Home

Privacy information

Privacy information

Overview

We, Sapera GmbH, would like to use this website to draw attention to our services and offers.

The purpose of processing personal data on this website is primarily in the area of customer acquisition and marketing.

Furthermore, measuring usage-related metrics is necessary to enable the smooth provision and improvement of our services and to ensure the optimization and management of technical and financial resources. We want to offer you a pleasant, safe and trouble-free use of our services.

Our primary goals in collecting information are to provide and improve our Services, to administer your use of the Services, and to enable you to enjoy and easily navigate our Services.

Introduction

The protection of your personal data is very important for us. This privacy notice provides information about how your personal data is processed by us when you visit and use our Website sapera.com, you apply for a job with us or you want to be included in our freelancer pool.

Furthermore, this privacy notice contains general information about your rights in connection with the processing of your personal data.

Sapera GmbH processes your data in accordance with the data protection provisions of the German Federal Data Protection Act ("BDSG") in the version that came into force on May 25, 2018, and the Regulation (EU) 2016/679 (hereinafter "GDPR").

If you have any questions or concerns after reading this privacy information, please contact our data protection team at dst@sapera.com.

Responsibilities and contact details

The data controller, i.e., the person responsible for processing your personal data is:

Sapera GmbH

Haus Cumberland

Kurfürstendamm 194

10707 Berlin, Germany

Represented by the managing director: Christopher Wynes

Phone: +49 30 22 18 36 80

Email: info@sapera.com

Website: sapera.com

Our data protection officer is available by email at: ‍privacy@sapera.com.

Processing of personal data

Depending on the reason for which you interact with us, we process different types of personal data.

Online Services

When you use this website we process different types of your personal data for different reasons.

Processing purposes

Delivering our website to your computer

  • ensuring a smooth connection setup to the website

  • deliver the content of our website properly and in a visually appealing design

Collection of contact data of interested parties

  • To send you further information about our services

    • via Email eg. after you used our Contact form

    • via Mailing list or newsletter

    • via Phone contact

  • To contact us to discuss your individual needs

  • For the initiation of contracts

Collecting usage data about the way you interact with our service

  • ensuring easy use of our website

  • optimise the content of our website

  • ensure the long-term viability of our information technology systems and website technology

Collecting error reports and data on crashes

  • evaluation of system security and stability

  • clarification of any improper page access (DoS/DDoS attacks, etc.)

  • when necessary, provide law enforcement authorities with the information required for criminal prosecution in case of a cyber attack

  • as well as further administrative purposes, e.g. cost optimisation

Legal bases for processing

Visit to the website

The legal basis for the processing of personal data is Article 6 (1), sentence 1, lit. f, GDPR, our legitimate interest.

We have a legitimate interest in technically enabling you to access and use our website. We also need to ensure that misuse is prevented and that safe use is guaranteed for our visitors.

Sending the contact form

The legal basis is on the one hand Article 6 (1), sentence 1, lit. b, GDPR, as the contact serves to initiate a contract, furthermore Article 6 (1), sentence 1, lit. a, GDPR, as you give your consent to be contacted by us by sending the contact form.

You can, of course, revoke this consent at any time by informing us of this using the contact details provided.

Evaluation of the use

The legal basis for processing personal data to evaluate the use of this website is Article 6 (1), sentence 1, lit. a, GDPR. as we ask your for your consent for web analytics when you come to our website.

Furthermore, we do have a legitimate interest in the usage of our online services in the sense of Article 6 (1), sentence 1, lit. f, GDPR because only through usage analysis it's possible for us to evaluate how effectively we use our marketing budget. Additionally, it is important for us to know how the website is used so that we can improve and optimize it.

Data storage and deletion

We do not keep your personal information for longer than necessary for the purposes for which we collected it. In some cases, it might be possible that we keep your information for a longer period for historical, statistical or scientific purposes with the appropriate safeguards in place.

