Privacy policy
Last modified: 28.06.2025
1. Introduction to the Privacy Policy of United In Recruitment
This privacy policy explains how your personal data is collected, used, processed, and disclosed by United In Recruitment GmbH (collectively "United In Recruitment", "we", "our", or "us") when you access or use our website and our other products and services (collectively referred to as "services") or otherwise interact with us.
We may revise this privacy policy from time to time. When we make changes, we will notify you by updating the date at the beginning of the policy accordingly. We may also provide you with additional notices, for example by adding a notice on our homepage or via a notification through our services. We encourage you to read the privacy policy each time you access our services or otherwise interact with us in order to stay informed about our information practices and the choices available to you.
2. Data Collection on This Website
2.1 Controller Responsible for Data Collection
United In Recruitment GmbH
Rotthauser Str. 46a
45309 Essen
Authorized representatives:
Deniz Ates
Timo Gatta
Constantin Soffner
Email address: privacy@blacksheep.black
2.2 Purposes and Legal Bases for Processing as well as Duration of Storage
When you use this website, various personal data is collected. Personal data is data with which you can be personally identified. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this is done.
2.2.1 Types of Data Processed, Categories of Data Subjects, and Purposes of Processing
In general, the types of data processed by us include inventory data (e.g., names, addresses), contact data (e.g., email, telephone numbers), content data (e.g., text entries, photographs, videos), usage data (e.g., websites visited, interest in content, access times), meta/communication data (e.g., device information, IP addresses), and others.
The categories of data subjects we collect from include, among others, customers, employees, prospects, and in particular applicants and business and contractual partners.
The main purposes of processing consist of the provision of contractual services and customer service, contact inquiries and communication, office and organizational procedures, as well as the administration and handling of inquiries, the organization of application procedures and interviews, and within the scope of the provision of all types of staffing services.
2.2.2 Applicable Legal Bases
The applicable legal bases under the GDPR on which we process your personal data are essentially consent (Art. 6 (1) (1)(a) GDPR), contract performance and pre-contractual inquiries (Art. 6 (1)(1)(b) GDPR), a legal obligation (Art. 6 (1) (1)(c) GDPR), or legitimate interests (Art. 6 (1)(1)(f) GDPR).
Special Case in the Recruiting Process
To the extent that special categories of personal data within the meaning of Art. 9 (1) GDPR (e.g., health data such as disability status or ethnic origin) are requested from customers and applicants as part of our services so that the controller or the data subject can exercise the rights arising from employment law and the law on social security and social protection and fulfill the corresponding obligations, such data is processed pursuant to Art. 9 (2)(b) GDPR, in the case of the protection of vital interests of the applicant or other persons pursuant to Art. 9 (2)(c) GDPR, or for the purposes of preventive health care or occupational medicine, for the assessment of the working capacity of the employee, pursuant to Art. 9 (2)(h) GDPR. In the case of voluntary disclosure of special categories of data based on consent, such data is processed on the basis of Art. 9 (2)(a) GDPR. If processing is based on your consent, we process your personal data on the basis of Art. 6 (1)(a) GDPR or Art. 9 (2)(a) GDPR insofar as special categories of data pursuant to Art. 9 (1) GDPR are processed.
2.2.3 Storage of Your Data
The data we process will be deleted in accordance with the statutory provisions as soon as the consents permitted for processing are revoked or other permissions no longer apply (e.g., when the purpose of processing such data no longer applies or they are not necessary for the purpose). If the data is not deleted because it is required for other and legally permissible purposes, its processing will be restricted to those purposes. This means the data will be blocked and not processed for other purposes. This applies, for example, to data that must be retained for commercial or tax law reasons or whose retention is necessary for the assertion, exercise, or defense of legal claims or for the protection of the rights of another natural or legal person.
Our privacy notices may also contain additional information on the retention and deletion of data that take precedence for the respective processing activities, such as in the case of applications.
2.3 General Information
As a data subject, you have various rights under the GDPR, which derive in particular from Arts. 15 to 21 GDPR. These are explained in more detail below under "Your Rights as a Data Subject". You can also find information there on how to exercise these rights. In addition to the data protection provisions of the GDPR, the Federal Data Protection Act (BDSG) contains in particular special provisions on the right of access, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes and transmission, and automated decision-making in individual cases including profiling. Furthermore, it governs data processing for purposes of the employment relationship (§ 26 BDSG), in particular with regard to the establishment, performance, or termination of employment relationships and employee consent. In addition, state data protection laws of the individual federal states may apply.
