As of: September 2026

Data protection and data security for our business partners and consumers have always been a top priority for our company. That is why protecting your personal data throughout all our business processes is very important to us and a matter of particular concern. Respecting this right to privacy is a matter of course for us. In general, you are not required to provide personal data to use our website. However, in order for us to provide our services, we may need your personal data. In doing so, we collect, process, and use personal data to the extent permitted by law and necessary for the transaction, or if you have given your consent.

As the data controller, we—SCHUFA Holding AG, Kormoranweg 5, 65201 Wiesbaden—take all measures required by law to protect your personal data. You can contact our in-house data protection officer at the address listed above, attention: Data Protection Department, or by email at .

3.1. Accessing Our Website

When you visit our website, the browser on your device automatically sends information to our website’s server, where it is temporarily stored in a so-called log file. We have no control over this process. The following information is collected automatically—without any action on your part—and stored until it is automatically deleted:

  • the IP address of the requesting Internet-enabled device
  • the date and time of access
  • the name and URL of the retrieved file
  • the website or application from which the access originated (referrer URL)
  • the browser you are using and, if applicable, the operating system of your Internet-enabled computer, as well as the name of your Internet service provider.

We use your device's IP address and the other data listed above for the following purposes:

  • Ensuring a smooth connection setup,
  • To ensure a comfortable user experience on our website,
  • Assessment of system security and stability.

The data is stored for a period of 31 days and then automatically deleted. In addition, we use cookies, tracking tools, and social media plug-ins on our website. Chapters 7 and 9 explain in more detail exactly which technologies we use and how your data is used in this context.

3.2 Data Processing in Response to Inquiries from Data Subjects

We collect, process, and use personal data to the extent necessary to handle your request, for example, to process your application to initiate and conduct a mediation proceeding or to respond to general inquiries regarding your data record. In addition, we also process personal data in this context for internal purposes (e.g., updating our SCHUFA database or further developing and optimizing our processes based on the analysis of inquiries). For more information on the SCHUFA process, please visit .

3.3 Data Processing When Using the Contact Forms for (Prospective) Companies

Registration forms for SCHUFA events, SCHUFA webinars, contact forms used in marketing campaigns, and forms used when registering for and using our partner portal, SCHUFA4Business, as well as the SCHUFA Content Hub.

We collect, process, and use personal data to the extent necessary to handle your request (e.g., to provide you with access to the SCHUFA Partner Portal or the SCHUFA Content Hub) and to transfer it to our CRM system or to the user management system of the SCHUFA4Business Partner Portal. Furthermore, we use your data in connection with webinar registration to contact you by mail, phone, or email regarding interesting products and services offered by SCHUFA or by our partners. We also use your information as part of this process to update our SCHUFA database. For more information on the SCHUFA process, please visit .

3.4 Data Processing for Media Contacts

We collect, process, and use personal data to the extent necessary to provide the information published by our company or to respond to your request for contact. We also use your data to inform you via email or phone about company news, such as when sending out press releases. When we contact you, we take into account the relevance of our message as well as the thematic focus of your journalistic work.

3.5 Data Processing for Contests

For contests, we use your information to notify you if you win and to promote our offers. You can find detailed information in the rules for each contest, if applicable.

3.6 Processing of Applicant Data (e.g., when using our application form or at career fairs, etc.)

We collect, process, and use personal data to the extent necessary to process your application and to contact you as requested.

Once the retention period has expired, personal data is completely anonymized. The anonymized data is used exclusively for statistical analysis and to optimize our recruiting processes (e.g., process metrics, quality assurance). It is not possible to identify individual persons. The legal basis is our legitimate interest (Article 6(1)(f) of the GDPR) in the analysis, quality assurance, and optimization of our recruiting processes, as well as in the preparation of statistical analyses.

3.7 Data Processing in Connection with the SCHUFA IdentChecker

We need your data to provide the SCHUFA-IdentChecker product. We process the personal data you provide by comparing it against a database of data breaches and displaying the results of that comparison to you. Immediately after processing, the personal data is deleted.

