-->

Privacy Policy

1. Overview and mandatory information

Data protection at a glance

The following notes give a simple overview of what happens to your personal data when you visit this website. Personal data is any data with which you can be personally identified. Detailed information can be found in the sections below.

Controller

The controller responsible for data processing on this website is:

SAFETEE GmbH, Wasserstraße 221, 44799 Bochum, Germany, phone +49 234 588850, e-mail info@safetee.eu, represented by its managing director Marc Riegel. Registered at the Local Court of Bochum, HRB 18360.

The controller is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data.

Data protection officer

We have appointed an external data protection officer: Andreas Reinke, arbeitgeber ruhr GmbH, phone +49 234 58877-27, e-mail reinke@datenschutzbeauftragter.ruhr.

How do we collect your data?

Some data is collected when you provide it to us – for example via the contact form, by e-mail or as part of a job application. Other data is collected automatically, or after your consent, by our IT systems when you visit the website. This is mainly technical data such as your browser, operating system or the time of the page request.

What do we use your data for?

Part of the data is collected to ensure the website is provided without errors. Other data may be used – only with your consent – to analyse user behaviour or for advertising purposes. Data from enquiries and applications is used exclusively to process your request.

Legal bases at a glance

Where you have given consent, we process your data on the basis of Art. 6(1)(a) GDPR; where cookies are stored or information is accessed on your device, additionally on the basis of Section 25(1) of the German Telecommunications Digital Services Data Protection Act (TDDDG). Where your data is required to perform a contract or to take steps prior to entering into a contract, Art. 6(1)(b) GDPR applies. Processing to comply with a legal obligation is based on Art. 6(1)(c) GDPR. In all other cases processing may be based on our legitimate interest under Art. 6(1)(f) GDPR. The applicable legal basis is stated for each service below.

Data transfers to third countries

Some of the services we use are operated by providers based outside the EU/EEA, in particular in the USA and Singapore. For transfers to the USA we rely on the European Commission's adequacy decision on the EU-US Data Privacy Framework (DPF) where the respective provider is certified, and additionally on the European Commission's Standard Contractual Clauses. For transfers to other third countries we rely on the Standard Contractual Clauses (Art. 46(2)(c) GDPR). Where a third-country transfer takes place for a specific service, we state this in the respective section.

Retention period

Unless a more specific retention period is stated in this policy, your personal data remains with us until the purpose of processing no longer applies. If you make a legitimate request for erasure or withdraw your consent, your data will be deleted unless there are other legally permissible reasons for retaining it (e.g. retention periods under tax or commercial law).

Recipients of personal data

We only pass personal data on to external parties where this is necessary to perform a contract, where we are legally obliged to do so, where we have a legitimate interest in the transfer, or where another legal basis permits it. Processors receive data exclusively on the basis of a contract under Art. 28 GDPR.

2. Hosting

Webflow

The content of our website is hosted by Webflow, Inc., 398 11th Street, 2nd Floor, San Francisco, CA 94103, USA. When you visit our website, Webflow records log files including your IP address and sets cookies or similar technologies that are required to display the site, to provide certain functions and to ensure security (strictly necessary cookies). Images, videos, scripts and stylesheets of our website are delivered via Webflow's content delivery network (cdn.prod.website-files.com and Amazon CloudFront); your IP address is transmitted to the respective delivery server in the process.

The legal basis is our legitimate interest in a reliable and secure presentation of our website (Art. 6(1)(f) GDPR). Strictly necessary cookies do not require consent under Section 25(2) no. 2 TDDDG.

The company is certified under the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards for data processing in the USA. In addition, the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR) have been agreed, so that the transfer remains safeguarded even if the DPF adequacy decision should cease to apply. Further information: DPF register entry. Webflow's privacy policy: https://webflow.com/legal/eu-privacy-policy.

We have concluded a data processing agreement (DPA) with the provider under Art. 28 GDPR. This ensures that the provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.

Further content delivery networks

Individual script libraries are loaded via the content delivery network jsDelivr (operator: Prospect One sp. z o.o., Kraków, Poland; delivered via Cloudflare and Fastly). Your IP address is transmitted to the delivering server. The legal basis is our legitimate interest in fast and stable provision of the website (Art. 6(1)(f) GDPR).

