Privacy Policy for the Use and Provision of the Onventis Supplier Portal

30st June 2023

Introduction

With the following data protection declaration, Onventis GmbH (hereinafter referred to as Onventis) clarifies which types of your personal data (hereinafter also referred to as “data”) are processed for which purposes and to what extent in the context of the provision of the Onventis Supplier Portal.

Onventis has taken appropriate technical and organizational protective measures to protect your personal data against loss, destruction, manipulation, and unauthorized access.

 

Outline

  1. Responsible
  2. Contact details of the data protection officer
  3. Overview of processing
    • Processing of your personal data for registration and use of the Supplier Portal
  4. Transmission of personal data
  5. Contact
  6. Transactional e-mails by Brevo
  7. Login Function by Cloud IAM
  8. Storage of data
  9. Cookies
  10. Rights of data subjects
  11. Changes and updates to the Privacy Policy

 

  1. Responsible

Onventis GmbH

Gropiusplatz 10

70563 Stuttgart

 

  1. Contact details of the data protection officer

E-mail address: privacy@onventis.de

  1. Overview of processing

The following overview summarizes the types of data processed and the purposes of their processing and refers to the data subjects.

 

3.1    Processing of your personal data for registration and subsequent use of the Supplier Portal

Onventis processes the following personal data:

  • E-mail address of the main contact
  • Telephone number of the main contact

Purposes of data processing

Your data will be collected and processed for the following purposes:

  • Registration in the Supplier Portal, in particular to fill in the registration form in step 2 (Personal data) and in step 4 (company data)
  • Administration of the customer user account
  • Elimination of support incidents
  • Documentation and logging of loggings
  • Provision of the Supplier Portal

 

If necessary, Onventis needs the generated logs and their evaluations for the maintenance of the technical system operation as well as for clarification in the event of damage or misuse.

 

Legal basis of processing

The basis for the processing of your personal data is your consent in accordance with Article 6 para. 1 a) GDPR. The use of Supplier Portals can only take place with your consent, which can be revoked at any time.

  1. Transmission of personal data

If this transfer takes place for administrative purposes, the transfer of the data is based on the legitimate business and business interests of Onventis or takes place if the fulfillment of the contract-related obligations is necessary or if there is a consent of the data subjects or a legal permission.

  1. Contact

When contacting Onventis (by e-mail or contact form), the details of the requesting persons will be processed insofar as this is necessary to answer the contact inquiries and any requested measures.

Types of data processed

Inventory data (i.e., name), contact data (i.e., e-mail, telephone numbers), content data (i.e., text information)

Purposes of processing:

  • Contact requests and communication

Legal bases

  • Performance of the contract and precontractual enquiries (Art. 6 para. 1 b) GDPR)
  • Legitimate interests (Art. 6 para. 1 f) GDPR)
  1. Transactional e-mails by Brevo

We use the services of the service provider Sendinblue GmbH SAS, 106 boulevard Haussmann, 75008 Paris, France (Brevo), to send transactional e-mails, for example to confirm orders. The service provider processes this data on our behalf in accordance with Art. 28 GDPR.

Through the use of the service provider, a third country transfer cannot be ruled out. The risk was assessed in cooperation with our data protection office and it was classified as low.

We process your data for the purpose of sending you transactional e-mails in order to fulfill our contractual obligations pursuant to Art. 6(1)(b) GDPR.

  1. Login Function by Cloud IAM

For the login function, we use the services of the following service provider: Cloud-IAM SAS 37 Boulevard Solférino, Immeuble Eurosquare, 35000, Rennes, France. The service provider processes this data on our behalf solely within the EU/EEA and in accordance with Art. 28 GDPR.

We process your login data to enable you to logon to our services. We process this data in order to fulfill our contractual obligations pursuant to Art. 6(1)(b) GDPR.

  1. Storage of data

The personal user data processed by Onventis will be deleted in accordance with the legal requirements as soon as their consents permitted for processing are revoked or other permissions

cease to apply (i.e., if the purpose of the processing of this data has ceased to exist or they are not necessary for the purpose).

Your data will only be stored for as long as is necessary to fulfil the respective purpose and to comply with legal requirements. After expiry of this statutory retention period, your personal data will be deleted by Onventis immediately.

  1. Cookies

Matomo
Onventis uses the Matomo web application for the purpose of collecting usage statistics in the Onventis Supplier Portal. Cookies are used to record page views. Matomo is operated on Onventis own servers (on-premises). No data will be passed on to third parties.

Google reCaptcha
On this website we use the reCAPTCHA function of Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland (“Google”). This function is primarily used to distinguish whether an input is made by a natural person or abusively by machine and automated processing. The service includes the sending of the IP address and, if applicable, other data required by Google for the reCAPTCHA service to Google and is carried out in accordance with Art. 6 para. 1 f) GDPR on the basis of our legitimate interest in determining individual responsibility on the Internet and avoiding misuse and spam. As part of the use of Google reCAPTCHA, personal data may also be transmitted to the servers of Google LLC. in the USA.

Further information on Google reCAPTCHA and Google’s privacy policy can be found at: https://www.google.com/intl/de/policies/privacy/

  1. Rights of data subjects

As a data subject, you are entitled to various rights under the GDPR, which result in particular from Articles 15 to 21 GDPR:

  • Right to information
  • Right to rectification
  • Right to erasure
  • Right to restriction of processing
  • Right to data portability
  • Right to object
  • Right to lodge a complaint with the competent supervisory authority

The State Commissioner for Data Protection and Freedom of Information Baden-Württemberg

Lautenschlagerstraße 20

70173 Stuttgart

Tel:0 711/615541-0Fax: 0711/615541-15

E-Mail: poststelle@lfdi.bwl.de

  1. Changes and updates to the Privacy Policy

Onventis asks that you regularly inform yourself about the content of the data protection declaration. Onventis will adapt the privacy policy as soon as the changes to the data processing carried out by Onventis make this necessary. We will inform you as soon as the changes require your cooperation (i.e., consent) or other individual notification.

Privacy
When you visit our website, information from certain services may be stored via your browser, usually in the form of cookies. Here you can change your privacy settings. Please note that blocking some types of cookies may affect your experience on our website and the services we offer.