Privacy policy
General information and version date
This privacy policy explains, in accordance with Articles 12 to 14 of the General Data Protection Regulation (GDPR), how personal data is processed when you use the website operated by Econocom ICT GmbH. It applies to all publicly accessible pages and functions of the new ICT website.
Last updated: September 2026
In the configuration reviewed, the website does not use analytics, marketing or profiling technologies before a user interacts with it. Technically necessary security mechanisms may be used without consent. YouTube videos are loaded only after separate consent has been given. The individual processing activities are explained below.
Controller
Econocom ICT GmbH
Erscheckweg 1
72664 Kohlberg
Phone +49 7025 102 0
Data protection officer
You can contact our data protection officer by email at datenschutz@ict.de
Legal bases
The basic principle of this website is: we provide you with information. That is why we do not collect any data.
We process personal data only where there is a legal basis for doing so. This is the case on the careers page, which links to our HR portal, Aventini; see below.
The relevant provisions include, in particular, Article 6(1)(a) GDPR for consent, Article 6(1)(b) GDPR for contracts and pre-contractual measures, Article 6(1)(c) GDPR for legal obligations and Article 6(1)(f) GDPR for legitimate interests. Section 26 of the German Federal Data Protection Act (BDSG) also applies to recruitment, as does Article 9 GDPR where special categories of personal data are involved.
Where information is stored on or accessed from your device, we also comply with section 25 TDDDG. Activities requiring consent take place only with your consent; technically strictly necessary activities are based on section 25(2), no. 2 TDDDG.
Website access, hosting and server log files
When you access the website, technical processing involves your IP address, date and time, the address requested and volume of data transferred, referrer, browser and operating system information, language, connection and status data, and security identifiers. This processing is necessary to deliver content, ensure stability and IT security, analyse errors and prevent abusive access.
The website is provided through Webflow, Inc. Webflow processes technical data as a processor to deliver content and, according to its own privacy policy, also to measure traffic, manage billing and security, and compile depersonalised usage statistics. Webflow uses subprocessors and delivery networks, including Cloudflare, Inc. and Amazon Web Services, Inc. The legal basis for our processing is Article 6(1)(f) GDPR. Our legitimate interests, as defined in law, are to provide a secure, stable and efficient website.
Webflow and individual subprocessors may also process data in the USA and other countries outside the European Economic Area. Where applicable, transfers take place on the basis of an adequacy decision, in particular the EU–US Data Privacy Framework, or appropriate safeguards such as the European Commission's Standard Contractual Clauses. A data processing agreement is in place with Webflow.
Webflow states that browser interaction data, such as cookies or trackers, is retained for up to one year from collection or expiry of the identifier. Webflow does not specify a general fixed retention period for other technical log data; according to the provider's information, it is processed only for as long as necessary to provide the platform or fulfil legal obligations. In the configuration reviewed, Econocom ICT GmbH does not keep its own raw logs of website visitors. Data relating to specific security incidents may be stored until the investigation and any legal proceedings have been concluded.
Technically necessary cookies and security mechanisms
The delivery infrastructure sets the session cookie “_cfuvid” only when a rate-limiting rule configured by Webflow or Cloudflare uses the function for distinguishing unique visitors. This cookie enables the Web Application Firewall to distinguish individual visits when several people share the same IP address.
When “_cfuvid” is set, the identifier prevents everyone sharing an IP address from being grouped together and potentially blocked when an access restriction is active. It is not used for audience measurement or advertising. In this technically necessary case, access to the device is based on section 25(2), no. 2 TDDDG, and the subsequent security processing on Article 6(1)(f) GDPR. Cloudflare may also process this data in the USA; it is engaged contractually as a subprocessor of Webflow.
In the configuration reviewed as at the date of this policy, no analytics, marketing or profiling cookies, advertising pixels or comparable recognition technologies are used before you interact with the website.
