Skip to content

Privacy Policy

This Privacy Notice informs visitors to the publicly accessible Aperta Services website about the processing of personal data. It does not apply to personal data processed by customers within an installation of the Aperta Platform.

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Aperta Services
Bernd G. Scheu
Im Schloßgarten 11
DE-78244 Gottmadingen
Germany
Email: aperta.services@gmail.com

You may direct questions about the processing of your personal data and requests to exercise your rights to the email address above.

2. Principles and legal bases

We process personal data only where necessary to provide and secure the website, respond to enquiries, perform the online assessments offered on the website or comply with legal obligations.

Depending on the processing activity, we rely in particular on Article 6(1)(b) GDPR for contracts and steps taken before entering into a contract, Article 6(1)(c) GDPR for legal obligations, and Article 6(1)(f) GDPR for our legitimate interests in maintaining a secure and functional website, handling business communications and preventing abuse. Where we request consent, Article 6(1)(a) GDPR is the legal basis.

For access to information on your terminal device that is strictly necessary, we rely on section 25(2), no. 2 TDDDG. Where access is not strictly necessary, it takes place only on the basis of consent under section 25(1) TDDDG.

3. Website access and server log data

Whenever the website is accessed, the web server processes technical information required for delivery. This may include the IP address, date and time of access, requested address, volume of data transferred, HTTP status, referrer address, browser type and version, and operating system.

The processing is used to deliver the website, maintain stability and technical administration, and detect and defend against attacks and abusive use. The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are the secure, reliable and traceable operation of our online service.

Recipients may include hosting, infrastructure and IT service providers used by us insofar as they need the data to provide their services. Routine server log data is deleted after 14 days. If a specific security incident occurs, relevant data may be retained for longer until the incident has been clarified and necessary evidence has been secured.

4. Language preference and strictly necessary cookie

The website uses the cookie “pll_language” to store the language selected by the user and provide that language on subsequent visits. The cookie contains the selected language, is set by aperta-services.de and has a lifetime of one year.

This storage is necessary to provide the multilingual presentation selected by the user. The legal bases are section 25(2), no. 2 TDDDG and Article 6(1)(f) GDPR. Our legitimate interest is to provide the expressly selected language consistently.

5. Contact form and other communications

If you contact us through the contact form or by email, we process the information you submit. This may include your name, email address, subject, message content and technical transmission data required to deliver the communication.

We use this data to assign, process and respond to your enquiry and to document the associated communication. If your enquiry relates to a contract or steps before entering into a contract, the legal basis is Article 6(1)(b) GDPR. For other business or general enquiries, we rely on Article 6(1)(f) GDPR. Our legitimate interests are the proper handling and documentation of communications.

Information marked as required is necessary to process the relevant enquiry. Without it, we may not be able to process the form.

Form messages are processed through our website and email infrastructure. Hosting, IT and email service providers may act as recipients or processors. We normally delete ordinary enquiries no later than twelve months after the communication has concluded. If the communication results in a contractual relationship or statutory retention duties apply, the relevant documents are retained for the applicable longer period.

6. Online assessments and result emails

The website offers role-based assessments for executives, PMO or project management leaders, department heads, and project managers or team leaders.

When you participate, we process the answers you select, the email address you provide, the relevant role variant, the score and result values calculated from your answers, and technical transmission data required to deliver the submission. The email address is required because the result is provided by email. Without an email address, the assessment cannot be completed.

The purpose is to evaluate the answers using predefined scoring rules, generate a result, send it to the specified email address and enable communication directly connected with the assessment. Where participation is requested in preparation for a possible advisory or contractual relationship, the legal basis is Article 6(1)(b) GDPR. Otherwise, we rely on Article 6(1)(f) GDPR for providing the requested result and for a one-time follow-up directly related to the submitted assessment. Our legitimate interests are to provide the expressly requested result, explain its relevance and enable a focused professional dialogue.

The assessment uses an automated, rule-based evaluation of the selected answers. It does not result in a solely automated decision producing legal effects or similarly significantly affecting the participant within the meaning of Article 22 GDPR. It does not assess individual work performance and is not used for employment decisions.

We do not use the information for newsletters or general bulk advertising without a separate legal basis. You may object at any time to follow-up based on Article 6(1)(f) GDPR.

The submitted information and directly related communications are generally deleted twelve months after the last substantive contact. If a contractual relationship results or statutory retention duties apply, the applicable periods take precedence.

7. Protection against abuse with Google reCAPTCHA

We use Google reCAPTCHA to protect our forms and systems against automated access, spam and abuse. The provider for users in the European Economic Area is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Processing by Google LLC and affiliated companies in the United States or other countries cannot be excluded.