2.4 Revocation of Your Consent
Many data processing operations are only possible with your express consent. You can revoke consent you have already given at any time. The lawfulness of the data processing carried out until the revocation is not affected by the revocation.
2.5 Security Measures
We implement appropriate organizational, technical, and administrative measures in accordance with legal requirements to protect information within our company. Unfortunately, there is no guarantee of 100% security of data transmission or storage systems. If you have reason to believe that the security of your account has been compromised, please notify us immediately at the address listed in the "Contact" section. To protect the data you transmit via our online offering, we use TLS encryption. You can recognize such encrypted connections by the https:// prefix in the address bar of your browser.
3. Data Processing in General Use of Our Services and Platforms
3.1 General Use of Our Services
3.1.1 Office Suite
We use Microsoft 365, a cloud-based office suite for editing, storing, and sharing documents, as well as for communication via email, video conferencing, and chat.
Service provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland, Parent company: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399 USA
Website: https://www.microsoft.com/de-de/microsoft-365
Privacy policy: https://privacy.microsoft.com/de-de/privacystatement
Data Processing Agreement: https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA
Security information: https://www.microsoft.com/de-de/trustcenter
Types of data processed: Meta, communication, and process data (e.g., IP addresses, timestamps, identification numbers, consent status), contact data (e.g., name, email address, telephone number), communication content (e.g., emails, chat messages, video conference recordings).
Data subjects: Customers and potential customers; applicants; prospects; users (e.g., website visitors, users of online services); business and contractual partners.
Purposes of processing: Internal and external communication; collaboration within the company; processing of text documents, spreadsheets, presentations, and emails, as well as conducting video conferences.
Legal bases: Legitimate interests (Art. 6 (1)(1)(f) GDPR), contract performance and pre-contractual inquiries (Art. 6 (1)(1)(b) GDPR)
3.1.2 Customer Relationship Management
We use a Customer Relationship Management (CRM) system to maintain and track customer and user relationships. It records customer/user contacts and data transmitted through use of the platform or interaction with United In Recruitment employees.
We currently use Pipedrive as our CRM system.
Service provider: Pipedrive OÜ
Website: https://www.pipedrive.com/
Privacy policy: https://www.pipedrive.com/de/privacy
Data Processing Agreement: https://www-cms.pipedriveassets.com/documents/Complete_with_Docusign_DPA_Pipedrive_March.pdf
Types of data processed: Inventory data (e.g., names, addresses); contact data (e.g., email, telephone numbers); content data (e.g., entries in online forms)
Data subjects: Users (e.g., website visitors, users of online services), customers
Purposes of processing: Provision of contractual services and customer service; administration and handling of inquiries
Legal bases: Contract performance and pre-contractual inquiries (Art. 6 (1)(1)(b) GDPR); Legitimate interests (Art. 6 (1)(1)(f) GDPR).
In addition, we use Lemlist to organize, execute, and evaluate targeted sales and communication campaigns across various channels (e.g., email and, if applicable, other contact methods provided by Lemlist) as part of customer acquisition and communication.
Service Provider: lempire SAS (Lemlist), 128 Rue La Boétie, 75008 Paris, France
Website: https://www.lemlist.com/
Privacy Policy: https://www.lemlist.com/privacy-policy
Data Processing Agreement: https://www.lemlist.com/de/legal/dpa
Types of Data Processed: Inventory data (e.g., names, company affiliation); Contact data (e.g., email addresses, and potentially other contact information); Usage data (e.g., interaction rates such as opens, clicks, responses); Content data (e.g., communication content)
Affected Persons: Prospects, customers, and contacts at customer/companies
Purposes of Processing: Direct marketing and sales communication across various channels; Provision of contractual services and customer support; Management and response to inquiries
Legal Bases: Legitimate interests (Art. 6 (1)(f) GDPR) for effective marketing and sales management; Consent (Art. 6 (1)(a) GDPR), where legally required
3.2 General Access to Our Webpage
Each time our platforms are accessed, we automatically collect data and information from the accessing device and store this data and information in the server log files.
Types of data processed: Usage data (e.g., browser types, websites visited (referrer), interest in content, access times); meta, communication, and process data (e.g., IP addresses, timestamps, identification numbers, consent status); operating system and internet service provider and other similar data and information that serve to prevent hazards in the event of attacks on our information technology systems.
