Privacy policy

Privacy policy

Last updated 27 October 2021

At VESTIGAS, data protection is a priority. This Privacy Policy sets forth how VESTIGAS GmbH and its group of companies („us,“ „our,“ or „we“) collect and use personal information from customers and other individuals (collectively, „you“) who access or use our websites, including https://vestigas.com, our app, our web app, and/or any of our other websites, products, or services linked to this Privacy Policy (collectively, „VESTIGAS Services“). By using our Services, you acknowledge that we may collect and use your personal information as described in this Privacy Policy.

In some cases, we may process your personal data pursuant to an agreement with a third party organization. In these cases, the terms of this agreement may determine how we process your personal data. If you believe that a third party organization has asked us to process your personal data on their behalf, please contact them first as they are responsible for how we process your data. This Privacy Policy does not apply to third-party websites and apps that you may use, including those linked in our Services. You should review the terms and policies for third-party websites and apps before clicking on links.

The core product of VESTIGAS services is the digital exchange of delivery data and its automatic post-processing. As part of our services, users want us to collect and record information that helps parties prove the validity and content of transactions. This information includes the people involved in the transactions, their exact location, and the devices these people use.

We respect your privacy to the fullest extent. To do so, we recommend that you read this Privacy Policy in its entirety to ensure that you are fully informed.

I. What personal data we process

You have a choice whether you visit our websites, install our apps, or provide us with personal information. However, if you do not provide us with certain personal information, you may not be able to use some parts of our Services. For example, if you do not want to submit your location and Bluetooth data, we cannot perform automated electronic signing of delivery bills. For information about choices and your privacy rights, see Sections V and VII of this Privacy Policy.

1. personal data that you provide to us

You provide us with personal information about yourself when you:

  • or an employee of your employer provides us with the relevant personal data when registering,
  • make an electronic signature,
  • Revise your personal user profile,
  • open and use the app, and/or
  • Contact customer support.

You also provide us with personal information about others when you use parts of our services, such as when you:

  • Start or participate in an electronic transaction, e.g. accept the electronic signature of your counterpart,
  • as IT administrator create employees during registration and/or
  • refer us to contacts of potential customers.

Your main choice for this type of personal data is to simply not provide it, for example by disabling geolocation in the app. For other choices, see Section V of this Privacy Policy. If certain data are issued, proper functioning of the program can no longer be guaranteed. Examples of the categories of personal information you provide include:

  • Identifiers: First and last name, e-mail address, phone number, company affiliation, position in the company, profile picture and selected language.
  • Radio information: Bluetooth connections
  • Geolocation: physical location incl. Distances and necessary storage, even when the application is not actively used.
  • In individual cases addresses and payment information

2. personal data that we collect automatically

We automatically collect personal information from you and your devices when you use our services, including when you visit our websites or applications without logging in. The categories of personal data we automatically collect include: Device, Usage Information, and Transaction Data.

We collect personal information about how you use our Services and which computers or other devices, such as cell phones or tablets, you use to access our Services. Some examples are:

  • IP address,
  • Unique device identifiers and device attributes, such as operating system and browser type,
  • Usage data, such as: Web log data, referring and exit pages and URLs, platform type, number of clicks, domain names, landing pages, pages and content visited and the order of those pages, time spent on specific pages, the date and time you used our Services, the frequency of your use of our Services, error logs, and other similar information,
  • Cookies and related technologies. Selection options can be taken from section V

3. information we collect from other sources.

We may collect personal information about you from others, such as:

  • Third Party Sources: Examples of third party sources include marketers, partners, researchers, affiliates, service providers and others who are permitted by law to share your personal information with us. For example, if you register for our services on another website, that website may share your personal information with us.
  • Other customers: Other customers may share with us your personal information. For example, if a customer wants you to sign an electronic delivery bill using our services, they give us your name,email address, and company affiliation.
  • Combining Personal Data from Different Sources: We may combine the personal information we receive from other sources with the personal information we collect from you (or your device) and use it as described in this Privacy Policy.

