Skip to Content
  •  +49 (861) 88 00 32 00
COD powered by extocode GmbH
  • 0
  • Sign in
  • Contact Us
  • Home
  • COD Overview
    Platform
    OverviewFeaturesIntegrationsPricing
    Operations & Network
    MonitoringNetworkNetwork Access Control (NAC)Captive PortalFirewall
    Security & Resilience
    Governance, Risk & ComplianceVulnerabilities (VAS)BackupHypervisorOTPAutomation
    Solutions & More
    NIS2 & CompliancecodPassLive demoReferencesDownloadsFAQ
  • Pricing
  • News
  • FAQ
  • About us
    • About us
    • Careers
    • References
  • Contact
COD powered by extocode GmbH
  • 0
    • Home
    • COD Overview
    • Pricing
    • News
    • FAQ
    • About us
      • About us
      • Careers
      • References
    • Contact
  •  +49 (861) 88 00 32 00
  • Sign in
  • Contact Us

Privacy Policy

I.     Controller for the Processing of Personal DataII. Our Data Protection Principles III. Our Internet Contact PointsIV. Communication V. Analytics, Marketing, and TrackingVI. Events and Competitions, Trade FairsVII. Customer Service VIII. Security Measures IX. Business Partners X. ApplicantsXI. Data Protection AuthorityXII. List of Third-Party Providers and Their Use

I.     Controller for the Processing of Personal Data

We, extocode GmbH, are the provider of the services described below (hereinafter "we" or "provider"), including the respective processing of personal data. This privacy notice provides you, the user of the services (hereinafter "you"), with information about the relevant processing of personal data for all contact points at which you interact with us.


II. Our Data Protection Principles


As part of providing the services described here and operating websites and other contact points, we process your personal data in various ways. We provide you with comprehensive information about the processing of personal data as well as the principles according to which this processing takes place.

We take the protection of your personal data very seriously. We therefore process your data with great care and in strict compliance with the applicable data protection laws and the individual consents that you may have given us. We have taken organizational and technical security measures to protect all of our websites, apps, and other (digital) contact points from the potential risks associated with the processing of personal data. Our partners who support us in providing the services must also comply with these provisions.

Please use the contact details provided in this privacy policy to contact us in general or with specific questions and/or requests regarding data protection.

Depending on the country in which you are located, different data protection laws apply. Based on the principles of the European General Data Protection Regulation[1] ("GDPR"), we have established the following fundamental guidelines for the processing and protection of your personal data when providing our website and services:


[1] REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC


1.       Lawfulness

We use personal data only where it is lawful, which is only the case if at least one of the following conditions is met:

  • You have given your consent.
  • The use of personal data is necessary for the performance of a contract to which you are a party.
  • The use of personal data is necessary to comply with a legal obligation , e.g. in the case of product safety measures where we are obliged to inform all of our customers.
  • The use of personal data is necessary for the protection of vital interests of the person, e.g. in cases where we inform individual customers about product safety issues.
  • The use of personal data is based on a legitimate interest in using personal data, and our use does not unreasonably affect your data protection rights.

For all processing of personal data described here, we also state the legal basis for the processing at the end of each main section, as well as in the description of the specific third-party service providers we use in Section XII of this privacy notice.

2.       Fairness and Transparency

In this privacy policy, we inform you in a fair and transparent manner about which personal data we collect and why we collect it. You can access the privacy policy directly or via a link when you register and/or at any contact point at which you interact with us.

Users under the age of 16 should only transmit personal data to us with the consent of their legal guardians. The data protection law applicable in your country may result in different age limits.

​3.       Purpose Limitation and Data Minimization

We only collect and use personal data that we really need and for the purpose for which you provided us with the personal data. If we can achieve the purpose with less personal data, we only use the minimum data required. Nevertheless, you are free at any time to provide additional personal data if this would improve your experience with the services offered.

4.       Types of Processing Including Third Parties

In cases where we do not process your personal data directly as the controller (e.g. website hosting, technical services, etc.), we commission third parties to provide these services on our behalf as processors. These contracts oblige them to process your personal data in a lawful and secure manner. This is referred to as a relationship between controller and processor and is defined in Art. 28 GDPR, with us being the controller and the respective third party the processor. You can find a list of the third-party providers we have commissioned in Section XII.

Joint controllership describes the situation in which several parties, including us, jointly decide how data is used and managed (joint controllers, see Art. 26 GDPR). Joint controllers must provide clear information about who processes which personal data and which obligations each party has assumed with regard to the applicable data protection regulations. The joint controllers agree on their roles and ensure that the data subjects (persons to whom the data relates) are informed about these roles. If we use a third-party provider or partner that processes personal data as a joint controller, we will inform you of the corresponding rights and roles in the list of third-party providers in Section XII at the end of this document.

Sometimes it is necessary to transfer personal data to a third party that acts as an independent controller in its own name and on its own account, e.g. when we commission a shipping company to send you products. In these cases, we have agreed minimum data protection standards with these independent controllers in order to protect your personal data.

Our website may also contain links to third-party websites whose content is not provided or controlled by us. In these cases, we have no control over the processing of your data on their websites or their compliance with data protection regulations, but we will inform you, e.g., when you leave our website. Please refer to the privacy notices that these third parties may provide.

