01Privacy policy
At ONETEEM we take the protection of your personal data seriously. This policy explains what personal data we process when you visit our website, contact us, apply for a job or work with us as a customer, why we process it, how long we keep it, and what rights you have.
For how we protect data technically and organisationally, see our security page. For the service providers we use, see our subprocessors page. Everything a procurement or security review needs is collected in our trust center.
02Controller
Company registration details are in our legal notice.
03Data protection officer
We are not required to appoint a data protection officer under Article 37 GDPR or Section 38 BDSG, because we do not meet the thresholds that trigger the obligation. Responsibility for data protection sits with the Managing Director. Write to [email protected] with any question or request, and it will reach the right person.
04What we process, why, and on what basis
05Website and server log files
Each time our website is accessed, our hosting and content delivery providers automatically record technical information, including the requesting IP address, the date and time, the page requested, the referring page, and browser and operating system details. This happens for every website and is necessary to deliver the page and to detect and defend against attacks. We do not use this data to identify individual visitors and we do not combine it with other data. Log files are deleted after 30 days, unless a specific security incident requires us to keep a copy for longer.
Our website is hosted by Odoo S.A. in Belgium, with domain and DNS services from IONOS SE in Germany and content delivery and attack protection from Cloudflare, Inc. Details are on our subprocessors page.
07Contacting us
If you write to us by email, use a contact form or call us, we process the details you give us in order to answer. Where your enquiry concerns a possible contract, the basis is Article 6(1)(b). Otherwise it is our legitimate interest in responding to business enquiries under Article 6(1)(f). We keep enquiry correspondence for 12 months after our last contact, unless it becomes part of a contract, in which case the statutory periods below apply.
08Job applications
If you apply to us, whether through our careers page or by email, we process your application documents in order to assess your suitability and to run the selection process. The basis is Article 6(1)(b) GDPR together with Section 26(1) BDSG.
If we do not offer you a position, we delete your application six months after the decision. That period covers the limitation period for claims under the German General Equal Treatment Act. If we would like to keep your details on file for future openings, we ask you separately and only keep them with your consent, which you can withdraw at any time.
09When we act as a processor for our customers
When we deliver services to a customer, the customer is normally the controller for the personal data in their systems and we act as processor on their instructions. That relationship is governed by a data processing agreement, not by this policy. This policy covers the personal data for which ONE T.E.E.M. GmbH is itself the controller, which is our website, our business operations and our own communications.
Our data processing agreement is available on request from [email protected] and forms part of our customer agreement. The controls we apply are described on our security page.
10Service providers and subprocessors
We use a small set of established providers for hosting, collaboration, business operations and software development. Each is bound by a data processing agreement, may process data only on our instructions, and receives only what it needs.
The full list, with the purpose, location and transfer mechanism for each, is on our subprocessors page. We update that page whenever the list changes, and we notify customers at least 30 days before adding or replacing a subprocessor that handles personal data.
11International data transfers
Some of our providers process data outside the European Economic Area, in the United States and in Tunisia.
For providers in the United States, we rely on the EU US Data Privacy Framework where the provider is certified under it, and otherwise on the standard contractual clauses approved by the European Commission.
For our collaboration with ONETEEM TUNISIA SUARL in Tunisia, we have concluded a data processing agreement and implemented the standard contractual clauses approved by the European Commission, supported by technical measures including encryption in transit and at rest and access limited to named personnel. Tunisia is not covered by an EU adequacy decision, which is why these safeguards are in place.
The mechanism that applies to each provider is shown on our subprocessors page. Customers who need processing restricted to the EEA can request that before contracting and we will record it in the agreement.
12Data retention
We keep personal data only as long as we need it for the purposes described above, or as long as the law requires.
Statutory retention periods under German commercial and tax law, principally Section 257 HGB and Section 147 AO, generally run between six and ten years depending on the type of document, and start at the end of the calendar year in which the document was created. During that period we restrict the data to what the retention obligation requires and do not use it for any other purpose.
The specific periods for each purpose are in the table above. Where no statutory period applies, we delete data once the purpose has been fulfilled.
13Your rights
Under the GDPR you have the right to:
Access the personal data we hold about you, under Article 15
Have inaccurate data corrected, under Article 16
Have your data deleted, under Article 17
Restrict processing, under Article 18
Receive your data in a portable format, under Article 20
Object to processing based on our legitimate interests, under Article 21
Withdraw any consent you have given, at any time and with effect for the future, under Article 7(3), without affecting the lawfulness of processing carried out before withdrawal
To exercise any of these, write to [email protected]. We respond within one month, and will tell you if we need longer because a request is complex.
15Automated decision making
We do not use your personal data for automated decision making or profiling that produces legal effects for you or otherwise significantly affects you.
16Data security
We use technical and organisational measures to protect your data against unauthorised access, loss and misuse, including encryption in transit and at rest, multi factor authentication, least privilege access and continuous vulnerability scanning. These measures are described in detail on our security page, including how to report a security issue to us.
17Changes to this policy
We update this policy when our technology, our providers or the legal requirements change. The current version is always published on this page with its effective date at the top. Material changes are announced through our usual customer channels.