Data Policy
Preamble
With the following privacy policy, we would like to inform you about the types of your personal data (hereinafter also referred to as “data”) that we process, the purposes for which we process them, and the extent of such processing. This privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and, in particular, on our websites, in mobile applications, and within external online presences such as our social media profiles (hereinafter collectively referred to as “online offering”).
The terms used are not gender-specific.
Last updated: September 7, 2026
Table of Contents
- Preamble
- Controller
- Overview of Processing
- Legal Bases
- Security Measures
- Transfer of Personal Data
- International Data Transfers
- Data Retention and Deletion
- Rights of Data Subjects
- Data Protection Officer
- Provision of Online Services and Web Hosting
- Use of Cookies
- Contact and Inquiry Management
- Application Process
- Marketing Communication
- Social Media Presence
- Changes and Updates
Controller
Dr. Guido Schroer / Dr. Tobias Riedl / Mr. Yannik Kohlhaas / Dr. Harald Rubner
Power2Polymers GmbH
Dennewartstrasse 25
52068 Aachen, Germany
Handelsregisternummer: HRB 28251, Amtsgericht Aachen
Umsatzsteuer-Identifikationsnummer (VAT ID): DE450454157
Email: founder@power2polymers.com
Imprint: https://www.power2polymers.com/
Overview of Processing
Types of Data Processed
- Master data
- Contact data
- Application data
- Content data
- Usage data
- Metadata, communication, and procedural data
- Log data
Categories of Data Subjects
- Communication partners
- Users
- Applicants
Purposes of Processing
- Communication
- Security measures
- Direct marketing
- Organizational and administrative processes
- Feedback
- Marketing
- Provision and improvement of our online services
- IT infrastructure
- Public relations
- Sales promotion
Legal Bases
Relevant Legal Bases under GDPR
- Consent (Art. 6(1)(a) GDPR)
- Contract performance and pre-contractual inquiries (Art. 6(1)(b) GDPR)
- Legitimate interests (Art. 6(1)(f) GDPR)
National Regulations (Germany)
In addition to the GDPR, German data protection laws apply, particularly the Federal Data Protection Act (BDSG).
Note on Swiss Data Protection Law
Power2Polymers GmbH also processes personal data of customers based in Switzerland. This policy therefore also serves to provide the information required under the Swiss Federal Act on Data Protection (FADP/DSG). For consistency, the GDPR terminology used throughout this policy is applied to fulfil the equivalent Swiss DSG requirements as well.
Security Measures
We implement appropriate technical and organizational measures to ensure a level of protection appropriate to the risk, considering:
- State of the art
- Implementation costs
- Nature, scope, and purpose of processing
- Risks to individuals
Measures include safeguarding:
- Confidentiality
- Integrity
- Availability of data
Transfer of Personal Data
Personal data may be shared with third parties such as:
- IT service providers
- Embedded service providers
We ensure appropriate safeguards through contracts and agreements.
International Data Transfers
Data transfers outside the EU/EEA occur only:
- Based on adequacy decisions (Art. 45 GDPR), or
- With safeguards such as standard contractual clauses (Art. 46 GDPR), or
- With explicit consent
More information:
https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en
Data Retention and Deletion
Personal data is deleted when:
- Consent is withdrawn, or
- Legal basis no longer applies
Retention Periods (Germany)
- 10 years: accounting records, financial statements
- 6 years: business correspondence
- 3 years: legal claims
Rights of Data Subjects
You have the following rights:
- Right to object
- Right to withdraw consent
- Right of access
- Right to rectification
- Right to erasure and restriction
- Right to data portability
- Right to lodge a complaint with a supervisory authority
Data Protection Officer
We have not appointed a Data Protection Officer. If you have questions about our processing of personal data or wish to exercise your rights, please contact us directly using the details provided under “Controller” above.
