Privacy policy
Below we inform you about the processing of your personal data in the course of using our online offering.
Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) and other data protection provisions is:
talessio GmbH
Alexanderstr. 52
72072 Tübingen
Germany
Phone: +49.7071.53938.0
Fax: +49.7071.9184942
Email: hello@talessio.com
Web: https://talessio.com/
If you have any questions about data protection, please contact us using the contact details provided above.
Contacting the data protection officer
The data protection officer of the controller is:
DataCo GmbH
Sandstr. 33
80335 München
Germany
Phone: +49.89.7400.45840
Web: https://dataguard.de/
Storage period
In principle, we delete your personal data when it is no longer necessary for the purposes for which it was collected or otherwise processed.
If we have asked for your consent and you have given it, we delete your personal data if you withdraw your consent and there is no other legal basis for the processing.
We delete your personal data if you object to the processing and there are no overriding legitimate grounds for the processing, or if you object to the processing for the purposes of direct marketing or associated profiling.
If deletion is not possible because processing is still necessary to fulfil a legal obligation to which we are subject (statutory retention periods, etc.) or to assert, exercise or defend legal claims, we restrict the processing of your personal data.
Further information on the storage period can also be found in the following passages.
Your rights
You have the following rights vis-à-vis us with regard to your personal data:
- Right of access
- Right to rectification
- Right to erasure
- Right to restriction of processing
- Right to object to processing
- Right to data portability
You have the right, on grounds relating to your particular situation, to object at any time to the processing of your personal data which is based on Article 6(1)(e) or (f) GDPR; this also applies to profiling based on these provisions. We will then no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims.
If we process your personal data in order to conduct direct marketing, you have the right to object at any time to the processing of your personal data for the purposes of such advertising; this also applies to profiling insofar as it is associated with such direct marketing. We will then no longer process your personal data for these purposes.
You have the right to withdraw consent to the processing of your personal data at any time, if you have given us such consent. The withdrawal of consent does not affect the lawfulness of the processing carried out on the basis of the consent up to the point of withdrawal.
You have the right to lodge a complaint with a supervisory authority about our processing of your personal data.
Supervisory authority
Below you will find the supervisory authority responsible for us:
The State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg
Heilbronner Straße 35
70191 Stuttgart
Germany
Provision of your personal data
The provision of your personal data is generally neither required by law nor by contract and is not necessary for entering into a contract. You are generally not obliged to provide your personal data. Insofar as this should nevertheless be the case, we will point this out to you separately when collecting your personal data (for example by marking the mandatory fields in input forms).
Failure to provide your personal data will regularly mean that we cannot process your personal data for one of the purposes described below and that you cannot take advantage of an offer associated with the respective processing (example: without providing your email address, you will not receive our newsletter).
Web hosting
For web hosting, we use external services. These services may have access to personal data that is processed in the course of using our online offering.
Web server log files
We process your personal data in order to display our online offering to you and to ensure the stability and security of our online offering. In doing so, information (for example the requested element, the URL accessed, operating system, date and time of the request, browser type and the version used, IP address, protocol used, volume of data transferred, user agent, referrer URL, time zone difference from Greenwich Mean Time (GMT) and/or HTTP status code) is stored in so-called log files (access log, error log, etc.).
If we have asked for your consent and you have given it, the legal basis for the processing is Art. 6(1)(a) GDPR. If we have not asked for your consent, the legal basis for the processing is Art. 6(1)(f) GDPR. Our legitimate interest then lies in the proper display of our online offering and ensuring the stability and security of our online offering.
Security
For security reasons and to protect the transmission of your personal data and other confidential content, we use encryption on our domain. You can recognise this in the browser bar by the string “https://” and the padlock symbol.
We use firewalls and malware scanners from external services to ensure the security of our online offering.
If we have asked for your consent and you have given it, the legal basis for the processing is Art. 6(1)(a) GDPR. If we have not asked for your consent, the legal basis for the processing is Art. 6(1)(f) GDPR. Our legitimate interest then lies in the security of our online offering.