3.8 Data Processing in Connection with the Consumer Self-Service Portal

If you have received a copy of your data pursuant to Article 15 of the GDPR or a SCHUFA credit report, you can log in to the Consumer Self-Service Portal by entering your SCHUFA ID (SCHUFA record number), your date of birth, and the document date, and submit correction requests to SCHUFA regarding inquiries made by SCHUFA’s contractual partners about you. When using the Consumer Self-Service Portal, you also have the option to provide your email address so that we can inform you of the processing status. In this case, we process your email address solely for the purpose of informing you about the processing status and the completion of the process. Your email address is stored for the duration of the processing. Once your request has been fully processed, it will be deleted.

If you would like to find out how long a payment default will remain on record in the SCHUFA database for your account, you can view the current retention period for the payment default in question by entering the case number of the default, your name, first name, gender, date of birth, address, and, if applicable, previous address, to view the current retention period for the payment default in question. The information you provide will be processed solely for the purpose of identification and displaying retention periods; in particular, it will not be transferred to the SCHUFA database and will be stored for a period of only 48 hours following your inquiry to verify and correct any potential technical errors.

3.9 Data Processing for Advertising Purposes and Market and Opinion Research

3.9.1 Marketing Purposes of SCHUFA Holding AG and Third Parties

If you have entered into a contract with us or if we have you on file as a prospective customer, we process your address information and advertising targeting criteria based on Article 6(1)(a) or (f) of the GDPR in order to send you such information and offers from us and other companies. If you do not wish to receive such communications, you may object to our use of your data for advertising purposes at any time.

3.9.2 Use of Data for Market Research and Opinion Polls

We also process your data for market and opinion research. We use this data exclusively in anonymized form for statistical purposes and only for SCHUFA Holding AG. Your survey responses will not be shared with third parties or published. We do not store the responses from our surveys together with your email address or other personal data. You may object to the use of your data for market and opinion research at any time, either in full or for specific activities, without incurring any costs other than the transmission costs according to standard rates. A written notice sent to the contact information listed below (e.g., email, fax, letter) is sufficient for this purpose. Of course, you will also find an unsubscribe link in every survey email.

3.9.3 Right to Object

You may object at any time to the use of your personal data for advertising purposes, either in general or with respect to specific measures, without incurring any costs other than the transmission costs charged at standard rates. Please send a written notice to SCHUFA Holding AG, Kormoranweg 5, 65201 Wiesbaden, or to , as well as by phone at +49 234 9761-200 or by fax at +49 611 9278-359, is sufficient for this purpose.

If you file an objection, the contact address in question will be blocked from further processing for advertising purposes. Please note that, in exceptional cases, you may still temporarily receive promotional material even after we have received your objection. This is due to the necessary lead time for advertisements and does not mean that we are not honoring your objection. Thank you for your understanding.

3.9.4 Personalization of Promotional Emails (Marketing Profiling)

If you have given us your consent to do so, we use automated processing methods to tailor the content of promotional emails to your interests (profiling). This processing is used exclusively for personalized advertising via email. The data is not used for any other purposes. The legal basis is your consent pursuant to Art. 6(1)(a) of the GDPR, which you may revoke at any time with future effect.

3.10 Data Processing in Connection with Complaints/Reports Under the Supply Chain Due Diligence Act (LkSG)

We collect, process, and use personal data to the extent necessary to handle your complaint or report in accordance with § 8 LkSG (e.g., to document your submission, to send a confirmation of receipt, or to clarify the facts in the event of follow-up questions).

3.11 Data Processing When Using Microsoft Teams

We use Microsoft Teams (hereinafter “Teams”) to conduct online meetings, presentations, training sessions, seminars, or similar events (hereinafter “meetings”) with customers, prospective customers, job applicants, service providers, or other external parties.

