Contents
1. Controller
2. Data Protection Officer
3. Collecting and Processing of Personal Data when the DATEV Websites are Visited
4. Necessary Cookies and Comparable Technologies
5. Collection and Processing of the Personal Data of Interested Parties
6. Collection and Processing of the Personal Data of Customers
7. Collection and Processing of the Personal Data of Suppliers or Business Partners
8. Collection and Processing of the Personal Data of Applicants and Prospective Candidates
9. Additional Processing Purposes
10. Duration of Data Storage
11. Recipients of Personal Data
12. Third Countries
13. Automated Decision Making
14. Subjects’ Rights
15. Obligation to Provide Data
16. Security
17. Social Media
18. Friendly Captcha
19. Video Integration via YouTube
20. Links to Other Websites
21. Specific Data Protection Information
1. Controller
DATEV eG, Nuremberg
Contact
Paumgartnerstrasse 6-14
90429 Nuremberg
Phone: +49 (0)911 3190
Email: info@datev.de
2. Data Protection Officer
DATEV eG
Data Protection Officer
Paumgartnerstrasse 6–14
90429 Nuremberg
Phone +49-911-3190
Email: datenschutz@datev.de
Responsible data protection supervisory authority: Bavarian State Office of Data Protection Supervision
3. Collecting and Processing of Personal Data when the DATEV Websites are Visited
3.1 Public Websites
DATEV logs personal usage data for up to two months to protect website functionality, to optimise the website and to guarantee website security. The legal basis for this processing is DATEV’s legitimate interest (Article 6 (1) (f) GDPR). When you visit our website, anonymised web server logbooks are generated which DATEV stores for statistical purposes (for example the number of page views) and for error tracking. Your usage data is not evaluated in any other way without your consent.
3.2 Use of websites and online applications with Protected Access
The following user information can be collected when the closed section of our websites and online applications is used (business processes between DATEV and its customers):
- User identification (in the case of SmartCard: SmartCard ID, certificate; SmartLogin; new national ID card; SMS TAN or similar, in the case of DATEV user account: username or similar; DATEV account: E-Mail address)
- Customer identification (consultant number, if available)
- Time of enquiry and our responses
- Data volume transmitted
- Transactions retrieved (URLs)
- Error messages within the authentication process and applications
The user-specific details are stored for a maximum of two months. This data is evaluated solely for the purposes of error and performance analysis, for customer service and to understand effected transactions. The legal basis for this processing is DATEV’s legitimate interest (Article 6 (1) (f) GDPR).
The legal basis for this processing is DATEV’s legitimate interest (Article 6 (1) (f) GDPR). The information aggregated under a consultant number, e.g. which consultant number retrieved which transaction on which day, is retained in accordance with the statutory provisions, e.g. the data retention periods pursuant to the German Commercial Code (HGB) and Germany’s Fiscal Code (AO). The same applies to application-specific information collected for billing purposes.
Legal basis: This processing is required for the purposes of contractual performance (Article 6 (1) (b) GDPR) and due to legal obligations (Article 6 (1) (c) GDPR).
3.3 Personal Input
Your personal data including your email address will additionally only be stored if you yourself provide us with these details, e.g. in a survey or when placing an order. Your data shall also only be used for the purpose stipulated on the page in question, e.g. to process your order.
Legal basis: Depending on the purpose stipulated on the page in question, this processing occurs
- on the basis of your consent (Article 6 (1) (a) GDPR)
- for contractual performance (Article 6 (1) (b) GDPR)
- on the basis of legal obligations (Article 6 (1) (c) GDPR) or
- to fulfil DATEV’s legitimate interests (Article 6 (1) (f) GDPR).
4. Use of Cookies and Comparable Technologies
DATEV uses temporary and permanent cookies on its own websites. Temporary cookies are time-limited and contain data such as an identification number (known as a session ID). They allow the server to associate consecutive browser enquiries with the same user. They are deleted automatically as soon as the user closes the browser. In contrast, permanent cookies remain in place even after the user has closed the browser. At DATEV, permanent cookies used for preferences and settings serve to make working with the SmartCard easier for you. DATEV additionally uses permanent cookies for non-personalised statistics in order to further develop and improve the services we provide. No personal data is evaluated in the process. Cookies from first-party providers are cookies that belong to the host domain datev.de, while cookies from third-party providers are assigned to another domain. We use cookies that are absolutely necessary on the legal grounds of our legitimate interest, Article 6 (1) (f) GDPR, namely, to provide a functional and usable website. Access to and storage of information on a user’s device is carried out in accordance with section 25 (2) of the German Telecommunications Digital Services Data Protection Act (Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz, TDDDG).
Furthermore, we use optional cookies for the purposes of analytical evaluations and marketing activities, for which we also use external service providers. This only takes place if you have consented to this (Article 6 (1) (a) GDPR, TDDDG section 25 (1) (1). You can revoke your consent or adjust your preferences at any time in the cookie settings in the footer. You can find an overview of the individual cookies that process personal data via the “Cookie Settings” in the footer of the website.
Furthermore, you can deactivate the storage of optional cookies through your browser settings and delete cookies that have already been stored in your browser at any time. Please note, however, that rejecting optional cookies means that the convenience functions of our website will be lost. If you delete your cookies, we will ask you for your consent again when you visit the page at a later date.
We use Adobe Launch Manager, a service provided by Adobe Systems Software Ireland Ltd., 4–6 Riverwalk, Citywest Business Campus, Saggart Dublin 24, Republic of Ireland.
Adobe Launch is a tag manager that serves as a sort of container for managing tracking tools and services from external providers such as OneTrust on the website and allows the use of tags. This makes it possible to control which elements of the page or service and tracking methods are activated and loaded on the website. Adobe Launch itself does not set any cookies and does not have access to the data collected by the tags. For more information, see Adobe’s Privacy Policy.
4.1 Necessary Cookies and Comparable Technologies
Necessary cookies help make a website usable by enabling basic functions such as page navigation, access to secure areas of the website, user input and serve the security of the application. The website cannot function properly without these cookies.
We use strictly necessary cookies on the legal basis of our legitimate interest
pursuant to Art. 6(1)(f) GDPR, in particular to provide a functional and usable
website. Access to and storage of information on the end user's terminal
equipment are carried out in accordance with Section 25(2) TDDDG.
4.2 Analytical Cookies and Comparable Technologies
These cookies are also used to store your preferences and settings, making it easier for you to use the website. In addition, we use cookies for statistical Web analysis and reach measurements, further development and improvement of our products, error analysis, crawling analysis, and user recognition.
The legal grounds for accessing and storing information on a user’s device are based on your consent pursuant to TDDDG section 25 (1). The legal grounds for downstream data processing are your consent in accordance with Article 6 (1) (a) GDPR. You can revoke your consent or adjust your preferences at any time via the cookie settings in the footer.
4.3 Marketing Cookies and Comparable Technologies
These cookies and similar technologies are used in order to display personalized and thus relevant advertisement content to you. These cookies also enable us to monitor the success of marketing campaigns. The tracking methods are applied not only on DATEV websites, but also on the websites of advertising partners, i.e., third-party providers. Data may be transferred to a third country during this process. For example, pseudonymous profiles of your interests may be created and relevant advertisement content made available to you, including on third-party websites.
