Privacy Policy
This notice explains how we protect your personal data, which is a top priority for us. We have implemented all necessary technical and organizational measures to properly comply with data protection laws and regulations, and we are continuously refining these measures.
To make this privacy policy easier to understand, we will first explain a few key terms from the General Data Protection Regulation (GDPR).
Personal data refers to any information that can be used to identify an individual. Identification can occur directly or indirectly based on various characteristics.
Typical examples of direct personal data include name, address, email addresses, phone number, location data, and date of birth. Typical examples of indirect personal data include IP addresses or user data stored in server log files.
A data subject is an identified or identifiable natural person whose personal data is being processed.
Processing means any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, distribution, or any other form of disclosure, the matching or linking, the restriction, erasure, or destruction.
Restriction of processing refers to the marking of stored personal data with the aim of limiting its future processing.
Profiling is any form of automated processing of personal data that involves using such personal data to evaluate certain personal aspects relating to a natural person, in particular to evaluate aspects concerning work performance, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements of that natural person.
The controller is the natural or legal person, public authority, agency, or other body that, alone or jointly with others, determines the purposes and means of the processing of personal data; if the purposes and means of such processing are determined by Union law or the law of the Member States, the controller or the specific criteria for its designation may be provided for by Union law or the law of the Member States.
A processor is a natural or legal person, public authority, agency, or other body that processes personal data on behalf of the controller.
A recipient is a natural or legal person, public authority, agency, or other body to whom personal data is disclosed, regardless of whether or not that entity is a third party. However, public authorities that may receive personal data in the course of a specific investigative mandate under Union law or the law of the Member States are not considered recipients; the processing of such data by those authorities is carried out in accordance with applicable data protection regulations and in line with the purposes of the processing.
A “third party” is a natural or legal person, public authority, agency, or other entity, other than the data subject, the controller, the processor, and the persons authorized to process the personal data under the direct responsibility of the controller or the processor.
Consent of the data subject means any freely given, specific, informed, and unambiguous indication of the data subject’s wishes, expressed in the form of a statement or other unambiguous affirmative action, by which the data subject indicates that he or she consents to the processing of personal data relating to him or her.
Please note that,
- that data transmission over the Internet (e.g., when communicating via email) may be subject to security vulnerabilities, and that it is not possible to completely protect data from access by third parties.
- that your browser transmits your IP address when you visit our website. The IP address is required to uniquely identify the device you are using for data transmission.
Person in Charge
This Privacy Notice applies to the processing of personal data by
WPW GmbH
Hochstraße 61
66115 Saarbrücken
Tel.: +49 681 99 20 0
Fax: +49 681 99 20 100
Legally represented by (Management)
Data Protection Officer
You can contact our Data Protection Officer as follows:
ZEiD GmbH
Email: DSB@zeid.de
Categories of Personal Data, Purposes, and Legal Bases
Server Log Files
When you visit our website https://www.wpw.de, the provider—
(intersaar GmbH, Heinrich-Barth-Str. 23, 66115 Saarbrücken) automatically and temporarily collects information in so-called server log files, which your browser automatically transmits to us and stores until it is automatically deleted. This information includes:
- IP address of the requesting computer
- Browser Type and Browser Version
- Operating system used
- Name and URL of the retrieved file
- Referrer URL (website from which the request originated)
- Hostname of the connecting computer (name of your Internet service provider)
- Date and time of the server request
This data cannot be linked to specific individuals. This data is not combined with other data sources. We reserve the right to review this data at a later date if we become aware of specific evidence of unlawful use.
Data is processed for the following purposes:
Establishing a connection, ensuring a stable and convenient user experience, evaluating system security, and administering our website
The legal basis is Article 6(1), sentence 1, subparagraph (f) of the GDPR. The operation of a website constitutes a legitimate interest.
Cookies
Some of the web pages on this site use so-called cookies. Cookies do not cause any damage to your computer and do not contain viruses. Cookies are used to make our website more user-friendly, effective, and secure, as well as for statistical analysis. Cookies are small text files that your browser automatically creates when you visit our website and stores on your device.
Most of the cookies we use are so-called “session cookies.” They are automatically deleted at the end of your visit.