5.       Cross-Border Processing Within and Outside the EU

Since some of the third parties that provide services for us (as described in this document) are not located in your country, the processing of your personal data may also involve a cross-border transfer of your personal data. Our goal is to process personal data only within the European Union, so most third-party providers process personal data in European data centers.

If this is not technically possible or if there is another reason why personal data may also be processed outside the European Union, we follow the principles set out in Art. 44 et seq. GDPR. We safeguard such transfers through contracts (based on specific legal transfer mechanisms) that we conclude with such providers, or on the basis of an adequacy decision of the Commission of the European Union, including the EU-US Data Privacy Framework ("DPF"). You can also find information on whether a provider participates in the DPF and actively meets the requirements at:

https://www.dataprivacyframework.gov/s/participant-search

6.       Security

We process your data in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical or organizational measures. When we commission a third party to process personal data, we also agree on an appropriate level of technical or organizational measures that these providers must comply with.

7.       Rights of Users

You have the following rights vis-à-vis us, which we will fulfill promptly and appropriately upon receipt of your corresponding request as described below:

  • Your right of access to your personal data pursuant to Art. 15 GDPR: We will inform you whether we have stored any personal data about you and, where applicable, provide you with information about this data.
  • Your right to rectification of your data pursuant to Art. 16 GDPR: We will correct inaccurate information or complete incomplete personal data, provided that this data is necessary for the intended purpose of processing your data.
  • Your right to erasure of your data pursuant to Art. 17 GDPR: We will erase the personal data stored about you, unless this data is subject to retention periods or retention rights, for example because we are required to retain your data to fulfill our contractual obligations or due to legal regulations.
  • Your right to restriction of processing of your data pursuant to Art. 18 GDPR: In the cases specified in Art. 18(1) GDPR, you can request that we block your data. We will only continue to process blocked data to a very limited extent, and only where this is necessary for the provision of services or the fulfillment of obligations that must be met after the blocking of your data that you requested.
  • Your right to withdraw consent pursuant to Art. 7(3) GDPR: For data processing that requires your consent, you can withdraw your consent at any time to prevent the future processing of your data. Data processing based on your consent prior to your withdrawal remains valid and lawful.
  • Your right to object to the processing of your data pursuant to Art. 21 GDPR: You can object to the future processing of your data if we process your data on the basis of one of the legal grounds specified in Art. 6(1)(e) or (f) GDPR. If you object, we will stop processing your data unless we have compelling legitimate grounds for continued processing that override your interests and rights, or which are necessary for the establishment, exercise, or defense of legal claims. The processing of your data for the purpose of direct marketing never constitutes a compelling legitimate ground for us.
  • Your right to data portability pursuant to Art. 20 GDPR: If the data processing is carried out automatically and is based on consent or a contract, we can provide you with the data you have provided to us in a structured, commonly used, and machine-readable format.
  • Your right to lodge a complaint with a supervisory authority: You can submit a complaint regarding data protection to a data protection authority. To do so, please contact the data protection authority responsible for your place of residence or the data protection authority whose jurisdiction we are subject to (see Section XI Data Protection Authority).

If you wish to exercise your rights, please contact the following email address: datenschutz@inducio.de

8.       Erasure Principles

We process your personal data only for specified, necessary purposes. As soon as the purpose of the processing has been fulfilled, we erase your personal data, unless there is a retention obligation or a right to longer storage. This applies to all personal data, regardless of how and where it is stored.

There are various local laws, such as tax or commercial laws, that set out the legal requirements for the retention of data. In addition, we may retain personal data on the basis of legitimate interests, e.g. to comply with product safety laws to protect our customers. We may also retain personal data for business purposes if the GDPR recognizes these purposes as justification for retention, e.g. retaining customer data to defend against legal claims.

Access to personal data stored solely for the purpose of fulfilling statutory retention periods or rights is restricted as soon as the original purpose of the data collection no longer applies. This ensures that the personal data is no longer actively used in our business operations.

9.       Data Protection Officer

If you have any questions about data protection or would like to exercise your rights, our data protection officer (DPO) will be happy to assist you. You can simply contact our DPO directly by sending a letter or email to the contact details provided below. He will be happy to address your concerns and support you in exercising your rights under the data protection laws. Please contact:

extocode GmbH

Attn.: Data Protection

Kotzingerstr. 21,

D-83278 Traunstein, Germany

Email: datenschutz@extoco.de

Phone: +49 (0)861/ 88003200


10.     Changes to This Privacy Notice

This privacy notice reflects the current status of data processing on our website and other contact points (e.g. administration, ticketing system, social media accounts, etc.). In the event of changes to data processing, this privacy notice will be updated accordingly. We always make the current version of this privacy notice available on our website so that you can inform yourself about the scope of data processing via this website.



III. Our Internet Contact Points

1.       Websites

a)       Provision of the Websites Themselves

To display the website correctly in your internet browser, we use various technical means to ensure that all content (texts, images, videos, etc.) is up to date and displayed correctly. The content of the website is provided directly by our own servers, without the use of external content delivery networks (CDN). This ensures that all data processing related to the display of the website takes place exclusively within our controlled infrastructure. The data generated in connection with the provision of the website is used exclusively to display the content in your browser and is deleted immediately after the caching required for provision.

b)       Categories of Data

For technical reasons, your internet browser automatically sends information to our web server each time you access our website (so-called log data). We store some of this information in log files, such as:

  • date and time of access,
  • URL and files of the accessed website, including the amount of data transferred
  • version of the HTTP protocol used, including the operating system type
  • type and version of the internet browser
  • IP address.

