Privacy Policy
Data protection declaration
1. Information on the collection of personal data
(1) In the following, we provide information on the collection of personal data when using the BRAIN Biotech Group website. Personal data is all data that can be related to you personally, e.g. name, address, e-mail addresses, user behavior.
(2) The controller pursuant to Art. 4 (7) of the EU General Data Protection Regulation (GDPR) for the BRAIN Biotech Group website is
BRAIN Biotech AG
Darmstädter Street 34 – 36
64673 Zwingenberg
Germany
(see our imprint).
You can contact our data protection officer at privacy@brain-biotech.com or at our postal address with the addition “Data Protection Officer”.
(3) If you contact us via one of our functional e-mail addresses, the data you provide (your e-mail address, possibly your name and telephone number) will be stored by us in order to answer your questions.
If the data provided by you is private contact data, we will delete this data in connection with your request as soon as it is no longer required to be stored, if it does not conflict with corresponding legal storage regulations or if we lawfully process your data for other purposes on the basis of your request.
(4) Insofar as we wish to use contracted service providers for individual functions of our offer or to use your data for advertising purposes, you will find detailed information about the respective processes below. We also specify the criteria for the storage period.
2. Your rights
(1) You have the following rights towards us with regard to personal data concerning you:
- right of information,
- right of correction or deletion,
- right of limitation of processing,
- right of opposition to the processing,
- right of data transferability.
(2) You also have the right to complain to a data protection supervisory authority about our processing of your personal data.
3. General information on the legal basis for data processing on this website
(1) If you have consented to data processing, we process your personal data on the basis of Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR, insofar as special categories of data are processed in accordance with Art. 9 para. 1 GDPR.
(2) In the event of express consent to the transfer of personal data to third countries, data processing is also carried out on the basis of Art. 49 para. 1 lit. a GDPR.
(3) If you have consented to the storage of cookies or access to information in your end device (e.g. via device fingerprinting), the data processing is also carried out on the basis of Section 25 (1) TDDDG. Consent can be revoked at any time.
(4) If your data is required to fulfill the contract or to carry out pre-contractual measures, we process your data on the basis of Art. 6 para. 1 lit. b GDPR.
(5) Furthermore, we process your data if this is necessary to fulfill a legal obligation on the basis of Art. 6 para. 1 lit. c GDPR.
(6) Data processing may also be carried out on the basis of our legitimate interest pursuant to Art. 6 para. 1 lit. f GDPR. Information on the relevant legal bases in each individual case is provided in the following paragraphs of this privacy policy.
4. Collection of personal data when visiting this website
(1) If you use the website for purely informational purposes, i.e. if you do not register or otherwise provide us with information, we only collect the personal data that your browser transmits to our server. If you wish to view our website, we collect the following data, which is technically necessary for us to display our website to you and to ensure stability and security (legal basis is Art. 6 para. 1 sentence 1 lit. f GDPR):
- IP address
- Date and time of the request
- Time zone difference to Greenwich Mean Time (GMT)
- Content of the website accessed
- Access status/HTTP status code
- Amount of data transferred in each case
- Website from which you accessed our website browser
- Operating system and its interface
- Language and version of the browser software
(2) In addition to the aforementioned data, cookies are stored on your computer when you use this website. Cookies are small text files that are stored on your hard disk and assigned to the browser you are using and through which certain information flows to the place that sets the cookie (here: by us). Cookies cannot execute programs or transfer viruses to your computer. They are used to make the website more user-friendly and effective overall.
(3) Use of cookies: This website uses different types of cookies, which depend on the functions used on this website.
a) Essential cookies
These cookies are necessary for the technically correct implementation of functions, as any other technical implementation without cookies is currently not possible. These cookies are only stored on your end device for the duration of your visit to this website.
b) Functional cookies
Functional cookies serve to improve and increase the usability of our website, as they save settings, for example, so that you do not have to make them each time. These are, for example, language switchers, which retain the selected language and save it for the duration of your visit to our website. Functional cookies are stored on your end device for the duration of your visit to this website.
c) Transient cookies
These cookies are only stored on your end device for the duration of your Internet browser use and are automatically deleted when you close the browser. These cookies include, for example, session cookies, which contain a session ID that is necessary for the assignment of requests from your browser to the joint session and serve to recognize the computer when you return to our website. Session cookies are deleted when you log out or close the tab or browser.
d) Persistent cookies
Persistent cookies are stored on your end device for a certain period of time. They are used, for example, to store certain settings that you have made for our website for a defined period of time (so-called consent cookies) so that you do not have to make these settings every time you visit this website. The duration depends on the cookie itself. However, you can delete these cookies at any time via the security settings of your browser.
