Name and contact details of the controller
This privacy policy of Platinion GmbH, Im Mediapark 5c, D-50670 Cologne, phone: +49 (0)221 58958-0, e-mail: info@bcgplatinion.com and its other BCG and BCG Platinion affiliates (“we” or “BCG Platinion”) as the controller describes in the following sections how we process personal data. This Privacy Policy was last updated in July 2024. For more information about our international offices, please visit http://www.bcg.com/about/offices/default.
Introduction
We take the protection of your privacy very seriously. The processing of personal data is carried out in accordance with the European General Data Protection Regulation (GDPR) and the Federal Data Protection Act (BDSG). The following declaration gives you an overview of what kind of data, to what extent and for what purpose it is processed. This Privacy Policy applies when you access the materials and information on the website bcgplatinion.com/de (hereinafter: the “Website”) or on other websites and apps that contain a link to this Privacy Policy and use our information and services offered there. This Privacy Statement also applies to information you provide to BCG Platinion by email or other form of contact.
We may change this Privacy Policy from time to time at our sole discretion. Material changes to this Privacy Policy will be posted on this page to ensure that you are always up to date on what information we collect and how we handle it.
This website may contain links to external online offers that have been carefully selected by us but are not regulated by this data protection declaration. By clicking on these links you will leave our website. We are not responsible for the privacy practices of third-party websites to which we link to comply with data protection standards. We recommend that you familiarize yourself with the privacy practices of such websites before providing any information to them.
Collection and processing of data by BCG Platinion
In the following we inform you about which data we collect. If you do not wish to provide such information, individual functions, such as registration or the sending of information, may only be usable to a limited extent or not at all.
A) What data do we collect?
Our pages offer different ways of use. Depending on this, different data may be collected; in detail:
When using the website for information purposes only, i.e. if you do not register or otherwise provide us with information, we only collect the personal data that your browser transmits to our server: date and time of the request, time zone difference to Greenwich Mean Time (GMT), content of the request (specific page), access status/HTTP status code, amount of data transferred, website from which the request comes, Browser, operating system, and its interface, language and version of the browser software. We collect the following data, which is technically necessary for us to display our website to you and to ensure stability and security, as well as to provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. The legal basis for this is Article 6 para. 1 lit. f GDPR.
If you contact us by e-mail or via a contact form, the data you provide (your e-mail address, if applicable. Your name and telephone number) are stored by us in order to answer your questions. At the time the message is sent, the following data is also stored: date and time of the message transmission. If we ask you in our contact form for information that is not necessary to contact us, we always mark these fields as “optional”. This information helps us to specify your request and to better process your request. The personal data transmitted by you serve us solely to process the contact or the request. The other personal data processed during the sending process serve to ensure the security of our information technology systems. The legal basis for this is Art. 6 para. 1 lit. f GDPR.
If you take part in a survey, this survey can either be anonymous, or personalized. When participating in a survey, we will inform you prior to participating, whether the survey will be anonymous or personalized.
Anonymous survey: Here, no personal data will be collected. If, in cases not intended by us, you enter personal data in free text fields as part of your participation in an anonymous survey, we will delete it anonymously and in accordance with data protection regulations. As a result, the data of the survey are only available in anonymous form and the evaluation of the data refers only to cumulative values. This means that, as a result, no one can identify by whom information has been provided, and no individual data is published or made available to third parties.
Personalized survey: In certain cases, we use personalized surveys, which means personal data will be collected, e.g. to organize events or send you merchandise. Which personal data are transmitted to the controller results from the respective input mask used for registration. This includes personal data such as your name, address, e-mail address, telephone number, user ID, bank details, your inquiry or order. The data transmitted to us is used exclusively for the purpose of using the respective offer or service. The legal basis for the processing of the data is Art. 6 para. 1 lit. a GDPR if the user has given his consent; you can revoke this at any time (see: G) Revocation of your consent). If the registration serves the fulfilment of a contract with you or the implementation of pre-contractual measures, the additional legal basis for the processing of the data is Art. 6 para. 1 lit. b GDPR.