Data subjects: Customers and potential customers; applicants; prospects; users (e.g., website visitors, users of online services); business and contractual partners.
Purposes of processing: Provision of our online offering and user-friendliness; provision of contractual services in recruiting and customer service; marketing.
Legal bases: Legitimate interests (Art. 6 (1)(1)(f) GDPR)
3.2.1 General Contact
When you contact us (in particular via the contact form on our homepage at blacksheep.black or by email, telephone, or via social media) and within the framework of existing user and business relationships, your information is processed insofar as this is necessary to respond to contact inquiries and any requested measures.
Types of data processed: Contact data (e.g., email, telephone numbers, company name); content data (e.g., entries in online forms); usage data (e.g., websites visited, interest in content, access times); meta, communication, and process data (e.g., IP addresses, timestamps, identification numbers, consent status); inventory data (e.g., names, addresses) and contract data (e.g., subject matter of contract, term, customer category).
Data subjects: Customers and potential customers; applicants; prospects; users (e.g., website visitors, users of online services); business and contractual partners.
Purposes of processing: Contact inquiries and communication; administration and handling of inquiries; feedback (e.g., collecting feedback via online form); provision of our online offering and user-friendliness; provision of contractual services in recruiting and customer service; marketing.
Legal bases: Legitimate interests (Art. 6 (1)(1)(f) GDPR); contract performance and pre-contractual inquiries (Art. 6 (1)(1)(b) GDPR)
Reservation regarding other means of communication: To conclude, we would like to point out that for security reasons we reserve the right not to respond to inquiries via various messengers such as Slack or Teams.
3.2.2 Online Services and Web Hosting
The provider of the pages collects and stores information automatically in so-called server log files, which your browser automatically transmits to us. We process this data in order to make our online services available to users. For this purpose, we process the user's IP address, which is necessary to transmit the content and functions of our online services to the user's browser or end device.
We currently use hosting by Hetzner: Services in the field of provision of information technology infrastructure and related services (e.g., storage space and/or computing capacity)
Service provider: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany
Website: https://www.hetzner.com
Privacy policy: https://www.hetzner.com/de/rechtliches/datenschutz
Data Processing Agreement: https://docs.hetzner.com/de/general/general-terms-and-conditions/data-privacy-faq/
Types of data processed: Usage data (e.g., websites visited, interest in content, access times); meta, communication, and process data (e.g., IP addresses, timestamps, identification numbers, consent status); content data (e.g., entries in online forms)
Data subjects: Users (e.g., website visitors, users of online services)
Purposes of processing: Provision of our online offering and user-friendliness; information technology infrastructure (operation and provision of information systems and technical devices (computers, servers, etc.)); security measures; server monitoring and error detection
Legal bases: Legitimate interests (Art. 6 (1)(1)(f) GDPR);
For the storage and provision of data transmitted to us via file upload, we use the Bunny service as a Content Delivery Network (CDN).
Service provider: BunnyWay d.o.o. Dunajska c. 165, 1000 Ljubljana, Slovenia
Website: https://bunny.net/
Privacy policy: https://bunny.net/privacy/
Types of data processed: Usage data (e.g., websites visited, operating systems and browsers used); meta, communication, and process data (e.g., IP addresses, timestamps, identification numbers, consent status)
Data subjects: Platform users
Purposes of processing: Optimization of loading times, storage of user data (e.g., CVs, profile photos)
Legal bases: Consent (Art. 6 (1)(1)(a) GDPR), Legitimate interests (Art. 6 (1)(1)(f) GDPR)
3.2.3 Email and SMS Sending Services
We use applications from other providers for sending email and SMS messages (hereinafter referred to as "email and SMS sending services"). These are used for sending notifications and for automating marketing messages (newsletters). Furthermore, these services are used to ensure enhanced security of user accounts through multi-factor authentication. When selecting email and SMS sending services and their features, we comply with legal requirements.
Messagebird: Omnichannel automation platform
Service provider: Messagebird B.V., Trompenburgstraat 2C1079 TX Amsterdam, Netherlands
Legal bases: Legitimate interests (Art. 6 (1)(1)(f) GDPR)
Website: https://messagebird.com/de/
Privacy policy: https://messagebird.com/de/legal/privacy
Data Processing Agreement: https://messagebird.com/de/legal/dpa.
