Privacy Policy

General Information

The protection of your personal data is a high priority for our organisation. This policy explains how we handle your data when you visit our website, our social media channels, communicate with us via e-mail or use our services. 

The term „personal data” (or “Data”) comprises all data that can be used to personally identify you, either directly (such as your first and last name, your email address or your telephone number), or indirectly (such as cookie identifier or technical data).

The following information will provide you with an overview of which personal data, how it is collected as well as the purposes we use this Data for when you visit this website.

  • Data controller: Proks Certification GmbH, Breite Str. 27, 40213 Düsseldorf. 
  • Data Protection Officer: Arthur Almeida, arthur@proks-cert.de

Data Collection on This Website

When visiting this website, certain technical data from your device is automatically processed. This information is transmitted by your browser to our web server in order to enable the delivery of the website and to ensure its proper functioning, security, and stability. In this context, we may process such as the IP address of the requesting device, date and time of access, referrer URL (the previously visited page), browser type and version and operating system. 

The processing of this data is necessary to provide the website to you and to safeguard our IT systems against misuse and technical disruptions. The legal basis for this processing is Article 6(1)(f) GDPR, as it serves our legitimate interest in maintaining the security, integrity, and functionality of our online services.

The information is stored in server log files and is not combined with other data sources. Log data is retained only for as long as required to achieve the purposes described above and is routinely deleted thereafter.

The following service providers act as data processors and process your personal data under our instructions with the exclusive purposes explained above: 

  • Webflow, Inc., 398 11th St., Fl 2, San Francisco, CA 94103, USA acts in hosting of the website and the Content Delivery Network (CDN)
  • GoDaddy.com, LLC, 100 S. Mill Ave, Suite 1600, Tempe, AZ 85281, USA is used for DNS routing

The transfer of data to a third country (in this case, the United States of America) is based on the European Commission’s adequacy decision for the EU-U.S. Data Privacy Framework (DPF) pursuant to Article 45 GDPR. Both Webflow and GoDaddy are certified under the DPF. Should this decision be invalidated at any point in the future, we also rely on the European Commission’s Standard Contractual Clauses pursuant to Article 46(2)(c) GDPR, which we have closed with the service provider,  and, where required, conduct a transfer impact assessment and implement supplementary safeguards.

Contact Form

Our website offers a contact form. Any personal data shared through this form is processed by us for the purposes of responding to your contact request. The legal basis for the processing is our legitimate interest to respond to contacts made through our website (Art. 6 para. 1 s. 1 lit. f GDPR). 

When you contact us, the following service providers are involved in processing your personal data: 

  • Webflow (Webflow, Inc., 398 11th St., Fl 2, San Francisco, CA 94103, USA) is used to temporarily process and route contact form submissions
  • GMail (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) is the provider of the e-mail system used to process incoming requests and customer communications. 

Storage of data

Unless this Privacy Policy provides otherwise, we retain personal data only for as long as it is necessary to fulfil the respective purpose for which it was collected. Once that purpose ceases to apply, the data will be erased, provided that no statutory retention obligations require continued storage. 

Where deletion is not possible due to legal requirements or other permissible grounds, the data will not be used for unrelated purposes. Instead, their processing will be limited to what is strictly necessary, meaning the data will be restricted and effectively blocked from further active use. 

Cookies and similar technologies

This website uses cookies and similar technologies (e.g., local storage). If you opt-in to cookies and tracking, we use cookies to offer you a range of features and to make our websites more convenient to use. Cookies are small files that your web browser stores on your computer when you visit our website. You can opt-in and -out of cookies at any time by reviewing the options in the cookie banner. 

Essential cookies are cookies that are technically necessary to provide the website and its core functionalities (e.g. page navigation, security features, load balancing, or saving consent preferences). The storage of, or access to, information on the user’s terminal equipment in this context is carried out on the basis of § 25(2) No. 2 TDDDG, as it is strictly necessary to provide the telemedia service explicitly requested by the user. Where personal data is processed in connection with such cookies, the legal basis under data protection law is Article 6(1)(f) GDPR, reflecting our legitimate interest in ensuring the secure, stable, and functional operation of our website.