Teams is operated by: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18D18 P521, Ireland

Meetings are typically conducted via the Teams app, but can also be held through a web browser. As a general rule, meetings are not recorded. Recordings are made only in exceptional cases and only with the participants' consent.

A user can read the chat history after the fact and without having participated in a meeting, as long as the meeting was initiated from within a team and the user is a member of that team. Therefore, the chat history of meetings can generally be reviewed.

When using Teams, documents in various file formats (Word, PDF, etc.) can be shared and are visible to all members of the respective team or meeting.

3.12 Data Processing When Using the Trust Center

We operate a so-called Trust Center to transparently provide information on information security, data protection, and our compliance certifications and measures.

We use an external service provider (Vanta Inc., 55 Montgomery Street, Suite 1600, San Francisco, CA 94111, USA) to host and operate the Trust Center.

Personal data is processed to enable access to security-related documents (e.g., certifications, policies), to process inquiries from prospective customers, customers, and partners regarding security and data protection issues, to manage access to protected content (e.g., via access restrictions), and to ensure the IT security and integrity of the Trust Center.

Vanta acts on our behalf as a data processor in accordance with Article 28 of the GDPR. In certain cases, the transfer of personal data to the United States cannot be ruled out, such as when Vanta provides support or administrative services. To protect your data, Vanta uses the Standard Contractual Clauses approved by the European Commission pursuant to Article 46(2)(c) of the GDPR, as well as supplementary technical and organizational measures.

For more information about data protection at Vanta, please visit:

SCHUFA processes personal data in accordance with the provisions of the General Data Protection Regulation (GDPR) (including through service providers). Processing is based on consent (Art. 6(1)(a) of the GDPR) as well as on Art. 6(1)(b) and (f) of the GDPR, to the extent that processing is necessary for the performance of a contract to which the data subject is a party, or for taking steps prior to entering into a contract, or if the processing is necessary to protect the legitimate interests of the controller or a third party and does not override the interests or fundamental rights and freedoms of the data subject that require the protection of personal data. Processing operations carried out by SCHUFA in connection with a legal obligation applicable to it are based on Article 6(1)(c) of the GDPR. Based on Article 6(1)(f) of the GDPR, we also process your address data and advertising targeting criteria in order to send you such information and offers from us and other companies. If you do not wish to receive these, you may object to the use of your data for advertising purposes at any time. Consent may be withdrawn at any time by notifying SCHUFA. This also applies to consent that was granted prior to the GDPR coming into effect. Withdrawal of consent does not affect the lawfulness of the processing of personal data that took place prior to the withdrawal.

5.1 When data subjects submit online inquiries, we process the data necessary for this purpose. This includes the following categories:

Personal data, such as last name (including, where applicable, previous last names, which are disclosed upon separate request), first name, date of birth, place of birth, current address, previous addresses, as well as communication data and identification information.

5.2 In connection with data processing when using the contact forms for interested companies, registration forms for SCHUFA events and webinars, contact forms used in marketing campaigns, and during registration for and use of our contract partner portal SCHUFA4Business or the SCHUFA Content Hub, we process the data necessary for these purposes. This includes the following categories:

  • Person Master Data (Title, First Name, Last Name, Address, Position within the Company, Company Master Data)
  • Communication Data
  • Usage Data
  • Settlement Data
  • Marketing data (e.g., consents)
  • Login information (e.g., SCHUFA4Business)

When you participate in webinars we offer, our webinar system generates the following reports:

  • Analysis of the feedback forms (for questions, see the participant report)
  • Questions asked by participants during the session are saved. (Participants' questions are usually submitted in writing. The microphone is muted.)
  • Registration Date/Time
  • Duration of Participation
  • Interest/Attention (Assessment of whether the participant followed the event fully or was working on the side—percentage)
  • Events could be recorded. (This feature has rarely, if ever, been used so far.)
  • Companies that are not yet SCHUFA-VP members can also participate in webinars. (Special events for interested parties)

5.3 As part of our data processing activities related to sweepstakes, we process the following data:

  • Master Data for Individuals
  • Communication Data
  • Consent Data

5.4 As part of our applicant tracking system, we process the following data:

  • Personal Master Data (Last Name, First Name, Address)
  • Communication Data
  • Other information from the application materials (e.g., enrollment certificates, transcripts, marital status, etc.)