Applicants

In accordance with the requirements of Articles 13, 14 and 21 of the General Data Protection Regulation (GDPR), we hereby inform you about the processing of personal data provided by you as part of the application process and, if applicable, collected by us, and your rights in this regard. To ensure that you are fully informed about the processing of your personal data as part of the application process, please take note of the information below.

Purposes of processing and types of personal data

We process the data you have sent us in connection with your application in order to assess your suitability for the position (or other open positions in our companies, if applicable) and to carry out the application process.

Legal bases for processing

The primary legal basis for processing your personal data in this application procedure is Section 26, BDSG. According to this, the processing of data required in connection with the decision on the establishment of an employment relationship is permissible.

Should the data be required for legal prosecution after completion of the application procedure, if applicable, data processing may be carried out on the basis of the requirements of Art. 6 GDPR, in particular to safeguard legitimate interests pursuant to Article 6 (1), sentence 1, lit. f, GDPR. Our interest then consists in the assertion or defense of claims.

Data storage and deletion

Data of applicants will be deleted after 6 months in case of rejection.

In the event that you have agreed to further storage of your personal data, we will transfer your data to our applicant pool. There, the data will be deleted after two years.

If you have been awarded a position during the application process, the data will be transferred from the applicant data system to our HR information system.

Recipient of the data

We use a specialized software provider for the application process. This provider acts as a service provider for us and may also become aware of your personal data in connection with the maintenance and servicing of the systems. We have concluded a so-called order processing agreement with this provider, which ensures that the data processing is carried out in a permissible manner.

Your applicant data will be viewed by the HR department after receipt of your application. Suitable applications are then forwarded internally to the department managers for the respective open position. The further procedure is then coordinated. As a matter of principle, only those persons in the company have access to your data who require it for the proper conduct of our application process.

Freelancer Pool

For our projects, we are looking for project-related freelancers and offer them to be included in our "Freelancer Pool".

Purposes of processing and types of personal data

The application documents for the Freelancer Pool will be processed solely in the context of future project inquiries.

We process the data necessary to check a suitability for project participation ("portfolio", work samples, CV, website) as well as contact data (name, email, phone number).

Legal bases for processing

The processing is based on your consent within the meaning of Article 6 (1), sentence 1, lit. b. and Art. 7 GDPR. Consent for inclusion in the freelancer pool is voluntary and no claim for actual employment is derived from it. Furthermore, you can revoke your consent at any time for the future, as well as declare your objection within the meaning of Art. 21 GDPR.

Data storage and deletion

After 14 months, we will contact you to inquire whether the storage in the freelancer pool should be maintained. If there is no active consent within one month, we will delete all personal data.

Newsletter

If you would like to subscribe to the newsletter offered on our website, we require an e-mail address from you as well as information that allows us to verify that you are the owner of the e-mail address provided and that you agree to receive the newsletter ("double-opt-in"). Further data will not be collected or only on a voluntary basis.

Contents of the newsletter: The latest trends and Insights, Inspiration, Best practices, Information about us, our services, promotions and offers.

We would like to explicitly point out that we use the provider "Mailchimp" from the USA as a service provider. This involves the processing of personal data in the USA. If you do not agree with this, we would kindly ask you not to subscribe to our newsletter.

Analysis and performance measurement

The newsletters contain a so-called "web beacon", i.e. a pixel-sized file that is retrieved from our server or from the server of our dispatch service provider ("Mailchimp") when the newsletter is opened. As part of this retrieval, technical information, such as information about the browser and your system, as well as your IP address and the time of retrieval, are initially collected.

This information is used to technically improve our newsletter based on the technical data or the target groups and their reading behaviour based on their retrieval locations (which can be determined using the IP address) or access times. This analysis also includes determining whether the newsletters are opened, when they are opened and which links are clicked. For technical reasons, this information can indeed be assigned to individual newsletter recipients. However, it is neither our intention nor that of the dispatch service provider to observe individual users. Rather, the evaluations serve us to recognize the reading habits of our users and to adapt our content to them or to send different content according to the interests of our users.