(4) Different cookies are used depending on the function visited or used on this website.
- Essential cookies
Cookie Name | Provider | Purpose |
klaro | brain-biotech.com | Stores chosen settings for cookie usage of this website (e.g. tracking) |
- Cookies for marketing, analysis & visitor statistics
Cookie Name | Provider | Purpose |
---|---|---|
_pk_id# | brain-biotech.com | Stores anonymous statistics about hte user’s visit to the website, such as the number of visits, average time spent on this website and which pages were read |
_pk_ses# | brain-biotech.com | Used by the Piwik Analytics Platform to track the visitor’s page views during the session |
PHPSESSID | brain-biotech.com | Contains a unique ID to recognize the user and store settings & other information |
(5) You can configure your browser settings according to your wishes and, for example, refuse to accept third-party cookies or all cookies. We would like to point out that you may not be able to use all functions of this website.
(6) This website is designed and maintained by RYZE digital GmbH, Mombacher Str. 4, 55122 Mainz, Germany. We have concluded an order processing contract with RYZE digital GmbH for the processing of personal data in accordance with the EU GDPR, which ensures that your data is processed by Ryze or one of its subcontractors exclusively in accordance with our instructions and the GDPR. Further information can be found in RYZE's privacy policy:
https://www.ryze-digital.de/de/datenschutzhinweise/
(7) The BRAIN Biotech website is hosted by uvensys GmbH, Robert-Bosch-Strasse 4b, 35440 Linden, Germany, as a subcontractor of RYZE digital GmbH. All data collected during your visit to this website is processed and stored exclusively on servers within the European Union (specifically: Germany, France). Personal data is not transferred to third countries. Further information can be found in the uvensys GmbH privacy policy: https://uvensys.de/datenschutzerklaerung/
uvensys GmbH may collect, process and store the data mentioned under points 4 (1) & (4) when you visit this website, whereby the data mentioned under point 4 (4) will only be processed if you allow us to do so or make it accessible to us (in accordance with Art. 6 para. 1 lit. a GDPR).
(8) In the case of our annual report, we also use the services of the provider RYZE digital GmbH, Mombacher Str. 4, 55122 Mainz, which hosts the annual report on its servers via RYZE Digital VRM Corporate Solutions GmbH, Erich-Dombrowski-Straße 2, 55127 Mainz. We have also concluded an order processing contract with RYZE digital GmbH for the processing of personal data in accordance with the EU GDPR.
When you visit our annual report website, log and tracking data is processed. These are
- Browser type and browser version
- Operating system used
- Website from which the visitor comes (referrer URL)
- Host name of the accessing computer
- Date and time of the server request
- IP address (anonymized)
All data collected when forwarding to the annual report via our website is stored on RYZE digital servers located in Germany. Further information can be found in the privacy policy of RYZE digital and its subsidiary RYZE digital VRM Corporate Solutions:
https://www.ryze-digital.de/de/datenschutzhinweise/
https://vrm-digital-communications.de/datenschutz/
5. Use of Matomo (ehem. PIWIK)
(1) This website uses the open source web analysis service Matomo to analyze and regularly improve the use of this website. The processing of your collected personal data (see point 4 (4)) serves exclusively to analyze the usage behavior of visitors to this website. We can use the statistics obtained to improve our offer and make it more interesting for you as a user.
(2) For this evaluation, cookies (see point 4) are stored on your computer and thus enable us to analyze the use of the BRAIN Biotech website. Matomo does not collect any data without your consent via the cookie consent banner on this website or your subsequently granted consent (under point 5 (5)). The legal basis for the processing of your personal data therefore results from Art. 6 (1) sentence 1 lit. a GDPR.