5.5 As part of the SCHUFA IdentChecker, we process the following data:

  • Email address
  • Credit card number
  • IBAN
  • ID card number
  • Passport number
  • Driver's license number
  • Cell phone number

5.6 As part of the personalization of promotional emails, we process the following data:

  • Communication data (e.g., email address)
  • Usage and response data related to emails (e.g., open and click behavior),
  • If applicable, additional information from an existing business relationship or from information you have provided.

5.7 In the context of media contacts, we process the following data:

  • Personal Master Data (Last Name, First Name)
  • Company Information (Media, Address)
  • Contact information (email address, phone number, department, position)

5.8 In connection with complaints or reports filed under the LkSG, we process the following data:

  • Personal Master Data (Title, Last Name, First Name)
  • Mailing address or email address

5.9 When using Microsoft Teams, we may process the following data:

The specific scope of the data also depends on what information is provided when using Teams.

  • User data: e.g., display name, email address. Profile information.
  • Meeting details: e.g., date, time, meeting ID, phone numbers, location
  • By using the chat feature, users can share text messages with other participants. The corresponding personal data is processed to the extent that it is contained in the text messages.

Audio and video data from the meetings are processed by Microsoft in its capacity as a telecommunications provider.

5.10 The following data may be processed in connection with the provision of the Trust Center:


  • Contact information (e.g., name, email address, company)
  • Access and usage data (e.g., IP address, time of access, content requested)
  • Communication data in connection with inquiries

All information you provide to us by entering it on these web pages is stored on a server located in a country within the European Union (“EU”) and forwarded to the appropriate departments within the company for the purpose of processing your inquiries and requests. If your personal data is used to update the SCHUFA database, this data will also be made available to contractual partners as part of SCHUFA’s services. For more information on the SCHUFA process, please visit .

Service providers we engage may also receive data from us for the purposes specified. These may include, for example, companies in the categories of IT services, printing services, marketing, sales, or telecommunications.

When conducting a mediation process, we forward the necessary personal data to the SCHUFA Ombudswoman.

7.1 Cookies – General Information

Cookies are small files that your browser automatically creates and that are stored on your device (laptop, tablet, smartphone, etc.) when you visit our website. Cookies do not cause any damage to your device and do not contain viruses, Trojan horses, or other malware. The cookie stores information that is specific to the device you are using.

The use of cookies may be either consent-free or subject to consent. Consent-free cookies are those that are necessary to use our online services or that serve the purpose of IT security (necessary cookies). The legal basis for data processing is Article 6(1)(f) of the GDPR. Cookies requiring consent, on the other hand, serve to make your use of our services more convenient (preference cookies). For example, we use cookies to recognize that you have already visited certain pages on our website or that you have already logged into your customer account. In addition, we also use temporary cookies for the purpose of user-friendliness, which are stored on your device for a specific, predetermined period of time. If you visit our site again to use our services, the system automatically recognizes that you have been here before and recalls the information and settings you previously entered, so you do not have to re-enter them.

In addition, we use cookies to collect statistical data on the use of our website, to analyze this data in order to optimize our offerings for you, and to display information tailored specifically to you (marketing and statistical cookies). The legal basis for data processing regarding cookies that require consent is Article 6(1)(a) of the GDPR. This data includes, among other things, page views, time spent on the site, referral source, country, etc. We analyze this statistical data to improve our offerings and assess the popularity of individual web pages. Invisible GIFs are used solely to position elements on the website. No other functions are associated with the invisible GIFs used. These cookies are stored by your browser and are typically deleted when you close the browser. Most browsers automatically accept cookies. However, you can configure your browser so that no cookies are stored on your computer or so that a notification always appears before a new cookie is created. Completely disabling cookies, however, may prevent you from using all features of our website. The storage duration of cookies depends on their intended use and varies from cookie to cookie.