If a newsletter can be subscribed to on our website, the data from the input mask will be transmitted to us when registering. You can also receive our newsletter if you have purchased a product or service from us. In order to provide you with our newsletter, we need your e-mail address. This is only used to provide our news and information about our services. We use the “double opt-in” procedure when you subscribe to the newsletter on our website. After you have entered your e-mail address, you will receive a confirmation e-mail and have the opportunity to confirm the registration in a legally secure manner. Only when the confirmation is made, your address will be actively included in the mailing list. The collection of the user’s e-mail address only serves to deliver the newsletter. When registering for the newsletter, we sometimes store the IP address assigned by your Internet service provider (ISP) at the time of registration as well as the date and time of registration. The collection of this data is necessary in order to be able to trace the (possible) misuse of your e-mail address at a later date and therefore serves your and our legal protection. If we receive personal data from you in another way (e.g. by handing over a business card), whereby you wish to receive information, we will use your data for this purpose. The legal basis for the processing of data after registration is Art. 6 para. 1 lit. a GDPR if the user has given his consent. ; you can revoke these at any time (see: G) Revocation of your consent). If you have purchased a product or service from us, we will use your email address to promote our own and similar products or services. In this case, the processing is based on sec. 7 para. 3 Act against Unfair Competition (UWG).
When you enter our application process, we collect the personal data necessary for proper implementation, such as name, address, telephone number and e-mail address, but also all data from the documents provided. The processing of personal data takes place based on sec. 26 para. 1 BDSG for decision-making on the establishment of a possible employment relationship. In order to be able to track the status of your application during the application process, you have the option of creating a user account. For this we need your e-mail address, a password and your consent to our privacy policy. The data and attachments stored in your account will also be retained after your application process in order to facilitate future applications. You can ask us to delete your data, attachments or user account at any time. Here, the processing of personal data takes place on the basis of Art. 6 para. 1 lit. a GDPR. In this case, we store your data as long as we have your consent; you can revoke it at any time (see: G) Revocation of your consent). If we do not hire it, we may retain and use your personal information for a period of time for system administration purposes and to conduct research. In addition, as part of our optional recruitment programs, we may ask you for permission to retain your personal information in order to consider you for future employment opportunities. Here, the processing of personal data takes place on the basis of Art. 6 para. 1 lit. a GDPR. In this case, we store your data as long as we have your consent; you can revoke it at any time (see: G) Revocation of your consent).
You can register for recruiting events. Which personal data are transmitted to the controller results from the respective input mask used for registration. This includes personal data such as your name, address, e-mail address, telephone number, user ID, bank details, your inquiry or order. The data transmitted to us is used exclusively for the purpose of using the respective offer or service. The legal basis for the processing of the data is Art. 6 para. 1 lit. a GDPR if the user has given his consent; you can revoke this at any time (see: G) Revocation of your consent). If the registration serves the fulfilment of a contract with you or the implementation of pre-contractual measures, the additional legal basis for the processing of the data is Art. 6 para. 1 lit. b GDPR.
If you conclude a contract with us as a customer or service provider, personal data such as your name, address, e-mail address, telephone number, bank details, your inquiry or order will be collected. The data transmitted to us is used exclusively for the purpose of fulfilling a contract with you or carrying out pre-contractual measures. For this reason, the legal basis for the processing of the data is Art. 6 para. 1 lit. b GDPR.
B) Where do we get the personal data about you?
We may collect or receive your personal information in a number of ways:
- When you provide us with personal data directly, for example by correspondence with us by email or through other direct interactions with us, such as filling out a form on our website or registering and using one of our online tools;
- Third party sources: for example, when we receive information about you from business partners in order to organize events and conferences or to carry out application processes.
Incidentally, you can read in detail where the data comes from under “What data do we collect?”
C) How do we use personal data?
The purposes and uses of your personal data depend on the use of the website and the personal information provided. We process your personal data (unless already mentioned above) as follows:
- For the purposes of protecting our legitimate interests: This includes data transmission during the sending process. The data is used to prevent misuse of the respective transaction and to ensure the security of our information technology systems. The legal basis for this is our legitimate interest pursuant to Art. 6 para. 1 lit. f GDPR.
- Furthermore, we process data for the purpose of complying with a legal obligation. These include measures to combat fraud and money laundering as well as tax and social law requirements. The legal basis for this is legal requirements acc. Art. 6 para. 1 lit. c GDPR.
