Data protection information

for online meetings, telephone conferences and webinars via “Microsoft Teams”of Remystahl GmbH & Co. KG

We would like to inform you below about the processing of personal data in conjunction with use of “Microsoft Teams”.

Purpose of the processing

We use the “Microsoft Teams” tool to conduct telephone conferences, online meetings, video conferences and/or webinars (hereinafter: “online meetings”). “Microsoft Teams” is a service provided by Microsoft Corporation.

Controller

The Controller for data processing directly related to the conduct of “Online Meetings” is Remystahl GmbH & Co. KG

You will find further information about our company, details of the persons authorised to represent us and also further contact options in the imprint on our website: www.remystahl.de/impressum

Note: if you access the “Microsoft Teams” website, the provider of “Microsoft Teams” is responsible for the data processing. However, accessing the “Microsoft Teams” website is only necessary to download the software to use “Microsoft Teams”.

If you do not want to or cannot use the “Microsoft Teams” app, you can also use “Microsoft Teams” via your browser. The service is then also provided via the “Microsoft Teams” website.

What data are processed?

Various types of data are processed when using “Microsoft Teams”. The scope of the data also depends on the data you provide before or during participation in an “Online Meeting”.

The following personal data are subject to processing:

User details: e.g. display name, e-mail address (if applicable), profile picture (optional) and preferred language.

Meeting metadata: e.g. date, time, meeting ID, phone numbers and location

Text, audio and video data: you may have the opportunity to use the chat function in an “Online Meeting”. In this respect, the text entries you make are processed to display them in the “Online Meeting”. To enable the display of video and the playback of audio, the data from the microphone of your terminal device and from any video camera of the terminal device are processed accordingly during the meeting. You can turn off or mute the camera or microphone yourself at any time via the “Microsoft Teams” applications.

Scope of the processing

We use “Microsoft Teams” to conduct “Online Meetings”. If we want to record “Online Meetings”, our transparent policy means we will notify you in advance and - where necessary - request your consent.

Chat content will be logged when using Microsoft Teams. We store the chat content for a period of one month. We will log the chat content if necessary for the purposes of logging the results of an online meeting. However, usually this will not be the case.

Automated decision-making within the meaning of Article 22, GDPR, is not applied.

Legal bases for the data processing

Section 26 BDSG is the legal basis for data processing insofar as personal data are processed by Remystahl GmbH & Co. KG employees. If personal data are not required for the establishment, implementation or termination of the employment relationship in conjunction with use of “Microsoft Teams”, but are nevertheless an elementary component of the use of “Microsoft Teams”, Article 6(1), point (f), GDPR, is the legal basis for data processing. In these cases, our interest lies in the effective implementation of “Online Meetings”.

In other respects, the legal basis for data processing when conducting “Online Meetings” is Article 6(1), point (b), GDPR, insofar as the meetings are conducted within the framework of contractual relationships.

Article 6(1), point (f), GDPR, is the legal basis if there is no contractual relationship. Our interest lies in effectively conducting “Online Meetings” in this case as well.

Recipients / forwarding of data

As a matter of principle, personal data that are processed via participation in “Online Meetings” are not forwarded to third parties provided they are not, in particular, intended for forwarding. Please note that content from “Online Meetings” and in the case of personal meetings used for discussions frequently serve the purpose of communicating information to customers, interested parties or third parties and are therefore earmarked for forwarding.

Other recipients: the provider of “Microsoft Teams” needs to gain knowledge of the above-mentioned data, insofar as this is provided for in the context of our order processing agreement with “Microsoft Teams”.

Data processing outside the European Union

“Microsoft Teams” is a service rendered by a provider from the USA. It cannot be ruled out therefore that the processing of personal data also takes place in a third country. We have entered into an order processing agreement with the provider of “Microsoft Teams” that complies with the requirements of Article 28, GDPR.

An appropriate level of data protection is guaranteed on the one hand by entering into the so-called EU standard contractual clauses. As a supplementary protective measure, we have also configured our teams in such a way that only data centres in the EU, the EEA or secure third countries such as Canada or Japan are used to conduct “Online Meetings”.

However, we cannot exclude that this service may transfer data outside the European Union and the European Economic Area and to a country that does not offer an adequate level of data protection. If the data are transferred to the USA, there is a risk that your data may be processed by US authorities for control and monitoring purposes without you possibly having any legal remedy.

However, the data are encrypted during forwarding via the internet and are therefore usually protected against unauthorised access by third parties.

Data protection officer

We have appointed a data protection officer.

You can reach the data protection officer as follows:

bits + bytes it-solutions GmbH & Co. KG

-Data Protection Officer-

Hommeswiese 136

D-57258 Freudenberg

E-mail: datenschutz@remove-this.bits-bytes.de

Your rights as a data subject

You have a right to obtain information about your personal data. You can contact us at any time to obtain information.

In the case of a request for information that is not made in writing, we hope you will understand that we may require proof from you that you are the person you claim to be.

Furthermore, you have the right to correction or erasure or the restriction of the processing, insofar as you are entitled to this by law.

Ultimately, you have a right to object to processing as part of the statutory requirements.

A right to data portability similarly applies as part of data protection law.

Erasing data

We erase personal data when there is no need for further storage. A requirement may apply, in particular, if the data are still needed to honour contractual services, review and grant or ward off warranty claims and, where applicable, guarantee claims. In the case of statutory retention obligations, erasure will only be considered following expiry of the respective storage obligation.

Right to lodge a complaint with a supervisory authority

You have the right to lodge a complaint with a supervisory authority for data protection about our processing of personal data.

Amending this data protection policy

We revise this data protection policy in the event of changes to data processing or other occasions that render such action necessary. You will find the respective, valid, version on this website at all times.