Privacy policy of the SENN Gruppe under GDPR. Data controller, data categories, purposes, legal bases, retention, data-subject rights, cookie notice.
Skip to main content

1. Controller and Data Protection Officer

The controller responsible for data processing on this website within the meaning of the GDPR is:

Senn Beteiligungs GmbH (SENN Gruppe)
Phone: +43 5373 76020
E-mail: info@senn-gruppe.com

Full company details (commercial register number, registered office, authorised representatives) can be found in our Legal Notice.

We have appointed a Data Protection Officer:

Stefan Müller
Phone: +43 5373 67020
E-mail: datenschutz@senn-gruppe.com

Please use this address for all questions regarding the processing of your personal data and for exercising your rights.

2. General information

Protecting your personal data is of particular importance to us. We process your data exclusively on the basis of statutory provisions (GDPR, Austrian Data Protection Act, Telecommunications Act 2021). This privacy policy informs you about the key aspects of data processing on our website.

Personal data is any information that can be used to identify you personally. Please note that data transmission over the internet (e.g. communication by e-mail) may have security gaps. Complete protection of data against access by third parties is not possible.

2.1 Legal bases at a glance

Where this policy refers to legal bases, the following applies:

ProvisionMeaning
Art. 6(1)(a) GDPRYou have consented to the processing (e.g. via our cookie banner). You may withdraw consent at any time with effect for the future.
Art. 6(1)(b) GDPRProcessing is necessary for the performance of a contract or pre-contractual measures (e.g. order processing in the online shop).
Art. 6(1)(c) GDPRProcessing is necessary to comply with a legal obligation (e.g. commercial and tax retention obligations).
Art. 6(1)(f) GDPRProcessing is based on our legitimate interest; the specific interest is stated with each processing activity.
§ 165(3) Austrian Telecommunications Act 2021Storing information on, or accessing information from, your device (cookies, local storage, fingerprinting) — permitted only with consent, except where strictly technically necessary.

3. Your rights

You are generally entitled to the following rights:

  • Access (Art. 15 GDPR) — whether and which personal data we process about you, and a copy of that data.
  • Rectification (Art. 16 GDPR) — correction or completion of inaccurate or incomplete data.
  • Erasure (Art. 17 GDPR) — unless statutory retention obligations apply.
  • Restriction of processing (Art. 18 GDPR).
  • Data portability (Art. 20 GDPR) — in a structured, commonly used, machine-readable format.
  • Objection (Art. 21 GDPR) — against processing based on Art. 6(1)(f) GDPR, in particular against direct marketing.
  • Withdrawal of consent (Art. 7(3) GDPR) — at any time with effect for the future. The lawfulness of processing carried out before withdrawal remains unaffected.
  • Information about recipients — the identity of third parties to whom your data is transferred.

An informal message to datenschutz@senn-gruppe.com is sufficient.

Right to lodge a complaint: If you believe that the processing of your personal data infringes applicable data protection law, you may lodge a complaint with the supervisory authority. In Austria this is the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, dsb@dsb.gv.at.

Objection to promotional e-mails: We hereby object to the use of contact data published under our legal notice obligations for sending unsolicited advertising. We expressly reserve the right to take legal action in the event of unsolicited advertising being sent.

4. Hosting, server log files and delivery of the website

4.1 Hosting

This website runs on servers operated by us or on our behalf within the European Economic Area. When you access the website, information is automatically recorded in so-called server log files, which your browser transmits automatically:

  • browser type and version
  • operating system used
  • referrer URL
  • host name of the accessing computer
  • time of the server request
  • IP address

This data is not merged with other data sources.

Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in providing the website free of technical errors, developing it further, and detecting, preventing and investigating attacks. For order processes, Art. 6(1)(b) GDPR applies in addition.

Retention period: Server log files are generally stored for three months. Longer storage occurs only where necessary to investigate detected attacks.