D) Disclosure of data
We will not sell, share, rent, lend or otherwise make your personal information available to third parties, except that we may share the information with service providers who work for us and need access to the information in connection with that activity. Third parties may only process this information to the extent and within the limits within which we ourselves are permitted to process this data. In addition, we may share your contact information when responding to requests from bona fide rights holders that are related to alleged copyright or other proprietary rights infringement related to information you have posted on the Site or otherwise provided to us.
Third parties with whom we may need to share personal information in order to provide you with services and products and to operate our website include:
- our subsidiaries or affiliates;
- our third-party service providers who process information on our behalf to help us operate some of our internal business operations, such as sending emails, IT services, recruiting processes, and marketing and event services;
- our business partners for publications and events organized jointly by us and these partners;
- Law enforcement authorities in order to comply with legal obligations or a court order.
For details of the legal bases, please read in detail under “What data do we collect”.
E) Transfer of data to third countries
Data will only be transferred to countries outside the EU or EEA (third countries) if this is necessary for the execution of your transactions or required by law. If a transaction requires us to receive data as part of a global organization, personal information may be processed within BCG Platinion and its affiliates (https://www.bcg.com/offices/default). These measures may affect your personal data stored in various countries around the globe, such as the United States, where different data protection laws apply. In order to ensure an adequate level of data protection, various measures are taken, such as the conclusion of standard contractual clauses.
F) Storage of your personal data
Personal data of data subjects will be deleted or blocked as soon as the purpose of storage no longer applies. If this data is no longer required to fulfil the respective purpose, it will be deleted. However, deletion does not take place if we have to store the data for the following purposes:
- Fulfillment of commercial and tax retention obligations (in particular obligations under the Commercial Code, Tax Code, which must be kept for up to 10 years)
- Securing evidence within the framework of limitation periods (which are generally 3 calendar years, starting from the end of the year).
G) Withdrawal of your consent
You have the right to revoke your declaration of consent under data protection law at any time. The revocation of consent does not affect the legality of the processing carried out on the basis of the consent until the revocation. You can send your revocation at any time to dataprivacy@bcgplatinion.com, as well as to our postal address (Platinion GmbH, Im Mediapark 5c, 50670 Cologne) with the addition “the data protection officer”.
If you do not wish to receive further newsletters from us, you have the option of unsubscribing from such communications at any time via a link. You will find this link in every e-mail you receive from us. You can also send your revocation to dataprivacy@bcgplatinion.com, as well as to our postal address (Platinion GmbH, Im Mediapark 5c, 50670 Cologne) with the addition “the data protection officer”.
H) Cookies and other tracking technologies
We use cookies on this website. A cookie is a small piece of data that is created when visiting a website and stored on the system of the user of the website. A cookie contains a characteristic string of characters that enables the browser to be uniquely identified when the website is called up again. In our Cookie Policy you can find out about essential and non-essential cookies and change your preferences.
Cookies are stored on your computer and transmitted to us by it. Therefore, as a user, you also have full control over the use of cookies. By changing the settings in your Internet browser, you can deactivate or restrict the transmission of cookies. Cookies that have already been stored can be deleted at any time. You can also change the cookie settings in our cookie banner.
In addition, we use the following tracking technologies:
Information on legal bases: The legal basis for the use of essential cookies (necessary for the operation of the website) is Art. 6 (1) sentence 1 lit. f GDPR. We use cookies required on our website to ensure the proper operation of the website and to provide basic functionality. These purposes also constitute our legitimate interest in data processing within the meaning of Art. 6 para. 1 lit. f GDPR. In the case of non-essential cookies, the legal basis is your consent pursuant to Art. 6 para. 1 lit. a GDPR; you can revoke this at any time (see: G) Revocation of your consent).
We use Piwik PRO for the analysis of our website. We collect first-party data about website visitors based on cookies, IP numbers and browser fingerprints; we create user profiles based on browsing history and calculate metrics related to website usage, such as bounce rate, intensity of visits, page views, etc. We host our solution in the Microsoft Azure infrastructure in the Netherlands and the data is stored in raw data for a period of 25 months. The cookies are only set after you have given us your consent. The purpose of data processing is analysis and conversion tracking on the basis of your consent in accordance with Art. 6 para. 1 sentence 1 lit. a GDPR; you can revoke this at any time (see: G) Revocation of your consent).
