Protecting your personal data is of particular importance to us. We therefore process your personal data (hereinafter referred to as "data") exclusively in accordance with the applicable legal provisions. With this Privacy Policy, we would like to provide you with comprehensive information, in accordance with Article 13 of the EU General Data Protection Regulation (GDPR), about the processing of your personal data by our company and about your rights under data protection law.
1. Who is responsible for data processing and whom can you contact?
Responsible is
SOFiSTiK AG
Flataustr. 14
90411 Nuremberg, Germany
Phone: + 49 911 399010
E-Mail: info@sofistik.com
Data Protection Officer
Eva-Daniela Jung, my-dsb.com UG (haftungsbeschränkt)
Neue Mainzer Straße 6-10
60311 Frankfurt am Main, Germany
E-Mail: jung@dsqm.org
2.1 Personal Data
Depending on your use of the software, we may process the following categories of personal data:
We only process personal data that are necessary for the respective purpose.
2.2 Additional Personal Data
When you download and use our software on your device, our Software Improvement Program is enabled by default. Within this program, we collect certain technical information, including: Information about your software usage, such as the frequency and duration of use and error information (e.g., crash frequency); Information about your operating system, device type, display configuration (e.g., GPU model, number and resolution of displays); Information about your regional location, country, and language settings.
We collect this information to improve the quality, stability, functionality, and hardware compatibility of our software. These technical data are not shared with third parties and are not combined with the personal data processed within your SOFiSTiK Account. Where a natural person can be identified from the processed technical information, the legal basis for processing is Article 6(1)(f) GDPR (legitimate interest).
If you do not wish SOFiSTiK to collect your technical data, you may disable this feature at any time, for example by using a Windows Registry key or through the settings in the SOFiSTiK Application Manager.
Processing is carried out at your request and is necessary for the purposes of our legitimate interests pursuant to Article 6(1)(f) GDPR. You will receive a registration email that must be confirmed in order to activate your SOFiSTiK Account (double opt-in procedure). Your confirmation serves as proof that you are the person who initiated the registration. Unless statutory retention obligations pursuant to Article 6(1)(c) GDPR apply, or you have consented to a longer retention period under Article 6(1)(a) GDPR, your SOFiSTiK Account data will be deleted after 37 months.
To improve software stability, security, and error analysis, the software may process technical diagnostic data, event logs, or crash information. Personal data are processed only to the extent necessary for these purposes.
Security-related events may be logged in order to detect attacks, analyze security incidents, and ensure the integrity of the software.
Where telemetry data are collected, this is done solely for the purposes described in this Privacy Policy and in compliance with applicable data protection laws. If enabled, the software may transmit technical diagnostic information such as:
These data are transmitted exclusively to improve software stability and security. Where telemetry is optional, it can be disabled at any time in the software settings.
If you contact our support team, we process the information you provide, including in particular:
Server Log Files
Our hosting provider automatically collects and stores information transmitted by your browser in server log files. This includes:
These data are not merged with other data sources. Processing is based on Article 6(1)(f) GDPR and our legitimate interest in improving the stability and functionality of our website. Where technically feasible, processing is carried out in encrypted form. For technical security reasons, particularly to defend against attacks on our web server, these data are stored temporarily. It is not possible for us to identify individual users based on these data. After no later than seven days, IP addresses are anonymized by shortening them at domain level so that they can no longer be linked to individual users. Anonymous data may additionally be processed for statistical purposes. They are not matched with other data sets nor disclosed to third parties, even in part.
Use of the Moodle Learning Platform
We use the Moodle learning platform to provide training, continuing education, and informational content. In connection with the use of Moodle, personal data are processed to the extent necessary for the creation and administration of user accounts, the delivery of courses, and the provision of learning content. The following categories of personal data may be processed in particular:
The data are processed for the purpose of providing and administering the learning platform, conducting training activities, documenting learning progress, and ensuring system security and the proper operation of the platform.
The legal basis for processing is Article 6(1)(b) GDPR where processing is necessary for the performance of a contract or pre-contractual measures. Where Moodle is used in the context of an employment relationship, processing is based on Article 6(1)(b) GDPR and, where applicable, Section 26 of the German Federal Data Protection Act (BDSG). Processing may also be based on Article 6(1)(f) GDPR. Our legitimate interest lies in the secure and efficient provision of a digital learning platform.
Personal data are generally retained only for as long as necessary to conduct the training activities, comply with statutory retention obligations, or establish, exercise, or defend legal claims. User accounts and associated data are deleted or anonymized once the purpose of processing no longer applies, unless statutory retention obligations require otherwise.
Where Moodle is hosted by an external service provider, personal data are processed under a data processing agreement pursuant to Article 28 GDPR. Where personal data are transferred to countries outside the European Union or the European Economic Area, such transfers are carried out exclusively in compliance with Articles 44 et seq. GDPR.
We process your personal data in accordance with the provisions of the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG), as amended from time to time.