4.2 Content Delivery Network — KeyCDN

We use the content delivery network KeyCDN to deliver static content (images, stylesheets, scripts, fonts) quickly and reliably. The provider is:

proinity LLC (d/b/a KeyCDN), Reichenauweg 1, 8272 Ermatingen, Switzerland

When you access our pages, these files are loaded from the CDN's servers. In doing so, your IP address is transmitted to KeyCDN and processed technically, as are details such as user agent and referrer. KeyCDN anonymises client IP addresses in the delivery logs it provides.

Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, performant and resilient provision of our online offering.

Processing agreement / third country: KeyCDN acts as a processor under Art. 28 GDPR. Switzerland is covered by an adequacy decision of the European Commission, so no additional transfer instrument is required.

4.3 Fonts

The fonts used on this website (Inter) are delivered locally from our own servers or our CDN. No connection to Google servers (Google Fonts) takes place. No cookies are set in this context.

4.4 SSL/TLS encryption

For security reasons and to protect the transmission of confidential content, this site uses SSL/TLS encryption. You can recognise an encrypted connection by the https:// prefix in your browser's address bar and the lock symbol.

5. Cookies and consent management

5.1 What cookies are

Cookies are small text files stored on your device. They cause no damage and contain no viruses. Most of the cookies we use are session cookies, which are automatically deleted at the end of your visit.

Cookies that are strictly necessary to carry out the electronic communication process or to provide functions you have expressly requested (e.g. the shopping cart) are stored on the basis of Art. 6(1)(f) GDPR. All other cookies and comparable technologies are used only with your consent (Art. 6(1)(a) GDPR in conjunction with § 165(3) TKG 2021).

5.2 Consent management

We use the consent management solution CookieConsent (version 3). It is delivered from our own servers or our CDN; no data is transmitted to third parties. Your selection is stored in a cookie (cc_cookie) so that the banner is not shown again on every page view.

The banner has two categories:

  • Strictly necessary — technically required functions (session, form protection, shopping cart). Not deselectable, as the website cannot function without them.
  • Analytics — the cookie-free reach measurement with Matomo and Leadinfo (sections 6.1 and 6.2). This category is active by default, because it rests on our legitimate interest and stores no information on your device. Choosing “Reject” exercises your right to object under Art. 21 GDPR; the analysis then stops immediately.

You can call up your settings at any time via the “Cookie settings” link in the site footer and change or withdraw them with effect for the future. You can also configure your browser to inform you about cookies being set, to allow cookies only in individual cases, or to exclude them generally. Disabling cookies may limit the functionality of this website.

5.3 Cookie overview

The table below lists the cookies that may be set on this website. Cookies from Snipcart, Stripe and PayPal are set only once you open the cart or begin checkout.

Name Provider Purpose Lifetime Type Category
cc_cookie Website operator Stores your cookie banner selection (consent status per category). 6 months HTTP cookie Necessary
kirby_session Website operator Session cookie during your visit (form processing, protection against duplicate submission). Session HTTP cookie Necessary
csrf / form token Website operator Protection against cross-site request forgery on forms. Session HTTP cookie Necessary
im_youtube, im_vimeo, im_googlemaps Website operator Stores whether you have released the respective embedded content for loading. 1 year HTTP cookie Necessary (consent record)
Snipcart cookies (snipcart-*, session) Snipcart Inc. Cart and checkout functionality; set only once you open the cart or checkout. Session to 30 days HTTP cookie / local storage Necessary (shop)
Stripe cookies (__stripe_mid, __stripe_sid) Stripe Payments Europe Ltd. Fraud prevention and payment processing; only during checkout. 1 day to 1 year HTTP cookie Necessary (payment)
PayPal cookies PayPal (Europe) S.à r.l. et Cie, S.C.A. Payment processing and fraud prevention; only during checkout. Session to 3 years HTTP cookie Necessary (payment)

Our web analytics with Matomo (section 6.1) and the company-level visitor identification with Leadinfo (section 6.2) operate without cookies — no cookies are set and no information is stored on or read from your device.

