Privacy policy
Certified data protection at INSITE
INSITE-Interventions GmbH has been awarded the ‘Data Protection’ certificate since 2013. All company processes are reviewed annually for data protection and security aspects. This ensures that personal data is protected and stored securely in the best possible way. INSITE not only meets the criteria of the Federal Data Protection Act and the General Data Protection Regulation, but also continuously installs new protective measures to protect personal data in accordance with best practice.
What does a ‘data protection’ certificate mean?
The ‘Data Protection’ certification checks compliance with all legal requirements of the Federal Data Protection Act, the General Data Protection Regulation and, in addition, aspects of information technology, personal rights, commissioned data processing and IT security. To this end, specialists carry out internal and external security analyses. As part of the comprehensive security analyses, our employees, business processes and systems are intensively examined to determine whether the confidentiality and integrity of the processed data meet the high security requirements, the statements in the data protection documents are effectively implemented, and personal data is effectively protected in accordance with the current German Federal Data Protection Act and the European General Data Protection Regulation, e.g. by technically securing all systems against unauthorised use.
The certificate is valid for three years and is reviewed in an annual surveillance audit. The audit includes checking whether the protection and security of the data are still guaranteed and how processes can be continuously optimised. After three years, a complete recertification is due, which ensures that the continuous improvement process in terms of data protection and data security is permanently continued. This cycle promotes trust and guarantees that security measures are always up to date.
What does data protection mean in consulting?
In principle, employees or relatives can use all counselling services anonymously by providing a nickname, i.e. without giving their name or personal data such as email address or telephone number. If individuals decide to entrust us with their data, they can be sure that we will protect their data and treat it with the utmost care, exclusively for the purpose of providing counselling.
Do you have any questions about our data protection policy? Give us a call (+49 69 90 555 29 - 0) or send your question to datenschutz@insite.de.
What is this data protection notice about?
This data protection notice informs you which personal data are collected and processed when you visit our website www.insite.de, for what purposes this takes place and what rights you have as a data subject. We hereby inform you in accordance with Article 13 of the General Data Protection Regulation (GDPR) and Section 25 of the German Telecommunications and Digital Services Data Protection Act (TDDDG). Our websites can generally be used without providing personal data. Where you provide us with personal data – for example by completing a contact form or subscribing to our newsletter – this is done voluntarily and the data are used solely for the purposes stated in each case.
Who is responsible for processing your data?
The controller within the meaning of the GDPR is:
INSITE-Interventions GmbH
Clemensstraße 10–12
60487 Frankfurt am Main
Telephone: +49 69 90555 29-0
Email: office@insite.de
How can you reach our Data Protection Officer?
If you have questions about data protection or the processing of your personal data, you can contact our Data Protection Officer at any time:
Deborah Schütt
Clemensstraße 10–12
60487 Frankfurt am Main
Telephone: +49 69 90555 29-0
Email: dsb@insite.de
Processing details
Provision of the website and hosting
Our website is hosted by an external service provider. For our website to be accessed and operated reliably, the hosting provider must technically process certain personal data.
Host used:
blackpoint GmbH
Friedberger Straße 106b
61118 Bad Vilbel
The host processes your data exclusively under a data processing agreement pursuant to Article 28 GDPR and in accordance with our instructions. The host does not use the data for its own purposes. Legal basis: Article 6(1)(f) GDPR. Our legitimate interest lies in the technical provision and stable operation of our website.
Server log files
Whenever our website is accessed, our server automatically records technical access data in so-called server log files. In particular, the following data are collected:
- name of the page or file accessed
- date and time of access
- amount of data transferred and success status
- browser type and version
- operating system
- IP address
- internet service provider
- referrer URL (the previously visited page)
These data are not assigned to individuals and are not combined with data from other sources. After seven days, the server log files are pseudonymised. They are not used to monitor performance or behaviour. Legal basis: Article 6(1)(f) GDPR. Our legitimate interest lies in the secure and error-free operation of our website and in detecting and preventing attacks on our systems. Retention period: seven days until pseudonymisation.
Cookies
Our website uses cookies. Cookies are small text files stored by your browser on your device. They do not cause damage and do not contain malware. Technically necessary cookies are required for our website to function properly. They are automatically deleted when you close your browser (session cookies). No consent is required for their use. Analytics and marketing cookies are used to analyse your usage behaviour and display personalised advertising. These cookies are only placed if you have given your consent in the cookie banner. You can withdraw your consent at any time via our cookie settings with effect for the future. Regardless of your cookie settings, you can configure your browser to reject cookies generally or to notify you before they are set. Please note that this may restrict the functionality of our website. Legal basis for technically necessary cookies: Article 6(1)(f) GDPR. Legal basis for analytics and marketing cookies: Article 6(1)(a) GDPR and Section 25(1) TDDDG (consent).
Consent management (Usercentrics)
We use the Usercentrics service to obtain, manage and document your cookie consents. Provider: Usercentrics GmbH, Sendlinger Str. 7, 80331 Munich. Usercentrics processes information about consents you have given or withdrawn and technical data used to identify your session. Processing is solely for documenting and managing your consents. Usercentrics acts as a processor pursuant to Article 28 GDPR. Legal basis: Article 6(1)(c) GDPR. Processing is necessary to fulfil our legal obligation under Article 7(1) GDPR. Retention period: three years. Further information: https://usercentrics.com/privacy-policy/
Google Tag Manager
We use Google Tag Manager to manage and activate tracking and analytics services on our website. Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Tag Manager itself does not create user profiles, set its own cookies or carry out independent analyses. It is used solely for the technical management and activation of the services integrated through it. Legal basis: Article 6(1)(f) GDPR. Our legitimate interest lies in the efficient and consistent management of our web services.
Google Analytics
We use Google Analytics to analyse use of our website. Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics uses cookies to analyse your usage behaviour. The information generated – such as the time, location and frequency of your visit – is transmitted to Google servers. We use Google Analytics with IP anonymisation enabled, meaning that your IP address is shortened within the European Union before transmission. The data collected are used solely to statistically analyse use of our website and improve our services. We do not assign the data to individual persons on our website. Legal basis: Article 6(1)(a) GDPR and Section 25(1) TDDDG. Processing takes place solely on the basis of your consent, which you can withdraw at any time via our cookie settings. Transfer to third countries: Google Analytics may transfer data to the United States. The basis is the European Commission adequacy decision for the EU–US Data Privacy Framework. You can prevent collection by Google Analytics by installing the browser add-on to disable it: https://tools.google.com/dlpage/gaoptout?hl=en.
Further information: https://policies.google.com/privacy?hl=en
Google Ads and conversion tracking
We use Google Ads to advertise our website and use Google conversion tracking for this purpose. Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. If you reach our website via a Google advert, a conversion cookie is placed on your device. This cookie expires after 30 days and is not used to identify you personally. While the cookie is active, we and Google can recognise whether and which pages of our website were visited after an advert was clicked. The information obtained is used solely to measure the statistical success of our adverts.
Legal basis: Article 6(1)(a) GDPR and Section 25(1) TDDDG. Processing takes place solely on the basis of your consent, which you can withdraw at any time via our cookie settings. Transfer to third countries: Google Ads may transfer data to the United States. The basis is the EU–US Data Privacy Framework and EU Standard Contractual Clauses pursuant to Article 46 GDPR. Due to the legal situation in the United States (including the CLOUD Act), a residual risk of access by public authorities cannot be completely ruled out. Further information: https://policies.google.com/privacy?hl=en
LinkedIn Insight Tag
We use the LinkedIn Insight Tag on our website for conversion tracking and retargeting functions via the LinkedIn advertising platform. Provider: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland. The LinkedIn Insight Tag establishes a connection to LinkedIn’s server when you visit our website while logged in to your LinkedIn account. Information about your visit to our website is transmitted to LinkedIn. This information may be used to display personalised adverts to you on LinkedIn and to create anonymous reports about the performance of our adverts. Legal basis: Article 6(1)(a) GDPR and Section 25(1) TDDDG. Processing takes place solely on the basis of your consent, which you can withdraw at any time via our cookie settings. Transfer to third countries: LinkedIn may transfer data to the United States. The basis is the EU–US Data Privacy Framework. Further information: https://www.linkedin.com/legal/privacy-policy
Contact by email or contact form
If you contact us via our contact form or by email, we process the data you provide solely to deal with your enquiry. This may include, in particular:
- first name and surname
- email address
- telephone number, where applicable
Data are not disclosed to third parties unless this is necessary to answer your enquiry or we are legally obliged to do so. Please note: Fully encrypted communication by email is currently not technically possible. Emails may generally be accessible to third parties during transmission. For confidential matters, we recommend contacting us directly by telephone. Legal basis: Article 6(1)(a), (b) or (f) GDPR, depending on the type and reason for the contact. Our legitimate interest under Article 6(1)(f) lies in answering legitimate enquiries and maintaining business contacts. Retention period: your data are deleted once your enquiry has been dealt with and provided that no statutory retention obligations apply.
Online appointment booking (timify)
Our website allows you to arrange an appointment with us directly. We use the timify appointment service for this purpose. Provider: TerminApp GmbH, Munich. When arranging an appointment, we process in particular:
- first name and surname
- email address
- telephone number where applicable and
- the requested appointment time.
The data transmitted are processed solely for arranging and conducting the appointment.
Legal basis: Article 6(1)(a) GDPR. Transfer to third countries: timify may transfer data to the United States. The basis is the EU–US Data Privacy Framework.
Retention period: 18 months after the appointment.
Further information: https://www.timify.com/en/legal/
Newsletter
Our website allows you to subscribe to our newsletter. We use it to inform you regularly about news, offers and events relating to our company and the topic of Corporate Health. Service provider: XQueue GmbH (Maileon), Christian-Pleß-Straße 11–13, 63069 Offenbach am Main. To send the newsletter, we require your email address and confirmation that you consent to receiving it. Registration takes place using the double opt-in procedure: after registering, you receive a confirmation email; your registration only becomes effective once you confirm it. When you register, we also store your IP address and the date and time of registration as evidence of your consent. Your newsletter data are used solely to send the newsletter and are not disclosed to third parties. You can unsubscribe at any time via the unsubscribe link in every newsletter email or by emailing datenschutz@insite.de. Your data are deleted after you unsubscribe.
Newsletter tracking
Our newsletters contain so-called tracking pixels – small, invisible graphic elements that enable us to recognise whether an email has been opened and which links it contains have been clicked. We use this information solely to optimise our newsletters and better tailor future content to the interests of our subscribers. Data are not disclosed to third parties. Legal basis: Article 6(1)(a) GDPR (consent given as part of newsletter registration). You can prevent newsletter tracking by disabling automatic loading of graphics in your email programme. Unsubscribing from the newsletter also constitutes withdrawal of this consent. Legal basis: Article 6(1)(a) GDPR. Consent can be withdrawn at any time with effect for the future. Transfer to third countries: XQueue GmbH stores newsletter data on ser vers in Germany. Where a transfer to the United States takes place, it is based on the EU–US Data Privacy Framework. Retention period: until you unsubscribe from the newsletter.
Company profiles on social networks
We operate company profiles on LinkedIn, Instagram and YouTube. When you visit our profiles or interact with our content, personal data are processed both by us and by the respective platform operator. We are jointly responsible with the respective platform operator for processing in connection with operating our profiles (joint controllership pursuant to Article 26 GDPR). The respective platform operator is solely responsible for any further processing for its own purposes. Processing personal data in the context of our social media activities – for example when publishing photos or videos – is based on Article 6(1)(a) GDPR and Article 9(2)(a) GDPR (consent). Consent given can be withdrawn at any time by emailing datenschutz@insite.de. Platform operators may transfer data to the United States. The basis for this is the EU–US Data Privacy Framework and EU Standard Contractual Clauses.
- LinkedIn – joint controller: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland; privacy notice: https://www.linkedin.com/legal/privacy/eu
- Instagram – joint controller: Meta Platforms Ireland Limited, Merrion Road, Dublin, Ireland; privacy notice: https://privacycenter.instagram.com/policy
- YouTube – joint controller: Google LLC, 1600 Amphitheatre Pkwy, Mountain View, CA 94043, USA; privacy notice: https://policies.google.com/privacy?hl=en
Who receives your personal data?
Within INSITE-Interventions GmbH, only those persons have access to your data who need it for their particular task (need-to-know principle). We also use external service providers that process personal data on our behalf (processors pursuant to Article 28 GDPR). These include:
- hosting provider (blackpoint GmbH)
- consent management (Usercentrics GmbH)
- web analytics and advertising services (Google Ireland Limited)
- social media advertising (LinkedIn Ireland Unlimited Company)
- newsletter distribution (XQueue GmbH / Maileon)
- online appointment booking (TerminApp GmbH / timify)
All processors are carefully selected, contractually obliged to comply with data protection requirements and regularly reviewed. Data are only disclosed to authorities or other third parties where we are legally obliged to do so.
Are personal data transferred to third countries?
In connection with individual services used, personal data may be transferred to countries outside the European Union or the European Economic Area. In these cases, we ensure an adequate level of data protection, in particular through European Commission adequacy decisions or EU Standard Contractual Clauses pursuant to Article 46 GDPR. If you would like further information about the safeguards used, please contact our Data Protection Officer at any time.
| Service | Recipient country | Safeguard |
| Google Analytics / Google Ads | USA | EU–US Data Privacy Framework |
| LinkedIn Insight Tag | USA | EU–US Data Privacy Framework |
| timify | USA | EU–US Data Privacy Framework |
| XQueue / Maileon | USA, where applicable | EU–US Data Privacy Framework |
If you would like more information about the safeguards in place, please feel free to contact our Data Protection Officer at any time.
How long do we store your personal data?
We store your data only for as long as necessary for the respective purposes or for as long as statutory retention obligations apply.
| Data type | Retention period |
| Server log files | 7 days (until pseudonymisation) |
| Consent records (Usercentrics) | 3 years |
| Contact enquiries | Until processing is complete; up to 10 years where relevant under commercial or tax law |
| Newsletter data | Until you unsubscribe |
| Conversion cookies (Google Ads) | 30 days |
| Appointment booking (timify) | 18 months |
| Social media content based on consent | Until consent is withdrawn or the purpose for use no longer applies |
What rights do you have?
- Access (Article 15 GDPR) You may request information about whether and which personal data we process about you and about the circumstances of processing, including purposes, recipients, storage periods and your further rights.
- Rectification (Article 16 GDPR) You may request rectification of inaccurate or completion of incomplete data.
- Erasure (Article 17 GDPR) Subject to statutory requirements, you may request erasure of your data, for example where the purpose of processing no longer applies or you withdraw your consent. Statutory retention obligations remain unaffected.
- Restriction of processing (Article 18 GDPR) Under certain conditions, you may request that your data only be processed to a limited extent.
- Data portability (Article 20 GDPR) Where processing is based on consent or a contract and carried out by automated means, you may receive your data in a structured, commonly used and machine-readable format or request its transfer to another controller.
- Right to object (Article 21 GDPR) Where we process data on the basis of our legitimate interests pursuant to Article 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation. We will then stop the processing concerned unless there are compelling legitimate grounds to the contrary.
- Withdrawal of consent (Article 7(3) GDPR) Where processing is based on your consent, you may withdraw it at any time with effect for the future. This does not affect the lawfulness of processing carried out before withdrawal.
- Right to lodge a complaint with a supervisory authority (Article 77 GDPR) If you consider that the processing of your data infringes data protection law, you have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for our registered office is:
Hessian Commissioner for Data Protection and Freedom of Information (HBDI)
Gustav-Stresemann-Ring 1
65189 Wiesbaden
https://datenschutz.hessen.de/
You may also contact the supervisory authority at your place of residence or habitual abode. An overview of all German supervisory authorities can be found at: https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html
Does automated decision-making take place?
No solely automated decision-making, including profiling within the meaning of Article 22 GDPR, takes place when using our websites.
Up-to-dateness of this data protection notice
This data protection notice reflects the current state of the processing of personal data when visiting https://www.insite.de/en/. If changes occur, we will update this notice and publish the new version.
What are these privacy notices about?
INSITE‑Interventions GmbH provides psychosocial counselling services. These services are intended for employees and family members of companies that have concluded a cooperation agreement with us. In these privacy notices, we inform you in accordance with Article 13 of the General Data Protection Regulation (GDPR) which personal data we process in connection with providing our counselling services, for which purposes and on which legal basis this takes place, and which rights you have.
Important information about anonymous use: All INSITE counselling services can generally be used anonymously. This means that you can use our services without telling us your name or other personal details — for example, by using a pseudonym or nickname. These privacy notices apply where you share personal data with us in connection with using our services. We recommend providing only the data that is actually required to carry out the counselling.
Who is responsible for processing your data?
The controller within the meaning of the General Data Protection Regulation is:
INSITE‑Interventions GmbH
Clemensstraße 10–12
60487 Frankfurt am Main
Telephone: +49 69 90555 29‑0
Email: office@insite.de
How can you contact our Data Protection Officer?
If you have questions about data protection or the processing of your personal data, you can contact our Data Protection Officer at any time:
Deborah Schütt
Clemensstraße 10–12
60487 Frankfurt am Main
Telephone: +49 69 90555 29‑0
Email: dsb@insite.de
Confidentiality and protection of your data
Counselling at INSITE takes place in a confidential setting. The counsellors providing your counselling are subject to professional duties of confidentiality and secrecy. Information that you share as part of the counselling will not be disclosed to third parties without your explicit consent. Your employer will not be informed whether or in what form you use our counselling services. If your employer receives statistical usage reports from INSITE, these consist exclusively of anonymised frequency statistics from which no conclusions can be drawn about individual persons. Personal data will not be disclosed to your employer. Access to your data within INSITE is granted exclusively on a need‑to‑know basis to a strictly limited, expressly authorised group of persons. All client data are transmitted and stored in encrypted form.
Which personal data do we process?
The personal data processed depend on whether and to what extent you provide us with personal details and which counselling services you use.
Contact and identification data
Where you provide us with your name and contact details: first and last name or pseudonym, email address, telephone number and — where provided — the name of your employer.
Appointment-booking data
When booking counselling appointments through our booking system: name or pseudonym, email address or telephone number and your preferred appointment time.
