Privacy Policy

Controller

The controller responsible for the processing of personal data in connection with this website is:

Information Factory AG
Förrlibuckstrasse 10
8005 Zurich
Switzerland
Email: info@information-factory.com
Phone: +41 (0)43 268 39 39

In this privacy policy, Information Factory Group AG is referred to as “Information Factory”, “we” or “us”.

Contact for data protection enquiries

If you have questions about the processing of your personal data or wish to exercise your rights, you can reach us at dsb@information-factory.com.

Our Data Protection Officer is:

Michael Sörgel, somitec
Marktplatz 30
91207 Lauf a.d. Pegnitz
Germany
Email: m.soergel@somitec.de

Scope and applicable data protection law

This privacy policy applies to the website information-factory.com including its German and English pages, as well as to the contact, whitepaper and application functions offered through it. Supplementary privacy information may apply to individual external services.

We process personal data in accordance with the Swiss Federal Act on Data Protection (FADP) and – where applicable – the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and the German Telecommunications Digital Services Data Protection Act (TDDDG).

Personal data is any information relating to an identified or identifiable natural person. This includes, for example, name, contact details, IP address and application documents.

Accessing the website and server logs

When you access our website, your browser transmits technically necessary data to our web server. This may include in particular:

  • the IP address of the requesting device,
  • the date and time of the request,
  • the page or file accessed,
  • the previously visited page, if transmitted by your browser,
  • browser type, browser version and operating system,
  • HTTP status code and volume of data transferred.

We process this data in order to deliver the website, to ensure its stability and security, to analyse errors and to prevent abusive access. Where the GDPR applies, the processing is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure and functional operation of the website.

Server logs are generally deleted after 14 days. In the event of a specific security incident, the affected log data may be retained for longer until the incident has been investigated and claims have been enforced or defended against.

For hosting and technical support we use carefully selected service providers who process data only in accordance with our instructions or contractual agreements.

Contacting us

You can contact us by email, by telephone or via the contact form. In doing so, we process the data you provide. In the contact form this is in particular your form of address, company, first and last name, telephone number, email address, message and preferred method of contact.

We use this data to process your enquiry, to respond to you and, where applicable, to carry out pre-contractual or contractual measures. Where the GDPR applies, the processing is based on Art. 6(1)(b) GDPR for contract-related enquiries and on Art. 6(1)(f) GDPR for other business enquiries. Our legitimate interest lies in handling and documenting business communication.

If another Information Factory company is responsible for your enquiry in terms of subject matter or location, we may forward the enquiry to that company within the group. Only the data required to handle the enquiry is transmitted.

We generally delete general enquiries no later than twelve months after they have been finally dealt with. Contract-related or accounting-related communication is retained in accordance with the statutory retention obligations.

The information marked as mandatory is required in order for us to deal with your enquiry properly. Without this information we cannot process the form.

Whitepapers and requested information

If you request a whitepaper, a study or further information, we process in particular your first and last name, your business email address and the areas of interest you have specified. We use this data to provide the requested material and to answer any related queries.

Where the GDPR applies, the processing is based on Art. 6(1)(b) or Art. 6(1)(f) GDPR, depending on the nature of the request. Our legitimate interest lies in dealing with specific information requests.

The data is generally deleted no later than twelve months after the material has been provided and the communication has been concluded, unless statutory retention obligations apply. The data is used for regular marketing communication only if you have given separate consent to this.

Information about studies and developments

If you select the voluntary option to be informed about current studies and developments, we use your email address and, where applicable, your name and the areas of interest you have specified in order to send you corresponding messages.

Where the GDPR applies, the processing is based on your consent pursuant to Art. 6(1)(a) GDPR. We confirm the registration by email so that ownership of the address provided can be documented. You may withdraw your consent at any time with effect for the future, in particular via the unsubscribe link in every message or by email to dsb@information-factory.com. The lawfulness of the processing carried out up to the point of withdrawal remains unaffected.

Following withdrawal, we will no longer use your data for this purpose. We may retain evidence of the consent given for as long as this is necessary to fulfil our accountability obligations or to defend against claims.

Protection against automated submissions

Our forms use a locally operated image CAPTCHA in order to prevent automated submissions and abuse. This involves processing the character string you enter together with the technical connection data that arises in any event when the form is accessed. No transfer to an external CAPTCHA provider takes place.