The above-mentioned log data does not contain any personal data. We analyze log data only when necessary, for example to remedy disruptions in the operation of our website or to manage security incidents.

In addition, it may be necessary for us to record the complete IP address of the device in addition to the log data in order to remedy disruptions or to secure evidence in connection with security incidents.

We delete this data after the error has been remedied, the security incident has been fully clarified, or when the original purpose of the processing is no longer required. In the event of a security incident, we transmit log data to the investigating authorities on a case-by-case basis, insofar as this is permissible and necessary.

2.       Our Social Media Pages

a)       General

The protection of your privacy when processing personal data is important to us. We process the personal data transmitted to us that is collected during your visit to our respective social media page (e.g. LinkedIn) confidentially and only in accordance with the statutory provisions.

b)       Categories of Data

The social media service processes your personal data as soon as you use our respective social media page. The processing is related, for example, to the following usage activities:

  • accessing a page or a post or video from a page
  • subscribing to or unsubscribing from a page
  • marking a page or post with "like" or "unlike" or similar functions
  • recommending a page in a post or comment
  • commenting on, sharing, or replying to a page post (including the type of response)
  • hiding a page post or reporting it as spam
  • clicking on another website on the social media provider, or on a website outside the social media provider on a link that leads to the page
  • moving the mouse over the name or profile picture of a page to display a preview of the page content
  • using the functions of the social media provider, such as the website, the phone number, the "plan route" button, or other buttons on a page
  • the information whether the login takes place via a computer or a mobile device.

c)       Recipients/Categories of Recipients

In addition to us, the respective operator of the social media page is responsible for the processing of your data via our social media page (see examples below). Insofar as the processing of this data takes place within our area of responsibility, we are available to you for all questions regarding data protection and the exercise of your rights in accordance with the information provided in this privacy notice. You can find out which personal data is collected by the social media provider, how it is processed, and which data protection rights you have vis-à-vis the social media provider in the following privacy policies of the social media provider. We have no influence on the data processing carried out by the social media provider.

d)       Data Processing by Us

On the website that we provide via the social media provider, the social media provider grants us access to the following categories of data:

  • The social media provider grants us access to statistical evaluations that provide us with information about the use of our social media website. The evaluations visible to us do not enable us to analyze the usage behavior of individual persons. We can only view aggregated data (such as the number of accesses, likes, followers, region of origin, age group, gender, etc.) that gives us insight into our system users and the use of our social media page. The data of the respective user on which the analyses are based is not transmitted to us.
  • We can define the target audience for the social media website or for individual published articles. The setting is based on general parameters (e.g. age group, language, region, interests) that allow us to tailor our content to specific groups. It is not possible for us to address or identify individual persons on the basis of the data provided to us by the social media provider.
  • If you contact us directly via the social media provider or interact with us in another way and consciously transmit personal data in the process (e.g. direct connection with our social media website), we store and process this personal data for the purposes for which you transmitted it to us
  • We process this data exclusively for the purpose of making content on our social media website known to the target audience and better understanding and optimizing the use of our social media website.

Beyond this, we have no influence on the data processing (for the provision of this data in advance) by the social media provider within its area of responsibility.

Please inform yourself with the respective third-party provider about which personal data is collected by it in detail, how it is processed, and which data protection rights you have vis-à-vis the respective social media provider (see list of third-party providers (Section XII)):

3.       Social Media Plugins as Hyperlinks

Some content on our website can be shared on social networks such as LinkedIn via integrated social media buttons. All social media buttons that enable content to be shared are integrated via simple hyperlinks and not via social plugins of the social network providers. This ensures that your data is not automatically transmitted to the servers of the social networks as soon as you access our website. When you share content from our website, we also only transmit the information to the social network that is required to share the relevant content (e.g. the link to the content you want to share). We do not transmit any personal data in this context.

At the same time, you will also find direct links to our websites on social networks. If you follow a link from our website to a social network or log in to your social network to share content from our website, your data will be processed by the provider of the respective social network.

If you are registered and logged in with other networks or services that require registration while you use our website or individual functions, the respective network/service may collect information about your usage or adopt settings, such as played videos/playback status. However, this data is collected exclusively by the respective network/service under its own data protection responsibility and processed by the respective provider.

For information about the purpose and scope of the data collection, the further processing and use by the respective network operator, as well as your related rights and setting options for protecting your privacy, please refer to the privacy notices on the website of the respective provider.

4.       User-Generated Content (UGC) from Social Media

UGC from social media enables us to share content created by customers and published on social media or other channels, such as texts, images, videos, and reviews, on our social networks. We acquire the rights to your content through a separate license agreement. When using such UGC, various types of personal data may be associated with the UGC. This data may include:

  • Profile information: This may include the username, the profile picture, and any other information that you have provided directly in your social media profile.
  • Posts and comments: Content that you have posted or commented on, including text, photos, videos, and links, may be processed.
  • Location data: If you have activated the location services in your social media account, the location information may be processed when you post content or interact with it.
  • Data from friends/followers: A user's connections or followers on social media may be processed if this is relevant to the user-generated content used.