Counselling data
The following personal data may arise during the counselling: information about your personal situation and the subject of your enquiry, conversation content and anamnestic information and — where you provide it — medical data, information about family and private circumstances, and other information that you share during the counselling session.
Care-management data
If you would like support in being referred to external treatment providers or care services: name or pseudonym, contact details, information about complaints or symptoms and — where required — information about membership of a health insurance fund.
Special categories of personal data
During counselling, information may arise that requires special protection under Article 9 GDPR. This includes, in particular, health data and information about your psychological condition, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, and data concerning your sex life or sexual orientation, where you voluntarily share these during the counselling session. Special categories of personal data are processed only where you expressly provide them or where processing is necessary to carry out the counselling, and are accessed only by expressly authorised persons.
Feedback data
After counselling has ended, we may optionally send you a short quality survey with standardised questions. Participation is voluntary. If you have provided an email address, we process it to send the survey, as well as your answers to the questions.
For which purposes and on which legal bases do we process your data?
Appointment booking and preparation for counselling
To arrange and coordinate counselling appointments, we process your contact and booking data. Appointments can be booked via our booking system (Timify) or by telephone through our client service.
Legal basis: Article 6(1)(a) GDPR; Article 9(2)(h) GDPR where special categories of personal data are involved.
Providing counselling
To provide psychosocial counselling, we process the data that you share with us during counselling sessions. Counselling may take place in person, by telephone or by video conference. Counselling is provided by qualified counsellors who are subject to professional duties of confidentiality and secrecy.
Legal basis: Article 6(1)(a) GDPR; Article 9(2)(h) GDPR. Processing serves the provision of health and social care services as well as preventive and occupational healthcare.
Care management and referral to external treatment providers
If you would like support in finding further therapy places or other care services, we process the information required for this purpose and coordinate referrals to suitable treatment providers. Data are disclosed to external treatment providers only with your consent and are limited to the information necessary for arranging the referral.
Legal basis: Article 6(1)(a) GDPR; Article 9(2)(h) GDPR.
Quality assurance and feedback
To safeguard and improve the quality of our counselling services, we evaluate feedback that you provide after counselling. Participation in a feedback survey is always voluntary.
Legal basis: Article 6(1)(f) GDPR; Article 9(2)(h) GDPR. Our legitimate interest is the continuous improvement of the quality of our counselling services.
Handling complaints
If you submit a complaint about our service, we process your information exclusively to handle your enquiry. Administrative follow-up of complaints takes place in a separate ticketing system in which no client-related counselling content is recorded.
Legal basis: Article 6(1)(b) GDPR; Article 6(1)(f) GDPR; Article 9(2)(h) GDPR.
Compliance with professional retention obligations
Records of counselling services are subject to a statutory retention period of ten years after completion of treatment pursuant to Section 630 of the German Civil Code (BGB). We are therefore obliged to retain your counselling documentation for this period, even if you request erasure. Your data will be deleted once the retention period has expired.
Legal basis: Article 6(1)(c) GDPR; Article 9(2)(h) GDPR.
Your employer does not receive your personal data
As INSITE provides its services on behalf of companies, we would like to make this point expressly clear: your employer will never receive information about whether or how you have used our counselling services, what was discussed during counselling sessions or what personal details you provided to us. Statistical usage reports supplied by INSITE to employers are fully anonymised. It is not possible to identify individuals from these reports.
Who receives your personal data?
Within INSITE‑Interventions GmbH, only persons directly involved in the counselling have access to your data. These include, in particular, the counsellor responsible for you, client-service and care-management staff and — to a strictly limited extent and only where necessary — department and team managers.
To provide our services, we use external service providers and partners:
- Freelance counsellors who conduct counselling sessions and are themselves subject to professional duties of confidentiality and secrecy.
- A call centre used for the initial telephone recording of counselling enquiries.
- eWorks (coordination platform for assignments and documentation).
- Timify / TerminApp GmbH (appointment-booking system).
- Zoom (video-conferencing tool for online counselling sessions).
- BUK (partner within the care network).
- Occupational health services, where you request their support as part of care management.
- Treatment providers (external therapists and specialist doctors), exclusively as part of care management and with your explicit consent.
- Freshworks, which is used as an additional ticketing system for handling complaints and stores only administrative case data without client-related counselling content.
Service providers and transfers to third countries
| Service provider | Purpose | Safeguard for transfer to a third country |
| Timify / TerminApp GmbH | Appointment booking | EU–US Data Privacy Framework adequacy decision |
| Zoom | Video conferences | EU–US Data Privacy Framework adequacy decision |
All external service providers are selected carefully, contractually obliged and reviewed for compliance with data protection requirements. Data are disclosed to authorities only where we are legally obliged to do so.
Are data transferred to third countries?
For some of the services used, personal data may be transferred to the United States. In these cases, we ensure that an adequate level of data protection is guaranteed.
How long do we store your personal data?
| Data category | Retention period |
| Counselling documentation | 10 years after completion of treatment (Section 630 BGB) |
| Care-management documentation | 10 years after completion of treatment (Section 630 BGB) |
| Appointment-booking data (Timify) | 18 months after the appointment |
| Feedback data | 10 years as part of the client documentation |
| Complaint data (client-related) | 10 years as part of the client documentation |
| Complaint data (administrative ticket data without counselling content) | Until the case has been closed |
All other systems used as part of client counselling process data exclusively within the European Union. If you do not want your data to be transferred to the United States, you can alternatively attend counselling sessions by telephone or in person. Please contact our client service for this purpose.
Once the applicable retention period has expired, your data will be deleted or anonymised in a way that no longer permits conclusions to be drawn about you.
What rights do you have?
- Right of access (Article 15 GDPR): you can request access to the data we store about you.
- Right to rectification (Article 16 GDPR): you can request the correction of inaccurate data or completion of incomplete data.
- Right to erasure (Article 17 GDPR): subject to the statutory requirements, you can request erasure of your personal data. Please note that, due to the statutory retention obligation under Section 630 BGB, we must retain counselling documentation for ten years after completion of treatment. An erasure request for this data therefore cannot be fully complied with during the applicable retention period. In this case, we will explain transparently which data are covered by the retention obligation and which can already be deleted.
- Right to restriction of processing (Article 18 GDPR): under certain conditions, you can request that your data be processed only in a restricted manner.
- Right to data portability (Article 20 GDPR): where processing is based on your consent and carried out by automated means, you can receive your data in a machine-readable format.
- Right to object (Article 21 GDPR): where we process personal data on the basis of our legitimate interests under Article 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation.
- Withdrawal of consent: where processing is based on your consent, you may withdraw it at any time with effect for the future. Please note that withdrawal may impair or make it impossible to provide ongoing counselling services. Withdrawal does not affect the lawfulness of processing carried out up to that point and does not prevent us from asserting the statutory retention obligation under Section 630 BGB.
Right to lodge a complaint with a data protection supervisory authority (Article 77 GDPR)
You have the right to lodge a complaint with the competent data protection supervisory authority:
Hessian Commissioner for Data Protection and Freedom of Information
PO Box 3163
65021 Wiesbaden
https://datenschutz.hessen.de/
You may also contact the supervisory authority at your place of residence or work. Our Data Protection Officer and client service are, of course, also available for all data protection questions.
Are you obliged to provide your personal data?
Our counselling services can generally also be used without providing personal data, under a pseudonym. Providing personal details is voluntary. Certain services — in particular arranging individual call-back appointments, conducting video calls via Zoom or referrals through care management — require contact details because they cannot technically be provided without a way to contact you. In these cases, we will inform you in advance which specific details are required.
Does automated decision-making or profiling take place?
No solely automated decision-making, including profiling within the meaning of Article 22 GDPR, takes place as part of the counselling services. Decisions about the provision, design and referral of counselling services are always made by qualified professionals.
Currency of these privacy notices
These privacy notices reflect the current state of the processing of personal data. We reserve the right to amend these notices if the systems used, processing procedures or legal position change. The current version will be made available on our website.
What are these privacy notices about?
INSITE‑Interventions GmbH provides counselling services to companies and organisations. In the context of these business relationships, we process personal data belonging to the individuals who act as customer contacts and communicate with us — from the initial enquiry until the end of the cooperation and beyond.
In these privacy notices, we inform you in accordance with Articles 13 and 14 of the General Data Protection Regulation (GDPR) which personal data we process, for which purposes and on which legal basis, to whom data are disclosed, how long we retain your data and which rights you have as a data subject.
These privacy notices apply to all persons who communicate with us as contacts of a customer organisation in connection with our service relationship — regardless of whether a contract already exists or whether contact takes place during the acquisition phase.
Where we have not collected your personal data directly from you — for example, where your contact details were researched from publicly available sources as part of our active customer outreach — we provide information in accordance with Article 14 GDPR. This is indicated in the relevant sections.
Who is responsible for processing your data?
The controller within the meaning of the General Data Protection Regulation is:
INSITE‑Interventions GmbH
Clemensstraße 10–12
60487 Frankfurt am Main
Telephone: +49 69 90555 29‑0
Email: office@insite.de
How can you contact our Data Protection Officer?
If you have questions about data protection or the processing of your personal data, you can contact our Data Protection Officer at any time:
Deborah Schütt
Clemensstraße 10–12
60487 Frankfurt am Main
Telephone: +49 69 90555 29‑0
Email: dsb@insite.de
Which personal data do we process?
The data we process depend on the relevant phase of the business relationship and the specific purpose of use. We process only the data required for the respective purposes.
- Master and contact data
First and last name, business email address, telephone number, position and role within the organisation, and the organisation’s address. - Contract data
Information about the scope of services, agreed terms, contract duration and any supplementary or amendment agreements. - Billing and account data
Billing address, bank details or other payment information, insofar as required for invoicing and payment processing. - CRM and acquisition data
Conversation notes, quotation data, sales activities and documented customer interactions. - Communication data
Content and metadata from emails, telephone calls and written correspondence arising in the course of the business relationship. - Meeting and conference data
When using online conference tools (Microsoft Teams, Zoom), depending on your use, we process in particular your email address or telephone number, the duration and time of participation, connection metadata and — where enabled — image and audio transmissions. - Customer dashboard access data
If you are given access to our customer dashboard, your access data and your usage activities within the portal are processed. - Image data
If you have given your consent to being listed as a reference contact on our website or social media channels, we process your first and last name, role, business contact details and a profile photograph.
For which purposes and on which legal bases do we process your data?
Acquisition and preparing quotations
We process personal data to approach potential customers, respond to incoming enquiries, prepare quotations and document the acquisition process. Where you have actively contacted us or responded to one of our enquiries, your data are collected directly from you (Article 13 GDPR). Where we have obtained your contact details during active customer outreach from publicly available sources — for example, the company website, professional directories or professional networks — the data were not collected directly from you (Article 14 GDPR). In this case, we inform you about the processing no later than our first direct contact.
Legal basis: Article 6(1)(b) GDPR for data processed in connection with a specific enquiry or quotation; Article 6(1)(f) GDPR for proactive contact. Our legitimate interest is acquiring new business customers and documenting our sales activities.
Conclusion and management of contracts
To conclude and administer service contracts, we process the data required as the contractual basis for our business relationship. This includes preparing and signing contracts and supplementary agreements, managing and updating contract data, and forwarding contract-related documents to the internal departments involved (customer consulting, Finance, Office).
Legal basis: Article 6(1)(b) GDPR.
Ongoing customer support
As part of the active business relationship, we process personal data so that we can provide the agreed services and coordinate cooperation with your organisation. This includes, in particular, communication about service content and programme updates, coordinating assignments and appointments, providing support with enquiries and maintaining the business relationship through our consulting team.
Legal basis: Article 6(1)(b) GDPR.
Reporting
We prepare annual usage reports on the counselling services booked by your organisation and send them to the relevant customer contacts. The data processed include your contact details and those of the customer consultants responsible for you.
Legal basis: Article 6(1)(b) GDPR.
Customer dashboard
At your request, we provide access to our customer dashboard. Through the portal, you can access materials and reports. To provide and operate the dashboard, we process your access data and information about your use of the portal.
Legal basis: Article 6(1)(b) GDPR.
Online meetings and video conferences
We use online conference tools, in particular Microsoft Teams and Zoom, to communicate with you. When these tools are used, personal data are processed by us and by the respective provider. The scope of processing depends on the data you provide to participate and on the functions used. Please note that we cannot fully influence the providers’ independent processing of data. Conversation content is generally not recorded unless a separate legal basis or consent applies in the individual case.
Legal basis: Article 6(1)(b) GDPR for meetings in the context of the contractual relationship; Article 6(1)(f) GDPR for general communication. Our legitimate interest is efficient and reliable business communication.
Invoicing and accounting
To issue invoices, process payments and comply with tax and commercial-law obligations, we process the necessary billing and account data.
Legal basis: Article 6(1)(b) GDPR and Article 6(1)(c) GDPR for statutory retention obligations under the German Commercial Code (HGB) and the German Fiscal Code (AO).
References
Where you have given your consent, we list you as a reference contact on our company website and, where applicable, on our social media channels (LinkedIn, Instagram). This includes publishing your name, role, profile photograph and — by agreement — business contact details. You may withdraw your consent at any time with effect for the future. Please contact datenschutz@insite.de.
Legal basis: Article 6(1)(a) GDPR.
Complaint management
We process incoming complaints to clarify your concerns appropriately and continuously improve the quality of our services.
Legal basis: Article 6(1)(b) GDPR and Article 6(1)(f) GDPR. Our legitimate interest is quality assurance and performance in accordance with the contract.
Archiving and compliance with legal obligations
To comply with commercial and tax retention obligations and to preserve evidence in potential legal disputes, we archive contract-related documents and correspondence beyond the duration of the active business relationship.
Legal basis: Article 6(1)(c) GDPR; Article 6(1)(f) GDPR. Our legitimate interest is legal protection and compliance with customary documentation obligations in the industry.
Who receives your personal data?
Within INSITE‑Interventions GmbH, only those persons have access to your personal data who require it to perform their respective duties. This applies in particular to employees in Sales, Customer Consulting, Finance and Office and, where necessary, to management and authorised signatories.
We also use external service providers who process personal data on our behalf (processors pursuant to Article 28 GDPR):
- Pipedrive (CRM system for managing customer relationships and sales activities).
- Tresorit (encrypted cloud storage for contracts and customer documents).
- DocuSign (electronic contract-signing platform).
- Microsoft (Microsoft 365, including Teams, for communication and collaboration).
- Zoom (video conferences).
- Lexware (accounting and invoicing).
- eWorks (coordination platform).
- hatch (technical provision of the customer dashboard).
- LinkedIn and Instagram, where applicable, if you have consented to being listed as a reference contact.
All processors used are contractually obliged and regularly reviewed for compliance with data protection requirements. We disclose personal data to authorities or other third parties only where we are legally obliged to do so or where an appropriate legal basis exists.
Are data transferred to third countries?
For our business processes, we use various service providers whose parent companies or infrastructure are based in the United States. In all cases, we ensure that an adequate level of data protection is guaranteed.
| Service provider | Purpose | Safeguard for transfer to a third country |
| Pipedrive | CRM | EU–US Data Privacy Framework adequacy decision |
| DocuSign | Contract signing | EU–US Data Privacy Framework adequacy decision |
| Microsoft (Teams, Office 365) | Communication, collaboration | EU–US Data Privacy Framework adequacy decision |
| Zoom | Video conferences | EU–US Data Privacy Framework adequacy decision |
| References (with consent only) | EU–US Data Privacy Framework adequacy decision | |
| References (with consent only) | EU–US Data Privacy Framework adequacy decision; standard contractual clauses |
How long do we retain your personal data?
All other systems used process data within the European Union. If you would like further information about the safeguards used, please contact our Data Protection Officer.
| Data category | Regular retention period |
| Quotation data (successful quotations) | 10 years |
| Quotation data (unsuccessful quotations) | 6 years |
| Contracts and supplementary agreements | 10 years |
| Billing data and invoices | 10 years (Section 14b(1) UStG, Section 257(1) no. 1 HGB) |
| Customer support and management documentation | 10 years |
| Reporting data | 10 years |
| Dashboard access data | 10 years; access blocked when the contract ends |
| Meeting content and correspondence | 10 years where relevant to the contract; otherwise until the purpose no longer applies |
| CRM data relating to contracts not concluded | 6 years |
| Reference data (consent-based) | Until consent is withdrawn or the business relationship ends |
In individual cases, longer retention periods may apply if legal obligations or pending legal disputes require this. Once the applicable retention period has expired, your data will be deleted or, where complete deletion is not technically possible immediately, blocked from further processing.
What rights do you have?
- Right of access (Article 15 GDPR): you can request information about the personal data we process, the purposes of processing, recipients, retention periods and your other rights.
- Right to rectification (Article 16 GDPR): you can request correction of inaccurate data or completion of incomplete data.
- Right to erasure (Article 17 GDPR): subject to the statutory requirements, you can request erasure of your personal data. Statutory retention obligations remain unaffected.
- Right to restriction of processing (Article 18 GDPR): under certain conditions, you can request that your personal data be processed only in a restricted manner.
- Right to data portability (Article 20 GDPR): where processing is based on consent or a contract and is carried out by automated means, you can receive your data in a machine-readable format.
- Right to object (Article 21 GDPR): where we process personal data on the basis of our legitimate interests under Article 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation. We will then cease processing unless compelling legitimate grounds override your interests.
- Withdrawal of consent: where processing is based on your consent — in particular for use as a reference contact — you may withdraw it at any time with effect for the future. Withdrawal does not affect the lawfulness of processing carried out up to that point.
Right to lodge a complaint with a data protection supervisory authority (Article 77 GDPR)
You have the right to lodge a complaint with the competent data protection supervisory authority:
Hessian Commissioner for Data Protection and Freedom of Information, PO Box 3163, 65021 Wiesbaden - https://datenschutz.hessen.de/
You may also contact the supervisory authority at your place of residence or work.
Are you obliged to provide your personal data?
We require certain personal data to initiate and conduct a business relationship. Providing your contact details, your role and — where contractually agreed — your payment details is a prerequisite for concluding and performing a contract. Without this data, we generally cannot establish or continue a business relationship. Where individual details are provided voluntarily — in particular consent to being used as a reference contact — choosing not to provide them will not disadvantage you in the contractual relationship.
Does automated decision-making or profiling take place?