Where the GDPR applies, the processing is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in protecting our forms and systems against spam and automated attacks.

Cookie consent with Cookiebot

We use the consent management platform “Cookiebot” on our website. This is a service provided by Usercentrics A/S, Havnegade 39, 1058 Copenhagen, Denmark.

Cookiebot enables us to obtain your consent to the storage of certain cookies on your device or to the use of certain technologies, and to document that consent in a manner compliant with data protection law. When you visit our website, a connection to the servers of Usercentrics is established. In this process your IP address, browser data, the URL from which the consent was sent and your consent status (yes/no) are processed.

Cookiebot is used in order to obtain the legally required consent for the use of cookies. Where the GDPR applies, this is based on Art. 6(1)(c) GDPR (compliance with a legal obligation). Your consent declaration is stored for 12 months so that we do not have to ask again when you visit our website again and so that we can comply with our obligation to provide evidence.

OpenStreetMap

We embed map material from the “OpenStreetMap” service on our website in order to present the geographical location of our company sites in a visually appealing way and to make it easier for you to find our offices.

OpenStreetMap is an open source project of the OpenStreetMap Foundation, St John’s Innovation Centre, Cowley Road, Cambridge, CB4 0WS, United Kingdom (hereinafter “OSM”).

When you access a page of our website on which an OpenStreetMap map is embedded, your browser establishes a direct connection to the servers of OSM. In this process the data required to display the map (the so-called map tiles) is loaded from the OSM servers. As part of this technical process, personal data – in particular your IP address as well as information about your browser and your operating system – is transmitted to OSM. We have no influence over this data transfer.

OpenStreetMap is used on the basis of your consent pursuant to Art. 6(1)(a) GDPR. You may withdraw your consent at any time with effect for the future via our cookie and privacy settings.

Further information on the handling of user data can be found in the OpenStreetMap privacy policy at: osmfoundation.org.

Google Analytics 4

With your consent, we use Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics helps us to understand how our website is used and which content should be improved.

This may involve processing information about the pages accessed, events and interactions, approximate geographical region, referrer, session duration as well as browser and device data. Google Analytics uses identifiers to distinguish between browsers and sessions, which may be stored in cookies. The specific cookies used and their lifetimes are shown in the cookie settings.

For access from the European Union, Switzerland and the United Kingdom, Google states that it uses the IP address to derive an approximate region and discards it before logging. The IP address is nevertheless transmitted to Google for technical reasons.

Google Analytics is activated only after you have given your consent. Where the TDDDG applies, the storage of, or access to, information on your terminal equipment is based on Section 25(1) TDDDG. The further processing of personal data is based on Art. 6(1)(a) GDPR. You may withdraw or change your consent at any time with effect for the future via the permanently accessible “Cookie settings” link.

We have set the retention period for user and event data in Google Analytics to two months. Aggregated reports may remain available for longer. We have deactivated Google Signals, the advertising personalisation features and the link to Google Ads.

Google may also process data on servers outside Switzerland and the European Economic Area, in particular in the USA. Where necessary, Google bases such transfers on the applicable adequacy decisions or certifications and, in addition, on standard contractual clauses. Further information can be found in Google’s privacy policy.

Applications and Recruitee

Responsible company

The controller responsible for processing your application data is generally the Information Factory company that has advertised the position or that is named to you as a potential employer during the application process:

  • Information Factory AG, Förrlibuckstrasse 10, 8005 Zurich, Switzerland;
  • Information Factory Deutschland GmbH, Äussere Bayreuther Strasse 59, 90409 Nuremberg, Germany;
  • Information Factory Unipessoal Lda, R. dos Heróis e dos Mártires de Angola 21, 4000-285 Porto, Portugal.

In the case of a speculative application covering more than one location, Information Factory Group AG initially receives your application and forwards it only to those companies for which your application may be relevant according to the locations and areas of activity you have specified.

Data processed and purposes

We process the data you provide to us during the application process. This may include in particular:

  • name, email address, telephone number and place of residence,
  • CV, cover letter, references and other documents,
  • qualifications, professional experience and language skills,
  • work authorisation, possible starting date and salary expectations,
  • communication, interview notes and assessments during the selection process.

A photograph and your date of birth are not required for your application. If you voluntarily provide such information, it will be processed together with the remaining application documents.

We use the data to conduct the application procedure, to assess your suitability, to communicate with you, to prepare a possible employment relationship and to defend against or assert legal claims.

