Content
1. Data protection statement
FGK Clinical Research GmbH is delighted that you have visited our website and are interested in our company. FGK Clinical Research GmbH (FGK) is committed to complying with the General Data Protection Regulation (GDPR) as the controller responsible for processing personal data. Below, we describe what personal data FGK collects about you when you use this website, what your personal data is used for, and how it is processed. You are not obliged to provide us with personal data. It is generally possible to use our website without providing personal data. If personal data is processed in certain areas (e.g. through cookies, analysis/tracking tools or contact forms), we will inform you in detail in the relevant section of this privacy policy. There you will also find information on how you can prevent or deactivate certain processing operations. The personal data that users transmit via this website will be processed in accordance with the provisions of this privacy policy. This privacy policy applies to all pages within our website. It does not apply to external third-party websites to which FGK refers. FGK accepts no responsibility for the content and processing of personal data on these external sites. This privacy policy also applies to other online presences operated by us, such as our company page on LinkedIn (see point 7 below, Social media presence, LinkedIn). Please note that data processing on such platforms is also subject to the privacy policies of the respective operator. FGK accepts no responsibility for compliance with data protection regulations by third parties and is not responsible for the content of external websites to which this website refers.
2. What personal data do we collect?
Depending on the purpose of the processing, we may collect the following categories of personal data:
- Identification data in connection with your inquiry (via the contact form/by email or telephone): e.g., first and last name, telephone number, email address, communication content, company information, or other details.
- Voluntary information: This is data that you provide to us on a voluntary basis without us asking for it, such as the reason for contacting us.
- Technical data/website usage data: This is data generated in connection with the use of the website, e.g., IP address, device and usage information, referrer URL; for example, cookies may store personal data, which may include: IP addresses, browser type, location, operating system, etc. For more information, please see our “Cookie Notice.”
3. For what purpose do we use your personal data?
- Customer support: We process your personal data for the purpose of handling and responding to your request.
- Job applications: The personal data you provide will be processed for the purpose of conducting the application process and deciding whether to establish an employment relationship. For this purpose, your data will be forwarded to our service provider Personio, which supports us in handling the application process (see section 6, Applications (Personio)).
- Technical data: See our “Note on cookies.”
4. On what basis do we use your personal data?
- Customer service: We process your personal data to handle the inquiries you submit via the various contact channels, depending on the type of inquiry, either on the basis of Art. 6 (1) (b) GDPR (to carry out pre-contractual measures or to fulfill a contract) or on the basis of Art. 6 (1) (f) GDPR (our legitimate interest in effective communication with interested parties).
- Applications: The processing of your application documents and the personal data provided in this context is based on Art. 6 (1) (b) GDPR (pre-contractual measures) and on § 26 (1) BDSG (Federal Data Protection Act) for the establishment of a possible employment relationship.
- Technical data: See our “Notice on cookies.”
5. How long will we retain your personal data?
The retention period for your personal data depends on the purposes for which we process this data, as explained below
- Customer service: We process your data for as long as is necessary to process your inquiry or request.
- Job applications: The duration of storage depends on the outcome of the application process. If an employment relationship is established, we process and store your personal data for the duration of your employment, which also includes the processing of the employment relationship. If your application is rejected, your data will be deleted no later than six months after the application process has been completed, unless there are legal retention obligations or longer storage is necessary to defend against any legal claims that may be asserted. If we store your personal data on the basis of your consent in order to be able to contact you when new vacancies arise (e.g., talent pool), we will store your data until you revoke your consent or until we no longer consider storage to be necessary (usually after 1 year).
- Technical data: See our “Note on cookies”
6. Third-party services
Applications
Personio
The data transmitted as part of your application is transferred using TLS encryption and stored in a database. Your personal data will only be processed for the purpose of your application.
The database is operated by Personio GmbH, which offers human resources management and applicant management software (Imprint | Personio). Personio is our processor within the meaning of Art. 28 GDPR. The basis for processing here is a data processing agreement between FGK as the controller and Personio as the processor.
Borlabs
This website uses the Borlabs Cookie plugin as a consent management tool. This enables FGK to inform users of this website about cookies (e.g., for tracking) and obtain their consent. See also our “Note on cookies.” The Borlabs cookie belongs to the category of “essential” cookies for the operation of our website and cannot be deactivated.
Google Analytics 4
This website uses functions of the web analysis service Google Analytics. The provider is Google Ireland Limited, Gordon House, Barrow Street Dublin 4, Ireland (“Google”). Google Analytics enables us to analyze the behavior of website visitors. Cookies are used for this purpose, which are stored on your device and enable an analysis of your use of our website (e.g., page views, origin, length of stay, device and browser data). The information collected by the cookies is usually transferred to a Google server in the USA and stored there. We use Google Analytics with IP anonymization enabled. This means that your IP address is truncated by Google within the EU or other contracting states of the EEA before being transmitted to the USA. The cookie expires after 2 years.