No solely automated decision-making, including profiling within the meaning of Article 22 GDPR, takes place in the context of our business relationship. Decisions relating to establishing, performing or ending the cooperation are always made by people.
Currency of these privacy notices
These privacy notices reflect the current state of the processing of personal data. We reserve the right to amend these notices if the systems used, processing procedures or legal position change. The current version will be made available on our website.
What is this privacy notice about?
Thank you for your interest in working with INSITE-Interventions GmbH.
Protecting your personal data is important to us. During the application process, we process personal data that you provide to us or that arise in connection with our assessment of your application.
Under Article 13 of the General Data Protection Regulation (GDPR), this privacy notice explains:
- which personal data we process;
- the purposes for which we process them;
- the legal basis for the processing;
- to whom the data may be disclosed;
- how long we retain personal data; and
- your rights as a data subject.
This privacy notice applies to anyone who applies to INSITE-Interventions GmbH for permanent employment or a freelance engagement, whether in response to an advertised vacancy or as a speculative application.
Who is responsible for processing your data?
The controller within the meaning of the General Data Protection Regulation is:
INSITE-Interventions GmbH
Clemensstraße 10-12
60487 Frankfurt am Main
Telephone: +49 69 90555 29-0
Email: office@insite.de
The controller determines the purposes and means of processing personal data.
How can you contact our Data Protection Officer?
You may contact our Data Protection Officer at any time with any questions about data protection or the processing of your personal data.
Data Protection Officer
Deborah Schütt
Clemensstraße 10-12
60487 Frankfurt am Main
Telephone: +49 69 90555 29-0
Email: dsb@insite.de
You may contact our Data Protection Officer confidentially at any time, for example if you have questions about your rights or wish to raise a data protection concern.
What personal data do we process?
We process the personal data that you provide as part of your application or that we need in order to assess it. The specific data processed depend on the information you submit.
Application-related data
This includes, in particular:
- First name and surname
- Postal address
- Date and place of birth
- Contact details (email address and telephone number)
- CV, including information about education and professional experience
- Qualifications, certificates and references
- Salary expectations and availability
- any other information you choose to provide in your covering letter or supporting documents
Special categories of personal data
Where your application documents contain special categories of personal data within the meaning of Article 9 GDPR, such as information about your health, religious or philosophical beliefs, or ethnic origin, we will process those data only where permitted by law.
We recommend that you do not include special categories of personal data in your application documents unless they are relevant to the advertised role.
Technical transmission information
If you send us your application by email, it will be transmitted without end-to-end encryption. To send your documents in encrypted form, you may password-protect them and provide the password separately, for example by telephone. Alternatively, we use Tresorit for secure data exchange.
For what purposes and on what legal basis do we process your data?
Conducting the application process
We process your personal data to assess your application, conduct the selection process and decide whether to enter into an employment relationship with you.
This includes, in particular:
- receiving and managing your application documents
- assessing your qualifications and suitability
- arranging and conducting interviews
- internal consultation on the selection decision
- communicating with you about the status of your application
- issuing a job offer or rejection
If an employment relationship is established, the data collected during the application process may be further processed for purposes connected with that employment relationship.
Legal bases
- Section 26(1) of the German Federal Data Protection Act (BDSG)
- Article 6(1)(b) GDPR
- Article 9(2)(b) GDPR, where special categories of personal data are processed
Defending legal claims
After the application process has ended, we may need to retain your data for a limited period in order to defend ourselves against potential legal claims, particularly claims under the German General Equal Treatment Act (AGG).
Legal basis
- Article 6(1)(f) GDPR
Our legitimate interest is to safeguard and defend our legal interests in the event of a dispute arising from the application process.
Inclusion in the applicant pool (only with your consent)
If we are unable to offer you a position but consider your application relevant to future vacancies, we may ask whether we may retain your documents in our applicant pool.
We will include you in the applicant pool only on the basis of your explicit consent. Inclusion is voluntary and has no effect on the current application process.
You may withdraw your consent at any time with effect for the future. To do so, please contact our Data Protection Officer or email datenschutz@insite.de.
Legal basis
- Article 6(1)(a) GDPR
Who receives your personal data?
Within INSITE-Interventions GmbH, access to your application documents is limited to those who need them to conduct the selection process. This includes, in particular:
- Human Resources
- the relevant managers and heads of department
- the Managing Directors
- Consultant Management, where applicable (for applications as a freelance contractor)
We also use external service providers that process data on our behalf (processors under Article 28 GDPR):
- Personio SE & Co. KG, Munich - HR administration and applicant management software
- Tresorit - encrypted storage and transmission of documents
All processors we use are contractually required to process your data only on our instructions and in accordance with data protection requirements.
We do not disclose your personal data to any other third parties unless we are legally required to do so.
Are personal data transferred to third countries?
As a rule, we process your application data within the European Union (EU) or the European Economic Area (EEA).
No transfer to countries outside the EU or EEA is intended as part of the application process.
How long do we retain your personal data?
We retain your application documents only for as long as necessary for the purposes of the application process, unless legal reasons require a longer retention period.
| Situation | Retention period |
| Unsuccessful application following completion of the selection process | 6 months after notification of rejection |
| Inclusion in the applicant pool for permanent positions (with consent) | 12 months from the date consent is given |
| Inclusion in the applicant pool for freelance contractors (with consent) | 36 months from the date consent is given |
| Entering into an employment relationship | Transfer to the personnel file; further retention in accordance with employment law |
Once the periods stated above have expired, your documents will be deleted unless statutory retention obligations or ongoing legal proceedings prevent deletion.
What rights do you have?
The GDPR gives you a number of rights in relation to the processing of your personal data.
Right of access
You may request confirmation as to whether we process personal data concerning you. If we do, you are entitled to information about the data processed, the purposes of processing, the recipients of your data, the retention period and your other rights.
Rectification
If personal data are inaccurate or incomplete, you may request that they be corrected or completed.
Erasure
Subject to the statutory requirements, you have the right to request erasure of your personal data. This applies, for example, where the data are no longer required for the original purpose, you withdraw your consent and there is no other legal basis, or the processing is unlawful. Statutory retention obligations remain unaffected.
Restriction of processing
In certain circumstances, you may request that the processing of your personal data be restricted.
Data portability
Where processing is based on consent or a contract and is carried out by automated means, you may request to receive your personal data in a structured, commonly used and machine-readable format or have them transmitted to another controller.
Right to object
Where we process personal data on the basis of our legitimate interests under Article 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation. We will then stop the processing unless there are compelling legitimate grounds for continuing it.
Withdrawal of consent
Where processing is based on your consent, you may withdraw that consent at any time with effect for the future. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
Right to lodge a complaint with a supervisory authority
If you believe that the processing of your personal data breaches data protection law, you have the right to lodge a complaint with a data protection supervisory authority.
The supervisory authority responsible for INSITE-Interventions GmbH is:
Hessian Commissioner for Data Protection and Freedom of Information (HBDI)
PO Box 3163
65021 Wiesbaden
Telephone: +49 611 1408-0
Email: poststelle@datenschutz.hessen.de
Website: https://datenschutz.hessen.de
You may also contact the supervisory authority for your place of residence or habitual residence.
We would appreciate it if you contacted our Data Protection Officer first about any data protection concerns so that we can try to resolve the matter together. However, this is not a condition for exercising your right to lodge a complaint.
To exercise your rights, please contact our Data Protection Officer at dsb@insite.de or email datenschutz@insite.de.
Are you required to provide your personal data?
You are not legally or contractually required to provide your application documents. However, without the information needed for the selection process, particularly your contact details and information about your qualifications and professional experience, we cannot assess your application or conduct the process.
Where individual details are optional, not providing them will not put you at any direct disadvantage in the application process. We recommend that you include in your documents only information relevant to the role for which you are applying.
Do we use automated decision-making or profiling?
We do not use solely automated decision-making, including profiling within the meaning of Article 22 GDPR, as part of the application process. Decisions about your application are always made by people.
Status of this privacy notice
This privacy notice reflects the current state of personal data processing at INSITE-Interventions GmbH. Changes to processes, legal requirements or the systems used may require this notice to be amended. The current version is available on our website at https://www.insite.de/en/data-protection.
What is this privacy notice about?
INSITE-Interventions GmbH works with freelance contractors to provide its counselling services. In connection with this working relationship, we process personal data that we receive from you or that arise in connection with the work you carry out for us.
Under Articles 13 and 14 of the General Data Protection Regulation (GDPR), this privacy notice explains which personal data we process, the purposes for which we process them, the legal basis for the processing, to whom data may be disclosed, how long we retain personal data and what rights you have as a data subject.
This privacy notice applies to all freelance contractors working with INSITE-Interventions GmbH. It applies from the first contact made in connection with a potential engagement and throughout the working relationship until it ends, as well as afterwards where statutory retention obligations apply.
Where we collect personal data not directly from you but from publicly accessible sources - particularly when actively searching for suitable freelance contractors - the information requirements under Article 14 GDPR apply. This is indicated separately in the relevant sections.
Who is responsible for processing your data?
The controller within the meaning of the General Data Protection Regulation is:
INSITE-Interventions GmbH
Clemensstraße 10-12
60487 Frankfurt am Main
Telephone: +49 69 90555 29-0
Email: office@insite.de
How can you contact our Data Protection Officer?
If you have any questions about data protection or the processing of your personal data, you may contact our Data Protection Officer at any time:
Deborah Schütt
Clemensstraße 10-12
60487 Frankfurt am Main
Telephone: +49 69 90555 29-0
Email: dsb@insite.de
You may contact our Data Protection Officer in confidence at any time, for example if you have questions about your rights or wish to raise a data protection concern.
What personal data do we process?
The personal data we process depend on the stage of the engagement at which they arise and on the data required for the relevant purposes.
- Contact and core data First name and surname, address, telephone number, email address and, where applicable, business address, tax number or VAT identification number, and bank details for the payment of fees.
- Qualification data Professional training and qualifications, certifications, areas of specialism, professional experience, language skills, driving licence and other evidence relevant to the engagement with INSITE.
- Contract data Freelance services agreement, service description, agreed fees, invoicing data, evidence of services provided and documents relating to amendments to or termination of the agreement.
- Assignment and coordination data Availability, assignment dates and times, location information, assignments and their administration, quality feedback, and information relating to day-to-day cooperation.
- Communication data Content and metadata from emails, telephone calls and other communication channels generated in connection with the engagement.
- IT access data User account, access permissions and log data where we grant you access to our IT systems.
- Profile on our corporate website Where you are featured on our website with your photograph, name and qualifications, we process the data provided for this purpose, in particular your first name and surname, image, professional qualifications and contact details.
Special categories of personal data At certain stages of the engagement, special categories of personal data within the meaning of Article 9 GDPR may arise. This includes, in particular, health data where you provide them in connection with your availability or as evidence of professional qualifications, as well as data revealing racial or ethnic origin or religious or philosophical beliefs where these are relevant to evidence of qualifications or professional suitability. Special categories of personal data are processed only where permitted by law and only by persons specifically authorised to do so.
For what purposes and on what legal basis do we process your data?
Establishing the engagement
We process personal data to identify and approach suitable freelance contractors to work with INSITE and to respond to enquiries from interested individuals.
Where you apply to us directly or respond to an advertisement, we collect your data directly from you (Article 13 GDPR). The data processed include, in particular, contact details, evidence of qualifications and information about professional suitability.
Where, as part of an active search, we use publicly accessible information - for example, your website, professional profiles or professional directories - those data are not collected directly from you (Article 14 GDPR). In this case, the source of the data is information that you have published on publicly accessible platforms. We process, in particular, contact details, qualification information and other professional information.
Data relating to individuals who are not selected are deleted from our systems after the selection process has been completed, and no later than six months afterwards, unless separate consent has been given for inclusion in an applicant pool.
Legal bases: Article 6(1)(b) GDPR (steps prior to entering into a contract); Article 6(1)(f) GDPR for active searches using publicly accessible sources. Our legitimate interest lies in identifying qualified freelance contractors for our counselling services.
Applicant pool
With your consent, we include your data in our applicant pool and may contact you about future opportunities. Data are retained in the applicant pool for up to 12 months where you are interested in permanent employment and for up to 36 months in relation to freelance engagements, calculated from the date on which consent is given.
Legal basis: Article 6(1)(a) GDPR. You may withdraw your consent at any time with effect for the future.
Entering into and managing the contract
To enter into and manage the freelance services agreement, we process personal data required as the contractual basis of our working relationship. This includes, in particular, entering into and signing the agreement using DocuSign, administering and updating contract data, fee invoicing and payment processing, documenting evidence of qualifications, and complying with tax and commercial law obligations.
Legal bases: Article 6(1)(b) GDPR; Article 6(1)(c) GDPR for legal obligations; Article 9(2)(b) GDPR where special categories of personal data are processed in connection with the engagement.
Active engagement and assignment planning
During the active engagement, we process personal data to coordinate service delivery and ensure the quality of our counselling services. This includes, in particular, planning and coordinating assignments, communicating in connection with individual assignments, documenting services provided, recording feedback on counselling services and handling assignment requests.
Legal bases: Article 6(1)(b) GDPR; Article 9(2)(b) GDPR where special categories of personal data arise.
Data protection and information security training
All freelance contractors working for INSITE attend mandatory data protection and information security training. In connection with this training, we process attendance data and training records.
Legal bases: Article 6(1)(c) GDPR; Article 6(1)(b) GDPR. Awareness training forms part of our statutory and contractual data protection obligations.
IT systems and access management
Where we grant you access to our IT systems, we process the data required to set up and manage user accounts, as well as log data relating to the use of those systems. The processing is carried out solely to ensure secure and proper IT operations. As a rule, it does not involve monitoring performance or conduct.
Legal bases: Article 6(1)(b) GDPR; Article 6(1)(f) GDPR. Our legitimate interest lies in ensuring information security and protecting our systems and the client data entrusted to us.
Profile on our corporate website
Where we feature you on our website using your professional information, we do so only on the basis of your prior consent. Publication usually includes your name, qualifications, areas of professional specialism and a profile photograph. You may withdraw your consent at any time with effect for the future. If you withdraw your consent or the engagement ends, your website profile will be removed without delay.
Legal basis: Article 6(1)(a) GDPR.
Creating and publishing photographs, audio and video recordings
At events, training sessions or for corporate communications, photographs, audio or video recordings may be made in which you appear. Any publication is based solely on your consent. You may withdraw consent at any time with effect for the future. To do so, please contact datenschutz@insite.de.
Legal basis: Article 6(1)(a) GDPR.
End of the engagement
When the working relationship ends, we process personal data to manage the formal termination of the engagement properly. This includes blocking access to IT systems, removing your website profile, settling final fees and archiving documents subject to statutory retention requirements.
Legal bases: Article 6(1)(b) GDPR; Article 6(1)(c) GDPR for statutory retention obligations.
Compliance with legal and data protection obligations
We also process personal data in order to comply with data protection requirements and other statutory record-keeping obligations.
Legal bases: Article 6(1)(c) GDPR; Article 6(1)(f) GDPR. Our legitimate interest lies in complying with and demonstrating compliance with data protection requirements.
Who receives your personal data?
Within INSITE-Interventions GmbH, access to your personal data is limited to those who need them in order to perform their duties. The need-to-know principle applies. Internal recipients may include Consultant Management, the Head of Interventions, team and department heads, Client Consulting, Human Resources, the Managing Directors, the Information Security Officer and Client Services staff, where this is necessary to coordinate individual assignments.
We also use external service providers that process personal data on our behalf (processors under Article 28 GDPR). These include, in particular:
Tresorit (encrypted cloud storage for contractual documents and personnel records), DocuSign (electronic contract signing), eWorks (a planning and coordination system for freelance contractors and assignments), and the call-centre service provider commissioned by us where freelance contractors are involved in assignments coordinated through the call centre.
All processors we use are carefully selected, contractually bound and regularly reviewed for compliance with data protection requirements.
We disclose your personal data to public authorities or other public bodies only where we are legally required to do so.
Are personal data transferred to third countries?
As a rule, we process your personal data within the European Union (EU) or the European Economic Area (EEA).
For certain services, we use providers whose systems may allow data to be transferred to third countries. In those cases, we ensure that an adequate level of data protection is maintained.
We use DocuSign for electronic contract signing. DocuSign is based in the United States; transfers to the United States take place on the basis of the European Commission's adequacy decision for the EU-US Data Privacy Framework and standard contractual clauses under Article 46 GDPR.
For more information about the safeguards used, please contact our Data Protection Officer at any time.
How long do we retain your personal data?
We retain your personal data only for as long as necessary for the relevant purposes or for as long as statutory retention obligations apply.
| Data category | Standard retention period |
|---|---|
| Data relating to an engagement that did not proceed | 6 months after completion of the selection process |
| Data in the applicant pool (with consent) | Up to 36 months from the date on which consent is given |
| Contract documents and fee data | 10 years (section 147 AO; section 257 HGB) |
| Coordination and assignment records | 10 years as part of the documentation system |
| IT access and log data | Access disabled and data deleted immediately after the engagement ends, unless retention obligations apply |
| Website profile | Removed without delay when the engagement ends or consent is withdrawn |
| Photographs and videos (consent-based) | Until consent is withdrawn or the purpose no longer applies |
| Training and data protection records | Generally up to 3 years, unless longer statutory periods apply |
Longer retention periods may apply in individual cases where legal obligations or ongoing legal proceedings require this.
What rights do you have?
The GDPR gives you a number of rights in relation to the processing of your personal data.
Right of access (Article 15 GDPR) You may request confirmation as to whether we process personal data concerning you, as well as information about the purposes of processing, recipients, the retention period and your other rights.
Right to rectification (Article 16 GDPR) If personal data are inaccurate or incomplete, you may request that they be corrected or completed.
Right to erasure (Article 17 GDPR) Subject to the statutory requirements, you have the right to request erasure of your personal data, for example where the data are no longer required for the original purpose or you have withdrawn your consent. Statutory retention obligations remain unaffected.
Right to restriction of processing (Article 18 GDPR) In certain circumstances, you may request that the processing of your personal data be restricted.
Right to data portability (Article 20 GDPR) Where processing is based on consent or a contract and is carried out by automated means, you may request to receive your data in a structured, commonly used and machine-readable format or have them transmitted to another controller.
