General – Information according to Art. 13 + 14 GDPR
BioGenes is pleased that you have decided to visit our website and are interested in our company and products. We treat the protection of your personal data seriously and strive to ensure that you feel secure and comfortable when visiting our Internet pages.
Due to statutory provisions we are obliged to inform you about the type, scope and purpose of the collection and use of personal data. Therefore we would kindly ask you to acknowledge the following information. This Privacy Statement describes and governs the information collection, use, and sharing practices of BioGenes GmbH and its corporate affiliates (collectively "BioGenes", "we", "us," and "our") with respect to BioGenes' websites, mobile applications and other digital and interactive services that link to this Privacy Statement (together, the "Services").
Before you submit any information on or through the Services, please carefully read this Privacy Statement. By using any part of the Services, you consent to the collection, use and disclosure of your information as further outlined in this Privacy Statement.
Without prejudice to your rights under applicable law, BioGenes reserves the right to amend this Privacy Statement without prior notice to reflect technological advancements, legal and regulatory changes, good business practices and any update or expansion of the Services. If BioGenes changes its privacy practices, an updated version of this Privacy Statement will reflect those changes and we will notify you of such changes by updating the effective date at the top of this Privacy Statement. Therefore please check this page periodically for updates. Your continued use of the Services will signify acceptance of the terms of the updated Privacy Statement.
Intended use of data processing
Wherever BioGenes GmbH processes personal data, such processing is carried out for the purposes defined in this data privacy statement.
In the case of specific services (in the sovereign or recognized sector), personal data and special categories of personal data are processed on a legal basis.
Personal data, in particular address data, contact data or payment data, are used for the execution of an emerging contractual relationship or its initiation. The processing of your personal data therefore takes place on the legal basis of Art. 6 (1) lit.b GDPR. For this purpose, it is usually necessary to transmit the collected data to our partner companies or other contract data processors.
Depending on the type of contractual service, these contract partners may also be located in countries outside the EU.
We also process your data for internal customer analyses.
The data processing is carried out based on art. 6 (1) lit. f GDPR and in the interest of providing you with optimal offers within the scope of our marketing.
Customer surveys that we conduct with our customers are voluntarily and serve to fulfill the standard requirements of our existing ISO certification. These are carried out on the basis of Art. 6 (1) lit. f GDPR.
Contact data of the controller:
Koepenicker Str. 325 (Building 211/212)
Phone: +49 (0) 30 6576 2396
Data Protection Officer
Please address any questions regarding the processing of your personal data, requests for information, applications, or complaints directly to:
External Data Protection Officer (TÜV Hessen)
Rights concerning the processing of personal data
Right of access
On request, you have the right to obtain information from us about the personal data concerning you and processed by us, to the extent defined in Art. 15 GDPR. You can send your request either by mail or email to the addresses given above.
Right to rectification
You have the right to require us to rectify any inaccurate personal data concerning you without undue delay (Art. 16 GDPR). For this purpose, please contact the address given above.
Right to deletion
Where the legal reasons defined in Art. 17 GDPR apply, you have the right to immediate deletion (“right to be forgotten”) of personal data concerning you. These legal reasons include: the personal data are no longer necessary for the purposes for which they were processed, or you withdraw your consent, and there are no other legal grounds for processing; the data subject objects to the processing (and there are no overriding legitimate grounds for processing––does not apply to objections to direct advertising). To assert your above right, please contact the contact address given above.
Right to restriction of processing
If the criteria defined in Art. 18 GDPR are fulfilled, you have the right to restriction of processing as established in the above article of the GDPR. According to this article, restriction of processing may be called for in particular if processing is unlawful and the data subject opposes deletion of the personal data and requests the restriction of their use instead, or if the data subject has objected to processing according to Art. 21 (1) GDPR as long as it is unclear whether our legitimate interest overrides the interest of the data subject. To assert your above right, please contact the contact address given above.
Right to data portability
You have the right to data portability as defined in Art. 20 GDPR. This means you have the right to receive the personal data concerning you, which you have provided to us, in a structured, commonly used, and machine-readable format, and have the right to transmit those data to another controller, such as another service provider. Prerequisite is that processing is based on consent or a contract and is carried out using automated means. To assert your above right, please contact the contact address given above.
