en_EN

Privacy Policy Fit for Work

This Privacy Policy satisfies the disclosure requirements according to Art. 12 ff. of the EU General Data Protection Regulation (“GDPR”) and provides a summary of the processing of your personally identifiable information (“personal data”, “personal information”) on this website, if you participate or have participated in the Fit for Work campaign (hereinafter referred to as "campaign") of the Sports and Health Department (ZPS) of Bertelsmann SE & Co. KGaA (hereinafter referred to as "Bertelsmann") with the support of Bertelsmann BKK.

1. Who is accountable for processing my data?

Bertelsmann SE & Co. KGaA
Department: Bertelsmann Sports and Health
Carl-Bertelsmann-Straße 270
33311 Gütersloh, Germany
E-Mail: zps@bertelsmann.de
is responsible for processing your data on this website (hereinafter referred to as “we” or “Bertelsmann”). Bertelsmann processes personal data in accordance with GDPR provisions.

You can contact our designated Data Protection Officer at the address indicated above by using the reference ‘For the attention of the Data Protection Officer’ or by writing an E-Mail to:
datenschutz@bertelsmann.de.

2. What data is collected?

When you visit our website, the data of the computer you use to access our website is automatically logged (“access data”). This access data includes server log files that generally consist of information pertaining to your web browser type and version, your operating system, your internet service provider (ISP), the date and time you used the website, the websites previously visited by you and the websites you accessed from our website, in addition to the IP address of your computer. Server log files can only be accessed by a restricted group of people in the event of technical or forensic requirements. The IP address contained in the server log files, leads to the Server Log Files becoming personal data, which are processed exclusively in the above-mentioned cases. This data is not used for analysis purposes.

If you participate in the campaign the personal data you enter to register and create a participation profile, such as e-mail address, last name, first name and title (hereinafter referred to as "contact data"), as well as optionally your telephone number and information about the company location, will be collected, which support the competitive nature among the companies and may be used and stored by Bertelsmann to enable a company-specific competition.

Some features of our website require that you divulge personal information to us. In this case, the information provided by you is used to provide the service requested by you or process a matter submitted by you (e.g. entries made in forms).

3. 3. What data is collected and for what purpose?

The purpose of data processing may be based on technical, contractual or statutory requirements or result from consent having been given by the user.

Bertelsmann uses the data described in section 2 for the following purposes:

  • To provide website features and content and ensure technical security in troubleshooting technical issues and also to ensure that unauthorized persons do not gain access to our website systems;
  • For the use of the provided activity calendar function on this website and the relating thereto prize draw or competition;
  • For communication, completion of precontractual procedures, and customer care purposes.

For information on other data processing purposes, please refer to the sections below of this Privacy Policy.

3.1. Server Log Files

In order to enable the proper functioning of our website, security analyses to be conducted, and denial-of-service attacks to be prevented and stopped, server log files are automatically collected and saved on a short-term basis as an integral part of access data that is created by the system of the visiting computer upon accessing our website and while using it (see section 2). The content of the server log files is not merged with other data. Bertelsmann uses the server log files for statistical analyses to troubleshoot and remedy technical issues, prevent and defend against denial-of-service attacks and attempted fraud, and to optimize the proper functioning of our website.

The legal basis for the creation of server log files follows from Art. 6(1)(f) GDPR. Our legitimate interests lie in the proper functioning of our website, conducting security analyses and defending against threats

When the pages of our website are accessed, information is logged to server log files that are stored on our web server; the IP address contained in them is deleted after 7 days at the latest. No analysis is conducted during this time unless there is a denial of service or other attack.

You have the right to lodge an objection to the processing of your data contained in the server log files provided that there are cogent reasons that arise from your specific situation. If you would like to exercise your right to lodge an objection, please write to the contact address in section 1.

3.2 Activity calendar and competition

To participate in the campaign offered on this website, you must register by providing your contact details as specified in section 2. Participation in the campaign is voluntary. With the registration you will create an user account in which you can manually enter the distance you have covered in your activity calendar and also view your total distance covered in the form of a table. By registering for the campaign, you will automatically be entered into our competition, provided that you have met the necessary conditions during the promotion period which are specified in the Terms and Conditions you accepted beforehand. Your data will be collected and stored for the competition (with the help of service providers). In the event of a win, your contact details will also be used for written or text notification of the winning and for sending the prize. In principle, your data will not be passed on to third parties, unless the prize is sponsored by a partner company or an agency, for example, and the passing on of your contact details is necessary for the dispatch of the prize. We have contractual agreements in place to ensure that your data is not processed by third parties for any other purposes.

The processing of your data is necessary for the creation of a participation profile to use the activity calendar as well as the participation in the competition. The legal basis is the fulfillment of the conditions of participation as described in the Terms and Conditions well as the fulfillment of a contract according to Art. 6 (1) b GDPR.

If and to the extent that you win a competition and we report on it, we will publish the data you provide to us (name and company, if applicable) for the purpose of reporting on our competition on the intranet of Bertelsmann. We do this on the basis of your consent pursuant to Art. 6 (1) a DSGVO.

Your data will be deleted immediately if the purposes for which it was collected no longer applies or the data required for the processing is no longer necessary to achieve the purposes described. This does not apply insofar as Bertelsmann is subject to statutory retention periods or retention is necessary for the assertion, exercise or defense of legal claims. Your personal data will be systematically deleted after a period of two years, provided that you have not registered into your participation profile on this website.