Please note that the specific personal data that is processed may vary depending on the social media platform and the data protection settings you have chosen.

5.       Legal Basis for the Data Processing

We base the above-mentioned data processing operations on a legal permission pursuant to Art. 6(1)(f) GDPR, with the exception of UGC, which is based on a legal permission pursuant to Art. 6(1)(b) GDPR.



IV. Communication


1.       Contacting Us

If you contact us outside a specific contractual relationship (e.g. to provide information) or a registration, we offer you various contact options, including purely technical ones, via our websites.

In order to process your specific request when you contact us in this way, we may ask you to provide personal data. This includes, for example, your name and email address, as well as further information such as the subject of your request and your message. Optionally, you can provide your postal address and/or phone number. We collect the requested information in order to be able to process your request appropriately.

The personal data transmitted to us in this way is used exclusively for the purpose for which you provide it to us when contacting us – in particular for processing your request. The data is not used for other purposes or passed on to third parties without your express consent. Excepted from this are – insofar as this is necessary to fulfill your request – the persons and companies (e.g. local service companies) involved in conducting the communication and answering the request.

Unless there are statutory retention obligations, your personal data will be deleted after your request has been processed.

2.       Contact by Telephone

You can contact us by telephone. We do not operate a call center and do not use any external call center services. Your call is always handled directly by our own employees.

When you call us, we may create a ticket in our internal ticketing system in order to document and process your request. The process depends on the type of call:

2.1 Direct Calls to Employees (No Automatic Ticket Creation)

If you call one of our employees directly (e.g. via their extension or direct dial number),  in our internal ticketing system, no ticket is automatically created.

  • A ticket is only created if this is necessary to process your request, and then exclusively manually by the employee handling your call.
  • In this case, the employee may enter your personal data into the ticketing system, such as:
    • name,
    • contact details,
    • date and time of the call,
    • reason for the call,
    • relevant details discussed (e.g. technical problems, agreements, notes on further steps).

This serves to document and efficiently process your request.

2.2 Priority Calls (PRIO) with Automatic Ticket Creation

In certain priority cases ("PRIO") our telephone system (PBX system) automatically creates a priority ticket in our internal ticketing system as soon as the call comes in.

  • This applies in particular if your call is classified as a priority call (e.g. via a specially designated priority number or a corresponding configuration of our PBX system).
  • In these cases, the PBX system automatically creates a PRIO ticket, which is then processed by our employees with the corresponding priority.

For this purpose, in particular the following data may be processed and stored in the ticket:

  • technical call data (e.g. caller number, time and duration of the call),
  • classification as a priority call (PRIO),
  • where applicable, information manually added by the caller (e.g. name, reason for the call, details of the incident) as a voice attachment.

Further Processing in Both Cases (Direct and PRIO Calls)

  • Ticket and Call Logging:
    When a ticket is created (manually or automatically), we log information such as your name (if provided), your contact details, the date and time of the call, the reason for your call, and relevant details that were discussed. This information is stored in the internal ticketing system in order to process your request and ensure efficient handling of your request.
  • Call Recording (optional):
    With your prior consent, we may record calls for quality assurance or training purposes. In this case, audio data is processed that may contain personal data disclosed during the call. If a recording is made, it may be linked to the corresponding ticket.
  • Internal Forwarding:
    Personal data may be processed in order to assign your ticket or request to the responsible employee or department depending on the nature of your request or your preferences. For this purpose, we may also use technical systems, including artificial intelligence (AI), to categorize requests and assign them to the responsible team.
  • Identity Verification:
    Our employees may need to process personal data (e.g. name, customer number, contact details) in order to verify your identity before providing account-specific information or making changes to your data or contracts.
  • Problem Solving and Support:
    To help you solve problems or answer your questions, our employees may access customer data or internal databases. In doing so, your personal data is processed as necessary to handle your request and document the outcome in the ticket.

For the technical provision and maintenance of our telephone and internal ticketing systems, we may use IT service providers that act as processors on our behalf. However, these service providers do not operate a call center and do not conduct their own customer communication; communication with you takes place exclusively through our own employees.

3.       Chatbot

The chat function (where available) enables us to answer your questions about our products and services promptly. When you ask a question in the chat, an application attempts to answer your questions. Through the use of potential artificial intelligence (AI), the system can send you relevant links or forward your request to a customer service representative in the live chat. We use the chatbot to process your request and to improve our business and our services. We use the services of a technical service provider to enable the chatbot function on our websites and via other contact points.

As part of the chat functionality, the following personal data may be processed:

  • mandatory information for initiating a chat
  • chat history as a transcript ("transcript")
  • IP address, approximate location, browser type and version, device type, visitor path
  • usage data (e.g. time of chat start, chat end, chat duration, chat performance data)
  • other content processed in the chat (e.g. phone number, email address)

4.       Surveys

We conduct surveys on your satisfaction with our products and services. We may ask you for feedback, for example via a form on our websites, or send you an email. When we ask you to rate our products and services by email, you can rate them on a scale of up to ten points. In addition, you can leave comments in a free-text field or, where applicable, provide your phone number to receive a callback regarding your rating and comments. Participation in these surveys is entirely voluntary. We store the data you provide us in such a survey together with your contact details and transaction data relating to the product or service we provided to you. We use this data to improve our products and services. Your personal data is anonymized after 12 months.