In the course of using the external services, profiling may also take place (for the purposes of advertising, personalised information, etc.). Profiling may also take place across services and devices. Further information on the services used, the scope of the data processing, and the technologies and procedures involved in using the respective services, as well as on whether profiling takes place when using the respective services and, where applicable, information on the logic involved and the significance and intended effects of such processing for you, can be found in the further information on the services we use at the end of this passage and under the links provided there.
Web Application Firewall
Provider: BunnyWay d.o.o., Slovenia.
Website: https://bunny.net/
Further information & data protection: https://bunny.net/privacy/
Content Delivery Networks
We use content delivery networks from external services to optimise the loading time, stability and security of our online offering.
If we have asked for your consent and you have given it, the legal basis for the processing is Art. 6(1)(a) GDPR. If we have not asked for your consent, the legal basis for the processing is Art. 6(1)(f) GDPR. Our legitimate interest then lies in optimising the loading time, stability and security of our online offering.
In the course of using the external services, profiling may also take place (for the purposes of advertising, personalised information, etc.). Profiling may also take place across services and devices. Further information on the services used, the scope of the data processing, and the technologies and procedures involved in using the respective services, as well as on whether profiling takes place when using the respective services and, where applicable, information on the logic involved and the significance and intended effects of such processing for you, can be found in the further information on the services we use at the end of this passage and under the links provided there.
Bunny CDN
Provider: BunnyWay d.o.o., Slovenia.
Website: https://bunny.net/
Further information & data protection: https://bunny.net/privacy/
Contact
If you contact us, we process your personal data in order to handle your enquiry.
If we have asked for your consent and you have given it, the legal basis for the processing is Art. 6(1)(a) GDPR. If we have not asked for your consent, the legal basis for the processing is Art. 6(1)(f) GDPR. Our legitimate interest then lies in handling your enquiry. Where the processing is necessary for the performance of a contract with you or for the implementation of pre-contractual measures in response to your enquiry, the legal basis for the processing is additionally Art. 6(1)(b) GDPR.
To provide and maintain our email mailboxes, we use external services. These services may have access to personal data that is processed in the course of contacting us.
To support the handling of your enquiry, we use support systems (appointment booking systems, live chats, ticketing systems or helpdesks, etc.) and use external services for this purpose. These services may have access to personal data that is processed in the course of contacting us via a support system. Further information on the services used, the scope of the data processing, and the technologies and procedures involved in using the respective services can be found below in the further information on the services we use and under the links provided there:
Freshdesk Support Desk
Provider: Freshworks, Inc., United States of America.
Website: https://freshdesk.com/de/support-desk/
Further information & data protection: https://www.freshworks.com/privacy/ and https://www.freshworks.com/security/
Safeguard: EU Standard Contractual Clauses. You can request a copy of the EU Standard Contractual Clauses from us. The provider has joined the EU-US Data Privacy Framework (https://www.dataprivacyframework.gov) joined, which, on the basis of a decision of the European Commission, ensures compliance with an adequate level of data protection.
Cookies & similar technologies
Cookies are used. Cookies are text information stored on your end device. A distinction is made between session cookies, which are deleted immediately after you close your browser, and persistent cookies, which are only deleted after a certain period of time.
In addition to cookies, similar technologies (tracking pixels, web beacons, etc.) may also be used. The following explanations regarding cookies apply accordingly to similar technologies. Likewise, these explanations apply to the further processing associated with cookies and similar technologies (analysis & marketing, etc.). This applies in particular to any consent you may have given for the use of cookies. Such consent also extends to other technologies and to the further processing associated with cookies and similar technologies.
Cookies may serve to enable the use of certain functions. Cookies may also serve to measure the reach of our online offering, to design it in a needs-based and interest-based way, and thereby to optimise our online offering and our marketing. Cookies may be used by us and by external services.
To manage the cookies used and the related consents, we use a consent tool. Details of the cookies used (purpose, storage period, external service where applicable, etc.) and the consent tool can be found in the following passages and in the consent tool we use.