Other cookies remain stored on your device until you delete them. These cookies allow us to recognize your browser the next time you visit. They store the information you’ve entered and the settings you’ve chosen so that you don’t have to re-enter this information.
You can configure your browser to notify you when cookies are set and to allow cookies only on a case-by-case basis. You can also disable cookies for specific cases or in general, and enable the automatic deletion of cookies when you close your browser. If you disable cookies, the functionality of this website may be limited.
The data is processed for the specified purposes.
The legal basis is Article 6(1), sentence 1, subparagraph (f) of the GDPR. The website is operated in our legitimate interest or that of a third party.
We use tracking cookies and non-essential cookies only if you have previously given your express consent. Tracking cookies show, among other things, which pages you have already visited and are used for statistical purposes (to analyze and improve our website).
You can find a detailed overview and options for managing, changing, revoking, or granting consent regarding cookies here.
The legal basis is your voluntary consent pursuant to Article 6(1), sentence 1, subparagraph (a) of the GDPR.
Web Design/Fonts
Adobe Fonts (Typekit)
We use Adobe web fonts on our website to ensure a consistent and visually appealing design.
We have purchased a license to use WebFonts and entered into a data processing agreement with Adobe.
The service provider is Adobe Systems Software Ireland Limited, 4-6 Riverwalk, Citywest Business Campus, Dublin 24, Ireland (for Europe). Data processing may also take place in the United States. Adobe is certified under the Adequacy Decision for data transfers to the United States.
The fonts are hosted by Adobe. When the web fonts are transmitted, Adobe processes your IP address.
You can view Adobe’s privacy policy at the following link
https://www.adobe.com/de/privacy/eudatatransfers.html
You can view the Adobe Fonts for Websites Privacy Policy below:
https://www.adobe.com/de/privacy/policies/adobe-fonts.html
The legal basis is Article 6(1)(f), which refers to our legitimate interest as listed above.
Contact Form
To the extent that direct personal data—such as name, address, email addresses, phone numbers, etc.—is collected via contact forms on our website, this is always done on a voluntary basis whenever possible. This data will not be shared with third parties without your express consent and will be deleted once your inquiry has been processed.
The data is processed for the purpose of establishing contact and submitting a statement.
The legal basis is your voluntary consent pursuant to Article 6(1), sentence 1, subparagraph (a) of the GDPR.
Privacy Policy: Job Application Process via Our Website
Description of Data Processing
When submitting application materials through our website (job postings are hosted and managed by our data processor, HR4YOU), the following information is requested:
- Salutation
- Last Name
- First Name
- Phone/Cell Phone Number
- Comments
- Your Voluntary Consents
Permission to store the data for a longer period and to use it for future job openings
Consent to share application materials within the WPW Group.
Document Upload
- Resume
- Personalized Cover Letter (optional)
- Certificates and School Transcripts/Diplomas (optional)
- Employment References (optional)
Legal Basis for Data Processing
Section 26 of the Federal Data Protection Act (BDSG), in conjunction with Article 88 of the General Data Protection Regulation (GDPR) and Article 6(1)(b) of the GDPR, forms the legal basis for establishing an employment relationship.
If you grant us your permission or consent to share your data within our corporate group or to store it for a longer period, Article 6(a) of the GDPR serves as the legal basis.
We anonymize the application data we receive based on our legitimate interest under Article 6(1)(f) of the GDPR so that we can use the anonymized data to evaluate our job postings in terms of efficiency, success, and media reach.
Purpose of the processing
Data processing ensures that the application process is carried out and, in the event of a rejection, creates a pool of applicants for future job openings, subject to your consent.
Retention period
Your personal data will be deleted as soon as the purpose for which it was collected no longer applies, unless we are required by law to retain it. As a general rule, your personal data will be deleted no later than 10 years after the end of your employment. Personal data of rejected applicants will be deleted 7 months after the conclusion of the application process. Unless you have given us your consent to longer-term storage or sharing within our group, in which case your data will be deleted no later than 2 years after the conclusion of the application process or at the end of the retention period you specified.
We delete the anonymized data after 5 years.