When we conduct surveys on our website, these are generally anonymous. If, in exceptional cases, we collect data from you as part of a survey, the preceding paragraph applies.

5.       Newsletter

On our website, you have the option to subscribe to our newsletter. We use a double opt-in procedure to verify that the holder of an email address has actually registered to receive the newsletter. The newsletter is only successfully subscribed to if the holder of the email address has expressly confirmed the activation of the newsletter by clicking the link in the confirmation email. We log the performance of the individual steps of the double opt-in procedure for evidentiary purposes.

For this purpose, we collect and process data about your use of our email newsletter. When you open an email newsletter from us, a file contained in the email (a so-called web beacon) establishes a connection to our servers. This allows us to determine whether an email newsletter has been opened and, if so, which content was clicked on. In addition, we collect technical information about the end device with which the content of the email newsletter is accessed (e.g. time of access, browser type, and operating system). We use this data exclusively for the statistical evaluation of our newsletter campaigns. If you subscribe to our newsletter and thereby consent to receiving it, your data will be used to send the newsletter and to analyze your use of the email newsletter. You can withdraw this consent at any time. The corresponding link is included in every issue of our newsletter. We will note in our database that you have unsubscribed from the newsletter.

6.       Legal Basis for the Data Processing

Depending on the nature of your contact with us, we base the above-mentioned data processing operations on a legal permission pursuant to

  • Art. 6(1)(a) GDPR based on your consent, e.g. for call recordings, newsletters, and surveys unrelated to a contractual relationship, as well as for surveys in which you have actively registered to participate;
  • Art. 6(1)(b) GDPR for (pre-)contractual communication, e.g. via our telephone contact or chatbots, questions about the delivery or return of products;
  • Art. 6(1)(f) GDPR in the event that you contact us, e.g. to conduct surveys.



V. Analytics, Marketing, and Tracking


1.       Analytics

Analytics refers to the process of collecting, processing, and analyzing data in order to gain insights and make decisions. For us, this is comparable to examining trends in order to better understand how you use our products and services. These insights enable us to make our products and services more user-friendly. They also allow us to identify areas in which our products and services can be improved and further developed in an innovative way. Our websites are integrated with analytics platforms. These platforms provide JavaScript code that is added to the website. This code interacts with cookies or similar technologies to collect data when users interact with our website. As users navigate the website, the analytics code collects data from the cookies/pixels. The data we collect includes information about page views, clicks, time spent on pages, and other relevant metrics.

Analytics platforms aggregate the collected data and provide us with insights into user behavior and website performance. This aggregated data is used to understand the demographics of the target audience, popular content, and areas that may need improvement.

2.       Marketing and Tracking (Including Re-Marketing)

We may collect and use your personal data in order to send you relevant marketing communications. These communications may include product updates, promotional offers, and newsletters. You can easily manage your communication preferences and unsubscribe if you wish.

We also carry out digital marketing activities, including retargeting. Retargeting, also known as remarketing, means displaying targeted advertising to users who have previously interacted with our website or our digital content but have not completed an action.

When a user visits our website and performs certain actions, a tracking pixel or cookie is placed on their device.

For further information about the providers, including information about the specific use and additional information on provider-specific data protection aspects, please refer to Section XII.

3.       Cookies and Similar Technologies

Cookies

4.       Legal Basis for the Data Processing

All of the processing described above, in particular the setting of pixels and cookies to read out information on the end device used, is only carried out if you have given us your consent to do so. You can withdraw your consent at any time with effect for the future, as described above under "Cookie Processing". Alternatively, you can use the opt-out page for EU customers at http://www.aboutads.info/choices or http://www.youronlinechoices.eu/.

We base the above-mentioned data processing operations on:

a)   Your consent pursuant to Art. 6(1)(a) GDPR:

  • web analytics and marketing via cookies and/or similar technologies

b) A legal permission pursuant to Art. 6(1)(b) GDPR

  • registration on our website
  • convenience registration (social sign-on option)

c) A legal permission pursuant to Art. 6(1)(f) GDPR:

  • technical cookies that are necessary for the provision of the website
  • interactive digital assistants
  • technical cookies for the display of the website (e.g. security functions)
  • additional website functions (e.g. product videos)
  • log data
  • session cookies and persistent cookies for convenience functions


VI. Events and Competitions, Trade Fairs

1.       Participation in Events

If you register for an event, we store and use the information you provide in order to carry out the event, including the follow-up. The data we collect for this purpose depends on the registration form on the respective websites on which you register. Your data will be deleted as soon as it is no longer required for carrying out the event or the follow-up. As a rule, such a registration process includes a confirmation email about your participation, additional emails about the organization/changes, and a follow-up email that may also include the option to give us feedback.

For some events, the participation fee is payable directly, or they are wholly or partly supervised and carried out by our partners. In this case, you may be redirected to the website of the respective partner. In this case, the relevant payment data (surname, first name, postal address, number of participants, and payment method) is transmitted to our partner in order to carry out the payment process for the event, provided that you have already provided this data.

2.       Participation in Prize Draws/Competitions

If you register for a prize draw or a competition, we store and use the information you provide exclusively for the purpose of organizing and carrying out the prize draw or competition, as well as for any necessary follow-up measures. The specific data we collect depends on the registration form that you fill out on the page for prize draws or competitions.