4. personal data that we collect and process on behalf of our customers

When our business customers use certain services, we generally process and store certain personal data on their behalf as a processor. For example, in the context of delivery note transmission, we act as a processor of the parties using VESTIGAS services (customers) and process their legal relationships in the form of delivery bills. In these cases, our customers are the contractual partners and responsible for the processing of personal data. If you have any questions or concerns about how personal data is processed in these cases, including how to exercise your rights as a data subject, you should contact your contractor (the person requesting your signature). If we receive requests for rights in relation to cases where we are acting as a processor, we will forward your request to the relevant client.

We collect your personal information to provide and improve our services and to support advertising and marketing. For more information, please refer to Section II „Use of Personal Data“. We may share your personal information with third parties as described in Section IV „Sharing Personal Information with Third Parties.“

II. use of personal data

In general, we collect, use, store and process your personal data to provide our services, to correct and improve them, to develop new services and to market our companies and their products and services. Here are some examples of how we use the personal data we process:

  • Process your requests via our website and app,
  • Provide you with the requested services and products and to invoice or collect payments,
  • Create your account(s) and manage your relationship with us,
  • Sending you records of our relationship,
  • Logging details about how delivery documents are handled, such as who processed or signed them, what equipment was used, and when these operations take place,
  • Conduct referral programs,
  • Creating and reviewing data about our users and how they use our Services,
  • Test changes to our services and develop new features and products,
  • Resolving issues you have with our Services, including answering support questions and resolving disputes,
  • Manage the service platform, including support systems and security,
  • Prevent, Investigate, and Respond to: Fraud, unauthorized access to or use of our services, violations of terms and policies, or other unlawful conduct,
  • Compliance with legal obligations and retention requirements,
  • Marketing features, products or special events by email or phone, or sending you marketing communications about third party products and services that we believe may be of interest to you,
  • Selecting and delivering content and personalized advertising, and supporting the marketing and promotion of our services.

Other uses. We may combine („aggregate“) or remove („de-identify“) portions of personal information we collect to limit or prevent identification of a particular user or device to support goals such as research and marketing. Once such information has been aggregated and anonymized so that it no longer qualifies as personal data under data protection law, this Privacy Policy will no longer apply.

Legal basis for the processing of your personal data. We collect or use personal data from you or other persons only if we have your consent to do so, if the personal data is necessary for the performance of a contract with you, or if the processing is in our legitimate interests and does not override your interests or fundamental rights and freedoms. In some cases, we are legally required to collect or retain personal data, or the personal data is necessary to protect your vital interests or those of another person. For example, when we:

  • Use personal information to create and manage an account. This is done to provide you with the appropriate services and to fulfill our contract with you. Only the first and last name, e-mail address, telephone number, company affiliation and position in the company are used for this purpose.
  • Collect and record data associated with the use of a digital certificate or digital signature to comply with regulatory requirements.
  • If we collect and analyze usage data, for example to improve our services or to ensure the security of our websites, we do so on the basis of our legitimate interest in securing and improving our services.
  • names and email addresses for email marketing purposes, we do so with your consent (which you may withdraw at any time) or, to the extent permitted by applicable law, based on our legitimate interests.

III. storage of personal data

We do not store your personal data for longer than is necessary for the purposes for which they are processed. The length of time we retain personal information depends on the purposes for which we collected and used it, and/ or as necessary to comply with applicable laws, as set forth in our Personal Information Retention Policy and Information Processing Standards, and/ or unless you have specifically consented to further use of your information. Where there are technical limitations that prevent deletion or anonymization, we protect personal data and restrict its active use.

IV. Disclosure of personal data to third parties

We do not share your personal information with third parties except as set forth in the list below. In addition, we do not share your personal information in a manner that would be considered a sale under applicable law.