The evaluation of the newsletter and the measurement of success are carried out, subject to the express consent of the users, on the basis of our legitimate interests for the purpose of using a user-friendly as well as secure newsletter system, which serves both our business interests and meets the expectations of the users.

Unfortunately, a separate revocation of the performance measurement is not possible, in which case the entire newsletter subscription must be cancelled, or it must be contradicted.

Legal bases for processing

Newsletters are sent on the basis of the recipients' consent or, if consent is not required, on the basis of our legitimate interests in direct marketing, if and to the extent that this is permitted by law, e.g. in the case of existing customer advertising. Insofar as we commission a service provider to send e-mails, this is done on the basis of our legitimate interests. The registration process is recorded on the basis of our legitimate interests to prove that it was carried out in accordance with the law.

Revocation, Data storage and deletion

You can revoke the consent granted for the storage of the data, the e-mail address as well as their use for sending the newsletter at any time, for example via the "unsubscribe" link in the newsletter. The legality of the data processing operations already carried out remains unaffected by the revocation.

The data you provide us for the purpose of subscribing to the newsletter will be stored by us until you unsubscribe from the newsletter and deleted after you unsubscribe from the newsletter. Data stored by us for other purposes (e.g., e-mail addresses for the member area) remain unaffected by this. You can also revoke the further sending of newsletters by sending an e-mail to privacy@sapera.com.

Transfer of personal data to other companies and countries

To deliver the experience we want you to have, we rely on the services of special providers that are experts in their dedicated area.

That means that data is transferred abroad, including to countries outside the European Union or the European Economic Area. An adequate level of data protection is ensured by either working with companies that are from countries with an adequate level of data protection as required by Article 45 (1), GDPR or by using the EU standard contractual clauses laid down by the EU Commission within the meaning of Article 46 (2), lit. c, GDPR.

List of sub-processors

Analytics

The services contained in this section enable the Owner to monitor and analyze web traffic and can be used to keep track of User behavior.

Google Analytics with anonymized IP (Google Ireland Limited)

Google Analytics is a web analysis service provided by Google Ireland Limited (“Google”). Google utilizes the Data collected to track and examine the use of sapera.com, to prepare reports on its activities and share them with other Google services. Google may use the Data collected to contextualize and personalize the ads of its own advertising network. This integration of Google Analytics anonymizes your IP address. It works by shortening Users' IP addresses within member states of the European Union or in other contracting states to the Agreement on the European Economic Area. Only in exceptional cases will the complete IP address be sent to a Google server and shortened within the US.

Personal Data processed: Cookies; Usage Data.

Place of processing: Ireland – Privacy Policy – Opt Out.

Matomo (sapera.com)

Matomo is an analytics software used by sapera.com to analyze data directly without the help of third parties.

Personal Data processed: Tracker; Usage Data.

Facebook Ads conversion tracking (Facebook pixel) (Facebook Ireland Ltd)

Facebook Ads conversion tracking (Facebook pixel) is an analytics service provided by Facebook Ireland Ltd that connects data from the Facebook advertising network with actions performed on sapera.com. The Facebook pixel tracks conversions that can be attributed to ads on Facebook, Instagram and Audience Network.

Personal Data processed: Tracker; Usage Data.

Place of processing: Ireland – Privacy Policy.

Google Analytics Demographics and Interests reports (Google Ireland Limited)

Google Analytics Demographics and Interests reports is a Google Advertising Reporting feature that makes available demographic and interests Data inside Google Analytics for sapera.com (demographics means age and gender Data).

Users can opt out of Google's use of cookies by visiting Google's Ads Settings.

Personal Data processed: Tracker; unique device identifiers for advertising (Google Advertiser ID or IDFA, for example).

Place of processing: Ireland – Privacy Policy – Opt Out.