We delete your data immediately after the prize draw or competition has ended and all necessary follow-up measures have been completed. We only store your data for as long as is necessary for carrying out the prize draw or competition and all associated activities.

3.       Trade Fairs and Similar Events

We participate in both in-person and digital trade fairs. In this context, data processing, in particular of your contact details, takes place in the following cases:

  • if you express the wish to receive further information from us by email or post
  • establishing a business relationship
  • your participation in prize draws
  • your request for newsletters and promotional materials
  • answering questions about our products
  • your order

For further information, please refer to the sections "Communication", "Business Partners", and "Customer Service" in this policy. How detailed our processing of your personal data is depends on the context in which you provide your data.

4.       Legal Basis for the Data Processing

We base the above-mentioned data processing operations on a legal permission pursuant to Art. 6(1)(b) GDPR.

VII. Customer Service

We offer you contact points through which you can purchase products or services directly, e.g. via our websites, technicians, and telephone contact. With regard to the processing of personal data, the following interactions may take place when using these contact points.

1.          Typical Interactions

  • Browsing and Product Selection: Customers browse various products or services and compare features, prices, and reviews before making a decision.
  • Payment and Order Confirmation: Customers complete the payment process and receive a confirmation of their order, including an order number and the expected delivery date.
  • Inquiries and Support: Customers may have questions or need assistance regarding products, orders, shipping, returns, or other topics. They can reach support via various channels such as telephone, email, or chat.
  • Problem Solving: Support staff help resolve customer problems or concerns, e.g. regarding product defects, delivery delays, or invoice discrepancies.
  • Returns and Exchanges: Customers can request returns or exchanges for products that arrived damaged. Support assists them in initiating the returns process and provides them with the necessary instructions.

2.       Contract

In order to fulfill your orders and conclude a contract with you, we process the following personal data:

  • company name
  • form of address
  • first and last name, department, complete postal address
  • phone number
  • email address
  • invoice data

3.       Payment and Credit Checks

Your payment data is transmitted to the respective payment service provider in order to carry out the payment. If you use paid services, invoice data is processed. Your personal data may also be processed to investigate and prevent fraud, abuse, security-related incidents, and other harmful activities, e.g. to combat money laundering and for criminal prosecution. This is based on compliance with applicable laws (e.g. on the prevention of money laundering) as well as on our legitimate interest in limiting the risk of payment defaults.

We commission external service providers with tasks relating to payment processing, programming, and data hosting. We have carefully selected these service providers and monitor them regularly, in particular with regard to their careful handling and protection of the data they store. All service providers are obliged by us to maintain confidentiality and to comply with the statutory provisions. Service providers may also be other companies of Trianis Holding GmbH.

During the ordering process, we may carry out credit checks depending on the payment method you have chosen. We work with providers/agencies for credit checks and transmit your order data in order to obtain information for such checks. Before we carry out credit checks, we inform you specifically at the relevant contact point about how we handle your data.

4.       Delivery, Cancellation of an Order, and Returns

As part of the delivery process, we work with logistics service providers, and your contact details are passed on to our logistics service providers so that they can carry out the delivery and contact you in order to arrange deliveries and inform you of any delivery problems that arise. We may also use your order information to plan delivery routes.

You may also be offered the option to select a day and time frame convenient for you for the delivery of your orders. In this case, our logistics service providers and suppliers receive your order information in order to offer you the available appointment. In some cases, you can also track the status of your products via the tracking link we send you.

The information required for returns may be a combination of your order number/order information and company information (e.g. company name/department/address or email address). After you have handed in your return package at our logistics service provider, you will receive emails about the status of your return and your refund.

5.       Insurance/Warranty Extension

We collect your company data and optional personal data in order to enable the insurance service you have chosen and to improve your overall customer experience. This includes information required for creating policies, processing claims, and communicating regarding your insurance coverage.

We may collect information such as your name, your contact details, your address, and specific information about the product you have purchased. We pass this data on to our partners who offer the insurance or warranty extension. This ensures that our partners can tailor insurance solutions individually to your needs.

6.       Debt Collection Agencies

Under certain circumstances, it may be necessary to pass on relevant information to a debt collection agency in order to facilitate the settlement of outstanding payments.

The disclosure of data to a debt collection agency serves exclusively the purpose of collecting outstanding payments in connection with our products or services. This ensures a fair and lawful handling of financial transactions.

The information passed on to the debt collection agency may include details such as your company name, your contact details, invoice data, and details of the outstanding payment. The processing of the information takes place exclusively to the extent necessary for the proper and effective provision of the debt collection agency's services..

7.       Registration on Our Website / Customer Platform

You can register on our website in order to use our helpdesk services. As part of the registration process, we collect and process the following information:

Required information: company name, company address, VAT identification number, company phone number, company email address, title, first and last name, business phone number (mobile or landline), business email address, password.

We store the data of registered users until the user requests deletion of the account or the account is no longer required for the collaboration.