Right to Cancel
Any applicant (f/m/d) may revoke their consent to the processing of their data (including extended storage and disclosure within the corporate group) at any time with future effect. The revocation must be submitted in writing or electronically via email to personal@wpw.de.
As of December 2025
Legitimate Interests
We operate our website to introduce ourselves and our products and to expand our reach.
Disclosure of Data to Recipients or Categories of Recipients
Indirect personal data may be shared with web hosting providers, plugin providers for tools, IT service providers, etc. For more detailed information, please refer to Section 15, “Tools Used,” in this Privacy Policy.
We will only share your direct personal data with third parties if the following conditions are met:
- Explicit consent has been given in accordance with Article 6(1)(a) of the GDPR
- The processing is necessary to safeguard the legitimate interests of the controller pursuant to Article 6(1)(f) of the GDPR, unless the interests or fundamental rights and freedoms of the data subject that require the protection of personal data take precedence.
- The processing is necessary to fulfill a legal obligation under Article 6(1)(c) of the GDPR to which the controller is subject;
- The processing is necessary for the performance of a contract pursuant to Article 6(1)(b) of the GDPR, to which the data subject is a party, or for the implementation of precontractual measures taken at the data subject’s request;
Transfer of Data to a Third Country
We do not intend to transfer your direct personal data—such as your name, address, email addresses, phone number, date of birth, etc.—to a third country. However, when using the Internet, technical data such as IP addresses or other technical user data (e.g., cookies) are also transmitted.
To the extent that tools or plugins are used on our website, indirect personal data may be transferred to the United States. This transfer is based on contractual agreements (e.g., Standard Data Protection Clauses or the Data Privacy Framework) with our contractual partners, which ensure an adequate level of data protection. For further details, please refer to Section 15, “Tools Used,” or to this Privacy Policy.
Duration of Storage
As stated in this Privacy Policy, your personal data will be deleted as soon as the purpose for which it was collected no longer applies, unless we are required by law to retain it.
Right of access, rectification, erasure, restriction, objection, and data portability
You have the right to access the personal data concerning you (Art. 15 GDPR), including the purposes of processing, the categories of personal data, the recipients or categories of recipients to whom your data has been or will be disclosed—particularly recipients in third countries—and the planned retention period. If the data was not collected by us, you have the right to information regarding the origin of the data. In addition, you have the right to rectification (Art. 16 GDPR) or erasure of your data (Art. 17 GDPR) or to restrict processing (Art. 18 GDPR), as well as the right to data portability (Art. 20 GDPR). The right to data portability includes the provision of your personal data in a structured, commonly used, and machine-readable format so that the data can be transmitted to another controller without hindrance.
In addition, you have the right to object to the processing (Art. 21 GDPR) if we are processing your data on the basis of a legitimate interest asserted by us (Art. 6 (1), sentence 1, letter f of the GDPR) and you have reasons arising from your particular situation, or if the objection is directed against direct marketing. In the latter case, you may object without having to specify a particular situation.
Withdrawal of Consent
To the extent that you have given us your consent to process your personal data, you have the right to withdraw your consent at any time without affecting the lawfulness of the processing carried out on the basis of your consent prior to its withdrawal (Art. 7(3) of the GDPR).
You can exercise your rights to object or withdraw consent by contacting the data controller or data protection officer using the contact information provided.
Right to File a Complaint
You have the right to file a complaint with the supervisory authority in your place of residence (Art. 77 of the GDPR).
In Saarland:
Saarland Independent Data Protection Center, Fritz-Dobisch-Straße 12, 66111 Saarbrücken, Tel. 0681 947810
Requirement to Provide Personal Data
You are under no legal or contractual obligation to provide us with your personal data. However, the provision of your indirect personal data (IP address, cookies) is required in order to visit our website.
Automated Decision-Making
We do not engage in automated decision-making based on personal data, including profiling and scoring.
Processing for Other Purposes
We do not process personal data for purposes other than those for which it was collected. Should this become necessary, we will provide you with information about this other purpose and all other relevant details prior to such processing.
Data Security
We use SSL (Secure Socket Layer) on our website. Data transmission is encrypted using 256-bit encryption, provided your browser supports it. Otherwise, 128-bit encryption is used. You can recognize the encrypted connection by a padlock icon in your browser.