The legal grounds for accessing and storing information on a user’s device are based on your consent pursuant to TDDDG section 25 (1). The legal grounds for downstream data processing are your consent in accordance with Article 6 (1) (a) GDPR. You can revoke your consent or adjust your preferences at any time via the cookie settings in the footer.
4.4 Adobe Analytics
DATEV uses the Adobe Analytics service of the service provider Adobe Systems Software Ireland Ltd., 4–6 Riverwalk, Citywest Business Campus, Saggart Dublin 24, Republic of Ireland. The information collected by cookies on your device is processed by Adobe Analytics, in particular for audience measurement, statistical Web analysis, visitor recognition, and the creation of pseudonymous profiles. For more information on the storage duration, description, and purpose of the individual Adobe Analytics cookies, please refer to the cookie settings in the footer.
The legal grounds for accessing and storing information on a user’s device are based on your consent pursuant to TDDDG section 25 (1). The legal grounds for downstream data processing are your consent in accordance with Article 6 (1) (a) GDPR. You can revoke your consent or adjust your preferences at any time via the “Cookie Settings” in the footer.
4.5. SalesViewer
On ourwebsite, we use the service provided by SalesViewer GmbH, Huestraße 30, 44787 Bochum, Germany (hereinafter “Sales Viewer”) on the basis of our legitimate interests (Art. 6(1)(f) GDPR) to analyse page views by companies for marketing and market research purposes and to optimise our services. This process does not involve storing cookies or similar files on the devices of visitors to our website. Instead, SalesViewer encrypts the visitor’s IP address using a non-reversible one-way function (known as hashing). Following a preselectionprocess in which access by private individuals is filtered out, the IP addresses are transmitted to SalesViewer in pseudonymised form.
These pseudonymised data are then compared against a database containing exclusively company-related information. If company visits are identified as part of this process, SalesViewer makes the corresponding company-related data available to us via a secure, encrypted login area. This area also allows us to research further publicly available information about the companies visiting our website, such as address and contact details.
In order to filter out visits by private individuals and to analyse our reach among companies, the following personal data relating to website visitors are processed:
- Technical information about the internet browser
- HTTP referrer
- URL of the previously visited website
- Interactions with the website
- IP address of the website visitor
The data stored in connection with SalesViewer are deleted as soon as they are no longer required for the purposes for which they were collected, unless statutory retention obligations require otherwise. The data are not transferred to any third country.
You can object to the collection and storage of your data at any time here to prevent SalesViewer from collecting your data on this website in the future. An opt-out cookie for this website will then be stored on your device. If you delete the cookies in this browser, you will need to click this link again.
4.6. Google Ads
On our website, we use technologies provided by Google (Google Ireland Limited, Google Building Gordon House, 4 Barrow Street, Dublin D04 E5W5, Ireland), which acts as an independent controller. These technologies are “Google Conversion Tracking” and “Google Retargeting” (collectively referred to as Google Ads).
If you have arrived at our website via a Google advert, both Google and we can determine that someone has clicked on an advert, been redirected to the website and reached a predefined landing page (‘conversion site’). Furthermore, Google and we can see that you have accessed the website via another route and made a purchase or used a service that has been defined as a conversion. We can use the data from the advertising campaigns to determine how successful the individual advertising measures have been.
We do not ourselves collect or process any personal data as part of the advertising activities referred to above. We only receive aggregated statistical analyses from Google. We do not receive any further data through the use of these advertising tools; in particular, we are unable to identify users on the basis of this information.
Google Retargeting technology is also used to collect and store information about your use of our website. These data are stored in cookies on your computer and accessed by Google. The cookies enable Google to collect, process and use the information they contain to create pseudonymised user profiles. These user profiles are used to analyse your behaviour when visiting our website and to serve you relevant and personalised advertisements on external websites.
As a result of the marketing tools used, your browser may automatically establish a direct connection to Google’s servers. We have no influence over the extent of the data collected by Google through the use of these tools or over how such data are subsequently used. We therefore provide you with the following information based on our current knowledge: By integrating Google Ads, Google is informed that you have accessed the relevant section of our website or clicked on one of our adverts. If you are registered with a Google service, Google may associate your visit with your account. Even if you are not registered with Google or are not logged in, the provider may obtain and store your IP address.
When you use our website, Google processes the following data in particular: IP address, cookie ID, mobile advertising ID (IDFA/GAID), pixel ID, device information, browser information, location information, usage data, user behaviour and user agent.
Your data are stored on servers within the EU and are not disclosed to third parties outside the Google network. However, your data may be transferred within the Google network to a third country within the meaning of the GDPR, such as the United States. Any transfer of your data to servers in the United States is based on the EU-US Data Privacy Framework and the EU Standard Contractual Clauses entered into with Google.
Log data are anonymised after nine months and cookie information after 18 months. Otherwise, the data are deleted as soon as the purpose of the processing has been fulfilled. To manage your Google Account, click here. For further details on data processing, please refer to Google’s Privacy Policy.
The legal basis for accessing and storing information on your terminal equipment is your consent pursuant to Section 25(1) TDDDG. The legal basis for the subsequent processing of your data is your consent pursuant to Art. 6(1)(a) GDPR. You can withdraw your consent at any time by disabling “Marketing Cookies” in the “Cookie Settings” in the footer. You can also adjust your preferences there.
4.7. Flashtalking
We use the ad server technologies of Flashtalking Inc., 142 West 36th Street, 10th Floor, New York, NY 10018, USA, on our website.In order to provide you with advertising in your web browser that is relevant to your interests, Flashtalking automatically collects certain information when you access our website. These data are stored in cookies on your computer and accessed by Flashtalking. This information does not allow us to identify you personally, but it does reflect information about the websites and mobile applications you visit and use, as well as how you interact with advertisements served by us.Flashtalking collects information about your browser and device, including browser type, device type, IP address, user agent, location information, operating system and identifiers assigned to your browser or device, such as advertising identifiers assigned by platform providers. In addition, Flashtalking collects information about the websites and mobile applications you visit, including the date and time your browser or device accesses these websites or applications, as well as the specific pages viewed.If you do not want the advertisements displayed to you to be optimised based on your interests, you can disable personalised advertising via the advertising settings. Further information and Flashtalking’s privacy policy can be found here.Your data are stored on servers within the EU for as long as necessary for the purposes for which they are processed. They are not disclosed to third parties outside Flashtalking. Cookies expire after 90 days and are not used to identify you personally. Flashtalking processes your data on our behalf in accordance with Art. 28 GDPR. Any transfer of your data to the United States is primarily based on the EU-US Data Privacy Framework. In addition, we have entered into the EU Standard Contractual Clauses with Flashtalking.The legal basis for accessing and storing information on your terminal equipment is your consent pursuant to Section 25(1) TDDDG. The legal basis for the subsequent processing of your data is your consent pursuant to Art. 6(1)(a) GDPR. You can withdraw your consent at any time by disabling “Marketing Cookies” via the “Cookie Settings” in the footer. You can also adjust your preferences there.
