Helping you stay informed
With this Privacy Notice, we inform you about how we handle your personal data and about your rights under the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (Bundesdatenschutzgesetz – BDSG). The controller responsible for the processing of personal data is isento GmbH (hereinafter referred to as “we”, “us” or “our”).
This Privacy Notice consists of two parts. Part A provides general information about data protection at isento, including your rights and how you may exercise them. Part B addresses the different categories of individuals whose data we process and explains in detail which personal data we collect and how we use it. This Privacy Notice applies to you in your role as:
a. Visitors to our websites,
b. Customers who use our services or purchase our products,
c. Contact persons at B2B customers whose employees use our services,
d. Newsletter subscribers whom we keep informed on a regular basis, and
e. Job applicants seeking employment with our company.
A. General information
1. Contact details
If you have any questions, suggestions, or requests regarding this Privacy Notice or if you wish to exercise your rights as a data subject, please contact us at:
isento GmbH
Ostendstraße 242, 90482 Nuremberg, Germany
Phone: +49 (0)911 21 7738 70
Email: team@pib.rocks
2. On what legal basis do we process your data?
The term “personal data” refers to any information relating to an identified or identifiable natural person. We process personal data in accordance with the applicable data protection laws, in particular the GDPR and the BDSG. We process personal data only where a valid legal basis exists. This includes processing on the basis of your consent (Art. 6(1)(a) GDPR), where necessary for the performance of a contract to which you are a party or in order to take steps at your request prior to entering into a contract (Art. 6(1)(b) GDPR), where necessary for compliance with a legal obligation (Art. 6(1)(c) GDPR), or where necessary for the purposes of our legitimate interests or those of a third party, provided that such interests are not overridden by your interests, fundamental rights or freedoms requiring the protection of personal data (Art. 6(1)(f) GDPR).
If you apply for a position within our company, we also process your personal data for the purpose of deciding whether to establish an employment relationship in accordance with Section 26(1) sentence 1 BDSG.
3. Your rights
You remain in control of your personal data. As a data subject, you have the right to exercise the following rights under applicable data protection laws:
- Pursuant to Art. 15 GDPR and Section 34 BDSG, you have the right to obtain confirmation as to whether we process personal data concerning you and, where that is the case, access to such data.
- Pursuant to Art. 16 GDPR, you have the right to request the rectification of inaccurate personal data concerning you.
- Pursuant to Art. 17 GDPR and Section 35 BDSG, you have the right to request the deletion of your personal data.
- Pursuant to Art. 18 GDPR, you have the right to request restriction of the processing of your personal data.
- Pursuant to Art. 20 GDPR, you have the right to receive personal data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format and to transmit those data to another controller.
- Where processing is based on your consent, you may withdraw that consent at any time pursuant to Art. 7(3) GDPR. Withdrawal of consent does not affect the lawfulness of processing carried out prior to such withdrawal.
- Pursuant to Art. 77 GDPR, you have the right to lodge a complaint with a supervisory authority if you believe that the processing of your personal data infringes applicable data protection laws.
Pursuant to Art. 21(1) GDPR, you have the right to object, on grounds relating to your particular situation, to the processing of your personal data where such processing is based on Art. 6(1)(e) or Art. 6(1)(f) GDPR. Where we process your personal data for direct marketing purposes, you have the right to object to such processing at any time pursuant to Art. 21(2) and (3) GDPR.
Where you exercise your rights under Arts. 15 to 22 GDPR, we process the personal data you provide for the purpose of fulfilling your request and documenting compliance with our legal obligations. Data stored for the preparation and provision of information requests will be processed solely for that purpose and for data protection compliance purposes. Processing will otherwise be restricted in accordance with Art. 18 GDPR.
This processing is based on Art. 6(1)(c) GDPR in conjunction with Arts. 15 to 22 GDPR and Section 34(2) BDSG.
4. Where do we process your data?
As a general principle, we process your data on servers located within the European Union and protected by state-of-the-art security measures. To provide our services, we engage external service providers who may receive personal data on our behalf. Certain processing activities may involve the transfer of personal data to countries outside the scope of the GDPR (“third countries”). Such transfers take place only where legally permitted. Where the European Commission has determined that a third country ensures an adequate level of data protection through an adequacy decision, personal data may be transferred on that basis. This applies to all transfers to countries listed here: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en
If no adequacy decision exists, personal data will only be transferred where appropriate safeguards under Art. 46 GDPR are in place or where one of the derogations under Art. 49 GDPR applies.
Unless otherwise stated below, we rely on the European Commission’s Standard Contractual Clauses (SCCs) as appropriate safeguards for transfers to third countries. Copies of these clauses can be obtained upon request using the contact details provided above.
Where you expressly consent to the transfer of personal data to a third country, such transfer is carried out on the basis of Art. 49(1)(a) GDPR.
5. To whom and why do we disclose your personal data?
In order to provide our services and operate our business efficiently, we engage various external service providers and, where necessary, disclose personal data to them. Where additional categories of recipients apply to specific groups of data subjects, these are described in Part B of this Privacy Notice.