Embedded content on Vercel

On individual pages (currently "Safety Consulting") we embed interactive content hosted on the Vercel platform. The provider is Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, USA. When you open these pages, your browser connects to Vercel's edge network; your IP address and technical access data (time, requested resource, browser) are processed and stored for the duration of operational logging. The data is not combined with other data. The enquiry form contained there does not send your input to a server; it opens your e-mail client with a prepared message, and the data is only transmitted to us when you send that e-mail.

The legal basis is our legitimate interest in a reliable presentation of our content (Art. 6(1)(f) GDPR).

The company is certified under the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards for data processing in the USA. In addition, the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR) have been agreed, so that the transfer remains safeguarded even if the DPF adequacy decision should cease to apply. Further information: https://www.dataprivacyframework.gov/list (entry "Vercel Inc."). Vercel's privacy policy: https://vercel.com/legal/privacy-policy.

We have concluded a data processing agreement (DPA) with the provider under Art. 28 GDPR. This ensures that the provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.

3. General data collection

Server log files

The hosting provider automatically collects and stores information in server log files that your browser transmits: browser type and version, operating system used, referrer URL, host name of the accessing computer, time of the server request and IP address. This data is not combined with other data sources. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in the technically error-free presentation and the security of the website.

SSL/TLS encryption

This website uses SSL/TLS encryption for the secure transmission of confidential content. You can recognise an encrypted connection by the "https://" in the address bar and the lock symbol in your browser.

Contact form

If you send us enquiries via the contact form, the details you enter, including the contact data you provide, are stored by us for the purpose of processing the enquiry and for follow-up questions. We do not pass this data on without your consent. The form data is technically transmitted via our hosting provider Webflow (see section 2).

The legal basis is Art. 6(1)(b) GDPR where your enquiry relates to the performance of a contract or is necessary to take steps prior to entering into a contract; in all other cases our legitimate interest in the effective handling of enquiries (Art. 6(1)(f) GDPR). The data remains with us until you ask us to delete it or the purpose of storage no longer applies; statutory retention periods remain unaffected.

Enquiries by e-mail or telephone

If you contact us by e-mail or telephone, your enquiry including all personal data resulting from it is stored by us for the purpose of processing your request. The legal basis and retention period correspond to those stated for the contact form. Our e-mail communication runs via Microsoft 365 (see section 7).

4. Cookies and consent management

Cookies

Our website uses cookies. Cookies are small data packets stored on your device – either temporarily for the duration of a session (session cookies) or permanently (persistent cookies). Cookies may originate from us (first-party) or from third-party companies (third-party).

Strictly necessary cookies that are required to provide the website are stored on the basis of Art. 6(1)(f) GDPR and Section 25(2) no. 2 TDDDG. We use all other cookies and comparable technologies – in particular for analysis or advertising purposes – exclusively with your consent under Art. 6(1)(a) GDPR and Section 25(1) TDDDG. You can withdraw your consent at any time with effect for the future by reopening the cookie settings via the link in the footer.

You can set your browser to inform you about the setting of cookies, to allow cookies only in individual cases, or to exclude them altogether. If cookies are deactivated, the functionality of this website may be restricted.

Consent management with Usercentrics

This website uses the consent technology of Usercentrics to obtain your consent to the storage of certain cookies or the use of certain technologies and to document it in a data-protection-compliant manner. The provider is Usercentrics GmbH, Sendlinger Straße 7, 80331 Munich, Germany.

When you enter the website, the following data is transmitted to Usercentrics: your consents or their withdrawal, your IP address, information about your browser and device, the time of your visit and geolocation. Usercentrics stores a cookie in your browser to be able to assign the consents you have given. The data is stored until you ask us to delete it, delete the cookie yourself, or the purpose no longer applies.

Usercentrics is used to obtain and document the legally required consents. The legal basis is Art. 6(1)(c) GDPR in conjunction with Art. 7(1) GDPR.

We have concluded a data processing agreement (DPA) with the provider under Art. 28 GDPR. This ensures that the provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.

5. Web analytics and form protection

We do not use advertising trackers or session-recording tools on this website. For audience measurement we use exclusively a cookieless analytics service (Ahrefs Web Analytics). To protect our contact form against automated input we use Google reCAPTCHA; this service is only loaded with your consent.