8.       Legal Basis for the Data Processing

We base the above-mentioned data processing operations on:

a)           A legal permission (performance of a contract) pursuant to Art. 6(1)(b) GDPR:

  • registration on our website
  • insurance/warranty extension
  • delivery (including delivery arrangements, shipment tracking, and returns)
  • customer service
  • product/service information by email
  • data processing for address verification
  • debt collection agencies

b)           A legal permission (legitimate interest) pursuant to Art. 6(1)(f) GDPR:

  • credit checks


VIII. Security Measures


1.       Product Recall

In the event of a product recall, we take proactive measures to ensure the safety of our customers. If you are affected by a product recall, we will notify you using the contact details you have provided, e.g. by email, in order to provide you with important information. To enable this communication, we use the contact details and associated product information stored in our customer database.

Please note that such a recall is a one-time data processing measure that serves exclusively the purpose of informing you about the product recall. Throughout the entire process, we attach the utmost importance to the security and confidentiality of your data. Your data is used exclusively for the purpose of processing the product recall and is not passed on or used for other purposes.

By promptly notifying you of product recalls, we aim to ensure your safety and make sure that you have the necessary information to take appropriate action.

​2.       Security Updates

We attach great importance to data protection and security and strive to continuously improve the security features of our products. In order to address potential vulnerabilities that may arise over time, we regularly offer security updates. These updates are of crucial importance for maintaining the integrity and security of your products.

We strongly recommend that you regularly commission us to install these security updates. In this way, you can ensure that your devices remain protected against potential security threats. If you do not have these updates installed, your personal data and connected devices may be exposed to unauthorized access or compromise.

3.       Specific Erasure Period

Personal data relevant to product safety measures is subject to a centrally defined specific erasure period of 30 years. After the regular erasure period has expired, this data is transferred to a separate, access-restricted archive for further storage. If you submit an erasure request via our website (see Section I above), your data will also be erased from this security archive regularly and promptly.

4.       Legal Basis for the Data Processing

We base the above-mentioned data processing operations on:

a)   Your consent pursuant to Art. 6(1)(b) GDPR:

  • security updates.

b)  A legal permission pursuant to Art. 6(1)(c) GDPR:

  • mandatory product recall.

c)   A legal permission pursuant to Art. 6(1)(d) GDPR:

  • voluntary product recall.




IX. Business Partners


1.       General

a)       Contractual Relationship with Business Partners

The following data protection notices apply to you if you are our business partner or a legal representative, employee, shareholder, or beneficial owner of a business partner. Business partners are legal entities or natural persons who are in negotiations with us about entering into a business relationship or who already have a corresponding business relationship with us. Contracts in connection with employment or training relationships are expressly excluded.

b)       Categories of Data

Which data is processed in detail depends heavily on the agreed services and the subject of our business relationship. Therefore, not all parts of this information are relevant to you.

As a rule, we collect your data directly from you. However, in certain constellations, due to legal regulations or legitimate interests (e.g. as part of compliance checks of business partners), it may also be necessary to process personal data that we receive from other companies, tax offices, authorities, credit agencies, insolvency registers, publicly accessible sources (internet research), or other third parties. The relevant personal data may include:

  • personal data (e.g. first and last name, address and other contact details, date and place of birth, and nationality)
  • legitimation and authentication data (e.g. extracts from the commercial register, identification data, signature sample)
  • company as well as position, function, and department in the company, superior
  • data within the scope of our business relationship (e.g. payment data, data on orders)
  • data on company structures and ownership relationships
  • log data
  • username and identification, user ID
  • compliance-relevant data (e.g. information on references, information on insolvencies
  • negative reports, checks against sanctions lists
  • information on criminal investigations in connection with the subject of the service
  • other data comparable to the aforementioned categories.

When concluding a contract, we may obtain data on your creditworthiness from credit agencies in order to fulfill the above-mentioned legitimate interests. We use the data from the credit agencies for credit checks in order to verify your creditworthiness. The credit agencies store data that they receive, for example, from banks or companies. You can obtain information about the data stored about you directly from the credit agencies.

If you conclude a contract with us using a digital signature, we process your associated data (in particular email address, IP address, times at which you edited the respective contract document). In addition, it is possible to sign certain contracts with a so-called qualified electronic signature. In this case, in addition to the categories mentioned, we also process the certificate data of your signature. This data is accessible to all persons involved in the approval and signing of the contract.

c)       Recipients/Categories of Recipients

Within our company, those departments receive access to the data you provide that need it to fulfill contractual or legal obligations or to protect legitimate interests, or that you have approved in the separate declaration of consent.

Within the scope of the contractual relationship, to fulfill legal obligations, and to protect legitimate interests, authorities or service providers also receive access to your personal data.

Compliance with the data protection regulations is ensured contractually. The data may also be passed on to companies within Trianis Holding GmbH in order to fulfill contractual obligations.

If you have concluded a framework agreement with the entire Trianis Holding GmbH as an authorized service provider, the respective procurement and purchasing departments of Trianis Holding GmbH receive access to the business partner data relevant for contacting you, and the national compliance departments of the companies of Trianis Holding GmbH each have access to the data for the compliance check of the business partners. Outside our group of companies, the data is only passed on if we are legally obliged to do so (e.g. in the case of official investigations).

2.       Legal Basis for the Data Processing

We base the above-mentioned data processing operations on:

a) A legal permission pursuant to Art. 6(1)(b) GDPR:

  • use of our website as a business partner (pre-contractual and contractual use)

b) A legal basis pursuant to Art. 6(1)(f) GDPR:

  • use of our website as a business partner (surveys, invitations to events, congratulations, and Christmas cards)
  • selection of a suitable business partner (e.g. intermediary check)


X. Applicants

As an applicant for a job vacancy, you can use one of our contact points to transmit your data to us. In addition to the information provided directly at the respective contact point (e.g. job page), we inform you below about our general handling of such personal data.