Optional cookies (e.g. analytics, marketing, or personalization cookies) are not required for the basic operation of the website. These technologies are used solely on the basis of the user’s prior consent. The legal basis for storing or accessing information on the user’s terminal equipment is § 25(1) TDDDG. Any subsequent processing of personal data is based on Article 6(1)(a) GDPR, i.e. the user’s consent, which may be withdrawn at any time with effect for the future.

To see more details about the concrete cookies used on the website, you can click on “see details” on the cookie banner. 

Your Rights

Under the GDPR, you have the following rights regarding your personal data:

  • Access: You can ask for a copy of your data.
  • Rectification: You can ask to correct inaccurate data.
  • Erasure: You can ask to delete your data ("Right to be forgotten").
  • Restriction: You can ask to limit how we use your data.
  • Data Portability: You can request your data in a machine-readable format.
  • Objection: You can object to processing based on legitimate interests. 
  • Withdrawal: You can withdraw a previously shared consent at any time

To exercise these rights, please contact us at the address listed above.

Right to Lodge a Complaint

If you believe your privacy rights have been violated, you have the right to lodge a complaint with a data protection supervisory authority, particularly in the Member State of your habitual residence (e.g., a state DPA in Germany). For our organisation, the competent supervisory authority is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestr. 2-4, 40213 Düsseldorf, E-Mail: poststelle@ldi.nrw.de

Third Party Tools on the Website

Google Analytics 

We use Google Analytics, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics helps us understand how visitors use our website, measure website performance, improve the structure and content of our pages, and evaluate the effectiveness of our online communication and marketing activities. In this context, information such as cookie identifiers, device and browser information, approximate location, pages visited, time of visit and interaction data may be processed. Google acts as a data processor for Google Analytics and processes personal data on our behalf and under our instructions, subject to the applicable Google Analytics terms and settings. 

Google Analytics is only used if you have given your consent through the cookie banner. The legal basis for storing or accessing information on your device is § 25(1) TDDDG. The legal basis for the subsequent processing of personal data is Article 6(1)(a) GDPR. You may withdraw your consent at any time with effect for the future through the cookie settings available on our website. Data collected through Google Analytics is retained only for as long as necessary for the above purposes and is deleted or anonymised thereafter, unless longer retention is required by law. Further information can be found in the Google Privacy Policy and the Google Analytics privacy information: https://policies.google.com/technologies/partner-sites

The transfer of data to a third country (in this case, the United States of America) is based on the European Commission’s adequacy decision for the EU-U.S. Data Privacy Framework (DPF) pursuant to Article 45 GDPR. Google is certified under the DPF. Should this decision be invalidated at any point in the future, we also rely on the European Commission’s Standard Contractual Clauses pursuant to Article 46(2)(c) GDPR, which we have closed with the service provider,  and, where required, conduct a transfer impact assessment and implement supplementary safeguards.

CookieYes

We use CookieYes (CookieYes Limited, 3 Warren Yard, Warren Park, Wolverton Mill, Milton Keynes, MK12 5NW, United Kingdom) as a consent management platform for our website. CookieYes enables us to display the cookie banner, obtain and manage user consent, document consent choices, and allow users to change their cookie preferences at a later time. In this context, CookieYes may process information such as consent status, consent ID, IP address, browser and device information, date and time of consent, and the selected cookie categories. CookieYes processes such data as a service provider acting on our behalf and under our instructions for the purpose of providing the consent management function. 

The use of CookieYes is necessary to manage legally required cookie choices and to document consent decisions. The legal basis for the processing of personal data is Article 6(1)(f) GDPR, based on our legitimate interest in operating a compliant and transparent consent management process. Where CookieYes is used to store or access information on your terminal equipment in order to save your consent preferences, this is based on § 25(2) No. 2 TDDDG, as this function is necessary to provide the consent management service requested by the user. Data processed through CookieYes is retained only for as long as necessary to document and manage consent choices and is deleted thereafter, unless statutory retention obligations require longer storage. Further information can be found in the CookieYes Privacy Policy: https://www.cookieyes.com/privacy-policy/

The transfer of data to a third country, in this case the United Kingdom, is based on the European Commission’s adequacy decision for the United Kingdom pursuant to Article 45 GDPR. 