6. Web analytics and reach measurement

6.1 Matomo (self-hosted, cookie-free)

This website uses the open-source web analytics service Matomo. We operate Matomo on our own servers under the domain ip.senn-gruppe.com. No transmission to third parties and no transfer to third countries takes place.

Our Matomo installation is configured so that it

  • sets no cookies (disableCookies) and neither stores nor reads information on your device,
  • anonymises your IP address before storage (truncation),
  • respects your browser's “Do Not Track” setting.

The following is recorded in particular: pages visited, time and duration of the visit, referrer, browser and device type used, and clicks on telephone and e-mail links (to measure how often contact options are used).

Purpose: Improving the quality of our website and its content.

Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in the statistical evaluation of user behaviour to optimise our offering. Since no information is stored on or read from your device, consent under § 165(3) TKG 2021 is not required.

Objection: You may object to the analysis at any time — most simply via the “Reject” button in the notice banner, or later at any point via the “Cookie settings” link in the footer. The objection takes effect immediately and is remembered for future visits. Alternatively by e-mail to datenschutz@senn-gruppe.com, or by enabling the “Do Not Track” function in your browser, which we also respect.

Retention period: Raw data is deleted after 14 months; aggregated, non-personal reports are retained beyond that.

6.2 Leadinfo (B2B company-level visitor identification) — cookie-free

We use the service Leadinfo on this website. The provider is:

Leadinfo B.V., Rivium Quadrant 141, 2909 LC Capelle aan den IJssel, Netherlands
Chamber of Commerce no. 78116643 · privacy@leadinfo.com · part of the team.blue Group

Leadinfo is a B2B service that uses the IP address of the website visit to determine which company has visited our website, and provides us with this information together with the visit history (pages viewed, time on site, referrer). To do so, Leadinfo matches the IP address against its own company database built from publicly available sources, which may also contain names, contact details and job titles of employees and directors. If Leadinfo identifies an IP address as belonging to a private connection, it is discarded according to the provider.

The following is processed: IP address, the approximate location derived from it, and the pages you visit together with the time of the visit.

We use Leadinfo in cookie-free mode. No cookies are set and no information is stored on or read from your device. The match is performed exclusively server-side on the basis of the IP address. There is therefore no access to your terminal equipment within the meaning of § 165(3) TKG 2021, which is why no consent is required for this.

Purpose: Identifying business prospects, assessing the reach of our B2B communication and approaching potential business partners.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest). Our legitimate interest lies in identifying which companies are interested in our products and services, in order to target our B2B offering and customer outreach. Processing is limited to company-level information; identification of individual natural persons does not take place and is not necessary for the service. If Leadinfo identifies an IP address as a private connection, it is discarded.

Your right to object: You may object to this processing at any time under Art. 21 GDPR. Click “Reject” in the notice banner, or open the “Cookie settings” link in the footer at any later point and switch off the “Analytics” category. The analysis then stops immediately and stays off for subsequent visits. Alternatively, an informal e-mail to datenschutz@senn-gruppe.com is sufficient. Leadinfo also offers its own opt-out at https://www.leadinfo.com/en/opt-out/.

Allocation of roles: For the analysis of visits to our website, Leadinfo acts as a processor on our behalf (Art. 28 GDPR). For building and maintaining its own company database, Leadinfo is an independent controller; in that respect, Leadinfo's own privacy policy applies: https://www.leadinfo.com/en/privacy-policy/

Storage location / third country: Leadinfo is established in the Netherlands (EU). Processing takes place on servers in Ireland (hosting: Amazon Web Services EMEA SARL, Luxembourg), with which Leadinfo has concluded a data processing agreement including standard contractual clauses. No transfer to the USA takes place. Leadinfo is certified to ISO/IEC 27001.

6.3 Google Analytics 4

Not currently in use. Google Analytics is not integrated on this website. We inform you here in advance of the conditions under which it would be used. Before activation we would add a separate consent category, switched off by default, to the cookie banner; the service would be loaded only after your explicit consent.