If we have asked for your consent and you have given it, the legal basis for the processing is Art. 6(1)(a) GDPR. If we have not asked for your consent, the legal basis for the processing is Art. 6(1)(f) GDPR. Our legitimate interest is the management of the cookies used and the related consents. Depending on the purpose of the processing, our legitimate interests can be found in the following passages.
You can prevent the storage of cookies by configuring your browser accordingly. Below we provide you with links for typical browsers where you can find further information on managing cookie settings:
- Firefox: https://support.mozilla.org/de/kb/verbesserter-schutz-aktivitatenverfolgung-desktop
- Chrome: https://support.google.com/chrome/answer/95647?hl=de&hlrm=en
- Internet Explorer / Edge: https://support.microsoft.com/de-de/windows/l%C3%B6schen-und-verwalten-von-cookies-168dab11-0753–043d-7c16-ede5947fc64d
- Safari: https://support.apple.com/de-de/guide/safari/sfri11471/mac
- Opera: https://help.opera.com/de/latest/web-preferences/#cookies
- Yandex: https://browser.yandex.com/help/personal-data-protection/cookies.html
Further options to object can be found under the following links: https://www.youronlinechoices.eu/, https://youradchoices.ca/en/tools and https://optout.aboutads.info/?c=2&lang=EN.
If you prevent the storage of cookies, this may impair the proper functioning of our online offering. If you delete all cookies, the above settings will also be lost and must be made again.
Furthermore, you can activate the “Do Not Track” function of your browser to signal that you do not wish to be tracked. Below we provide you with links for typical browsers where you can find further information on the “Do Not Track” setting:
- Firefox: https://support.mozilla.org/de/kb/wie-verhindere-ich-dass-websites-mich-verfolgen
- Chrome: https://support.google.com/chrome/answer/2790761?co=GENIE.Platform%3DDesktop&hl=de
- Internet Explorer / Edge: https://support.microsoft.com/de-de/windows/verwenden-von-do-not-track-in-internet-explorer-11-ad61fa73-d533-ce96-3f64-2aa3a332e792
- Opera: https://help.opera.com/de/latest/security-and-privacy/
- Safari has not supported the “Do Not Track” function since February 2019. Under the following link, cross-site tracking can be prevented in Safari: https://support.apple.com/de-de/guide/safari/sfri40732/12.0/mac
- Yandex: https://yandex.com/support/browser/personal-data-protection/ytp.html
You can also withdraw or manage your consents regarding the cookies used in the consent tool we use.
Analysis & marketing
We process your personal data in order to measure the reach of our online offering, to design it in a needs-based and interest-based way, and thereby to optimise our online offering and our marketing.
If we have asked for your consent and you have given it, the legal basis for the processing is Art. 6(1)(a) GDPR. If we have not asked for your consent, the legal basis for the processing is Art. 6(1)(f) GDPR. Our legitimate interest then lies in optimising our online offering and our marketing.
We use external services for analysis and marketing. This may also involve profiling (for the purposes of advertising, personalised information, etc.). Profiling may also take place across services and devices. Further information on the services used, the scope of the data processing, and the technologies and procedures involved in using the respective services, as well as on whether profiling takes place when using the respective services and, where applicable, information on the logic involved and the significance and intended effects of such processing for you, can be found in the further information on the services we use at the end of this passage and under the links provided there.
Further information on cookies & similar technologies can be found above.
Google Analytics
Provider: Within the European Economic Area (EEA) and Switzerland, Google services are provided by Google Ireland Limited, Ireland. Google Ireland Limited is a subsidiary of Google LLC, United States of America. Website: https://marketingplatform.google.com/intl/de/about/analytics/ Further information & data protection: https://support.google.com/analytics/answer/6004245?hl=de, https://policies.google.com/?hl=de and https://business.safety.google/privacy/ The transfer of personal data to third countries takes place depending on the respective Google service and under the various EU Standard Contractual Clauses, where these are offered by Google. Further information on this and on Google’s responsibility can be found under the following link: https://business.safety.google/gdpr/. You can view a copy of the EU Standard Contractual Clauses there. The provider has joined the EU-US Data Privacy Framework (https://www.dataprivacyframework.gov), which, on the basis of a decision of the European Commission, ensures compliance with an adequate level of data protection.