In addition, we have implemented technical and organizational measures to ensure the ongoing security of your data.
Tools, Plugins, and Links Used on This Website
This website uses tools, plugins, and links from various providers.
If you follow a link, you will leave our website. The operator of that website is responsible for its content.
Google Maps
This website contains a link to Google Maps, a product of Google. The operator of Google Maps in the EEA and Switzerland is Google Ireland Limited, a company incorporated and operating under Irish law (registration number: 368047) with its registered office at Gordon House, Barrow Street, Dublin 4, Ireland. By clicking the link on this website to Google Maps, you consent to the collection, processing, and use of automatically collected data by Google Inc., its representatives, and third parties. The Google Maps Terms of Service can be found at https://www.google.com/intl/de_US/help/terms_maps.html.
Data is processed for the following purposes:
Finding our location using an online map service.
The legal basis is Article 6(1), sentence 1, subparagraph (a) of the GDPR.
Information on Data Processing on Our Social Media Pages
We maintain company pages on various social media platforms.
We use these platforms to keep our customers and prospective customers informed about our products, news, and events. At the same time, they give us the opportunity to receive feedback and suggestions.
These corporate pages are operated on the basis of the legitimate interests mentioned above, pursuant to Article 6(1)(f) of the GDPR.
In some cases, we have included links to these platforms on our website.
If you click on these links, you will leave our website; this is done based on your consent.
Social Media Links with Consent, Art. 6 (1), Sentence 1, Subparagraph a of the GDPR
Data is processed for the following purposes:
Advertising, Increasing Awareness of the Website
The legal basis is your voluntary consent pursuant to Article 6(1), sentence 1, subparagraph (a) of the GDPR to access the social media platform by clicking on the link.
The social media providers are responsible for data processing on their respective platforms.
When you click the LinkedIn link, your browser connects to the servers of LinkedIn Ireland Unlimited Company.
To find out what data LinkedIn processes and how it does so, please refer to LinkedIn’s privacy policy at https://de.linkedin.com/legal/privacy-policy?trk=homepage-basic_footer-privacy-policy
Data transfers from LinkedIn to third countries that comply with data protection regulations are governed by LinkedIn’s responsibility and privacy policy.
LinkedIn provides us with anonymized statistics for our LinkedIn Company Page, which give us insights into how visitors use our page. This processing of information (Page Insights) is carried out jointly by LinkedIn and us as joint controllers.
This processing is based on our legitimate interests in improving our website and increasing our reach.
The legal basis is Article 6(1)(f) of the GDPR
As part of our joint responsibility, we have entered into a joint controller agreement with LinkedIn Ireland Unlimited Company. You can find details on the division of responsibilities at the following link.
https://legal.linkedin.com/pages-joint-controller-addendum
As a data subject, you can exercise your rights (see: “Right of access, rectification, erasure, restriction, objection, and data portability”) directly with LinkedIn, or we can forward your request to LinkedIn.
https://www.linkedin.com/help/linkedin/ask/PPQ?lang=de
The lead data protection authority in this case is the Irish Data Protection Commission.
When you click the link to XING, your browser connects to the servers of New Work SE at Strandkai 1 in 20457 Hamburg, Germany.
To find out what data is collected and how it is processed by XING, please refer to LinkedIn’s privacy policy at https://privacy.xing.com/de/datenschutzerklaerung
Data transfers from XING to third countries that comply with data protection regulations are governed by XING’s responsibility and privacy policy.
XING provides us with the opportunity, through our XING company page, to introduce ourselves to a wider audience and connect with others
This processing is based on our legitimate interests in improving our website and increasing our reach.
The legal basis is Article 6(1)(f) of the GDPR
Tools/Plugins Based on Consent, Art. 6(1), Sentence 1, Subparagraph (a) of the GDPR
These tools/plug-ins are integrated using the two-click method. This means that these tools are activated only with your explicit consent.
Privacy Policy Update
This Privacy Policy is effective as of December 15, 2025. It is subject to change if the content of our website changes, if legal regulations change, or if we are required to comply with official requirements.
© 2025 ZEiD GmbH. This privacy policy is protected by copyright.