Back to the cookie settings

Data protection

Data protection

1. Data protection at a glance

General information

The following information provides a basic overview of what happens with your personal data when you visit this website. Personal data refers to all data which allows you to be personally identified. For detailed information on the topic of data protection, please refer to our privacy notice, which you will find below this text.

Data collection on this website

Who is responsible for data collection on this website?

The processing of data on this website is performed by the website operator. You will find the operator's contact information in this website's legal notice.

How do we collect your data?

For one, your data is collected when you provide it to us. This includes, for example, the data you enter in a contact form.

Other data is collected automatically or with your consent by our IT systems when you visit the website. Above all, this includes technical data (e.g., Internet browser, operating system, or time of the page request). The collection of this data takes place automatically as soon as you enter the website.

What do we use your data for?

Some of the data is collected to ensure that the website is error-free. Other data may be used to analyze user behavior.

What rights do you have with regard to your data?

You have the right to obtain information on the origin, recipient, and purpose of the personal data stored about you, at any time and at no cost. You also have the right to request the rec-tification or erasure of this data. If you have given your consent to data processing, you can withdraw this consent at any time for the future. In addition, under certain circumstances, you also have the right to request the restriction of processing of your personal data. Further-more, you are also entitled to lodge a complaint with the competent supervisory authority.

For inquiries regarding this as well as other questions on the topic of data protection, you can contact us at any time via the address specified in the legal notice.

Analysis tools and tools from third-party providers

When you visit this website, your surfing behavior may be statistically evaluated. This is mainly done with the help of analysis programs.

Detailed information on these analysis programs can be found in the following privacy notice.

2. Hosting and Content Delivery Networks (CDN)

External hosting

This website is hosted by an external service provider (hoster). The personal data collected on this website is stored on the hoster's servers. In particular, this data may include IP ad-dresses, contact requests, meta and communication data, contract data, contact details, names, website access data, and other data generated via a website.

The hoster is used for the purpose of contract fulfillment with our potential and existing cus-tomers (Art. 6(1)(b) GDPR) and in the interest of a secure, fast, and efficient provision of our online offering by a professional provider (Art. 6(1)(f) GDPR).

Our hoster will process your information only to the extent necessary to fulfill its obligations and will follow our instructions with respect to such information.

Conclusion of a data processing agreement

In order to ensure data protection-compliant processing, we have concluded a data pro-cessing agreement with our hoster.

3. General and mandatory information

Data protection

The operators of this website take the protection of your personal data extremely seriously. We handle your personal data in strict confidence and in compliance with statutory data protection regulations, as well as according to this privacy notice.

When you use this website, various forms of personal data are collected. Personal data refers to data which allows you to be personally identified. This privacy notice explains which data we collect and what we use it for. It also explains how and for what purpose this takes place.

We would like to point out that data transmission on the Internet (e.g., during communica-tions via e-mail) may have security gaps. Absolute protection of data against access by third parties is not possible.

Information on the controller

Controller pursuant to data protection laws:

nicos cyber defense GmbH
Thomas Brosch, Dipl.-Kfm. Robert Holm
Robert-Bosch-Str. 17a
48153 Münster
Germany

Phone: +49 251 986 33-0
E-mail: info@nicos-cdc.com

The controller is the natural or legal person who, alone or jointly with others, decides on the purposes and means of the processing of personal data (e.g., names, e-mail addresses, or similar).

Withdrawal of your consent for data processing

Many data processing operations are only possible with your express consent. You may with-draw consent that was previously given at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.

Right to object to data collection in special cases, as well as to direct marketing (Art. 21 GDPR)

WHEN DATA PROCESSING TAKES PLACE BASED ON ART. 6(1)(E) OR (F) OF THE GDPR, YOU HAVE THE RIGHT TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA AT ANY TIME DUE TO REASONS ARISING FROM YOUR SPECIAL SITUATION; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. FOR THE RESPECTIVE LEGAL BASIS ON WHICH PROCESSING IS BASED, PLEASE REFER TO THIS PRIVACY NOTICE. WHEN YOU OBJECT, WE WILL NO LONGER PROCESS THE PERSONAL DATA OF YOURS IN QUESTION, UNLESS WE ARE ABLE TO DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING WHICH OVERRIDE YOUR INTERESTS, RIGHTS, AND FREEDOMS OR FOR THE ESTABLISHMENT, EXERCISE, OR DEFENSE OF LEGAL CLAIMS (OBJECTION IN ACCORDANCE WITH ART. 21(1) GDPR).