Right to object (Article 21 GDPR) Where we process personal data on the basis of our legitimate interests under Article 6(1)(f) GDPR, you may object to the processing at any time on grounds relating to your particular situation. We will stop the processing unless there are compelling legitimate grounds for continuing it.
Withdrawal of consent Where processing is based on your consent, you may withdraw that consent at any time with effect for the future. Withdrawal does not affect the lawfulness of processing carried out before the consent was withdrawn.
Right to lodge a complaint with a supervisory authority (Article 77 GDPR) You have the right to lodge a complaint with the competent data protection supervisory authority if you believe that the processing of your personal data breaches the GDPR. The supervisory authority responsible for INSITE-Interventions GmbH is:
Hessian Commissioner for Data Protection and Freedom of Information, PO Box 3163, 65021 Wiesbaden - https://datenschutz.hessen.de/
You may also contact the supervisory authority for your place of residence or place of business.
Are you required to provide your personal data?
To enter into and perform the freelance services agreement, we need various personal data. Providing these data is a prerequisite for entering into and carrying out the engagement. Without these data, we will generally be unable to establish or continue the working relationship.
This applies, in particular, to contact and core data, evidence of qualifications, tax and bank details, and other information required to manage the contractual relationship.
Where individual items of information are voluntary - particularly where processing is based on consent, for example for inclusion in our applicant pool, a profile on our website or the publication of photographs - not providing those data will not disadvantage you in relation to the engagement.
Do we use automated decision-making or profiling?
We do not use solely automated decision-making, including profiling within the meaning of Article 22 GDPR, as part of the engagement. Decisions on whether to establish or continue a working relationship are always made by individuals.
If we introduce procedures in the future that involve automated decision-making within the meaning of Article 22 GDPR, we will inform you separately.
Status of this privacy notice
This privacy notice reflects the current state of personal data processing at INSITE-Interventions GmbH. If changes are made, we will update this notice and make the new version available.
What is this data protection notice about?
On our website, we offer you the option of booking appointments online via the timify service. In the course of booking an appointment, we process personal data that you provide to us. With this data protection notice, we inform you, in accordance with Article 13 of the General Data Protection Regulation (GDPR), which personal data we process in connection with appointment booking, for what purpose, on what legal basis the processing takes place, who receives your data and how long it is stored. We also inform you about your rights as a data subject.
Who is responsible for processing your data?
The controller within the meaning of the GDPR is:
INSITE-Interventions GmbH
Clemensstraße 10–12
60487 Frankfurt am Main
Telephone: +49 69 90555 29-0
Email: office@insite.de
How can you reach our Data Protection Officer?
If you have questions about data protection or the processing of your personal data, you can contact our Data Protection Officer at any time:
Deborah Schütt
Clemensstraße 10–12
60487 Frankfurt am Main
Telephone: +49 69 90555 29-0
Email: dsb@insite.de
Which personal data do we process?
In the context of online appointment booking, we process only the data that you enter in the booking form. Depending on the booking process, this may include:
- First name and surname
- Email address
- Telephone number (where provided)
- Requested appointment (date and time)
- Type of appointment or request
Please do not enter any information in the booking form that goes beyond what is required to arrange the appointment – in particular, no detailed information about your state of health or personal circumstances. Such information can be discussed during the agreed appointment.
For what purpose and on what legal basis do we process your data?
We process your personal data solely for the purpose of arranging, administering and conducting the appointment you have requested. This includes, in particular, confirming your appointment, preparing for the conversation and communicating with you in connection with the appointment.
The legal basis for processing your personal data is your consent pursuant to Article 6(1)(a) GDPR, which you provide by using the booking form. Where information indicating health-related or comparable sensitive content is provided in connection with booking the appointment, processing is additionally based on Article 9(2)(h) GDPR.
Consent is voluntary. You may decline to use the online booking service at any time and arrange an appointment by telephone or email instead.
Who receives your personal data?
Within our company Only those persons who prepare or conduct the appointment have access to your data. Access is provided on a need-to-know basis.
External service provider (processor)
For the technical provision of the online booking system, we use the timify service provided by TerminApp GmbH, Munich. TerminApp GmbH processes your personal data on our behalf and solely in accordance with our instructions. We have concluded a data processing agreement with TerminApp GmbH pursuant to Article 28 GDPR.
Further information about data processing by timify can be found in the provider’s privacy policy at: https://www.timify.com/en/legal/
Are personal data transferred to third countries?
In connection with using timify, personal data may be transferred to the United States. This transfer takes place on the basis of the European Commission’s adequacy decision for the EU–US Data Privacy Framework pursuant to Article 45 GDPR, which ensures an adequate level of data protection.
How long do we store your personal data?
The personal data collected in connection with arranging an appointment are deleted 18 months after the appointment has been arranged, unless statutory retention obligations prevent earlier deletion. If a counselling or contractual relationship is established following the appointment, the data required for this purpose are stored and processed in accordance with the periods applicable to that relationship. You will be informed separately about this.
What rights do you have?
Access: You may request information about whether and which personal data we process about you, as well as the purposes, recipients, storage period and your further rights.
Rectification: You may request rectification of inaccurate or completion of incomplete personal data.
Erasure: Subject to statutory requirements, you may request erasure of your personal data, for example where the data are no longer required for the original purpose or you withdraw your consent.
Restriction of processing: Under certain conditions, you may request that your personal data only be processed to a limited extent.
Data portability: Where processing is based on consent and is carried out by automated means, you may request to receive your personal data in a structured, commonly used and machine-readable format.
Right to object: Where we process data on the basis of a legitimate interest pursuant to Article 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation.
Withdrawal of consent: As the processing of your data in connection with appointment booking is based on your consent, you may withdraw it at any time with effect for the future. Please contact our Data Protection Officer (details above) or datenschutz@insite.de. Withdrawal does not affect the lawfulness of processing carried out up to that point.
Please note that withdrawing consent after an appointment has been booked may result in cancellation of the appointment.
Right to lodge a complaint: If you consider that the processing of your personal data infringes data protection law, you have the right to lodge a complaint with a data protection supervisory authority. The supervisory authority responsible for INSITE-Interventions GmbH is the Hessian Commissioner for Data Protection and Freedom of Information (HBDI): https://datenschutz.hessen.de/. You may also contact the supervisory authority at your place of residence or habitual abode.
Are you obliged to provide your personal data?
Providing your personal data in the context of online appointment booking is voluntary. However, without the required contact details, it is technically impossible to arrange an appointment via the online booking system. Alternatively, you can arrange an appointment by telephone on +49 69 90555 29-0 or by email at kontakt@insite.de.
Does automated decision-making or profiling take place?
No automated decision-making, including profiling within the meaning of Article 22 GDPR, takes place in the context of online appointment booking.
Up-to-dateness of this data protection notice
This data protection notice reflects the current state of the processing of personal data in connection with online appointment booking. We reserve the right to adapt this notice in the event of changes to the systems used, processing operations or the legal situation. The current version is made available on our website.
What is this privacy notice about?
When you contact INSITE-Interventions GmbH by email - whether as a customer, client, business partner, prospective customer or other interested party, or in another capacity - we process personal data that you provide in your message or that arise as a technical consequence of email communications.
Under Article 13 of the General Data Protection Regulation (GDPR), this privacy notice explains which personal data we process in connection with our email communications, the purposes and legal bases of the processing, who receives your data, how long we retain them and what rights you have.
This notice applies to all incoming and outgoing emails processed through the email infrastructure of INSITE-Interventions GmbH (Microsoft Outlook / Exchange / Mailstore archive). Because we collect your data directly from you in connection with your email message, Article 13 GDPR applies.
Employees of INSITE-Interventions GmbH are also covered by the separate Privacy Notice for Employees.
Who is responsible for processing your data?
The controller within the meaning of the General Data Protection Regulation is:
INSITE-Interventions GmbH
Clemensstraße 10-12
60487 Frankfurt am Main
Telephone: +49 69 90555 29-0
Email: office@insite.de
How can you contact our Data Protection Officer?
If you have any questions about data protection or the processing of your personal data, you may contact our Data Protection Officer at any time:
Deborah Schütt
Clemensstraße 10-12
60487 Frankfurt am Main
Telephone: +49 69 90555 29-0
Email: dsb@insite.de
What personal data do we process?
In connection with email communications, we process the following categories of data.
Identification and contact data Your email address and your name, insofar as it appears in the email address, signature or message text.
Communication content The content of your email messages, including any attachments and files sent with them.
Communication metadata Sender and recipient addresses, subject line, date and time of sending, and technical header information generated during transmission of the message.
Technical log data Server logs generated for the secure operation of the email infrastructure and the detection of security incidents.
Special categories of personal data In individual cases, email content may include health data or other special categories of personal data within the meaning of Article 9 GDPR, particularly where the communication relates to EAP services (Employee Assistance Programme). Such data are processed only where permitted by law and only by persons expressly authorised to do so.
For what purposes and on what legal basis do we process your data?
Handling enquiries and managing communications
We process the content and metadata of your emails in order to handle your enquiries, communicate with you and manage existing business or contractual relationships. This includes all business correspondence relating to cooperation arrangements, contractual engagements and the provision of services.
Legal basis: Article 6(1)(b) GDPR, where the communication serves to prepare for or perform a contract; Article 6(1)(f) GDPR for general business communications and documentation. Our legitimate interest lies in dealing with enquiries properly and maintaining business relationships.
Processing health-related information in the EAP context
Where emails contain health data connected with the provision of EAP counselling services, processing is carried out on the basis of the legal provisions applicable to healthcare and support provided by professionals.
Legal basis: Article 9(2)(h) GDPR in conjunction with section 22 of the German Federal Data Protection Act (BDSG).
IT security and system stability
Technical log data and metadata are processed to ensure the security and availability of the email infrastructure, detect and address security incidents, and prevent misuse. As a rule, email content is not analysed for this purpose.
Legal basis: Article 6(1)(f) GDPR. Our legitimate interest lies in ensuring secure IT operations and protecting our systems and the data entrusted to us.
Legally compliant email archiving
All incoming and outgoing emails are stored in full and automatically in our Mailstore archive. This enables us to comply with retention obligations under commercial and tax law and to document business-relevant communications.
Legal basis: Article 6(1)(c) GDPR for statutory retention obligations (section 147 of the German Fiscal Code (AO) and section 257 of the German Commercial Code (HGB)); Article 6(1)(f) GDPR for documenting business communications. Our legitimate interest lies in the verifiability and traceability of business transactions.
Who receives your personal data?
Within INSITE-Interventions GmbH, only employees who need email content for their particular duties are given access. The need-to-know principle applies.
To operate the email infrastructure, we use the following processors, which process personal data solely on our behalf and in accordance with our instructions:
Blackpoint GmbH is our IT service provider and, as a processor, is responsible for operating and administering the email infrastructure, including the Mailstore archive.
NTT Global Data Centers EMEA GmbH operates the data centre in which the email infrastructure is hosted. The systems are operated exclusively within the European Union.
In addition, normal email communications inevitably involve transfers of data to the email infrastructure used by the relevant recipients to whom you address messages or from whom you receive messages. We have no control over that infrastructure.
All processors we use are contractually required to comply with data protection requirements and are reviewed regularly. Data are disclosed to authorities or other public bodies only where we are legally required to do so.
Are personal data transferred to third countries?
Personal data are processed by our email infrastructure and the Mailstore archive exclusively within the European Union. Our IT service providers Blackpoint and NTT operate the systems used in EU data centres; no data are transferred to third countries.
Please note that we have no control over the infrastructure of the email providers you use. If your email address is hosted by a provider outside the EU, transmission of your message to us may involve a transfer of data to the country concerned. This is outside our area of responsibility.
How long do we retain your data?
We retain your personal data only for as long as necessary for the relevant purposes or for as long as statutory retention obligations apply.
| Data category | Standard retention period |
|---|---|
| Emails in the Mailstore archive (all incoming and outgoing messages) | 10 years (statutory retention obligation pursuant to section 147 AO and section 257 HGB) |
| Emails in active mailboxes | 3 years; up to 10 years for legally relevant communications |
| Technical log data | As required for IT operations; generally for a significantly shorter period |
In individual cases, longer retention periods may apply where required by law or by pending legal proceedings.
Archiving note: Please be aware that all emails you send to us or that we send to you are stored automatically and in full in our Mailstore archive for ten years. This also applies to messages that you may consider confidential. If you wish to send particularly sensitive information, we recommend agreeing a secure method of communication with us in advance.
What rights do you have?
The GDPR gives you various rights in relation to the processing of your personal data.
Right of access (Article 15 GDPR) You may ask whether we process personal data concerning you and, if so, which data, together with information about the purposes of processing, recipients, retention period and your other rights.
Rectification (Article 16 GDPR) If personal data are inaccurate or incomplete, you may ask us to correct or complete them.
Erasure (Article 17 GDPR) Subject to the statutory requirements, you have the right to request the erasure of your personal data. Please note that emails subject to statutory retention obligations cannot be deleted before the applicable statutory period has expired.
Restriction of processing (Article 18 GDPR) In certain circumstances, you may request that the processing of your personal data be restricted.
Data portability (Article 20 GDPR) Where processing is based on consent or a contract and is carried out by automated means, you may receive your data in a structured, commonly used and machine-readable format or request that they be transmitted to another controller.
Right to object (Article 21 GDPR) Where we process personal data on the basis of our legitimate interests under Article 6(1)(f) GDPR, you may object to this processing at any time on grounds relating to your particular situation. We will cease the processing unless there are compelling legitimate grounds for it. This does not apply insofar as retention is required by law.
Right to lodge a complaint with a supervisory authority (Article 77 GDPR) You have the right to lodge a complaint with the competent data protection supervisory authority if you believe that our processing of your personal data infringes the GDPR. The supervisory authority responsible for INSITE-Interventions GmbH is:
Hessian Commissioner for Data Protection and Freedom of Information · PO Box 3163 · 65021 Wiesbaden · https://datenschutz.hessen.de/
You may also contact the supervisory authority for your place of residence or business.
Are you required to provide your data?
If you send us an email, your email address is a technically necessary component of the message. Email communication is not possible without it. Otherwise, you decide which information you provide to us by email. You are not required to contact us by email; you may also reach us by other means.
Do we use automated decision-making or profiling?
No automated decision-making within the meaning of Article 22 GDPR takes place in connection with email communications. Decisions based on the content of emails are always made by individuals. Technical systems for automated spam and virus detection analyse emails for harmful content; this is used solely for IT security and has no legal or similarly significant effects on you.
Status of this privacy notice
This privacy notice reflects the current state of the processing of personal data in connection with email communications by INSITE-Interventions GmbH. If changes are made, we will update this notice and publish the new version.
What is this data protection notice about?
INSITE-Interventions GmbH sends out a newsletter at regular intervals to inform subscribers about news, offers and relevant topics from our company. With this data protection notice, we inform you, in accordance with Article 13 of the General Data Protection Regulation (GDPR), which personal data we process in connection with the newsletter, for what purposes and on what legal basis, to whom data are disclosed, how long we store your data and what rights you have as a data subject. This data protection notice applies to all persons who have subscribed to our newsletter or apply for a subscription.
Who is responsible for processing your data?
The controller within the meaning of the GDPR is:
INSITE-Interventions GmbH
Clemensstraße 10–12
60487 Frankfurt am Main
Telephone: +49 69 90555 29-0
Email: office@insite.de
How can you reach our Data Protection Officer?
If you have questions about data protection or the processing of your personal data, you can contact our Data Protection Officer at any time:
Deborah Schütt
Clemensstraße 10–12
60487 Frankfurt am Main
Telephone: +49 69 90555 29-0
Email: dsb@insite.de
Which personal data do we process?
Registration data
To subscribe to our newsletter, we collect the following personal data: title, first name, surname and email address. Providing your name and title is voluntary and serves to personalise the way we address you in the newsletter. Only your email address is required for sending the newsletter.
Technical data documenting consent
When you register, we store the IP address of the device you use and the date and time of registration to document your consent. These data are used exclusively to demonstrate that you lawfully requested the newsletter and are not used for any other purposes.
Newsletter tracking
Our newsletters contain so-called tracking pixels. These are small, invisible graphic elements that are loaded when a newsletter is opened and enable analysis of user behaviour. This allows us to assess whether and when a newsletter was opened and which links it contained were accessed.
In particular, we process the time at which the email was opened, information on whether the email was opened (yes/no), links clicked and technical information about your email programme and device.
Tracking is carried out solely on the basis of your consent. You can object to tracking by disabling the loading of images in your email programme. Please note that the newsletter may not be displayed in full in this case.
For what purposes and on what legal basis do we process your data?
Sending the newsletter
We send the newsletter exclusively to persons who have actively registered in advance and given their consent to receive it. Registration takes place using the double opt-in procedure: after entering your email address, you receive a confirmation email through which you must expressly confirm your registration. Only after this confirmation will we add you to our newsletter mailing list.
Legal basis: Article 6(1)(a) GDPR. You may withdraw your consent at any time with effect for the future.
Documentation of consent
Storing the IP address, date and time at registration serves exclusively to demonstrate that consent was lawfully given and to prevent possible misuse.
Legal basis: Article 6(1)(f) GDPR. Our legitimate interest lies in documenting consent in a legally secure manner and protecting against unauthorised use of email addresses.
Newsletter tracking and measuring success
Analysing open rates and click behaviour helps us tailor the content of our newsletters more closely to the interests of our subscribers and continuously improve the quality of our communications.
Legal basis: Article 6(1)(a) GDPR. Consent to tracking forms part of consent to receive the newsletter. Unsubscribing from the newsletter automatically also constitutes withdrawal of consent to tracking.
Who receives your personal data?
Within INSITE-Interventions GmbH, only employees in Marketing have access to the data required for sending the newsletter.
For the technical distribution of the newsletter, we use the Maileon service provided by XQueue GmbH, Christian-Pleß-Straße 11–13, 63069 Offenbach am Main. XQueue processes your personal data solely on our behalf and in accordance with our instructions on the basis of a data processing agreement pursuant to Article 28 GDPR. The primary data processing takes place on servers in Germany.
Are data transferred to third countries?
XQueue GmbH is a German company based in Offenbach am Main. As part of providing the technical service, personal data may be transferred to sub-processors based in the United States. In this case, the transfer is based on the European Commission’s adequacy decision for the EU–US Data Privacy Framework. If you would like further information about the safeguards used, you may contact our Data Protection Officer at any time.
