Privacy Policy
Last updated: June 2026
1. Introduction
With the following information, we wish to provide you as the "data subject" with an overview of how we process your personal data and to outline your rights under data protection laws. In principle, it is possible to use our websites without entering any personal data. However, if you wish to utilize specific services offered by our company via our website, the processing of personal data may become necessary. If the processing of personal data is required and there is no statutory basis for such processing, we generally obtain your consent. The processing of personal data—such as your name, address, or e-mail address—is always carried out in accordance with the General Data Protection Regulation (GDPR) and in compliance with the country-specific data protection regulations applicable to "SeriSoft GmbH." Through this privacy policy, we aim to inform you about the scope and purpose of the personal data we collect, use, and process. As the data controller, we have implemented numerous technical and organizational measures to ensure the most comprehensive protection possible for the personal data processed via this website. However, internet-based data transmissions can inherently have security vulnerabilities, meaning that absolute protection cannot be guaranteed. For this reason, you are free to transmit personal data to us via alternative means, such as by telephone or by mail. You, too, can take simple and easily implementable measures to protect yourself against unauthorized third-party access to your data. We would therefore like to offer a few tips here on the secure handling of your data: • Protect your account and your IT system with secure passwords. • Only you should have access to the passwords. • Ensure that you use each password for only one account. • Do not use the same password for different websites, applications, or online services. • Particularly when using publicly accessible IT systems: log out after every session. Passwords should consist of at least 12 characters and include uppercase and lowercase letters, numbers, and special characters.
2. Data Controller
The controller within the meaning of the GDPR is: SeriSoft GmbH Hohenloher Weg 37, 33102 Paderborn, Germany Phone: 05254 64078-0 Fax: 05254 64078-99 Representative of the controller: Dr. Stefan Öing
3. Data Protection Officer
You can contact our Data Protection Officer at datenschutz@serisoft.de or via our postal address, marked "Datenschutzbeauftragter" (Data Protection Officer).
4. Definitions
This data protection declaration is based on the terminology used by the European legislator when adopting the General Data Protection Regulation (GDPR). 1. Personal data – any information relating to an identified or identifiable natural person. 2. Data subject – any identified or identifiable natural person whose personal data is being processed. 3. Processing – any operation performed on personal data, such as collection, recording, storage, adaptation, retrieval, use, disclosure, erasure, or destruction. 4. Restriction of processing – the marking of stored personal data with the aim of limiting their future processing. 5. Profiling – any form of automated processing of personal data to evaluate certain personal aspects relating to a natural person. 6. Pseudonymisation – the processing of personal data in such a manner that the personal data can no longer be attributed to a specific person without the use of additional information. 7. Processor – a person or entity that processes personal data on behalf of the controller. 8. Recipient – a person or entity to whom personal data is disclosed. 9. Third party – a person or entity other than the data subject, the controller, and the processor. 10. Consent – any freely given, specific, informed, and unambiguous indication of the data subject's wishes.
5. Legal Basis for Processing
Article 6(1)(a) of the GDPR (in conjunction with Section 25(1) of the TDDDG) serves as the legal basis for processing operations for which we obtain consent. If processing is necessary for the performance of a contract, the processing is based on Article 6(1)(b) of the GDPR. The same applies to pre-contractual measures. If our company is subject to a legal obligation, the processing is based on Article 6(1)(c) of the GDPR. In rare cases, processing may be necessary to protect vital interests (Article 6(1)(d) of the GDPR). Finally, processing operations may be based on Article 6(1)(f) of the GDPR if the processing is necessary to safeguard a legitimate interest of our company or a third party. Our services are generally directed at adults. Persons under the age of 16 may not transmit personal data to us without the consent of their parents or legal guardians.
6. Technology
6.1 SSL/TLS Encryption This site uses SSL or TLS encryption to ensure the security of data processing. You can recognize an encrypted connection by the fact that the browser's address bar displays "https://" and a padlock icon appears. 6.2 Data Collection When Visiting the Website When using our website for purely informational purposes, we only collect data that is technically necessary to provide the service (so-called server log files). The following data may be collected: 1. browser types and versions used 2. the operating system used 3. the website from which an accessing system reaches our site (referrer) 4. the sub-pages accessed 5. date and time of access 6. a shortened Internet Protocol address (anonymized IP address) 7. the internet service provider of the accessing system This data is required to deliver content correctly, ensure the functionality of our IT systems, and provide necessary information to law enforcement authorities in the event of a cyberattack. The legal basis for data processing is Art. 6 (1) (f) GDPR.
7. Cookies
7.1 General information on cookies Cookies are small files that your browser automatically creates and stores on your IT system when you visit our website. We use session cookies to recognize that you have already visited specific pages; these are automatically deleted after you leave our site. In addition, we use temporary cookies to optimize user-friendliness. We also use cookies to gather statistics on the use of our website. Details regarding the specific storage duration can be found in the settings of the consent tool used. 7.2 Information on avoiding cookies in common browsers You can delete cookies, allow only selected cookies, or disable cookies entirely at any time via your browser settings. Further information is available on the support pages of the respective providers: • Chrome: https://support.google.com/chrome/answer/95647 • Safari: https://support.apple.com/de-at/guide/safari/sfri11471/mac • Firefox: https://support.mozilla.org/de/kb/cookies-und-website-daten-in-firefox-loschen • Microsoft Edge: https://support.microsoft.com/de-de/microsoft-edge/cookies-in-microsoft-edge-löschen
8. Content of our Website
8.1 Contacting us / Contact form Personal data is collected when you contact us (e.g., via the contact form or email). This data is stored and used exclusively for the purpose of responding to your inquiry and for the associated technical administration. The legal basis for this processing is our legitimate interest in responding to your inquiry pursuant to Art. 6(1)(f) GDPR. If your contact aims to conclude a contract, an additional legal basis is Art. 6(1)(b) GDPR. Your data will be deleted once your inquiry has been fully processed, provided there are no statutory retention obligations to the contrary.