Google Analytics Advertising Reporting Features (Google Ireland Limited)

Google Analytics on sapera.com has Advertising Reporting Features activated, which collects additional information from the DoubleClick cookie (web activity) and from device advertising IDs (app activity). It allows the Owner to analyze specific behavior and interests Data (traffic Data and Users' ads interaction Data) and, if enabled, demographic Data (information about the age and gender).

Users can opt out of Google's use of cookies by visiting Google's Ads Settings.

Personal Data processed: Tracker; unique device identifiers for advertising (Google Advertiser ID or IDFA, for example); various types of Data as specified in the privacy policy of the service.

Place of processing: Ireland – Privacy Policy – Opt Out.

Google Ads conversion tracking (Google LLC)

Google Ads conversion tracking is an analytics service provided by Google LLC that connects data from the Google Ads advertising network with actions performed on sapera.com.

Personal Data processed: Tracker; Usage Data.

Place of processing: United States – Privacy Policy.

Heat mapping and session recording

Heat mapping services are used to display the areas of sapera.com that Users interact with most frequently. This shows where the points of interest are. These services make it possible to monitor and analyze web traffic and keep track of User behavior. Some of these services may record sessions and make them available for later visual playback.

Hosting and backend infrastructure

This type of service has the purpose of hosting Data and files that enable sapera.com to run and be distributed as well as to provide a ready-made infrastructure to run specific features or parts of sapera.com.

Some services among those listed below, if any, may work through geographically distributed servers, making it difficult to determine the actual location where the Personal Data are stored.

Contentful (Contentful GmbH)

Contentful is a hosting and backend service provided by Contentful GmbH.

Personal Data processed: various types of Data.

Place of processing: Germany – Privacy Policy.

Amazon Web Services (AWS) (Amazon Web Services, Inc.)

Amazon Web Services (AWS) is a hosting and backend service provided by Amazon Web Services, Inc.

Personal Data processed: various types of Data as specified in the privacy policy of the service.

Place of processing: Germany – Privacy Policy.

Remarketing and behavioral targeting

This type of service allows sapera.com and its partners to inform, optimize and serve advertising based on past use of sapera.com by the User. This activity is facilitated by tracking Usage Data and by using Trackers to collect information which is then transferred to the partners that manage the remarketing and behavioral targeting activity. Some services offer a remarketing option based on email address lists. In addition to any opt-out feature provided by any of the services below, Users may opt out by visiting the Network Advertising Initiative opt-out page.

Users may also opt-out of certain advertising features through applicable device settings, such as the device advertising settings for mobile phones or ads settings in general.

LinkedIn Website Retargeting (LinkedIn Corporation)

LinkedIn Website Retargeting is a remarketing and behavioral targeting service provided by LinkedIn Corporation that connects the activity of sapera.com with the LinkedIn advertising network.

Personal Data processed: Cookies; Usage Data.

Place of processing: United States – Privacy Policy – Opt Out.

Google Ad Manager Audience Extension (Google Ireland Limited)

Google Ad Manager Audience Extension is a remarketing and behavioral targeting service provided by Google Ireland Limited that tracks the visitors of sapera.com and allows selected advertising partners to display targeted ads across the web to them.

Personal Data processed: Tracker; Usage Data.

Place of processing: Ireland – Privacy Policy – Opt Out.

Google Ads Remarketing (Google Ireland Limited)

Google Ads Remarketing is a remarketing and behavioral targeting service provided by Google Ireland Limited that connects the activity of sapera.com with the Google Ads advertising network and the DoubleClick Cookie.

Users can opt out of Google's use of cookies for ads personalization by visiting Google's Ads Settings.

Personal Data processed: Tracker; Usage Data.

Place of processing: Ireland – Privacy Policy – Opt Out.

Managing contacts and sending messages

This type of service makes it possible to manage a database of email contacts, phone contacts or any other contact information to communicate with the User. These services may also collect data concerning the date and time when the message was viewed by the User, as well as when the User interacted with it, such as by clicking on links included in the message.

Mailchimp (The Rocket Science Group LLC)

Mailchimp is an email address management and message sending service provided by The Rocket Science Group LLC.