The provider would be Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (for processing in the USA: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA).

Google Analytics uses cookies and similar technologies that enable an analysis of your use of the website. The following would be processed in particular: pseudonymous user and event IDs, truncated IP address, pages visited and interactions, time and duration, referrer, approximate location (country/region), device, operating system and browser. IP anonymisation would be activated; your IP address would be truncated within the EU/EEA before being transmitted to Google.

Legal basis: Art. 6(1)(a) GDPR (consent) in conjunction with § 165(3) TKG 2021. Withdrawal at any time via the cookie settings in the footer.

Processing agreement and third country: A data processing agreement with Google would be in place (Google Ads Data Processing Terms). Personal data may be transferred to Google LLC in the USA. Google LLC is certified under the EU-U.S. Data Privacy Framework; by decision of 10 July 2023, the European Commission determined an adequate level of data protection for certified companies. In addition, Google has concluded standard contractual clauses pursuant to Art. 46(2)(c) GDPR.

Retention period: Data collected at user and event level would be automatically deleted after 14 months.

Further information: https://policies.google.com/privacy · Browser opt-out add-on: https://tools.google.com/dlpage/gaoptout

6.4 Google Tag Manager

Not currently in use. Should the Google Tag Manager provided by Google Ireland Limited be used in future for the technical management of analytics and marketing tags, the following applies: the Tag Manager itself collects no personal data and sets no cookies; it serves solely to deliver and control other tags. However, loading the Tag Manager technically transmits your IP address to Google. It would be loaded only once you have consented to at least one of the categories it controls; the tags it triggers respect the selection you made in the cookie banner.

Legal basis: Art. 6(1)(a) GDPR (consent).

7. Advertising and conversion measurement

Not currently in use. No advertising or conversion tracking services are integrated on this website. The following sections describe in advance the conditions under which they would be used. In every case this would require a separate consent category “Marketing” in the cookie banner, switched off by default.

7.1 Google Ads with conversion tracking

The provider would be Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

If you reach our website by clicking on a Google ad we have placed, Google stores a cookie on your device. If you subsequently visit certain pages of our website (e.g. an order confirmation or a submitted contact form), Google and we can recognise that you previously clicked on one of our ads. We receive statistics on the total number of users who clicked on our ads and the pages subsequently visited. This does not enable us to identify you personally. Conversion cookies expire after 30 to 90 days.

Purpose: Measuring and optimising the cost-effectiveness of our online advertising.
Legal basis: Art. 6(1)(a) GDPR (consent) in conjunction with § 165(3) TKG 2021.
Third country: as described in section 6.3 (EU-U.S. Data Privacy Framework, supplemented by standard contractual clauses).

Further information and opt-out options: https://policies.google.com/technologies/ads · https://adssettings.google.com

7.2 Google Remarketing / “Similar Audiences”

Google's remarketing function allows us to display interest-based advertising for our products to you on third-party websites that also participate in the Google advertising network. For this purpose, Google stores a cookie with an identifier on your device that records your visit and use of our online offering in pseudonymous form.

Through so-called cross-device marketing, Google may under certain circumstances track your usage behaviour across multiple devices, provided you have consented to linking your browsing history with your Google account.

Legal basis: Art. 6(1)(a) GDPR (consent).
Deactivation: via the cookie settings in the footer, via https://adssettings.google.com/authenticated, and via https://www.youronlinechoices.com or https://optout.networkadvertising.org.

8. Online shop, order processing and payment

8.1 Cart and checkout system: Snipcart

Our online shop is technically operated using Snipcart. The provider is Snipcart Inc., Québec, Canada.

The Snipcart script is not loaded when a page is merely viewed. It is loaded only once you actively open the cart or add an item to it. Until then, no connection to Snipcart takes place.

As soon as you begin the ordering process, Snipcart processes the following on our behalf:

  • first and last name
  • billing and delivery address
  • e-mail address and telephone number
  • cart contents, order value, currency, shipping method
  • order and payment status
  • IP address, browser and device data, and timestamps (fraud prevention)

Purpose: Carrying out the ordering process, contract performance and fraud prevention.