How long do we store your personal data?
| Data category | Retention period |
| Registration data (name, email address, title) | Until you unsubscribe from the newsletter; then deleted without undue delay. |
| Technical registration data (IP address, timestamp) | Until you unsubscribe from the newsletter. |
| Tracking data | Until you unsubscribe from the newsletter. |
After you unsubscribe, all data stored for this purpose will be deleted without undue delay unless statutory retention obligations prevent this.
What rights do you have?
Access (Article 15 GDPR) You may request access to the personal data we process.
Rectification (Article 16 GDPR) You may request rectification of inaccurate or incomplete data.
Erasure (Article 17 GDPR) You may request erasure of your personal data unless statutory retention obligations prevent this.
Restriction of processing (Article 18 GDPR) Under certain conditions, you may request restriction of processing.
Data portability (Article 20 GDPR) Where the requirements are met, you may receive your data in a machine-readable format.
Withdrawal of consent As all processing of your personal data in connection with the newsletter is based on your consent, you may withdraw it at any time and without stating reasons with effect for the future. This does not affect the lawfulness of processing carried out before withdrawal. You can unsubscribe from the newsletter at any time. Unsubscribing automatically constitutes withdrawal of your entire newsletter consent, including consent to tracking. You can unsubscribe using the unsubscribe link included in every newsletter or by emailing datenschutz@insite.de.
Right to lodge a complaint (Article 77 GDPR) You have the right to lodge a complaint with the competent data protection supervisory authority. The supervisory authority responsible is the Hessian Commissioner for Data Protection and Freedom of Information, PO Box 3163, 65021 Wiesbaden, https://datenschutz.hessen.de/. You may also contact the supervisory authority at your place of residence or work.
Are you obliged to provide your data?
Providing your email address is technically necessary to subscribe to the newsletter. Without a valid email address, we cannot send you the newsletter. Providing your name and title is voluntary and serves solely to personalise the way we address you. Receiving the newsletter is entirely voluntary. If you do not subscribe or unsubscribe at any time, you will not suffer any disadvantages.
Does automated decision-making or profiling take place?
No solely automated decision-making, including profiling within the meaning of Article 22 GDPR, takes place. Analysing user behaviour serves solely to optimise the content of the newsletter and has no legal or similarly significant effects on you.
Up-to-dateness of this data protection notice
This data protection notice reflects the current state of the processing of personal data in connection with receiving the newsletter. We reserve the right to adapt this notice in the event of changes to the systems used, processing operations or the legal situation. The current version is made available on our website.
What is this data protection notice about?
INSITE-Interventions GmbH designs and conducts seminars, training courses, workshops, training sessions and webinars on behalf of customer companies. In the course of planning, preparing and conducting these events, we process personal data of registered participants.
With this data protection notice, we inform you, in accordance with Article 13 of the General Data Protection Regulation (GDPR), which personal data we process, for what purposes and on what legal basis, to whom data are disclosed, how long we store your data and what rights you have as a data subject.
This data protection notice applies to all persons who register for or participate in an in-person or online event planned or conducted by INSITE-Interventions GmbH.
Who is responsible for processing your data?
The controller within the meaning of the GDPR is:
INSITE-Interventions GmbH
Clemensstraße 10–12
60487 Frankfurt am Main
Telephone: +49 69 90555 29-0
Email: office@insite.de
How can you reach our Data Protection Officer?
If you have questions about data protection or the processing of your personal data, you can contact our Data Protection Officer at any time:
Deborah Schütt
Clemensstraße 10–12
60487 Frankfurt am Main
Telephone: +49 69 90555 29-0
Email: dsb@insite.de
Which personal data do we process?
The data we process in connection with seminars and training courses are limited to the minimum required for smooth organisation and delivery.
Registration data First name and surname, professional function and – where required for the invitation or provision of access details for online events – a business email address.
Participant lists For event preparation and coordination, we maintain a participant list containing the first names, surnames and functions of registered persons. This list is shared internally only and with the trainers conducting the event, and is deleted immediately after the event has ended.
Technical data in online events When participating in online seminars and webinars, the conference and webinar platforms used (ON24, Zoom, Microsoft Teams) process technical connection and usage data. This may include, in particular: IP address, device information, operating system version, display name, email address (where provided during registration), time and duration of participation, interactions within the event (e.g. polls, Q&A questions and reactions) and, where activated, camera and microphone transmissions.
Content from online seminars If you contribute via chat, question or survey functions, the texts you enter are processed for the duration of the event. Online seminars are generally not recorded without prior information and, where legally required, without your consent.
For what purposes and on what legal basis do we process your data?
Planning and preparation of the event
We process your registration data to coordinate seminar organisation with the booking customer company, reserve your place at the event, compile the participant list for the trainers conducting the event and – for online events – send access details or invitation links.
Legal basis: Article 6(1)(b) GDPR. Processing is necessary to fulfil INSITE-Interventions GmbH’s contractual obligations towards the booking customer company, which include properly organising and conducting the registered event.
Conducting in-person seminars
For in-person events, we maintain an attendance list to document participation and ensure an orderly event. Your data may be visible to other participants during the event where this is consistent with the nature of the joint seminar.
Legal basis: Article 6(1)(b) GDPR.
Conducting online seminars and webinars
For online events, we use conference and webinar platforms through which the event is technically provided. The platforms process the technical data listed above to establish and maintain the connection. Your display name is visible to other participants and to the trainer. Please note that we have no complete control over the data processing activities of platform providers where they process data for their own purposes. Further information can be found in the data protection information of the relevant platform.
Legal basis: Article 6(1)(b) GDPR.
Recording of events
Where an event is to be recorded, you will be expressly informed in advance. A recording that makes you identifiable is only made on the basis of your explicit consent or another explicit legal basis.
Legal basis: Article 6(1)(a) GDPR, where consent is obtained.
Documentation and contract performance
Event-related planning documents and documentation of the scope of services are retained as part of our contractual invoicing records vis-à-vis the booking customer company for the duration of the statutory retention periods. These documents generally contain no personal data of participants, but rather details of the event services. Legal basis:
Article 6(1)(b) GDPR; Article 6(1)(c) GDPR for statutory retention obligations.
Who receives your personal data?
Within INSITE-Interventions GmbH, only employees of Customer Advisory have access to your registration data where this is necessary for organising the seminar. The participant list is shared with the trainer responsible for your event – generally a fee-based contractor of INSITE. The trainer therefore knows your name and function in order to prepare and conduct the event.
For online events, the platform providers used process your data as processors pursuant to Article 28 GDPR or – insofar as they process data for their own purposes – as independent controllers:
ON24 (webinar platform for online seminars), Zoom Video Communications (video conferencing) and Microsoft (Microsoft Teams for video conferencing and collaboration).
We also use Tresorit for encrypted storage of planning documents and eWorks for internal coordination. Both services are based in the European Economic Area and do not process participant data.
Your name and function are visible to other participants during the event where this is consistent with the event format.
Are data transferred to third countries?
For online events, we use platform providers whose parent companies are based in the United States. In all cases, we ensure that an adequate level of data protection is maintained.
| Platform | Purpose | Safeguard for third-country transfer |
| ON24 | Conducting webinars | EU–US Data Privacy Framework adequacy decision |
| Zoom | Video conferencing | EU–US Data Privacy Framework adequacy decision |
| Microsoft Teams | Video conferencing | EU–US Data Privacy Framework adequacy decision |
If you participate in an event held exclusively in person, no transfer to a third country takes place. Further information about the platform providers’ data protection practices can be found in their privacy notices:
- ON24: https://www.on24.com/privacy-policy/
- Zoom: https://explore.zoom.us/de/privacy/
- Microsoft Teams: https://www.microsoft.com/en-us/privacy/privacystatement#page-top
How long do we store your personal data?
| Data category | Retention period |
| Participant lists (first name, surname, function) | Deleted immediately after the event has ended |
| Access details for online events (email address, where collected) | Deleted immediately after the event has ended |
| Technical connection data for online events | In accordance with the retention periods of the respective platform providers; INSITE has no influence over these |
| Event planning documents (without personal participant data) | 10 years as part of the contractual documentation |
| Recordings (only with consent) | Until consent is withdrawn or the purpose for use no longer applies |
The early deletion of participant lists after the event has ended is a deliberate application of the principle of data minimisation. INSITE does not retain participants’ personal data for purposes extending beyond the event itself.
What rights do you have?
Access (Article 15 GDPR) You may request access to the personal data we process.
Rectification (Article 16 GDPR) You may request rectification of inaccurate or completion of incomplete data.
Erasure (Article 17 GDPR) Subject to statutory requirements, you may request erasure of your personal data. Please note that participant lists are deleted immediately after the event has ended in any event.
Restriction of processing (Article 18 GDPR) Under certain conditions, you may request restriction of processing.
Data portability (Article 20 GDPR) Where the requirements are met, you may receive your data in a machine-readable format.
Right to object (Article 21 GDPR) Where we process personal data on the basis of legitimate interests, you may object on grounds relating to your particular situation.
Withdrawal of consent Where processing – in particular event recording – is based on your consent, you may withdraw it at any time with effect for the future. Please contact datenschutz@insite.de.
Right to lodge a complaint with a data protection supervisory authority (Article 77 GDPR) You have the right to lodge a complaint with the competent data protection supervisory authority.
Hessian Commissioner for Data Protection and Freedom of Information, PO Box 3163, 65021 Wiesbaden - https://datenschutz.hessen.de/.
You may also contact the supervisory authority at your place of residence or work.
Are you obliged to provide your personal data?
To participate in an event organised by INSITE-Interventions GmbH, you must provide your name and function, as this information is needed to create the participant list and for the trainer to prepare the event. Without this information, registration and participation are not possible. For online events, a valid email address is also required where access to the platform is provided via a personalised invitation link. Processing these minimum details is essential for delivering the seminar service. We do not collect any data beyond this.
Does automated decision-making or profiling take place?
No solely automated decision-making, including profiling within the meaning of Article 22 GDPR, takes place.
Up-to-dateness of this data protection notice
This data protection notice reflects the current state of the processing of personal data. We reserve the right to adapt this notice in the event of changes to the systems used, processing operations or the legal situation. The current version is made available on our website.
What is this privacy notice about?
INSITE-Interventions GmbH operates an electronic whistleblowing system on behalf of client companies. The system enables reports of suspected breaches of statutory provisions, internal rules or ethical principles to be submitted confidentially and, if desired, anonymously.
Under Articles 13 and 14 of the General Data Protection Regulation (GDPR), this privacy notice explains how we process personal data in connection with the operation of the whistleblowing system.
This notice is intended for:
- people who submit a report (reporting persons);
- people who are named in a report; and
- designated reporting office staff and contacts at client companies who are involved in handling reports.
Where your data are not collected directly from you - particularly where you are named in a report without submitting one yourself - the provisions of Article 14 GDPR also apply. Please also read the separate section below.
Who is responsible for processing your data?
The controller within the meaning of the GDPR is:
INSITE-Interventions GmbH
Clemensstraße 10-12
60487 Frankfurt am Main
Telephone: +49 69 90555 29-0
Email: office@insite.de
The controller determines the purposes and means of processing personal data.
How can you contact our Data Protection Officer?
If you have any questions about data protection or the processing of your personal data, you may contact our Data Protection Officer at any time:
Deborah Schütt
Clemensstraße 10-12
60487 Frankfurt am Main
Telephone: +49 69 90555 29-0
Email: dsb@insite.de
You may contact our Data Protection Officer in confidence at any time, for example if you have questions about your rights or wish to raise a data protection concern.
Key features of the whistleblowing system
Confidentiality
The identity of reporting persons is treated as strictly confidential. We will not disclose your identity to the client company or to third parties without your express consent, unless we are legally required to do so or disclosure is essential to prevent serious and imminent harm.
Option to report anonymously
The whistleblowing system allows reports to be submitted anonymously. If you report anonymously, no personal data identifying you will be collected. Please note that an anonymous report may limit our ability to ask follow-up questions and may therefore restrict our ability to handle the report.
Protection against retaliation
Reporting persons who submit reports in good faith are legally protected against work-related or personal detriment under the German Whistleblower Protection Act (Hinweisgeberschutzgesetz - HinSchG).
What personal data do we process?
The personal data processed through the whistleblowing system depend on the content of the individual report. Depending on the circumstances, the following data may be involved.
Data relating to reporting persons (unless the report is anonymous)
- First name and surname
- Position or role within the company
- Contact details (e.g. email address and telephone number)
- Any other information you provide voluntarily in your report
Data relating to persons named in a report
- First name and surname
- Position or role within the company
- Any information provided in connection with the circumstances described
Special categories of personal data
A report may also include special categories of personal data within the meaning of Article 9 GDPR. This may include, in particular:
- data revealing racial or ethnic origin
- political opinions
- religious or philosophical beliefs
- trade union membership
- health data
- data concerning a person's sex life or sexual orientation
Such data are processed only to the extent necessary to handle the report. Sensitive data that are not relevant to the decision will be deleted without delay.
Technical log data
Technical metadata may be generated when the system is used, for example the time at which a report is submitted and system log data. Where technically possible, these data are generated without being linked to an individual.
For what purposes and on what legal basis do we process your data?
Receiving and handling reports
We process personal data in order to receive, document, assess the plausibility of and properly handle incoming reports. This also includes communicating with the reporting person, unless the report was submitted anonymously.
Legal bases:
- Article 6(1)(b) GDPR (performance of a contract in connection with the provision of services to the client company)
- Article 6(1)(c) GDPR in conjunction with section 12 HinSchG (compliance with the legal obligation to establish and operate a reporting office)
- Article 9(2)(a) GDPR for special categories of personal data, where these are provided voluntarily by the reporting person
Disclosure to the client company and investigation
Where a report requires further investigation, the information needed to handle it will be disclosed to the responsible departments of the client company or to appointed external bodies. As a rule, the identity of the reporting person will not be disclosed.
Legal bases:
- Article 6(1)(c) GDPR in conjunction with the HinSchG
- Article 6(1)(f) GDPR; our legitimate interest is in properly investigating breaches of rules and protecting the client company and third parties from harm.
Compliance with statutory documentation and retention obligations
The HinSchG requires us to document incoming reports and retain them for a statutory minimum period.
Legal basis:
- Article 6(1)(c) GDPR in conjunction with section 11 HinSchG
Who receives your personal data?
Within INSITE-Interventions GmbH, only designated reporting office staff have access to the content of incoming reports. Access is strictly limited to those individuals who need it to handle the case.
Depending on the individual case, external recipients may include:
LegalInnovate Technologies GmbH, An der Niers 6, 47608 Geldern - as the technical operator of the DPMS (Data Protection Management System) whistleblowing software; a data processing agreement under Article 28 GDPR is in place.
Tresorit - as an encrypted cloud storage service for the secure storage of case-related documents; a data processing agreement under Article 28 GDPR is in place.
Responsible departments of the client company - where this is necessary to handle the report and the confidentiality of the reporting person can be maintained.
External legal advisers - where legal advice or representation is required in connection with the reported matter.
Investigative and law enforcement authorities - where there is a statutory reporting obligation or where disclosure is necessary to avert an immediate and substantial danger.
Personal data are not disclosed to any other third parties.
Are personal data transferred to third countries?
No transfer of personal data to countries outside the European Union (EU) or the European Economic Area (EEA) is generally envisaged in connection with the whistleblowing system. The service providers used process data exclusively within the EU.
How long do we retain your personal data?
Reports and related personal data are generally retained for three years after the procedure has concluded. This corresponds to the statutory minimum retention period under section 11(5) HinSchG.
Where a case is the subject of legal proceedings or statutory retention obligations require longer storage, the retention period may be extended to up to ten years.
At the end of the applicable retention period, the data will be deleted or fully anonymised.
Special notice for persons named in a report (Article 14 GDPR)
If you are named in an incoming report without having submitted a report yourself, your personal data are not collected directly from you but from the reporting person. In that case, we will inform you about the processing of your data in accordance with Article 14 GDPR.
Restriction of the duty to provide information
Under section 29 of the German Federal Data Protection Act (Bundesdatenschutzgesetz - BDSG), in conjunction with Article 14(5)(b) GDPR and the provisions of the HinSchG, information about the processing of your data may be restricted or temporarily deferred where providing information at an early stage would jeopardise the investigation or impair the confidentiality and protection of the reporting person.
As soon as this is possible without jeopardising the purpose of the investigation or the protection of the reporting person, you will be informed about the processing of your data.
What rights do you have?
The GDPR gives you a number of rights in relation to the processing of your personal data.
Right of access (Article 15 GDPR)
You may request confirmation as to whether we process personal data concerning you and, if so, which data are processed, for what purposes, for how long and to whom they may have been disclosed.
Rectification (Article 16 GDPR)
You have the right to request the correction of inaccurate data or the completion of incomplete data.
Erasure (Article 17 GDPR)
Subject to the statutory requirements, you may request the erasure of your personal data, particularly where the data are no longer needed for the original purpose or the processing is unlawful. Statutory retention obligations remain unaffected.
Restriction of processing (Article 18 GDPR)
In certain circumstances, you may request that the processing of your data be restricted.
Data portability (Article 20 GDPR)
Where processing is based on your consent and is carried out by automated means, you may request to receive your data in a structured, commonly used and machine-readable format.
Right to object (Article 21 GDPR)
Where we process your data on the basis of our legitimate interests under Article 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation. We will then stop the processing unless there are compelling legitimate grounds for continuing it.
Withdrawal of consent
Where processing is based on your consent, you may withdraw that consent at any time with effect for the future. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
Restrictions in the context of the whistleblowing system
During ongoing procedures, certain rights - in particular the right of access - may be temporarily restricted under section 29 BDSG if exercising them would jeopardise the investigation of the reported matter or impair the confidentiality of the reporting person. In that case, we will inform you of the reasons for the restriction insofar as this is possible without jeopardising the purpose of the procedure. Once the procedure has concluded, all your rights will be available without restriction.
Right to lodge a complaint
If you believe that the processing of your personal data breaches data protection law, you have the right to lodge a complaint with the competent data protection supervisory authority.