We recommend that, when using shared computers that are configured to accept cookies, you always log out completely when you're finished.

You can view the cookies we currently use at any time , as well as quickly and easily manage any consents you may have provided.

7.2 Friendly Captcha (Bot/Spam Protection)

Our website uses the “Friendly Captcha” service ( ). This service is provided by Friendly Captcha GmbH, Am Anger 3-5, 82237 Wörthsee, Germany. Friendly Captcha is an innovative, privacy-friendly security solution designed to prevent automated programs and scripts (so-called “bots”) from using our website. To this end, we have integrated Friendly Captcha’s code into our website (e.g., for contact forms) so that the visitor’s device can establish a connection to Friendly Captcha’s servers to receive a computational task from Friendly Captcha. The visitor’s device solves the math problem—which consumes certain system resources—and sends the result to our web server. The web server then contacts the Friendly Captcha server via an interface and receives a response indicating whether the puzzle was solved correctly by the device. Depending on the result, we can apply security rules to requests made through our website and, for example, process them further or reject them. The data is used exclusively for the purpose of protecting against spam and bots, as described above. Friendly Captcha does not set or read any cookies on the visitor’s device. IP addresses are stored only in hashed (one-way encrypted) form and do not allow us or Friendly Captcha to identify any individual. If personal data is stored, it is deleted within 30 days. The legal basis for this processing is our legitimate interest in protecting our website from unauthorized access by bots, including protection against spam and attacks (e.g., mass requests), pursuant to Article 6(1)(f) of the GDPR. For more information on data protection when using Friendly Captcha, please visit

7.3 CDN (Content Delivery Network)

For the purpose of delivering and providing our website, its content is delivered via a so-called CDN (Content Delivery Network), depending on the user’s location. A CDN serves to ensure security and distribute load during the operation of the website. In this context, the data described in Section 3.1 (Visiting Our Website)—such as the IP address—may also be processed for the aforementioned purposes when you visit our website. Similarly, depending on the user’s location, we may also process the data described above in other third countries outside the EEA, including third countries without an adequacy decision.

7.4 etracker

Our website uses the “etracker” service provided by etracker GmbH, Erste Brunnenstraße 1, 20459 Hamburg (https://www.etracker.com) to analyze usage data. etracker cookies are also used for this purpose. The data generated by etracker is processed and stored exclusively in Germany by etracker on our behalf.

Data processing as part of the consent-based etracker cookie solution is carried out on the basis of consent in accordance with Article 6(1)(a) of the GDPR and Section 25(1), sentence 1, of the TTDSG. A more detailed description of consent-based data processing can be found in the description in the cookie management section.

Further data processing in connection with the etracker services used is carried out on the basis of legitimate interest pursuant to Art. 6(1)(f) of the GDPR. The purpose of data processing based on legitimate interest is to optimize our online offerings and our website. Data that could potentially be linked to an individual, such as IP addresses, login IDs, or device identifiers, is anonymized or pseudonymized as soon as possible. Such data is not used for any other purpose, combined with other data, or disclosed to third parties.

You can object to the data processing described above at any time by clicking the slider. Objecting will not result in any adverse consequences. If no slider is displayed, data collection has already been prevented by other blocking measures.

For more information about etracker's privacy policy, please visit .

We use the services of HubSpot Germany GmbH, Am Postbahnhof 17, 10243 Berlin, for managing contactand customer relationships (CRM), to carry out double-opt-in processes, to manage newsletters and subscription services, and—provided you have given your consent—to send and personalize promotional emails via the “HubSpot Enterprise Customer Platform.”

HubSpot acts on our behalf as a data processor in accordance with Article 28 of the GDPR. The processing of personal data for CRM and service, service, and transactional purposes is carried out to fulfill contractual or precontractual measures pursuant to Article 6(1)(b) of the GDPR or on the basis of our legitimate interests pursuant to Article 6(1)(f) of the GDPR.

