Information on data protection for users of our website (privacy policy)
§ 1 Information on the collection of personal data
(1) In the following, we inform you about the processing of personal data in connection with the use of this website. Personal data is all data that relates to you personally. This includes, for example, name, address, e-mail address, user behavior.
(2) The controller pursuant to Art. 4 No. 7 of the EU General Data Protection Regulation (GDPR) is SIGMA Enterprise Solutions GmbH, Am Erlenwald 13, 09128 Chemnitz, Germany, e-mail: datenschutz@sigma-chemnitz.de. You can contact our data protection officer at datenschutz@fardit.de or at our postal address: FARADIT Beratung + Service GmbH, Bernsdorfer Str. 291, 09125 Chemnitz with the addition “External Data Protection Officer”.
(3) When you contact us by e-mail, the data you provide - name, e-mail address, message text - will be stored by us for the purposes of individual communication with you. We will delete your data collected in this context once it is no longer necessary to store it. If statutory retention obligations exist, we restrict the processing.
(4) If we use contracted service providers for individual functions of our offer, we will inform you in detail below about the respective processes. We will also state the specified criteria for the storage period.
§ 2 Your rights
(1) You have the following rights vis-à-vis us with regard to your personal data:
- Right to information
- Right to rectification or erasure
- Right to restriction of processing
- Right to object to the processing
- Right to data portability.
(2) With regard to your personal data, you also have the right to complain to a data protection supervisory authority about the processing by us.
(3) To exercise your rights, please contact SIGMA Enterprise Solutions GmbH using the contact details provided in Section 1 (2).
§ 3 Collection of personal data for informational use
(1) If you use the website for informational purposes only, i.e. if you do not transmit information to us in any other way, we only collect the personal data that your browser transmits to our server. If you wish to view our website, we collect the following data, which is technically necessary for us to display our website to you and to ensure stability and security (the legal basis results from Art. 6 para. 1 sentence 1 lit. f GDPR):
- IP address
- Date and time of the request
- Time zone difference to Greenwich Mean Time (GMT)
- Content of the request (specific page)
- Access status/http status code
- amount of data transferred in each case
- Website from which the request originates
- browser
- Operating system and its interface
- Language and version of the browser software.
(2) Furthermore, cookies are stored on your computer when you use the website. Cookies are small text files that are stored on your hard disk assigned to the browser you are using and through which certain information flows to the body that sets the cookie (in this case us). Cookies cannot execute programs or transmit viruses to your computer. They are used to make the website more user-friendly and effective overall.
a) This website uses the following types of cookies, the scope and function of which are explained below:
- Transient cookies (session cookies)
- Persistent cookies
Session cookies store a so-called session ID, with which various requests from your browser can be assigned to the joint session. This allows your computer to be recognized when you return to our website. The session cookies are deleted when you log out or close the browser.
Persistent cookies (time-limited use) are automatically deleted after a specified period, which may vary depending on the cookie. You can delete cookies at any time in the security settings of your browser.
b) This website uses technically necessary cookies, statistical cookies and cookies for marketing purposes. Your consent is not required for the use of technically necessary cookies. For the use of cookies for marketing purposes or to compile statistics, we require your consent before using them. Our cookie notice (cookie banner), which we make available to you at the start of your visit to our website, serves this purpose.
c) Below you will find detailed information on the technically necessary cookies. (The legal basis is Art. 6 para. 1 sentence 1 lit. f GDPR):
²fe_typo_user² (session cookie):
This is a standard cookie of the content management system used. It is set to identify a user during their visit to the website. The cookie is deleted when the session is ended (closing of all browser windows). The cookie is absolutely necessary for us.
²be_typo_user² (session cookie):
This is a standard cookie of the content management system used. It is required to log in to the content management system. The cookie is deleted when the session is ended (closing of all browser windows). The cookie is absolutely necessary for us.
²be_lastLoginProvider² (persistent cookie):
This is a standard cookie of the content management system used. It is required to log in to the content management system. The cookie is deleted after 90 days. The cookie is absolutely necessary for us.
²cookie_consent² (persistent cookie):
This cookie stores that the user has seen the cookie consent and made their settings. The cookie is deleted after 30 days. The cookie is absolutely necessary for us.
²cookie_essential² (persistent cookie):
This cookie stores the user settings for the essential cookies. The cookie is deleted after 30 days. The cookie
d) Below you will find detailed information on the cookies used to compile statistics and for marketing purposes. (After consent has been given, the legal basis is Art. 6 para. 1 sentence 1 lit. f GDPR):
²cookie_tracking² (persistent cookie):
This cookie stores the user setting for the tracking cookies. The cookie is deleted after 30 days.