3.1 Purposes of Processing
Your personal data are processed in particular for the following purposes:
3.2 Legal Bases for Processing
Depending on the processing activity, personal data are processed on one or more of the following legal bases:
3.3 Processing of Personal Data for Marketing Purposes
You may object at any time to the use of your personal data for marketing purposes, either entirely or with respect to individual marketing measures, without incurring any costs other than the transmission costs according to the basic rates.
Subject to the requirements of Section 7(3) of the German Act Against Unfair Competition (UWG), we are entitled to use the email address you provided when concluding a contract to send you direct advertising relating to our own similar products or services. You may receive these product recommendations regardless of whether you have subscribed to our newsletter.
If you no longer wish to receive such recommendations by email, you may object to the use of your email address for this purpose at any time. A notification in text form is sufficient. Every marketing email also contains an unsubscribe link.
The processing of your personal data is necessary for the conclusion and performance of the contract entered into with us. If you do not provide the required data, we may be unable to conclude the contract or continue performing an existing contract and may therefore have to terminate it. However, you are not obliged to consent to the processing of personal data that are not required for the performance of the contract or by law.
Where we engage service providers acting as data processors, we remain responsible for protecting your personal data. All processors are contractually obligated to treat your data confidentially and to process them solely within the scope of the services provided. Our processors receive only the personal data necessary for the performance of their respective services. These include, for example:
Your data are processed within our customer database, which serves to improve the quality of our customer data. Where necessary for the performance of a contract, customer data may be shared with companies within our corporate group. Customer data are stored separately for each company, while our parent company provides centralized services to participating group companies.
Where required by law or for the establishment, exercise, or defense of legal claims, public authorities, courts, and external auditors may also receive your personal data. Insurance companies, banks, credit agencies, and other service providers may also receive your personal data where this is necessary for initiating or performing contractual relationships.
Personal data are retained only for as long as necessary for the purposes for which they were collected or where statutory retention obligations apply. Once the relevant purpose no longer exists, the personal data are deleted unless legal retention obligations require continued storage.
As a general rule, we do not transfer personal data to countries outside the European Union or the European Economic Area. Transfers only take place in individual cases on the basis of an adequacy decision issued by the European Commission, the use of Standard Contractual Clauses, other appropriate safeguards, or your explicit consent.
We have implemented appropriate technical and organizational security measures to protect your personal data against loss, destruction, manipulation, and unauthorized access. All employees and service providers working on our behalf are required to comply with applicable data protection laws.
Whenever personal data are collected and processed, they are encrypted before transmission to prevent misuse by unauthorized third parties. Our security measures are continuously reviewed and improved, and this Privacy Policy is regularly updated. Please ensure that you are using the latest version.
9. Newsletter
We use the so-called double opt-in procedure to subscribe users to our newsletter. This means that we will only send you newsletters by email after you have expressly confirmed that you wish to activate the newsletter service.
Following your registration, you will receive a confirmation email asking you to verify your subscription by clicking the link contained in that email.
When you subscribe to our newsletter, we store your IP address and the date and time of your registration. This serves solely as evidence in the event that a third party misuses your email address to subscribe to the newsletter without your knowledge or authorization. The legal basis for this processing is your consent pursuant to Article 6(1)(a) GDPR.
If you unsubscribe from the newsletter and no ongoing business relationship exists between you and us, your personal data will be deleted without undue delay.
You may object to receiving newsletters at any time without incurring any costs other than the transmission costs according to the basic rates, for example by using the unsubscribe link included in every newsletter.
We also use Microsoft Dynamics conversion tracking to measure the effectiveness of our marketing and sales activities. For this purpose, cookies or similar technologies may be used to record certain user interactions.
10. Cookies
When you visit our website, we may store information on your computer in the form of cookies. Cookies are small files that are transferred from a web server to your browser and stored on your device. Only the Internet Protocol (IP) address is stored in this process; no additional personal data are stored.
The information stored in cookies enables us to recognize your browser automatically during your next visit, thereby making the use of our website more convenient. You may, of course, use our website without accepting cookies.
If you do not wish your computer to be recognized on future visits, you can disable cookies by changing your browser settings accordingly. Instructions can be found in the documentation provided by your browser. Please note, however, that disabling cookies may limit the functionality of certain areas of our website.
11.1 UpCloud - Hosting
We use the services of Aiven Ltd. ("Aiven") and UpCloud Ltd. ("UpCloud") to provide hosting services.
Aiven and UpCloud provide hosting infrastructure on our behalf. The use of hosting services is necessary for the provision of our services and is based on our legitimate interest pursuant to Article 6(1)(f) GDPR.
Further information is available in the respective privacy and security policies of Aiven and UpCloud.
11.2 Microsoft SharePoint Online (sofistik.sharepoint.com – Webinar Videos)
In certain areas of our website, we integrate content hosted on Microsoft SharePoint Online, a service provided by Microsoft Corporation.
When accessing such content, a connection to Microsoft servers may be established.