Right to object
You have the right to object at any time under Art. 21 GDPR to processing of personal data concerning you which is based on Art 6 (1) lit. e or f GDPR, on grounds relating to your particular situation. We will desist from processing your personal data unless we can demonstrate compelling legitimate grounds for processing which override your interests, rights, and freedoms, or unless processing is for the establishment, exercise, or defence of legal claims. To assert your above right, please contact the contact address given above
Right to file a complaint with a supervisory authority
If you think that processing of personal data concerning you and carried out by us is unlawful or impermissible, you have the right to file a complaint with the supervisory authority responsible for us. You can contact this authority at
Berliner Beauftragter für Datenschutz und Informationssicherheit
Phone: +49 30 13889-0
Intended data transfer to third countries
At present, data transfer to third countries is not planned. Otherwise we will establish the required legal conditions. You will be informed of the respective recipients or categories of recipients of the personal data in line with the legal requirements.
BioGenes GmbH takes appropriate technical and organizational measures to protect any personal data you provide to BioGenes from accidental or intentional manipulation, loss, destruction, or access by unauthorized parties. This also applies to any external services purchased. We verify the effectiveness of our data protection measures and continuously improve them in line with technological development. Any personal data entered are encrypted during transfer using a secure encryption process.
Standard periods for deletion of data
Legislation has defined numerous data storage periods and obligations. At the end of these periods, the relevant data will be routinely deleted. Data that are not affected by the above storage periods and obligations are deleted or anonymized as soon as the purposes defined in this data privacy statement no longer apply. Unless this data privacy statement includes other deviating provisions for data storage, we will store any data we collect for as long as they are required for the above purposes for which they were collected.
Other data use and deletion
Any further processing or use of your personal data will generally only be carried out to the extent permitted based on a legal regulation or where you have consented to data processing or data use. In the case of further processing for other purposes than the ones for which the data were originally collected, we will inform you about these other services and provide you with all other significant information before further processing.
On our career site biogenes.de/about-us/career you have the opportunity to apply via e-mail for advertised positions or submit a speculative application. If you make use of this offer, a new browser window will open for each position with more information about the position.
We store your applicant data for the duration of the examination of your application. If your application is not successful or if you withdraw your application, your application data will be deleted after a maximum of 6 months, unless you have expressly agreed to longer storage. In case of a successful application, the data you have provided us via the application system will be processed further with regard to your future employment in our company. The legal basis is Art. 6 (1) lit. a, b and f GDPR as well as § 26 BDSG.
If you do not provide us the required personal data, this will not have any negative consequences for you. However, incomplete or incorrectly completed applications will not be considered. Unfortunately, the application cannot be submitted without providing your personal data and will therefore be deleted.
Registration and user profile
To place an order you have to register on our website with your personal user profile. After that you can log in to our website again and enter, save and transmit personal data to us in your profile. In order to place an order at our website, we need your details of gender, date of birth, first and last name, e-mail address and an address details for the shipping.
We use the double opt-in procedure for registration, i.e. Your registration is only completed if you have previously confirmed your registration via a confirmation e-mail sent to you for this purpose by clicking on the link contained therein.
At the time of login, the following data is also stored:
- The IP address of the user, date and time of login.
We process your data for the above purposes on the basis of the following legal bases:
- with your consent, if the registration for advertising purposes, such as the subscription to the newsletter, takes place, Art. 6 para. 1 lit. a GDPR;
- to safeguard our legitimate interests in accordance with Art. 6 para. 1 lit. f GDPR; our legitimate interest is based on our economic interests in the implementation of advertising measures and target group-oriented advertising that is individually adapted to your interests and preferences on the basis of your profile.
- to safeguard the contractual relationship in accordance with GDPR Art. 6 para. 1 lit.b.
If you confirm a order at our website, we collect personal data information. For the payment we offer you various payment options, the specification of personal data is necessary for the conclusion of the contract.
We transmit the data to the following network operators. The data protection provisions of the network operators can be accessed via the following links.
The network operator processes the data for payment processing, to prevent card misuse, to limit the risk of non-payment and for legally prescribed purposes, such as combating money laundering and criminal prosecution. For these purposes your data will also be transmitted to other responsible parties, such as your card-issuing bank. The legal basis for the processing is art. 6 (1) b, c, and f GDPR.
The following data will be processed for the payment:
- Card data: IBAN or account number and short bank code, card expiry date and card sequence number
- Further payment details: Amount, date, time, identification of the payment terminal (place, company where you pay), your signature.
Specific information about the website
Visiting our website
When you visit our website www.biogenes.de, the browser used on your device automatically sends information to the server of our websites. This information is temporarily stored in a so-called log file. The following information will be collected without your intervention and stored until automated deletion:
- IP address of the requesting computer,
- Date and time of access,
- Name and URL of the retrieved file,
- Website from which access is made (referrer URL),
- Used browser and, if applicable, the operating system of your computer as well as the name of your access provider
We process the data mentioned for the following purposes:
- ensuring a smooth connection of the website,
- ensuring comfortable use of our website,
- evaluation of system security and stability as well for further administrative purposes.
