dxm GmbH & Co. KG
Data protection
This English version is a translation for your convenience. In legal terms, only the German original applies.
dxm GmbH & Co. KG is pleased that you are visiting our website. Data protection and security when using our site matter to us. Below we explain which personal data we collect during your visit and for which purposes it is used. Changes in the law or our processes may require updates; please review this policy regularly. The current version is always available at Privacy policy.
§1 Scope of application
This privacy policy applies to the online offering of dxm GmbH & Co. KG at www.dxm.space and related subdomains (hereinafter “our website”), where this policy is referenced. Separate offerings (e.g. the careers portal at karriere.dxm.space) may provide additional notices.
§2 What is personal data?
Personal data is information that can be used to learn about your personal or factual circumstances (e.g. name, address, telephone number, date of birth, email address). Information for which we cannot establish a link to your person (or can do so only with disproportionate effort), for example through anonymisation, is not personal data.
§3 Which personal data is collected / processed and used by us?
You can use large parts of our website without entering personal data. When pages are requested, technically necessary access data is generated (e.g. IP address in truncated or full form depending on the service used, date and time, URL requested, referrer, browser and device information). This data is used to operate and secure the website and – where you have given consent – to measure and improve our offering. Personal data that you actively provide is collected in particular via the contact form (name, email address, message content) and in the application process via our careers portal. Your personal data is not transferred to third parties or used for advertising purposes without your consent, except in the cases described in this policy, where we are legally obliged to disclose information, or where we engage processors under a data processing agreement.
§4 Processing of personal data within our application procedure
We process applicants’ personal data in accordance with the law for the purpose of handling the application procedure and taking pre-contractual measures within the meaning of Art. 6(1)(b) GDPR. By submitting an application you express interest in employment with us and transmit personal data that we use and store solely for your job search / application. Only authorised HR staff and persons involved in the procedure have access to your data. Data is generally stored solely for filling the vacancy you applied for or, for unsolicited applications, to assess possible roles. As a rule, data is retained for 6 months beyond the end of the procedure, in particular to meet legal obligations or defend against claims. We then erase or anonymise the data. Metadata without direct personal reference may remain for statistics. Application data is transmitted via TLS and stored in a database operated by Personio SE & Co. KG (https://www.personio.de/impressum/). Personio acts as our processor under Art. 28 GDPR on the basis of a data processing agreement. Further information: https://www.personio.de/datenschutzerklaerung/. The careers portal is available at https://karriere.dxm.space/. We may offer inclusion in a “talent pool” for 12 months on the basis of consent (Art. 6(1)(a), Art. 7 GDPR). Documents are used only for future vacancies and destroyed at the latest when the period ends. Consent is voluntary, does not affect the current procedure and may be withdrawn at any time with effect for the future. If you accept an offer of employment, we store the application data at least for the duration of the employment relationship.
§5 Contact form
If you use our contact form, we collect your name, email address and message content. Providing this information is voluntary; without it we generally cannot handle your request. Transmission is encrypted (TLS). We use the data solely to process your enquiry and retain it as long as needed for correspondence and any proof obligations. The legal basis is Art. 6(1)(b) GDPR (pre-contractual / contractual communication) or Art. 6(1)(f) GDPR (legitimate interest in handling enquiries).
§6 Cookies and consent management (Cookiebot)
We use cookies and similar technologies. Strictly necessary cookies are required to operate the website (legal basis Art. 6(1)(f) GDPR). Statistics, marketing and preference cookies are used only if you consent via our consent banner (Art. 6(1)(a) GDPR).
For consent management we use Cookiebot by Usercentrics A/S, Havnegade 39, 1058 Copenhagen, Denmark (https://www.cookiebot.com). Cookiebot itself sets strictly necessary cookies to store your choice and document consent. Further information: https://www.cookiebot.com/en/privacy-policy/.
You can change or withdraw your choice at any time via the cookie notice or cookie settings. An up-to-date overview of cookies and providers is in the cookie declaration at the end of this page.
§7 Web analytics with Matomo
To analyse use of our website we use Matomo (self-hosted at https://matomo.dxm.space/). Matomo helps us understand which content is used and improve our offering. Measurement starts only after you have consented via Cookiebot. The legal basis is Art. 6(1)(a) GDPR.
