Privacy notice at SYNEDAT
1. Responsible body and contact
The responsible body for the websites described here is Synedat Group GmbH, Philipsbornstraße 2, 30165 Hannover, Germany. General enquiries: [email protected], phone +49 511 546850-0.
You can reach our data protection team at [email protected] or by telephone on the general number. You can send data protection inquiries by post to the company address with the addition "Data protection team".
2. Scope
This privacy notice applies to the public websites of Synedat Group GmbH, including pages about the company, data centres, technology, consulting, integration, services, careers, the blog, wiki, FAQ, newsletters and publicly accessible services. Additional privacy information may apply to authenticated applications, customer accounts or specific ordering processes.
3. Website access and technical logs
When you access a website, our systems and technical service providers process the data required for transmission. This may include the IP address, date and time, requested address, response status, amount of data, browser, operating system and a referring page sent by the browser.
Processing serves delivery, stability, troubleshooting and IT security. The legal basis is Article 6(1)(f) GDPR. Logs are retained only for as long as needed for operation and security. If a specific security incident occurs, necessary data may be kept until the investigation is complete and for the establishment, exercise or defence of legal claims.
4. Hosting, delivery and technical providers
We use Microsoft Azure for parts of our technical infrastructure and Cloudflare for DNS, content delivery and security functions. In particular, IP addresses, requested resources, timestamps and technical security characteristics may be processed. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is secure, available and efficient operation.
Where a provider processes data on our behalf, it is engaged under Article 28 GDPR. Where data is processed outside the European Economic Area, we rely on a lawful basis under Articles 44 et seq. GDPR, in particular an adequacy decision or appropriate safeguards. Public files may be loaded from static.synedat.com or a domain-specific SYNEDAT static host. The Inter font is served through infrastructure under our control without contacting Google Fonts.
5. Consent management and Matomo
Your choices regarding optional analytics and external media are stored for no more than 180 days. Connected subdomains may use the essential cookie __Secure-synedat_consent_v2; otherwise the choice is stored as synedat.consent.v1 in the local storage of the respective website. It contains the version, scope, choice and expiry time, but no visitor identifier. Essential device access is based on section 25(2)(2) TDDDG; processing to reliably respect your choice is based on Article 6(1)(f) GDPR.
Matomo is loaded only after your voluntary consent under Article 6(1)(a) GDPR and, where applicable, section 25(1) TDDDG. The self-operated analytics service is provided through stats.synedat.com or a domain-specific SYNEDAT analytics endpoint. This integration uses no analytics cookies; IP addresses are masked, search parameters and URL fragments are removed, and Do Not Track is respected. Form entries, customer identifiers and contact or application content are not sent to Matomo. Analytics is disabled on form pages.
You can change your choice at any time in Cookie settings with effect for the future. Matomo remains disabled without consent. Detailed data is retained only as long as required for statistical analysis and is then deleted or aggregated so that individuals can no longer be identified.
6. Contact by e-mail or phone
If you contact us, we will process the information you provide and the content of your request in order to process your request and answer any queries. This may include your name, company, contact details, and project or service information.
In the case of an enquiry about a contract with you, Article 6 (1) (b) GDPR is relevant. In the case of a company's professional contact persons and other general enquiries, the processing may be based on Article 6 (1) (f) GDPR; the interest lies in appropriate business communication. Processing required by law is based on Article 6 (1) (c) GDPR.
No passwords, secret keys or particularly sensitive documents are required for an initial inquiry. Coordinate a protected transmission path for confidential documents with your contact person.
7. Offers, contracts and supplier contacts
Contact, contract, service and billing data may be processed for the preparation of offers, contract execution, service coordination and billing. In the case of natural contractual partners, this is done for the purpose of initiating or fulfilling a contract in accordance with Article 6 (1) (b) GDPR. Article 6 (1) (f) GDPR applies to contact persons of legal entities. Retention and documentation obligations may require processing in accordance with Article 6 (1) (c) GDPR.
The recipients are the persons involved in the respective task and the service providers actually used for this purpose. A transfer to authorities or other bodies takes place if there is a legal obligation or another viable legal basis.
8. Online applications and project profiles
On our Jobs website, you can apply for a permanent position or freelance collaboration as well as on your own initiative. We process the chosen application path, name, e-mail address and professional focus. You can voluntarily submit your telephone number, experience, availability, work location preference, scope of assignment, salary or fee expectations, a profile link, a message and a PDF profile. Please do not send any identification documents, bank or health data. Without the information described as required, we cannot process the online form.
The information is used to review your application, to contact you and to decide on a possible cooperation. For employment applications, Section 26 (1) BDSG in conjunction with the relevant provisions of the GDPR is particularly relevant. In the case of a freelance contract with you, the processing is based on Article 6 (1) (b) GDPR; in the case of contact persons of a company, if applicable, on Article 6 (1) (f) GDPR. Additional consent to the necessary processing is not made a condition.
