Datenschutzerklärung
Privacy Policy
This English translation is provided for convenience. Only the German version is legally binding.
This privacy policy explains which personal data (that is, any information that allows conclusions to be drawn about your identity) ByteBakery UG (haftungsbeschränkt) collects, processes and uses when you use our website and our ePIverity platform. It is governed by the General Data Protection Regulation (GDPR) and other applicable data protection laws in Germany.
1. Data protection at a glance
General information:
We take the protection of your personal data very seriously. This privacy policy gives you an overview of which data is collected, stored and processed when you visit our website and use our ePIverity platform, whether you enter it actively (e.g. via the contact form or when registering) or it is collected automatically (e.g. through server log files or cookies).
Collection and use:
Some data is collected to display and improve our services without errors; other data is used to perform a contract or is based on your consent. You have the right at any time to access, rectify or erase your data or to restrict its processing.
2. Controller
ByteBakery UG (haftungsbeschränkt)Heinefelder Weg 28
33034 Brakel, Germany
Email: hallo@schenkwerk.com
The entity named above is responsible for all questions regarding the collection, processing and use of your personal data.
3. General information and mandatory disclosures
Legal bases:
We process your personal data exclusively on the basis of the GDPR. Depending on the case, we rely on the following, among others:
- Art. 6(1)(a) GDPR (consent, e.g. for cookies or newsletters),
- Art. 6(1)(b) GDPR (performance of a contract, e.g. for registrations or purchases),
- Art. 6(1)(c) GDPR (legal obligations) and
- Art. 6(1)(f) GDPR (legitimate interests, e.g. to improve our website).
Retention period:
Personal data is stored for as long as necessary for the respective purpose or as required by statutory retention periods (e.g. under tax or commercial law). When the business relationship ends, or at your request, the data is deleted unless statutory retention periods prevent this.
Disclosure to third parties:
We only disclose personal data to third parties if this is necessary to perform a contract, if we are legally obliged to do so, if there is a legitimate interest or if you have expressly consented. Where we use processors (e.g. AWS, Stripe, Cal.com), data is only disclosed on the basis of a valid data processing agreement.
Withdrawal and objection:
Where processing is based on your consent, you can withdraw it at any time without giving reasons. You also have the right to object to certain types of processing.
Security:
Data is transmitted over the internet using encrypted connections (SSL/TLS). Despite careful security measures, complete protection against access by third parties cannot be guaranteed.
4. Data collection on our website
4.1 Data you provide
Contact forms:
If you contact us via a contact form, email, phone or fax, the data you send us is stored and processed solely to handle your enquiry.
Legal basis: Art. 6(1)(b) GDPR, or Art. 6(1)(a) GDPR where you have given consent.
Newsletter:
If you subscribe to our newsletter, we collect your email address and any further information you choose to provide, which is used solely to send you information.
Legal basis: Art. 6(1)(a) GDPR (consent).
Appointment booking via Cal.com:
To book calls, we embed the calendar of the Cal.com service (Cal.com, Inc., USA) on our website. The calendar only loads after you click “Show available times” (“Freie Termine anzeigen” on the German site); only then is a connection to Cal.com’s servers established, transmitting, among other things, your IP address. If you book an appointment, Cal.com processes the data you enter (name, email address, selected time, optional notes) and makes it available to us so that we can hold the call.
Legal basis: Art. 6(1)(a) GDPR (consent by loading the calendar) and Art. 6(1)(b) GDPR (steps prior to entering into a contract).
More information: https://cal.com/privacy
4.2 Data collected automatically
Server log files:
When you visit our website, information such as your IP address, browser type, operating system, time of the request, referrer URL and host name of the accessing computer is automatically stored in server log files.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the secure and error-free operation of our website).
Cookies:
Our website uses cookies, small text files stored on your device. We distinguish between:
- Necessary cookies: these are technically required (e.g. to maintain a session or for a shopping cart).
- Analytics and marketing cookies: these may be used to analyse your usage behaviour and for advertising purposes.
You can control or disable the storage of cookies in your browser settings.
Legal basis: necessary cookies are based on Art. 6(1)(f) GDPR; all others on your consent (Art. 6(1)(a) GDPR and § 25(1) TTDSG).
Changing cookie settings:
You can change your cookie settings at any time via our cookie banner. Click here to open your cookie settings.
Storage and disclosure of email addresses:
Where email addresses are collected (e.g. for sending newsletters), they are stored solely on the basis of your consent. They are only disclosed to third parties if you have expressly agreed or there is a legitimate interest.