4.8. Bing Universal Event Tracking (UET) Tag
We use the Bing Universal Event Tracking (UET) Tag from Microsoft (Microsoft Ireland Operations Limited, One Microsoft Place South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland) on our website. This is a tracking technology that allows us to analyze userbehavior after they click on an advert. This includes, for example, information about which pages were visited or which actions (e.g., conversions) were performed. The processing serves to analyze and optimize our online marketing activities and to enable targeted communication with users.A Bing UET Tag is integrated into our website. This is a code that, in conjunction with cookies, stores certain data regarding the use of the website. This includes, among other things, the IP address, device and browser information, cookie IDs, and information about user behavior on our website (e.g., page views, clicks, and conversions).When using Microsoft’s Bing UET Tag, personal data may be transferred to Microsoft servers, particularly in the U.S., where it may be stored for a maximum of 13 months. The transfer of your data to servers in the U.S. is based on the EU-U.S. Data Privacy Framework and on EU Standard Contractual Clauses.For further details on data processing by Microsoft, please refer to the Microsoft Privacy Statement.The legal grounds for accessing and storing information on a user’s device are based on your consent pursuant to section 25 (1) TDDDG. The legal grounds for downstream data processing are your consent in accordance with Article 6 (1) (a) GDPR. You can revoke your consent or adjust your preferences at any time via the “Cookie Settings” in the footer.
4.9 Other Tracking Technologies
Information about the tracking technologies used by Meta and LinkedIn can be found in Sections 17.1 and 17.4, respectively.
4.10 Adobe Real Time Customer Data Platform
We combine data collected about your use of our website with data from your customer account, information about your registration for and participation in DATEV seminars, and data from advertising and social media services (Google Ads, Meta Ads and LinkedIn Ads) in a Customer Data Platform. This allows us to gain a comprehensive understanding of your interests in DATEV products and to use this information to personalise content and advertisements in marketing emails andacross our online services.Your data are also processed by our processor, Adobe Systems Software Ireland Limited (4–6 Riverwalk, City West Business Campus, Saggart D24, Dublin, Ireland; hereinafter “Adobe”). Adobe also processes your data in the United States and India. The European Commission has adopted an adequacy decision for the United States under the EU-US Data Privacy Framework, and Adobe is certified under this framework. In addition, we have entered into Standard Contractual Clauses with Adobe to ensure an adequate level of data protection. A copy of the Standard Contractual Clauses is available upon request. The combined data are stored in the Customer Data Platform (CDP) for two years. The legal basis for accessing and storing information on your terminal equipment is your consent pursuant to Section 25(1) TDDDG. The legal basis for the subsequent processing of your data is your consent pursuant to Art. 6(1)(a) GDPR. You can withdraw your consent at any time via the “Cookie Settings” in the footer or adjust your preferences there.
5. Collection and Processing of the Personal Data of Interested Parties
DATEV collects your personal data when you contact us, in particular if you are interested in our products, wish to position your products with DATEV, register for our online services or contact us my email or phone.
DATEV can process the following data relating to you: contact details, customer group/interest, offer data, quotations, credit rating data, log data, company data.
Legal bases and purposes of processing
5.1 On the Basis of Your Consent (Article 6 (1) (a) GDPR)
Insofar as you have given your consent to the processing of personal data for specific purposes (e.g. the evaluation of data for marketing purposes), such processing is lawful on the basis of the consent granted by you. You may revoke the consent you have granted at any time. Please note that a revocation is effective for the future only. Data processing performed prior to a revocation is not affected.
5.2 For the Performance of Contractual Obligations (Article 6 (1) (b) GDPR)
Personal data is processed for us to provide our services, in particular for us to implement pre-contractual measures.
5.3 On the Basis of Legal Provisions (Article 6 (1) (c) GDPR) or Public Interest (Article 6 (1) (e) GDPR)
DATEV may process your personal data on the basis of other legal obligations, such as court orders.
5.4 On the Basis of Legitimate Interests (Article 6 (1) (f) GDPR)
Where required, DATEV processes your data beyond the actual performance of the contract for the purposes of safeguarding our legitimate interests or those of third parties. For instance, for:
- Better customer service
- Safeguarding IT security and operation, e.g. transfer protocols
- Reviewing and optimising processes for needs analysis and direct customercommunication
- Advertising by DATEV or market research and opinion polling insofar as you have not objected to the use of your data for these purposes
- Asserting legal claims and defending legal disputes
- Measures for business management and to further develop services and products
6. Collection and Processing of the Personal Data of Customers
DATEV collects your personal data when you contact us, i.e. in particular when you register for our online services or contact us by email or phone or when you use our products and services on the basis of existing business relations. We additionally process personal data from publicly accessible sources if said data is necessary for our service. We acquire this data in a permissible manner, e.g. from debtors’ lists or commercial registers and registers of associations. We are additionally provided with personal data by other third parties (e.g. credit reference agencies).
DATEV can process the following data relating to you: contact details, customer
group/interest, sales data, offer data, quotations, credit rating data, payment
data, log data, audit data, numbers of documents accessed from the DATEV Help Center, billing data,protocols and company data.
If you are the employee of a client, DATEV may have saved your contact details, in particular in your capacity as the contact for a certain process. If you work with DATEV applications/programs, log data from these applications and technical data from the systems with which you work may additionally be saved.
Legal bases and purposes of processing
6.1 On the Basis of Your Consent (Article 6 (1) (a) GDPR)
Processing your personal data is lawful if you have explicitly consented to it in advance for specific purposes, such as data analysis for marketing, collecting customer feedback, and creation of user profiles. You may revoke your consent at any time without giving a reason. To withdraw your consent, please use the "DATEV Einverständniserklärungen" (DATEV Consent Forms, available in German).
Please note that revoking your consent only applies to future processing. Any processing that took place before you withdrew your consent remains unaffected.
Email tracking
Once you give us your consent, we use technologies such as Tracking Pixels and personalized links in promotional emails to collect information about your activity. For example, we collect data when you open an email or click on a link within it.
These technologies allow us to track when and if an email has been opened, as well as which links have been clicked. This provides us with personal and location-related information on the effectiveness and reach of our email communications. We use email tracking to optimize personalized content, dispatch dates, and marketing campaigns, among other things.
Processing is based on your consent, in accordance with Art. 6, para. 1, no. a, of the GDPR, and in conjunction with TDDDG section 25 (1). You may revoke your consent to receive promotional emails at any time, which will take effect immediately. You may also unsubscribe by clicking the link in the respective email.
6.2 For the Performance of Contractual Obligations (Article 6 (1) (b) GDPR)
Personal data is processed for us to provide our services, in particular to execute our contracts or pre-contractual measures agreed with you and to perform your orders as well as in the course of customer management and care.
6.3 On the Basis of Legal Provisions (Article 6 (1) (c) GDPR) or Public Interest (Article 6 (1) (e) GDPR)
DATEV may process your personal data on the basis of other legal obligations, such as court orders and to maintain the integrity of the data..
