Privacy Policy

1. Data Protection at a Glance

General Information

The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data means any data that can be used to identify you personally. Detailed information on data protection is set out in the Privacy Policy below.

Data Collection on This Website

Who is responsible for data collection on this website?

The website operator processes data on this website. The operator’s contact details can be found in the section “Information on the Data Controller” in this Privacy Policy.

How do we collect your data?

We collect some data when you provide it to us. This may include, for example, data that you enter into a contact form.

We also collect other data automatically, or after you give your consent, when you visit the website, through our IT systems. This mainly includes technical data, such as your internet browser, operating system or the time at which the page was accessed. This data is collected automatically as soon as you access this website.

What do we use your data for?

We collect some data to ensure the website is provided without errors. We may use other data to analyze your user behavior. If contracts can be concluded or initiated via the website, we will also process the transmitted data for contractual offers, orders, or other contract-related inquiries.

What rights do you have regarding your data?

You have the right at any time to receive information free of charge about the origin, recipient, and purpose of your stored personal data. You also have the right to request the correction or deletion of this data. If you have given your consent to data processing, you may withdraw this consent at any time with effect for the future. Furthermore, under certain circumstances, you have the right to request restriction of the processing of your personal data.

You also have the right to lodge a complaint with the competent supervisory authority.

You can contact us at any time with questions about this or any other data protection matters.

Analytics Tools and Third-Party Tools

When you visit this website, your browsing behavior may be statistically analyzed. This is mainly carried out using analytics programs.

Detailed information on these analytics programs can be found in the following Privacy Policy.

2. Hosting

We host the content of our website with the following provider:

External Hosting

This website is hosted externally. Personal data collected on this website is stored on the hosting provider(s) ‘ servers. This may include, in particular, IP addresses, contact requests, metadata and communication data, contractual data, contact details, names, website access data and other data generated via a website.

External hosting is carried out for the purpose of fulfilling contracts with our potential and existing customers (Art. 6(1)(b) GDPR) and in the interest of providing our online services securely, quickly and efficiently through a professional provider (Art. 6(1)(f) GDPR).

Where we request corresponding consent, we process data exclusively based on Art. 6(1)(a) GDPR and Section 25(1) TDDDG, insofar as the consent includes the storage of cookies or access to information on the user’s terminal device, e.g. device fingerprinting, within the meaning of the TDDDG. Consent may be withdrawn at any time.

Our hosting provider(s) will process your data only to the extent necessary to fulfill their service obligations and will follow our instructions regarding this data.

We use the following hosting provider(s):

AVANTARO – Lars Gebhardt
Hugo-Pöschmann Str. 34
09127 Chemnitz

Data Processing Agreement

We have concluded a data processing agreement (DPA) for the use of the service referred to above. This contract, required under data protection law, ensures that the provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.

3. General Information and Mandatory Information

Data Protection

The operators of this website take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with statutory data protection regulations and this Privacy Policy.

When you use this website, various types of personal data are collected. Personal data is data that can be used to identify you personally. This Privacy Policy explains what data we collect and how we use it. It also explains how and why we do this.

Please note that data transmission over the internet, e.g., communication by email, may be subject to security vulnerabilities. Complete protection of data against third-party access is not possible.

Information on the Data Controller

The data controller responsible for data processing on this website is:

3D-Micromac AG
Technologie-Campus 8
D-09126 Chemnitz
Telefon: +49 (0)371 400 43 – 0
E-Mail: info@3d-micromac.com

The controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of processing personal data, e.g., names, email addresses or similar information.

Storage Period

Unless this Privacy Policy states a more specific storage period, we will keep your personal data until the purpose of the processing no longer applies. If you submit a legitimate request for deletion or withdraw your consent to data processing, we will delete your data unless we have other legally permissible reasons for storing it, e.g., retention periods under tax or commercial law. In that case, we will delete the data once these reasons no longer apply.