IF YOUR PERSONAL DATA IS PROCESSED FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR SUCH MARKETING; THIS ALSO APPLIES TO PROFILING TO THE EXTENT THAT IT IS RELATED TO SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL SUBSEQUENTLY NO LONGER BE USED FOR DIRECT MARKETING PURPOSES (OBJECTION IN ACCORDANCE WITH ART. 21(2) GDPR).

Right to lodge a complaint with the competent supervisory authority

In cases of violations of the GDPR, data subjects are entitled to lodge a complaint with a su-pervisory authority, in particular in the member state of their habitual residence, place of work, or place of the alleged infringement. The right to lodge a complaint shall exist without prejudice to other administrative law or judicial remedy.

Right to data portability

You have the right to have data which we automatically process based on your consent or as part of the fulfillment of a contract handed over to you or a third party in a commonly used, machine-readable format. If you request direct transmission of the data to another controller, this shall only take place where technically feasible.

SSL and TLS encryption

For security reasons and to protect the transmission of confidential content, such as orders or inquiries which you send to us, the website operators, this website utilizes SSL and/or TLS encryption. You can identify an encrypted connection by the fact that the address bar of the browser changes from "http://" to "https://" and a lock symbol appears in your browser's ad-dress bar.

When SSL and/or TLS encryption is activated, the data that you transmit to us cannot be read by third parties.

Information, erasure, and rectification

According to prevailing statutory provisions, you have the right, at any time and at no cost, to obtain information on the personal data stored about you, its origin and recipient, the pur-pose of the data processing, and where applicable, the right to have this data rectified or erased. For inquiries regarding this as well as other questions on the topic of personal data, you can contact us at any time via the address specified in the legal notice.

Right to restriction of processing

You have the right to request the restriction of the processing of your personal data. To do so, you can contact us at any time at the address given in the legal notice. The right to restriction of processing exists in the following cases:

  • If you dispute the accuracy of your personal data stored by us, we generally need time to check this. For the duration of the review, you have the right to request that the processing of your personal data be restricted.
  • If the processing of your personal data was/is carried out unlawfully, you can request the restriction of data processing instead of erasure.
  • If we no longer need your personal data, but you need it for the exercise, defense or assertion of legal claims, you have the right to request the restriction of the processing of your personal data instead of deletion.
  • If you have lodged an objection pursuant to Art. 21 (1) GDPR, a balance must be struck between your interests and ours. As long as it has not yet been determined whose interests prevail, you have the right to request the restriction of the processing of your personal data.

If you have restricted the processing of your personal data, this data - apart from its storage - may only be processed with your consent or for the establishment, exercise or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the European Union or of a Member State.

Objection to advertising e-mails

We hereby object to the use of contact data published as part of our obligation to provide a legal notice for the purpose of sending unsolicited advertising and information material. The operators of this website expressly reserve the right to take legal action in the event of the unsolicited sending of advertising information, such as spam e-mails.

4. Data collection on this website

Cookies

Our website uses cookies. Cookies are small text files and do not cause any damage to your end device. They are stored on your device either temporarily for the duration of a session (session cookies) or permanently (permanent cookies). Session cookies are automatically deleted at the end of your visit. Permanent cookies remain stored on your device until you delete them yourself or they are automatically deleted by your web browser.

In certain cases, cookies from third-party companies may also be stored on your device when you visit our website (third-party cookies). These enable us or you to use certain services of the third-party company (e.g., cookies for processing payment services).

Cookies have various functions. Many cookies are technically necessary, as certain website functions would not work without them (e.g., the shopping cart function or the displaying of videos). Other cookies are used to evaluate user behavior or display advertising.

Cookies that are required to carry out the electronic communication process (necessary cook-ies) or to provide certain functions that you have requested (functional cookies, e.g., for the shopping cart function) or to optimize the website (e.g., cookies to assess the web audience) are stored on the basis of Art. 6(1)(f) GDPR, unless another legal basis is specified. The web-site operator has a legitimate interest in the storage of cookies in order to provide its ser-vices in a technically faultless and optimized manner. If consent to the storage of cookies has been requested, the cookies in question are stored exclusively on the basis of this consent (Art. 6(1)(a) GDPR); consent may be withdrawn at any time.