6.4 On the Basis of Legitimate Interests (Article 6 (1) (f) GDPR)
Where required, DATEV processes your data beyond the actual performance of the contract for the purposes of safeguarding our legitimate interests or those of third parties. For instance, for:
- Better customer service
- Safeguarding IT security, the integrity of the data. and operation, e.g. transfer protocols
- viewing and optimising processes for needs analysis and direct customercommunication
- Advertising by DATEV or market research and opinion polling insofar as you have not objected to the use of your data for these purposes
- Asserting legal claims and defending legal disputes or based on other legal obligations, e.g., court orders
- Measures for business management and to further develop services and products
7. Collection and Processing of the Personal Data of Suppliers or Business Partners
DATEV collects your personal data when you contact us. We additionally process personal data from publicly accessible sources. We acquire this data in a permissible manner, e.g. from debtors’ lists or commercial registers and registers of associations.We are additionally provided with personal data by other third parties (e.g. credit reference agencies).
DATEV can process the following data relating to you: contact details, sales data, offer data, quotations, credit rating data, log data, audit data, service provision data, billing data, protocols, company data, existing certificates.
If you are the employee of a supplier, DATEV may have saved your contact details,in particular in your capacity as the contact for a certain process. If you work with DATEV applications/programs, log data from these applications and technical data from the systems with which you work may additionally be saved.
Legal bases and purposes of processing
7.1 On the Basis of Your Consent (Article 6 (1) (a) GDPR)
Insofar as you have given your consent to the processing of personal data for specific purposes (e.g. the evaluation of data for marketing purposes), such processing is lawful on the basis of the consent granted by you. You may revoke the consent you have granted at any time. Please note that a revocation is effective for the future only. Data processing performed prior to a revocation is not affected.
7.2 For the Performance of Contractual Obligations (Article 6 (1) (b) GDPR)
Personal data is processed for the execution of and payment for your services and in the course of supplier management. Additionally, for cooperation partners, it is processed for collaboration with DATEV.
7.3 On the Basis of Legal Provisions (Article 6 (1) (c) GDPR) or Public Interest (Article 6 (1) (e) GDPR)
DATEV may process your personal data on the basis of other legal obligations, such as court orders.
7.4 On the Basis of Legitimate Interests (Article 6 (1) (f) GDPR)
Where required, DATEV processes your data beyond the actual performance of the contract for the purposes of safeguarding our legitimate interests or those of third parties. For instance, for:
- Safeguarding IT security and operation, e.g. transfer protocols
- Consultation with credit reference agencies (to determine credit/default risks)
- Asserting legal claims and defending legal disputes
- Information about partnerships at datev.de
8. Collection and Processing of the Personal Data of Applicants and Prospective Candidates
We process personal data which relates to your application. This may be general information about you (such as name, address and contact details), details of your professional qualifications and school education or professional development, or other information with which you provide us in connection with your application. Insofar as we do not collect data directly from you and you have an active profile on XING and LinkedIn or disclose an inactive or only partially active profile to us in the course of the application process, we may also collect personal data from here.
8.1 Legal Bases and Purposes of Processing
We process your personal data for the purpose of processing your application for an employment relationship insofar as this is necessary in order to reach a decision regarding the establishment of an employment relationship with us. The legal basis for this is Section 26 (1) in conjunction with Section 8 sentence 2 of the Federal Data Protection Act (BDSG).
Further, we can process your personal data insofar as this is necessary for the defence of legal claims asserted against us on the basis of the application process. The legal basis for this is Article 6 (1) (f) GDPR (safeguarding the legitimate interests of the controller). DATEV’s legitimate interest is, for example, the burden of proof in legal proceedings pursuant to Germany’s General Act on Equal Treatment (AGG).
Insofar as an employment relationship is established between you and us, pursuant to Section 26 (1) BDSG we may continue to process the personal data provided by you for the purposes of the employment relationship if this is necessary for the execution or termination of the employment relationship or to exercise or perform the rights and obligations regarding employee advocacy pursuant to a law or company agreement.
8.2 Recipient of Personal Data
Within DATEV, the internal entities or organizational units receiving your data are the ones that require your data in order to fulfill our contractual and statutory obligations, such as recruitment managers and specialists who are looking for a new employee or who are involved in the decision regarding the appointment of a new employee; accounting departments, the company doctor, if applicable; occupational safety, employee representation, or in the context of processing and realizing our legitimate interests.
Access to your data is afforded to those within DATEV who need it for the purposes stipulated above. Processors contracted by DATEV (Article 28 GDPR) and other service providers may likewise receive data for the purposes stipulated. Here you will find an overview of all processors employed by DATEV in various matters. These are companies in the areas of IT services, logistics, telecommunications and marketing. DATEV additionally cooperates with universities to develop and improve its services. Data shall only be shared with recipients outside of DATEV if provisions allow for this or mandate this, you have given your consent or we are otherwise authorised to share data. Under these circumstances, the recipients of personal data may be, for example:
- Public authorities and institutions in the event of a statutory or official obligation.
- In rare individual cases of maintenance or for fault analysis, we may use hardware or software support partners. In this case, we will enter into agreements with these partners that include the legally stipulated contractual provisions governing purpose limitation and confidentiality as well as – if necessary – confidentiality obligations in accordance with section 203 of the German Criminal Code (Strafgesetzbuch, StGB).
- Other recipients of data may be the entities for which you have granted us your consent to the transfer of data.
8.3 Duration of Data Storage
We store your personal data for as long as it is necessary to decide on your application. If an employment relationship is not established between you and us, we may also continue to store data insofar as this is necessary for defense against possible legal claims. The application documents are deleted six months after notification of the rejection decision, unless it is necessary to store them for a longer period due to legal disputes.
Upon successful recruitment, the application documents will be kept for 12 months from the date of acceptance in order to be able to review your classification after successfully completing the probation period. The data relevant to the employment relationship is also transferred to the employee file and is subject to the deletion dates applicable to that.
8.4 Consequences of a Failure to Provide Data
The provision of personal data is not required by law or contract and you are not obliged to do so. However, the provision of personal data is necessary for the conclusion of an employment contract with us. This means that we cannot enter into an employment relationship with you unless you provide us with personal data in an application.
You can also register with us and create a prospective applicant profile. To do so, we require your personal data, namely your name, email address and telephone number. You also have the option of uploading an attachment, such as your CV.
9. Additional Processing Purposes
DATEV may process your personal data on the basis of other legal obligations, such as court orders. The legal basis is legal provisions (Article 6 (1) (c) GDPR) or public interest (Article 6 (1) (e) GDPR). Where required, DATEV processes your data beyond the actual performance of the contract for the purposes of safeguarding our legitimate interests or those of third parties. For instance, for:
- Safeguarding IT security and operation, e.g. transfer protocols
- Asserting legal claims and defending legal disputes
The legal basis for this processing is DATEV’s legitimate interest (Article 6 (1) (f) GDPR).