²_ga² (persistent cookie):
This cookie is used to identify the user. It contains a randomly generated user ID. Using this ID, Google Analytics can recognize returning users on this website and merge the data from previous visits. The provider is Google. The cookie is deleted after two years.
²_gid² (persistent cookie):
This cookie is used to identify the user. It contains a randomly generated user ID. Using this ID, Google Analytics can recognize returning users on this website and merge the data from previous visits. The provider is Google. The cookie is deleted after 24 hours.
²_gat_gtag_UA_XXX² (persistent cookie):
This cookie is used to throttle the transfer rate to Google Analytics. As long as it is set, certain data transfers are prevented. XXX stands for the account number of the website operator. The provider is Google. The cookie is deleted after one minute.
e) You can configure your browser settings according to your wishes. However, we would like to point out that you may then not be able to use all the functions of this website.
§ 4 Contact form
When you contact us via our contact form, the data you provide - e-mail address as a mandatory field, name, telephone number, message text - will be stored by us for the purpose of individual communication with you. We will delete your data collected in this context once it is no longer necessary to store it. If statutory retention obligations exist, we restrict the processing.
§ 5 Newsletter
(1) With your consent, you can subscribe to our newsletter, with which we inform you about our current interesting offers. The advertised goods and services are named in the declaration of consent.
(2) We use the so-called double opt-in procedure to subscribe to our newsletter. This means that after you have registered, we will send you an e-mail to the specified e-mail address in which we ask you to confirm that you wish to receive the newsletter. If you do not confirm your registration within 24 hours, your information will be blocked and then automatically deleted. We also store the IP addresses you use and the times of registration and confirmation. The purpose of this procedure is to be able to prove your registration and, if necessary, to clarify any possible misuse of your personal data.
(3) The only mandatory information for sending the newsletter is your e-mail address. The provision of further, separately marked data is voluntary and is used to address you personally. After your confirmation, we will store your e-mail address for the purpose of sending you the newsletter. The legal basis is Art. 6 para. 1 sentence 1 lit. a GDPR.
(4) You can revoke your consent to the sending of the newsletter at any time and unsubscribe from the newsletter. You can declare your revocation by clicking on the link provided in every newsletter e-mail, by e-mail to vertrieb@chemnitz-sigma.de or by sending a message to the contact details given in the imprint.
(5) We would like to point out that we evaluate your user behavior when sending the newsletter. For this analysis, the emails sent contain so-called web beacons or tracking pixels, which are one-pixel image files stored on our website. For the evaluations, we link the data mentioned in § 3 and the web beacons with your e-mail address and an individual ID. By assigning an individual ID, we protect (pseudonymize) your data.
You can object to this tracking at any time by clicking on the separate link provided in every e-mail or by informing us via another contact channel. The data will then be stored anonymously.
§ 6 Use of Mouseflow
(1) This website uses Mouseflow, a web analysis service of Mouseflow Ltd, Flaesketorvet 68, 1711 Copenhagen V, Denmark (Europe) (“Mouseflow”). Mouseflow records randomly selected individual visits. This allows a log to be created of the mouse movements and clicks of visitors. These logs can be used to randomly replay individual visits to our website in order to derive possible improvements to the user experience of our website. The information recorded by Mouseflow is not personal. In particular, IP addresses are only processed anonymously. The information recorded by Mouseflow is not passed on. We use Mouseflow for the purpose of analyzing the use of our website and continuously improving individual functions and offers as well as the user experience. By statistically evaluating user behavior, we can improve our offer and make it more interesting for you as a user. This is also our legitimate interest in the processing of data by Mouseflow. The legal basis is Art. 6 para. 1 sentence 1 lit. f GDPR.
(2) You can prevent the collection of the aforementioned information by Mouseflow by setting an opt-out cookie on the following linked website: www.mouseflow.de/opt-out/
Note: If cookies are deleted, an incognito mode is used or the browser is changed, the visitor may still or again be recorded and must again expressly object to recording by Mouseflow.
(3) Information from the third-party provider:
Privacy policy: mouseflow.de/privacy
Further information on data protection: mouseflow.de/gdpr/
§ 7 Use of chatbot
(1) This website uses a chatbot that was specially developed by us. The chatbot is a software-based dialog system that enables a text or voice-based communicative exchange with a technical system.