General Information on the Legal Basis for Data Processing on This Website

If you have consented to data processing, we process your personal data based on Art. 6(1)(a) GDPR or Art. 9(2)(a) GDPR where special categories of data pursuant to Art. 9(1) GDPR are processed. If you have given explicit consent to the transfer of personal data to third countries, processing is additionally based on Art. 49(1)(a) GDPR.

If you have consented to the storage of cookies or access to information on your terminal device, e.g. via device fingerprinting, processing is additionally based on Section 25(1) TDDDG. Consent may be withdrawn at any time.

If your data is required to perform a contract or for pre-contractual measures, we process your data based on Art. 6(1)(b) GDPR. Furthermore, we process your data where necessary to comply with a legal obligation, based on Art. 6(1)(c) GDPR.

Data processing may also be based on our legitimate interests pursuant to Art. 6(1)(f) GDPR. Information on the applicable legal basis in each case is provided in the following sections of this Privacy Policy.

Data Protection Officer

We have appointed a Data Protection Officer.

TH Kanzlei für Datenschutz und KI
Thomas HankeAn der Steilen Wand 51
08393 Meerane
Telefon: +49 (0) 173 8856639
E-Mail: datenschutz@3d-micromac.org

Information on Data Transfers to Third Countries That Are Not Considered Secure Under Data Protection Law and Transfers to US Companies That Are Not DPF-Certified

Among other things, we use tools from companies based in third countries that are not considered secure under data protection law, as well as US-based tools whose providers are not certified under the EU-US Data Privacy Framework (DPF). When these tools are active, your personal data may be transferred to and processed in these countries. Please note that a level of data protection comparable to that of the EU cannot be guaranteed in third countries considered insecure under data protection law.

Please note that, as a secure third country, the USA generally provides a level of data protection comparable to that of the EU. Data may therefore be transferred to the USA if the recipient is certified under the EU-US Data Privacy Framework (DPF) or has other appropriate safeguards in place. Information on transfers to third countries, including the recipients of the data, is available in this Privacy Policy.

Recipients of Personal Data

As part of our business activities, we work with various external parties. In some cases, this also requires transferring personal data to such external parties. We disclose personal data to external parties only when necessary to perform a contract, when legally required (e.g., disclosure to tax authorities), when we have a legitimate interest pursuant to Art. 6(1)(f) GDPR in the disclosure, or where another legal basis permits the disclosure.

When using processors, we disclose our customers’ personal data only under a valid data processing agreement. In the case of joint processing, we conclude a joint processing agreement.

Withdrawal of Your Consent to Data Processing

Many data processing operations are only possible with your explicit consent. You may withdraw consent you have already given at any time. The lawfulness of data processing carried out before the withdrawal remains unaffected.

Right to Object to Data Collection in Specific Cases and to Direct Marketing (Art. 21 GDPR)

IF DATA PROCESSING IS CARRIED OUT BASED ON ART. 6(1)(E) OR (F) GDPR, YOU HAVE THE RIGHT AT ANY TIME, ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION, TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE RESPECTIVE LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY.

IF YOU OBJECT, WE WILL NO LONGER PROCESS THE PERSONAL DATA CONCERNED UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING THAT OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS, OR THE PROCESSING SERVES THE ESTABLISHMENT, EXERCISE OR DEFENCE OF LEGAL CLAIMS (OBJECTION PURSUANT TO ART. 21(1) GDPR).

IF YOUR PERSONAL DATA IS PROCESSED FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR SUCH MARKETING PURPOSES; THIS ALSO APPLIES TO PROFILING TO THE EXTENT THAT IT IS RELATED TO SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL SUBSEQUENTLY NO LONGER BE USED FOR DIRECT MARKETING PURPOSES (OBJECTION PURSUANT TO ART. 21(2) GDPR).

Right to Lodge a Complaint with the Competent Supervisory Authority

In the event of breaches of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, particularly in the Member State of their habitual residence, their place of work or the place of the alleged infringement. The right to lodge a complaint is without prejudice to any other administrative or judicial remedies.