10. Duration of Storage
If your personal data is no longer required for the above purposes, it is deleted on a regular basis, unless its – temporary – retention is still necessary for the purposes of fulfilling contractual or legal obligations. Grounds for this may include:
- Keeping evidence for legal disputes in the context of legal statutes of limitation: statutory limitation periods under civil law may last up to 30 years, with the standard limitation period being three years.
- Log data may be stored for up to two years and your enquiries to our customer service may be stored for up to three years.
Once these periods have passed, the data is deleted following a subsequent period of review. For data with a statutory retention period of ten years, this may last up to four years.
11. Recipients of Personal Data
Within DATEV, access to your data is restricted to those organisational units that require it for the purposes described here. Processors engaged by DATEV (Art. 28 GDPR) and other service providers may also receive your data for these purposes. These include companies providing IT, consulting, logistics, telecommunications and marketing services. DATEV also collaborates withuniversities to develop and improve its services.
Your data are only disclosed to recipients outside DATEV where permitted or required by law, where you have given your consent, or where we are otherwise authorised to disclose them. Subject to these conditions, recipients of personal data may include, for example:
- Public authorities and institutions, where required by law or by a public authority.
- Inrare cases, hardware or software support providers may be engaged for maintenance or troubleshooting purposes. The contractual arrangements required by law are put in place with these providers to ensure that the data are used only for the specified purposes and are treated confidentially.
12. Third Countries
In the course of remote maintenance of standard IT components, it cannot be ruled out that an IT service provider from a third country (e.g. USA) may in rare cases have controlled and limited insights into personal data for troubleshooting purposes. A transfer of personal data e.g. to Microsoft as well as other service providers outside of the European Economic Area (EEA) will only take place if the third country has been confirmed by the European Commission to have an adequate level of data protection or other appropriate data protection guarantees are in place, e.g.:
- a self-certification under the Trans-Atlantic Data Privacy Framework,
- EU standard data protection clauses with additional safeguards, if required on the basis of a transfer impact assessment, or
- binding corporate data protection regulations.
A transfer to a third country may also take place if you have consented to it or if it is necessary in the context of a contract performance, Article 6 (1), Article 49 (1) GDPR.
13. Automated Decision Making
To a degree, your data is processed by us automatically with the aim of evaluating certain aspects of relevance to customer relations (profiling for, for example, ABC analysis). However, we do not make any automated decisions on this basis which would have a legal impact on you or would otherwise considerably harm you without the involvement of a person. Should we solely make use of automated decisions in individual cases in the future, we shall notify you of this separately insofar as this is stipulated by law.
14. Subjects’ Rights
To exercise a right as a data subject, please contact info@datev.de, stating your contact details and the data subject’s rights that you wish to exercise.
Right of access: You have the right to request information about the stored data concerning you and about how we collect, process, and store this data in accordance with Article 15 (1) GDPR. Information is available on request within the scope provided by statutory provisions.
Right to rectification: You may request that incorrect or incomplete data concerning you be corrected or supplemented in accordance with Article 16 of the GDPR.
Right to erasure: In certain situations, you have the right to request the erasure of data concerning you in accordance with Article 17 (1) GDPR. For example, you may request erasure if the data is no longer required for the intended purpose or is processed unlawfully, or if you have withdrawn your previously granted consent or have raised a legitimate objection to the processing. However, we may only delete your personal data if there are no statutory or other retention obligations.
Right to restriction of processing: You may also request the restriction of data processing based on the conditions of Article 18 GDPR.
Right to data portability: Pursuant to Article 20 GDPR, you have the right to have data that we process automatically on the basis of your consent or for the performance of a contract handed over to you or to a third party in a commonly used, machine-readable format. If you request the direct transmission of the data to another controller, this will only be done to the extent that is technically feasible.
Right to object: Pursuant to Article 21 (1) GDPR, you have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you, insofar as the processing is carried out after balancing interests (Article 6 (1) (f) GDPR) or in the public interest (Article 6 (1) (e) GDPR). You can object to the use of your personal data for direct marketing at any time without stating a reason by contacting widerspruch@datev.de.
Right to lodge a complaint with a supervisory authority: In the event of a complaint, you can contact a data protection supervisory authority. The Bavarian Data Protection Authority (BayLDA) is the responsible supervisory authority for DATEV.
15. Obligation to Provide Data
We require the following personal data from you in the course of the business relationship:
- Data required to initiate and execute a business relationship
- The data necessary for the performance of the related contractual obligations
- Data which we are legally obliged to collect
Without this personal data, we are unable to enter into or execute a contract with you.
16. Security
DATEV takes suitable technical and organisational measures to ensure a level of protection appropriate to the risk involved and to protect personal data from destruction, loss, alteration or unauthorised disclosure and access. The effectiveness of these measures is reviewed, assessed and evaluated on a regular basis.
17. Social Media
We operate accounts on various social media platforms in order to better communicate with our existing and prospective customers, and also to better present DATEV as a company as well as our products and services. Furthermore, we also use our social media accounts for advertising purposes, with target audiences being defined in order to be able to address them in a targeted manner. In this context, we also use services from external service providers that may be located in a third country outside the EU. We process personal data as part of our social media activities on the legal grounds of our legitimate interest pursuant to Art. 6 (1) (f) GDPR, insofar as the processes do not require consent.
17.1 Meta Platforms
We operate several Facebook fan pages as joint controllers with Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland (hereinafter “Facebook”), in order to present our products and services on the platform, provide interested parties with a channel for communicating with us, and promote DATEV as a company.
In this context, we may receive information from Facebook, such as statistical analyses of how our fan pages are used, based on interactions, likes and comments. This information may also include device information, such as your IP address, operating system or browser type. Further information about these statistical analyses can be found here or in Facebook’s Privacy Policy. You can manage your personal advertising preferences here.
We use the information we receive to improve our Facebook presence and tailor our products and services more closely to our customers’ interests. The legal basis for this processing is our legitimate interest pursuant to Art. 6(1)(f) GDPR.
Please note that we have no control over the extent to which Facebook collects and processes data for its own purposes and under its own responsibility. However, it can be assumed that Facebook uses the information described above to compile detailed statistics and for its own market research and marketing purposes. Further information about how Facebook processes data can be found here in Facebook’s Privacy Policy. If you wish to exercise your data protection rights, the easiest way to do so is to contact Facebook directly, as Facebook has access to the platform and therefore to all user data, as well as information about the specific purposes for which those data are processed. We will, of course, be happy to assist you in exercising your rights.
In addition, we use Meta’s retargeting and conversion technologies on our website. These technologies allow us to show relevant advertisements and offers on Meta to users who have previously shown an interest in our website, content or services and who are also Meta users.
For this purpose, Meta’s “Facebook Pixel” is integrated into our website. When you visit our website, the pixel informs Meta that you have accessed our website and indicates which parts of our content or services you have shown an interest in (retargeting). If you have reached our website via a Facebook advertisement or through another channel, this technology allows us and Meta to determine whether you clicked on an advertisement, were redirected to our website and subsequently reached a predefined target page (conversion page) linked to the advertisement. It also allows us to determine whether you completed a purchase or performed anotheraction or used another service defined as a conversion.