The use of data processed in HubSpot for the purposes of marketing personalization (profiling) is based solely on your consent pursuant to Article 6(1)(a) of the GDPR and is limited to the purposes described in Section 3.9.4.

In certain cases, the transfer of personal data to the United States cannot be ruled out, such as when HubSpot provides support or administrative services. To protect your data, HubSpot uses the Standard Contractual Clauses approved by the European Commission pursuant to Article 46(2)(c) of the GDPR, as well as supplementary technical and organizational measures.

For more information about HubSpot's privacy policy, visit:

SCHUFA is active on social media to provide information, communicate with interested individuals, and offer insights into our activities. The platforms we currently use include, in particular, Facebook, Instagram, TikTok, LinkedIn, and Bluesky.

When using these platforms, personal data is processed both by us, as the operators of the respective accounts, and by the respective platform operators.

Below, we provide information about data processing in connection with our social media presence and explain which privacy policies from the respective platform operators you can access for additional details.

9.1 Facebook

We operate the Facebook page Below, we provide information about how we and Meta Platforms Ireland Limited (4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland—hereinafter “Meta”), the operator of Facebook, process your personal data in this context.

Joint controllership pursuant to Article 26 of the GDPR: We are jointly responsible with Meta for certain data processing activities related to so-called Page Insights features. This data includes, for example, your IP address and your interactions with our page (e.g., “Likes,” comments). The joint controller agreement can be found at:

Purposes of processing:

  • Providing and optimizing the content on our Facebook page,
  • Analysis of user behavior using Facebook Insights for market research, advertising purposes, and the placement of targeted ads
  • Processing inquiries and
  • Getting in touch.

Legal Basis: The processing of personal data is based on your consent pursuant to Article 6(1)(a) of the GDPR, provided that you have given such consent. For the use of Facebook Insights, we rely on our legitimate interest pursuant to Article 6(1)(f) of the GDPR, in particular our interest in optimizing our content and reach. Details regarding the processing of your data by Meta can be found in Facebook’s Privacy Policy at

Data Transfer: Meta may transfer data to third countries (e.g., the U.S.) and states that it takes appropriate safeguards in accordance with Art. 44 et seq. of the GDPR.

9.2 Instagram Account

We operate the Instagram account The provider is Meta Platforms Ireland Limited (4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland), and we are jointly responsible with Meta for certain processing activities. In this regard, reference can essentially be made to the information provided regarding the Facebook page (see Section 8.1 of this Privacy Policy).

Purposes of processing:

  • Posting and optimizing content on our Instagram page,
  • Communication with Prospective Clients
  • Statistical analyses (aggregated usage data from Meta).

Legal Basis: The processing of personal data is based on your consent pursuant to Article 6(1)(a) of the GDPR, provided that you have given such consent. For the use of Instagram Analytics, we rely on our legitimate interest pursuant to Article 6(1)(f) of the GDPR, in particular our interest in optimizing our content and reach. Details regarding the processing of your data by Meta can be found in Instagram’s Privacy Policy at https://privacycenter.instagram.com/policy.

For more information, please visit:

9.3 TikTok

We operate the TikTok account Below, we provide information regarding the processing of your personal data in this context by TikTok Inc., 10100 Venice Blvd., Culver City, CA 90232, USA (“TikTok”).

Joint controllership pursuant to Article 26 of the GDPR: To the extent that we receive aggregated statistics (“TikTok Insights”) from TikTok regarding the use of our profile, joint controllership applies. This data does not allow us to identify individual users.

Purposes of processing:

  • Analysis of user behavior to optimize our offerings,
  • Communication with Prospective Clients
  • Measuring the reach of our content and marketing it.

Legal Basis: For the use of TikTok Insights, we rely on our legitimate interest pursuant to Article 6(1)(f) GDPR, in particular our interest in conducting data analyses and statistically tracking the use of our TikTok profile, in optimizing our offerings for you, in promoting our posts and videos on our website, and in continuously improving and managing our offerings and services.