  • Affiliated companies. We may share your personal information with other companies that are under common ownership or control of VESTIGAS. These companies use your personal information as described in this Privacy Policy.
  • Your employer or organization. If you create an account or user role with an email address assigned to you as an employee, contractor, or member of an organization, that organization may find your account as a VESTIGAS customer and perform certain actions that may affect your account.
  • Data transactions. If you are registered with VESTIGAS and have a profile, other VESTIGAS users may view your profile information (in particular name and company affiliation) as part of data transactions (e.g.: by scanning close users).
  • Business transactions. We may share your personal information during a corporate transaction such as a merger or sale of our assets, or as part of the due diligence process for such proposed transactions. When a corporate transaction occurs, we will notify you of any changes in control of your personal information and of your choices.
  • Public or government agencies. We may disclose your personal information only if we are legally required to do so to comply with applicable laws or to respond to legal process (such as an injunction). We may also share your personal information when an individual’s physical safety is threatened, when there are violations of this Privacy Policy or other agreements, or to protect the legal rights of third parties, including our employees, users or the public.
  • Service provider. We only share your personal data with third parties that we use to support our services, such as the error analysis tool „Sentry“. These companies provide services such as intelligent search technologies, intelligent error analysis, evaluations, advertising, authentication systems, bill collection, fraud detection, and customer support. We have contracts with our service providers that ensure the protection and proper processing of your personal data.

V. Your choices

This section describes many of the steps you can take to change or limit the collection or use of your personal information.

  • Profile. You are not obliged to enter any further data in your profile apart from the basic information described in section I.1 (in particular first and last name, e-mail address and company affiliation). You may access and review or revise this personal information at any time.
  • Device and Usage Information. If you do not want us to view and process your device’s geolocation (GPS location) or Bluetooth radio information, you can disable location and Bluetooth sharing on your device, change your device’s privacy settings, or opt out of location sharing in your browser or directly in the mobile app. Proper functioning of the app is then no longer guaranteed.
  • Marketing News. If you register for our newsletter, we use the data required for this purpose or separately provided by you to regularly send you our e-mail newsletter based on your consent. Unsubscribing from the newsletter is possible at any time and can be done either by sending a message to the contact option described below or via a link provided for this purpose in the newsletter. After unsubscribing, we will delete your e-mail address unless you have expressly consented to further use of your data or we reserve the right to use data beyond this, which is permitted by law and about which we inform you in this statement.
  • Postal advertising. In addition, we reserve the right to use your first and last name as well as your postal address (on the employer side or on the part of the organization for which you use VESTIGAS) for our own advertising purposes, e.g. to send you interesting offers and information about our products by mail. This serves to protect our legitimate interests in addressing our customers in an advertising manner, which outweigh our interests in the context of a balancing of interests. The postal advertising is sent as part of processing on our behalf by a service provider to whom we pass on your required postal delivery data for this purpose. This service provider is located within a country of the European Union or the European Economic Area. You can revoke the postal advertising at any time using the contact described below.
  • Cookies and other related technologies. You can refuse cookies through your browser settings or through Real Cookie Banner’s Cookie Preference Center and other methods. In order to make the visit to our website attractive and to enable the use of certain functions, to display suitable products or for market research, we use so-called cookies on various pages. This serves to protect our legitimate interests in an optimized presentation of our offer, which outweigh our interests in the context of a balancing of interests. If cookies are not accepted, the functionality of our website may be limited. Cookies are small text files that are automatically stored on your terminal device. Some of the cookies we use are deleted at the end of the browser session, i.e. after you close your browser (so-called session cookies). Other cookies remain on your terminal device and enable us to recognize your browser on your next visit (persistent cookies). The duration of storage can be found in the overview in the cookie settings of your web browser. You can set your browser so that you are informed about the setting of cookies and decide individually about their acceptance or exclude the acceptance of cookies for certain cases or in general. Each browser differs in the way it manages cookie settings. This is described in the help menu of each browser, which explains how you can change your cookie settings. You can find these for the respective browsers under the following links:

Internet Explorer™: https://support.microsoft.com/de-de/windows/löschen-und-verwalten-von-cookies-168dab11-0753-043d-7c16-ede5947fc64d