If you have consented to the use of the Facebook Pixel, your browser will automatically establish a direct connection to Meta’s servers via the pixel. We have no control over the extent to which Meta collects and subsequently uses the data obtained through these technologies beyond the purposes described above. We therefore provide the following information based on our current knowledge: By integrating these technologies into our website, Meta is informed that you have accessed the relevant part of our website or clicked on one of our advertisements. If you are registered with Meta, Meta may associate your visit with your account. Even if you are not registered with Meta or are not logged in, Meta may obtain and store your IP address via the Facebook Pixel. When you use our website, Meta processes, in particular, your IP address, Facebook user ID, mobile advertising ID (IDFA/GAID), device information, browser information, location information, usage data, user behaviour, marketing information, interactions with advertising materials, interactions with products, interactions with website services, and advertisements and content viewed.
Your data are stored on servers within the EU for as long as necessary for the purposes for which they are processed and are not disclosed to third parties outside the Meta network. However, your data may be transferred within the Meta network to third countries within the meaning of the GDPR, such as the United States. Transfers of your data to servers in the United States are primarily based on the EU-US Data Privacy Framework. In addition, data transfers are governed by the Meta Page Controller Addendum, the Meta Data Processing Terms, the Meta EU Data Transfer Addendum, the Meta Controller Addendum, as well as the EU Standard Contractual Clauses entered into between Meta Platforms Ireland Ltd. and Meta Platforms LLC in the United States. The processing carried out for conversion tracking purposes is performed by Meta on our behalf pursuant to Art. 28 GDPR. Processing for all other purposes described above is carried out under joint controllership pursuant to Art. 26 GDPR.
For this purpose, we have entered into Meta’s Controller Addendum, under which we have agreed that we are responsible for providing the information required by law, while Meta is responsible for facilitating the exercise of data subjects’ rights. Each controller is responsible for its respective part of the processing, including ensuring that there is a valid legal basis for the processing, maintaining the security of the joint processing and addressing personal data breaches relating to the joint processing. Further details about the processing of personal data can be found in Meta’s Data Processing Terms. The legal basis for accessing and storing information on your terminal equipment is your consent pursuant to Section 25(1) TDDDG. The legal basis for the subsequent processing of your data is your consent pursuant to Art. 6(1)(a) GDPR. You can withdraw your consent at any time by disabling “Marketing Cookies” in the “Cookie Settings” in the footer or adjust your preferences there.
17.2 Instagram
Furthermore, we use the Instagram service in joint responsibility with Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland (hereinafter “Instagram”). As Facebook and Instagram are operated by the same service provider, the above information on Facebook essentially also applies to Instagram. To this end, we operate Instagram accounts in order to present ourselves as a company and as an employer, market our products and services, and offer our prospective customers a simple and fast channel for communication and interaction. If you contact us via our account, for example by commenting on posts or writing private messages, Instagram processes and stores your personal data.
We have no control over the extent to which Instagram collects and processes personal data for its own purposes, such as the IP address of your device or other information about log-ons. However, it cannot be ruled out that Instagram may use this collected data for advertising purposes and transfer personal data to a third country, in particular the US, on its own responsibility. For more information on data processing, please refer to the Instagram Privacy Policy of Meta Platforms Ireland Limited. You can manage your individual privacy and security settings on Instagram here.
17.3 X
DATEV also uses the X short message service provided by X Internet Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland (hereinafter referred to as “X”). For this purpose, we operate X profiles in order to present our products and services, offer prospective customers a communication channel, and market DATEV as a company.
If you are on X, which includes when you visit our X profile, X processes personal data as a data protection controller independently of us and may transfer this data to countries outside the EU/EEA. In addition to the data you voluntarily provide, such as your name, username, and e-mail address, X processes the following additional data: IP address, information about visited websites, location data, data about the cellular service provider, and information about the device used (device ID and application ID). X also processes the personal data of unregistered visitors. We have no influence on the nature or scope, or on the type of processing or use, or on the disclosure of this data by X to third parties. You can find more information about which data is processed by X and for what purposes it is used here.
Please note that you use the various functions of X, e.g., sharing, liking, commenting, etc., on your own responsibility and that we have no influence on the extent to which X collects and processes data as a data controller independent of us. In particular, we are not aware of how X uses the data from your visit to X for its own purposes, how long X stores this data, and whether this data is passed on to third parties.
This data is processed by X in the US, although X undertakes to comply with European data protection law. Through using X, data may reach third parties, in particular the operators of these systems. Their processing can be found in their privacy policy. We expressly point out that in instances like these where data is transferred to third countries, the level of data protection in the third country may not have been determined by the EU Commission in accordance with Article 45 GDPR and that there are no suitable guarantees within the meaning of Article 46 GDPR. It is therefore possible that the level of data protection in the third country is not equivalent to that of the GDPR. Possible risks of transfer to these countries include access by third parties, in particular by state security authorities, and processing for commercial purposes in order to display specific advertising to users.
We ourselves do not collect, process, or receive any personal data from X arising from your use, only aggregated analyses of your use. However, if we repost or respond to your posts or even compose posts that link to your profile, we will also process the data you enter into the service, in particular your (user) name and the content published on your account, insofar as it is incorporated into our offer and made available to our followers.
If you are logged into X as a user, X may be able to associate this information with your user account. If you want to avoid this, you should log out of X, delete the cookies on your device, and close and restart your browser. You can also restrict the processing of your data by applying further restrictions in the general settings of your X account and under “Privacy and Security.” Depending on the operating system, mobile devices (smartphones, tablets, etc.) let you restrict X’s access to contacts, calendar data, photos, location data, etc. in the settings options. You can also customize your settings for personalized ads here.
Further information on X’s privacy and data protection can be found here:
- Privacy Policy
- Information about the cookies used by X
- Option for viewing your own data on X
- Information about the inferences that X has made about you
- Information about the available personalization and privacy settings
- X Privacy Form and Archive Requirements
17.4 LinkedIn
We also have a presence on the LinkedIn platform, operated by LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland (hereinafter “LinkedIn”). We operate our LinkedIn company page on this platform as joint controllers withLinkedIn within the meaning of Art. 26 GDPR.
When you use LinkedIn but are not visiting our LinkedIn company page, LinkedIn processes personal data as a controller independently of us. Please note that you use the various functions provided by LinkedIn, such as sharing, liking and commenting, on your own responsibility and that we have no influence over the extent to which LinkedIn, as a controller independently of us, collects and processes data.
In particular, we do not know how LinkedIn uses data relating to your visit to the LinkedIn website for its own purposes, how long LinkedIn stores these data or whether these data are disclosed to third parties. However, it can be assumed that LinkedIn uses your IP address, information about your device and other personal data to compile detailed statistics and for its own market research and marketing purposes.
If you are logged in to LinkedIn as a user, LinkedIn may be able to associate this information with your user account. If you wish to prevent this, you should log out of LinkedIn, delete the cookies stored on your device, and close and restart your browser. Further information about the processing of data by LinkedIn as a controller independently of us can be found here.