We use Google Ads (formerly: AdWords) and, as part of Google AdWords, conversion tracking, an online advertising service provided by Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland. We use this for search and display ads and, in this context, conversion tracking (visit action evaluation). When you click on an ad served by Google, a conversion tracking cookie is stored on your computer. These cookies lose their validity after 30 days, do not contain any personal data and are therefore not used for personal identification. If you visit certain pages of ours and the stored cookie on your computer has not yet expired, it can be seen that someone has been redirected to our website through the advertisement. Each AdWords customer receives a different cookie. Cookies can thus be tracked via the websites of AdWords customers. The assignment takes place via a statistical evaluation of non-personal data. Further detailed information on the information processed can be found under https://www.google.com/intl/de/policies/privacy/#infocollect under “Data we receive as a result of your use of our services”, as well as under https://privacy.google.com/businesses/adsservices/.The cookies are only set after you have given us your consent. The legal basis for data processing is your consent pursuant to Art. 6 para. 1 sentence 1 lit. a) GDPR; you can revoke this at any time (see: G) Revocation of your consent).
We use Google Tag Manager on our website. Google Tag Manager is a service provided by Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland. The Google Tag Manager enables us to integrate various codes and services on our website in a simplified way and to get an overview of the integrated services; in addition, the loading times of the various services are optimized. Tags are implemented by Google Tag Manager. In doing so, Google may process information (including personal data), such as: Your IP address and your online identifier. It cannot be ruled out that Google may also transmit the information to a server in a third country. Detailed information about Google Tag Manager can be found here: https://www.google.de/tagmanager/use-policy.html. The tags will only be set after you have given us your consent. The legal basis for data processing is your consent pursuant to Art. 6 para. 1 sentence 1 lit. a) GDPR; you can revoke this at any time (see: G) Revocation of your consent).
We use Bing Universal Event Tracking (UET) (formerly “Bing Ads”) on our website. UET is a service of Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA.UET allows us to track the activities of you as a user on our website if you have come to our website via advertisements from Microsoft Ads. If you access our website via such an advertisement, a cookie will be placed on your computer. Some non-personal data about the use of the website is stored, including the time spent on the website, areas of the website accessed and on the basis of which display the website was reached. Information about your identity is not collected. In doing so, UET may process information (including personal data), such as: Your IP address and your online identifier. It cannot be ruled out that the information may also be transmitted to a server in a third country. For more information about privacy at Microsoft, see the Microsoft Privacy Statement (https://privacy.microsoft.com/de-de/privacystatement).The cookies are only set after you have given us your consent. The legal basis for data processing is your consent pursuant to Art. 6 para. 1 lit. a GDPR; you can revoke this at any time (see: G) Revocation of your consent).
On our website we use the “Meta-Pixel” of Meta (formerly Facebook). The meta-pixel is operated by Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. When you click on an ad placed on Facebook, Instagram, or another Meta product, a Meta “tracking pixel” (“Meta Pixel”) is placed on your computer for conversion tracking. Among other things, collects your IP address, device and browser properties, and page events. These meta-pixels lose their validity after 30 days, do not contain any personal data and are therefore not used for personal identification. If you visit certain pages of ours and the stored cookie on your computer has not yet expired, it is recognizable that someone has been redirected to our website through the ad on Facebook. Each Facebook user receives a different meta pixel. Meta-pixels can thus be tracked via the ads placed on Facebook websites. The assignment takes place via a statistical evaluation of non-personal data. As a result, the effectiveness of the Meta advertisements can be evaluated for statistical and market research purposes and future advertising measures can be optimized. This allows Facebook to place advertisements on Facebook pages as well as outside of Facebook. This use of the data cannot be influenced by us as the site operator. In Facebook’s privacy policy you will find further information on the protection of your privacy: https://de-de.facebook.com/about/privacy/. The cookies/ pixels are only set after you have given us your consent. The legal basis for data processing is your consent pursuant to Art. 6 para. 1 lit. a GDPR; you can revoke this at any time (see: G) Revocation of your consent).