The legal basis for the use of Google Analytics is your consent in accordance with Art. 6 (1) lit. a GDPR and §25 (1) TTDSG.
You can revoke your consent at any time with effect for the future by deactivating this service via the “Cookie Consent Tool” provided on the website (category “Statistics”). You can also prevent the storage of cookies by adjusting your browser software settings accordingly. However, if you configure your browser to reject all cookies, this may result in restrictions on the functionality of this website. In addition, you can prevent Google from collecting the data generated by the cookie and relating to your use of the website (including your IP address) and from processing this data by downloading and installing the browser plug-in available at the following link: : http://tools.google.com/dlpage/gaoptout
We have concluded a contract with Google for order processing in accordance with Art. 28 GDPR. Google Ireland Limited is a subsidiary of Google LLC, based in the USA (1600 Amphitheatre Parkway, Mountain View, CA). It cannot be ruled out that Google may also store personal data on servers in the USA. The USA does not have a level of data protection that is fully compliant with EU law. However, Google LLC is certified under the EU-U.S. Data Privacy Framework. Data transfers to the USA are therefore based on the adequacy decision of the EU Commission, which ensures an adequate level of data protection. For certain data transfers, Google may also use the EU’s Standard Contractual Clauses (SCCs) to ensure compliance with the GDPR.
Further information on Google Analytics can be found at:
https://policies.google.com/privacy
https://support.google.com/analytics/answer/12017362
Google Tag Manager
We use Google Tag Manager. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Tag Manager is used to manage website tags via an interface. This allows us to integrate other tracking or analysis tools on our website. Google Tag Manager itself (which implements the tags) does not set any cookies and does not process any personal data of users. It merely triggers other tags, which in turn may collect personal data. However, Google Tag Manager does not have access to this data. If you refuse to use Google Tag Manager via the “Cookie Consent Tool” (category: “Statistics”) provided on the website, the corresponding tags, e.g. from Google Analytics, will not be triggered via Google Tag Manager. Your data will then not be collected by these services.
The legal basis for the use of Google Tag Manager is Art. 6 (1) lit. a GDPR and §25 TTDSG.
Processing is carried out within the framework of the data processing agreement concluded with Google and under the data protection measures described in the section on Google Analytics. Further information can be found in Google’s privacy policy:
https://policies.google.com/privacy.
Google Ads and Conversion Tracking
Our website uses Google Ads, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
As part of Google Ads, we use conversion tracking for the statistical recording of marketing campaigns. If you access our website via an ad placed on Google, Google will set a cookie for conversion tracking on your device. The cookie is not used to personally identify users.
If the user visits certain pages of this website and the cookie has not yet expired, Google and we can recognize that the user clicked on the ad and was redirected to this page. The information obtained using the conversion cookie is used to generate conversion statistics for Google Ads customers who use conversion tracking. Customers learn the total number of users who clicked on their ad and were redirected to a page tagged with a conversion tracking tag. However, they do not receive any information that can be used to personally identify users.
The legal basis for the use of Google Ads is your consent in accordance with Art. 6 (1) (a) GDPR and § 25 (1) TTDSG.
The cookies used for conversion tracking by Google Ads expire after 540 days at the latest.
You can revoke your consent at any time with future effect by deactivating this service via the “Cookie Consent Tool” (category: “Marketing”) provided on the website. You can also prevent the storage of cookies by adjusting your browser software settings accordingly. In addition, you can deactivate the collection of your data by Google via the Google advertising settings (https://www.google.com/settings/ads).
Processing is carried out within the framework of the data processing agreement concluded with Google and under the data protection measures described in the section on Google Analytics. For more information about Google Ads and conversion tracking, please refer to Google’s privacy policy at https://policies.google.com/privacy
Contact form
If you use the contact form integrated on our website or contact us in any other way, e.g. to request information about our services, the mandatory information requested in the contact form and any other information you provide voluntarily (e.g. communication content) will be stored by our IT service provider and transmitted to us.
We process this data for the purpose of handling the request, including providing information about our services and answering follow-up questions, as well as to prevent misuse of the contact form. We base this data processing on our legitimate interests (Art. 6 (1) (f) GDPR) in processing your request and ensuring the security of our information technology systems. In the event of booking our services, we base this on the preparation and execution of the contract with you (Art. 6 (1) (b) GDPR).
7. Social media presence
We maintain a company page on the LinkedIn platform, which is operated by LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland. In addition, LinkedIn Corporation, located at 1000 W. Maude Avenue, Sunnyvale, CA 94085, USA, may also be involved in the processing of personal data. Our website contains an external link to our LinkedIn company page. No personal data is transferred to LinkedIn when you visit our website. Data processing by LinkedIn only takes place when you actively click on the link and thus access the LinkedIn platform.
Data processing by LinkedIn
When you visit our LinkedIn company page, LinkedIn may process users’ personal data, such as:
- Profile data (if you are logged in)
- Usage, interaction, and device data
- Tracking data collected using cookies and similar technologies
- Anonymized statistical data (“Page Insights”) provided to us by LinkedIn
We only receive anonymized statistics and have no influence on the primary data processing by LinkedIn. LinkedIn is solely responsible for this.