When you visit our LinkedIn company page, LinkedIn also processes personal data relating to users of our LinkedIn company page and provides us with statistical analyses of how our LinkedIn company page is used, based on interactions, likes and comments (so-called “Page Insights”). To produce these statistical analyses, LinkedIn also processes data that you have already provided to LinkedIn in your profile, such as your age, country of origin, industry, employer and employment status. We do not receive any personal data relating to you in this context and are unable to draw any conclusions about specific individuals. Furthermore, we do not collect any data relating to your use of our LinkedIn company page.
The processing of personal data in connection with Page Insights is carried out by LinkedIn and us as joint controllers. We use the information obtained to make our LinkedIn company page, as well as the services we offer to our customers, more attractive and better tailored to their interests. The legal basis for this processing is your consent pursuant to Art. 6(1)(a) GDPR. Further information about these statistical analyses can be found in the LinkedIn Privacy Policy. To set out our respective data protection responsibilities, we have entered into a joint controller agreement with LinkedIn. You can find the agreement here. In particular, the agreement provides that LinkedIn is responsible for providing you with the required information about the joint processing of personal data by LinkedIn and us on our LinkedIn company page. We therefore recommend that you review LinkedIn’s Privacy Policy regularly.
If you wish to exercise your rights as a data subject under data protection law, the easiest way to do so is to contact LinkedIn or its Data Protection Officer directly, as LinkedIn has access to the platform and therefore to all user data, as well as information about the specific purposes for which such data are processed.
We will be happy to assist you in exercising your rights as a data subject. You can also contact us directly at widerspruch@datev.de. In this case, we will forward your request to LinkedIn.
According to the LinkedIn Privacy Policy, LinkedIn also processes personal data in the United States and other third countries. According to LinkedIn, personal data are only transferred to countries for which an adequacy decision by the European Commission pursuant to Art. 45 GDPR or appropriate safeguards pursuant to Art. 46 GDPR are in place. Further information can be found here.
We have also agreed that the Irish Data Protection Commission will act as the lead supervisory authority for the processing of data for Page Insights. You have the right to lodge a complaint with the Irish Data Protection Commission or with any other supervisory authority.
In addition, we use LinkedIn’s retargeting and conversion tracking technologies on our website. As part of LinkedIn’s retargeting technology, information about your behaviour on our website is collected and stored. These data are stored in cookies on your computer and accessed by LinkedIn. The cookies enable LinkedIn to collect, process and use the information they contain and to create a pseudonymised user profile. These user profiles are used to analyse your behaviour when visiting our website and to display relevant and personalised content and advertisements to you on the LinkedIn platform based on your behaviour on our website. If you have reached our website via an advert on the LinkedIn platform, LinkedIn stores a so-called conversion cookie on your computer. If you subsequently visit certain pages on our website, both LinkedIn and we can determine that someone has clicked on the advert and was redirected to our website. The information obtained using the conversion cookie is used to compile conversion statistics.
As an advertising customer, we receive information about the total number of users who clicked on our advert on LinkedIn and were redirected to a page containing a conversion tracking tag. However, we do not receive any information that enables us to identify individual users.
When you use our website, LinkedIn processes, in particular, your IP address, browser type and browser language, the date and time of your request, and one or more cookies that may identify your browser.
If you do not want to receive personalised advertising across your devices, you can disable this feature in the Advertising Settings.
Your data are stored on servers within the EU and retained only for as long as necessary for the purposes for which they are processed. They are not disclosed to third parties outside LinkedIn. Conversion cookies expire after 90 days and are not used to identify you personally. Transfers of your data to the United States are based on the EU-US Data Privacy Framework. In addition, we have entered into the EU Standard Contractual Clauses with LinkedIn.
Data are transferred to LinkedIn on the basis of a data processing agreement pursuant to Art. 28 GDPR. Further information and LinkedIn’s Privacy Policy can be found here.
We access and store information on your terminal equipment on the basis of your consent in accordance with Section 25(1) TDDDG. Any subsequent processing of your personal data is based on your consent in accordance with Art. 6(1)(a) GDPR.
You may withdraw your consent at any time by disabling “Marketing Cookies” in the “Cookie Settings” in the footer. You can also adjust your preferences
there.
17.5 XING
Furthermore, we use the social network XING, owned by New Work SE, Am Strandkai 1, 20457 Hamburg, Germany (hereinafter referred to as “XING”), to present ourselves as an employer by means of an employer branding profile, to advertise vacancies in our company, to contact you, and to add you to our network. For more information on the application process at DATEV when using a XING profile, please refer to section 8 of our privacy policy.
In addition, we display our own ads and posts on XING. In this process, XING collects data about your interaction with the ad. This includes data such as reach, clicks, and frequency. In doing so, XING gives us access to statistical analyses of our advertisements as well as activities on our profile, but we do not receive any information from XING about your personal interaction with the advertisement or personal evaluations or analyses. It is not possible for us to make inferences about individual user profiles.
When you visit us on our company profile, XING processes personal data on its own responsibility, e.g., to create detailed evaluations and statistics. We have no influence on this data processing nor do we receive personal evaluations from XING. Here you can view the Privacy Policy and you can assert your rights as a data subject against XING here.
17.6 YouTube
With our YouTube channels (“DATEV” and “DATEV Help Videos”), we want to use videos to present our products and services, report on the latest news at DATEV, and present DATEV as an employer.
If you visit the video platform YouTube from the European Economic Area or Switzerland, your personal data will be processed by the platform’s service provider, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter referred to as “Google”).
When you visit YouTube, Google collects and processes personal data for its own purposes, such as providing, maintaining, or improving the desired Google service. The data that Google collects and how it is used depends on how you use these services and how you manage your privacy settings. DATEV has no influence over this processing.
Google provides us with a statistical and anonymized analysis of user behavior with regard to the videos we post on the YouTube platform. No further processing of (personal) data takes place.
Google’s Privacy Policy can be found here. You can make changes to your Google account here. You can make changes to personalized advertising for Google services here.
17.7. TikTok
In addition to Instagram, Facebook, YouTube, Xing and LinkedIn, DATEV now also has a presence on TikTok, where it publishes social media content. Through its presence on TikTok, DATEV aims to reach apprentices and students and present the company as an attractive employer.
If you interact with us through our account, for example by commenting on posts or sending us private messages, TikTok processes and stores your personal data. Although Standard Contractual Clauses are used for transfers to third countries, the processing remains insufficiently transparent, meaning that data subjects do not have access to effective legal remedies.
To analyse and assess the risks associated with the use of TikTok, DATEV has carried out a data protection impact assessment.
If you wish to exercise your data subject rights, the easiest way to do so is to contact TikTok directly, as TikTok has access to the platform and therefore to the relevant user data and information concerning the specific purposes of the associated processing activities. We will, of course, be happy to assist you in exercising your data subject rights.
18. Friendly Captcha
We use Friendly Captcha, a service provided by Friendly Captcha GmbH, located at Am Anger 3-5, 82237 Wörthsee, Germany (referred to as "Friendly Captcha").