Personal Data processed: email address.

Place of processing: United States – Privacy Policy.

Mandrill (The Rocket Science Group LLC)

Mandrill is an email address management and message sending service provided by The Rocket Science Group, LLC.

Personal Data processed: company name; email address; first name; last name; phone number.

Place of processing: United States – Privacy Policy.

Tag Management

This type of service helps the Owner to manage the tags or scripts needed on sapera.com in a centralized fashion. This results in the Users' Data flowing through these services, potentially resulting in the retention of this Data.

Matomo Tag Manager (sapera.com)

Matomo Tag Manager is a tag management service hostet by sapera.com.

Personal Data processed: Usage Data.

Google Tag Manager (Google Ireland Limited)

Google Tag Manager is a tag management service provided by Google Ireland Limited.

Personal Data processed: Usage Data.

Place of processing: Ireland – Privacy Policy.

Handling productivity related activity

This type of service helps the Owner to manage tasks, collaboration and, in general, activities related to productivity. In using this type of service, Data of Users will be processed and may be retained, depending on the purpose of the activity in question. These services may be integrated with a wide range of third-party services disclosed within this privacy policy to enable the Owner to import or export Data needed for the relative activity.

G Suite

G Suite is an integrated suite of cloud-based productivity, collaboration and storage services provided by Google LLC or by Google Ireland Limited, depending on the location sapera.com is accessed from. Gmail or other G Suite services are not scanned by Google for advertising purposes. In addition, Google does not collect or use data inside these services for advertising purposes in any other way.

Personal Data processed: Data communicated while using the service.

Place of processing: United States – Privacy Policy; Ireland – Privacy Policy.

Gmail (Google Ireland Limited)

Gmail is a service that manages email communication provided by Google Ireland Limited. Such email communication is not scanned by Google for advertising purposes. In addition, Google does not collect or use data inside this service for advertising purposes in any other way.

Personal Data processed: Data communicated while using the service.

Place of processing: Ireland – Privacy Policy.

Google Docs (Google Ireland Limited)

Google Docs is an online text-editing and collaboration service provided by Google Ireland Limited.

Personal Data processed: email address.

Place of processing: Ireland – Privacy Policy.

Asana (Asana, Inc.)

Asana is a project management service provided by Asana, Inc.

Personal Data processed: email address; first name; last name; screenshots; Usage Data.

Place of processing: United States – Privacy Policy.

Google Sheets (Google Ireland Limited)

Google Sheets is an online spreadsheet and collaboration service provided by Google Ireland Limited.

Personal Data processed: Data communicated while using the service; email address.

Place of processing: Ireland – Privacy Policy.

Advertising

This type of service allows User Data to be utilized for advertising communication purposes. These communications are displayed in the form of banners and other advertisements on sapera.com, possibly based on User interests. This does not mean that all Personal Data are used for this purpose. Information and conditions of use are shown below. Some of the services listed below may use Trackers to identify Users or they may use the behavioral retargeting technique, i.e. displaying ads tailored to the User’s interests and behavior, including those detected outside sapera.com. For more information, please check the privacy policies of the relevant services. In addition to any opt-out feature offered by any of the services below, Users may opt out by visiting the Network Advertising Initiative opt-out page.

Users may also opt-out of certain advertising features through applicable device settings, such as the device advertising settings for mobile phones or ads settings in general.

Google Ad Manager (Google Ireland Limited)

Google Ad Manager is an advertising service provided by Google Ireland Limited that allows the Owner to run advertising campaigns in conjunction with external advertising networks that the Owner, unless otherwise specified in this document, has no direct relationship with. In order to opt out from being tracked by various advertising networks, Users may make use of Youronlinechoices. In order to understand Google's use of data, consult Google's partner policy. This service uses the “DoubleClick” Cookie, which tracks use of sapera.com and User behavior concerning ads, products and services offered.  

Users may decide to disable all the DoubleClick Cookies by going to: Google Ad Settings.