Processed data includes pages viewed, referrer, approximate location/device information and a pseudonymous visitor ID. Data is processed on our systems or on our behalf and is not sent to Google Analytics. You can withdraw consent at any time via the cookie settings.
§8 Google Tag Manager
We use Google Tag Manager by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). Tag Manager is a tool for centrally managing measurement and marketing tags and – together with Cookiebot – deploying them depending on your consent. Tag Manager itself usually does not set its own cookies but can trigger other tags. The legal basis for consent-based tags is Art. 6(1)(a) GDPR; for the technically necessary operation of the manager Art. 6(1)(f) GDPR may apply.
Google information: https://policies.google.com/privacy
§9 Marketing and conversion tags (including Meta and LinkedIn)
After you consent to the marketing category (or comparable categories in the cookie banner), third-party tags may be loaded via Google Tag Manager, in particular the Meta Pixel (Meta Platforms Ireland Limited) and the LinkedIn Insight Tag (LinkedIn Ireland Unlimited Company). These services may set cookies, process device identifiers and – if you are logged in with the respective provider – link usage data to your profile to measure reach and conversions and to deliver or optimise ads.
The legal basis is your consent (Art. 6(1)(a) GDPR). You may withdraw consent at any time via the cookie settings. Details of cookies and retention periods are in the cookie declaration below and in Meta’s and LinkedIn’s privacy notices.
Google services that are likewise loaded via Tag Manager only after consent follow the same principles.
§10 Security measures to protect the data we store
We undertake to protect your privacy and treat your personal data confidentially. To prevent loss or misuse we apply technical and organisational security measures that are reviewed regularly and adapted to the state of the art. Owing to the structure of the internet, persons or institutions outside our control may not always observe data protection rules. In particular, data transmitted without encryption – including by email – may be read by third parties. We have no technical influence on that. It is the user’s responsibility to protect the data they provide appropriately.
§11 Hyperlinks and social media profiles
Our website contains hyperlinks to third-party websites and to our company profiles (including Facebook and Instagram). Activating these links takes you away from our website. We have no influence on whether those providers comply with data protection law and accept no responsibility for how they handle your data. Please consult the providers directly.
§12 Data protection information on photo / film recordings
We may publish photo and film recordings in our company accounts, including on Facebook and Instagram. Recipients include the respective platform operators (including Meta Platforms Ireland Limited). Retention (publication and internal archiving) depends on the informational value of the recordings. Publications on our website are reviewed over time and removed when they no longer have informational value; social posts follow the platforms’ use and our internal archiving. Individual recordings may be archived long-term under restricted processing to protect copyright claims or for company history. Please note that published images online may be distributed worldwide and attributed to a person, and complete erasure from the internet cannot always be guaranteed. You have rights to access, rectification, erasure or restriction of processing and – for particular reasons – to object to the use of your photos. You may also lodge a complaint with the competent supervisory authority:
Landesbeauftragte für Datenschutz und Informationsfreiheit
Nordrhein-Westfalen
Postfach 20 04 44
40102 Düsseldorf
fon +49 211 384 240
fax +49 211 3 842 410
poststelle@ldi.nrw.de
For questions or suspected misuse of recordings, contact our internal data protection coordination at sandra.wiora@dxm.space or datenschutz@dxm.space.
§13 Withdrawal / objection
You may withdraw consent at any time with effect for the future. You may also object to processing and use of your data for advertising purposes. Please contact datenschutz@dxm.space or use the cookie settings on our website.
§14 Information on the personal data we store about you, retention and erasure
We store your personal details only for as long as permitted by law and required for the respective purpose. Data is erased if you withdraw consent or if it is no longer needed for the purpose or storage is otherwise unlawful. On request we will tell you what data we hold about you. If incorrect data is stored despite our efforts, we will rectify it without undue delay. Erasure on request is likewise carried out without undue delay unless legal retention duties apply; otherwise the data is blocked. Please contact datenschutz@dxm.space.
§15 Processing on behalf of the controller
Where we have personal data processed by service providers, this is based on data processing agreements under Art. 28 GDPR. This includes in particular Cookiebot / Usercentrics (consent management), operation of our Matomo instance and Personio (applicant management). Providers loaded via Google Tag Manager after your consent (e.g. Meta, LinkedIn, Google) process data within the scope of the respective service and consent; details are in the cookie declaration below and in the providers’ privacy policies.
You can change or withdraw your consent at any time via the cookie notice on our website. The current cookie declaration is shown below.