Legal bases

Where the GDPR applies, the processing is based on Art. 6(1)(b) GDPR for the purpose of carrying out pre-contractual measures. For applications to Information Factory Deutschland GmbH, Section 26 BDSG applies in addition. Where necessary, data may be processed in order to comply with legal obligations pursuant to Art. 6(1)(c) GDPR and to establish, exercise or defend legal claims.

Inclusion in a talent pool after the specific procedure has been completed takes place only on the basis of your voluntary consent pursuant to Art. 6(1)(a) GDPR. You may withdraw this consent at any time with effect for the future.

Applicant management with Recruitee

We use Recruitee for applicant management. Under the standard terms currently provided for customers in Germany, Austria and Switzerland, Recruitee GmbH, Grafenberger Allee 277–287, Entrance C, 40237 Düsseldorf, Germany, is the contracting party and the processor. The contract concluded with us is authoritative.

Recruitee processes application data on our behalf and provides in particular the application form, the storage of documents, the communication and the management of deletion periods. According to the provider, customer data is hosted within the European Union. Details of sub-processors and technical protective measures are set out in the data processing agreement.

Persons with access and recipients

Access to the data is granted only to persons involved in the relevant selection procedure, in particular employees from recruiting or HR, the responsible managers and, where necessary, members of the management board. Data is passed on to other group companies only where this is necessary for a cross-location application requested by you or where you have consented to this. Further recipients may be IT service providers, legal advisors or public authorities, insofar as this is necessary or required by law.

Retention

If no employment relationship is established, we generally delete your application data no later than six months after the application procedure has been concluded or withdrawn, unless longer retention is necessary in order to comply with a legal obligation or to establish, exercise or defend claims.

If you consent to inclusion in a talent pool, we store your application data for twelve months after the specific procedure has been concluded. The data is deleted thereafter unless you consent again to further storage.

If an employment relationship is established, the data required for this purpose is transferred to your personnel file and processed in accordance with the rules applicable to employee data.

Links to social networks and other websites

Our website contains simple links to social networks and other external websites. As long as you do not click on such a link, no connection to the respective operator is established merely by displaying the link. Once you have clicked on it, the data protection provisions of the external provider apply. We have no influence over their data processing.

Recipients and transfers abroad

We disclose personal data only where this is necessary for a purpose described in this privacy policy, where there is a legal obligation to do so or where you have consented. Recipients may include in particular companies of Information Factory, hosting and IT service providers, providers of applicant management systems, communication service providers, legal advisors and public authorities.

If data is transferred to a country outside Switzerland or the European Economic Area, this takes place only where an adequate level of data protection is recognised or where appropriate safeguards are in place. Such safeguards include in particular the applicable standard contractual clauses with the necessary Swiss amendments, together with additional protective measures. We will provide information about the safeguards used in each case on request.

Retention period

Unless a specific period is stated in this privacy policy, we store personal data only for as long as is necessary for the respective purpose. We then delete or anonymise the data, unless statutory retention obligations, legitimate interests in preserving evidence or ongoing legal proceedings require longer storage.

Your rights

Depending on the applicable data protection law and the respective conditions, you have in particular the right:

  • to request information about the personal data we process,
  • to have inaccurate or incomplete data corrected,
  • to request the deletion or destruction of data,
  • to request the restriction of processing,
  • to object to the processing on grounds relating to your particular situation,
  • to receive data in a structured, commonly used and machine-readable format, insofar as the right to data portability applies,
  • to withdraw consent you have given at any time with effect for the future.

To exercise your rights, please contact us at dsb@information-factory.com. We may request suitable proof of your identity where this is necessary in order to protect your data.

You also have the right to lodge a complaint with a competent data protection supervisory authority. In Switzerland this is the Federal Data Protection and Information Commissioner (FDPIC). For processing carried out by a German company, you may in particular contact the Bavarian Data Protection Supervisory Authority (Bayerisches Landesamt für Datenschutzaufsicht) or another competent European supervisory authority.

Data security

We take appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, alteration or disclosure. These include in particular access restrictions, up-to-date systems, encrypted transmission and appropriate organisational requirements. However, absolute security cannot be guaranteed for data transmissions over the internet.

Amendments to this privacy policy

We amend this privacy policy when our processing operations or the legal requirements change. The version published on this website at the relevant time applies. The date of the last update can be found at the beginning of this privacy policy.