Provision of Online Services and Web Hosting
We process user data to provide online services, including:
- IP address
- Usage data
- Log files
Legal Basis
Legitimate interests (Art. 6(1)(f) GDPR)
Hosting Provider
IONOS SE, Germany
Use of Cookies
Cookies store and retrieve information on user devices.
Types
- Session cookies
- Persistent cookies (up to 2 years)
Legal Basis
- Consent (Art. 6(1)(a) GDPR)
- Legitimate interests (Art. 6(1)(f) GDPR)
- Consent under Section 25 TTDSG (German Telecommunications-Telemedia Data Protection Act) for the storage of, and access to, information on end devices
Users can withdraw consent at any time.
Contact and Inquiry Management
When contacting us, we process:
- Name
- Contact details
- Message content
Purpose
- Communication
- Handling inquiries
Legal Basis
- Contract performance
- Legitimate interests
Application Process
When you apply for a position with us, we process the data you provide to us in the course of the application and selection procedure.
Types of Data Processed
- Master data (e.g. name, date of birth)
- Contact data (e.g. email address, telephone number, postal address)
- Application data (CV, cover letter, certificates and references, qualifications, availability, salary expectations)
- Communication and procedural data (correspondence, interview notes, assessment results)
Categories of Data Subjects
- Applicants
Purposes of Processing
- Conducting the application and selection procedure
- Decision on the establishment of an employment relationship
- Organizational and administrative processes
- Establishment, exercise, and defence of legal claims
Legal Bases
- Decision on the establishment of an employment relationship (Sec. 26(1) BDSG in conjunction with Art. 6(1)(b) GDPR)
- Consent (Art. 6(1)(a) GDPR), where you agree to the storage of your application beyond the end of the procedure
- Legitimate interests (Art. 6(1)(f) GDPR), in particular the defence of claims under the German General Equal Treatment Act (AGG)
- Special categories of personal data (e.g. information on severe disability) are processed only on the basis of Art. 9(2)(b) GDPR in conjunction with Sec. 26(3) BDSG
Submission of Applications
Applications are usually submitted by email. Please note that unencrypted email is not a secure means of transmission. If you prefer, you may send your application by post to the address given under “Controller”.
We do not require a photograph, your marital status, or information about religious affiliation. Please only provide data that is relevant to the position you are applying for.
Recipients
- Members of management and the persons responsible for the respective position within our company
- IT service providers acting as processors under Art. 28 GDPR, in particular our email and document management provider (Microsoft Ireland Operations Ltd., Microsoft 365)
Data Retention and Deletion
- Application data is deleted no later than six months after the conclusion of the application procedure, unless a longer retention period is required for the establishment, exercise, or defence of legal claims.
- If you consent to being included in our talent pool, we store your data for up to 24 months after the end of the procedure. You may withdraw this consent at any time with effect for the future.
- If we enter into an employment relationship with you, the data is transferred to your personnel file.
Automated Decision-Making
We do not use automated decision-making, including profiling, within the meaning of Art. 22 GDPR, in our application procedure.
Provision of Data
The provision of your data is neither required by law nor by contract. However, without the data indicated as necessary, we are unable to assess your application or to enter into an employment relationship with you.
Your Rights
The rights set out under “Rights of Data Subjects” apply to applicants without restriction. The supervisory authority responsible for us is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Kavalleriestr. 2–4, 40213 Düsseldorf.
Marketing Communication
We process personal data for marketing via:
- Phone
Users can withdraw consent at any time.
Data may be retained up to 3 years for legal purposes.
Social Media Presence
We maintain profiles on social networks to:
- Communicate with users
- Share information
Data may be processed outside the EU.
Example: LinkedIn
Data is processed jointly with LinkedIn Ireland for analytics (“Page Insights”). A summary of this joint controllership arrangement, including the allocation of responsibilities under Art. 26 GDPR, is published by LinkedIn and available at linkedin.com/legal/l/pages-joint-controller-addendum.
Changes and Updates
We regularly update this privacy policy.
Users are advised to review it periodically.