When reCAPTCHA is loaded and used, data such as the IP address, date and time, referrer address, browser and device information, operating system, interactions with the website and reCAPTCHA element, and cookies or similar identifiers may be transmitted to and evaluated by Google. Google uses this information to assess automatically whether access originates from a person or an automated system.

Under the current technical configuration, reCAPTCHA components are loaded when pages of our website are accessed. Our processing serves to prevent spam and technical attacks and protect our communication channels. We rely on Article 6(1)(f) GDPR. Our legitimate interests are website security and functionality and the prevention of abusive form submissions. We rely on section 25(2), no. 2 TDDDG for access to information on the terminal device required for the security function.

If you do not wish to use reCAPTCHA, you may contact us directly by email. If you wish to avoid any transfer to Google, you must not use the website beyond that point because reCAPTCHA components are currently loaded across the website.

Further information: Google Privacy Policy and reCAPTCHA FAQ.

8. Email infrastructure and Google services

Our published contact address is a Gmail account. If you contact us by email or submit a form or assessment, messages, results and metadata may be processed through services provided by Google Ireland Limited and, where applicable, Google LLC. This processing is carried out to transmit, store and handle the communication on the respective legal bases described in sections 5 and 6.

Google may process data in the United States and other third countries. According to Google, transfers to the United States may, depending on the processing, rely on the EU-US Data Privacy Framework or Standard Contractual Clauses.

Google information on international transfers: Legal frameworks for data transfers.

9. No web analytics or advertising trackers

As of the date of this Privacy Notice, we do not use separate web analytics services, advertising pixels or personalised advertising trackers on the website. Google reCAPTCHA is a security service and is described separately in section 7. If analytics or marketing services are introduced in the future, we will update this Privacy Notice and, where necessary, the consent-management mechanism before activation.

10. External links and LinkedIn

The website contains links to external services, in particular the Aperta Services LinkedIn company page. Merely viewing our website does not transmit data to LinkedIn through an ordinary external link. Only when you select the link do you access the relevant third-party service. From that point, the third-party provider processes data under its own terms and privacy notices. We generally have no control over that processing.

11. Recipients and processors

Within Aperta Services, access to personal data is limited to persons who need it for the relevant task. External recipients may include hosting and infrastructure providers, IT administration and maintenance providers, email service providers, Google in connection with Gmail and reCAPTCHA, and public authorities or other public bodies where disclosure is legally required.

Where service providers process personal data exclusively on our behalf, they are engaged under a data processing agreement in accordance with Article 28 GDPR. We do not disclose personal data for third parties’ own advertising purposes.

12. Transfers to third countries

When Google services are used, processing may take place in countries outside the European Union and European Economic Area, particularly the United States. If no adequacy decision applies to the relevant recipient country, appropriate safeguards such as the Standard Contractual Clauses approved by the European Commission must be used unless a statutory exception applies. Even with such safeguards, risks arising from access by public authorities in the third country cannot be completely excluded.

13. Retention

We retain personal data only for as long as necessary for the relevant purpose. The standard periods for server logs, enquiries and assessments are stated in the relevant sections above. The data is then deleted or anonymised unless statutory retention duties, the establishment, exercise or defence of legal claims, or a specific security incident require longer retention. Backup copies are overwritten as part of the technical backup cycle.

14. Data security

We implement appropriate technical and organisational measures to protect personal data against loss, manipulation, unauthorised access and other risks. The website uses an encrypted HTTPS connection. However, no electronic transmission or storage method can guarantee absolute security.

15. Your rights

Where the statutory requirements are met, you have the right of access under Article 15 GDPR, rectification under Article 16 GDPR, erasure under Article 17 GDPR, restriction of processing under Article 18 GDPR, data portability under Article 20 GDPR and objection under Article 21 GDPR. Where processing is based on consent, you may withdraw that consent at any time with effect for the future under Article 7(3) GDPR. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

Right to object

Where we process personal data on the basis of Article 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation. You may object to direct marketing at any time without stating specific grounds. We will then no longer process the relevant data for those purposes unless compelling legitimate grounds or the establishment, exercise or defence of legal claims take precedence.

To exercise your rights, send a message to aperta.services@gmail.com. We may request additional information if we have reasonable doubts about your identity.

16. Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority. The supervisory authority particularly responsible for Aperta Services is:

The State Commissioner for Data Protection and Freedom of Information Baden-Württemberg
Heilbronner Straße 35
70191 Stuttgart
Germany

Website: www.baden-wuerttemberg.datenschutz.de

17. Changes to this Privacy Notice

We update this Privacy Notice when the website, services used or legal requirements change. The version published on this website with the stated revision date is the applicable version.