Google Tag Manager
Provider: Within the European Economic Area (EEA) and Switzerland, Google services are provided by Google Ireland Limited, Ireland. Google Ireland Limited is a subsidiary of Google LLC, United States of America. Website: https://support.google.com/tagmanager/answer/6102821?hl=de Further information & data protection: https://policies.google.com/?hl=de and https://business.safety.google/privacy/ The transfer of personal data to third countries takes place depending on the respective Google service and under the various EU Standard Contractual Clauses, where these are offered by Google. Further information on this and on Google’s responsibility can be found under the following link: https://business.safety.google/gdpr/. You can view a copy of the EU Standard Contractual Clauses there. The provider has joined the EU-US Data Privacy Framework (https://www.dataprivacyframework.gov), which, on the basis of a decision of the European Commission, ensures compliance with an adequate level of data protection.
Social media presences
We maintain social media presences with external services in order to communicate with users there and thereby optimise our online offering and our marketing.
This privacy policy also applies to the following social media presences:
- https://www.linkedin.com/company/talessio/
- https://www.xing.com/pages/talessiogmbh
If we have asked for your consent and you have given it, the legal basis for the processing is Art. 6(1)(a) GDPR. If we have not asked for your consent, the legal basis for the processing is Art. 6(1)(f) GDPR. Our legitimate interest then lies in optimising our online offering and our marketing.
In the course of using the external services, profiling may also take place (for the purposes of advertising, personalised information, etc.). Profiling may also take place across services and devices. Further information on the services used, the scope of the data processing, and the technologies and procedures involved in using the respective services, as well as on whether profiling takes place when using the respective services and, where applicable, information on the logic involved and the significance and intended effects of such processing for you, can be found in the further information on the services we use at the end of this passage and under the links provided there.
Provider: If you are located in the EU, the European Economic Area (EEA) or Switzerland, this service is provided by LinkedIn Ireland Unlimited Company, Ireland. If you are located outside the EU, the European Economic Area (EEA) or Switzerland, this service is provided by LinkedIn Corporation, United States of America.
Website: https://www.linkedin.com
Further information & data protection: https://de.linkedin.com/legal/privacy-policy?trk=homepage-basic_footer-privacy-policy and https://de.linkedin.com/legal/cookie-policy?trk=homepage-basic_footer-cookie-policy
Safeguard: EU Standard Contractual Clauses. You can request a copy of the EU Standard Contractual Clauses from us. The provider has joined the EU-US Data Privacy Framework (https://www.dataprivacyframework.gov) joined, which, on the basis of a decision of the European Commission, ensures compliance with an adequate level of data protection.
Provider: New Work SE, Germany.
Website: https://www.xing.de
Further information & data protection: https://privacy.xing.com/de and https://privacy.xing.com/de/datenschutzerklaerung
Fonts & scripts
We use fonts and scripts from external services in order to display our online offering to you and to ensure up-to-date fonts and scripts at all times.
If we have asked for your consent and you have given it, the legal basis for the processing is Art. 6(1)(a) GDPR. If we have not asked for your consent, the legal basis for the processing is Art. 6(1)(f) GDPR. Our legitimate interest then lies in the proper display of our online offering and ensuring up-to-date fonts and scripts.
In the course of using the external services, profiling may also take place (for the purposes of advertising, personalised information, etc.). Profiling may also take place across services and devices. Further information on the services used, the scope of the data processing, and the technologies and procedures involved in using the respective services, as well as on whether profiling takes place when using the respective services and, where applicable, information on the logic involved and the significance and intended effects of such processing for you, can be found in the further information on the services we use at the end of this passage and under the links provided there.
Font Awesome
Provider: Fonticons, Inc., United States of America.
Website: https://www.fontawesome.com
Further information & data protection: https://fontawesome.com/privacy
Safeguard: The provider has joined the EU-US Data Privacy Framework (https://www.dataprivacyframework.gov) joined, which, on the basis of a decision of the European Commission, ensures compliance with an adequate level of data protection.