We also advertise on Reddit (so-called Reddit ads). For this purpose, we use the Reddit pixel to check the effectiveness of this advertising. Reddit, Inc., 548 Market St. #16093, San Francisco, California 94104.When you click on an ad placed on Reddit, a conversion tracking cookie is placed on your computer. These cookies lose their validity after 30 days, do not contain any personal data and are therefore not used for personal identification. If you visit certain pages of ours and the stored cookie on your computer has not yet expired, it can be seen that someone has been redirected to our website through the advertisement. Each Reddit Ads customer receives a different cookie. Cookies can thus be tracked via the websites of Reddit Ads customers. The assignment takes place via a statistical evaluation of non-personal data. Further information on data protection at Reddit can be found in the Reddit privacy policy: https://www.reddit.com/policies/privacy-policy?tid=130340934. The cookies are only set after you have given us your consent. The legal basis for data processing is your consent pursuant to Art. 6 para. 1 lit. a GDPR; you can revoke this at any time (see: G) Revocation of your consent).
Our website uses the conversion tool “LinkedIn Insight Tag” of LinkedIn Ireland Unlimited Company. When you click on an ad placed on LinkedIn, a conversion tracking cookie is stored on your computer. Among other things, Collects your IP address, device and browser properties, and page events. These cookies lose their validity after 30 days, do not contain any personal data and are therefore not used for personal identification. If you visit certain pages of ours and the stored cookie on your computer has not yet expired, it is recognizable that someone has been redirected to our website by the advertisement. Each LinkedIn customer receives a different cookie. Cookies can thus be tracked via the websites of Reddit Ads customers. The assignment takes place via a statistical evaluation of non-personal data. Further information on data protection at LinkedIn can be found in the LinkedIn data protection information: https://www.linkedin.com/legal/privacy-policyThe cookies are only set after you have given us your consent. The legal basis for data processing is your consent pursuant to Art. 6 para. 1 lit. a GDPR; you can revoke this at any time (see: G) Revocation of your consent).
We also advertise on TikTok. For this purpose, we use the TikTok pixel to check the effectiveness of this advertising. This service is provided by TikTok Technology Limited (Ireland), 10 Earlsfort Terrace, Dublin, D02 T380, Ireland.When you click on an ad placed on TikTok, a conversion tracking cookie is placed on your computer. These cookies lose their validity after 30 days, do not contain any personal data and are therefore not used for personal identification. If you visit certain pages of ours and the stored cookie on your computer has not yet expired, it can be seen that someone has been redirected to our website through the advertisement. Each visitor clicking on a TikTok Ad receives a different cookie. Cookies can thus be tracked via the websites of TikTok Ads issuers. The assignment takes place via a statistical evaluation of non-personal data.
Further information on data protection at TikTok can be found in the TikTok privacy policy: https://www.tiktok.com/legal/page/eea/privacy-policy/en
The cookies are only set after you have given us your consent. The legal basis for data processing is your consent pursuant to Art. 6 para. 1 lit. a GDPR; you can revoke this at any time (see: G) Revocation of your consent).
I) Security measure
We use industry-standard technical and organizational security measures to protect your personal data from loss, misuse, manipulation, or deletion by third parties, but we cannot guarantee that unauthorized persons will not access your personal data.
J) Compliance
We may be compelled to disclose personal information of users or customers to judicial authorities in order to comply with a subpoena or similar judicial or administrative order, or if we are required or authorized to do so by the laws, ordinances and regulations of any country, state, or other competent jurisdiction. Even in the event of a violation of the restrictions on the use of the materials made available on the Website, we are entitled to disclose personal user information to our business partners concerned or to the judicial authorities.
The legal basis for data processing is Art. 6 para. 1 lit. c GDPR.
K) Data subjects’ rights
You have a right to information, correction, deletion, restriction of processing, objection to processing and data portability. If processing is based on your consent, you have the right to revoke it with effect for the future. Please contact us at dataprivacy@bcgplatinion.com.
The revocation of consent does not affect the legality of the processing carried out based on the consent until the revocation.
You also have the right to complain to a data protection supervisory authority responsible for you about the processing of your personal data by us.
Children
We recognize the importance of protecting children’s privacy, especially regarding Internet communications. This website is not intended for minors, i.e. persons under the age of 18, and is not intended to address them.
Contact
If you have any questions about this privacy policy, you can contact our data protection team at dataprivacy@bcgplatinion.com or at our postal address (Platinion GmbH, Im Mediapark 5c, 50670 Cologne); You can also reach our data protection officer directly at dsb-platinion@intersoft-consulting.de or at the postal address (Platinion GmbH, Im Mediapark 5c, 50670 Cologne) with the addition "the data protection officer".