Personal data may be transferred to the United States on the basis of the European Commission's Standard Contractual Clauses.
Further information is available in Microsoft's Privacy Statement.
11.3 Microsoft Dynamics Forms
We use Microsoft Dynamics 365 Customer Engagement to collect and process contact requests submitted via our website.
Personal data entered into these forms are processed on Microsoft servers.
Further information is available in Microsoft's Privacy Statement.
11.4 WiCE (SOFiSTiK Online)
For the purpose of storing customer information, technologies provided by WiCE are used to collect personal data, which are subsequently transferred to our Customer Relationship Management (CRM) system. The following categories of personal data may be collected:
Processing is based on your consent pursuant to Article 6(1)(a) GDPR.
You may withdraw your consent at any time with effect for the future.
Your personal data are disclosed internally only for the stated purpose. A data processing agreement has been concluded with the service provider in accordance with Article 28 GDPR.
Further information is available in the WiCE Privacy Policy.
11.5 Synadia
Synadia is used as the communication infrastructure between the individual software components.
Synadia serves exclusively to transmit messages between participating system components.
Data processed through Synadia are handled only temporarily for message transmission purposes. The transmitted content is not permanently stored within the Synadia system.
Communication is encrypted. After successful transmission, the data are processed and stored by the intended target systems, such as Microsoft Dynamics, in accordance with their respective processing purposes.
The use of Synadia is necessary to ensure reliable and secure communication between software components and to provide the software's functionality.
Further information is available in the Synadia Privacy Policy.
11.6 FusionAuth
FusionAuth is used as the identity provider for the SOFiSTiK Account and is responsible for user authentication and account management.
As part of the registration and login process, FusionAuth processes the personal data required for authentication, in particular login credentials and account information.
Processing is carried out solely for the purpose of providing secure user authentication and managing user accounts.
The use of FusionAuth is necessary to provide access to protected areas of the software and to ensure the security of user accounts.
Further information is available in the FusionAuth Privacy Policy.
11.7 Wildbit
Wildbit LLC sends the account confirmation email on our behalf during the user registration process.
Further information is available in the Wildbit Privacy Policy.
11.8 Video Integration (Bunny.net)
We use Bunny.net (BunnyWay d.o.o., Cesta komandanta Staneta 4A, 1215 Medvode, Slovenia) to embed and deliver videos on our website. When you access a page containing embedded videos, a connection is established to Bunny.net's servers. In the process, technically necessary information, including your IP address, browser and operating system information, as well as the date and time of the request, may be transmitted to Bunny.net to enable the delivery of the video content.
The processing is carried out for the purpose of providing and optimizing our video content. Depending on the implementation, the legal basis is either Article 6(1)(f) GDPR (our legitimate interest in providing user-friendly and efficient video delivery) or, where videos are only loaded after your consent, Article 6(1)(a) GDPR (your consent).
For more information about how Bunny.net processes personal data, please refer to Bunny.net's Privacy Policy: https://bunny.net/privacy/.
You have the right to information, correction, deletion or restriction of the processing of your stored data, a right to object to the processing and a right to data portability and to lodge a complaint at any time in accordance with the requirements of data protection law.
12.1 Right of Access
You can request information from us as to whether and to what extent we process your data.
12.2 Right to Rectification
If we process your data incompletely or incorrectly, you can request that we correct or complete it at any time.
12.3 Right to Erasure
You can request that we erase your data if we process it unlawfully or if the processing disproportionately interferes with your legitimate protection interests. Please note that there may be reasons that prevent immediate erasure, e.g. in the case of statutory retention or processing obligations.
Irrespective of the exercise of your right to erasure, we will erase your data immediately and completely, provided that there is no legal or statutory retention obligation to the contrary.
12.4 Right to Restriction of processing
You can request that we restrict the processing of your data if
12.5 Right to Object
If we process your data on the basis of legitimate interest, you can object to this at any time. This would also apply to profiling based on these provisions. We will then no longer process your data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms or the processing serves the establishment, exercise or defense of legal claims. You can object to the processing of your data for the purpose of direct advertising at any time without giving reasons.
12.6 Right to Data Portability
You may request that we provide you with the data you have provided to us in a structured, commonly used and machine-readable format and that you may transmit this data to another controller without hindrance from us, provided that
If technically feasible, you can request that we transfer your data directly to another controller.
12.7 Right to Lodge a Complaint with a Supervisory Authority
If you are of the opinion that we are violating German or European data protection law when processing your data, please contact us so that we can clarify any questions. Of course, you also have the right to contact the supervisory authority responsible for you, the respective state office for data protection supervision.
If you wish to assert one of these rights against us, please contact our data protection officer. In case of doubt, we may request additional information to confirm your identity.
12.8 Right to Withdraw Consent
If we process your data on the basis of consent, you can withdraw this consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
12.9 Automated individual decision-making, including profiling
You have the right not to be subject to a decision based solely on automated processing - including profiling - which produces legal effects concerning you or similarly significantly affects you.