Content delivery networks and technical libraries
For presentation, animations, smooth scrolling and filtering functions, the website loads technical files through Webflow delivery networks and jsDelivr, operated by Volentio JSD Limited in England. The libraries used include Lenis, GSAP including Observer, and Finsweet Attributes. The scripts run in the browser; according to the provider, Finsweet Attributes itself does not transmit user data to Finsweet.
When files are requested, jsDelivr processes technically necessary connection data such as the IP address, time, file requested, referrer, and browser and device information. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is in fast, secure and reliable delivery. An adequacy decision is in place for England. jsDelivr uses CDN subprocessors including Cloudflare, Fastly and Gcore; for transfers to third countries that are not otherwise covered, the jsDelivr data processing agreement provides for Standard Contractual Clauses. We do not use these libraries for analytics or advertising.
Locally hosted fonts
We use the Montserrat font to display the website. It is hosted locally through Webflow's delivery infrastructure. Loading the font does not establish a connection to Google Fonts. Only the technical connection data described under “Website access, hosting and server log files” is generated.
YouTube videos with prior consent
On project pages, preview images are initially loaded from our own infrastructure. A connection to YouTube is established only when you select “Agree & load video”. Without this selection, no YouTube player is loaded.
After you give consent, the website loads a player in privacy-enhanced mode through youtube-nocookie.com, together with the YouTube Iframe API. In particular, your IP address, device and browser information, referrer, the page accessed, playback and interaction data, and cookie or local storage identifiers may be transmitted to Google Ireland Limited and Google LLC. If you are signed in to Google, Google may associate this activity with your account. Privacy-enhanced mode does not rule out processing.
The legal bases are your consent under Article 6(1)(a) GDPR and, where information is stored on or accessed from your device, section 25(1) TDDDG. Consent is voluntary, is not required to use the rest of the website and can be withdrawn with future effect using “Withdraw consent”. For transfers to the USA, Google may use the EU–US Data Privacy Framework and supplementary safeguards.
Applications through Aventini
Vacancies and speculative applications link to the external application portal operated by aventini GmbH. A connection to ict.aventini.io is established only after you click the link. Econocom ICT GmbH remains the controller of applicant data. Aventini processes the data as a processor.
The data processed includes, in particular, basic personal and contact details, the desired role and locations, proposed start date, salary expectations, information about professional qualifications and geographical flexibility, communications, and documents you upload, such as your CV, certificates, photograph and other documents. Mandatory fields are marked in the portal; an application cannot be processed without the information required to assess it.
Processing takes place to decide whether to enter into an employment relationship, on the basis of section 26(1) BDSG and, where applicable, Article 6(1)(b) GDPR. Article 6(1)(f) GDPR may additionally apply to the defence or enforcement of claims. Where necessary, we process special categories of personal data under Article 9(2)(b) GDPR in conjunction with section 26(3) BDSG; voluntary processing takes place only on the basis of explicit consent under Article 9(2)(a) GDPR in conjunction with section 26(2) BDSG.
The Aventini portal offers an optional function that automatically reads the contents of an uploaded CV and transfers them into structured form fields. The CV and the information extracted from it are processed for this purpose; the recipient is Aventini as the portal operator. This function is used only with separate consent, is not required to apply and can be withdrawn with future effect by contacting datenschutz@ict.de. It does not involve scoring or ranking applications.
Decisions on applications and other matters are not made solely by automated means within the meaning of Article 22 GDPR. Optional CV parsing merely transfers information into form fields. Every selection and hiring decision is reviewed and made by the responsible members of staff.
If an application does not result in employment, applicant data is normally deleted no later than six months after the specific recruitment process ends through rejection or withdrawal, unless a specific legal defence requires longer retention. Inclusion in an applicant pool takes place only with separate, time-limited consent. If an applicant is hired, the data required for the employment relationship is transferred to their personnel file.
Scheduling appointments through Calendly
Some careers pages offer an optional external Calendly link for scheduling appointments. No connection to Calendly is established before you click it. When you visit the external Calendly page, Calendly is itself responsible for the page, security and cookie data processed there. When you book an appointment, the data processed includes, in particular, your name, email address, selected appointment, any additional answers, and technical access, device, time zone and usage data. Alternatively, you can contact us by email or telephone.
