Privacy Policy

Below, we inform you about the collection of personal data when using our website. Personal data means all data that can be related to you personally, e.g. name, address, e-mail addresses, user behavior. We have taken extensive technical and organizational security measures to protect your data from accidental or intentional manipulation, loss, destruction, or unauthorized access. Our security procedures are regularly reviewed and adjusted to technological progress.

1. Controller for Data Processing

The controller pursuant to Art. 4 (7) EU General Data Protection Regulation (GDPR) is:

Rexx Systems GmbH
Süderstrasse 75-79
20097 Hamburg
Germany

Tel. +49 40 8 900 800
Fax +49 40 8 900 80 – 120

2. Contact Details of the Data Protection Officer

You can reach our Data Protection Officer at datenschutz@rexx-systems.com or by post at:

Rexx Systems GmbH
Confidential/personal to the Data Protection Officer: Vanessa Martin
Süderstraße 75-77
20097 Hamburg

3. Your Rights

You have the following rights regarding your personal data processed by us:

3.1 General Rights

You have the right to access, rectification, erasure, restriction of processing, objection to processing, and data portability. Where processing is based on your consent, you have the right to withdraw that consent at any time with effect for the future.

3.2 Rights Related to Processing Based on Legitimate Interests

Under Art. 21 (1) GDPR, you have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you that is based on Art. 6 (1) e GDPR (data processing in the public interest) or Art. 6 (1) f GDPR (data processing for legitimate interests). This also applies to profiling based on these provisions.
In the event of your objection, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or the processing serves the establishment, exercise, or defense of legal claims.

3.3 Rights in Case of Direct Marketing

If we process your personal data for direct marketing purposes, you have the right under Art. 21 (2) GDPR to object at any time to the processing of personal data concerning you for such marketing, including profiling related to such direct marketing.
If you object to processing for direct marketing purposes, we will no longer process your personal data for these purposes.

3.4 Right to Lodge a Complaint with a Supervisory Authority

You also have the right to lodge a complaint with a competent data protection supervisory authority concerning our processing of your personal data.

4. Collection of Personal Data When Visiting Our Website

When you use our website purely for informational purposes, meaning you do not register or otherwise transmit information to us, we only collect the personal data your browser transmits to our server.
If you wish to view our website, we collect the following data, which are technically necessary for us to display our website and to ensure its stability and security. The legal basis is Art. 6 (1) f GDPR:

– IP address
– Date and time of the request
– Time zone difference from Greenwich Mean Time (GMT)
– Content of the request (specific page)
– Access status/HTTP status code
– Amount of data transmitted
– Website from which the request originates
– Browser
– Operating system and its interface
– Language and version of the browser software

5. Contact via E-Mail or Contact Form

When you contact us by e-mail or via a contact form, the data you provide (your name, e-mail address, company name, and area of interest) are stored by us to answer your inquiry.
Where we request information in our contact form that is not necessary for contacting us, this is always marked as optional. Such information helps us to specify your request and handle your concern more effectively. The provision of such information is entirely voluntary and based on your consent pursuant to Art. 6 (1) a GDPR.
If this includes contact details (e.g. e-mail address, phone number), you also consent to us contacting you via these channels to answer your inquiry. You may withdraw this consent at any time with effect for the future.

We delete the data collected in this context once storage is no longer required or restrict processing if statutory retention obligations exist.

6. Applications

You can apply to our company through our application portal at https://rexx-systems.com/jobs/. Please note that e-mails sent without encryption are not protected against unauthorized access.

Your data will be used to process your application and make a decision regarding potential employment. The legal basis is Art. 6 (1) (b) GDPR.
Additionally, your personal data may be processed where this is necessary to defend against legal claims arising from the application process. The legal basis here is Art. 6 (1) (f) GDPR. This is also our legitimate interest.

If an employment relationship is established, we may further process the personal data already received from you for employment-related purposes if necessary for the performance or termination of the employment relationship, pursuant to Art. 6 (1) (b) GDPR. No further processing beyond the stated purposes takes place.

Your personal data will be deleted no later than six months after completion of the application process unless deletion conflicts with other legitimate interests on our part or you have given consent for longer storage. Legitimate interests in this sense include, for example, the burden of proof in proceedings under the General Equal Treatment Act (AGG). Further information can be found in our “Information Obligations for Applicants.”

Use of AI Support in Application Analysis:
We use a non-self-learning, German-language AI software to assist in analyzing applications.
This helps us match qualifications and experience with the job requirements and identify relevant information from résumés.

The AI serves solely as a support tool for our HR personnel – it does not make automated decisions. Final evaluation and selection are always carried out by humans.

Voluntary Use During CV Upload:
When uploading a résumé, applicants can choose whether to use AI-assisted support for automatically filling in form fields (e.g. importing personal data from the résumé).
This feature is optional and can be deselected at any time without affecting the application.

7. Newsletter

With your consent under Art. 6 (1) a GDPR, you can subscribe to our newsletter, which informs you about our current offers.

We use the double opt-in procedure for newsletter registration. This means that after your registration, we send an e-mail to the address you provided, asking you to confirm that you wish to receive the newsletter. If you do not confirm your registration within 24 hours, your information will be blocked and automatically deleted after one month.

We also store your IP addresses and the time of registration and confirmation. The purpose of this process is to be able to prove your registration and, if necessary, to clarify any possible misuse of your personal data.

The only mandatory information for receiving the newsletter is your e-mail address. Any additional data requested is voluntary and used to address you personally. After your confirmation, we store your e-mail address to send you the newsletter. The legal basis is Art. 6 (1) a GDPR.