Legal basis: Art. 6(1)(b) GDPR (contract performance); for fraud prevention additionally Art. 6(1)(f) GDPR. For commercial and tax retention: Art. 6(1)(c) GDPR.

Processing agreement: Snipcart acts as a processor on the basis of a Data Processing Addendum (available at https://cdn.snipcart.com/legal/dpa.pdf). Snipcart may engage sub-processors and informs us of changes.

Third-country transfer: Snipcart is established in Canada. For Canadian companies subject to PIPEDA, an adequacy decision of the European Commission exists (Decision 2002/2/EC), on which the transfer is based. Where sub-processors in further third countries are engaged, transfers are based on standard contractual clauses.

Retention period: Order data is stored for the duration of contract performance and within the statutory retention periods (in Austria generally 7 years under § 132 BAO, with comparable commercial-law requirements).

8.2 Payment methods

Depending on the delivery country, the following payment methods are available in the online shop: cash on collection, prepayment by bank transfer, PayPal, purchase on account (from the second order onwards), and Sofortüberweisung (instant bank transfer).

If you select a payment method processed via a payment service provider, we pass on the data required for payment processing (name, address, e-mail address, invoice amount, order reference and, where applicable, bank or card details) to the relevant provider. We neither collect nor store complete credit card or bank account details — you enter these directly with the payment service provider.

Legal basis: Art. 6(1)(b) GDPR (contract performance), supplemented by Art. 6(1)(f) GDPR for fraud prevention and Art. 6(1)(c) GDPR for the providers' statutory retention and anti-money-laundering obligations.

Stripe — Stripe Payments Europe Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland. Stripe processes payment data as an independent controller for payment processing, fraud prevention and to meet its own legal obligations. Stripe also uses cookies for fraud detection (__stripe_mid, __stripe_sid). Transfers to Stripe, Inc. in the USA may occur, based on standard contractual clauses or the EU-U.S. Data Privacy Framework. Privacy information: https://stripe.com/privacy

PayPal — PayPal (Europe) S.à r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg. When paying via PayPal, payment data is transmitted to PayPal. PayPal acts as an independent controller and may transmit data to credit agencies for creditworthiness and fraud checks. Privacy information: https://www.paypal.com/uk/webapps/mpp/ua/privacy-full

Sofortüberweisung (Klarna) — Klarna Bank AB (publ), Sveavägen 46, 111 34 Stockholm, Sweden. If you select Sofortüberweisung, you will be redirected to a Klarna page where you enter your online banking credentials directly with Klarna. Klarna checks the account balance in real time and executes the transfer. We receive only a confirmation of payment. Privacy information: https://www.klarna.com/international/privacy-policy/

Purchase on account — For purchases on account (from the second order onwards), we process your order and invoice data for payment processing and receivables management. The legal basis is Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR (legitimate interest in mitigating our payment default risk).

9. Contacting us

9.1 Contact form

If you send us enquiries via the contact form, we process the data you provide:

  • Mandatory fields: name, e-mail address, message
  • Voluntary fields: company, telephone number

In addition, we technically process the time of submission and the IP address to prevent spam. The form contains hidden fields (“honeypots”) used solely for automated spam detection; these collect no personal data from you.

Before submitting, you must confirm by ticking a checkbox that you have taken note of this privacy policy.

Purpose: Handling your enquiry and answering follow-up questions.

Legal basis: Art. 6(1)(b) GDPR where your enquiry is aimed at concluding or performing a contract; otherwise Art. 6(1)(f) GDPR (legitimate interest in responding to enquiries).

Retention period: We store the data until the purpose of storage ceases to apply (generally once processing is complete), until you request deletion, or until you withdraw your consent. Mandatory statutory retention periods — in particular for business letters — remain unaffected.

9.2 Contact by e-mail and telephone

If you contact us by e-mail or telephone, we process your details to handle your request. Legal basis and retention period correspond to section 9.1.