The supervisory authority responsible for INSITE-Interventions GmbH is:
Hessian Commissioner for Data Protection and Freedom of Information (HBDI)
PO Box 3163
65021 Wiesbaden
Telephone: +49 611 1408-0
Email: poststelle@datenschutz.hessen.de
Website: https://datenschutz.hessen.de
You may also contact the data protection supervisory authority for your place of residence or work.
Are you required to provide your personal data?
Use of the whistleblowing system is voluntary. You are not required to submit a report.
The system allows reports to be submitted anonymously. If you choose to report anonymously, you do not need to provide any personal data identifying you.
If you submit a report in your own name, providing your contact details is voluntary, but it enables us to ask follow-up questions in order to clarify the circumstances. Without a substantive description of the reported matter, we cannot handle the report properly.
Do we use automated decision-making or profiling?
No solely automated decision-making, including profiling within the meaning of Article 22 GDPR, takes place in connection with the whistleblowing system. All incoming reports are reviewed and handled manually by the designated reporting office staff.
Status of this privacy notice
This privacy notice reflects the current state of the processing of personal data through the whistleblowing system operated by INSITE-Interventions GmbH.
Changes to legal requirements, the systems used or internal processes may require this notice to be amended. The current version is available on our website at www.insite.de/datenschutz.
What is this data protection notice about?
INSITE-Interventions GmbH uses digital communication tools to conduct audio and video conferences. With this data protection notice, we inform you, in accordance with Article 13 of the General Data Protection Regulation (GDPR), which personal data are processed in connection with the use of these tools, for what purposes, on what legal basis the processing takes place and what rights you have as a data subject. This notice applies to all persons who participate in audio or video conferences with INSITE – regardless of whether these are counselling sessions, seminars, webinars, customer meetings or other discussions.
Who is responsible for processing your data?
The controller within the meaning of the GDPR is:
INSITE-Interventions GmbH
Clemensstraße 10–12
60487 Frankfurt am Main
Telephone: +49 69 90555 29-0
Email: office@insite.de
How can you reach our Data Protection Officer?
If you have questions about data protection or the processing of your personal data, you can contact our Data Protection Officer at any time:
Deborah Schütt
Clemensstraße 10–12
60487 Frankfurt am Main
Telephone: +49 69 90555 29-0
Email: dsb@insite.de
Which tools do we use?
We use the following services for audio and video conferences:
- Zoom – Zoom Video Communications, Inc., 55 Almaden Boulevard, 6th Floor, San Jose, CA 95113, USA
- Microsoft Teams – Microsoft Ireland Operations Ltd., One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland
Please note that we do not have complete control over the data processing activities of the tool providers. For details of data processing by the respective providers, please refer to their privacy notices:
- Zoom: https://www.zoom.com/en/trust/privacy/privacy-statement/
- Microsoft Teams: https://www.microsoft.com/en-us/privacy/privacystatement
Which personal data are processed?
Data you provide to us
When participating in an audio or video conference, the following data are processed in particular:
Your name and, where provided, your email address and telephone number; image and audio recordings during the conference, if you activate your camera and microphone; chat contributions and messages you submit during the conference; screen content, if you share your screen; and uploaded files or presentations.
Technical connection data and metadata
Regardless of your active inputs, the tools used process technical data required to operate the connection. This includes, in particular, your IP address, device type and operating system, client version used, date, time and duration of participation, meeting ID and type of connection and, where you dial in by telephone, your telephone number.
Special categories of personal data
In counselling sessions, special categories of personal data under Article 9 GDPR may be processed depending on the content of the conversation, in particular health data. This only occurs where you provide such data yourself and the statutory requirements are met.
For what purposes and on what legal basis do we process your data?
Conducting counselling sessions with clients
Where audio or video conferences are used to conduct counselling sessions as part of our EAP service, processing is based on your consent and on providing the agreed service.
Legal bases: Article 6(1)(a) GDPR and Article 9(2)(h) GDPR.
Communication with customers and business partners
For discussions with customer companies, prospective customers and other business contacts, audio and video conferences serve to carry out contractual or pre-contractual measures and for general business communication.
Legal bases: Article 6(1)(b) GDPR and Article 6(1)(f) GDPR. Our legitimate interest lies in efficient, modern communication with our business contacts and the provision of digital communication channels.
Conducting seminars and webinars
When audio and video conference tools are used for training courses, seminars and webinars, processing serves to fulfil the booked scope of services.
Legal basis: Article 6(1)(b) GDPR.
Recordings
Conferences are generally not recorded. If a recording is to be made in exceptional cases, you will be informed in advance and asked for your explicit consent. No recording will be made without your knowledge.
Legal basis where a recording is made: Article 6(1)(a) GDPR.
Who receives your personal data?
Within INSITE-Interventions GmbH, only those persons have access to conference-related data who need it to provide the relevant service. The tool providers Zoom and Microsoft act as processors pursuant to Article 28 GDPR. We have data processing agreements with both providers ensuring that your data are processed solely on our instructions and in compliance with the GDPR. Your data are not disclosed to other third parties unless we are legally obliged to do so or you have expressly consented.
Are personal data transferred to third countries?
Both Zoom and Microsoft are headquartered in the United States. In connection with using these tools, personal data may be transferred to the United States. The transfer is based on the European Commission’s adequacy decision for the EU–US Data Privacy Framework pursuant to Article 45 GDPR. Both providers are certified under the EU–US Data Privacy Framework, ensuring a level of data protection comparable to that in the EU. If you would like further information about the safeguards used, you may contact our Data Protection Officer at any time.
How long do we store your data?
Connection data and metadata are deleted once the purpose of processing no longer applies, generally after the conference has ended. We have no influence over the storage periods for data that the tool providers store for their own purposes. Where content from conferences – such as chat histories or shared documents – is required to document the relevant matter (e.g. a counselling session or seminar), the retention periods for the relevant processing activity apply. For client counselling, the retention period is ten years for professional-law reasons (Section 630f of the German Civil Code (BGB)).
Where a conference is recorded on the basis of your consent, the recordings are deleted once the purpose for use no longer applies or when you withdraw your consent.
What rights do you have?
Access You may request information about whether and which personal data we process about you, as well as information about the purposes of processing, recipients, storage periods and your further rights.
Rectification You may request rectification of inaccurate or completion of incomplete data.
Erasure Subject to statutory requirements, you may request erasure of your personal data, for example where the data are no longer required for the original purpose or you withdraw your consent. Statutory retention obligations remain unaffected.
Restriction of processing Under certain conditions, you may request that your data only be processed to a limited extent.
Data portability Where processing is based on consent or a contract and carried out by automated means, you may request to receive your data in a structured, commonly used and machine-readable format.
Right to object Where we process your data on the basis of our legitimate interest pursuant to Article 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation.
Withdrawal of consent Where processing is based on your consent, you may withdraw it at any time with effect for the future. The lawfulness of processing carried out before withdrawal remains unaffected.
Right to lodge a complaint with a supervisory authority You have the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of your personal data infringes the GDPR. The supervisory authority responsible for us is:
Hessian Commissioner for Data Protection and Freedom of Information (HBDI), Gustav-Stresemann-Ring 1, 65189 Wiesbaden - https://datenschutz.hessen.de/
You may also contact the supervisory authority at your place of residence or habitual abode.
Are you obliged to provide your data?
To participate in an audio or video conference, certain data must be provided for technical reasons, in particular a displayed name and technical connection data. Without these data, participation in the conference is not possible. Activating your camera and microphone and using the chat function are at your discretion. You are generally not obliged to do so unless this follows from the particular service context.
Does automated decision-making or profiling take place?
No solely automated decision-making, including profiling within the meaning of Article 22 GDPR, takes place when using our conference tools.
Up-to-dateness of this data protection notice
This data protection notice reflects the current state of the processing of personal data in connection with audio and video conferences at INSITE. We will update this notice accordingly in the event of material changes.
What is this privacy notice about?
At events, presentations, training sessions and other corporate communications activities, INSITE-Interventions GmbH occasionally takes photographs and makes audio and video recordings. These photographs and recordings may subsequently be published on our website, on our social media channels or in other communications materials.
This privacy notice applies to anyone who is photographed, filmed or recorded on such occasions, regardless of whether you are present as a customer contact, speaker, guest, participant or in another capacity. The relevant group-specific privacy notices also apply to employees and freelance contractors of INSITE-Interventions GmbH.
Under Article 13 of the General Data Protection Regulation (GDPR), this privacy notice explains which personal data we process, the purposes and legal basis of the processing, who receives your data, how long we retain them and what rights you have.
As photographs and recordings are made in your presence and on the basis of your consent, Article 13 GDPR applies.
Who is responsible for processing your data?
The controller within the meaning of the General Data Protection Regulation is:
INSITE-Interventions GmbH
Clemensstraße 10-12
60487 Frankfurt am Main
Telephone: +49 69 90555 29-0
Email: office@insite.de
How can you contact our Data Protection Officer?
If you have any questions about data protection or the processing of your personal data, you may contact our Data Protection Officer at any time:
Deborah Schütt
Clemensstraße 10-12
60487 Frankfurt am Main
Telephone: +49 69 90555 29-0
Email: dsb@insite.de
You may contact our Data Protection Officer in confidence at any time, for example if you have questions about your rights or wish to raise a data protection concern.
What personal data do we process?
When photographs and recordings are taken and published, we process the following categories of personal data.
Photographic, audio and video material Photographs, video footage and audio recordings in which you can be seen or heard.
Name and role details Where intended for publication, we may add your name and your role or professional capacity to the photographs or recordings, for example if you are a speaker or customer contact.
Business contact details Where intended for publication, business contact details may also be included.
For what purposes and on what legal basis do we process your data?
Taking and publishing photographs and recordings
We take photographs and make audio and video recordings at events, speaker presentations, training sessions and similar occasions in order to report on our activities and support our corporate communications. They may be published in particular on our website, on our social media channels or in other communications materials.
Legal basis: Article 6(1)(a) GDPR. We take and publish photographs and recordings in which you are identifiable solely on the basis of your prior consent. Without your consent, you will not appear in any photographs or recordings that we publish.
Who receives your personal data?
Within INSITE-Interventions GmbH, the Marketing team and, where employees are concerned, Human Resources have access to the photographs and recordings. The need-to-know principle applies.
For storage and publication, we use the following external service providers:
Tresorit is used as encrypted cloud storage for photographic and video material.
Personio is also used to manage employee photographs in the HR management system, where employees are concerned.
Social media platforms Where you have consented to publication, photographs and recordings may be published on our company profiles on Meta platforms (e.g. Instagram), LinkedIn and YouTube. Further information about how these platforms process personal data is available in our separate privacy notices for the relevant company profiles.
All processors we use are contractually required to comply with data protection requirements and are reviewed regularly.
Are personal data transferred to third countries?
Before any publication, your photographs and recordings are stored within the European Union. Where you have consented to publication on social media platforms, the operation of those platforms may involve transfers to the United States.
| Platform | Operator | Data transferred | Legal basis for transfer |
|---|---|---|---|
| Meta Platforms Ireland Ltd. / Meta Platforms, Inc. (USA) | Published photographs and video recordings | EU-U.S. Data Privacy Framework | |
| LinkedIn Ireland / LinkedIn Corporation (USA) | Published photographs and video recordings | EU-U.S. Data Privacy Framework | |
| YouTube | Google Ireland Limited / Google LLC (USA) | Published video and audio recordings | EU-U.S. Data Privacy Framework |
For further information about the safeguards used, please contact our Data Protection Officer at any time.
How long do we retain your data?
The retention period for photographs and recordings in which you are identifiable depends on your consent remaining in force.
| Data category | Standard retention period |
|---|---|
| Unpublished photographs and recordings (raw material) | Until a decision is made on publication; deleted afterwards if not published |
| Published photographs and recordings | Until you withdraw your consent or the purpose of publication no longer applies |
| Photographs and recordings on social media platforms | Until you withdraw your consent or we delete them; the deletion practices of the relevant platform may differ |
After you withdraw your consent, we will remove the relevant photographs and recordings from our own channels without undue delay. Please note that any onward dissemination by third parties that has already taken place, for example through sharing on social networks, may be beyond our control.
What rights do you have?
The GDPR gives you various rights in relation to the processing of your personal data.
Right of access (Article 15 GDPR) You may ask whether we process personal data concerning you and, if so, which data, together with information about the purposes of processing, recipients, retention period and your other rights.
Rectification (Article 16 GDPR) If personal data are inaccurate or incomplete, you may ask us to correct or complete them.
Erasure (Article 17 GDPR) Subject to the statutory requirements, you have the right to request the erasure of your personal data, particularly after withdrawing your consent.
Restriction of processing (Article 18 GDPR) In certain circumstances, you may request that the processing of your personal data be restricted.
Data portability (Article 20 GDPR) As the processing is based on your consent, you may receive your data in a structured, commonly used and machine-readable format or request that they be transmitted to another controller, where technically feasible.
Withdrawal of consent You may withdraw your consent to the taking and publication of photographs and recordings at any time with effect for the future. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal. To do so, please contact datenschutz@insite.de.
Right to lodge a complaint with a supervisory authority (Article 77 GDPR) You have the right to lodge a complaint with the competent data protection supervisory authority if you believe that our processing of your personal data infringes the GDPR. The supervisory authority responsible for INSITE-Interventions GmbH is:
Hessian Commissioner for Data Protection and Freedom of Information, PO Box 3163, 65021 Wiesbaden - https://datenschutz.hessen.de/
You may also contact the supervisory authority for your place of residence or business.
Are you required to provide your data?
It is entirely voluntary whether photographs are taken or audio and video recordings are made in which you are identifiable, and we require your consent. If you do not wish to be photographed, filmed or recorded, please tell the INSITE staff present before recording begins. Refusing or subsequently withdrawing your consent will not result in any disadvantage to you.
Do we use automated decision-making or profiling?
No automated decision-making, including profiling within the meaning of Article 22 GDPR, takes place as part of this processing activity.
Recommended communication channel
If you have questions about a particular photograph or recording, wish to withdraw consent or request deletion, please contact our data protection team at datenschutz@insite.de. For photographs or recordings made at a particular event, you may also speak directly to the INSITE staff present at the venue.
Status of this privacy notice
This privacy notice reflects the current state of personal data processing in connection with photographs and audio and video recordings at INSITE-Interventions GmbH. If changes are made, we will update this notice and publish the new version.
What is this privacy notice about?
INSITE-Interventions GmbH operates a company profile on the Instagram platform. Under Articles 13 and 14 of the General Data Protection Regulation (GDPR), this privacy notice explains which personal data are processed in connection with visits to our profile and interactions with our content.
This privacy notice applies to you if you
- visit our Instagram company profile,
- like, comment on, share or save our posts, Reels or Stories,
- send us a direct message,
- respond to our advertisements or are shown content from us, or
- appear in photographs or videos published by us.
Where your data are not obtained directly from you - particularly when photographs or videos are published - the information is provided under Article 14 GDPR.
This notice supplements the privacy notices issued by Instagram and Meta. Meta is solely responsible for its own processing of personal data, particularly for profiling, targeting and operating the platform.
Who is responsible for processing your data?
Joint controllership under Article 26 GDPR
For certain processing operations connected with the operation of our Instagram company profile, INSITE-Interventions GmbH and Meta Platforms Ireland Limited are joint controllers within the meaning of Article 26 GDPR. This applies in particular to the processing of visit and interaction data where Meta uses them to provide us with aggregated usage statistics (known as Insights). This arrangement is based on the case law of the Court of Justice of the European Union concerning the joint controllership of fan-page operators and platform providers.
INSITE-Interventions GmbH
Clemensstraße 10-12
60487 Frankfurt am Main
Telephone: +49 69 90555 29-0
Email: office@insite.de
Meta Platforms Ireland Limited Merrion Road, Dublin 2, Ireland
- Information about the Instagram and Meta privacy policy is available at: https://privacycenter.instagram.com/policy
- For data protection enquiries addressed to Meta, please use: https://privacycenter.instagram.com/
How can you contact our Data Protection Officer?
If you have any questions about data protection or the processing of your personal data, you may contact our Data Protection Officer at any time:
Deborah Schütt
Clemensstraße 10-12
60487 Frankfurt am Main
Telephone: +49 69 90555 29-0
Email: dsb@insite.de
What personal data do we process?
Visits to the profile and Instagram Insights
When you visit our Instagram profile, Meta collects data about your visit. We receive only aggregated statistics that do not identify individual users. Meta compiles these statistics using the following data:
Profile information (age group, gender, location and language), interaction data (profile visits, post reach, Story views and clicks), as well as device information and IP addresses.
Interactions with posts, Reels and Stories
If you like, comment on or share our content, or react to Stories, these actions are visible to us to the extent permitted by your privacy settings. We process information that you have made publicly available on Instagram, in particular your username and profile picture, as well as the content of your comments or reactions.
Direct messages
If you contact us using Instagram direct messages, we process your username and profile information, the content of your message and the time at which you contacted us.
Meta Ads
We place audience-targeted advertisements on Instagram through Meta Ads Manager. We define audience criteria without ourselves processing users' personal data. In its capacity as an independent controller, Meta uses the profile data provided by platform users to deliver advertisements.
Photographs and videos featuring you (Article 14 GDPR)
Where we publish photographs or videos on our Instagram profile in which you appear and the material was not obtained directly from you, we provide you with information under Article 14 GDPR. The material typically comes from events, speaker presentations, professional conferences or collaborative activities.
We process, in particular, images of you and, where available, your name, professional role and information about the context in which the image or recording was made.
For what purposes and on what legal basis do we process your data?
Operation of the profile and corporate communications We operate our Instagram profile to present our company to a broad public audience and engage with interested parties. Legal basis: Article 6(1)(f) GDPR. Our legitimate interest lies in maintaining our corporate communications and attracting new customers.
Analysis of usage statistics (Instagram Insights) We use aggregated statistics to analyse and optimise our content. Legal basis: Article 6(1)(f) GDPR. Our legitimate interest lies in improving our corporate communications.
Responding to direct messages We process incoming messages solely to deal with your enquiry. Legal basis: Article 6(1)(f) GDPR. Our legitimate interest lies in maintaining contacts and responding to incoming enquiries.
Advertising We use Meta Ads on the basis of our legitimate interests. Where this involves tracking through our website (Meta Pixel), tracking takes place only on the basis of the consent you give via our website's cookie banner. Legal basis: Article 6(1)(f) GDPR or Article 6(1)(a) GDPR, as applicable.