(3) We use Matomo with the “AnonymizeIP” setting. This means that your IP address is further processed in abbreviated form so that a direct personal reference can be excluded. In addition, the IP address transmitted by your browser via Matomo is not associated with other data collected by us.
(4) If you consent to the use of the web analysis service, the following data will be collected when you access individual pages of this website:
- the first 6 bytes of your IP address (anonymized IP)
- the access to the website
- the website from which you came to our website (referrer)
- the subpages that are accessed from this website
- the time spent on this website
- the frequency of visits to our website
The data collected about the use of this website is transmitted to a server in France, from where we can retrieve the data. The data is stored on the server for 180 days and then automatically deleted. Statistics generated from this data and the underlying data are not deleted.
(5) You can change the settings you have made via the cookie consent banner for the use of the Matomo web analysis service in this privacy policy at any time. To do this, you can check or uncheck the box for the use of Matomo in the following field:
OPTOUT-FRAME
If you subsequently allow or prohibit the use, a consent cookie (see point 4 (3) d) and point 4 (4) of this privacy policy) will be stored on your device via your Internet browser, which contains your last decision and thus enables or prevents the analysis.
Please note, however, that you must make the corresponding setting again if you delete the cookies stored on your end device or if the duration of the storage of the consent cookie has expired.
(6) The Matomo program (formerly Piwik) is an open source project. You can obtain information from the third-party provider on data protection https://matomo.org/docs/privacy.
6. Further functions and offers of the BRAIN Biotech website
(1) In addition to the purely informational use of the BRAIN Biotech website, we offer various services that you can use if you are interested. To do so, you must generally provide additional personal data that we use to provide the respective service and to which the aforementioned data processing principles apply.
(2) In some cases, we use external service providers to process your data. These have been carefully selected and commissioned by us, are bound by our instructions and are regularly monitored.
(3) If our service providers or partners are based in a country outside the European Economic Area (EEA), we will inform you of the consequences of this circumstance in the description of the offer.
(4) This privacy policy applies only to the BRAIN Biotech website. However, this website also contains links to websites and applications of all companies within the BRAIN Biotech Group, each with its own privacy policy. We are not responsible for the collection, processing and use of your data in the context of websites or applications that are not operated by us, nor for their content.
Furthermore, this website also contains links to third-party websites that may be of interest to you. We are not responsible for the collection, processing and use of your data in the context of websites or applications that are not operated by us, nor for their content.
7. Social plugins, links to social networks and options for content sharing
(1) This website uses a link to the X (formerly Twitter) service. This function is offered by X Corp, 1355 Market Street, Suite 900, San Francisco, CA 9410, USA795. When a user uses this link, the browser establishes a direct connection with the X servers. The content of the link (which is linked to the BRAIN Biotech AG account) is transmitted by X directly to the user's browser. We therefore have no influence on the scope of the data that X collects with the help of this plugin and inform users according to our level of knowledge. To the best of our knowledge, only the user's IP address and the URL of the respective website are transmitted when the link is accessed. Further information on this can be found in X's privacy policy:
https://x.com/en/privacy
(2) Plugins from YouTube are used on this website to improve the presentation of our website. This is a video portal operated by YouTube, LLC, 901 Cherry Ave, 94066 San Bruno, CA 94066, USA - hereinafter referred to as “YouTube”.
YouTube itself is a subsidiary of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043 USA - hereinafter referred to as “Google”.
Google's certification in accordance with the EU-US Privacy Shield (https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active) means that Google, and therefore also its subsidiary YouTube, guarantees that the data protection regulations of the EU are also complied with when processing data in the USA.
The integration of videos on this website takes place on the legal basis of Art. 6 para. 1 sentence 1 lit. f) GDPR, the legitimate interest here lies in the quality improvement and extended provision of information on our website as part of our public relations work.
When integrating YouTube or videos from the platform, we use the “extended data protection mode” function to be able to display the videos. According to YouTube, this function means that data is only transmitted to YouTube's servers after the displayed video has started. Without this function, a connection to the YouTube servers in the USA is already established when you visit the BRAIN Biotech website with an embedded YouTube video.