Personal Data processed: Tracker; Usage Data.

Place of processing: Ireland – Privacy Policy.

Google Ads Similar audiences (Google Ireland Limited)

Similar audiences is an advertising and behavioral targeting service provided by Google Ireland Limited that uses Data from Google Ads Remarketing in order to display ads to Users with similar behavior to Users who are already on the remarketing list due to their past use of sapera.com. On the basis of this Data, personalized ads will be shown to Users suggested by Google Ads Similar audiences.

Users who don't want to be included in Similar audiences can opt out and disable the use of advertising cookies by going to: Google Ad Settings.

Personal Data processed: Tracker; Usage Data.

Place of processing: Ireland – Privacy Policy – Opt Out.

Infrastructure monitoring

This type of service allows sapera.com to monitor the use and behavior of its components so its performance, operation, maintenance and troubleshooting can be improved. Which Personal Data are processed depends on the characteristics and mode of implementation of these services, whose function is to filter the activities of sapera.com.

Sentry (Functional Software, Inc. )

Sentry is a monitoring service provided by Functional Software, Inc. .

Personal Data processed: various types of Data as specified in the privacy policy of the service.

Place of processing: United States – Privacy Policy.

Skylight (Tilde Inc.)

Skylight is a monitoring service provided by Tilde Inc.

Personal Data processed: various types of Data as specified in the privacy policy of the service.

Place of processing: United States – Privacy Policy.

Your legal rights in relation to personal data

If you are in the European Economic Area (EEA) you have the following rights:

  • Access:

    You have the right to request a copy of the personal data that we hold about you. There are exceptions to this right, so that access may be denied if, for example, making the information available to you would reveal personal data about another person, or if we are legally prevented from disclosing such information. You are entitled to see the personal data held about you. If you wish to do this, please contact us using the contact details provided below.

  • Objecting: 

    In certain circumstances, you also have the right to object to the processing of your personal data and to ask us to block, erase and restrict your personal data. If you would like us to stop using your personal data, please contact us via Email.

  • Portability:

    You have the right to request that some of your personal data is provided to you, or to another data controller, in a commonly used, machine-readable format.

  • Deletion: 

    You have the right to request that we delete personal data that we process about you unless we are required to retain such data in order to comply with a legal obligation or to establish, exercise or defend legal claims.

  • Withdrawing Consent:

    If you have consented to our processing of your Personal Data, you have the right to withdraw your consent at any time, free of charge. This includes cases where you wish to opt-out from marketing messages that you receive from us.

  • Complaints:

    If you believe that your data protection rights may have been breached, you have the right to lodge a complaint with the applicable supervisory authority, in our case the State Representative for Data Protection of the State of Berlin, or to seek a remedy through the courts.

You can exercise the above rights, where applicable by contacting the data protection team. We will require you to provide satisfactory proof of your identity in order to ensure that your rights are respected and protected. This is to ensure that your personal data is disclosed only to you.

Further business

Protecting your personal information

Sapera GmbH is committed to protecting the security of your personal information and we take all reasonable precautions to protect it from unauthorised access, modification or disclosure. Your personal information is stored on secure servers that have SSL Certificates issued by leading certificate authorities, and all data transferred between you and the service is encrypted.

Automated decision-making

We do not use automated decision-making without human intervention, including profiling, in a way that produces legal effects concerning you or otherwise significantly affects you.

Changes to this Privacy Notice

We may update our Privacy Information from time to time in order to reflect any changes to the way in which we process your personal data or changing legal requirements. We will notify you of any changes by posting the new Privacy Notice on this page and update the "effective date" at the top of this Privacy Notice.

The first version of this Privacy Notice was issued in October 2020. Please check back frequently to see any updates or changes.

Latest update: March 23, 2021

linkedin
instagram
medium

You like to read all about new trends and industry insights first?

Subscribe now and don’t miss a thing later.

Input not valid

© 2021 Sapera GmbH

linkedin
instagram
medium