Types of data processed: Contact data (e.g., email, telephone numbers, company name); content data (e.g., entries in online forms); meta, communication, and process data (e.g., IP addresses, timestamps, identification numbers, consent status); inventory data (e.g., names, addresses)
Data subjects: Platform users, prospects
3.3 Data Processing When Using the United In Recruitment Account
3.3.1 Registration, Login, and Creation of United In Recruitment Account
You can create a customer account and thereby conclude a contract for a United In Recruitment Account. As part of the registration, you will be informed of the required mandatory information, which is processed for the purpose of providing the user account on the basis of contractual obligations. The data processed includes in particular login information (email address and password). As part of the contract for your United In Recruitment Account, you can create a profile. Which personal data is transmitted to us in this context depends on your respective uploads or your entries in the corresponding input fields. Any uploaded documents will be automatically analyzed by us in terms of structure and content in order to optimize our services for you. You can individually define the scope of contractual use of this profile.
We store your profile until you delete it or the account contract ends. You may be informed by email about operations relevant to your customer account, such as technical changes.
Types of data processed: Inventory data (e.g., names, addresses); contact data (e.g., email, telephone numbers); content data (e.g., entries in online forms); meta, communication, and process data (e.g., IP addresses, timestamps, identification numbers, consent status)
Data subjects: Users (e.g., website visitors, users of online services), customers
Purposes of processing: Provision of contractual services and customer service; security measures; administration and handling of inquiries; provision of our online offering and user-friendliness
Legal bases for processing: Contract performance and pre-contractual inquiries (Art. 6 (1)(1)(b) GDPR); Legitimate interests (Art. 6 (1)(1)(f) GDPR).
For further details on the United In Recruitment Account, please refer to our terms of use.
3.3.2 Recruiting Services
As part of our services, which include in particular the search for potential applicants, contacting them, their placement, as well as coaching and mentoring, we process your data as an applicant or the personal data of you as a potential employer or your employees.
We process the information and contact data you provide as an applicant for the purposes of establishing, performing, and, if applicable, terminating a contract for job placement as well as for coaching and mentoring. In addition, we may contact you as an interested party at a later date, in accordance with legal requirements, with follow-up questions about the success of our placement services. We process your data both as a job candidate and as an employer to fulfill our contractual obligations and to process the placement requests entrusted to us to the satisfaction of both parties involved. In doing so, we pseudonymize your data as a job candidate by removing personal data and providing an ID as a reference. We may log placement processes in order to be able to demonstrate the existence of the contractual relationship and consent of interested parties in accordance with legal accountability obligations (Art. 5 (2) GDPR). Your information will be stored for a period of three to four years if we need to evidence the original inquiry (e.g., to demonstrate the authorization to contact job candidates).
Types of data processed: Inventory data (e.g., names, addresses); contact data (e.g., email, telephone numbers); contract data (e.g., subject matter of contract, term, customer category); usage data (e.g., websites visited, interest in content, access times); meta, communication, and process data (e.g., IP addresses, timestamps, identification numbers, consent status); applicant data (e.g., personal information, postal and contact addresses, application documents and the information contained therein, such as cover letters, CVs, certificates, as well as further information regarding a specific position, coaching and mentoring, or voluntarily disclosed by applicants regarding their person or qualifications).
Data subjects: Customers and potential customers; applicants; prospects; users (e.g., website visitors, users of online services); business and contractual partners.
Purposes of processing: Contact inquiries and communication; administration and handling of inquiries; feedback (e.g., collecting feedback via online form); provision of our online offering and user-friendliness; provision of contractual services in recruiting, mentoring, coaching, and customer service; marketing.
Legal bases: Contract performance and pre-contractual inquiries (Art. 6 (1)(1)(b) GDPR).
3.4 Online Marketing
We use various social media platforms and service providers to, for example, advertise job openings of our customers or to support our advertising measures.
3.4.1 Social Media Channels
Our social media channels on Instagram, Facebook, and LinkedIn are used to get in touch with you and to inform you about our services and offers.