Friendly Captcha is used to protect our websites and/or online-forms from attacks by automated programs/scripts (so-called "bots"). For this purpose, a JavaScript element is integrated into the source code. As part of this process, your IP address is captured by Friendly Captcha in order to send a cryptographic task to your device. This task is solved in the background by your device. The purpose of this is to be able to determine whether the visitor is a human being or whether the use is abusive through automated, machine processing (e.g. bots).
Friendly Captcha does not set or read any cookies on the visitor's device. The IP addresses are only stored in hashed form (one-way encryption) and are not used to personally identify the visitor of the website. No data is transferred to a third country.
Friendly Captcha processes and stores the following data as described above:
- IP address of the visitor
- Number of requests from the (hashed) IP address per time period
- Request header data, especially user agent (browser, operating system), origin and referrer (previous websites)
- Response of the cryptographic task solved by the visitor's device
- Date/time of the request
- Version of the Friendly Captcha service used
The legal basis for this processing is the legitimate interest of DATEV eG (Article 6 (1) (f) GDPR), namely to protect our website from abusive access by bots.
Further information on data processing can be found in the privacy policy for end users of Friendly Captcha.
19. Video integration via YouTube
YouTube videos are incorporated into a number of our websites. These are incorporated using what is known as a two-click solution – only when you click on the video will the standard data be transmitted to Google. In individual cases, the data transmitted may be the IP address, the specific address of the page viewed on our website, if applicable the page from which you were redirected to us (link source), the browser’s transmitted identifier, and the system date and time of the page view. Google may receive additional data regarding cookies already stored. Google is responsible for this data. No data is transmitted to You Tube/Google if no pages with integrated videos are viewed.
20. Links to Other Websites
If you access an external website from our site (external link), the external provider may obtain information from your browser regarding which site you accessed theirs from. The external provider is responsible for this data. Like any other provider, we are unable to influence this process.
21. Specific Data Protection Information
The following provisions apply primarily to DATEV surveys conducted using Microsoft Forms:
Collection and processing of personal data when taking part in DATEV surveys using Microsoft Forms
DATEV uses Microsoft Forms to conduct surveys and polls, either directly in Forms or as part of online meetings, video conferences and/or webinars. Microsoft Forms is a service provided by Microsoft Corporation. The data are processed on behalf of DATEV by:
Microsoft Ireland Operations Limited
One Microsoft Place
South County Business Park
Leopardstown
Dublin 18
D18 P521
Ireland
Please note that this privacy notice only provides information about how DATEV processes your personal data when you participate in a survey conducted using Microsoft Forms. For information about how Microsoft processes your personal data, please refer to Microsoft’s relevant privacy notice.
Microsoft Privacy Statement – Microsoft Privacy
- MicrosoftServices Agreement
- Security and Privacy in Microsoft Forms
When you use Microsoft Forms, various types of data are processed. The extent of the data processed also depends on the information you provide when participating in a poll or survey in Forms, particularly when responding to open-ended questions.
The following personal data are processed:
- IPaddress
- Username
- Display name
- Email address
- Profile picture (optional, if stored in Microsoft 365)
- Preferred language
- Status (optional, if stored in Microsoft 365)
- Date and Time the questionnaire was opened
- Date and time the response was submitted
- Information provided in surveys: The information collected varies depending on the survey. When responding to open-ended questions, users decide what personal data, if any, they wish to provide.
Legal basis: The legal basis for the processing depends on the specific context in
which the survey is conducted. The processing may be necessary for the
performance of a contract (Art. 6(1)(b) GDPR) or for the purposes of the
legitimate interests pursued by us or by a third party (Art. 6(1)(f) GDPR), for
example, to ensure IT security and the proper operation of our IT systems.
Where personal data of employees are processed, the legal basis for the processing is Art. 88(1) GDPR in conjunction with Section 26(1), sentence 1 BDSG and the DATEV eG works agreement on employee surveys, insofar as the processing is necessary for the establishment, performance or termination of the employment relationship. In all other cases, the legal basis for the processing is Art. 6(1)(f) GDPR, where the processing is necessary for the purposes of legitimate interests.
DATEV eG’s legitimate interest lies in obtaining information to improve its services, offerings and products, as well as customer and employee satisfaction.
Participation in surveys and/or polls is generally voluntary.
Device Identifiers and Location Data
No device identifiers or other location data are collected.
Further Purposes of Processing
In additionto Section 9, “Further Purposes of Processing”, of DATEV’s Privacy Policy, the following additional purposes for which Microsoft processes data apply when using Microsoft Forms:
According to information provided by Microsoft, Microsoft processes data as part of its “business operations” for the following activities, each of which is related to providing products and services to the customer: (1) billing and account management; (2) compensation (e.g. calculating employee commissions and partner incentives); (3) internal reporting and business modelling (e.g. forecasting, revenue, capacity planning and product strategy); (4) combating fraud, cybercrime or cyberattacks that may affect Microsoft or Microsoft products; (5) improving core functionality relating to accessibility, privacy or energy efficiency; and (6) financial reporting and compliance with legal obligations (subject to the restrictions on the disclosure of processed data described below).
When processing data for these business operations, Microsoft applies the principles of data minimisation and does not use or process Customer Data, Professional Services Data or Personal Data for: (a) user profiling; (b) advertising or similar commercial purposes; or (c) any other purpose other than those specified in this section.
For the processing of data for the business purposes described above, Microsoft determines both the means and purposes of the processing. Microsoft considers itself solely responsible for ensuring compliance with all applicable laws and fulfilling the relevant obligations in relation to such processing.
Storage Period
Anonymised log data are retained for up to 30 days and can be accessed by DATEV. The data are accessed solely for the purposes of identifying and resolving system errors, investigating security issues, and detecting manipulation or other forms of misuse. Access is restricted exclusively to administrators of the Microsoft 365 platform.
Data collected through surveys are retained only for as long as necessary for the purposes for which they were collected. The applicable retention period and the timeframe for deletion depend on the specific survey. Participants are informed about the applicable retention and deletion arrangements as part of the relevant survey.
Recipients of Personal Data
The datarequired to provide the service are transferred to Microsoft for the
performance of the contractual services. In particular, the user ID and IP
address are transmitted to Microsoft. When the service is used, content data
are also transferred to Microsoft. According to Microsoft, content data are
encrypted in transit.
Further information about Microsoft’s processing of personal data and its use of
encryption can be found in the Microsoft Privacy Statement and on the Microsoft Purview information pages.
Third Countries
As a general rule, personal data are not processed outside the European Union (EU), as we have restricted data storage to data centres located within the EU.
However, we cannot rule out the possibility that data may be routed through
internet servers located outside the EU. This may occur, in particular, if
participants in an online meeting or a Forms survey are located in a third
country.
In individual cases, we also cannot rule out the possibility that data may be
accessed from a third country for support or maintenance purposes or where
Microsoft processes data for its own business purposes.
However, the data are encrypted during transmission over the internet and are therefore protected against unauthorised access by third parties.
What Happens if You Do Not Provide Your Data?
If you do not provide your personal data, we will be unable to include you in the poll or survey.
Version dated: September 2026