Data Transfer: TikTok may also transfer personal data to third countries (in particular, the United States) and states that it takes appropriate safeguards in accordance with Art. 44 et seq. of the GDPR.

For more information about data processing, please see TikTok's Privacy Policy at:

9.4 YouTube

We operate the YouTube channel YouTube LLC is operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”).

When you visit our YouTube channel, Google processes your personal data as an independent data controller. This includes, in particular, your connection data (e.g., IP address, information about your device, browser type and settings, operating system, mobile network, and app version), as well as your usage behavior on YouTube (e.g., videos watched, search terms, and interactions).

If you are logged in to YouTube during your visit, this data may be associated with your profile. Please note that we do not have full control over the data processed by Google or its further use.

Purposes of processing:

  • Delivery and Optimization of Our Video Content
  • Communication with Prospective Clients
  • Measuring reach and marketing our content.

Legal Basis: The processing of your data in connection with your use of our YouTube channel is based on our legitimate interest (Article 6(1)(f) of the GDPR) in effective communication and interaction with users, as well as in optimizing our video content.

Data Transfer: Google may transfer your data to countries outside the EU/EEA, particularly the United States. Google states that it takes appropriate safeguards in accordance with Article 44 et seq. of the GDPR.

For more information about Google's data processing practices, please see Google's Privacy Policy:

9.5 LinkedIn

We maintain a company profile on LinkedIn. The provider is LinkedIn Ireland Unlimited Company (“LinkedIn”), Wilton Plaza, Wilton Place, Dublin 2, Ireland.

When you visit our LinkedIn profile, LinkedIn processes your personal data as an independent data controller. This includes, in particular, connection data (e.g., IP address, device information) as well as information about your usage behavior on LinkedIn. If you are logged into LinkedIn during your visit, this data may be associated with your profile.

Joint controllership pursuant to Article 26 of the GDPR: To the extent that we receive aggregated statistics (“Page Analytics”) from LinkedIn regarding the use of our company profile, we are joint controllers. This data does not allow us to identify individual users. The joint controller agreement can be found at: https://legal.linkedin.com/pages-joint-controller-addendum.

Purposes of processing:

  • Delivery and Optimization of Our Content
  • Communication with Prospective Clients
  • Analysis of Aggregated Usage Statistics

Legal basis: Processing is based on our legitimate interest, pursuant to Article 6(1)(f) of the GDPR, in effective communication with users and in optimizing our LinkedIn presence.

Data Transfer: LinkedIn may also transfer personal data to third countries (in particular, the United States) and states that it takes appropriate safeguards in accordance with Art. 44 et seq. of the GDPR.

For more information about LinkedIn's data processing, please see LinkedIn's Privacy Policy:

9.6 Bluesky

We operate the Bluesky website The provider is Bluesky PBLLC, 548 Market St, PMB 78725, San Francisco, CA 94104, USA (“Bluesky”).

When you visit our Bluesky profile, Bluesky processes your personal data as an independent data controller. This includes, in particular, connection data (e.g., IP address, device information) as well as information about your use of the platform.

Purposes of processing:

  • Delivering and Optimizing Our Content on Bluesky
  • Communication with Interested Parties
  • Analysis of Aggregated Usage Statistics

Legal Basis: Processing is based on our legitimate interest, pursuant to Article 6(1)(f) of the GDPR, in optimizing our content and communication with users. To the extent that Bluesky uses cookies or similar technologies, the processing is based on your consent in accordance with Article 6(1)(a) of the GDPR.

Data Transfer: Bluesky may also transfer personal data to third countries (in particular, the United States) and states that it takes appropriate safeguards in accordance with Art. 44 et seq. of the GDPR.

For more information about Bluesky's data processing practices, please see Bluesky's Privacy Policy:

9.7 Exercising Your Rights as a Data Subject

To the extent that joint controllership exists pursuant to Article 26 of the GDPR, we recommend that you primarily exercise your rights (Articles 15 et seq. of the GDPR) with the respective platform operator, as that operator typically has direct access to the relevant data.