The legal basis for data processing is the Art. 6(1)(f) of the EU General Data Protection Regulation (GDPR). Our legitimate interest follows from the data collection purposes listed above. In no case we use the collected data for the purpose of drawing conclusions about you.
We also process personal data that you provide voluntarily, e.g. when you make an inquiry, an order or when you order information material or newsletters. Legal basis in this case is Art. 6 (1) lit. b GDPR. The data processed by us in this context include the data of customers, employees, and suppliers to the extent necessary for the purposes specified within the scope of this data privacy statement.
In as far as we process your data as described above for the purpose of accepting and processing your inquiry, order or (newsletter) order, you are contractually bound to make these data available to us. We are unable to process your request without the data.
Where you have given your consent to the processing of personal data (cf. Art. 6 (1) lit. a GDPR), you can withdraw your consent at any time. Withdrawal of consent will not affect the lawfulness of processing based on consent up to the time of withdrawal of consent.
If you have a specific question to us, you can send us an e-mail request using the contact menu. At the contact menu you can find serveral employees with their current positions and a e-mail link to send them a direct e-mail.
When you contact us, the data you provide will be stored by us. The processing is carried out for the purpose of processing the requests based on Art. 6 (1) lit. b, f GDPR.
The data collected during your contact, will be deleted as soon as they are no longer required to process your request.
With your consent, you can subscribe to our newsletter, with which we will inform and send you updates on our latest offers or services, products and partners via email.
For the receipt of the newsletter the indication of an e-mail address, your name, company and country is sufficient. The following personal data is also collected and stored:
- Email address
- Profile ID
- Date and time of subscription
In addition, we store your IP addresses and times of registration and confirmation. The purpose of the procedure is to prove your registration and, if necessary, to inform you about possible misuse of your personal data.
If you have signed up or otherwise agreed to receive newsletters (e.g. as part of the free provision of white papers) or other update services, we will process your contact data that you have given to provide those services for you. The processing is based on our legitimate interests according to Art. 6 (1) (f) GDPR to pursue business development activities, or, as the case may be, for the performance of a contract according to Art. 6 (1) (b) GDPR. In other cases, we may ask you for your explicit consent under Art. 6 (1) (a) GDPR.
Our newsletter is distributed via “rapidmail”, a platform of the German email marketing provider rapidmail GmbH, Wentzingerstraße 21, 79106 Freiburg im Breisgau.
Therefore, your email address as well as other contact data that you have given will be processed on the servers of rapidmail.
Due to our data processing agreement, rapidmail is obliged to comply with our data protection regulations. For more detailed information on the conditions of use and data privacy of rapidmail please visit www.rapidmail.de/datenschutz.
The un-subscription is possible at any time via sending your unsubscribe request to newsletter(at)biogenes.de by e-mail.
We use the following types of cookies:
- Essential/necessary cookies
These cookies are essential for the functioning of our website. This includes, for example, issue of anonymous session IDs to summarize multiple queries to a web server or ensuring fault-free functioning of registrations and orders.
- Performance/statistics cookies
These cookies collect information about how you use our website (e.g. which Internet browser you use, how often you visit our website, which pages you open, or how long you stay on our website). These cookies do not store any information that enables visitors to be personally identified. The information collected with the help of these cookies is aggregated, and thus anonymous.
You can accept or decline cookies - including those used for website tracking - by selecting the appropriate settings for your browser. You can set your browser to notify you when you receive a new cookie, or to decline cookies altogether. However, if you choose to decline cookies you may not be able to use all the features of our website (e.g. for purchasing orders). Your browser also offers you the option to delete cookies (e.g. via the Clear Browsing History function). For further information, please refer to the user help function under Settings in your web browser.
You will find below a list of the different types of cookies that we and third parties use on the website: Essential cookies, Performance cookies, Functional cookies, Marketing cookies.
We process your personal data for cookie management of our website on the following legal bases:
- for the performance of a contract or for the implementation of pre-contractual measures pursuant to Art. 6 (1) lit. b DSGVO, insofar as you visit our website to find out about our products and our competitions;
- for the use of cookie management to fulfill a legal obligation to which we as the responsible party are subject pursuant to Art. 6 (1) lit. c DSGVO. The legal obligation is to inform you about cookies we use and to obtain and document your consent to data processing; and
- for the protection of our legitimate interests pursuant to Art. 6 (1) lit. f DSGVO, in order to be able to provide you with the cookie management technically. Our legitimate interest is to be able to provide you with an appealing, technically functioning and user-friendly cookie management, as well as to take measures to protect the cookie management from cyber risks and to prevent the cookie management from posing cyber risks to third parties.
