App Privacy Policy
Version: October 2024
We, NEWWORK Software SE together with our subsidiaries (hereinafter collectively referred to as “the company”, “we” or “us”), take the protection of your personal data seriously and would like to inform you here about data protection when using the “Every” app (hereinafter referred to simply as the “app”).
Where we determine the purposes and means of data processing, either alone or jointly with others, this includes, in particular, the obligation to provide you with transparent information about the nature, scope, purpose, duration and legal basis of the processing (see Articles 13 and 14 GDPR). This statement (hereinafter referred to as the “Privacy Policy”) informs you how we process your personal data in connection with your use of the app.
A. General Information
1. Definitions
Following Article 4 GDPR, this Privacy Policy is based on the following definitions:
– “Personal data” (Article 4(1) GDPR) means any information relating to an identified or identifiable natural person (“data subject”). A person is identifiable if they can be identified directly or indirectly, in particular by reference to an identifier such as a name, an identification number, an online identifier, location data or information about factors specific to their physical, physiological, genetic, mental, economic, cultural or social identity. Identifiability may also arise from combining such information or other additional knowledge. How the information originates, its form or the medium in which it is recorded is immaterial (photographs, video or audio recordings may also contain personal data).
– “Processing” (Article 4(2) GDPR) means any operation involving personal data, whether or not by automated (i.e. technology-assisted) means. This includes, in particular, collection (i.e. obtaining data), recording, organisation, structuring, storage, adaptation or alteration, reading, retrieval, use, disclosure by transmission, dissemination or otherwise making available, alignment, combination, restriction, erasure or destruction of personal data, as well as any change to the objective or purpose originally underlying the data processing.
– “Controller” (Article 4(7) GDPR) means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
– “Third party” (Article 4(10) GDPR) means any natural or legal person, public authority, agency or other body other than the data subject, the controller, the processor and persons who, under the direct authority of the controller or processor, are authorised to process the personal data; this also includes other legal entities within the same group.
– “Processor” (Article 4(8) GDPR) means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller, in particular in accordance with the controller’s instructions (e.g. an IT service provider). In particular, a processor is not a third party for the purposes of data protection law.
– “Consent” of the data subject (Article 4(11) GDPR) means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which they, by a statement or other clear affirmative action, signify agreement to the processing of personal data relating to them.
2. Changes to the Privacy Policy
(1) As data protection law develops and technological or organisational changes occur, particularly in our app, we regularly review our Privacy Policy to determine whether amendments or additions are required. You will be informed of any changes.
3. No Obligation to Provide Personal Data
We do not make entering into contracts with us conditional on your providing us with personal data beforehand. As a customer, you are generally under no statutory or contractual obligation to provide us with your personal data; however, we may only be able to provide certain services to a limited extent or not at all if you do not provide the data required for them. If, exceptionally, this applies to any of the products we offer as described below, you will be notified separately.
B. Information on the Processing of Your Data
1. Collection of Personal Data Relating to You
(1) When you use our app, we collect personal data about you.
(2) Personal data means all data relating to you as an individual (see General Information above). For example, your name, location data, IP address, device identifier, SIM card number, postal address and email address are personal data.
2. Legal Bases for Data Processing
(1) As a matter of law, any processing of personal data is prohibited in principle and is permitted only if it falls within one of the following legal bases:
– Article 6(1), first sentence, point (a) GDPR (“consent”): where the data subject has freely, in an informed and unambiguous manner, indicated by a statement or other clear affirmative action that they agree to the processing of personal data relating to them for one or more specific purposes;
– Article 6(1), first sentence, point (b) GDPR: where processing is necessary for the performance of a contract to which the data subject is a party or in order to take steps at the data subject’s request prior to entering into a contract;
– Article 6(1), first sentence, point (c) GDPR: where processing is necessary for compliance with a legal obligation to which the controller is subject (e.g. a statutory retention obligation);
– Article 5(1), first sentence, point (d) GDPR: where processing is necessary in order to protect the vital interests of the data subject or of another natural person;
– Article 6(1), first sentence, point (e) GDPR: where processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller; or
– Article 6(1), first sentence, point (f) GDPR (“legitimate interests”): where processing is necessary for the purposes of the legitimate interests (in particular legal or economic interests) pursued by the controller or a third party, unless the opposing interests or rights of the data subject override those interests (in particular where the data subject is a minor).