Right to Data Portability

You have the right to receive data that we process automatically based on your consent or in the performance of a contract, either for yourself or for a third party, in a commonly used, machine-readable format. If you request the direct transfer of the data to another controller, we will do so only where technically feasible.

Access, Rectification and Erasure

Within the framework of applicable statutory provisions, you have the right at any time to obtain information free of charge about your stored personal data, its origin and recipients and the purpose of data processing, and, where applicable, the right to have this data corrected or erased. You may contact us at any time with questions about this or any other matters concerning personal data.

Right to Restriction of Processing

You have the right to request restriction of the processing of your personal data. You may contact us at any time regarding this matter. The right to restriction of processing applies in the following cases:

If you dispute the accuracy of the personal data we store, we generally need time to verify it. During the verification process, you have the right to request restriction of the processing of your personal data.

If the processing of your personal data was or is unlawful, you may request restriction of data processing instead of erasure.

If we no longer need your personal data but you require it for the establishment, exercise or defense of legal claims, you have the right to request restriction of processing instead of erasure.

If you have objected pursuant to Art. 21(1) GDPR, we must balance your interests with ours. As long as it has not yet been determined whose interests prevail, you have the right to request restriction of the processing of your personal data.

If you have restricted the processing of your personal data, such data may, apart from storage, only be processed with your consent, for the establishment, exercise or defense of legal claims, for the protection of the rights of another natural or legal person, or for reasons of important public interest of the European Union or a Member State.

SSL or TLS Encryption

For security reasons and to protect the transmission of confidential content, such as orders or inquiries that you send to us as the website operator, this website uses SSL or TLS encryption. You can recognize an encrypted connection by the change in the browser address bar from “http://” to “https://” and by the padlock symbol in your browser bar.

When SSL or TLS encryption is enabled, third parties cannot read the data you transmit to us.

Objection to Promotional Emails

We hereby object to the use of contact details published as part of our legal notice obligations for the purpose of sending unsolicited advertising and informational materials. The operators of this website expressly reserve the right to take legal action in the event of unsolicited advertising information, such as spam emails.

4. Data Collection on This Website

Cookies

Our websites use so-called “cookies”. Cookies are small data packages and do not damage your terminal device. They are stored on your device either temporarily for the duration of a session (session cookies) or permanently (persistent cookies). Session cookies are automatically deleted at the end of your visit. Persistent cookies remain on your terminal device until you delete them yourself or your web browser deletes them automatically.

Cookies may originate from us (first-party cookies) or from third-party companies (third-party cookies). Third-party cookies enable certain third-party services to be integrated into websites, e.g. cookies used to process payment services.

Cookies serve various functions. Many cookies are technically necessary because certain website functions would not work without them, e.g. the shopping basket function or the display of videos.

Other cookies may be used to analyze user behavior or for advertising purposes. Cookies required to carry out electronic communications, provide certain functions you request (e.g., the shopping basket function), or optimize the website (e.g., cookies for measuring website audiences) are stored based on Art. 6(1)(f) GDPR unless another legal basis is specified. The website operator has a legitimate interest in storing necessary cookies to ensure the technically error-free and optimized provision of its services.

Where consent has been requested for the storage of cookies and comparable recognition technologies, processing takes place exclusively based on this consent (Art. 6(1)(a) GDPR and Section 25(1) TDDDG); consent may be withdrawn at any time.

You can configure your browser to inform you when cookies are set, to allow cookies only in individual cases, to exclude the acceptance of cookies in certain cases or altogether, and to automatically delete cookies when you close your browser. Disabling cookies may limit this website’s functionality.

If additional cookies and services are used on this website, information about them can be found in this Privacy Policy.

Consent Using Borlabs Cookie

Our website uses the Borlabs Cookie consent technology to obtain your consent to store certain cookies in your browser or use certain technologies, and to document this consent in compliance with data protection law. The provider of this technology is Borlabs GmbH, Hamburger Str. 11, 22083 Hamburg, Germany (“Borlabs”).