You can configure your browser to notify you when a cookie is placed, to accept cookies only in specific instances, to reject cookies in certain instances or in general, and to automatically delete cookies when you close your browser. If cookies are deactivated, the functionality of this website may be limited.

If cookies are used by third parties or for analysis purposes, we will inform you separately of this in this privacy notice and ask for your consent where necessary.

Contact form

When you send us inquiries via a contact form, we will save your information from the inquiry form including the contact data you have specified in it for the purpose of processing the in-quiry and in case of follow-up questions. We will not disclose this data without your consent.

The processing of this data takes place based on Art. 6(1)(b) GDPR in cases where your inquiry is related to the fulfillment of a contract or is necessary to perform pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective processing of inquiries addressed to us (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR), provided it was previously requested.

The data you enter into the contact form remains with us until you request its deletion, with-draw your consent for its storage, or the purpose for storing the data no longer exists (e.g., after processing of your inquiry is complete). Mandatory legal regulations—in particular re-tention periods—remain unaffected.

Inquiries via e-mail, telephone, or fax

When you contact us via e-mail, telephone, or fax, we will store and process your inquiry including all the resulting personal data (name, inquiry) for the purposes of processing your concern. We will not disclose this data without your consent.

The processing of this data takes place based on Art. 6(1)(b) GDPR in cases where your inquiry is related to the fulfillment of a contract or is necessary to perform pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective processing of inquiries addressed to us (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR), provided it was previously requested.

The data you transmit to us via contact inquiries remains with us until you request its deletion, withdraw your consent for its storage, or the purpose for storing the data no longer ex-ists (e.g., after processing of your inquiry is complete). Mandatory legal regulations—in par-ticular statutory retention periods—remain unaffected.

5. Analysis tools and advertising

Google Analytics

This website utilizes functions of the web analytics service Google Analytics. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.

Google Analytics allows the website operator to analyze the behavior of website visitors. The website operator receives various usage data, such as page views, time spent on the site, operating systems used, and user origin. This information may be aggregated by Google into a profile associated with the respective user or the user's device.

Google Analytics uses technologies that recognize users for the purpose of analyzing user behavior (e.g., cookies and device fingerprinting). The information stored by Google about the use of this website is generally transmitted to a Google server in the USA and stored there.

The use of this analytics tool takes place based on Art. 6(1)(f) GDPR. The website operator has a justified interest in the analysis of user behavior in order to optimize both its web offer-ings as well as its advertising. If corresponding consent has been requested (e.g., consent to the storage of cookies), the processing will be carried out exclusively on the basis of Art. 6(1)(a) GDPR; this consent may be withdrawn at any time.

IP anonymization

We have activated the IP anonymization feature on this website. This means that Google will truncate your IP address within member states of the European Union or in other countries which are contracting parties to the Agreement on the European Economic Area before transmission to the USA. Only in exceptional cases is the full IP address transmitted to a Google server in the USA and truncated there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website in order to compile re-ports on website activity and to provide the website operator with additional services related to website and Internet use. The IP address transmitted by your browser as part of Google Analytics will not be combined with other data from Google.

Browser plugin

You can prevent the collection and processing of your data by Google by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=de.

For more information on how Google Analytics handles user data, please refer to Google's privacy policy: https://support.google.com/analytics/answer/6004245?hl=de.

Data processing agreement

We have signed a data processing agreement with Google and fully implement the strict reg-ulations of the German data protection authorities for the use of Google Analytics.

Demographics by Google Analytics

This website uses the "Demographics" feature of Google Analytics in order to be able to dis-play suitable advertisements to website visitors within the Google advertising network. This allows reports to be compiled that contain information on the age, gender, and interests of website visitors. This data comes from interest-related advertising from Google as well as from user data from third-party providers. This data cannot be linked to any particular per-son. You can deactivate this feature at any time via the advertising settings in your Google account or generally prohibit the collection of your data by Google Analytics as described in the section "Objection to data collection."