Applications
If you apply to us, we process your personal data in order to carry out the application procedure and to make a decision on the establishment of an employment relationship. After the application procedure has ended, we restrict the processing of your personal data and delete or destroy it no later than 6 months after you receive the rejection, or we return your application documents to you and delete or destroy any copies, unless you have consented to our continued use of your personal data.
If we have asked for your consent and you have given it, the legal basis for the processing is Art. 6(1)(a) GDPR. If we have not asked for your consent, the legal basis for the processing is Art. 6(1)(f) GDPR. Our legitimate interest then lies in the proper conduct of the application procedure and, where applicable, the defence against claims arising from the rejection of an application. Where the processing is necessary for a decision on the establishment of an employment relationship, the legal basis for the processing is additionally Section 26(1) sentence 1 BDSG (German Federal Data Protection Act).
Telephone contact
If you contact us by telephone, we process your personal data in order to handle your enquiry. To automatically receive and handle incoming calls, we use an AI-supported telephone assistant. This processes the content of the conversation on our behalf in order to record, forward or answer your request. In doing so, automatic speech recognition (speech-to-text), semantic analysis (natural language processing) and, where applicable, speech output (text-to-speech) are used.
The content of conversations may be recorded, transcribed or documented. This only happens if you were informed accordingly at the beginning of the conversation and continue the conversation. You can end the connection at any time to avoid processing.
In particular, your statements during the conversation, technical connection data (date, time, duration) and, where applicable, voluntarily provided master data such as name or telephone number are processed. In addition, interaction data, for instance on the conduct of the conversation or on call interruptions, is processed.
If we have asked for your consent and you have given it, the legal basis for the processing is Art. 6(1)(a) GDPR. If we have not asked for your consent, the legal basis for the processing is Art. 6(1)(f) GDPR. Our legitimate interest then lies in the efficient and scalable handling of your telephone enquiry. Where the processing is necessary for the performance of a contract with you or for the implementation of pre-contractual measures in response to your enquiry, the legal basis for the processing is additionally Art. 6(1)(b) GDPR.
For the technical implementation, the provider uses subprocessors, in particular for hosting, speech recognition and semantic analysis. In this context, personal data may also be transferred to the USA. Where an adequacy decision of the European Commission pursuant to Art. 45 GDPR exists, the transfer takes place on that basis; the providers concerned have in this respect joined the EU-US Data Privacy Framework. Where no such decision exists, the transfer takes place on the basis of EU Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR and supplementary protective measures. The requirements of Art. 44 GDPR are complied with.
To improve speech processing, pseudonymised data may be used for training purposes. Tracing back to individual persons is thereby excluded or considerably hindered. A decision based solely on automated processing within the meaning of Art. 22 GDPR does not take place.
We store the data referred to only for as long as is necessary for the stated purposes. The data is then automatically deleted or anonymised. Further information on the service used, the scope of the data processing, and the technologies and procedures involved in using the service can be found below in the further information on the service we use and under the links provided there:
IONOS AI phone assistant
Provider: IONOS SE, Germany.
Website: https://www.ionos.de/momentum/ki-telefonassistent
Further information & data protection: https://www.ionos.de/terms-gtc/datenschutzerklaerung/
Safeguard: Processing takes place in data centres in Germany. Insofar as the provider uses subprocessors outside the EU or the EEA, the transfer takes place on the basis of an adequacy decision (in particular the EU-US Data Privacy Framework, https://www.dataprivacyframework.gov) or on the basis of EU Standard Contractual Clauses. You can request a copy of the EU Standard Contractual Clauses from us.
Final provisions
The German version of this document takes precedence over all other language versions.
This privacy policy is reviewed and updated regularly. We therefore reserve the right to supplement it from time to time and to make changes to the collection, processing or use of your data. We therefore ask you to inform yourself regularly about the content of this privacy policy. We will actively notify you as soon as changes require your involvement (e.g. consent) or other individual notification.
Insofar as we provide addresses and contact information of companies and organisations in this privacy policy, please note that these may change over time. Please verify them before contacting us or them.