When you access our website, a Borlabs cookie is stored in your browser in which the consent you have granted or withdrawn is recorded. This data is not passed on to the provider of the Borlabs Cookie.

We store the collected data until you request that we delete it, you delete the Borlabs cookie yourself, or the purpose for storing the data no longer applies. Mandatory statutory retention periods remain unaffected. Details about data processing by Borlabs Cookie can be found at:
https://de.borlabs.io/kb/welche-daten-speichert-borlabs-cookie/

Borlabs Cookie consent technology is used to obtain the consent required by law for the use of cookies. The legal basis is Art. 6(1)(c) GDPR.

Server Log Files

The provider of this website automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These include:

  •         Browser type and browser version
  •         Operating system used
  •         Referrer URL
  •         Hostname of the accessing computer
  •         Time of the server request
  •         IP address

This data is not combined with other data sources.

This data is collected based on Art. 6(1)(f) GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimization of the website; server log files must be collected for this purpose.

Inquiries by Email, Telephone or Fax

If you contact us by email, telephone, or fax, we will store and process your inquiry, including all personal data arising from it (such as your name and the nature of your inquiry), to deal with your request. We do not pass this data on without your consent.

We process this data based on Art. 6(1)(b) GDPR where your inquiry is related to the performance of a contract or is required to take pre-contractual measures. In all other cases, processing is based on our legitimate interest in effectively processing inquiries addressed to us (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR), if such consent has been requested. Consent may be withdrawn at any time.

Data sent to us via contact inquiries remains with us until you request its deletion, withdraw your consent to its storage, or the purpose for storing the data no longer applies (e.g., once your inquiry has been fully processed). Mandatory statutory provisions, particularly statutory retention periods, remain unaffected.

Web Analytics

Our website uses the web analytics tools Avostats and Avofomo to understand visitor behavior better and improve the user experience. Avostats and Avofomo collect anonymized data relating to page views, mouse movements, click behavior, and other interactions on our website.

Avostats and Avofomo use the data collected exclusively for statistical analysis and technical optimization of our website. Data processing is based on Art. 6(1)(f) GDPR (legitimate interest). Our legitimate interest is to analyze and optimize our website.

Avostats and Avofomo operate without cookies and do not store personal data such as IP addresses in plain text. All data is processed in pseudonymized form and is not shared with third parties.

If you do not wish your visit to be statistically recorded, you may object to data collection by Avostats at any time. A corresponding opt-out link can be found at:
http://www.3d-micromac.com/?pixel_optout=true

Further information about data protection at Avostats and Avofomo can be found at:
https://avostats.com/page/privacy
https://avofomo.com/page/privacy

5. Newsletter

Newsletter Data

If you would like to receive the newsletter offered on the website, we require an email address from you as well as information enabling us to verify that you are the owner of the email address provided and that you consent to receiving the newsletter. We collect no additional data, or only voluntarily. We use this data exclusively for sending the requested information and do not disclose it to third parties.

The data entered in the newsletter registration form is processed exclusively based on your consent (Art. 6(1)(a) GDPR). You may withdraw your consent to the storage of your data and email address and their use for sending the newsletter at any time, for example via the “unsubscribe” link in the newsletter. The lawfulness of data processing operations already carried out remains unaffected by the withdrawal.

The data you provide to us for the purpose of subscribing to the newsletter will be stored by the newsletter service provider until you unsubscribe from the newsletter and will be deleted from the newsletter distribution list after you unsubscribe or once the purpose no longer applies. We reserve the right to delete or block email addresses from our newsletter distribution list at our discretion within the scope of our legitimate interest pursuant to Art. 6(1)(f) GDPR.

Our email newsletters are sent using the following provider:

MAILINGWORK Positive Group Chemnitz GmbH, Schönherrstraße 8, 09113 Chemnitz, Germany.