Publication of photographs and videos Publication is generally based on your prior consent. Where obtaining consent was not possible or reasonable in an individual case, we rely on our legitimate interest in documenting our corporate activities. Legal basis: Article 6(1)(a) GDPR or Article 6(1)(f) GDPR, as applicable. You may withdraw your consent at any time by emailing datenschutz@insite.de.
Who receives your personal data?
Within INSITE-Interventions GmbH, access to interaction data from our Instagram profile is restricted to staff in Marketing and Client Consulting. Meta Platforms Ireland Limited processes personal data as the platform operator, as a joint controller and as an independent controller for its own purposes.
Are data transferred to third countries?
Meta Platforms Ireland Limited is based in Ireland. As part of the Meta group, personal data may be transferred to the United States. Transfers are made on the basis of the European Commission's adequacy decision for the EU-US Data Privacy Framework and the Standard Contractual Clauses (Controller Addendum) under Article 46 GDPR.
Further information is available in Instagram's privacy notice: https://privacycenter.instagram.com/policy
How long are your data retained?
| Data category | Retention period |
|---|---|
| Direct messages | Until the enquiry has been resolved; thereafter in accordance with statutory retention obligations, where applicable |
| Comments and interactions | For as long as the relevant post remains published |
| Photographs and videos (consent-based) | Until consent is withdrawn or the purpose no longer applies |
| Instagram Insights (aggregated) | For as long as made available by Meta |
We have no influence over how long Meta retains data for its own purposes.
What rights do you have?
You have the following rights in relation to INSITE-Interventions GmbH:
Right of access: You may ask whether we process personal data concerning you and, if so, which data, as well as information about the purposes, recipients, retention period and your other rights.
Rectification: You may request the correction of inaccurate personal data or the completion of incomplete personal data.
Erasure: Subject to statutory requirements, you may request the erasure of your personal data, for example where the data are no longer required for the original purpose or you withdraw your consent.
Restriction of processing: In certain circumstances, you may request that the processing of your personal data be restricted.
Data portability: Where processing is based on consent and carried out by automated means, you may request to receive your personal data in a structured, commonly used and machine-readable format.
Right to object: Where we process data on the basis of legitimate interests under Article 6(1)(f) GDPR, you may object to that processing at any time on grounds relating to your particular situation.
Withdrawal of consent: As the processing of your data in connection with arranging appointments is based on your consent, you may withdraw it at any time with effect for the future. To do so, please contact our Data Protection Officer (contact details above) or datenschutz@insite.de. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal. Please note that withdrawing consent after an appointment has been booked may result in the appointment being cancelled.
Right to lodge a complaint: If you believe that the processing of your personal data infringes data protection law, you have the right to lodge a complaint with a data protection supervisory authority. The supervisory authority responsible for INSITE-Interventions GmbH is the Hessian Commissioner for Data Protection and Freedom of Information (HBDI): https://datenschutz.hessen.de/. You may also contact the supervisory authority for your place of residence or habitual residence.
Status of this privacy notice
This privacy notice reflects the current state of personal data processing. We reserve the right to amend it if the systems used, processing activities or legal requirements change. The current version will be made available on our website.
What is this data protection notice about?
INSITE-Interventions GmbH operates a company page on the LinkedIn platform. With this data protection notice, we inform you, in accordance with Articles 13 and 14 of the General Data Protection Regulation (GDPR), which personal data are processed in connection with visiting our page and interacting with our content.
This data protection notice applies to you if you:
- visit our LinkedIn company page,
- like, comment on, share or save our posts,
- send us a message (InMail or direct message),
- react to our adverts or are shown content from us, or
- appear in photos or videos published by us.
Where your data are not collected directly from you – in particular when photos and videos are published – the information is provided pursuant to Article 14 GDPR. This notice applies in addition to LinkedIn’s own data protection information. For LinkedIn’s independent processing of data – in particular for profiling, targeting and operating the platform – LinkedIn alone is responsible.
Who is responsible for processing your data?
Joint controllership under Article 26 GDPR
For certain processing operations in connection with operating our LinkedIn company page, INSITE-Interventions GmbH and LinkedIn are jointly responsible within the meaning of Article 26 GDPR. This applies in particular to the processing of visitor and interaction data insofar as LinkedIn provides us with aggregated usage statistics (so-called Page Insights).
LinkedIn Ireland Unlimited Company
Wilton Place
Dublin 2
Ireland
INSITE-Interventions GmbH
Clemensstraße 10–12
60487 Frankfurt am Main
Telephone: +49 69 90555 29-0
Email: office@insite.de
Information on the arrangement on joint controllership between LinkedIn and page operators can be found at: https://www.linkedin.com/legal/l/page-joint-controller-addendum
To exercise your rights against LinkedIn, please use: https://www.linkedin.com/help/linkedin/ask/PPQ
How can you reach our Data Protection Officer?
If you have questions about data processing by INSITE-Interventions GmbH, you can contact:
Deborah Schütt
Clemensstraße 10–12
60487 Frankfurt am Main
Telephone: +49 69 90555 29-0
Email: dsb@insite.de
Which personal data do we process?
Visits to the page and Page Insights
When you visit our LinkedIn page, LinkedIn collects technical and profile-related data about your visit. We only receive aggregated, non-personal statistics. These are compiled by LinkedIn on the basis of the following data: profile information (industry, job function, company size, seniority, location), interaction data (page views, clicks, dwell time) as well as device information and IP addresses.
Interactions with our posts
If you like, comment on, share or save our posts, these actions are visible to us and other LinkedIn users insofar as your privacy settings allow this. In doing so, we process the information you have made publicly available on LinkedIn, in particular your name and profile picture, job title and employer, as well as the content of your comments or reactions.
Direct messages
If you contact us via LinkedIn’s messaging system, we process your name and profile information, the content of your message and the time of contact.
LinkedIn Ads and the LinkedIn Insight Tag
We use LinkedIn Campaign Manager for interest-based advertising and the LinkedIn Insight Tag on our company website. Via the Insight Tag, visit data from our website can be linked to LinkedIn profile data, provided you are logged in to your LinkedIn account. INSITE only receives aggregated analyses, not individual personal data.
Photos and videos featuring you (Article 14 GDPR)
Where we publish photos or videos on our LinkedIn page in which you are visible and these recordings were not collected directly from you, we inform you pursuant to Article 14 GDPR. The recordings typically originate from events, speaker presentations, specialist conferences or cooperation activities.
In this context, we collect in particular image recordings of you and – where available – your name, your professional role/function and information about the context in which the recording was made.
For what purposes and on what legal basis do we process your data?
Operation of the page and corporate communications
We operate our LinkedIn page to increase awareness of our company, provide information about our services, and get in touch with interested parties and customers.
Legal basis: Article 6(1)(f) GDPR. Our legitimate interest lies in maintaining our corporate communications, acquiring new customers and strengthening our employer brand.
Analysis of usage statistics (Page Insights)
We use aggregated statistics to understand how our page is used and to improve our communications.
Legal basis: Article 6(1)(f) GDPR. Our legitimate interest lies in analysing and optimising our content.
Responding to direct messages
We process incoming messages solely to handle your enquiry.
Legal basis: Article 6(1)(f) GDPR. Our legitimate interest lies in maintaining business contacts and responding to incoming enquiries.
Advertising and Insight Tag
The integration of the LinkedIn Insight Tag on our website is carried out solely on the basis of your consent via our website’s cookie banner.
Legal basis: Article 6(1)(a) GDPR. You can withdraw your consent at any time via the cookie settings.
Publication of photos and videos
As a rule, we publish photos and videos in which you are visible on the basis of your prior consent. Where obtaining consent was not possible or reasonable in the specific individual case, we base the publication on our legitimate interest in documenting our corporate activities.
Legal basis: Article 6(1)(a) GDPR and/or Article 6(1)(f) GDPR. You can withdraw your consent at any time with effect for the future. Please contact datenschutz@insite.de.
Further information
Further information can be found in LinkedIn’s privacy policy: https://www.linkedin.com/legal/privacy-policy
How long will your data be stored?
| Data category | Retention period |
| Direct messages | Until the enquiry has been dealt with; thereafter in accordance with statutory retention obligations where relevant. |
| Comments and interactions | For as long as the relevant post is published. |
| Photos and videos (consent-based) | Until consent is withdrawn or the purpose for use no longer applies. |
| Page Insights (aggregated) | In line with availability provided by LinkedIn, typically up to 2 years. |
Who receives your personal data?
Within INSITE-Interventions GmbH, only employees from Marketing and Customer Advisory have access to interaction data from our LinkedIn page, insofar as this is necessary for their tasks.
LinkedIn Ireland Unlimited Company processes personal data as the platform operator, as a joint controller and as an independent controller for its own purposes over which we have no influence.
Are data transferred to third countries?
LinkedIn Ireland Unlimited Company is based in Ireland. As part of the Microsoft group, personal data may be transferred to the United States. The transfer takes place on the basis of the European Commission’s adequacy decision for the EU–US Data Privacy Framework and on the basis of Standard Contractual Clauses pursuant to Article 46 GDPR.
What rights do you have?
You have the following rights in relation to INSITE-Interventions GmbH:
Right of access: You may request information on whether and which personal data we process about you, as well as the purposes, recipients, storage periods and your further rights.
Right to rectification: You may request rectification of inaccurate personal data or completion of incomplete personal data.
Right to erasure: Subject to statutory requirements, you may request erasure of your personal data, for example where the data are no longer necessary for the original purpose or you withdraw your consent.
Right to restriction of processing: Under certain conditions, you may request that your personal data only be processed to a limited extent.
Right to data portability: Where processing is based on consent and is carried out by automated means, you may request to receive your personal data in a structured, commonly used and machine-readable format.
Right to object: Where we process data on the basis of a legitimate interest pursuant to Article 6(1)(f) GDPR, you may object to this processing at any time on grounds relating to your particular situation.
Withdrawal of consent: Where processing is based on your consent (e.g. Insight Tag on our website or publication of photos/videos), you may withdraw your consent at any time with effect for the future. Please contact our Data Protection Officer (details above) or datenschutz@insite.de. Withdrawal does not affect the lawfulness of processing carried out up to that point.
Right to lodge a complaint: If you consider that the processing of your personal data infringes data protection law, you have the right to lodge a complaint with a data protection supervisory authority. The supervisory authority responsible for INSITE-Interventions GmbH is the Hessian Commissioner for Data Protection and Freedom of Information (HBDI): https://datenschutz.hessen.de/. You may also contact the supervisory authority at your place of residence or habitual abode.
Up-to-dateness of this data protection notice
This data protection notice reflects the current state of the processing of personal data. We reserve the right to adapt this notice in the event of changes to the systems used, processing operations or the legal situation. The current version is made available on our website.
What is this data protection notice about?
INSITE-Interventions GmbH operates a publicly accessible channel on the YouTube platform, through which we publish informational videos about our counselling services, company topics and events. YouTube is operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, together with Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (jointly referred to below as “Google”). When you visit our YouTube channel, Google processes personal data about your usage behaviour. This data protection notice informs you, in accordance with Article 13 of the General Data Protection Regulation (GDPR), about the processing that takes place in connection with operating our channel and about an important aspect of the relationship between INSITE and Google, which we explain separately for the sake of maximum transparency. Please note that Google, as the platform operator, carries out its own additional processing operations over which we have no influence. Further information can be found in Google’s privacy policy at policies.google.com/privacy.
Who is responsible for processing your data?
The following is responsible for the content and editorial design of our YouTube channel:
INSITE-Interventions GmbH
Clemensstraße 10–12
60487 Frankfurt am Main
Telephone: +49 69 90555 29-0
Email: office@insite.de
For the processing of personal data carried out by the YouTube platform itself when you visit our channel, in particular technical usage data, INSITE and Google Ireland Limited are jointly responsible pursuant to Article 26 GDPR. Further explanations can be found in the section “Joint controllership with Google” below.
How can you reach our Data Protection Officer?
If you have any questions about data protection or the processing of your personal data, you can contact our Data Protection Officer in confidence at any time – for example if you have questions about your rights or would like to provide a data protection tip or report:
Deborah Schütt
Clemensstraße 10–12
60487 Frankfurt am Main
Telephone: +49 69 90555 29-0
Email: dsb@insite.de
Which personal data do we process?
When you visit our YouTube channel, the platform processes the following categories of data in particular:
Technical usage data
IP address, device identifiers, browser type and version, operating system and time of access.
Usage and interaction data
Videos viewed, viewing duration, interactions such as comments, subscriptions and “likes”, and, where applicable, data on usage behaviour collected via cookies or comparable technologies.
Special categories of personal data within the meaning of Article 9 GDPR are not knowingly collected or analysed by us as part of operating the channel. We receive only limited, aggregated statistics from Google about channel usage, such as view counts. We do not have access to individual usage data of individual visitors.
For what purposes and on what legal basis do we process your data?
Operating the YouTube channel for corporate communications
We operate the YouTube channel to provide information about our counselling services, give insights into our company activities and engage with interested persons. Legal basis: Article 6(1)(f) GDPR. Our legitimate interest lies in public relations and communication with customers, interested persons and the general public. Google’s further processing of technical usage data is based on a separate legal basis explained by Google in its privacy policy. We have no influence over this processing.
Joint controllership with Google
INSITE and Google Ireland Limited are jointly responsible within the meaning of Article 26 GDPR for processing carried out by the platform itself when you visit our YouTube channel. Article 26 GDPR provides that, in such cases, the joint controllers must transparently determine in an arrangement who fulfils which data protection obligations and must make the essential content of that arrangement available to data subjects.
We expressly and transparently inform you that Google currently does not provide YouTube channel operators with an arrangement compliant with Article 26 GDPR. We have asked Google in writing to provide such an arrangement; Google has not yet complied with this request. This situation is outside our control.
To enable you to exercise your rights effectively nonetheless, we recommend the following: For questions and concerns relating to technical processing by YouTube itself – for example cookies, individual usage profiles or personalised recommendations – please contact Google directly. Google’s privacy policy is available at https://policies.google.com/privacy and the relevant contact form for data subject enquiries at https://support.google.com/policies/contact/general_privacy_form.
Our Data Protection Officer remains available for questions about our own editorial activities on the channel. As part of our annual review cycle, we check whether Google has since provided an arrangement compliant with Article 26 GDPR. As soon as this is the case, we will promptly include the arrangement in our documentation and provide a link here.
Who receives your personal data?
Within INSITE-Interventions GmbH, the Marketing and Public Relations departments in particular have access to the aggregated statistics provided to us by Google. The technical usage data collected when you visit the channel are processed by Google Ireland Limited and Google LLC as joint controllers to the extent described above.
| Service provider | Purpose | Data transferred / safeguard |
| Google LLC (USA) | Operation of the YouTube platform | Technical usage and interaction data / adequacy decision for the EU–US Data Privacy Framework; supplemented by Standard Contractual Clauses pursuant to Article 46 GDPR |
Further information about the safeguards adopted by Google can be found in Google’s privacy policy.
How long do we store your data?
We use the aggregated statistics we receive from Google for as long as this remains useful for analysing our channel activity. We do not separately store individual usage data because we do not have access to it.
Google decides how long it stores technical usage data processed under its own responsibility. Further information can be found in Google’s privacy policy.
What rights do you have?
Access (Article 15 GDPR)
You may request information about whether and which personal data we process about you, as well as information about the purposes of processing, recipients, storage periods and your further rights.
Rectification (Article 16 GDPR)
If personal data are inaccurate or incomplete, you may request that they be corrected or completed.
Erasure (Article 17 GDPR)
Subject to statutory requirements, you have the right to request erasure of your personal data.
Restriction of processing (Article 18 GDPR)
Under certain conditions, you may request that your personal data only be processed to a limited extent.
Data portability (Article 20 GDPR)
Where processing is based on consent or a contract and is carried out by automated means, you may receive your data in a structured, commonly used and machine-readable format.
Right to object (Article 21 GDPR)
Where we process personal data on the basis of our legitimate interest pursuant to Article 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation.
Right to lodge a complaint with a data protection supervisory authority (Article 77 GDPR)
You have the right to lodge a complaint with the competent data protection supervisory authority if you consider that the processing of your personal data infringes the GDPR. The supervisory authority responsible for INSITE-Interventions GmbH is:
Hessian Commissioner for Data Protection and Freedom of Information · PO Box 3163 · 65021 Wiesbaden · https://datenschutz.hessen.de/
In relation to processing by Google, you may also contact the supervisory authority responsible for Google Ireland Limited, the Irish Data Protection Commission.
Regarding the exercise of your rights vis-à-vis Google: where your concern relates to technical processing by YouTube itself, we recommend contacting Google directly, as we have no influence over this processing and this may enable faster handling. We will be happy to assist you in classifying your enquiry on request.
Are you obliged to provide your data?
Visiting our YouTube channel is voluntary. If you do not want the technical data processing normally associated with operating the channel by YouTube, we recommend that you refrain from visiting the channel or adjust the privacy settings of your YouTube or Google account accordingly.
Does automated decision-making or profiling take place?
Google uses algorithmic processes when operating YouTube, for example to display personalised video recommendations. Whether and to what extent this constitutes profiling within the meaning of Article 4(4) GDPR is determined by Google under its own responsibility; we have no influence over this. We are not aware of any automated decision-making within the meaning of Article 22 GDPR with legal or similarly significant effects in connection with operating our channel.
Up-to-dateness of this data protection notice
This data protection notice reflects the current state of the processing of personal data in connection with our YouTube channel. The notice concerning the absence of an Article 26 arrangement with Google is based on a documented residual-risk assessment that is reviewed annually as part of our data protection management system. If changes occur – in particular as soon as Google provides a compliant arrangement – we will update this notice and publish the new version.
What is this data protection notice about?
INSITE-Interventions GmbH works with a wide range of suppliers and service providers to ensure its business operations. In the course of these business relationships, we process personal data of contact persons working for our suppliers and service providers – for example, contacts in order processing, sales or invoicing. With this notice, we inform you, in accordance with Articles 13 and 14 of the General Data Protection Regulation (GDPR), which personal data we process, for what purposes, on what legal basis, to whom data may be disclosed, how long we store personal data, and what rights you have as a data subject.