For booking data that Calendly processes under our instructions within ICT's business account, Calendly LLC, USA, acts as a processor; for its own account, security and product purposes, Calendly acts as an independent controller. The legal basis for our processing is Article 6(1)(b) GDPR for pre-contractual matters and, otherwise, Article 6(1)(f) GDPR based on our interest in straightforward appointment scheduling. Calendly LLC is certified under the EU–US Data Privacy Framework; where this does not apply, the Calendly data processing agreement provides for Standard Contractual Clauses.
Contact through WhatsApp
Some careers pages offer an optional external link to WhatsApp. No connection to WhatsApp is established before you click it. If you use WhatsApp, we process your telephone number, profile details, messages, attachments and communication metadata to deal with your enquiry. Email and telephone are available as alternatives.
The legal basis for our processing is Article 6(1)(b) GDPR for pre-contractual communications and, otherwise, Article 6(1)(f) GDPR. For users in the European Region, WhatsApp is provided by WhatsApp Ireland Limited, which processes data as an independent controller; Meta's global infrastructure may also involve processing outside the EEA. According to WhatsApp, personal messages are end-to-end encrypted.
Google Maps and other external links
Locations are not loaded through an embedded Google Maps map or Maps API. The website contains only external links to route planners and other resources. The destination page opens only after you click the link; its operator then receives the usual connection data and, where applicable, the referrer. Depending on your settings, Google Maps may also process destination and location data. The relevant external provider is responsible for this processing.
Contact by email and telephone
If you contact us by email or telephone, we process your contact details, the content of your enquiry and the associated correspondence. Providing this information is voluntary; without the details needed to handle your enquiry, we may be unable to respond.
The legal basis is Article 6(1)(b) GDPR where the communication concerns a contract or pre-contractual measures and, otherwise, Article 6(1)(f) GDPR based on our interest in handling enquiries. We delete the data when the purpose no longer applies and there are no statutory retention obligations or legitimate grounds for keeping it longer.
Search and filters
Search and filter fields on careers, projects and rental pages are processed in the browser. In the configuration reviewed, the filter values entered are not transmitted to us or an external analytics service and are not stored permanently.
Downloads and media files
Images, videos and documents available for download are provided through Webflow or AWS delivery infrastructure, or through addresses operated by ICT. Accessing them generates the technical connection data described in the hosting section. In the configuration reviewed, we do not carry out any additional analysis of download behaviour.
Retention periods
Unless this policy specifies a particular period, we retain personal data only for as long as the relevant purpose applies. The data is then deleted or anonymised unless statutory retention obligations, the establishment, exercise or defence of legal claims, or valid consent justify longer retention.
Recipients and processors
Data is received only by the service providers named in this policy, the responsible internal departments and other recipients where this is necessary for the relevant purpose or required by law. Processors are engaged under contracts in accordance with Article 28 GDPR. We do not disclose data for advertising purposes.
Your data protection rights
Subject to the applicable statutory conditions, you have the right of access under Article 15 GDPR, rectification under Article 16 GDPR, erasure under Article 17 GDPR, restriction of processing under Article 18 GDPR, data portability under Article 20 GDPR and objection under Article 21 GDPR. To exercise your rights, simply send a message to datenschutz@ict.de.
Withdrawal of consent and objections
You may withdraw consent at any time with future effect; this does not affect the lawfulness of processing carried out before withdrawal. Where processing is based on Article 6(1)(f) GDPR, you may object on grounds relating to your particular situation. You have the right to object to direct marketing at any time; the website described here does not currently involve direct marketing.
Right to lodge a complaint
Under Article 77 GDPR, you may lodge a complaint with a data protection supervisory authority. In particular, the authority responsible for our registered office is the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg: Heilbronner Straße 35, 70191 Stuttgart; email: poststelle@lfdi.bwl.de; www.baden-wuerttemberg.datenschutz.de.
Changes to this privacy policy
We update this privacy policy when the website, the services used or legal requirements change. The version made available on this page is the applicable version.