AuditOne

We use AuditOne (AuditOne GmbH, Im Mediapark 5, 50670 Cologne, Germany) to process audit application forms, certification-related requests, offers, contracts, and related pre-contractual or contractual information submitted by customers or their contact persons. If you complete an application form or submit information through the AuditOne platform, the information provided may include your name, business contact details, job title, company information, certification scope information, and other information necessary to evaluate the request and prepare or manage the certification process. AuditOne processes such data as a service provider acting on our behalf and under our instructions for the purpose of providing the application, workflow, contract and certification administration functions. 

The legal basis for this processing is Article 6(1)(b) GDPR where the processing is necessary for pre-contractual steps or the performance of a contract with the customer or its representatives. Where the processing concerns communication with contact persons of a business customer, the legal basis may also be Article 6(1)(f) GDPR, based on our legitimate interest in communicating with customers, managing certification requests, and conducting commercial interactions in a structured and traceable manner. Data processed through AuditOne is retained only for as long as necessary for the respective pre-contractual, contractual, audit, certification, legal or documentation purposes and is deleted or restricted thereafter, unless statutory retention obligations require longer storage. 

Social media

LinkedIn

We maintain a company profile on LinkedIn (LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland)  in order to present our organisation, communicate with interested persons, share information about our services, and enable professional interaction. If you visit or interact with our LinkedIn page, LinkedIn may process personal data such as your profile information, interactions with our posts, messages, comments, and technical information about your use of the platform. The primary responsibility for the operation of the LinkedIn platform lies with LinkedIn. LinkedIn provides its own privacy information and determines many aspects of the processing carried out on the platform. For certain statistical information relating to visitors of LinkedIn pages, LinkedIn provides Page Insights and states that LinkedIn and the organisation operating the page may act as joint controllers within the meaning of the GDPR.

We process personal data received through LinkedIn for the purpose of responding to messages or comments, maintaining professional communication, and providing information about Proks Certification GmbH. The legal basis is Article 6(1)(f) GDPR, based on our legitimate interest in professional external communication and public presentation of our organisation. If communication through LinkedIn relates to a contractual or pre-contractual request, Article 6(1)(b) GDPR may also apply. Data that we receive directly through LinkedIn is retained only for as long as necessary for the respective communication or business purpose and is deleted thereafter, unless legal retention obligations apply. Further information about LinkedIn’s processing of personal data can be found in the LinkedIn Privacy Policy (https://www.linkedin.com/legal/privacy-policy) and, where applicable, the LinkedIn Page Insights Joint Controller Addendum (https://www.linkedin.com/legal/l/page-joint-controller-addendum

Data processing during the use of our services and further commercial interaction with us

If you contact us regarding our services, request information, submit an audit or certification application, negotiate contractual terms, receive an offer, or enter into a certification contract with us, we process the personal data necessary for the respective communication, pre-contractual, contractual and administrative purposes. Since our customers are generally organisations, the personal data processed in this context usually relates to contact persons, representatives, employees or other persons acting on behalf of the customer.

The data processed may include name, business contact details, job title, organisation, communication content, information provided in application forms, offer and contract information, signature data, billing-related information, and any other personal data that is provided to us in connection with the request, negotiation, offer, contract or certification process. The purposes of the processing are to respond to enquiries, assess certification requests, prepare offers, discuss and conclude contracts, manage customer relationships, document commercial decisions, and administer the services requested by the customer.

The legal basis for this processing is Article 6(1)(b) GDPR where the processing is necessary for pre-contractual steps or for the performance of a contract. Where the data relates to contact persons of a business customer and the contract itself is concluded with the organisation, the legal basis may also be Article 6(1)(f) GDPR, based on our legitimate interest in communicating with business customers, managing contractual relationships, and documenting commercial interactions. Where we are legally required to retain certain information, the legal basis is Article 6(1)(c) GDPR.

For e-mail communication, we use Gmail / Google Workspace provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google processes personal data as a service provider on our behalf for the purpose of providing e-mail and related communication services. For audit application forms, offer and contract workflows, and related certification administration, we use AuditOne as described above. These service providers process personal data under our instructions and only for the purposes of providing the relevant technical or organisational service.

Personal data processed in the context of enquiries, offers, contracts and customer communication is retained only for as long as necessary for the respective communication, pre-contractual or contractual purpose. Where statutory retention obligations apply, the relevant data will be retained for the legally required period and then deleted or restricted.

