/Data protection

Data protection

Kyon Energy Solutions GmbH (hereinafter “we” or “us”) is pleased that you are visiting our website https://en.kyon-energy.de (hereinafter “website”). Data protection and data security when using our website are very important to us. We would therefore like to take this opportunity to inform you which of your personal data we collect when you visit our website and for what purposes it is used.

§ 1 Responsible body
Responsible within the meaning of the EU General Data Protection Regulation (hereinafter “GDPR”) for the processing of personal data on our website is:

Kyon Energy Solutions GmbH
Dachauer Strasse 15b,
80335 Munich
email: info@kyon-energy.com
Site: https://en.kyon-energy.de

§ 2 Data Protection Officer
The data protection officer of Kyon Energy Solutions GmbH is:

Dr. Kilian Schmidt
Kertos GmbH
Nymphenburger Strasse 86
80636 Munich
email: dsb@kertos.io

§ 3 What is personal data?
Personal data is any information relating to an identified or identifiable natural person. This includes, for example, information such as your name, age, address, telephone number, date of birth, email address or IP address. Information for which we cannot (or can only with disproportionate effort) establish a link to your person, e.g. by anonymising the information, is not personal data. The processing of personal data (e.g. the collection, retrieval, use, storage or transmission) always requires a legal basis or your consent.

§ 4 Data processing on our website
1) Provision and use of the website

a) Scope and purpose of data processing
We collect and use the personal data of our users only to the extent necessary to provide a functional website and our content and services or information. When you access and use our website, we collect the personal data that your browser automatically transmits to our server. This information is temporarily stored in a so-called log file.  The following information is collected without any action on your part and stored until it is automatically deleted:
- IP address of the requesting computer,
- date and time of access,
- name and URL of the retrieved file,
- website from which access is made (referrer URL),
- the browser used and, if applicable, the operating system of your computer and the name of your access provider.

The above data is processed by us for the following purposes:
- Ensuring a smooth connection to the website
- Ensuring safe and convenient use of our website

b) Legal basis
Art. 6 para. 1 lit. f GDPR serves as the legal basis for the data processing mentioned under a) if it is technically necessary. The processing of the aforementioned data is necessary for the provision of a website and to enable secure and convenient use and thus serves to safeguard a legitimate interest of our company. In addition, there are no overriding interests of the website user, so that the interest of the website operator prevails. For data that is not technically required, the legal basis is your consent in accordance with  
Art. 6 para. 1 lit. a GDPR.  

c) Storage period and data erasure
As soon as the aforementioned data is no longer required to display the website, it is deleted. The collection of data for the provision of the website and the storage of data in log files is absolutely necessary for the operation of the website. Consequently, the user has no option to object. Further storage will take place in individual cases if this is required by law.

2) Contact via email
a) Type and scope of data processing
On our website, we offer you the opportunity to contact us by e-mail. When you contact us, the personal data you provide (such as title, name, content of the e-mail) and your e-mail address will be processed. This data is processed by us for the purpose of enabling us to process your enquiry properly. If you contact us by e-mail, your personal data will not be passed on to third parties.

b) Legal basis
The data processing described above for the purpose of establishing contact is carried out in accordance with Art. 6 para. 1 lit. f GDPR on the basis of our legitimate interests in being able to process your enquiries. If the contact leads to the conclusion of a contract, we rely on Art. 6 para. 1 lit. b GDPR on the basis of the initiation of the contract.

c) Storage duration
As soon as your enquiry has been dealt with and the matter in question has been finally clarified, your personal data processed via the contact form will be deleted. Further storage may take place in individual cases if this is required by law or is necessary for the fulfilment of the contract.

3) Application form
a) Type and scope of data processing
On our website, we offer you the opportunity to apply for vacancies using an application form. If you contact us via this form, the following personal data will be processed:
- Name
- email address
- phone number
- Start date
- Desired salary
- LinkedIn (optional)
- CV
- Certificates
- Cover letter

This data is processed by us for the purpose of enabling usto process your application properly.When using the form, your personal data will not be passed on to third parties.

b) Legal basis
The data processing described above for the purpose of processing applications is carried out in accordance with Art. 6 para. 1 lit. b GDPR in conjunction with § 26 (1) 1 BDSG on the basis of contract initiation.

c) Storage duration
If the application leads to an employment relationship, the processed data will be stored until the end of the employment relationship. If no employment relationship is entered into, we will store your data for 6 months on the basis of the General Equal Treatment Act and then delete it.