9. Our Activities in Social Networks
To communicate with you via social networks and inform you about our services, we maintain a presence on these platforms with our own pages. When you visit one of our social media pages, we and the respective provider act as joint controllers for data processing within the meaning of Art. 26 of the GDPR. Please note that your data may also be processed outside the European Union. Processing on social networks is frequently carried out directly by the providers for advertising purposes or to analyze user behavior. The processing operations described are carried out based on our legitimate interests in accordance with Art. 6(1)(f) of the GDPR. 9.1 LinkedIn Joint controller for data processing in Europe: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland Privacy Policy: https://www.linkedin.com/legal/privacy-policy
10. Web Analysis
10.1 Google Analytics Universal We use Google Analytics, a web analytics service provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland), on our websites. In this context, pseudonymized usage profiles are created and cookies are used. The information generated by the cookie regarding your use of this website is transmitted to a Google server in the USA and stored there. IP addresses are anonymized (IP masking). These processing operations take place only upon the granting of express consent pursuant to Art. 6(1)(a) GDPR. The parent company, Google LLC, is certified under the EU-US Data Privacy Framework (adequacy decision pursuant to Art. 45 GDPR). Privacy policy: https://support.google.com/analytics/answer/6004245?hl=en 10.2 Google Analytics Remarketing We have integrated Google Remarketing into this website (Google Ireland Limited, Dublin 4, Ireland). Google Remarketing enables the display of advertisements to internet users who have previously visited the website. These processing operations take place only upon the granting of express consent pursuant to Art. 6(1)(a) GDPR. The parent company, Google LLC, is certified under the EU-US Data Privacy Framework (adequacy decision pursuant to Art. 45 GDPR). Privacy policy: https://www.google.de/intl/en/policies/privacy/
11. Plugins and Other Services
11.1 TeamViewer Meeting – Video Conferencing We use the "TeamViewer Meeting" tool to conduct conference calls, online meetings, video conferences, and webinars. The provider is TeamViewer Germany GmbH, Bahnhofsplatz 2, 73033 Göppingen. The following personal data may be processed: • User details: First name, last name, telephone number (optional), email address (optional), password, profile picture (optional) • Meeting metadata: Topic, description (optional), participant IP addresses, device/hardware information • In the case of recordings (optional): Video, audio, and presentation recordings, as well as chat text files • In the case of dial-in via telephone: Phone number, country name, start and end times Depending on the situation, the legal basis is Art. 6 (1) (a), (b), or (f) of the GDPR, or Section 26 of the BDSG (Federal Data Protection Act) in the context of an employment relationship. If we record online meetings, we will inform you in advance and, where applicable, obtain your consent. Further information on TeamViewer: https://www.teamviewer.com/de/datenschutzinformation/
12. Your Rights as a Data Subject
12.1 Right to confirmation You have the right to request confirmation from us as to whether personal data concerning you is being processed. 12.2 Right of access (Art. 15 GDPR) You have the right to obtain information about the personal data stored concerning you, as well as a copy of this data, free of charge at any time. 12.3 Right to rectification (Art. 16 GDPR) You have the right to request the rectification of incorrect personal data and the completion of incomplete data. 12.4 Erasure (Art. 17 GDPR) You have the right to request the immediate erasure of personal data concerning you, provided the statutory requirements are met. 12.5 Restriction of processing (Art. 18 GDPR) You have the right to request the restriction of processing if one of the statutory requirements applies. 12.6 Data portability (Art. 20 GDPR) You have the right to receive the personal data concerning you in a structured, commonly used, and machine-readable format and to transmit this data to another controller. 12.7 Objection (Art. 21 GDPR) You have the right to object, on grounds relating to your particular situation, at any time to the processing of your personal data if the processing is based on Art. 6(1)(e) or (f) GDPR. If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds. 12.8 Withdrawal of data protection consent You have the right to withdraw consent to the processing of personal data at any time with effect for the future. 12.9 Complaint to a supervisory authority You have the right to lodge a complaint with a supervisory authority responsible for data protection regarding our processing of personal data.
13. Routine Storage, Deletion and Blocking of Personal Data
We process and store your personal data only for the period necessary to achieve the purpose of storage or as required by the legal provisions to which our company is subject. If the purpose of storage ceases to apply or a prescribed retention period expires, the personal data will be routinely blocked or deleted in accordance with legal requirements.
14. Validity and Amendment of this Privacy Policy
This privacy policy is currently in effect and is dated June 2026. It may become necessary to amend this privacy policy due to the further development of our websites and services, or as a result of changes in legal or regulatory requirements. The current version of the privacy policy can be accessed and printed by you at any time on the website at “https://www.serisoft.de/datenschutzerklaerung/”.