The chatbot is based on the RAG approach (Retrieval Augmented Generation), which retrieves data from a database in order to answer questions as best as possible. This data, together with the question, is sent to the language models of OpenAI, Inc. without disclosing any personal information of the user. The models try to answer the question as best as possible with the data provided and return this answer.
The data comes from one of our internal databases and consists of text documents with marketing information about products and services of our SIGMA Group.
(2) The following data is processed: Session ID for the user's requests, time of the request, the request itself and the chatbot's response, topic, language.
(3) We process the data for the purpose of analyzing the productivity of our chatbot and making continuous improvements. This includes the following aspects:
Chatbot performance optimization: we record and analyze interactions with the chatbot to evaluate its efficiency and performance. This includes, for example, questions that the chatbot was unable to answer, repeated requests on certain topics and similar.
Improving the user experience: We use data to improve the user experience. This includes analyzing user feedback to make adjustments and enhancements to the chatbot to better meet your needs.
Error detection and correction: The data enables us to detect errors and problems in real time to ensure that the chatbot is corrected and updated more quickly.
Statistical evaluations: We create aggregated, anonymized statistical reports on the use of the chatbot. These reports do not contain any personal information and are used to analyze trends and patterns.
The legal basis is Art. 6 para. 1 sentence 1 lit. f GDPR.
§ 8 Use of Google Analytics
(1) This website uses Google Analytics, a web analysis service of Google Inc (“Google”). Google Analytics uses “cookies”, which are text files placed on your computer, to help the website analyze how users use the site. The information generated by the cookie about your use of this website is usually transmitted to a Google server in the USA and stored there. However, if IP anonymization is activated on this website, your IP address will be shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and truncated there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, to compile reports on website activity and to provide other services relating to website activity and internet usage to the website operator.
(2) The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.
(3) You may refuse the use of cookies by selecting the appropriate settings on your browser, however please note that if you do this you may not be able to use the full functionality of this website. You can also prevent Google from collecting the data generated by the cookie - relating to your use of the website - (including your IP address) and from processing this data by Google by downloading and installing the browser plug-in available at the following link: tools.google.com/dlpage/gaoptout.
(4) We use Google Analytics to analyze and regularly improve the use of our website. We can use the statistics obtained to improve our offer and make it more interesting for you as a user. Google is certified in accordance with the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the USA, which is intended to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this can be obtained from the provider at: www.dataprivacyframework.gov/s/participant-search/participant-detail
The legal basis for the use of Google Analytics is Art. 6 para. 1 sentence 1 lit. f GDPR.
(5) Informationen des Drittanbieters:
Google Dublin, Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Irland, Fax: +353 (1) 436 1001.
Nutzerbedingungen:
www.google.com/analytics/terms/de.html
Übersicht zum Datenschutz:
www.google.com/intl/de/analytics/learn/privacy.html
Datenschutzerklärung:
www.google.de/intl/de/policies/privacy
§ 9 Use of XOVI
(1) For web analysis, we use the service of XOVI GmbH, Hohenzollernring 72, 50672 Cologne, Germany.
(2) XOVI allows us to track user flows and carry out keyword and link analyses. In this way, we obtain valuable information to make our website even faster and more customer-friendly.
(3) If personal data is processed, the legal basis is Art. 6 para. 1 lit. f GDPR.
§ 10 Use of social media plug-ins
(1) We currently use the following social media plug-ins: Google+, Twitter / X. We use the so-called two-click solution. This means that when you visit our website, no personal data is initially passed on to the providers of the plug-ins. You can recognize the provider of the plug-in by the logo. We give you the option of communicating directly with the provider of the plug-in via the button. Only if you click on the marked field and thereby activate it will the plug-in provider receive the information that you have accessed the corresponding website of our online offering. In addition, the data mentioned under § 3 of this declaration will be transmitted. By activating the plug-in, your personal data is therefore transmitted to the respective plug-in provider and stored there (in the case of US providers in the USA). As the plug-in provider collects data in particular via cookies, we recommend that you delete all cookies via your browser's security settings before clicking.
(2) We have no influence on the data collected and data processing procedures, nor are we aware of the full scope of data collection, the purposes of processing or the storage periods. We also have no information on the deletion of the data collected by the plug-in provider.