Types of data processed: Profile data (e.g., name, username, profile picture); interaction data (e.g., comments, likes, messages); meta, communication, and process data (e.g., IP addresses, timestamps, identification numbers, device information); usage data (e.g., websites visited, interest in content)
Data subjects: Applicants, prospects
Legal bases: Consent (Art. 6 (1)(1)(a)), Legitimate interests (Art. 6 (1)(1)(f) GDPR)
Service provider: Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, Parent company: Facebook, 1 Hacker Way, Menlo Park, CA 94025, USA
Privacy policy: https://privacycenter.instagram.com/policy
Data Processing Agreement: https://www.facebook.com/legal/Workplace_GDPR_Addendum
Third country transfer basis: Data Privacy Framework (DPF)
Service provider: Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, Parent company: Facebook, 1 Hacker Way, Menlo Park, CA 94025, USA
Privacy policy: https://www.facebook.com/privacy/policy/
Data Processing Agreement: https://www.facebook.com/legal/Workplace_GDPR_Addendum
Third country transfer basis: Data Privacy Framework (DPF)
Joint controllership (Facebook & Instagram)
There is joint responsibility between us and Meta Platforms Ireland Limited for the processing of Insights data (statistics on page views and interactions). You can view the agreement on this at the following link: https://www.facebook.com/legal/terms/page_controller_addendum
Service provider: LinkedIn Ireland Unlimited Company
Website: https://linkedin.com/
Privacy policy: https://linkedin.com/legal/privacy/eu
Data Processing Agreement: https://de.linkedin.com/legal/l/dpa
3.4.2 Meta Pixel
We use Meta Pixel from Meta Platforms, Inc. (Facebook and Instagram) to track the behavior of users who reach our websites via an advertisement. This allows us to evaluate the effectiveness of Facebook and Instagram ads for statistical and market research purposes and to optimize future advertising measures.
Service provider: Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, Parent company: Facebook, 1 Hacker Way, Menlo Park, CA 94025, USA
Website: https://www.facebook.com
Privacy policy: https://www.facebook.com/privacy/policy/
Opt-out option: https://www.facebook.com/settings?tab=ads
Data Processing Agreement: https://www.facebook.com/legal/Workplace_GDPR_Addendum
Third country transfer basis: Data Privacy Framework (DPF)
Types of data processed: Contact data (e.g., email, telephone numbers, company name); content data (e.g., entries in online forms); meta, communication, and process data (e.g., IP addresses, timestamps, identification numbers, consent status); usage data (e.g., browser types, websites visited (referrer), interest in content, access times)
Data subjects: Applicants, prospects
Legal bases: Consent (Art. 6 (1)(1)(a) GDPR), Legitimate interests (Art. 6 (1)(1)(f) GDPR)
3.4.3 Perspective
We use the Perspective service to provide mobile funnels used for lead generation, marketing campaigns, and recruiting activities.
Service provider: Perspective Software GmbH, Müggelstraße 22, 10247 Berlin
Website: https://www.perspective.co/
Privacy policy: https://www.perspective.co/de/datenschutzerklaerung
Types of data processed: Contact data (e.g., email, telephone numbers, company name); content data (e.g., entries in online forms); meta, communication, and process data (e.g., IP addresses, timestamps, identification numbers, consent status); inventory data (e.g., names, addresses)
Data subjects: Applicants, prospects
Legal bases: Legitimate interests (Art. 6 (1)(1)(f) GDPR)
3.5 Data Processing of Companies or Their Employees
Our services for you as a company aim to offer entrepreneurs and companies the widest possible selection of suitable applicants in order to successfully fill open vacancies. In doing so, we process your personal data (data relating to entrepreneurs only constitutes personal data when the entrepreneur is a natural person) or data of company employees. The respective companies or entrepreneurs may be in a contractual or pre-contractual relationship with us; in individual cases, however, we may also process data of companies and their employees when no such pre-contractual or contractual relationship exists.
3.5.1 Business Services
We process your data as our contractual and business partner, e.g., customers and prospects (collectively referred to as "contractual partners") within the framework of contractual and comparable legal relationships as well as associated measures and within the framework of communication with contractual partners.
We process your data to fulfill our contractual obligations in the provision of staffing services. This includes in particular the obligations to provide the agreed staffing services, any update obligations, and remedying performance issues. In addition, we process the data to safeguard our rights and for the purposes of the administrative tasks associated with these obligations as well as business organization. Furthermore, we process the data on the basis of our legitimate interests in proper and business-minded management and in security measures to protect our contractual partners and our business operations from misuse, endangerment of their data, secrets, information, and rights (e.g., involvement of telecommunications, transport, and other auxiliary services as well as subcontractors, banks, tax and legal advisors, payment service providers, or financial authorities). Within the framework of applicable law, we only pass on data of contractual partners to third parties to the extent that this is necessary for the aforementioned purposes or to fulfill legal obligations. Contractual partners are informed about further forms of processing, e.g., for marketing purposes, within the framework of this privacy policy.