The storage of information on an end user’s terminal equipment, or access to information already stored on that terminal equipment, is permitted only if covered by one of the following legal bases:
– Section 25(1) TDDDG: where the end user has given consent on the basis of clear and comprehensive information. Consent must be given in accordance with Article 6(1), first sentence, point (a) GDPR;
– Section 25(2), point 1 TDDDG: where the sole purpose is to carry out the transmission of a communication over a public telecommunications network; or
– Section 25(2), point 2 TDDDG: where the storage or access is strictly necessary for the provider of a telemedia service to provide a telemedia service expressly requested by the user.
(2) Below, we specify the applicable legal basis for each processing operation we carry out. Processing may also be based on more than one legal basis.
3. Data Collected When Downloading the App
(1) When you download this app, certain data relating to you that are required for the download are transmitted to the relevant app store (e.g. Apple App Store or Google Play).
(2) In particular, the email address, username and customer number of the account used for the download, the individual device identifier, payment information and the time of the download are transmitted to the app store when the app is downloaded.
(3) We have no influence over the collection and processing of these data; these activities are carried out exclusively by the app store you select. Accordingly, we are not responsible for this collection and processing; responsibility lies solely with the app store. Information about how the app store operators process your personal data can be found in the privacy policies provided there by the respective operators.
4. Data Collected During Use
(1) To make the benefits of our app available to you, we necessarily need to collect certain data relating to you during use that are required for the operation of the app.
(2) We collect these data only where this is necessary for the performance of the contract between you and us (Article 6(1)(b) GDPR). We also collect these data where this is necessary for the app to function and your interest in protecting your personal data does not take precedence (Article 6(1)(f) GDPR), or where you consent to their collection and processing (Article 6(1)(a) GDPR).
(3) We collect and process the following data relating to you:
– Device information: Access data include the IP address, device ID, device type, device-specific settings and app settings, as well as the date and time of access, the time zone, the volume of data transferred and a notification of whether the data exchange was completed and, where applicable, data about app crashes. These access data are processed to enable the technical operation of the app
– Data you provide to us: A user account must be created to use the app. For this purpose, you must provide at least your login name. We also process your employee master data (such as name, address, job title, position, etc.).
– Information processed with your consent: We process other information (e.g. camera images) if you permit us to do so.
– Contact form data: When contact forms are used, the data submitted through them are processed (e.g. gender, surname and first name, address, company, email address and the time of submission).
(4) Where processing the data requires information to be stored on your terminal equipment or access to information already stored on that terminal equipment, the legal basis is Section 25(1) and (2) TDDDG.
(5) When you register for our app, single sign-on access is created through Keycloak. Keycloak is an open-source identity and access management solution designed to secure modern applications and services. Further information about Keycloak is available at https://www.keycloak.org. The following personal data are processed during registration: email address. These data are processed to identify users for access control purposes. Processing these data is necessary for the performance of the contract so that you can use our app. The legal basis for processing is Article 6(1)(b) GDPR.
5. Use of Cookies
(1) We use cookies in the operation of our app. Cookies are small text files that are placed in the memory of your mobile device and stored in association with the mobile app you use. They provide certain information to the entity that sets the cookie. Cookies cannot execute programs or transmit viruses to your computer and therefore cannot cause damage. They are used to make our app more user-friendly and effective overall, and thus more convenient for you.
(2) Cookies may contain data that enable the device used to be recognised. In some cases, however, cookies contain only information about certain settings that cannot be linked to a person. Cookies cannot directly identify a user.