6. How long do we store your data?
Unless otherwise specified in this Privacy Notice, we retain personal data only for as long as necessary to fulfil the relevant processing purpose or to comply with contractual or statutory obligations. Statutory retention obligations may arise in particular under commercial and tax legislation. From the end of the calendar year in which the data were collected, we generally retain personal data contained in accounting records for ten (10) years and personal data contained in commercial correspondence and contracts for six (6) years. Furthermore, we may retain data relating to documented consents, complaints, warranty claims, legal claims and defences for the duration of the applicable statutory limitation periods. Personal data processed for marketing purposes will be deleted if you object to processing for such purposes.
7. How do we use cookies and other tracking technologies?
We use cookies and similar technologies on our websites and in connection with the provision of our services. Further information about our use of these technologies is available through our Cookie Banner, also referred to as a Consent Management Platform (CMP). The Cookie Banner can be accessed when you first visit our website, via a link in the website footer or via a consent badge displayed on the edge of the website. The Cookie Banner also allows you to manage your preferences and to accept or reject specific categories of cookies and similar technologies.
How can you contact our data protection officer?
You may contact our data protection officer using the following details:
Cortina Consult GmbH
Email: datenschutzbeauftragter@isento.de
B. Specific information – How and why we process your data
1. Website visitors
- Customer acquisition and business development;
- Support and communication, including responding to enquiries.
Legal Basis: Art. 6(1)(a) GDPR
- Ensuring the security, availability and stability of our services, including detecting and preventing attacks.
Legal Basis: Art. 6(1)(f) GDPR
- Analytics and measurement of website reach to improve our websites, increase customer satisfaction and identify errors;
- Conversion tracking and performance measurement;
- Remarketing and personalised advertising for customer acquisition.
Legal Basis: Art. 6(1)(a) GDPR
2. Customers
- Provision of services;
- Payment processing;
- Customer account administration;
- Support and communication, including responding to enquiries.
Legal Basis: Art. 6(1)(b) GDPR
- Non-marketing communications concerning technical, security-related and contractual matters, such as fraud alerts, account restrictions or contract amendments;
- Product updates, feature announcements and communications designed to encourage product usage;
- Marketing of similar products and services.
Legal Basis: Art. 6(1)(f) GDPR
- Conducting customer satisfaction and product surveys.
Legal Basis: Art. 6(1)(a) GDPR
- Compliance with statutory obligations and retention requirements.
Legal Basis: Art. 6(1)(c) GDPR
- Improving our products and services, increasing customer satisfaction and identifying errors;
- Publishing testimonials or customer statements on our website and other marketing channels for promotional purposes.
Legal Basis: Art. 6(1)(a) GDPR
3. Contact persons at B2B customers
- Performance of the contract with your employer or organisation, account administration and invoicing;
- Support and communication, including responding to enquiries;
- Non-marketing communications regarding product updates and new features.
Legal Basis: Art. 6(1)(f) GDPR
- Conducting customer satisfaction and product surveys;
- Marketing of products and services.
Legal Basis: Art. 6(1)(a) GDPR
- Compliance with legal obligations and statutory retention requirements.
Legal Basis: Art. 6(1)(c) GDPR
4. Job applicants
- Assessing whether employment is possible;
- Managing the recruitment process and taking steps prior to entering into an employment relationship.
Legal Basis: Art. 6(1)(b) GDPR and Section 26 BDSG
- Compliance with statutory retention obligations or establishing, exercising or defending legal claims.
Legal Basis: Art. 6(1)(c) GDPR
- Where you have given your consent, inclusion in our talent pool in order to contact you regarding future employment opportunities if no employment relationship is established at the present time.
Legal Basis: Art. 6(1)(a) GDPR
- Maintaining records of previous applications submitted to our company.
Legal Basis: Art. 6(1)(f) GDPR
If we are unable to offer you employment, we will generally retain the application documents you submitted for up to six (6) months following a rejection in order to respond to questions relating to your application and our decision. This does not apply where statutory provisions prevent deletion, where further storage is necessary for evidentiary purposes or where you have expressly consented to longer retention. We retain your name and contact details for three (3) years in order to maintain records of previous applicants.
5. Newsletter subscribers
- Sending promotional newsletters with information and updates about our products, promotions and events for sales promotion and customer acquisition purposes.
Legal Basis: Art. 6(1)(a) GDPR
- Measuring the effectiveness of our communications and optimising our content.
Legal Basis: Art. 6(1)(f) GDPR
6. Social Media visitors
Facebook and Instagram:
- Privacy Policy of Meta Platforms Ireland Limited
- Opt-out options
LinkedIn:
Privacy Policy of LinkedIn Ireland Unlimited Company
YouTube:
Privacy Policy of Google LLC
Facebook and Instagram:
- Joint Controller Agreement
- Data subject rights may also be exercised directly against Meta. Further information is available in Meta’s Privacy Policy.
LinkedIn:
- Joint Controller Agreement
- Data subject rights may be exercised against LinkedIn via this contact form. LinkedIn’s Data Protection Officer can be contacted via this link.
- We have agreed with LinkedIn that the Irish Data Protection Commission is the lead supervisory authority for the processing of Page Insights data. You may lodge a complaint with the Irish Data Protection Commission (see www.dataprotection.ie) or with any other competent supervisory authority.
YouTube:
- Google’s Controller-to-Controller Data Protection Terms
- Google’s privacy settings are available here.
- Support, communication and responding to enquiries.
Legal Basis: Art. 6(1)(f) GDPR
- Processing in connection with competitions and giveaways, including identifying winners and sending prizes.
Legal Basis: Art. 6(1)(b) GDPR







