Privacy notice
1. Responsible body and contact
The responsible body for the websites described here is Synedat Group GmbH, Philipsbornstraße 2, 30165 Hannover, Germany. General enquiries: kontakt@synedat.com, phone +49 511 546850-0.
You can reach our data protection team at datenschutz@synedat.com or by telephone on the general number. You can send data protection inquiries by post to the company address with the addition "Data protection team".
2. Scope of Application
This information is intended for the public SYNEDAT pages on companies, data centers, technology, consulting, integration, offers, careers, blog, wiki, FAQ, newsletters and customer services. The technical inventory refers to the 13 DEV websites with the extension synedat.dev. Authenticated customer applications, the content management system and later added ordering or login functions require a separate consideration of their actual processing.
3. Call and technical provision
When a website is accessed, technically necessary connection data is processed. This may include IP address, time, requested address, response status, amount of data transferred as well as information on browser and operating system. A referring page is only transmitted if your browser sends it.
The processing serves the purpose of delivery, error analysis, availability and protection against improper access. The legal basis is Article 6 (1) (f) GDPR; the legitimate interest lies in secure and functional operation. Which log data is permanently stored in the individual infrastructure components and which deletion periods apply must be compared with the operation before final publication.
4. Hosting and technical service providers
The DEV environment uses Microsoft Azure for the technical platform and Azure Front Door for web delivery and upstream protection functions. Public images, fonts and files are also delivered via static.synedat.dev. For this static domain, Cloudflare is intended as an additional delivery and cache service. During deployment, the service providers involved can process IP address, requested file, timestamp and technical connection information in particular.
The Inter font is provided on our own infrastructure. No connection to Google Fonts is established for this purpose. The caching of public files serves to provide the requested website reliably and quickly. As far as personal data is concerned, it is based on Article 6 (1) (f) GDPR.
Before the final version, the actually activated Cloudflare configuration, the contractual Microsoft and Cloudflare companies, other processors, the agreed processing locations and any third-country accesses must be documented. This draft does not claim exclusive processing in Germany or the EU. Insofar as service providers act on behalf of the EU, the requirements of Article 28 GDPR must be taken into account. For transfers to third countries, the applicable basis in each case must be specified in Chapter V GDPR.
5. Consent and voluntary statistics
When the consent notice describes a shared choice for synedat.dev and its subdomains, your new acceptance or refusal applies to the connected SYNEDAT websites in that domain family. Changes made in Cookie settings are shared as well. Pages that are already open check the choice when you return to them, before download analytics and regularly during use.
We store the choice for a maximum of 180 days in the essential cookie __Secure-synedat_consent_v2. It contains the version, domain family, your yes/no decision on analytics, and the choice and expiry times, but no visitor identifier. The cookie is transmitted only over HTTPS and applies to all paths in that domain family. Matomo stays off without consent.
On websites without this shared integration, the choice in synedat.consent.v1 in localStorage remains limited to the individual domain. An earlier agreement for one website is never extended to other websites. Other browsers, devices and registrable domains such as synedat.de have their own choice. After expiry or deletion, we ask again. If your browser blocks storage, an explicit choice applies only to the current page; the notice explains this.
This storage is necessary to comply with your selected setting (§ 25 (2) number 2 TDDDG; if personal data is processed, Article 6 (1) (f) GDPR).
Only with your voluntary consent in accordance with Article 6 (1) (a) GDPR and, if necessary, § 25 (1) TDDDG do we download Matomo from matomo.synedat.dev. The operator of these statistics is Synedat Group GmbH. We use it to evaluate page views and clicks on public download files. Matomo is operated without analysis cookies; IP addresses are completely masked in its statistical data. Before transmission, we remove search parameters and URL fragments. This integration does not transmit any referring page, no form entries and no customer ID. An activated do-not-track setting is taken into account. Technical information on the browser and device class may be part of the statistics; complete anonymity of all connection data is not claimed.
Without consent, Matomo will not be loaded and no analysis requests will be sent. You can agree, reject and change your selection at any time via "Cookie settings" at the bottom of the page . "Only necessary" revokes a given statistical consent for the future. The public pages remain usable in case of rejection. Retention periods of the statistics and the upstream operating protocols are still to be conclusively documented in this test version. Further details can be found in the cookie policy of this website.
6. Contact by e-mail or phone
If you contact us, we will process the information you provide and the content of your request in order to process your request and answer any queries. This may include your name, company, contact details, and project or service information.
In the case of an enquiry about a contract with you, Article 6 (1) (b) GDPR is relevant. In the case of a company's professional contact persons and other general enquiries, the processing may be based on Article 6 (1) (f) GDPR; the interest lies in appropriate business communication. Processing required by law is based on Article 6 (1) (c) GDPR.
No passwords, secret keys or particularly sensitive documents are required for an initial inquiry. Coordinate a protected transmission path for confidential documents with your contact person.
7. Offers, contracts and supplier contacts
Contact, contract, service and billing data may be processed for the preparation of offers, contract execution, service coordination and billing. In the case of natural contractual partners, this is done for the purpose of initiating or fulfilling a contract in accordance with Article 6 (1) (b) GDPR. Article 6 (1) (f) GDPR applies to contact persons of legal entities. Retention and documentation obligations may require processing in accordance with Article 6 (1) (c) GDPR.
The recipients are the persons involved in the respective task and the service providers actually used for this purpose. A transfer to authorities or other bodies takes place if there is a legal obligation or another viable legal basis.