§ 5 Use of cookies
a) Type and scope of data processing
We use cookies on our website. Cookies are small text files that are stored on your computer when you visit our website and enable your browser to be reassigned. Cookies store information such as your language setting, the duration of your visit to our website or the entries you make there. There are different types of cookies. Session cookies are temporary cookies that are stored in the user's Internet browser until the browser window is closed and the session cookies are deleted. Permanent or persistent cookies are used for repeated visits and are stored in the user's browser for a predefined period of time. First-party cookies are set by the website that the user visits. Only this website is authorised to read information from the cookies. Third-party cookies are set by organisations that do not operate the website that the user is visiting. A distinction can also be made between technically necessary, functional and advertising cookies. The former are necessary to ensure basic website functions (saving the language setting). Functional cookies collect information about the user's behaviour and whether they receive any error messages. Advertising cookies, on the other hand, are used to offer the user customised advertising.

b) Legal basis
Due to the purposes of use described (see § 5a), the legal basis for the processing of personal data using technically necessary cookies is Art. 6 para. 1 lit. f GDPR, as we have an interest in the user-friendly presentation of our website. If you have given us your consent to the use of functional and advertising cookies on the basis of a notice ("cookie banner") provided by us on the website, the legality of the use is also governed by Art. 6 para. 1 sentence 1 lit. a GDPR.

c) Storage duration
As soon as the data transmitted to us via the cookies is no longer required to fulfil the purposes described above, this information is deleted. Further storage will take place in individual cases if this is required by law.

d) Configuring browser settings
Most browsers are set to accept cookies by default. However, you can configure your browser so that it only accepts certain cookies or no cookies at all. However, we would like to point out that you may no longer be able to use all the functions of our website if cookies are deactivated by your browser settings on our website. You can also use your browser settings to delete cookies already stored in your browser or to display the storage period. It is also possible to set your browser to notify you before cookies are stored. As the various browsers may differ in their respective functions, we ask you to use the respective help menu of your browser for the configuration options.

§ 6 Tracking and analysis tools
We use tracking and analysis tools to ensure the continuous optimisation and needs-based design of our website. With the help of tracking measures, we are also able to statistically record the use of our website by visitors and to further develop our online offering for you with the help of the knowledge gained. Based on these interests, the use of the tracking and analysis tools described below is justified in accordance with Art. 6 para. 1 sentence 1 lit. f GDPR. If you have given us your consent to the use of cookies on the basis of a notice ("cookie banner") provided by us on the website, the legality of the use is also based on Art. 6 para. 1 sentence 1 lit. a GDPR. The following description of the tracking and analysis tools also shows the respective processing purposes and the processed data.

a) Google Analytics
This website uses Google Analytics, a web analytics service provided by Google Ireland Limited, Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"). Google Analytics uses "cookies", which are text files placed on your computer, to help the website analyse how users use the site.
The information generated by these cookies, for example about the time, place and frequency of your use of this website, is usually transferred to a Google server in the USA and stored there. When using Google Analytics, it cannot be ruled out that the cookies set by Google Analytics may also collect other personal data in addition to the IP address. Please note that Google may transfer this information to third parties where required to do so by law, or where such third parties process the information on Google's behalf. Google will use the information generated by cookies on behalf of the operator of this website to analyse your use of the website, to compile reports on website activity and to provide the website operator with other services relating to website activity and internet usage. According to Google, the IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.
You can generally prevent the storage of cookies by selecting the appropriate settings in your browser software. However, we would like to point out that in this case you may not be able to use all functions of this website to their full extent.