The aforementioned provider processes personal data only after registration is complete and consent has been given pursuant to Art. 6(1)(a) GDPR.

All relevant data protection information, including information regarding free withdrawal from the newsletter at any time, is available from the provider. The provider’s Privacy Policy can be viewed at:
https://mailingwork.de/datenschutzerklaerung

We do not pass personal data on to the aforementioned provider.

Following your explicit consent pursuant to Art. 6(1)(a) GDPR, the provider also carries out statistical performance analyses of newsletter campaigns using web beacons or tracking pixels in the emails sent. These may measure opening rates and specific interactions with newsletter content.

Device information, e.g. the time of access, IP address, browser type and operating system, is also collected and analyzed but is not combined with other datasets. You may withdraw your consent to newsletter tracking at any time with effect for the future.

We have concluded a data processing agreement with the provider that protects the personal data collected on our behalf and prohibits disclosure to third parties.

Data we store for other purposes remains unaffected.

After you unsubscribe from the newsletter distribution list, the newsletter service provider may store your email address in a blocklist, where necessary, to prevent future mailings.

We use the data in the blocklist exclusively for this purpose and do not combine it with other data. This serves both your interest and our interest in complying with the legal requirements governing the sending of newsletters (legitimate interest within the meaning of Art. 6(1)(f) GDPR). Storage in the blacklist is not subject to a time limit. You may object to this storage if your interests override our legitimate interest.

6. Plugins and Tools

Vimeo

This website uses plugins from the Vimeo video portal. The provider is Vimeo Inc., 555 West 18th Street, New York, New York 10011, USA.

When you visit one of our pages containing a Vimeo video, a connection is established with Vimeo’s servers. The Vimeo server is informed which of our pages you have visited. Vimeo also obtains your IP address. This applies even if you are not logged into Vimeo or do not have a Vimeo account. Vimeo transmits the information it collects to Vimeo servers in the USA.

If you are logged into your Vimeo account, you enable Vimeo to associate your browsing behavior directly with your personal profile. You can prevent this by logging out of your Vimeo account.

To recognize website visitors, Vimeo uses cookies or comparable recognition technologies, e.g., device fingerprinting.

Vimeo is used to present our online content in an appealing way. This constitutes a legitimate interest within the meaning of Art. 6(1)(f) GDPR. Where corresponding consent has been requested, processing is carried out exclusively based on Art. 6(1)(a) GDPR and Section 25(1) TDDDG, insofar as the consent includes the storage of cookies or access to information on the user’s terminal device, e.g. device fingerprinting, within the meaning of the TDDDG. Consent may be withdrawn at any time.

Data transfers to the USA are based on the European Commission’s Standard Contractual Clauses and, according to Vimeo, on “legitimate business interests”. Details can be found at:
https://vimeo.com/privacy

Further information on how user data is handled can be found in Vimeo’s Privacy Policy:
https://vimeo.com/privacy

The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards when data is processed in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information can be obtained from the provider at:
https://www.dataprivacyframework.gov/participant/5711

7. eCommerce and Payment Providers

Processing Customer and Contract Data

We collect, process, and use personal customer and contractual data to establish, structure, and modify our contractual relationships.

We collect, process, and use personal data concerning the use of this website (usage data) only to the extent necessary to enable users to use the service or to invoice them. The legal basis is Art. 6(1)(b) GDPR.

We will delete customer data collected after completion of the order or termination of the business relationship, and after expiry of any applicable statutory retention periods. Statutory retention periods remain unaffected.

Payment Services

We integrate payment services from third-party companies into our website. When you purchase from us, the payment service provider processes your payment data (e.g., name, payment amount, bank details, or credit card number) to process the payment.

The respective contractual and data protection provisions of the individual providers apply to these transactions. We use payment service providers based on Art. 6(1)(b) GDPR (contractual processing) and in the interest of providing a payment process that is as smooth, convenient and secure as possible (Art. 6(1)(f) GDPR).