8. Online applications and project profiles
On our Jobs website, you can apply for a permanent position or freelance collaboration as well as on your own initiative. We process the chosen application path, name, e-mail address and professional focus. You can voluntarily submit your telephone number, experience, availability, work location preference, scope of assignment, salary or fee expectations, a profile link, a message and a PDF profile. Please do not send any identification documents, bank or health data. Without the information described as required, we cannot process the online form.
The information is used to review your application, to contact you and to decide on a possible cooperation. For employment applications, Section 26 (1) BDSG in conjunction with the relevant provisions of the GDPR is particularly relevant. In the case of a freelance contract with you, the processing is based on Article 6 (1) (b) GDPR; in the case of contact persons of a company, if applicable, on Article 6 (1) (f) GDPR. Additional consent to the necessary processing is not made a condition.
We store the application data in our self-operated ERPNext with HRMS. Access is granted to authorized persons involved in recruiting and the respective professional review as well as required technical administrators. PDF attachments are stored as private files and are not made available via the public download or static domain. The form does not transmit any application data to Matomo; this statistic is switched off on application pages. There is no automated selection decision.
To protect the transmission, the form uses a technically required, random session cookie __Host-ngw-application for a maximum of two hours and a form verification linked to the session, website and expiry time. Short-lived connection identifiers hashed with a secret key limit abusive calls for a maximum of one hour. This is based on Section 25 (2) number 2 TDDDG and, as far as personal data is concerned, on Article 6 (1) (f) GDPR; our interest is the protection of the application service.
During an ongoing procedure, the information required for this will be retained. For rejected applications received via this form and completed in ERPNext, deletion after 180 days is provided. Documented further storage, for example for the assertion or defense of legal claims, may justify longer storage. If a cooperation is established, the data required for this will be further processed in the corresponding personnel or contract process. Storage in backup copies is based on the separate backup and restoration procedure, the specific deadlines of which are still to be supplemented in the final version.
An unsolicited application is not consent to a permanent talent pool, newsletter dispatch or the sharing of a profile with potential clients. Such additional purposes will be clarified separately with you. For questions and data subject rights, you can reach our data protection team at datenschutz@synedat.com.
9. Newsletters and customer portals
The currently checked homepages provide information about newsletters and customer services; no newsletter registration or customer login was carried out there. A mere request does not result in a newsletter subscription.
Before a registration is introduced, the shipping service provider, content, frequency, proof of required consent, deregistration and storage period must be documented. Consent-based processing is based on Article 6 (1) (a) GDPR and can be revoked for the future. For specific portal offers, the identity services, roles, protocols and contractual references used must be described separately.
10. Links, Sharing and Social Networks
Maps, social media profiles and sharing functions for X, Facebook and LinkedIn are integrated as normal links. The website does not load any social media scripts, embedded profiles or tracking pixels in advance. When a network is opened, the data required to establish a connection is transmitted to this provider; its data protection information applies there. A post is only published by the respective provider after your action.
"Copy Link" writes the cleaned page address to the clipboard when you explicitly click on it. The native sharing feature passes the address and page title to your chosen service. Search parameters and URL fragments are removed. An active public company profile may also require its own privacy information and responsibilities.
11. Storage period
Personal data must be deleted or anonymised if it is no longer needed for the respective purpose and there is no other legal basis for retention. Statutory retention obligations may be relevant for contract and billing documents; relevant limitation periods may be important for the assertion or defence of claims.
Specific deadlines and technical deletion procedures for access logs, general enquiries, applications, talent pool data and newsletter references are still to be compared with the procedures actually operated for the final version. This draft does not specify any unchecked blanket retention periods.
12. Your rights
Under the respective legal conditions, you have rights to information, correction, deletion, restriction of processing and data portability. If processing is based on your consent, you can revoke it with effect for the future. The lawfulness of the processing until the revocation remains unaffected.
Objection: If processing is based on Article 6 (1) (e) or (f) GDPR, you can object for reasons relating to your particular situation. You can object to processing for direct marketing at any time; this also applies to related profiling.
You can complain to a data protection supervisory authority, in particular at the place of your habitual residence, your place of work or the suspected violation. Information on the Lower Saxony supervisory authority can be found at The State Commissioner for Data Protection Lower Saxony.
To exercise your rights, please contact datenschutz@synedat.com. An automated individual case decision with legal or comparably significant effect was not established in the audited public website; such a function is not covered by this draft.
Online contact requests
You can use our forms to reach sales, purchasing, marketing, partnership, or general concerns. Name, email address, request, subject, and message are required. Phone, company, and mailing address are voluntary. Email repetition is to avoid errors; mailing addresses are only checked for format and completeness, not for actual deliverability.
We store your request with a transaction number in our ERPNext and assign it to a new or existing lead. Authorized employees process the request; an automatic e-mail confirms receipt. There is no newsletter subscription. Depending on the request, the processing serves the initiation of a contract (Article 6 (1) (b) GDPR) or appropriate business communication (Article 6 (1) (f) GDPR). Information will be deleted as soon as it is no longer required for these purposes, provided that there are no retention obligations or legitimate interest in providing evidence. Specific operational review and deletion deadlines are still to be documented in the final version.
A technically required session cookie __Host-ngw-contact protects the transmission for a maximum of two hours. To limit misuse, we store short-lived connection and e-mail identifiers hashed with a secret key for a maximum of one hour. Form entries are not permanently stored in the browser. Matomo is switched off on contact form pages. Please direct data protection inquiries to datenschutz@synedat.com.