Where you provide us with your contact details yourself in the context of the business relationship – for example during contract initiation, on invoices or in ongoing correspondence – we collect your data directly from you (Article 13 GDPR). Where we obtain your contact details instead from your employer or from publicly accessible business documents without you providing them to us, the information is provided pursuant to Article 14 GDPR. In this case, the data originates from business documents and correspondence in the context of the business relationship with your employer.
Who is responsible for processing your data?
The controller within the meaning of the GDPR is:
INSITE-Interventions GmbH
Clemensstraße 10–12
60487 Frankfurt am Main
Telephone: +49 69 90555 29-0
Email: office@insite.de
How can you reach our Data Protection Officer?
If you have any questions about data protection or the processing of your personal data, you can contact our Data Protection Officer at any time:
Deborah Schütt
Clemensstraße 10–12
60487 Frankfurt am Main
Telephone: +49 69 90555 29-0
Email: dsb@insite.de
You may contact our Data Protection Officer in confidence at any time – for example if you have questions about your rights or would like to provide a data protection tip or report.
Which personal data do we process?
In the context of the business relationship with your organisation, we process the following categories of personal data relating to you.
| Category | Examples |
| Contact details | Surname, first name, business address, business telephone number and email address, and, where applicable, private contact details where you provide these to us. |
| Role/function data | Your function or position with your employer, insofar as this is relevant to the business relationship. |
| Contract and invoicing data | Information from contracts, purchase orders, order confirmations and invoices, including bank details, insofar as required in connection with payment processing. |
| Communication data | Content and metadata from business correspondence arising in the course of the cooperation. |
For what purposes and on what legal basis do we process your data?
Pre-contractual measures and contract performance
We process your contact details to initiate the business relationship with your organisation, conclude contracts and coordinate ongoing cooperation. This includes, in particular, communication in the context of quotations, purchase orders and order processing.
Legal basis: Article 6(1)(b) GDPR where you are a party to the contract; otherwise Article 6(1)(f) GDPR. Our legitimate interest is the maintenance and performance of our business relationships with suppliers and service providers.
Incoming invoices and payment processing
We process your contact and invoicing data to process incoming invoices, initiate payments and perform related accounting procedures.
Legal basis: Article 6(1)(b) GDPR for contract performance; Article 6(1)(c) GDPR for compliance with commercial and tax-law retention and documentation obligations.
Financial accounting and controlling
Your data is recorded as part of financial accounting in order to document expenditure and ensure the company’s economic management.
Legal basis: Article 6(1)(c) GDPR in conjunction with Section 257 of the German Commercial Code (Handelsgesetzbuch, HGB) and Section 147 of the German Fiscal Code (Abgabenordnung, AO).
Who receives your personal data?
Within INSITE-Interventions GmbH, only those persons have access to your personal data who need it to perform their respective tasks. The need-to-know principle applies. Internal recipients may include Finance, Management, Office Management and the responsible team or department lead.
We also use external service providers who process personal data on our behalf (processors pursuant to Article 28 GDPR) or who receive data in the context of their own independent legal obligations. This includes in particular:
- Asklepios Business Service GmbH (support for financial accounting)
- Lexware (accounting and invoicing software)
- Our tax adviser (tax advice and processing via DATEV)
All processors are carefully selected, contractually bound and regularly reviewed for compliance with data protection requirements.
We only disclose your personal data to authorities or other public bodies where we are legally obliged to do so.
Are personal data transferred to third countries?
No personal data are transferred to countries outside the European Union or the European Economic Area as part of this processing activity. All involved service providers process your data within the EU.
How long do we store your personal data?
We store your personal data only for as long as necessary for the respective purposes or for as long as statutory retention obligations apply.
| Data / document type | Regular retention period |
| Contact details in the context of ongoing business relationships | For the duration of the business relationship |
| Contract, order and invoice documentation | 10 years (Section 147 AO, Section 257 HGB) |
| Accounting and payment data | 10 years (Section 147 AO, Section 257 HGB) |
| General correspondence without tax relevance | Typically up to 3 years after the end of the business relationship |
In individual cases, longer retention periods may apply where statutory obligations or pending legal disputes require this.
What rights do you have?
The GDPR grants you various rights in relation to the processing of your personal data:
Access (Article 15 GDPR)
You may request information on whether and which personal data we process about you, as well as information about the purposes of processing, recipients, storage periods and your further rights.
Rectification (Article 16 GDPR)
If personal data are inaccurate or incomplete, you may request that they be corrected or completed.
Erasure (Article 17 GDPR)
Subject to the statutory requirements, you have the right to request erasure of your personal data. Statutory retention obligations remain unaffected.
Restriction of processing (Article 18 GDPR)
Under certain conditions, you may request that your personal data only be processed to a limited extent.
Data portability (Article 20 GDPR)
Where processing is based on consent or a contract and is carried out by automated means, you may receive your data in a structured, commonly used and machine-readable format or request that it be transferred to another controller.
Right to object (Article 21 GDPR)
Where we process personal data on the basis of our legitimate interests under Article 6(1)(f) GDPR, you may object to this processing at any time on grounds relating to your particular situation. We will cease processing unless there are compelling legitimate grounds for the processing that override your interests.
Right to lodge a complaint with a supervisory authority (Article 77 GDPR)
You have the right to lodge a complaint with a competent supervisory authority if you consider that the processing of your personal data infringes the GDPR.
The supervisory authority responsible for INSITE-Interventions GmbH is:
Hessian Commissioner for Data Protection and Freedom of Information · PO Box 3163 · 65021 Wiesbaden · https://datenschutz.hessen.de/
You may also contact the supervisory authority at your place of residence or business.
Are you obliged to provide your personal data?
To initiate and carry out the business relationship between your organisation and INSITE-Interventions GmbH, we require certain contact and invoicing data. Without this information, we will generally be unable to establish a cooperation or to process it properly, in particular with regard to invoice processing and compliance with statutory documentation requirements.
Does automated decision-making or profiling take place?
No solely automated decision-making, including profiling within the meaning of Article 22 GDPR, takes place as part of this processing activity.
Up-to-dateness of this data protection notice
This data protection notice reflects the current state of the processing of personal data of contact persons at suppliers and service providers of INSITE-Interventions GmbH. If changes occur, we will update this notice and publish the new version.
What is this data protection notice about?
INSITE-Interventions GmbH operates a systematic quality management system with the aim of continuously developing its services and ensuring compliance with the standards applicable to it. In the course of these activities, we process personal data of people who are involved in or initiate quality assurance processes. With this data protection notice, we inform you, in accordance with Article 13 of the General Data Protection Regulation (GDPR), about the processing of your personal data in this context.
This data protection notice applies to you if you:
- submit a complaint to INSITE as a contact person at a customer company or as an interested person;
- receive a feedback request as a client after completion of a counselling service;
- are involved in our quality assurance or certification processes as an external service provider, auditor or QM officer.
Note for employees: The processing of personal data in the context of internal QM processes is governed by the separate data protection notice for employees.
Who is responsible for processing your data?
The controller within the meaning of the GDPR is:
INSITE-Interventions GmbH
Clemensstraße 10–12
60487 Frankfurt am Main
Telephone: +49 69 90555 29-0
Email: office@insite.de
How can you reach our Data Protection Officer?
If you have questions about data protection or the processing of your personal data, you can contact our Data Protection Officer at any time:
Deborah Schütt
Clemensstraße 10–12
60487 Frankfurt am Main
Telephone: +49 69 90555 29-0
Email: dsb@insite.de
Which personal data do we process?
The data processed depend on the context in which you come into contact with our quality management system.
Quality management and certification
In general quality management and certification processes, we process, in particular, the first and last names, business contact details (email address and telephone number), department and function of external service providers, auditors and contacts at customer companies. Where personal data of third parties are contained in QM documentation, these data are also processed as part of the audit activity.
Complaint management
From the person submitting a complaint, we process, in particular, their first and last name, business or private contact details (email address and telephone number) and the content of the complaint. If a complaint relates to a counselling service and is submitted by a client, the complaint may contain special categories of personal data pursuant to Article 9 GDPR – in particular health data and information about racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, or sex life or sexual orientation – insofar as the data subject has voluntarily included this information in the complaint.
Feedback on counselling services
When collecting feedback on counselling services, we process the email address provided by clients, their assessment of the counselling service using standardised questions and, where applicable, the names of the counsellors working on a fee basis and information that may indicate health data.
For what purposes and on what legal basis do we process your data?
Quality management and certification
We process personal data of external service providers, auditors and contacts at customer companies to coordinate our quality assurance measures, carry out external audits and certification processes, and continuously improve our processes and services. This includes, in particular, cooperation with external QM officers, preparing and carrying out surveillance and certification audits, and documenting quality measures.
Legal basis: Article 6(1)(f) GDPR. Our legitimate interest lies in assuring the quality of our services, complying with recognised standards and maintaining our certifications.
Complaint management
We process incoming complaints from customer contacts, clients and interested persons in order to clarify concerns appropriately, remedy quality issues and continuously improve the quality of our services. For follow-up purposes, we use a ticketing system in which complaint cases are recorded without being linked to client-related content.
Legal basis: Article 6(1)(b) GDPR for complaints connected with an existing contractual relationship; Article 6(1)(f) GDPR for complaints without a contractual background. Our legitimate interest lies in quality assurance and safeguarding legitimate counterclaims. Where complaints contain special categories of personal data in connection with counselling services, processing is based on Article 9(2)(h) GDPR.
Feedback on counselling services
After completion of a counselling service, we send clients who have provided an email address a standardised feedback request containing four questions about the quality of the counselling. We use the findings exclusively for quality assurance and to develop our services further.
Legal basis: Article 6(1)(f) GDPR. Our legitimate interest lies in measuring and improving the quality of our counselling services. Where health data are included in the feedback, processing is based on Article 9(2)(h) GDPR. Clients receive further information about the processing of their personal data in the separate data protection notice for clients.
Who receives your personal data?
As part of QM management, the following persons within INSITE-Interventions GmbH have access to the data required: Management, the QM Coordinator, the responsible team and department leads, and participating employees. Data are disclosed externally to external QM officers and, where necessary, to contacts at customer companies. For document storage, we use Tresorit.
Within complaint management, access is provided to Management, the Head of Customer Advisory, the Head of Interventions, the Head of Finance, the Head of Sales and the employees responsible for the particular matter. For document storage, we use Tresorit and eWorks where complaints relating to clients are concerned. We use the Freshworks ticketing system for the technical follow-up of complaint cases. Only status information and metadata are recorded in Freshworks; client-related complaint content is not stored there.
For feedback collection, Client Services, the responsible counsellors and the Head of Interventions have access to the feedback data. External fee-based counsellors may also be involved as part of their cooperation with INSITE. eWorks is used to support the system.
Are data transferred to third countries?
According to the current state of affairs, the systems used as part of quality management are not intended to transfer data to third countries outside the European Union.
How long do we store your personal data?
| Data category | Regular retention period |
| Certification documents | 10 years |
| General QM documentation | 6 years |
| Complaints relating to clients | 10 years |
| Complaints from customer contacts and interested persons | 6 years |
| Feedback data | 10 years (as part of the client documentation) |
After the applicable period has expired, the data are deleted or, where immediate deletion is not technically possible, blocked from further processing.
What rights do you have?
Access (Article 15 GDPR)
You may request access to the personal data we process.
Rectification (Article 16 GDPR)
You may request rectification of inaccurate or incomplete data.
Erasure (Article 17 GDPR)
Subject to statutory requirements, you may request erasure of your personal data. Statutory retention obligations remain unaffected.
Restriction of processing (Article 18 GDPR)
Under certain conditions, you may request restriction of the processing of your data.
Data portability (Article 20 GDPR)
Where the requirements are met, you may receive your data in a machine-readable format.
Right to object (Article 21 GDPR)
Where we process personal data on the basis of our legitimate interest, you may object at any time on grounds relating to your particular situation.
Right to lodge a complaint with a data protection supervisory authority (Article 77 GDPR)
If you consider that the processing of your personal data infringes data protection law, you have the right to lodge a complaint with a data protection supervisory authority. The supervisory authority responsible for INSITE-Interventions GmbH is the Hessian Commissioner for Data Protection and Freedom of Information (HBDI): https://datenschutz.hessen.de/. You may also contact the supervisory authority at your place of residence or habitual abode.
Hessian Commissioner for Data Protection and Freedom of Information, PO Box 3163, 65021 Wiesbaden - https://datenschutz.hessen.de/
Are you obliged to provide your personal data?
Providing personal data in the context of complaint management is voluntary. However, without contact details, it may only be possible to process your complaint to a limited extent or anonymously. Providing data in the context of certification audits follows from the relevant contractual or statutory obligations.
Does automated decision-making or profiling take place?
No solely automated decision-making, including profiling within the meaning of Article 22 GDPR, takes place.
Up-to-dateness of this data protection notice
This data protection notice reflects the current state of the processing of personal data. We reserve the right to adapt this notice in the event of changes to the systems used, processing operations or the legal situation. The current version is made available on our website.
What is this privacy notice about?
In the course of its business activities, INSITE-Interventions GmbH is legally required to retain business-relevant documents and correspondence for specified periods. This obligation applies regardless of how the documents were created or the business relationship to which they relate. Records are retained in both physical and digital form.
Under Article 13 of the GDPR, this privacy notice explains which personal data are processed in this context, the legal basis for the processing and the rights available to you.
This privacy notice applies to all individuals whose personal data are contained in documents that we retain, particularly contacts at customer companies, employees, prospective customers and other interested parties, representatives of cooperation partners and service providers, and contacts at public authorities and insurance companies.
Please note: Separate privacy notices are available for most of the groups of individuals listed here and provide a comprehensive description of the relevant business relationship. This privacy notice supplements those group-specific notices by covering general statutory retention obligations.
Who is responsible for processing your data?
The controller within the meaning of the General Data Protection Regulation is:
INSITE-Interventions GmbH
Clemensstraße 10-12
60487 Frankfurt am Main
Telephone: +49 69 90555 29-0
Email: office@insite.de
How can you contact our Data Protection Officer?
If you have any questions about data protection or the processing of your personal data, you may contact our Data Protection Officer at any time:
Deborah Schütt
Clemensstraße 10-12
60487 Frankfurt am Main
Telephone: +49 69 90555 29-0
Email: dsb@insite.de
What personal data do we process?
As part of our general records retention, we process personal data contained in documents subject to retention requirements. The type and scope of the data depend on the document concerned. Typically, this includes:
First name and surname, business contact details (email address and telephone number), address, role and any other information contained in the relevant correspondence, contracts, quotations, invoices or other business records.
Special categories of personal data within the meaning of Article 9 GDPR are not generally collected separately as part of general records retention. Where such data are contained in documents that must be retained, their processing is governed by the legal bases applicable to the relevant processing context, as set out in the group-specific privacy notices.
For what purposes and on what legal basis do we process your data?
Business records are retained in order to comply with statutory retention obligations under commercial and tax law. We are legally required to retain certain documents for the periods specified in section 147 of the German Fiscal Code (Abgabenordnung - AO) and section 257 of the German Commercial Code (Handelsgesetzbuch - HGB), and to make them available for any official audits.
Legal basis: Article 6(1)(c) GDPR.
Where individual documents are retained beyond the statutory minimum retention period - for example, for the establishment, exercise or defence of legal claims - processing is based on Article 6(1)(f) GDPR. In this case, our legitimate interest is in safeguarding our legal position and preserving evidence.
Who receives your personal data?
Within the company, physical records are accessible only to Office Management, the Managing Directors and the Head of Finance. Digital records are managed on a need-to-know basis; access is limited to those individuals and departments that need the relevant documents to perform their duties.
For encrypted digital storage, we use Tresorit. At the end of the retention period, we engage a certified document destruction service provider to destroy physical records in accordance with DIN 66399.
In addition, Asklepios is documented as an external recipient in connection with records retention. For further information about Asklepios's specific role in this context, please contact our Data Protection Officer.
Are data transferred to third countries?
No data are transferred to countries outside the European Union as part of general records retention.
How long do we retain your personal data?
Retention periods are governed by statutory requirements:
| Document category | Retention period | Legal basis |
|---|---|---|
| Accounting records, invoices, tax records, bank records | 10 years | Section 147 AO; section 257(1) no. 1 HGB |
| Business and commercial correspondence, contracts, quotation documents | 6 years | Section 257(1) nos. 2 and 3 HGB; section 147(1) no. 2 AO |
After the relevant period has expired, the documents are securely destroyed or deleted in accordance with data protection requirements, unless further statutory obligations or legitimate interests require a longer retention period.
What rights do you have?
Right of access (Article 15 GDPR): You may request confirmation as to whether personal data concerning you are processed in our record-keeping systems and, if so, which data.
Rectification (Article 16 GDPR): You may request the rectification of inaccurate data. Please note that, in the case of original documents subject to statutory retention requirements, it is generally not permissible to alter the document itself.
Erasure (Article 17 GDPR): The right to erasure does not apply, for the duration of the retention obligation, to documents retained under statutory retention requirements pursuant to Article 6(1)(c) GDPR. Once the statutory periods have expired, the documents will be deleted or destroyed as a matter of course.
Restriction of processing (Article 18 GDPR): In certain circumstances, you may request restriction of processing. However, for documents subject to statutory retention requirements, restriction can only take the form of blocking access; processing cannot be stopped entirely during the retention period.
Objection (Article 21 GDPR): Where processing is based on Article 6(1)(f) GDPR, you may object to the processing. There is no right to object to retention required by law under Article 6(1)(c) GDPR.
Right to lodge a complaint with a supervisory authority (Article 77 GDPR):
Hessian Commissioner for Data Protection and Freedom of Information, PO Box 3163, 65021 Wiesbaden - https://datenschutz.hessen.de/
Are you required to provide your personal data?
The processing of personal data as part of records retention does not result from your actively providing the data, but is a necessary consequence of the business relationship or correspondence from which the relevant documents arose. Without retaining these documents, we would be unable to meet our statutory obligations.
Do we use automated decision-making or profiling?
No solely automated decision-making, including profiling within the meaning of Article 22 GDPR, takes place.
Status of this privacy notice
This privacy notice reflects the current state of the processing of personal data. We reserve the right to amend it if the systems used, processing activities or legal requirements change. The current version will be made available on our website.