9.3 WhatsApp Business

Our website offers you the option of contacting us via WhatsApp. The corresponding buttons are plain links to https://wa.me/… with a graphic stored locally on our server. Merely visiting our website therefore establishes no connection to Meta or WhatsApp and sets no cookies. Data is transmitted only once you actively click the button.

When you click the button, the WhatsApp service opens on your device or in your browser and prepares a conversation with our business number +43 5373 7602012. From that point, the following applies:

Service provider: WhatsApp Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland (part of the Meta group of companies; processing may also be carried out by Meta Platforms, Inc., 1601 Willow Road, Menlo Park, CA 94025, USA).

Data processed: your mobile number, your WhatsApp profile name and picture (where you have made these available), the content of your messages, and metadata such as time, online status and delivery/read receipts. Message content is end-to-end encrypted between your device and ours; metadata is not and is processed by WhatsApp.

Purpose: Fast and straightforward communication with prospects and customers via a channel you have chosen yourself.

Legal basis: Art. 6(1)(a) GDPR — by actively contacting us via WhatsApp you consent to the use of this channel. Where your enquiry is aimed at a contract, Art. 6(1)(b) GDPR applies in addition.

Third-country transfer: Your data may be transferred to Meta Platforms, Inc. in the USA. Meta Platforms, Inc. is certified under the EU-U.S. Data Privacy Framework; standard contractual clauses apply in addition.

Retention period: We delete conversations once your request has been conclusively handled and no statutory retention obligations apply, at the latest after 12 months.

Important note: We have no influence over the nature and extent of data processing by WhatsApp/Meta. Further information can be found in WhatsApp's privacy policy at https://www.whatsapp.com/legal/privacy-policy-eea. Please do not send us sensitive data via WhatsApp (e.g. health data, payment data, identity documents). For confidential matters, please use e-mail, telephone or our contact form.

10. Job applications

Our job portal offers an online application form (senn-gruppe.com/jobs/kontakt). Alternatively, you can apply by e-mail to jobs@senn-gruppe.com.

Data processed:

  • Mandatory: first name, surname, e-mail address, desired position, earliest possible start date
  • Voluntary: telephone number, cover letter / motivation text
  • Uploaded documents: CV and further application documents (each in PDF format). These may contain additional personal data — such as address, date of birth, nationality, photograph, education and employment history, references and qualifications.

Before submitting, you must confirm by ticking a checkbox that you have taken note of this privacy policy.

Recipients: The application is forwarded to the person responsible for the advertised position at the relevant SENN Gruppe company. Within the group, only those involved in the selection process (HR, the relevant department, management) have access.

Purpose: Conducting the application procedure and preparing for the possible establishment of an employment relationship.

Legal basis: Art. 88 GDPR in conjunction with Art. 6(1)(b) GDPR (initiation of an employment relationship). Where you voluntarily provide additional information or consent to longer storage: Art. 6(1)(a) GDPR. If special categories of personal data (e.g. information on a disability) are submitted as part of the application, processing is based on Art. 9(2)(b) GDPR.

Retention period: If your application is unsuccessful, we delete your application documents six months after the procedure is concluded. This period serves to protect our legal defence against potential claims under equal treatment legislation. If you would like us to keep your documents for future positions, please let us know — we will then store them on the basis of your consent for a further 12 months. If your application is successful, the documents are transferred to your personnel file.

11. Whistleblowing system

At leaks.senn-gruppe.com we operate an internal reporting system in accordance with the EU Whistleblower Directive (EU) 2019/1937 and the Austrian Whistleblower Protection Act (HSchG). Reports of legal violations can be submitted through this system — anonymously if desired.

Processing within the reporting system is based on Art. 6(1)(c) GDPR (legal obligation to operate an internal reporting channel) and Art. 6(1)(f) GDPR (legitimate interest in investigating legal violations). The identity of whistleblowers is treated confidentially; access is restricted exclusively to the persons designated for this purpose.