Which data is required for the aforementioned purposes will be communicated to you before or in the context of data collection, e.g., in online forms, by special marking (e.g., colors) or symbols (e.g., asterisks or the like), or in person.
As a rule, we delete data after the expiry of statutory warranty and comparable obligations, i.e., generally after 4 years, unless the data must be retained for statutory archiving reasons. The statutory retention period is ten years for tax-relevant documents as well as for commercial books, inventories, opening balance sheets, annual financial statements, the work instructions required for understanding these documents, and other organizational documents and accounting vouchers, and six years for received commercial and business correspondence and copies of sent commercial and business correspondence. The period begins at the end of the calendar year in which the last entry was made in the book, the inventory, opening balance sheet, annual financial statement, or management report was prepared, the commercial or business correspondence was received or sent, or the accounting voucher was created, or the recording was made or the other documents were created.
To the extent that we use third-party providers or platforms for the provision of our services, the terms and conditions and privacy notices of the respective third-party providers or platforms apply in the relationship between users and providers.
3.5.2 Recruiting Services
See 3.3.2
3.5.3 Customer Advisory / Consulting
In addition, we process your data as our customers, clients, as well as prospects and other clients or contractual partners (uniformly referred to as "customers") in order to be able to provide them with our personnel consulting services within the framework of individual recruitings as well as in the full-service package. The processed data, the type, scope, purpose, and necessity of their processing are determined by the underlying contractual and customer relationship. If it is necessary for our contract performance, for the protection of vital interests, or legally required, or if customer consent exists, we disclose or transmit customer data to third parties or agents, such as authorities, subcontractors, or in the IT, office, or comparable services sector, in compliance with professional regulations.
Types of data processed: Inventory data (e.g., names, addresses); payment data (e.g., bank details, invoices, payment history); contact data (e.g., email, telephone numbers); contract data (e.g., subject matter of contract, term, customer category); usage data (e.g., websites visited, interest in content, access times); meta, communication, and process data (e.g., IP addresses, timestamps, identification numbers, consent status); applicant data (e.g., personal information, postal and contact addresses, application documents and the information contained therein, such as cover letters, CVs, certificates, as well as further information regarding a specific position or voluntarily disclosed by applicants regarding their person or qualifications).
Legal bases: Contract performance and pre-contractual inquiries (Art. 6 (1)(1)(b) GDPR).
4. Use of Cookies and Similar Technologies
4.1 General Information
Our website uses so-called "cookies". Cookies are small text files or other storage markers that store information on end devices and read information from end devices. For example, to store the login status in a user account, a shopping cart in an e-shop, or the content accessed or functions used of an online offering. Cookies can also be used for various other purposes, e.g., for the functionality, security, and comfort of online offerings as well as for the creation of analyses of visitor flows.
Information on consent: We use cookies in accordance with legal provisions. We therefore obtain prior consent from you as a user, unless this is not legally required. Consent is in particular not necessary when the storage and reading of information, including cookies, is strictly necessary to provide users with a telemedia service (i.e., our online offering) that they have expressly requested. The revocable consent is communicated clearly to users and contains information on the respective cookie use.
General information on revocation and objection: You can revoke the consents you have given at any time and also lodge an objection to the processing in accordance with the statutory provisions in Art. 21 GDPR. You can also declare your objection via your browser settings, e.g., by deactivating the use of cookies (which may also restrict the functionality of our online services). An objection to the use of cookies for online marketing purposes can also be declared via the websites https://optout.aboutads.info and https://www.youronlinechoices.com/.
We currently only use strictly necessary, technically required cookies. These are those that are exclusively required to capture certain information on our platforms in order to provide a service requested or desired by you as a user.
4.2 Cookies and Technologies We Use via Third-Party Providers
4.2.1 Plugins and Embedded Functions and Content
We integrate functional and content elements into our online offering that are obtained from the servers of their respective providers (hereinafter referred to as "third-party providers"). These can include, for example, graphics, videos, or maps (hereinafter uniformly referred to as "content").
We use the Mapbox map service and integrate the maps of this service. The data processed may include in particular IP addresses and location data of users.