Where your consent is requested for certain activities, Art. 6(1)(a) GDPR forms the legal basis for data processing; consent may be withdrawn at any time with effect for the future.

We use the following payment services/payment service providers on this website:

Stripe

The provider for customers within the EU is Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland (“Stripe”).

Data transfers to the USA are based on the European Commission’s Standard Contractual Clauses. Details can be found at:

https://stripe.com/de/privacy
https://stripe.com/de/guides/general-data-protection-regulation

Further details can be found in Stripe’s Privacy Policy:
https://stripe.com/de/privacy

8. Audio and Video Conferencing

Data Processing

We use online conferencing tools, among other services, to communicate with our customers. The individual tools we use are listed below.

If you communicate with us via video or audio conference over the internet, the provider of the respective conferencing tool collects and processes your personal data.

The conferencing tools collect all data that you provide or use in connection with the tools, such as your email address and/or telephone number. The conferencing tools also process the duration of the conference, the start and end time of participation, the number of participants and other “contextual information” relating to the communication process (metadata).

Furthermore, the tool provider processes all technical data required to facilitate online communication. This includes, in particular, IP addresses, MAC addresses, device IDs, device type, operating system type and version, client version, camera type, microphone or speakers, and connection type.

If content is exchanged, uploaded, or otherwise made available within the tool, it is also stored on the tool provider’s servers. Such content includes, in particular, cloud recordings, chat/instant messages, voicemails, uploaded photos and videos, files, whiteboards and other information shared while using the service.

Please note that we do not have complete control over the data processing operations of the tools used. The respective provider’s corporate policies largely determine our options. Further information on data processing by the conferencing tools can be found in the Privacy Policies of the respective tools listed below.

Purpose and Legal Bases

The conferencing tools are used to communicate with prospective or existing contractual partners or to provide certain services to our customers (Art. 6(1)(b) GDPR).

We also use the tools to simplify and accelerate communication with our company and us in general (legitimate interest within the meaning of Art. 6(1)(f) GDPR). Where consent has been requested, we use the respective tools based on this consent; you may withdraw consent at any time, with effect for the future.

Storage Period

We delete data collected directly by us via the video and conferencing tools as soon as you request deletion, withdraw your consent to storage, or the purpose for storing the data no longer applies.

Stored cookies remain on your terminal device until you delete them. Mandatory statutory retention periods remain unaffected.

We do not influence how long the operators of the conferencing tools store your data for their own purposes. For details, please get in touch with the operators of the conferencing tools directly.

Conferencing Tools Used

We use the following conferencing tools:

GoToMeeting

We use GoToMeeting. The provider is LogMeIn, Inc., 320 Summer Street, Boston, MA 02210, USA.

Details on data processing can be found in GoToMeeting’s Privacy Policy:
https://www.logmeininc.com/de/legal/privacy

Data transfers to the USA are based on the European Commission’s Standard Contractual Clauses. Details can be found at:
https://logmeincdn.azureedge.net/legal/lmi-customer-dpa-2020v1-de.pdf

Data Processing Agreement

We have concluded a data processing agreement (DPA) for the use of the service referred to above. This contract, required under data protection law, ensures that the provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.

9. Our Own Services

Handling Applicant Data

We offer you the opportunity to apply for a position with us, e.g. by email, post or via an online application form. Below, we provide information on the scope, purpose, and use of your personal data collected as part of the application process.

We assure you that your data is collected, processed and used in accordance with applicable data protection law and all other statutory provisions and that your data will be treated as strictly confidential.

Scope and Purpose of Data Collection

If you submit an application to us, we process the associated personal data (e.g., contact and communication data, application documents, notes made during interviews, etc.) insofar as this is necessary to decide whether to establish an employment relationship.

The legal basis is Section 26 BDSG under German law (initiation of an employment relationship), Art. 6(1)(b) GDPR (general initiation of a contractual relationship) and, where you have given your consent, Art. 6(1)(a) GDPR. Consent may be withdrawn at any time.