Ahrefs Web Analytics

We use Ahrefs Web Analytics, a web analytics service of Ahrefs Pte. Ltd., 16 Raffles Quay, #33-03 Hong Leong Building, Singapore 048581. Ahrefs Web Analytics does not set cookies and does not use comparable recognition technologies on your device.

When a page is opened, the following data is transmitted to Ahrefs and evaluated in aggregated form: the page opened (URL), the referring page (referrer), browser type and version, operating system, device type and your IP address. IP address and request are stored exclusively as a hash value and deleted after 24 hours; they are not combined with other data and you are not identified personally.

The purpose of the processing is to analyse the use of our website in order to improve content and reach. The legal basis is our legitimate interest in privacy-friendly, cookieless audience measurement (Art. 6(1)(f) GDPR). You may object to the processing at any time, for example by using a script blocker in your browser.

Ahrefs Pte. Ltd. is based in Singapore, a third country without an adequacy decision of the European Commission. The transfer is based on the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR). Further information: https://ahrefs.com/privacy-policy.

We have concluded a data processing agreement (DPA) with the provider under Art. 28 GDPR. This ensures that the provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.

Google reCAPTCHA

We use Google reCAPTCHA to protect input in our contact form against automated misuse (spam, bots). The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Once loaded, reCAPTCHA analyses the behaviour of the website visitor on the basis of various characteristics. For this purpose reCAPTCHA evaluates, among other things, the IP address, time spent on the site, mouse movements, browser and device information and cookies set by Google. The data collected is transmitted to Google and may be transferred to the USA. The analysis runs in the background; you are not notified that it is taking place.

The service is used exclusively on the basis of your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG), which you give via our consent banner. Without consent, reCAPTCHA is not loaded; you can then reach us by e-mail or telephone. Consent may be withdrawn at any time. Google's privacy policy: https://policies.google.com/privacy, terms of service: https://policies.google.com/terms.

The company is certified under the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards for data processing in the USA. In addition, the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR) have been agreed, so that the transfer remains safeguarded even if the DPF adequacy decision should cease to apply. Further information: https://www.dataprivacyframework.gov/participant/5780.

6. Fonts

Google Fonts

This website uses Google Fonts, provided by Google, for a uniform display of typefaces. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. When you open a page, your browser loads the required fonts into its cache. To do so, your browser must connect to Google's servers; Google thereby learns that this website was accessed via your IP address. The service is used exclusively on the basis of your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG); without consent, a standard font of your system is used instead.

The company is certified under the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards for data processing in the USA. In addition, the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR) have been agreed, so that the transfer remains safeguarded even if the DPF adequacy decision should cease to apply. Further information: https://www.dataprivacyframework.gov/participant/5780. Google's privacy policy: https://policies.google.com/privacy.

7. Communication and conferencing tools

For communication with customers, prospects and applicants we use Microsoft 365 (e-mail, calendar, Teams) and – where requested by the other party – Zoom. If you communicate with us via video or audio conference, your personal data is processed by us and by the provider of the respective tool: the data you provide (name, e-mail address, telephone number), metadata of the conference (duration, start and end, number of participants) and technical data (IP address, device IDs, operating system, client version). Content you share in a conference (chat, files, recordings) is also stored on the provider's servers.

The tools are used to communicate with contractual partners or to provide services (Art. 6(1)(b) GDPR) and to generally simplify communication (Art. 6(1)(f) GDPR). Data collected by us is deleted as soon as you ask us to delete it or the purpose no longer applies; we have no influence on the retention period at the provider.

Microsoft 365 and Microsoft Teams

The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. Privacy statement: https://privacy.microsoft.com/en-gb/privacystatement.

The company is certified under the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards for data processing in the USA. In addition, the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR) have been agreed, so that the transfer remains safeguarded even if the DPF adequacy decision should cease to apply. Further information: DPF register entry.

We have concluded a data processing agreement (DPA) with the provider under Art. 28 GDPR. This ensures that the provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.

Zoom

The provider is Zoom Communications Inc., 55 Almaden Boulevard, 6th Floor, San Jose, CA 95113, USA. Privacy statement: https://explore.zoom.us/en/privacy/. The transfer of data to the USA is based on the European Commission's Standard Contractual Clauses; Zoom is also certified under the EU-US Data Privacy Framework.