Service provider: Mapbox Inc
Legal bases: Legitimate interests (Art. 6 (1)(1)(f) GDPR); If corresponding consent has been obtained, processing is carried out exclusively on the basis of Art. 6 (1)(a) GDPR and § 25 (1) TTDSG (German Telecommunications Telemedia Data Protection Act), insofar as the consent includes the storage of cookies or access to information in the user's end device (e.g., device fingerprinting) within the meaning of the TTDSG. Consent can be revoked at any time.
Website: https://www.mapbox.com/;
Privacy policy: https://www.mapbox.com/legal/privacy
Data Processing Agreement: https://cdn.prod.website-files.com/609ed46055e27a02ffc0749b/664566d2c410e5dbd4e1b7c7_6564ea7c56944fcdb871cc28_Form_of_Customer_DPA_(Nov%2C_2023).docx.pdf
Third country transfer basis: Data Privacy Framework (DPF)
Legal bases: Consent (Art. 6 (1)(1)(a) GDPR), contract performance and pre-contractual inquiries (Art. 6 (1)(1)(b) GDPR), legitimate interests (Art. 6 (1)(1)(f) GDPR).
5. Disclosure of Information
5.1 Transfer of Personal Data to Third Parties
In the course of our processing of personal data, it may happen that your personal data is transferred to or disclosed to other bodies, companies, legally independent organizational units, or persons. Recipients of this data may include, for example, service providers commissioned with IT tasks or providers of services and content that are integrated into a website. In such cases, we comply with legal requirements and in particular conclude corresponding contracts or agreements with the recipients of your data that serve to protect your data.
5.2 Data Processing in Third Countries
If we process your data in a third country (i.e., outside the European Union (EU), the European Economic Area (EEA)) or if processing takes place in the context of the use of third-party services or the disclosure or transfer of data to other persons, bodies, or companies, this will only occur in accordance with legal requirements.
Subject to express consent or contractually or legally required transfer, we process or have data processed only in third countries with a recognized level of data protection, contractual obligation through so-called standard contractual clauses of the EU Commission, in the presence of certifications, or binding internal data protection regulations (Arts. 44 to 49 GDPR, EU Commission information page: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection_de).
6. Use by Minors
United In Recruitment is committed to complying with all applicable laws and regulations regarding the collection, storage, and use of personal data of minors under 16 years of age.
If you are a parent or guardian and would like to review the data collected from your child or have this data changed or deleted, you can contact us as described below. If we find that a child has provided us with personal data in violation of applicable law, we will delete all personal data we have collected, unless we are legally required to retain it, and we will terminate the child's account.
7. Your Rights as a Data Subject
As a data subject, you have various rights under the GDPR, which derive in particular from Arts. 15 to 21 GDPR. If you wish to exercise any of these rights, you can log in to your customer account and edit certain account information, or assert your rights at privacy@blacksheep.black.
Right to object: You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data which is carried out on the basis of Art. 6 (1)(e) or (f) GDPR; this also applies to profiling based on these provisions. Where your personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of your personal data for such marketing; this also applies to profiling insofar as it is related to such direct marketing.
Right to withdraw consent: You have the right to withdraw consent given at any time.
Right of access: You have the right to obtain confirmation as to whether or not data concerning you is being processed and to receive information about this data as well as further information and a copy of the data in accordance with legal requirements.
Right to rectification: You have the right, in accordance with legal requirements, to request the completion of data concerning you or the rectification of incorrect data concerning you.
Right to erasure and restriction of processing: You have the right, in accordance with legal requirements, to request that data concerning you be erased without undue delay or, alternatively, to request a restriction of the processing of the data in accordance with legal requirements.
Right to data portability: You have the right to receive the data concerning you that you have provided to us in a structured, commonly used, and machine-readable format in accordance with legal requirements, or to request that it be transmitted to another controller.
Right to lodge a complaint with a supervisory authority: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement, if you consider that the processing of your personal data infringes the provisions of the GDPR.
Supervisory authority responsible for us:
State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia
Kavalleriestr. 2-4
40213 Düsseldorf
Phone: 0211/38424-0
Fax: 0211/38424-999
8. Contact Us
If you have questions about the processing of your data or about this privacy policy, please contact United In Recruitment by email at: privacy@blacksheep.black
Since email communication is not always secure, we ask you not to include credit card or other confidential information in your emails to us.