You can object to their storage and use at any time.
5. Analytics tools and advertising
Google Maps JavaScript API:
Our website uses the Google Maps JavaScript API to show you interactive maps and location-based information. When you open pages with embedded Google Maps content, a connection to Google’s servers is established. Personal data such as your IP address, browser information and, where applicable, location data may be transmitted to Google.
Google may use this data to evaluate your use of the map features, compile reports on map activity and provide other services related to map usage. Processing also takes place in the USA. Google LLC is certified under the EU-US Data Privacy Framework.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in presenting our services in a user-friendly way). Where consent has been requested, processing is based solely on Art. 6(1)(a) GDPR and § 25(1) TTDSG. Consent can be withdrawn at any time.
More information:
Google privacy policy: https://policies.google.com/privacy
Google Maps terms of use: https://www.google.com/intl/en/help/terms_maps/
Google Analytics:
This website uses Google Analytics, a web analytics service provided by Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics uses cookies and similar technologies to record and analyse how visitors use our website. This allows us to see, for example, which pages were viewed when and from which region. We also collect various data (e.g. IP address, referrer, browsers and operating systems used) and can measure whether visitors to our website perform certain actions (e.g. clicks, purchases).
The information generated by Google Analytics about your use of this website is usually transmitted to and stored on a Google server in the USA. Google LLC is certified under the EU-US Data Privacy Framework.
Legal basis: Google Analytics is used solely on the basis of your consent pursuant to Art. 6(1)(a) GDPR and § 25(1) TTDSG. We have implemented a cookie consent banner through which you can give or refuse consent to the use of Google Analytics. Consent can be withdrawn at any time.
IP anonymisation:
We have activated IP anonymisation. Google truncates your IP address within member states of the European Union or other states party to the Agreement on the European Economic Area before transmitting it to the USA. Only in exceptional cases is the full IP address transmitted to a Google server in the USA and truncated there.
Data processing by Google:
Google uses the collected information on our behalf to evaluate the use of the website, compile reports on website activity and provide other services related to website and internet use.
More information:
Google Analytics privacy policy: https://policies.google.com/privacy
Google Analytics terms of use: https://marketingplatform.google.com/about/analytics/terms/us/
Cookie settings:
You can withdraw your consent to the use of Google Analytics at any time via our cookie banner. Click here to change your cookie settings.
Third-party advertising:
When third-party tools and cookies are used, please note that your data may also be transferred to other countries (e.g. the USA). More information is available under Transfers of data to third countries.
6. Hosting and third-party providers
Hosting with Amazon Web Services (AWS):
Our website is hosted by AWS (Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, 1855 Luxembourg). Your personal data is processed on AWS servers. Transfers to the USA are based on the EU Standard Contractual Clauses.
For more information, please see the AWS privacy notice:
https://aws.amazon.com/privacy/
Legal basis: Art. 6(1)(f) GDPR, or Art. 6(1)(a) GDPR where you have given consent.
Payment processing:
For payments, both on our website and on the ePIverity platform, we use external service providers:
- Stripe (Stripe Payments Europe, Ltd.):
Privacy policy: https://stripe.com/privacy
Payment processing involves transmitting, among other things, your name, billing address and transaction data (amount, currency). Sensitive payment data (e.g. credit card details) is transmitted directly to the payment provider and is not stored on our servers.
Legal basis: Art. 6(1)(b) GDPR.
Data processing on our behalf:
Where we use service providers (processors), data is processed solely on the basis of a valid data processing agreement. A detailed list is available from the respective providers.
7. Data protection on the ePIverity platform
ePIverity is software for pharmaceutical companies. It converts approved Product Information (e.g. Package Leaflets and SmPCs) into structured electronic Product Information (ePI) in FHIR format, validates it technically, supports internal review and exports it for import into the EMA PLM Portal. The following provisions supplement the general data protection provisions.
7.1 Purpose and scope
Purpose:
Collecting, processing and using data to provide, manage and improve the ePIverity platform. This includes setting up and managing user accounts for business customers, processing content provided by customers and keeping every processing step traceable.
7.2 Registration and user accounts for business customers
Data collected:
- Name and company name
- Business email address
- Role in the organisation (e.g. author, reviewer, administrator)
- Login credentials (stored only in hashed or encrypted form)
Purpose:
Enabling use of the ePIverity platform and enforcing role and approval rules (e.g. independent internal review).
Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
Retention period:
The data is stored for as long as the customer account is active. After the account is terminated or deleted, it is deleted unless statutory retention periods apply (e.g. up to 10 years under § 147 of the German Fiscal Code, AO).