3.3 Contact form, email and telephone contact information

On our website you have the option of contacting us by a contact form, by email or by telephone. If you take advantage of this option, the information you enter in the contact form, your email address and/or your phone number are disclosed to us. Depending on the reason you are contacting us (questions about our products and services, pursuing your rights as a data subject, e.g. submitting a request for information) your contact details are processed (with the assistance of service providers). If necessary for processing your request, this information may be shared with third parties (e.g. partner companies). The legal basis for processing your contact details follows from Art. 6(1)(f) GDPR. We have legitimate interests in processing your request and in continued communication.

Your contact details are deleted once your request has been processed and further communication has been discontinued. This does not apply if the purpose of your establishing contact with us is to conclude a contract or you wish to exercise your right as a data subject (e.g. request information). In this case your details are stored until all contractual and/or statutory obligations have been fulfilled and statutory retention periods (currently 6 to 10 years) do not prevent this information from being deleted.

You have the right to lodge an objection to the processing of your contact information provided that there are cogent reasons that arise from your specific situation. If you would like to exercise your right to lodge an objection, please write to the contact address in section 1. If you lodge an objection, communication with you cannot be continued.

3.4 External content on our website

We integrate external content on our website. If you are shown the content of third parties, communication data is exchanged between you and the provider of that service or content for technical purposes. Bertelsmann and the third-party provider do not communicate with your data.

That provider may use your data for their own purpose. However, since we have no control over the data collected by third parties and its processing by them we are unable to make any binding statements pertaining to the purpose and scope of the processing of your data. Bertelsmann is also not the controller of the third-party providers' data processing of your data.

For further information on the purpose and scope of the collection and processing of your data, please refer to the privacy policy of the responsible provider (under data protection law) of the content integrated by us.

If you give your consent to the processing of your data by Bertelsmann BKK on our website for the purpose of sending newsletters or other content for information about BKK services and products by the BKK, the BKK and not Bertelsmann is responsible for the subsequent processing of your data and the associated authorization process for registering for the newsletter. In this respect, we refer to the privacy policy of theDatenschutzhinweise der BKK.

3.5 Use of the Fit for Work application

Besides entering the data manually, from spring 2024 you will also have the option of using an app to record the distances you cover as part of Fit for Work. However, this is basically only a way to remotely access your user profile in the web portal – no data is stored persistently on your smartphone. To use the app, you must download it from the app store on your device (iOS/Android) and connect to your Fit for Work user account or create one. You can update and change your user profile at any time. In the app, you can view your recorded achievements and those of your team. As in the web portal, you can record your performance manually in the app as well, or use the import function, which then synchronizes the training data from your device’s health app (Google Health, Apple Health) – in this case, however, we only use information about distances covered, and no other information from your health app or your location (geo-location). You are free to decide which data you wish to exclude from synchronization.

The Fit for Work app is a completely optional service that is solely for your convenience and depends on your individual configuration (e.g. with regard to connecting it to a health app). The legal basis for the use of your data is therefore your consent in accordance with Art. 6 para. 1 lit. a GDPR. Depending on your use and configuration, your location information may also be processed and stored (viewable) in your profile when using the app, along with the data mentioned in section 2.

4. Who comes into possession of my personal data?

Within Bertelsmann those who need access to your information for the purposes described in section 3 will be given access to it. Service providers contracted by us may also be given access to your information (“contract data processors”, e.g. data centers). They are bound by our directives and must provide for data security and the confidential treatment of your information under the contract data processing agreements we have concluded with them.

A data transfer of your data according to section 2 to the BKK can take place due to the support services and in the context of the implementation of the competitions, provided that the data transfer is necessary for the performance of the contract. Likewise, a transfer of your e-mail address to the BKK will take place if you have agreed to receive information on benefits of membership with the BKK during the creation process of your user account on this website. No sharing of information with other recipients such as advertising partners, providers of social media services or credit institutions (“third parties”) takes place.

5. Is my personal data processed outside of the EU or EEA (‘transfer to a third country’)?

Your data will not be processed outside the European Union or the European Economic Area ("EU" or "EEA"). The service providers we use for the technical provision of the website also do not process your data outside the EU or the EEA.

6. What data privacy rights do I have?

You have the right to request access to your personal data that is currently stored by us. If this data is incorrect or not up to date, you have the right to request rectification. You also have the right to have your personal data erased and/or its processing restricted as provided for in Art. 17 and Art. 18 GDPR. You also have the right to request a copy of the personal data provided by you in a structured, commonly-used, machine-readable format (right to data portability).

If you have given your consent to the processing of your personal information for specific purposes, you can revoke that consent at any time for the future. Your notice of revocation is to be addressed to us by writing to the contact address indicated in section 1.

Pursuant to Art. 21 GDPR, you also have the right for reasons relating to your specific situation to raise an objection to the processing of your data that is done on the basis of Art. 6(1)(f) GDPR.

You also have the right to lodge a complaint with the competent data protection authority. The authority responsible for us is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestr. 2-4
40213 Düsseldorf
Telefon: 0211/38424-0
E-Mail: poststelle@ldi.nrw.de

You also have the right to contact the data protection authority at your place of residence and request support in pursuing your matter.

7. To what extent does automated decision-making take place?

We do not use any fully automated decision-making processes for any of the purposes set out in section 3.

8. Is profiling done?

No profiling takes place for any of the purposes set out in section 3.

Status of privacy policy: 02/2024

Add to Home Screen