1.       General  

We use your applicant data

  • to identify you as an applicant
  • to get in contact with you
  • to carry out the application procedure

Your personal data is transmitted to

  • our employees responsible for your application
  • where applicable, to our service providers for the technical support of the application/applicant portal/job platform
  • where applicable, to our postal and logistics service providers.

Your personal data will be deleted as specified on the respective applicant website, unless we have received your consent to store your data for longer, e.g. for processing in an applicant pool. If there are legal or contractual obligations to retain such data, your data will be stored for as long as is necessary to fulfill these legal/contractual obligations, but access to your data will be restricted. For statistical purposes, some data originating, for example, from the application procedure is anonymized and further processed after the deletion of your personal data.

2.       Legal Basis for the Data Processing

We base the above-mentioned data processing operations on your consent pursuant to Art. 6(1)(a) GDPR for the retention of applicant data beyond the regular erasure period, or on a legal permission pursuant to Art. 6(1)(b) GDPR for the regular processing.



XI. Data Protection Authority

Germany: Bavarian State Data Protection Authority (BayLDA),  http://www.baylda.de



XII. List of Third-Party Providers and Their Use


  • LinkedIn as a business network is provided by the following companies:

​o   for countries of the European Union (EU), the European Economic Area (EEA), and Switzerland: LinkedIn Ireland  ​ ​Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland and

​o   for all other countries: LinkedIn Corporation, 1000 W. Maude Avenue, Sunnyvale, CA 94085, USA.

  • Google offers various services that are or can be used via our website. These services are provided by

Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland

General information on the processing of personal data when using Google tools can be found at the following link: https://policies.google.com/privacy. Opt-out: To permanently prevent the collection of usage data, Google offers a plugin for various internet browsers: http://www.google.com/settings/ads/plugin. To deactivate only interest-based ads, you can block the use of third-party cookies or cookies from the domain "www.googleadservices.com" or deactivate interest-based ads via this link at https://support.google.com/ads/answer/2662922?hl=en-GB.

We use the following Google tools in the following specific ways:

  • YouTube for presenting videos on our website. If you have rejected the use of cookies via the cookie banner, you may be asked to give your consent separately before such videos are displayed on our website. A possible data transfer will only be initiated if you have given your consent.
  • YouTube as a social media provider, where we may present videos on various YouTube channels. Please refer to the privacy notices mentioned above if you use such channels.
  • Google reCAPTCHA: In order to protect your website interactions such as logins or registrations, we carry out risk assessments for website users and use Google reCAPTCHA for this purpose. These assessments use cookies and collect personal data. However, Google may only set cookies and use personal data with the prior consent of users, which can be given via the cookie layer.
  • Google Maps as a service for location and map services, whereby only such data is used that you yourself provide when using this service. An approximate location is used, e.g., to display the distance to our location or to verify the postal code for support requests.
  • Google GA4 technology is used by us (only if you have given your cookie consent) to implement server-side tracking as a technology similar to cookies. When using this tool, we send no usage data or similar data to Google; instead, we use the tool to send statistical and/or event-based information about the use of the website to our servers. This data is processed by us and does not allow you or the device from which you use the website/service to be individually identified.
  • Google Tag Manager (GTM) is a tool used by us that allows us to manage and deploy marketing tags on websites without code changes. The tags include analytics and tracking codes that provide insights into website performance and user behavior. While GTM itself does not set cookies, the tags deployed via it may use cookies for tracking. 
  • Google Ads & Remarketing We use online marketing tools from Google under our own responsibility. The cookies used in this service generally expire after 30 days and are not used to identify you personally. Google merely provides us with statistical evaluations. Google processes your data in accordance with Google's privacy policy. Opt-out: To permanently prevent the collection of usage data, Google offers a plugin for various internet browsers: http://www.google.com/settings/ads/plugin.To deactivate interest-based ads, you can block the use of third-party cookies or cookies from the domain "www.googleadservices.com" or deactivate interest-based ads via this link:https://adssettings.google.com/authenticated?hl=en_GB

​Interest-based ads can also be deactivated via the link http://www.aboutads.info/choices if the  ​      provider has joined the „About Ads“ self-regulation.

  • Google Ad Server We use the online marketing tool from Google. The usage data is deleted 540 days after the time of collection. Further information can be found athttps://support.google.com/admanager/answer/6022000?hl=en

We use online marketing tools from Google under our own responsibility. For this purpose, we have agreed with Google in a data protection contract that the data of our customers may only be processed on our instructions, may not be passed on to third parties, and must be adequately protected technically.





Folgen Sie uns
​
  • COD Overview
  • Features
  • Pricing
  • Integrations
  • NIS2
  • codPass
  • References
  • Downloads
  • FAQ
  • Contact

Kotzinger Straße 21 • 83278 Traunstein • Deutschland

  • ​+49 (861) 88 00 32 00
  • ​info@extoco.de
Datenschutz Impressum ​
Copyright © extocode GmbH
English (US) Français Deutsch Español Türkçe

We use cookies to provide you a better user experience on this website. Privacy Policy

Decline Accept