The connection to the YouTube servers is necessary in order to be able to display the respective video on this website via your Internet browser. In the course of this, YouTube will record and process at least your IP address, date and time as well as the website you have visited. In addition, a connection to Google's “DoubleClick” advertising network will be established.
If you are logged in to YouTube at the same time, YouTube will assign the connection information to your YouTube account. If you wish to prevent this, you must either log out before visiting this website or make the appropriate settings in your YouTube account.
For the purpose of functionality and analysis of user behavior, YouTube permanently stores cookies on your end device via your Internet browser. If you do not agree to this processing, you have the option of preventing the storage of cookies by changing the settings in your internet browser. You can find more information on this under point 4 above in this privacy policy.
Google provides further information about the collection and use of data as well as your rights and protection options in this regard in the data protection information available at
https://policies.google.com/privacy
8. Usage of web fonts
This website uses so-called web fonts for the uniform display of fonts. These are loaded using a JavaScript code.
The use of these web fonts represents a legitimate interest of our company in accordance with Art. 6 para. 1 f of the GDPR in the sense of a uniform and appealing presentation of our online offer.
If your browser does not support web fonts or blocks JavaScript, a standard font will be used by your computer.
The individual web font services used on this website are listed below.
(1) Adobe Typekit
Our website uses fonts (web fonts) from Adobe Systems Incorporated, 345 Park Avenue, San Jose, CA 95110-2704, USA (Adobe), which are provided on the website by the Adobe Typekit service.
When you access the website, your browser loads the required web fonts into your browser cache to display them correctly. This is done by establishing a connection from your browser to the Adobe servers in the USA.
Your IP address and your visit to the website are transmitted to Adobe for this purpose. According to its own statement, Adobe does not use cookies when providing the fonts.
Adobe is certified in accordance with the EU-US Privacy Shield. This is an agreement between the European Union (EU) and the United States of America (USA), which is intended to ensure compliance with European data protection standards. You can find more information on this at
https://www.adobe.com/de/privacy/eudatatransfers.html
Further information on Adobe's data protection policy and the use of Adobe Typekit can be found under the following links:
https://www.adobe.com/de/privacy/policy.html
https://www.adobe.com/de/privacy/policies/typekit.html
(2) Fonts.com / Monotype
Our website uses fonts (web fonts) from Monotype Imaging Inc, 600 Unicorn Park Drive, Woburn, MA 01801, USA (Monotype) which are provided on the website by the Fonts.com service.
When you access this website, your browser loads the required web fonts into your browser cache to display them correctly. This is done by establishing a connection between your browser and Monotype's servers in the USA.
As a result, Monotype becomes aware that our website (date and time of the visit) was accessed from your IP address. Monotype and Fonts.com do not use cookies when providing the fonts.
In addition, further data is collected via the Monotype Web Font Tracking Tool. These are in detail:
- Web font project number (anonymized)
- URL of the licensed website (incl. the customer ID)
- Referring URL
The transmission of this data is used to log the use or access of the corresponding website, to count the number of hits (counter) and to prevent misuse of the counter. This data is stored in the form of log files and deleted after 30 days so that the corresponding data can no longer be processed.
Further information can be found in the data protection notices of Fonts.com and Monotype, which can be viewed under the following links:
https://www.fonts.com/info/legal
https://www.monotype.com/legal/privacy-policy/
https://www.monotype.com/legal/privacy-policy/web-font-tracking-privacy-policy/
9. Integration of further external web services and processing of data outside the EU
On the BRAIN Biotech website, we use active content from external providers, so-called web services. By accessing this website, these external providers may receive personal information about your visit to this website. This may involve the processing of data outside the EU. You can prevent this by installing an appropriate browser plugin or deactivating the execution of scripts in your browser. This may result in functional restrictions on websites that you visit.
We use the following external web services:
A web service from Google Ireland Limited, Gordon House, Barrow Street, 4 Dublin, Ireland (hereinafter Google) is loaded on this website. We use this data to ensure the full functionality of the website. In this context, your browser may transmit personal data to Google. The legal basis for data processing is Article 6 (1) (f) GDPR. The legitimate interest lies in the error-free functioning of the website. Further information on how to handle the transferred data can be found in Google's privacy policy:
https://policies.google.com/privacy
You can prevent Google from collecting and processing your data by deactivating the execution of script code in your browser or installing a script blocker in your browser.