We store the application data in our self-operated ERPNext with HRMS. Access is granted to authorized persons involved in recruiting and the respective professional review as well as required technical administrators. PDF attachments are stored as private files and are not made available via the public download or static domain. The form does not transmit any application data to Matomo; this statistic is switched off on application pages. There is no automated selection decision.
To protect the transmission, the form uses a technically required, random session cookie __Host-ngw-application for a maximum of two hours and a form verification linked to the session, website and expiry time. Short-lived connection identifiers hashed with a secret key limit abusive calls for a maximum of one hour. This is based on Section 25 (2) number 2 TDDDG and, as far as personal data is concerned, on Article 6 (1) (f) GDPR; our interest is the protection of the application service.
During an ongoing procedure, the information required for this will be retained. For rejected applications received via this form and completed in ERPNext, deletion after 180 days is provided. Documented further storage, for example for the assertion or defense of legal claims, may justify longer storage. If a cooperation is established, the data required for this will be further processed in the corresponding personnel or contract process. Storage in backup copies is based on the separate backup and restoration procedure, the specific deadlines of which are still to be supplemented in the final version.
An unsolicited application is not consent to a permanent talent pool, newsletter dispatch or the sharing of a profile with potential clients. Such additional purposes will be clarified separately with you. For questions and data subject rights, you can reach our data protection team at [email protected].
9. Newsletters and customer portals
The currently checked homepages provide information about newsletters and customer services; no newsletter registration or customer login was carried out there. A mere request does not result in a newsletter subscription.
Before a registration is introduced, the shipping service provider, content, frequency, proof of required consent, deregistration and storage period must be documented. Consent-based processing is based on Article 6 (1) (a) GDPR and can be revoked for the future. For specific portal offers, the identity services, roles, protocols and contractual references used must be described separately.
10. Links, Sharing and Social Networks
Maps, social media profiles and sharing functions for X, Facebook and LinkedIn are integrated as normal links. The website does not load any social media scripts, embedded profiles or tracking pixels in advance. When a network is opened, the data required to establish a connection is transmitted to this provider; its data protection information applies there. A post is only published by the respective provider after your action.
"Copy Link" writes the cleaned page address to the clipboard when you explicitly click on it. The native sharing feature passes the address and page title to your chosen service. Search parameters and URL fragments are removed. An active public company profile may also require its own privacy information and responsibilities.
11. Retention
We retain personal data only for as long as required for the relevant purpose. It is then deleted or anonymised unless statutory retention obligations, a specific security investigation or legitimate interests in the establishment, exercise or defence of legal claims require further retention. The periods stated in section 8 apply to applications. Commercial, tax and contractual records are retained for the applicable statutory periods.
Backups are overwritten in accordance with the operational backup cycle. They are not used as an archive for data deleted in the ordinary course; following a necessary restoration, the deletion rules of the relevant production system apply again.
12. Your rights and complaints
Subject to the statutory requirements, you have rights of access, rectification, erasure, restriction and data portability. You may withdraw consent at any time with future effect. Where processing is based on Article 6(1)(e) or (f) GDPR, you may object on grounds relating to your particular situation. You may object to direct marketing at any time.
To exercise your rights, contact [email protected]. You may also lodge a complaint with a data protection authority. For Synedat Group GmbH, this includes the State Commissioner for Data Protection of Lower Saxony. We do not make solely automated decisions within the public websites described here that produce legal or similarly significant effects within the meaning of Article 22 GDPR.
Online contact requests
You can use our forms to reach sales, purchasing, marketing, partnership, or general concerns. Name, email address, request, subject, and message are required. Phone, company, and mailing address are voluntary. Email repetition is to avoid errors; mailing addresses are only checked for format and completeness, not for actual deliverability.
We store your request with a transaction number in our ERPNext and assign it to a new or existing lead. Authorized employees process the request; an automatic e-mail confirms receipt. There is no newsletter subscription. Depending on the request, the processing serves the initiation of a contract (Article 6 (1) (b) GDPR) or appropriate business communication (Article 6 (1) (f) GDPR). Information will be deleted as soon as it is no longer required for these purposes, provided that there are no retention obligations or legitimate interest in providing evidence. Specific operational review and deletion deadlines are still to be documented in the final version.
A technically required session cookie __Host-ngw-contact protects the transmission for a maximum of two hours. To limit misuse, we store short-lived connection and e-mail identifiers hashed with a secret key for a maximum of one hour. Form entries are not permanently stored in the browser. Matomo is switched off on contact form pages. Please direct data protection inquiries to [email protected].
YouTube videos and your choice
This video is provided by YouTube. A connection to YouTube is made only after you give permission, transmitting data such as your IP address. You can withdraw permission at any time in Cookie settings.
Your YouTube permission is independent of analytics. The existing consent storage also records this yes/no choice for up to 180 days within the scope shown in the dialog. Earlier analytics consent does not permit videos. When permission is refused or withdrawn, we remove the embedded player. The preview image is served from our own infrastructure.