7.3 Uploaded content and audit trail
Customers upload Product Information (e.g. Word or FHIR files). These documents usually contain no personal data. Where we process content on behalf of our customers, we do so on the basis of a data processing agreement pursuant to Art. 28 GDPR.
For regulatory traceability, ePIverity records which user imported documents, changed mappings, ran validations, and approved or exported versions, and when (audit trail). These entries cannot be changed afterwards.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(f) GDPR (legitimate interest in complete documentation of regulated content).
7.4 Verified Search
The optional Verified Search module allows searching authority-published Product Information. No user account is required to search. Search queries are not recorded in the audit trail and are not linked to any person.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in providing a secure and functional search).
7.5 Contract processing and invoicing
Data collected:
Company name, billing address, contact person, email address, and contract and invoicing data.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(c) GDPR (retention obligations under commercial and tax law).
7.6 Retention and deletion
Personal data collected on the ePIverity platform is only stored for as long as necessary to fulfil the respective purpose or to comply with statutory retention periods.
On request, and when the business relationship ends, the data is deleted unless statutory retention obligations apply.
8. Security measures
To protect your personal data, we have implemented extensive technical and organisational measures, including:
- Encryption: all data transmissions use SSL/TLS to protect your data against unauthorised access.
- Password storage: passwords are stored using modern hashing methods (e.g. bcrypt), so that access to plain-text passwords is technically impossible.
- Access and authentication controls: access to personal data is restricted to authorised staff and is reviewed regularly.
- Regular security reviews: our IT security infrastructure is continuously kept up to date and regularly checked for vulnerabilities.
9. Rights of data subjects
Irrespective of the other provisions of this privacy policy, you have the following rights:
- Right of access: you have the right at any time to obtain information about the data stored about you, its origin, its recipients and the purpose of processing.
- Right to rectification: if your data is incorrect or incomplete, you can request that it be corrected.
- Right to erasure: you have the right to request the erasure of your personal data unless statutory retention periods prevent this.
- Right to restriction of processing: under certain conditions, you can request that the processing of your data be restricted.
- Right to data portability: you can request that the data we process be transmitted to you or to a third party you name in a common, machine-readable format.
- Right to withdraw consent: where processing is based on your consent, you can withdraw it at any time without giving reasons.
- Right to object: where processing is based on Art. 6(1)(f) GDPR, you have the right to object to the processing of your data on grounds relating to your particular situation.
- Right to lodge a complaint with a supervisory authority: if you believe that the processing of your personal data infringes applicable data protection law, you have the right to lodge a complaint with the competent supervisory authority. In Germany, this is usually the data protection authority of the relevant federal state or, where applicable, the Federal Commissioner for Data Protection and Freedom of Information (BfDI).
10. Data protection officer
Where our company has appointed a data protection officer (which is required in particular under § 38 BDSG or for extensive processing of special categories of personal data), you can contact us directly with any questions about data protection:
ByteBakery UG (haftungsbeschränkt)Heinefelder Weg 28
33034 Brakel, Germany
Email: hallo@schenkwerk.com
11. Links to third-party websites and external content
Our website contains links to third-party websites whose content we cannot influence. We therefore cannot accept any liability for this external content.
Note: the privacy policies of linked websites may contain their own rules on data processing. We recommend that you read these privacy policies carefully.
12. Transfers of data to third countries
Data transfers:
Some of our service providers, in particular AWS, Stripe, Cal.com and Google (Google Analytics, Google Maps), process your personal data in third countries (e.g. the USA).
Legal basis:
Transfers are based on, among other things, the EU Standard Contractual Clauses, the EU-US Data Privacy Framework and other appropriate safeguards.
More information:
For details, please refer to the privacy policies of the respective providers:
- AWS: https://aws.amazon.com/privacy/
- Cal.com: https://cal.com/privacy
- Stripe: https://stripe.com/privacy
- Google: https://policies.google.com/privacy
13. Changes to this privacy policy
We reserve the right to change this privacy policy at any time, in particular to adapt it to changed legal requirements or changes to our services. The current version of the privacy policy is always available on our website. Please check its content regularly.
14. Contact
If you have questions about data protection or want to exercise your rights, you can contact us at any time:
ByteBakery UG (haftungsbeschränkt)Heinefelder Weg 28
33034 Brakel, Germany
Email: hallo@schenkwerk.com
15. Managing cookie settings
You can change and adjust your cookie settings at any time. To do so, use our cookie banner, which gives you detailed control over all cookie categories.