(3) A distinction is made between session cookies, which are deleted when you close your browser, and persistent cookies, which remain stored beyond an individual session. In terms of their function, a further distinction is made between:
– Technical cookies: these are strictly necessary to navigate within the app, use basic functions and ensure the security of the app; they neither collect information about you for marketing purposes nor record which websites you have visited;
– Performance cookies: these collect information about how you use our app, which pages you visit and, for example, whether errors occur when using the app; they do not collect information that could identify you — all information collected is anonymous and is used only to improve our app and to find out what interests our users;
– Advertising cookies, targeting cookies: these are used to provide app users with relevant advertising within the app or offers from third parties and to measure the effectiveness of these offers; advertising and targeting cookies are stored for a maximum of 13 months;
– Sharing cookies: these are used to improve the interactivity of our app with other services (e.g. social networks); sharing cookies are stored for a maximum of 13 months.
(4) The legal basis for cookies that are strictly necessary to provide you with the service you have expressly requested is Section 25(2), point 2 TDDDG.
(5) Any use of cookies that is not strictly necessary for technical reasons constitutes data processing that is permitted only with your express and active consent pursuant to Section 25(1) TDDDG in conjunction with Article 6(1), first sentence, point (a) GDPR. This applies in particular to the use of performance, advertising, targeting or sharing cookies. Furthermore, we disclose your personal data processed through cookies to third parties only if you have given your express consent under Article 6(1), first sentence, point (a) GDPR.
6. Cookie Policy
No cookies or similar tracking measures are currently used.
7. Data Retention Period
(1) We erase your personal data as soon as they are no longer necessary for the purposes for which we collected or used them. As a rule, we retain your personal data for the duration of the relationship arising from your use of the app or your contractual relationship relating to the app.
(2) However, data may be retained beyond the period specified in the event of an actual or threatened legal dispute with you or other legal proceedings.
(3) Third parties engaged by us will store your data on their systems for as long as necessary in connection with providing their services to us in accordance with the respective assignment.
(4) Statutory requirements governing the retention and erasure of personal data remain unaffected by the above (e.g. Section 257 HGB or Section 147 AO). When the retention period prescribed by law expires, the personal data will be blocked or erased unless we need to retain them further and there is a legal basis for doing so.
8. Data Security
We use appropriate technical and organisational security measures to protect your data against accidental or intentional manipulation, partial or complete loss, destruction or unauthorised access by third parties, taking into account the state of the art, implementation costs, the nature, scope, context and purpose of the processing, and the risks of a data breach (including its likelihood and consequences) for the data subject. Our security measures are continually improved in line with technological developments.
9. No Automated Decision-Making (Including Profiling)
We do not intend to use personal data collected from you for an automated decision-making process (including profiling).
10. Change of Purpose
(1) Your personal data will be processed for purposes other than those described only where this is permitted by law or where you have consented to the changed purpose of the data processing.
(2) If data are further processed for purposes other than those for which they were originally collected, we will inform you of those other purposes before the further processing takes place and provide you with all other relevant information.
C. Responsibility for Your Data and Contact Details
1. Controller, Contact Details and Data Protection Officer
(1) We, NewWork Software SE, Hofwiesenstraße 14, 08527 Plauen (E: info@newwork.com; T: +49 (0) 30 23590473), are the controller responsible for processing your personal data within the meaning of Article 4(7) GDPR.
(2) The contact details of our data protection officer are:
privacy@newwork.com
resource Software AG
Rübgrund 19
64347 Griesheim.
2. Data Collection When You Contact Us
(1) If you contact us by email or via a contact form, we store your email address, your name and any other personal data you provide when contacting us so that we can contact you to answer your enquiry.
(2) We erase these data as soon as storage is no longer necessary. Where statutory retention periods apply, the data remain stored, but we restrict their processing.
D. Data Processing by Third Parties
1. Processing on Our Behalf
(1) We may engage service providers for individual functions of our app. Like any larger company, we also use external service providers in Germany and abroad to conduct our business (e.g. in IT, logistics, telecommunications, sales and marketing). They act only on our instructions and have been contractually obliged to comply with data protection provisions within the meaning of Article 28 GDPR.