Joint responsibility
With regard to the processing of Page Insights, there is joint responsibility between us and LinkedIn in accordance with Art. 26 GDPR. The relevant agreement can be accessed here: https://legal.linkedin.com/pages-joint-controller-addendum.
Data subject rights
You can assert your data subject rights both against us and against LinkedIn. If you assert your data subject rights against us, we will forward your request to LinkedIn. In practical terms, LinkedIn can fulfill these rights most effectively, as only LinkedIn has access to the complete user data.
Data processing outside the EU
LinkedIn may process personal data outside the EU. In particular, data may be transferred to the USA. According to LinkedIn, this is done on the basis of EU standard contractual clauses or within the framework of the EU-U.S. Data Privacy Framework. Further information is provided by LinkedIn here: https://www.linkedin.com/legal/privacy-policy; https://de.linkedin.com/legal/privacy/eu?.
Legal basis
Our processing of personal data in connection with the LinkedIn page is based on our legitimate interests pursuant to Art. 6 (1) lit. f GDPR in effective communication, information, and interaction with you as a user, as well as an optimized presentation of our company and our range of services.
When using the LinkedIn platform, data processing is also based on your agreement with LinkedIn in accordance with their terms of use or your consent in accordance with Art. 6 (1) (a) GDPR, which you gave to LinkedIn when you registered. To avoid tracking, you can visit our LinkedIn page while logged out, contact us via an alternative communication channel, and/or adjust your LinkedIn advertising and cookie settings (https://www.linkedin.com/psettings/guest-controls).
Further information:
- Privacy policy:
https://www.linkedin.com/legal/privacy-policy - Cookie policy:
https://www.linkedin.com/legal/cookie-policy - Opt-out settings:
https://www.linkedin.com/psettings/guest-controls
Note
We do not collect any personal data from visitors to our LinkedIn page unless you actively contact us via LinkedIn (e.g., via messages or comments). In this case, the scope of the data collected depends on the information you provide.
8. How do we protect your data?
- FGK treats your personal data confidentially and applies at least the same level of care to the protection of your personal data as FGK applies to its own confidential information of a similar nature.
- Your personal data is stored behind secure networks and is only accessible to a limited number of people who have special access rights to these systems and are obliged to treat the information confidentially.
9. Your rights
Under the GDPR, you have the following rights:
- Right of access (Art. 15 GDPR). You have the right to request confirmation as to whether or not personal data concerning you is being processed and, if so, you have the right to access this personal data, as well as information about the processing and a copy of the processed data.
- Rectification (Art. 16 GDPR). You have the right to request the rectification of inaccurate personal data concerning you. Furthermore, you are entitled to request the completion of incomplete personal data, including by means of a supplementary statement.
- Erasure (Art. 17 GDPR). You have the right to request the erasure of your personal data in the cases provided for in the applicable data protection law (“right to be forgotten”).
- Restriction of processing (Art. 18 GDPR). You have the right to restrict the processing of data under certain, precisely defined circumstances.
- Data portability (Art. 20 GDPR). You have the right to receive the personal data concerning you and provided to us in a structured, commonly used, and machine-readable format and, where technically feasible, to request the transfer of this data to another controller.
- Withdrawal of consent. If you have expressly consented to the processing of your data, you can withdraw this consent at any time without giving reasons for the future.
If you wish to exercise your rights, please contact our data protection officer at: dataprotection@fgk-cro.com
You also have the right to lodge a complaint with your local data protection authority or with the data protection authority of the country where the alleged infringement took place.
10. Changes to our privacy policy
We reserve the right to amend this privacy policy as necessary to ensure that it always complies with current legal requirements or to implement changes to our services in the privacy policy, e.g. when introducing new services. The current version will then come into effect the next time you visit our website.
11. Note on cookies
Cookies are used on our website. Cookies are small text files that are stored on the device you use to access this website. Some are essential, while others help us to improve this website and its content.
Cookies are generally used for the basic functioning of the website and to ensure security when visiting a website (“Essential/Absolutely Necessary”), to improve the user experience or performance on the website (“Statistics”/Performance-related), or to track the use of target group-based advertising (“Marketing”).
Duration of cookie storage: see “Third-party services” or our cookie consent tool.
Right to object: You can object to the use of cookies and tracking technologies at any time via our consent tool or adjust your consent. Furthermore, you can use your browser settings to decide for yourself whether you want to allow cookies or object to the use of cookies. Please note that deactivating cookies may result in limited or complete deactivation of the functionality of this application website, as the use of cookies is essential for the provision of some services (e.g., application website).
12. Contact
Name and address of the controller:
FGK Clinical Research GmbH
Heimeranstrasse 35
80339 München, Deutschland
+ 49 (0) 89 893 119-0
Contact details of the data protection officer:
E-Mail: dataprotection@fgk-cro.com