Within our company, we disclose your personal data exclusively to persons involved in processing your application.

If your application is successful, the data you have submitted will be stored in our data processing systems based on Section 26 BDSG and Art. 6(1)(b) GDPR for the purpose of implementing the employment relationship.

As part of the application process, we may also carry out internet research relating to you. This includes, in particular, Google searches, LinkedIn and Xing. The legal basis for this type of processing is our legitimate interest in obtaining an overall impression of publicly available information about you pursuant to Art. 6(1)(f) GDPR.

Data Retention Period

If we are unable to offer you a position, you reject a job offer, or you withdraw your application, we reserve the right to retain the data you have submitted for up to six months after completion of the application process (rejection or withdrawal), based on our legitimate interests pursuant to Art. 6(1)(f) GDPR.

We will then delete the data and destroy physical application documents. The purpose of the retention period is, in particular, to provide evidence in the event of a legal dispute.

If it is apparent that the data will still be required after the six-month period expires, e.g. due to pending or anticipated litigation, we will delete the data only once the purpose for further retention no longer applies.

A longer retention period may also apply if you have given corresponding consent (Art. 6(1)(a) GDPR) or where statutory retention obligations prevent deletion.

Our Social Media Profiles

This Privacy Policy Applies to the Following Social Media Profiles

https://www.facebook.com/3DMicromac
https://x.com/3dmicromacag
https://www.instagram.com/3dmicromacag/
https://www.xing.com/pages/3d-micromacag
https://de.linkedin.com/company/3d-micromac-ag
https://www.youtube.com/channel/UCI-HLfaix5_l9LYwSWzinJQ

Data Processing by Social Networks

We maintain publicly accessible profiles on social networks. The individual social networks we use are listed below.

Social networks such as Facebook, X, and others can generally analyze your user behavior extensively when you visit their website or a website containing integrated social media content, e.g., like buttons or advertising banners.

Visiting our social media profiles triggers numerous data processing operations relevant to data protection. In detail:

If you are logged into your social media account and visit one of our social media profiles, the social media platform operator may associate this visit with your user account.

Under certain circumstances, your personal data may also be collected if you are not logged in or do not have an account with the respective social media platform. In this case, data may be collected, for example, via cookies stored on your terminal device or by recording your IP address.

Using the data collected in this way, social media platform operators can create user profiles containing your preferences and interests. This enables interest-based advertising to be displayed to you both within and outside the respective social media platform.

If you have an account with the respective social network, interest-based advertising may be displayed on all devices on which you are or have been logged in.

Please also note that we cannot track all processing operations carried out on social media platforms. Depending on the provider, social media platform operators may carry out additional processing operations. Details can be found in the terms of use and Privacy Policies of the respective social media platforms.

Legal Basis

Our social media profiles are intended to ensure the broadest possible online presence. This constitutes a legitimate interest within the meaning of Art. 6(1)(f) GDPR.

The analytics processes initiated by the social networks may be based on different legal bases, which must be specified by the operators of the social networks, e.g., consent within the meaning of Art. 6(1)(a) GDPR.

Controller and Exercise of Rights

When you visit one of our social media profiles, e.g. Facebook, we and the operator of the social media platform are jointly responsible for the data processing operations triggered by this visit.

You can generally exercise your rights to access, rectification, erasure, restriction of processing, data portability and lodging a complaint both against us and against the operator of the respective social media platform, e.g. Facebook.

Please note that despite our joint responsibility with the operators of the social media platforms, we do not have full control over the data processing operations carried out by the platforms. The respective provider’s corporate policies largely determine our options.

Storage Period

We delete data collected directly by us via our social media profiles as soon as you request its deletion, withdraw your consent to storage, or the purpose for storing the data no longer applies.

Stored cookies remain on your terminal device until you delete them. Mandatory statutory provisions, particularly retention periods, remain unaffected.