(2) We currently use the following service providers to provide our app:
– External hosting: We use “Microsoft Azure”, a service provided by Microsoft Corporation (hereinafter referred to simply as “Microsoft USA”), One Microsoft Way, 98052-6399 Richmond WA, United States of America, for the external hosting of our app (Microsoft USA has obtained certification under the EU-US Data Privacy Framework, available at https://www.dataprivacyframework.gov/list); however, our app is hosted exclusively in data centres of Microsoft Ireland Operations Ltd. One Microsoft Place, South Country Business Park, Leopardstown, Dublin 18, D18 P521, Ireland, within the European Union. The legal basis for data processing is Article 6(1)(f) GDPR. Our legitimate interest is the error-free functioning of our app. We have entered into an agreement with the provider for the processing of personal data on our behalf pursuant to Article 28 GDPR. Further information about Microsoft Azure Cloud is available in the provider’s privacy policy: https://www.microsoft.com/de-de/trust-center.
– Data conversion: We use Kafka, an open-source application of the Apache Software Foundation, for data conversion; in this case, however, the service is offered and operated by Microsoft USA (for further details about the provider, see “External hosting”). The service is software that we use to process data streams. It stores and processes these data streams and provides an interface for loading and exporting them to third-party systems. The legal basis for data processing is Article 6(1)(f) GDPR. Our legitimate interest is the error-free functioning of our app. We have entered into an agreement with the provider for the processing of personal data on our behalf pursuant to Article 28 GDPR;
– Database: We use MongoDB as our database service, a service provided by Mongo DB, Inc., 1633 Broadway, 38th Floor, New York, NY 10019, USA (hereinafter referred to simply as “MongoDB USA”); in this case, however, it is offered and distributed by Microsoft Irland (for further details about the provider, see “External hosting”).
The legal basis for data processing is Article 6(1)(f) GDPR. Our legitimate interest is the error-free functioning of our app. The databases managed through MongoDB are located on European servers in Microsoft Azure Cloud (for further details and information about the existence of an agreement for processing on our behalf within the meaning of Article 28 GDPR, see the explanation under “External hosting”).
– Voice assistant: Our integrated AI-powered voice assistant uses a chat function from Microsoft Arzure OpenAI (hereinafter referred to simply as “Azure OpenAI”). This service is operated by Microsoft Ireland Operations Ltd., One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland, and is provided within Microsoft Azure (see the explanation under “External hosting”). Azure Open AI is based on OpenAI GPT-3 or GPT-4, Codex and DALL-E models. When the chat function is used, text messages or inputs are sent to Azure OpenAI Services. The precise content and purpose of the communication are determined by the message content you specify. As a customer, you also have the choice of whether to use our AI-powered voice assistant. Our app can also be used without this function. Data entered into the chat function are processed on Microsoft Azure servers, but only within the instances provided for us. When communicating with Azure OpenAI Services, certain data, including the texts entered, may be transmitted to Microsoft Azure to carry out the AI processing. No further disclosure to third parties takes place. Microsoft guarantees that all customer requests (inputs) and AI responses (outputs), as well as all actual customer and training data, are not available to other customers, are not available to OpenAI, are not used to improve OpenAI models, and are not used to improve Microsoft or third-party products or services. Microsoft does not use your personal data for training for third parties. To continually improve our app and the integrated AI-powered voice assistant, your inputs are used to train the Azure OpenAI model we use. The training data do not leave the Microsoft Azure instance for which we are responsible. If you have questions about your contract, the legal basis for processing your personal data when using our AI-based voice assistant is Article 6(1)(a) GDPR. The processing of your data in connection with the use of the chat function, including training the Azure OpenAI model, is also carried out under Article 6(1)(f) GDPR. Our legitimate interest is to provide you with an optimised (in particular, error-free) and personalised user experience. Microsoft provides further information on data protection matters in connection with the use of Azure OpenAI Services on the following pages: https://learn.microsoft.com/de-de/azure/ai-services/openai/faq and https://learn.microsoft.com/de-de/legal/cognitive-services/openai/data-privacy. Microsoft’s core principles for responsibility in the development and use of AI are available at https://www.microsoft.com/de-de/ai/responsible-ai.