§ 7 Social Plug-ins
a) Type and scope of data processing
Our presence on social networks and platforms serves to improve active communication with our customers and interested parties. For this reason, social plugins from the social networks "LinkedIn" (LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland), "X" (X Crop., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA) and "Instagram" (Meta Ireland Limited, Merrion Road, Dublin 4, Ireland) are integrated on our website. Based on the data transmitted to the respective service via the social plugin, the service may be able to assign you to your account with it.  
The social plugins are integrated in such a way that no data is transmitted directly to the social networks. Data is only transferred when you click on the respective button, thereby leaving our website and establishing a direct connection between your browser and the social network servers. Information on the data that is subsequently collected by the respective social network can be found here:


b) Legal basis
The legal basis for this processing of your personal data is our legitimate interest in communicating with our interested parties and customers, analysing and further developing services and products and improving business processes in accordance with Art. 6 para. 1 lit. f GDPR.

§ 8 Recipients of personal data
Within our company, only those persons have access to your personal data who need it for the purposes stated in each case. Your personal data will only be passed on to external recipients if we are legally authorised to do so or if we have your consent. Below you will find an overview of the relevant recipients:
-Processors: Group companies or external service providers, for example in the areas of technical infrastructure and processing, maintenance and payment processing, which are carefully selected and checked. The processors may only use the data in accordance with our instructions.
-Public authorities: Authorities and state institutions, such as tax authorities, public prosecutors or courts, to which we (have to) transfer personal data, e.g. to fulfil legal obligations or to protect legitimate interests

§ 9 International data transfer
We process your data mainly within the European Union (EU) and the European Economic Area (EEA). However, some of our service providers may be based outside the EEA in so-called "third countries". The General Data Protection Regulation places high demands on the transfer of personal data to third countries. All our data recipients must fulfil these requirements. Before we transfer your data to a service provider in a third country, each service provider is first checked for its level of data protection. A service provider is only selected if it can demonstrate an adequate level of data protection outside the EEA. Regardless of whether our service providers are based within the EEA or in third countries, each service provider must conclude an order processing agreement with us. Service providers outside the EEA must fulfil additional requirements. In accordance with Art. 44 ff. GDPR, personal data may be transferred to service providers who fulfil at least one of the following requirements:
-The European Commission has decided that the third country guarantees an adequate level of protection (e.g. Israel and Canada).
-Standard contractual clauses have been included in our contract with the data recipient (including any additional measures, if necessary).
-Further appropriate safeguards pursuant to Art. 46 GDPR provided (e.g. Binding Corporate Rules).
-In special exceptional cases in accordance with Art. 49 GDPR

§ 10 Data security and security measures
We undertake to treat your personal data confidentially. In order to prevent manipulation, loss or misuse of your data stored by us, we take extensive technical and organisational security precautions, which are regularly reviewed and adapted to technological progress. However, we would like to point out that due to the structure of the Internet, it is possible that the rules of data protection and the above-mentioned security measures may not be observed by other persons or institutions outside our area of responsibility. In particular, unencrypted data - e.g. when sent by e-mail - may be read by third parties. We have no technical influence on this. It is your responsibility as a user to protect the data you provide against misuse by means of encryption or in any other way.

§ 11 Rights of data subjects
You have the following legal rights vis-à-vis us with regard to your personal data:

Right to information
You have the right to request confirmation as to whether we are processing personal data concerning you. If this is the case, you have the right to information about this personal data and to further information, e.g. the processing purposes, the recipients and the planned duration of storage or the criteria for determining the duration.

Right to correction and completion
You have the right to request the rectification of inaccurate data without undue delay. Taking into account the purposes of the processing, you have the right to request the completion of incomplete data.

Right to erasure (“right to be forgotten”)
You have the right to erasure if the processing is not necessary. This is the case, for example, if your data is no longer required for the original purposes, if you have revoked your declaration of consent under data protection law or if the data has been processed unlawfully.

Right to restrict processing
You have the right to restrict processing, e.g. if you believe that the personal data is incorrect.

Right to data portability
You have the right to receive personal data concerning you in a structured, common and machine-readable format.

Right to object
You have the right to object at any time, on grounds relating to your particular situation, to the processing of certain personal data concerning you.  In the case of direct advertising, you as the data subject have the right to object at any time to the processing of personal data concerning you for the purpose of such advertising; this also applies to profiling insofar as it is associated with such direct advertising.

Right to withdraw your data protection consent
You can revoke your consent to the processing of your personal data at any time with effect for the future. However, this does not affect the legality of the processing carried out up to the point of revocation.