You may withdraw your consent to receive the newsletter at any time and unsubscribe. You can declare your withdrawal by clicking the link provided in every newsletter e-mail or by contacting our Data Protection Officer as stated above.

8. Participation in Competitions

If you participate in one of our competitions, we collect the data required to carry out the competition. This generally includes an individual competition entry (e.g. a comment or photo) as well as your name and contact details.
We may share your data with our competition partners, for example, to deliver the prize. The exact data processing and data sharing may vary per competition and are described in the respective participation terms.
Participation and related data collection are, of course, voluntary. The legal basis for data processing is your consent under Art. 6 (1) a GDPR, which you may withdraw at any time with effect for the future. Your data will be deleted after the competition has ended.

9. Podcast Plugins

To share our experience in the HR software field, we offer a podcast with interesting topics. Episodes can be accessed via various providers. For this purpose, this website uses podcast plugins from the following providers:

  • Spotify (Operator: Spotify AB, Regeringsgatan 19, SE-111 53 Stockholm, Sweden)

  • SoundCloud (Operator: SoundCloud Global Limited & Co. KG, Rheinsberger Str. 76/77, 10115 Berlin, Germany)

  • Deezer (Operator: Deezer limited Company, 24 rue de Calais, 75009 Paris, France)

  • Player.fm (Operator: Maple Media LLC, 1510 Fashion Island Blvd Suite 300, San Mateo, CA 94404, USA)

  • Apple Podcasts (Operator: Apple GmbH, Katharina-von-Bora-Str. 3, 80333 Munich, Germany)

  • Podcast.de (Operator: podcast.de, Brunnenstraße 147, 10115 Berlin, Germany)

  • Podtail (Operator: Fredrik Jungstedt AB, Rutger Fuchsgatan 8, 116 67 Stockholm, Sweden)

  • YouTube (Operator: YouTube LLC, 901 Cherry Ave., San Bruno, CA 94066, USA)

Functions of these podcast services are integrated via plugins. These plugins are only activated when you click on them, thereby giving your consent for data to be transmitted to the respective podcast service.

The legal basis for the use of these plugins is your consent under Art. 6 (1) a GDPR and § 25 (1) TDDDG. Once activated, these plugins collect personal data such as your IP address and transmit it to the provider’s servers, where it is stored. Activated podcast plugins may also set cookies with a unique identifier, enabling providers to create profiles of your usage behavior.
If you have an account with the podcast service and are logged in during your visit to our site, your data and information about your visit may be linked to your personal account. You can prevent this by logging out of your podcast account and deleting the relevant cookies before visiting our site.

We have no control over the exact scope of data collected by the respective podcast service. For more information on the nature, scope, and purpose of data processing, as well as your rights and privacy options, please consult the privacy policies of the respective providers:

10. Use of Cookies

When using our website, cookies are stored on your device. Cookies are small data files stored by the website you visit, allowing your browser to be recognized on subsequent visits. Cookies transmit information to the entity that set them.

Cookies can store various types of information, such as language preferences, time spent on the website, or input made. This helps, for example, to avoid re-entering data in forms. The information stored can also be used to tailor content to user preferences.

There are different types of cookies:

  • Session cookies are temporarily stored in memory and deleted when you close your browser.

  • Persistent cookies are automatically deleted after a specified duration that may vary per cookie.

  • First-party cookies are set by the website you are visiting and can only be read by that site.

  • Third-party cookies are set by organizations other than the operator of the website you are visiting (e.g., marketing companies).

The legal basis for processing personal data via cookies and their storage duration may vary. Where you have given consent, the legal basis is Art. 6 (1) a GDPR and § 25 (1) TDDDG. Where processing is based on legitimate interests, the legal basis is Art. 6 (1) f GDPR and § 25 (2) No. 2 TDDDG.

You can configure your browser to reject third-party or all cookies. However, doing so may prevent you from using all functions of this website.
We use cookies to ensure the website functions properly, provide essential functionalities, measure reach, and – with your consent – tailor our services to your interests. We use both transient and persistent cookies.

This website uses the following types of cookies, explained in more detail below.

11. Website Analytics

For the purpose of analyzing and optimizing our website, we use various services described below. This helps us understand how many users visit our site, which content is most popular, and how visitors navigate our offerings. We collect data such as the referring website (referrer), accessed subpages, frequency and duration of visits, etc. This information helps us make our content more user-friendly and effective.

11.1 Matomo

Our website uses the open-source web analytics service Matomo, operated by InnoCraft Ltd, 7 Waterloo Quay, PO625 Wellington, New Zealand. Since InnoCraft is based outside the EU, it has appointed an EU representative: ePrivacy Holding GmbH, Große Bleichen 21, 20354 Hamburg (privacy@innocraft.com).

We use Matomo data to statistically analyze user behavior to optimize website functionality, stability, and marketing effectiveness. Our legitimate interest and purpose lie in improving our website and services.

Matomo uses cookies to analyze website use. The information collected (including your shortened IP address) is transmitted to Matomo’s EU-based server and stored for analysis. No data is transferred to servers outside our control. Your IP address is immediately anonymized, making you unidentifiable. The data will not be shared with third parties.

We store analysis data only as long as necessary for processing purposes, but no longer than 5 months and 28 days.

You can prevent cookies from being set via your browser settings, but this may limit website functionality.
If you do not agree to the storage and evaluation of your data, you can opt out below. An opt-out cookie will then be set in your browser to prevent data collection by Matomo. Please note that if you delete cookies, this opt-out cookie will also be deleted and must be reset.

The legal basis for this data processing is your consent under Art. 6 (1) a GDPR and § 25 (1) TDDDG. You may withdraw your consent at any time with future effect via our Consent Management Platform.