specific posts and stories created to find out how users interacted with them. When classifying people into target groups, demographic data or data about the location of a person is also included in order to place targeted advertisements with these people. If you use Instagram on several end devices, a cross-device analysis of the data can take place. The data collected in this way is statistically processed and usually anonymous, i.e. we cannot establish any reference to the individual person.
Instagram also uses cookies and similar technologies. For more information please refer to: http://instagram.com/about
/legal/privacy/
As an Instagram user, you can at any time influence how your user behavior is recorded when you visit Instagram pages. To do this, you can manage the settings for advertising preferences in your Instagram account or under https://www.instagram.com
/accounts
/privacy_and_security/. Instagram also provides opportunities to contact or exercise rights at https://help.instagram.com
/contact
/1845713985721890 or
http://instagram.com/about
/legal/privacy/.
4.4 Twitter
When you use Twitter, even if you're just looking at Tweets, Twitter receives some personal information from you like the type of device you're using and your IP address. Twitter uses this information for things like showing you more relevant Tweets, people to follow, events, and ads, as described in detail in the Twitter privacy policy. This may also involve providing your payment information to Twitter to use their paid services. Twitter also uses cookies and similar technologies. For more information please refer to https://help.twitter.com/en
/rules-and-policies/twitter-cookies.
As Twitter user, you can at any time influence how your user behavior is recorded when you visit Twitter pages. To do this, you can manage the settings for advertising preferences in your Twitter account or under https://twitter.com
/personalization or
https://twitter.com/de/privacy
#overlay-chapter2.10.1 or without an account under https://pscp.tv/account
/settings. Twitter also provides opportunities to contact or exercise rights at https://help.twitter.com/forms
/privacy.
4.5 LinkedIn
LinkedIn and we may use your data for careers and recruiting services for our LinkedIn pages (see also the data processing agreement: https://legal.linkedin
.com/dpa). Data on how you use LinkedIn may be shared with us and certain third parties as described in detail here: https://www.linkedin.com
/legal/privacy-policy#share LinkedIn also uses cookies and similar technologies as set forth here: https://www.linkedin.com
/legal/cookie_policy
As LinkedIn user you can at any time influence how your user behavior is recorded when you visit LinkedIn pages. To do this, you can manage the advertising and general settings in your account under https://www.linkedin.com
/psettings/privacy. LinkedIn also provides opportunities to contact and exercise rights under https://www.linkedin.com
/legal/privacy-policy, https://www.linkedin.com
/legal/cookie-policy and for individual messages online via https://www.linkedin.com
/help/linkedin/ask/TSO-DPO.
5. Questions ?
For further information you may contact us any time, for example via email to datenschutzbeauftragter@datenschutzexperte.de.