(3) The plug-in provider stores the data collected about you as usage profiles and uses these for the purposes of advertising, market research and/or the needs-based design of its website. Such an evaluation is carried out in particular (even for users who are not logged in) to display needs-based advertising and to inform other users of the social network about your activities on our website. You have the right to object to the creation of these user profiles, whereby you must contact the respective plug-in provider to exercise this right. We offer you the opportunity to interact with the social networks and other users via the plug-ins so that we can improve our offering and make it more interesting for you as a user. The legal basis for the use of the plug-ins is Art. 6 para. 1 sentence 1 lit. f GDPR.
(4) Data is transferred regardless of whether you have an account with the plug-in provider and are logged in there. If you are logged in with the plug-in provider, your data collected by us will be assigned directly to your existing account with the plug-in provider. If you confirm the activated button and, for example, link the page, the plug-in provider also saves this information in your user account and shares it publicly with your contacts. We recommend that you log out regularly after using a social network, but especially before activating the button, as this will prevent you from being assigned to your profile with the plug-in provider.
(5) Further information on the purpose and scope of data collection and its processing by the plug-in provider can be found in the data protection declarations of these providers provided below. There you will also find further information on your rights in this regard and setting options to protect your privacy.
(6) Addresses of the respective plug-in providers and URL with their data protection notices:
(a) Google Inc, 1600 Amphitheater Parkway, Mountainview, California 94043, USA; www.google.com/policies/privacy/partners/. Google is certified in accordance with the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the USA, which is intended to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this can be obtained from the provider at: www.dataprivacyframework.gov/s/participant-search/participant-detail
b) Twitter Inc, 1355 Market St, Suite 900, San Francisco, California 94103, USA; www.twitter.com/privacy.
§ 11 Integration of YouTube videos
(1) We have integrated YouTube videos into our online offering, which are stored on YouTube.com and can be played directly from our website. These are all integrated in “extended data protection mode”, i.e. no data about you as a user is transferred to YouTube if you do not play the videos. Only when you play the videos will the data mentioned in paragraph 2 be transmitted. We have no influence on this data transfer.
(2) By visiting the website, YouTube receives the information that you have accessed the corresponding subpage of our website. In addition, the data mentioned under § 3 of this declaration will be transmitted. This takes place regardless of whether YouTube provides a user account through which you are logged in or whether no user account exists. If you are logged in to Google, your data will be assigned directly to your account. If you do not wish your data to be associated with your YouTube profile, you must log out before activating the button. YouTube stores your data as usage profiles and uses them for the purposes of advertising, market research and/or the needs-based design of its website. Such an evaluation is carried out in particular (even for users who are not logged in) to provide needs-based advertising and to inform other users of the social network about your activities on our website. You have the right to object to the creation of these user profiles, whereby you must contact YouTube to exercise this right.
(3) Further information on the purpose and scope of data collection and its processing by YouTube can be found in the privacy policy. There you will also find further information on your rights and setting options to protect your privacy: www.google.de/intl/de/policies/privacy. The information collected is stored on Google servers, including in the USA. Google is certified in accordance with the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the USA, which is intended to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this can be obtained from the provider: www.dataprivacyframework.gov/s/participant-search/participant-detail
§ 12 SSL and TLS Encryption
(1) For security reasons and to protect the transmission of confidential content—such as inquiries you send to us as the website operator—this website uses SSL or TLS encryption. You can recognize an encrypted connection by the fact that the address line of the browser changes from “http://” to “https://” and by the lock icon displayed in your browser.
(2) When SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.
§ 13 Revocation of Consent under Data Protection Law
(1) If you have given your consent to the processing of your data, you can revoke this consent at any time. Such a revocation affects the lawfulness of the processing of your personal data after you have communicated it to us.
(2) To exercise your right of revocation, you can directly use the contact details of SIGMA Enterprise Solutions GmbH provided in § 1 para. 2.
§ 14 Objection to the Processing of Your Data
(1) If we base the processing of your personal data on a balancing of interests, you may object to the processing. This is particularly the case if the processing is not required for fulfilling a contract with you. When exercising such an objection, please explain the reasons why you do not want us to process your personal data as we have been doing. In the event of your justified objection, we will review the situation and either stop or adjust the data processing or demonstrate our compelling legitimate grounds for continuing the processing.
(2) To exercise your right to object, you can directly use the contact details of SIGMA Enterprise Solutions GmbH provided in § 1 para. 2.
§ 15 Updating This Privacy Policy
We reserve the right to update this privacy policy regularly. Therefore, we kindly ask you to review our privacy policy from time to time.