Use of reCAPTCHA
If you are logged in to Google with an existing user account while visiting our website, Google may also be able to associate your visit to our website with your user behavior. In addition, further cookies may be sent to your browser by Google. We would like to point out that we, as the provider of our websites, do not have precise knowledge of the content of the transmitted data and its use by Google, nor do we have the possibility to further restrict the transmission of data to Google and its partners. According to the information provided by Google, Google stores the data as user profiles and uses them for purposes of advertising, market research and / or tailored design of your web pages. Such an evaluation is carried out in particular (even for users who are not logged in) for the provision of needs-based advertising.
The data processing is based on the consent you have given (Art. 6 para. 1 lit. a DSGVO, § 25 para. 1 TTDSG). To exercise your right of withdrawal, see the explanations on your rights mentioned under „Rights concerning the processing of personal data“.
Use of Matomo
The cookie banner captures and stores the consent to cookie usage for the respective user of our website.
The Opting out of using of Matomo is possible by removing the tick in the Opt-Out, so that the Opt-out-Plug-in is activated.
This website uses Matomo including of the"AnonymizeIP" add-on. By using this, IP addresses are truncated for processing, so that a direct connection to the person can be excluded. Your IP address, transferred by Matomo from your browser, is not connected to other data assessed by us.
Matomo is an Open-Source-Project. You can find any necessary information concerning data protection at matomo.org/privacy-policy/.
During your visit of our website the following data is collected and stored to serve marketing and optimizing purposes:
- Request (pagename)
- Browser (e.g. Internet Explorer)
- Browser language (e.g. English)
- Operating system (e.g.: Windows 10)
- Referrer URL (previously visited page)
- Anonymized (shortened) IP address
- Time of access
- City and country
These data can be used to create pseudonymized user profiles. For this purpose, cookies can be used (see Cookies). Without the consent of the affected person, the collected data are not used to identify the visitor of the website or to merge personal data with the pseudonym.
Embedding of social plugins
Our website uses buttons for the following social Networks
- LinkedIn, LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA
- Twitter, Twitter Inc., 1355 Market St, Suite 900, San Francisco, CA 94103, USA
The buttons show the logos of the individual social networks. However, the buttons are not standard social plugins, i.e. plugins provided by social networks, but links with button icons. These buttons are only activated by deliberate actions (clicking). If you do not click the buttons, no data will be transferred to the social networks. By clicking the buttons, you accept communication with the servers of the social network, thereby activating the buttons and establishing the link.
Once clicked, the button functions as a share plugin. The social network then obtains information about the site you have visited, which you can share with your friends and contacts. You need to be logged in to “share” information. If you are not logged in, you will be forwarded to the login page of the social network you have clicked, thereby leaving the pages of tuev-hessen.de. If you are logged in, your “like” or recommendation of the article in question will be transmitted.
When you activate the button, the social networks will also receive the information that you accessed the respective page of our website and when you did so. In addition, information such as your IP address, details about the browser you used, and your language settings may be transmitted. If you click the button, your click will be transferred to the social network and used according to their data policy.
When you click the button, we have no control over the data collected and the data-processing operations. We are not responsible for this data processing, nor are we the “controller” as defined in the GDPR. Neither are we aware of the full extent of data collection, its legal basis, purposes and storage periods. Given this, the information provided here is not necessarily complete.
As far as we know, these providers store these data in user profiles which they use for advertising, market research and/or demand-oriented website design. This type of analysis is performed (also for users who are not logged in) to present demand-oriented advertising and inform other users of the social network of your activities on our website. You have the right to object to the creation of these user profiles. To exercise your right of objection, please contact the relevant provider.
Please consult the information provided by the following social media sites for details of the purpose and scope of data collection and of further processing and use of the data by the respective social network, and for your rights and privacy settings:
- Twitter: http://twitter.com/privacy
- LinkedIn: http://www.linkedin.com/static?key=privacy_policy&trk=hb_ft_priv
If you do not wish social networks to obtain data about you, do not click the button.
Use of Open Street Map
The BioGenes website uses Open Street Map a service, to display an interactive map. Open Street Map is operated by OpenStreetMap Foundation, St John´s Innovation Centre, Cowley Road, Cambridge, CB4 oWS, United Kingdom.