Safari™: https://support.apple.com/de-de/guide/safari/sfri11471/mac

Chrome™: https://support.google.com/chrome/answer/95647?hl=de&hlrm=en

Firefox™: https://support.mozilla.org/de/kb/cookies-erlauben-und-ablehnen

Opera™: https://help.opera.com/de/latest/web-preferences/

  • Web analytics. For website analysis, this website uses the web analysis software Google Analytics, a service of the provider Google Inc. to automatically collect and store data during page visits, from which usage profiles are created using pseudonyms. As an equivalent, the analysis software Google Analytics Firebase (provider: Google Inc.) and Sentry (provider: Software Inc.) are used for the mobile application. These serve to protect our legitimate interests in an optimized presentation of our offer, which prevail in the context of a balancing of interests. Cookies may be used for this purpose. The pseudonymized user profiles are not combined with personal data about the bearer of the pseudonym without a separate, express consent. You can object to the collection and storage of data at any time with effect for the future by contacting us.
  • Complaints. We are committed to resolving legitimate complaints about your privacy and our collection or use of your personal information in accordance with applicable laws. If you have any questions or complaints about our practices regarding the use of personal information or our privacy policy, please contact us at info@vestigas.com.

VI. privacy of children

Our Services are not intended for, and are not marketed to, persons under the age of 18 („Children“). We do not knowingly collect or ask for personal information from children. We do not knowingly allow children to use our services. If you are a child, please do not use our services or send us any personal information. We delete personal information that we learn was collected from a child without verified parental consent. Please contact us at info@vestigas.com if you believe we may have personal information from or about a child.

VII. Your data protection rights

You may have certain rights with respect to your personal data subject to national data protection laws. These rights include:

  • You can access and review the personal information associated with your account at any time by logging into your account and viewing your profile under Settings. You may also request the following information: How we collect and use your personal information and why; the categories of personal information involved; the categories of recipients of your personal information; how we obtained your personal information and its source; our business purpose for using your personal information; and how long we use or retain your personal information or how we determine relevant retention periods.
  • You have the right to correct inaccurate or false personal information about you.
  • In certain situations, you may request that we erase/remove your personal data or restrict processing (and object to the use of your personal data) or export your personal data to another provider in a structured, commonly used and machine-readable format.
  • If we rely on your consent to process your personal data, you have the right to refuse consent and/ or, if given, to withdraw consent at any time. The revocation of consent shall not affect the lawfulness of the processing carried out on the basis of the consent until the revocation.
  • If you are not satisfied with our response to your complaint, you have the right to raise questions or complaints with a competent data protection authority at any time.

We will take reasonable steps to verify your identity. If you have an account with us and your IT administrator has registered, we can verify you via your login to your account. If you do not have an account with us, we may ask you to provide additional information that will allow us to verify your identity. You may authorize a representative to make a request to us on your behalf, and we will verify the identity of your representative or agent by requesting either confirmation from you or documents evidencing the representative’s authority to act on your behalf.

Certain personal information may be exempt from such requests under applicable law. We need certain types of personal information to provide you with the Product and Services. If you ask us to delete them, you may no longer be able to access or use our product and services.

If you wish to exercise these rights, please contact us at https://www.vestigas.com or by email at info@vestigas.com.

VIII. How we protect your personal data

To protect your personal information, we use physical, electronic and managerial tools. We will adapt these tools based on the sensitivity of the personal data we collect, use and store and the current state of the art. We protect your personal data through appropriate technical and organizational measures to minimize security risks related to data loss, misuse, unauthorized access, and unauthorized disclosure and alteration.

IX. Changes to this Privacy Policy

We may amend this Privacy Policy to reflect changes in legislation, our businesses, our services, our collection and use of data, or advances in technology. Our use of the personal information we collect is governed by the privacy policy in effect at the time we use that personal information. Depending on the type of customization, we may notify you of the change by posting it on this website, by adding a banner to https://app.vestigas.com or the mobile app, or by email.

X. How to contact us

If you have any questions or complaints regarding our use of your personal information or the Privacy Policy, please contact VESTIGAS at Dorf Zellhub 48, 84307, Eggenfelden, call +49 89 95893094.

GDPR Cookie Consent mit Real Cookie Banner