(3) The following additional categories of recipients, who are generally processors, may have access to your personal data:
– Service providers for the operation of our app and the processing of data stored or transmitted by the systems (e.g. for data centre services, payment processing or IT security). Where these are not processors, the legal basis for disclosure is Article 6(1), first sentence, point (b) or (f) GDPR;
– Government bodies or authorities, where this is necessary to comply with a statutory obligation. In such cases, the legal basis for disclosure is Article 6(1), first sentence, point (c) GDPR;
– Persons engaged in conducting our business operations (e.g. auditors, banks, insurers, legal advisers, supervisory authorities, parties involved in company acquisitions or the establishment of joint ventures). In such cases, the legal basis for disclosure is Article 6(1), first sentence, point (b) or (f) GDPR.
(4) Apart from this, we disclose your personal data to third parties only if you have given your express consent under Article 6(1), first sentence, point (a) GDPR.
(5) Where we disclose your personal data to our subsidiaries, or our subsidiaries disclose them to us (e.g. for advertising purposes), this takes place on the basis of existing arrangements for processing on behalf of a controller.
2. Conditions for Transferring Personal Data to Third Countries
(1) In the course of our business relationships, your personal data may be transferred or disclosed to third-party companies. These companies may also be located outside the European Economic Area (EEA), i.e. in third countries. Such processing takes place exclusively to fulfil contractual and business obligations and to maintain your business relationship with us (the legal basis is Article 6(1)(b) or (f), in each case in conjunction with Article 44 et seq. GDPR). Your personal data are currently not transferred to any third country.
3. Statutory Obligation to Transfer Certain Data
In certain circumstances, we may be subject to a specific statutory or legal obligation to make lawfully processed personal data available to third parties, in particular public bodies (Article 6(1), first sentence, point (c) GDPR).
F. Your Rights
1. Right of Access
(1) You have the right to obtain from us access to personal data relating to you to the extent provided for in Article 15 GDPR.
(2) To exercise this right, you must submit a request either by email or by post to the addresses given above.
2. Right to Object to Data Processing and to Withdraw Consent
(1) Under Article 21 GDPR, you have the right to object at any time to the processing of personal data relating to you. We will cease processing your personal data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or unless the processing serves the establishment, exercise or defence of legal claims.
(2) Under Article 7(3) GDPR, you have the right to withdraw at any time any consent you have previously given to us (including consent given before the GDPR became applicable, i.e. before 25.5.2018). Consent means your freely given, informed and unambiguous indication, by a statement or other clear affirmative action, that you agree to the processing of the personal data concerned for one or more specific purposes. If you withdraw such consent, we may no longer continue, in the future, the data processing that was based on it.
(3) To do so, please contact the contact point specified above.
3. Right to Rectification and Erasure
(1) Where personal data relating to you are inaccurate, you have the right under Article 16 GDPR to obtain their rectification from us without undue delay. Please submit any such request to the contact point specified above.
(2) Under the conditions set out in Article 17 GDPR, you have the right to request the erasure of personal data relating to you. Please submit any such request to the contact point specified above. In particular, you have the right to erasure where the data in question are no longer necessary for the purposes for which they were collected or processed, where the data retention period has expired, where an objection has been raised or where processing is unlawful.
4. Right to Restriction of Processing
(1) In accordance with Article 18 GDPR, you have the right to obtain from us restriction of the processing of your personal data.
(2) Please submit any such request to the contact point specified above.
(3) In particular, you have the right to restriction of processing where the accuracy of the personal data is disputed between you and us; in this case, the right applies for the period required to verify their accuracy. The same applies where it remains disputed between you and us whether a right to object has been successfully exercised. In addition, this right applies in particular where you have a right to erasure and request restricted processing instead of erasure.
5. Right to Data Portability
(1) In accordance with Article 20 GDPR, you have the right to receive from us the personal data relating to you that you have provided to us, in a structured, commonly used and machine-readable format.
(2) Please submit any such request to the contact point specified above.
6. Right to Lodge a Complaint with a Supervisory Authority
Under Article 77 GDPR, you have the right to lodge a complaint with a competent supervisory authority concerning the collection and processing of your personal data.