We have concluded a data processing agreement (DPA) with the provider under Art. 28 GDPR. This ensures that the provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.

8. Application process

We offer you the opportunity to apply to us – via our careers portal karriere.safetee.eu, by e-mail or by post. Below we inform you about the scope, purpose and use of the personal data collected in the application process.

Scope and purpose of data collection

If you send us an application, we process the associated personal data (contact and communication data, application documents, notes from interviews) to the extent necessary to decide on the establishment of an employment relationship. The legal basis is Section 26 of the German Federal Data Protection Act (BDSG) (initiation of an employment relationship), Art. 6(1)(b) GDPR and – where you have given consent – Art. 6(1)(a) GDPR. Within our company, your data is passed on only to persons involved in processing your application. If your application is successful, the data is stored in our systems for the purpose of carrying out the employment relationship.

Applicant management with Personio

For applicant management we use the software Personio of Personio SE & Co. KG, Seidlstraße 3, 80335 Munich, Germany. Personio processes applicant data on our behalf; the servers are located in the European Union. Applications via our careers portal are recorded directly in Personio, where scheduling, correspondence and application documents are also managed. Personio's privacy notice: https://www.personio.com/privacy-policy/.

We have concluded a data processing agreement (DPA) with the provider under Art. 28 GDPR. This ensures that the provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.

Retention period

If we do not make you a job offer, if you decline an offer or withdraw your application, we retain your data on the basis of our legitimate interest (Art. 6(1)(f) GDPR) for up to six months after the end of the application process, in particular for evidentiary purposes under the German General Equal Treatment Act (AGG). The data is then deleted and physical documents destroyed. If it is foreseeable that the data will be required beyond this (e.g. in the event of an impending legal dispute), deletion takes place only once the purpose no longer applies.

Inclusion in the applicant pool

If we do not make you a job offer, we may include you in our applicant pool in order to contact you about suitable vacancies. Inclusion is based exclusively on your express consent (Art. 6(1)(a) GDPR); it is voluntary and unrelated to the current process. You may withdraw your consent at any time; your data will then be irrevocably deleted. Data is deleted from the applicant pool no later than two years after consent was given.

9. Social media presences

Our website links to our company profiles on LinkedIn, Xing, Instagram, Facebook and YouTube. These are plain links; no data is transmitted to these networks when you visit our website. Only when you follow a link do the privacy policies of the respective provider apply. For our company profiles we are jointly responsible with the respective network operator; details are governed by the providers' agreements (e.g. LinkedIn Page Insights Joint Controller Addendum, Meta Page Insights Addendum).

10. Your rights

Access, rectification, erasure, restriction, data portability

Within the scope of the statutory provisions you have the right at any time to obtain free information about your stored personal data, its origin and recipients and the purpose of processing (Art. 15 GDPR), to rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR) and data portability (Art. 20 GDPR). To exercise these rights, contact the controller named above or our data protection officer.

Withdrawal of your consent

You may withdraw consent you have given at any time with effect for the future. The lawfulness of processing carried out until withdrawal remains unaffected. Cookie consents can be withdrawn via the cookie settings in the footer of this website.

Right to object (Art. 21 GDPR)

Where data processing is based on Art. 6(1)(e) or (f) GDPR, you have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data; this also applies to profiling based on these provisions. We will then no longer process your data unless we can demonstrate compelling legitimate grounds that override your interests, or the processing serves the establishment, exercise or defence of legal claims. Where your data is processed for direct marketing purposes, you may object at any time; your data will then no longer be used for this purpose.

Right to lodge a complaint with a supervisory authority

In the event of infringements of the GDPR you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement. The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW), Kavalleriestraße 2–4, 40213 Düsseldorf, Germany, www.ldi.nrw.de.

Objection to advertising e-mails

We hereby object to the use of contact data published in accordance with our legal notice obligations for the purpose of sending unsolicited advertising. We reserve the right to take legal action in the event of unsolicited advertising, such as spam e-mails.


This privacy policy was last updated: September 2026

We update this policy whenever the legal situation or our processing activities change. The version published on this website applies. This English version is provided for convenience; in case of discrepancies, the German version (www.safetee.eu/datenschutz) prevails.