Misuse detection and prosecution
Information for the detection and prosecution of misuse, in particular your IP address, will be kept available for a maximum of 7 days. The legal basis in this respect is Art. 6 (1) lit. f GDPR. Our legitimate interest in the retention of data for 7 days is to ensure the proper functioning of our website and the transactions conducted over it, and to be able to ward off cyber attacks and the like. We may use anonymous usage information to design our website to meet your needs.
Specific information about our online presence in social media
BioGenes maintains online presences within social networks and platforms, such as Twitter and LinkedIn, in order to be able to communicate with active users there and to inform them about our service portfolio. BioGenes uses the technical platforms and services offered by the operators. In social networks and on other external platforms the data protection regulations of the operators apply, even though we publish information and maintain presences there.
We would like to point out that you use the services of the social networks and platforms offered here as well as their functions under your own responsibility.
This applies in particular to the use of interactive functions (e.g. commenting, sharing, rating etc.). The data collected about you in this context will be processed by the platform operators and, if necessary, transferred to countries outside the European Union. Which information the operators receive and how these are used, describe the respective data protection guidelines in general form. On the individual platforms you will also find information on how to contact the operators and on the setting for advertisements.
- Twitter: http://twitter.com/privacy
- LinkedIn: http://www.linkedin.com/static?key=privacy_policy&trk=hb_ft_privacy
In which way the social network operators use the data from the visits of the respective pages for own purposes, to what extent activities on the pages are assigned to individual users, how long these data are stored and whether data from a visit of the respective page are passed on to third parties, is not conclusively and clearly named by the operators and is not known to us.
- Facebook Pixel
LinkedIn uses the remarketing tool „Facebook Pixel“, a service of Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA. This function is used to display interest-based adverts (“Facebook ads”) to visitors when they visit the website. For this purpose, Facebook's remarketing tag has been implemented on this website. The tag establishes a direct connection to the Facebook servers when you visit the website. This information is transmitted to the Facebook server that you have visited this website and Facebook assigns this information to your personal Facebook user account.https://www.facebook.com/business/help/742478679120153?helpref=search&sr=3&query=pixel
- Nielsen NetRatings
Nielsen NetRatings is provided by Nielsen GmbH, Lindwurmstraße 10, 80634 Munich and is an Internet tracking service for measuring and analyzing consumer behavior. You can object to the collection or evaluation of your data using this tool by downloading or setting and saving the opt-out cookie available under the following link: http://www.nielsen.com/us/en/privacy-statement/digital-measurement.htm
AppNexus is provided by von AppNexus Inc., 28 W 23rd Street, 4th floor, New York, NY - 10010, USA and is a tool for web analysis and interest-oriented advertisement. You can object the collection and evaluation of your data here: https://www.appnexus.com/en/company/platform-privacy-policy-de.
- Eloqua Tracking
Eloqua, a service of Oracle Cor, 500 Oracle Parkway, M/S 5op7, Redwood Shores, CA 94065, USA, places a persistent cookie on the respective login page, if no Eloqua cookie already exists on your device. If you have already used a website that uses Eloqua, you may already have an Eloqua cookie. The Eloqua cookie may be used to analyze your use of pages to improve them. Emails sent using Eloqua use the tracking technologies described above. If you want to completely eliminate the use of Eloqua tracking technologies for your device, you can do so on the Eloqua Opt-Out page.
- Twitter Analytics & Twitter Ads
Twitter Analytics is a service provided by Twitter Inc., 1355 Market St, Suite 900, San Francisco, CA 94103, USA. Twitter Analytics stores and processes information about your behaviour on our online presences within social media. Twitter Analytics uses, among other things, cookies that are stored locally in the cache of your browser and which enables the analysis of your use of social media platforms. Twitter Ads enables target-oriented campaigns.
- Facebook Insights
When visiting our Facebook page, Facebook (Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA) collects your IP address and other information available on your device via cookies. This information is used to provide the operator of a Facebook fanpage with statistical information about the use of this page. Facebook provides more information on this under the following link
- Google Analytics
Infusionsoft is a program for preparing, creation and executing targeted marketing campaigns. The operator of Infusionsoft is Infusionsoft Inc, 1260 p. Spetrum Blvd, Chandler, AZ 85286, USA. The software makes it possible to link statistical data and network behaviour of individual users with the contact data of specific persons for marketing purposes. If you install a deactivation add-on for your web browser, you can object to the collection of your data.
Since October 2022