Further information about the processing of personal data during and after the audit and certification process is provided as an attachment to the certification contract. When Proks Certification GmbH performs audit and certification activities, it acts as an independent controller for the personal data processed in that context. Proks Certification GmbH does not act as a data processor on behalf of the certified organisation when conducting independent audit and certification activities. This reflects the independent nature of certification activities and the requirement that certification decisions and audit conclusions are made independently.

Auditor applications and unsolicited applications

Our website includes an application form for individuals who are interested in working with Proks Certification GmbH as auditors or audit-related experts. If you submit this form, we process the personal data you provide for the purpose of reviewing your profile, assessing your qualifications and areas of expertise, communicating with you about possible cooperation, and determining whether your profile may be suitable for future audit or certification-related activities.

The data processed in this context may include your name, e-mail address, telephone number, years of audit experience, standards or areas of expertise, professional background, and any further information you voluntarily provide in the free-text field or in documents submitted to us, such as a resume, certificates or other supporting information. Please do not include sensitive personal data in your application unless it is relevant and necessary for the assessment of your profile.

The legal basis for this processing is Article 6(1)(b) GDPR where the processing is necessary in order to take steps prior to entering into a possible contractual or cooperation relationship with you. If we ask for your consent to retain your profile for future opportunities, the legal basis is Article 6(1)(a) GDPR. You may withdraw such consent at any time with effect for the future.

If you send us an unsolicited application for another position, either by e-mail or through the auditor application form, we will process the personal data provided for the purpose of reviewing your submission and, where applicable, responding to you or considering whether your profile may be relevant for current or future opportunities. The legal basis is § 26 BDSG and Article 6(1)(b) GDPR where the processing relates to a possible employment relationship, and Article 6(1)(f) GDPR where the processing relates to general business communication or possible freelance, external or cooperation arrangements.

Application and profile data is retained only for as long as necessary for the review and communication process. If no cooperation, contractual relationship or employment relationship is established, we delete or restrict the data after 6 months have passed since the rejection, unless you have consented to longer retention for future opportunities or we are legally required to retain the data for a longer period.

No automated decision-making

We do not use any type of fully automated decision-making processes, as these are described in Article 22 of the GDPR. If we do apply such processes in exceptional cases, clear information will be provided separately. 

International Data Transfers

We may transfer personal data to recipients located outside the European Union (EU) or the European Economic Area (EEA) (“third countries”) where this is necessary for the provision of our services, for example when using external service providers or data processors based in countries such as the United States.

In such cases, we ensure that an adequate level of data protection is maintained in accordance with the General Data Protection Regulation. Where the European Commission has issued an adequacy decision for the respective third country, data transfers are based on this decision.

In the absence of an adequacy decision, we rely on appropriate safeguards, in particular the conclusion of Standard Contractual Clauses (SCCs) adopted by the European Commission. These clauses contractually oblige the data recipient to comply with European data protection standards. In particular, they impose strict obligations regarding the protection of personal data, including requirements to implement appropriate technical and organizational security measures, to process data only on documented instructions, to ensure enforceable data subject rights, and to provide effective legal remedies. Furthermore, recipients are required to assess and, where necessary, mitigate any risks arising from local laws that may affect the level of data protection, thereby ensuring that the transferred data remains protected in a manner essentially equivalent to that guaranteed within the EU.

Security Measures

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk associated with the processing of personal data.

These measures include, in particular, the use of encryption technologies (e.g. HTTPS/SSL) for data transmission, access controls to restrict unauthorized access to our systems, regular updates and maintenance of our IT infrastructure, and the careful selection and monitoring of service providers. Furthermore, we apply internal policies and procedures designed to ensure the confidentiality, integrity, availability, and resilience of our systems and services.

Taking into account the state of the art, the costs of implementation, as well as the nature, scope, context, and purposes of processing and the varying likelihood and severity of risks to the rights and freedoms of natural persons, we implement measures designed to ensure a level of protection appropriate to the risk, in accordance with Article 32 of the General Data Protection Regulation.

Updates to this Privacy Policy

We reserve the right to amend this Privacy Policy at any time in order to ensure its continued compliance with applicable legal requirements or to reflect changes in our services or data processing activities. The version made available on this website is the current and applicable version.