Storage duration

Data stored by Google at user and event level that is linked to cookies, user IDs, or advertis-ing IDs (e.g., DoubleClick cookies, Android advertising ID) is anonymized or deleted after 14 months. For more details, please visit the following link: https://support.google.com/analytics/answer/7667196?hl=de

6. Plugins and tools

Google Web Fonts

This website uses web fonts provided by Google for the uniform display of fonts. These Google fonts are installed locally. No connection is established to Google servers.

Further information on Google Web Fonts can be found at https://developers.google.com/fonts/faq and in Google's privacy policy: https://policies.google.com/privacy?hl=de.

Privacy policy: nicos cyber defense recruiting page

1. Personal data in the application process

Personal data refers to information about the personal or factual circumstances of an identi-fied or identifiable natural person. This includes information such as your name, address, phone number, and date of birth, as well as information about your specific job history, etc. that can be associated with a specific person with a reasonable amount of effort. In contrast, information that is not (in)directly associated with your real identity is not personal data.

2. Basis and purposes of the processing of personal data for applications and in the application process

If you submit your application to us electronically, i.e., by e-mail or via our web form, we will collect and process your personal data for the purpose of processing your application and carrying out pre-contractual measures.  By submitting an application on our recruiting page, you express your interest in taking up employment with us. In doing so, you provide us with personal information that we will use and store solely for the purpose of your job search/application.  In particular, the following data is collected:

  • Name (first and last name)
  • E-mail address
  • Phone number
  • LinkedIn profile (optional)
  • How you heard about us

You may also upload supporting documents such as a cover letter, your resume, and certifi-cates. These may contain additional personal data, such as your date of birth, address, etc.  Only authorized HR personnel or those involved in the application process have access to your information.  This personal data is stored exclusively for the purpose of filling the vacant position for which you have applied.  Your data will be stored for a period of 180 days after the end of the application process. This is usually done to comply with legal obligations or to defend against any claims arising under the law. We are subsequently obliged to delete or anonymize your data. In this case, the data will be available to us only as metadata without any direct reference to your identity for sta-tistical evaluations (e.g., proportion of women or men applying, number of applications in a particular period, etc.).  In addition, we reserve the right to keep your information in our talent pool for 365 days after the end of the application process in order to identify other opportunities that may be of in-terest to you. This also includes, for example, applications for an apprenticeship or intern-ship. By accepting the privacy notice, you consent to further storage of your data and inclu-sion in our talent pool.  If you receive an offer of employment with us during the application process and accept it, we will store the personal data collected during the application process for at least the duration of the employment relationship.

3. Disclosure of data to third parties

The data transmitted as part of your application will be transferred using TLS encryption and stored in a database. This database is managed by Personio GmbH, which offers personnel administration and applicant management software (https://www.personio.de/impressum/). Personio is our processor in this context in accordance with Art. 28 GDPR. The basis for the processing is a data processing agreement between us as the controller and Personio.

4. Rights of data subjects

If personal data is processed by us as the controller, you as the data subject have certain rights under Chapter III of the EU General Data Protection Regulation (GDPR), depending on the legal basis and purpose of the processing.

Rights of data subjects affected by data processing

As a data subject, you are generally entitled to the following rights, provided that contractual and legal obligations do not conflict with this and the conditions specified in the individual articles are met:

  • Right of access (Art. 15 GDPR) with the restrictions according to Sections 34, 35 of the Federal Data Protection Act (BDSG), new version;
  • Right to rectification of inaccurate data (Art. 16 GDPR);
  • Right to erasure (Art. 17 GDPR) with the restrictions according to Sections 34, 35 BDSG, new version;
  • Right to restriction of processing of personal data (Art. 18 GDPR);
  • Right to data portability (Art. 20 GDPR);
  • Right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR);
  • Right to object on a case-by-case basis (Art. 21(1) GDPR) for reasons arising from your particular situation and relating to data processing in accordance with Art. 6(1)(e) GDPR and Art. 6(1)(f) GDPR. The objection can be addressed to the aforementioned contact details.

The supervisory authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW), Kavalleriestr. 2-4, 40213 Düsseldorf, phone: +49 (0)211/38424-0, e-mail:  poststelle@ldi.nrw.de

5. Final provisions

We reserve the right to amend this privacy notice at any time to ensure that it always com-plies with current legal requirements or to reflect changes in the application process, etc. If you visit this recruiting page again or submit a new application, the new privacy notice will apply.

Last updated: 01/27/2023