Detailed data protection information on the reporting system is provided directly within the reporting portal.

12. Embedded third-party content (two-click solution)

On individual pages we embed third-party content — in particular YouTube videos, Vimeo videos and Google Maps. This content is not loaded automatically. Instead, you will first see a placeholder with a notice. Only when you actively release the content by clicking is a connection established to the respective provider's servers, transmitting your IP address and further technical data.

Your release is stored in a cookie (im_youtube, im_vimeo, im_googlemaps) so that you do not have to release the content again on every visit. You may withdraw this release at any time via the cookie settings in the footer.

Legal basis: Art. 6(1)(a) GDPR (consent through active release) in conjunction with § 165(3) TKG 2021.

ServiceProviderPrivacy information
YouTubeGoogle Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irelandpolicies.google.com/privacy
VimeoVimeo.com, Inc., 330 West 34th Street, New York, NY 10001, USAvimeo.com/privacy
Google MapsGoogle Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irelandpolicies.google.com/privacy

Transfers to the USA may occur for YouTube and Google Maps; Google LLC is certified under the EU-U.S. Data Privacy Framework. Vimeo.com, Inc. processes data in the USA; transfers are based on standard contractual clauses. If you are logged in with the respective provider, it may associate your visit with your personal profile; you can prevent this by logging out beforehand.

13. Social media presences

We maintain presences on social networks in order to communicate with customers, prospects and applicants and to provide information about our company. Our website contains only plain links to these profiles — no social plugins are embedded that would transmit data to the networks already when the page loads. Data is transmitted only when you click one of these links.

If you visit our profiles, the respective platform operator processes your data (including IP address, usage data and, where applicable, association with your user account) and sets cookies. We receive aggregated statistics from the platforms about the use of our presences that cannot be traced back to individual persons.

Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in our external presentation, communication with prospects and customers, and the promotion of our products and services. The legal basis may also be consent granted to the platform operator under Art. 6(1)(a) GDPR, which you may withdraw there at any time.

PlatformOperatorPrivacy information
FacebookMeta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Irelandfacebook.com/privacy/policy
InstagramMeta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Irelandprivacycenter.instagram.com/policy
LinkedInLinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Irelandlinkedin.com/legal/privacy-policy
X (formerly Twitter)Twitter International Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Irelandx.com/en/privacy
PinterestPinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Irelandpolicy.pinterest.com/en/privacy-policy

13.1 Joint controllership

For the collection and processing of data for page insights (statistics on the use of our presences), we are joint controllers within the meaning of Art. 26 GDPR together with the following providers:

You may generally assert data subject rights regarding data processed on the platforms directly with the respective provider; we forward requests received by us accordingly.

13.2 Third-country transfer

It cannot be ruled out that processing also takes place outside the European Union, in particular in the USA. Meta Platforms, Inc., LinkedIn Corporation and Pinterest, Inc. are certified under the EU-U.S. Data Privacy Framework; standard contractual clauses apply in addition. This may entail increased risks, for example because subsequent access to your data may be more difficult and we have no access to this data.

14. Search function

Our website offers a full-text and product search. The search terms entered are processed on our server in order to display results to you. Search terms may be evaluated in aggregated, non-personal form in order to improve our offering.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a functional website that meets user needs).

15. Newsletter

We do not currently offer a newsletter; no sign-up form is embedded on this website and no data is collected for that purpose. Should we offer a newsletter in future, sign-up will take place exclusively via the double opt-in procedure on the basis of your consent (Art. 6(1)(a) GDPR), withdrawable at any time via the unsubscribe link in every mailing. This privacy policy will be updated accordingly before activation.