- Gstatic
A web service from Google Ireland Limited, Gordon House, Barrow Street, 4 Dublin, Ireland (hereinafter Gstatic) is loaded on this website. We use this data to ensure the full functionality of the website. In this context, your browser may transmit personal data to Gstatic. The legal basis for data processing is Article 6 (1) (f) GDPR. The legitimate interest lies in the error-free functioning of the website. Further information on the handling of transferred data can be found in Gstatic's data protection declaration: https://policies.google.com/privacy
You can prevent the collection and processing of your data by Gstatic by deactivating the execution of script code in your browser or installing a script blocker in your browser.
- Gstatic Fonts
A web service from Google Ireland Limited, Gordon House, Barrow Street, 4 Dublin, Ireland (hereinafter Gstatic Fonts) is loaded on this website. We use this data to ensure the full functionality of the website. In this context, your browser may transmit personal data to Gstatic Fonts. The legal basis for data processing is Article 6 (1) (f) GDPR. The legitimate interest lies in the error-free functioning of the website. Further information on the handling of transferred data can be found in the data protection declaration of Gstatic Fonts: https://policies.google.com/privacy
You can prevent the collection and processing of your data by Gstatic Fonts by deactivating the execution of script code in your browser or installing a script blocker in your browser.
- Google reCaptcha
A web service from Google Ireland Limited, Gordon House, Barrow Street, 4 Dublin, Ireland (hereinafter Google reCaptcha) is loaded on this website. We use this data to ensure the full functionality of the website. In this context, your browser may transmit personal data to Google reCaptcha. The legal basis for data processing is Article 6 (1) (f) GDPR. The legitimate interest lies in the error-free functioning of the website. Further information on the handling of transferred data can be found in the Google reCaptcha data protection declaration: https://policies.google.com/privacy
You can prevent the collection and processing of your data by Google reCaptcha by deactivating the execution of script code in your browser or installing a script blocker in your browser.
- Gstatic reCaptcha
A web service from Google Ireland Limited, Gordon House, Barrow Street, 4 Dublin, Ireland (hereinafter Gstatic reCaptcha) is loaded on this website. We use this data to ensure the full functionality of the website. In this context, your browser may transmit personal data to Gstatic reCaptcha. The legal basis for data processing is Article 6 (1) (f) GDPR. The legitimate interest lies in the error-free functioning of the website. Further information on the handling of transferred data can be found in the Gstatic reCaptcha data protection declaration: https://policies.google.com/privacy
You can prevent the collection and processing of your data by Gstatic reCaptcha by deactivating the execution of script code in your browser or installing a script blocker in your browser.
10. Data protection information for appilcants
(1) Applicants are also subject to the data protection information on the Career website, which can be viewed there or directly at the following link:
English version: https://brain-biotech.jobs.personio.com/privacy-policy?language=en
German version: https://brain-biotech.jobs.personio.com/privacy-policy?language=de
11. Information about contradiction or revocation against the processing of your data
(1) If you have given your consent to the processing of your data, you can revoke this at any time. Such a revocation affects the lawfulness of the processing of your personal data after you have expressed it to us.
(2) If we base the processing of your personal data on the balance of interests, you can object to the processing. This is the case if the processing is not necessary to fulfill a contract with you, which is explained by us in the following description of the functions. If you exercise such an objection, we will ask you to explain the reasons why we should not process your personal data as we have done so far. In the event of your justified objection, we will examine the situation and will either stop or adjust data processing or show you our compelling legitimate reasons on the basis of which we continue processing.
(3) Of course, you can object to the processing of your personal data for advertising and data analysis purposes at any time. You can inform us about your objection to advertising by email using the following contact details (privacy@brain-biotech.com) or inform by post:
BRAIN Biotech AG
Data Privacy Officer
Darmstädter Straße 34 - 36
64673 Zwingenberg
Germany
12. Final provisions
(1) We reserve the right to adapt this data protection declaration at any time with effect for the future so that it always complies with current legal requirements or to reflect changes or similar.