We do not influence how long social network operators store your data for their own purposes. For details, please get in touch with the operators of the social networks directly, e.g. via their Privacy Policies listed below.

Your Rights

You have the right at any time to receive information free of charge about the origin, recipients and purpose of your stored personal data.

You also have the right to object, the right to data portability and the right to lodge a complaint with the competent supervisory authority.

Furthermore, you may request the rectification, blocking or erasure of your personal data and, under certain circumstances, restriction of the processing of your personal data.

Individual Social Networks

Facebook

We maintain a profile on Facebook. The provider of this service is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland (“Meta”). According to Meta, data collected is also transferred to the USA and other third countries.

We have entered into a joint processing agreement (Controller Addendum) with Meta. This agreement specifies which data processing operations Meta or we are responsible for when you visit our Facebook page. The agreement can be viewed at:
https://www.facebook.com/legal/terms/page_controller_addendum

You can adjust your advertising settings yourself in your user account. To do so, click the following link and log in:
https://www.facebook.com/settings?tab=ads

Data transfers to the USA are based on the European Commission’s Standard Contractual Clauses. Details can be found at:

https://www.facebook.com/legal/EU_data_transfer_addendum
https://de-de.facebook.com/help/566994660333381

Details can be found in Facebook’s Privacy Policy:
https://www.facebook.com/about/privacy/

The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards when data is processed in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information is available from the provider at:
https://www.dataprivacyframework.gov/participant/4452

X (formerly Twitter)

We use the short-message service X (formerly Twitter). The provider is its parent company X Corp., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA.

For individuals residing outside the USA, the entity responsible for data processing is Twitter International Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland.

You can adjust your X privacy settings yourself in your user account. To do so, click the following link and log in:
https://x.com/settings/account/personalization

Data transfers to the USA are based on the European Commission’s Standard Contractual Clauses. Details can be found at:
https://gdpr.x.com/en/controller-to-controller-transfers.html

Details can be found in the Privacy Policy of X (formerly Twitter):
https://x.com/de/privacy

Instagram

We maintain a profile on Instagram. The provider of this service is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.

Data transfers to the USA are based on the European Commission’s Standard Contractual Clauses. Details can be found at:

https://www.facebook.com/legal/EU_data_transfer_addendum
https://de-de.facebook.com/help/566994660333381

Details regarding the handling of your personal data can be found in Instagram’s Privacy Policy:
https://privacycenter.instagram.com/policy/

The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards when data is processed in the USA. Every company certified under the DPF undertakes to comply with these data protection standards.

Further information is available from the provider at:
https://www.dataprivacyframework.gov/participant/4452

XING

We maintain a profile on XING. The provider is New Work SE, Am Strandkai 1, 20457 Hamburg, Germany.

Details regarding the handling of your personal data can be found in XING’s Privacy Policy:
https://privacy.xing.com/de/datenschutzerklaerung

LinkedIn

We maintain a profile on LinkedIn. The provider is LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland. LinkedIn uses advertising cookies.

If you wish to disable LinkedIn advertising cookies, please use the following link:
https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out

Data transfers to the USA are based on the European Commission’s Standard Contractual Clauses. Details can be found at:

https://www.linkedin.com/legal/l/dpa
https://www.linkedin.com/legal/l/eu-sccs

Details regarding the handling of your personal data can be found in LinkedIn’s Privacy Policy:
https://www.linkedin.com/legal/privacy-policy

The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards when data is processed in the USA. Every company certified under the DPF undertakes to comply with these data protection standards.

Further information is available from the provider at:
https://www.dataprivacyframework.gov/participant/5448

YouTube

We maintain a profile on YouTube. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Details regarding the handling of your personal data can be found in YouTube’s Privacy Policy:
https://policies.google.com/privacy?hl=de

The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards when data is processed in the USA. Every company certified under the DPF undertakes to comply with these data protection standards.

Further information is available from the provider at:
https://www.dataprivacyframework.gov/participant/5780

Revision date: 05/2026