However, you can also contact us at any time. In that case, we will forward your request to the relevant provider.

We generally store your data only for as long as is necessary for the specific purpose of data processing (e.g., handling your request or complying with statutory retention periods).

We store the data collected for contract processing until the expiration of any statutory or contractual warranty and guarantee rights. After this period expires, we retain the information regarding the contractual relationship required under commercial and tax law for the periods specified by law. During this period (typically ten years from the conclusion of the contract), the data will be processed again solely in the event of an audit by the tax authorities.

We initially store the data collected for registration on SCHUFA4Business until the account is deactivated. This can be done by the user or occurs automatically after 120 days have elapsed, provided the user has not actively visited the portal during this period, or upon termination of the contractual relationship. The personal data is then deleted exactly one year after the account is deactivated.

All data related to the conduct of a conciliation proceeding is generally retained for up to ten years.

The duration of data retention for advertising purposes does not follow any rigid principles and is determined by whether the retention is necessary for advertising purposes. In addition, we follow the principle of deleting data used for advertising purposes 4 years after the end of the contract or 4 years after the end of marketing efforts. Objections to advertising are not deleted.

We store the data we process as part of the recruitment process for up to 6 months after the application process is completed.

In cases where there are particularly compelling reasons, we may also store data for longer periods, such as when a government agency requires it or when the data is needed for legal reasons—for example, to present evidence in a court proceeding.

We transfer your data to contractual and business partners located in other third countries (provided that a corresponding adequacy decision by the European Commission exists for those countries or that standard contractual clauses have been agreed upon, which can be viewed at www.schufa.de). SCHUFA is also subject to the statutory powers of intervention by government agencies.

12.1 Overview

In addition to the right to revoke the consents you have granted us, you are entitled to the following additional rights, provided the respective legal requirements are met:

  • Right to access your personal data stored by us pursuant to Article 15 of the EU GDPR,
  • Right to rectification of inaccurate data or to have complete data corrected in accordance with Article 16 of the EU GDPR,
  • Right to erasure of your data stored by us pursuant to Art. 17 of the EU GDPR,
  • Right to restrict the processing of your data pursuant to Article 18 of the EU GDPR,
  • Right to data portability pursuant to Article 20 of the EU GDPR.

SCHUFA has set up a Private Customer Service Center to handle your specific inquiry. You can contact the center in writing at SCHUFA Holding AG, Private Customer Service Center, P.O. Box 10 34 41, 50474 Cologne, by phone at +49 611 9278-0, and online via an inquiry form ( ). In addition, you have the option of contacting the supervisory authority responsible for SCHUFA, the Hessian Commissioner for Data Protection and Freedom of Information.

12.2 Right to Object

Under the conditions set forth in Article 21(1) of the GDPR, an individual may object to data processing for reasons arising from their specific situation (e.g., women’s shelters, witness protection). The objection may be submitted in any form and may be addressed, for example, to SCHUFA Holding AG, Privatkunden ServiceCenter, P.O. Box 10 34 41, 50474 Cologne.

The general right to object described above applies to all processing purposes described in this Privacy Notice that are carried out on the basis of Article 6(1)(f) of the GDPR. Unlike the specific right to object to data processing for advertising purposes, under the GDPR we are only obligated to honor such a general objection if you provide us with compelling reasons (e.g., a potential threat to life or health). In addition, you have the option of contacting the supervisory authority responsible for SCHUFA, the Hessian Commissioner for Data Protection and Freedom of Information.

All data you personally submit is transmitted using the widely accepted and secure TLS (Transport Layer Security) standard. TLS is a secure and proven standard that is also used, for example, in online banking. You can recognize a secure TLS connection by, among other things, the “s” appended to “http” (i.e., https://...) in your browser’s address bar or by the padlock icon at the bottom of your browser.