16. Recipients and processors at a glance

Service / recipientProvider and locationRolePurposeLegal basisThird country / safeguard
Web hostingown operation / EEAProvision of the websiteArt. 6(1)(f)EEA
KeyCDNproinity LLC, Ermatingen, SwitzerlandProcessorDelivery of static contentArt. 6(1)(f)Switzerland — adequacy decision
Matomoown operation (ip.senn-gruppe.com)Cookie-free reach measurementArt. 6(1)(f)no transfer
LeadinfoLeadinfo B.V., Capelle aan den IJssel, NL — servers in Ireland (AWS EMEA SARL, LU)Processor (website analysis) / independent controller (company database)B2B visitor identification, cookie-freeArt. 6(1)(f)EU — no third-country transfer
SnipcartSnipcart Inc., Québec, CanadaProcessorCart and checkoutArt. 6(1)(b)Canada — adequacy decision (PIPEDA)
StripeStripe Payments Europe Ltd., Dublin, IEIndependent controllerPayment processingArt. 6(1)(b), (f)USA — DPF / SCC
PayPalPayPal (Europe) S.à r.l. et Cie, S.C.A., LuxembourgIndependent controllerPayment processingArt. 6(1)(b), (f)EU
Klarna / SofortüberweisungKlarna Bank AB (publ), Stockholm, SEIndependent controllerPayment processingArt. 6(1)(b)EU
YouTube, Google MapsGoogle Ireland Limited, Dublin, IEIndependent controllerEmbedded content (after release)Art. 6(1)(a)USA — DPF
VimeoVimeo.com, Inc., New York, USAIndependent controllerEmbedded videos (after release)Art. 6(1)(a)USA — SCC
WhatsAppWhatsApp Ireland Limited, Dublin, IEIndependent controllerCommunication after active clickArt. 6(1)(a), (b)USA — DPF / SCC
Meta (Facebook, Instagram)Meta Platforms Ireland Limited, Dublin, IEJoint controllers (Art. 26)Social media presenceArt. 6(1)(f), (a)USA — DPF
LinkedInLinkedIn Ireland Unlimited Company, Dublin, IEJoint controllers (Art. 26)Social media presenceArt. 6(1)(f), (a)USA — DPF
X, Pinterestsee section 13Independent controllersSocial media presenceArt. 6(1)(f)USA — DPF
Tax advisors, auditors, IT service providers, shipping providers, debt collectionEEA in each caseProcessors or independent controllersContract performance and legal obligationsArt. 6(1)(b), (c), (f)EEA

Beyond this, we only pass on your data where we are legally obliged to do so or where you have expressly consented.

17. Transfers to third countries

Where we transfer data to countries outside the European Economic Area, or use services where this cannot be excluded, we base this on one of the following grounds:

  • an adequacy decision of the European Commission (Art. 45 GDPR) — this applies to Switzerland (KeyCDN), Canada (Snipcart, for companies subject to PIPEDA) and to US companies certified under the EU-U.S. Data Privacy Framework;
  • standard contractual clauses of the European Commission (Art. 46(2)(c) GDPR), supplemented by additional technical and organisational protective measures;
  • your explicit consent (Art. 49(1)(a) GDPR).

Please note that in third countries — particularly the USA — the level of data protection may not correspond to the European standard, and that authorities may access data under certain conditions. This may make it more difficult to enforce your rights.

18. Retention periods at a glance

Data categoryRetention period
Server log files3 months (longer only to investigate attacks)
Matomo raw data14 months
Contact form and e-mail enquiriesuntil conclusively handled; business letters per statutory periods
WhatsApp conversationsuntil resolved, at most 12 months
Application documents (rejection)6 months after conclusion of the procedure
Application documents (talent pool, with consent)12 months
Order and invoice data7 years (§ 132 BAO)
Consent records (consent log)up to 3 years after withdrawal (evidence obligation, Art. 7(1) GDPR)

19. Automated decision-making

Automated decision-making, including profiling, within the meaning of Art. 22 GDPR with legal effect for you does not take place.

20. Currency and amendment of this privacy policy

This privacy policy is dated 04/08/2026.

As our website and the services offered through it develop, or due to changed legal or regulatory requirements, it may become necessary to amend this privacy policy. The current version is available at any time at senn-gruppe.com/en/gdpr.


© SENN Group