Data Policy

Preamble

With the following privacy policy, we would like to inform you about the types of your personal data (hereinafter also referred to as “data”) that we process, the purposes for which we process them, and the extent of such processing. This privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and, in particular, on our websites, in mobile applications, and within external online presences such as our social media profiles (hereinafter collectively referred to as “online offering”).

The terms used are not gender-specific.

Last updated: September 7, 2026

Table of Contents

  • Preamble
  • Controller
  • Overview of Processing
  • Legal Bases
  • Security Measures
  • Transfer of Personal Data
  • International Data Transfers
  • Data Retention and Deletion
  • Rights of Data Subjects
  • Data Protection Officer
  • Provision of Online Services and Web Hosting
  • Use of Cookies
  • Contact and Inquiry Management
  • Application Process
  • Marketing Communication
  • Social Media Presence
  • Changes and Updates

Controller

Dr. Guido Schroer / Dr. Tobias Riedl / Mr. Yannik Kohlhaas / Dr. Harald Rubner
Power2Polymers GmbH
Dennewartstrasse 25
52068 Aachen, Germany
Handelsregisternummer: HRB 28251, Amtsgericht Aachen
Umsatzsteuer-Identifikationsnummer (VAT ID): DE450454157

Email: founder@power2polymers.com

Imprint: https://www.power2polymers.com/

Overview of Processing

Types of Data Processed

  • Master data
  • Contact data
  • Application data
  • Content data
  • Usage data
  • Metadata, communication, and procedural data
  • Log data

Categories of Data Subjects

  • Communication partners
  • Users
  • Applicants

Purposes of Processing

  • Communication
  • Security measures
  • Direct marketing
  • Organizational and administrative processes
  • Feedback
  • Marketing
  • Provision and improvement of our online services
  • IT infrastructure
  • Public relations
  • Sales promotion

Legal Bases

Relevant Legal Bases under GDPR

  • Consent (Art. 6(1)(a) GDPR)
  • Contract performance and pre-contractual inquiries (Art. 6(1)(b) GDPR)
  • Legitimate interests (Art. 6(1)(f) GDPR)

National Regulations (Germany)

In addition to the GDPR, German data protection laws apply, particularly the Federal Data Protection Act (BDSG).

Note on Swiss Data Protection Law

Power2Polymers GmbH also processes personal data of customers based in Switzerland. This policy therefore also serves to provide the information required under the Swiss Federal Act on Data Protection (FADP/DSG). For consistency, the GDPR terminology used throughout this policy is applied to fulfil the equivalent Swiss DSG requirements as well.

Security Measures

We implement appropriate technical and organizational measures to ensure a level of protection appropriate to the risk, considering:

  • State of the art
  • Implementation costs
  • Nature, scope, and purpose of processing
  • Risks to individuals

Measures include safeguarding:

  • Confidentiality
  • Integrity
  • Availability of data

Transfer of Personal Data

Personal data may be shared with third parties such as:

  • IT service providers
  • Embedded service providers

We ensure appropriate safeguards through contracts and agreements.

International Data Transfers

Data transfers outside the EU/EEA occur only:

  • Based on adequacy decisions (Art. 45 GDPR), or
  • With safeguards such as standard contractual clauses (Art. 46 GDPR), or
  • With explicit consent

More information:
https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en

Data Retention and Deletion

Personal data is deleted when:

  • Consent is withdrawn, or
  • Legal basis no longer applies

Retention Periods (Germany)

  • 10 years: accounting records, financial statements
  • 6 years: business correspondence
  • 3 years: legal claims

Rights of Data Subjects

You have the following rights:

  • Right to object
  • Right to withdraw consent
  • Right of access
  • Right to rectification
  • Right to erasure and restriction
  • Right to data portability
  • Right to lodge a complaint with a supervisory authority

Data Protection Officer

We have not appointed a Data Protection Officer. If you have questions about our processing of personal data or wish to exercise your rights, please contact us directly using the details provided under “Controller” above.

Provision of Online Services and Web Hosting

We process user data to provide online services, including:

  • IP address
  • Usage data
  • Log files

Legal Basis

Legitimate interests (Art. 6(1)(f) GDPR)

Hosting Provider

IONOS SE, Germany

Use of Cookies

Cookies store and retrieve information on user devices.

Types

  • Session cookies
  • Persistent cookies (up to 2 years)

Legal Basis

  • Consent (Art. 6(1)(a) GDPR)
  • Legitimate interests (Art. 6(1)(f) GDPR)
  • Consent under Section 25 TTDSG (German Telecommunications-Telemedia Data Protection Act) for the storage of, and access to, information on end devices

Users can withdraw consent at any time.

Contact and Inquiry Management

When contacting us, we process:

  • Name
  • Contact details
  • Message content

Purpose

  • Communication
  • Handling inquiries

Legal Basis

  • Contract performance
  • Legitimate interests

Application Process

When you apply for a position with us, we process the data you provide to us in the course of the application and selection procedure.

Types of Data Processed

  • Master data (e.g. name, date of birth)
  • Contact data (e.g. email address, telephone number, postal address)
  • Application data (CV, cover letter, certificates and references, qualifications, availability, salary expectations)
  • Communication and procedural data (correspondence, interview notes, assessment results)

Categories of Data Subjects

  • Applicants

Purposes of Processing

  • Conducting the application and selection procedure
  • Decision on the establishment of an employment relationship
  • Organizational and administrative processes
  • Establishment, exercise, and defence of legal claims

Legal Bases

  • Decision on the establishment of an employment relationship (Sec. 26(1) BDSG in conjunction with Art. 6(1)(b) GDPR)
  • Consent (Art. 6(1)(a) GDPR), where you agree to the storage of your application beyond the end of the procedure
  • Legitimate interests (Art. 6(1)(f) GDPR), in particular the defence of claims under the German General Equal Treatment Act (AGG)
  • Special categories of personal data (e.g. information on severe disability) are processed only on the basis of Art. 9(2)(b) GDPR in conjunction with Sec. 26(3) BDSG

Submission of Applications

Applications are usually submitted by email. Please note that unencrypted email is not a secure means of transmission. If you prefer, you may send your application by post to the address given under “Controller”.

We do not require a photograph, your marital status, or information about religious affiliation. Please only provide data that is relevant to the position you are applying for.

Recipients

  • Members of management and the persons responsible for the respective position within our company
  • IT service providers acting as processors under Art. 28 GDPR, in particular our email and document management provider (Microsoft Ireland Operations Ltd., Microsoft 365)

Data Retention and Deletion

  • Application data is deleted no later than six months after the conclusion of the application procedure, unless a longer retention period is required for the establishment, exercise, or defence of legal claims.
  • If you consent to being included in our talent pool, we store your data for up to 24 months after the end of the procedure. You may withdraw this consent at any time with effect for the future.
  • If we enter into an employment relationship with you, the data is transferred to your personnel file.

Automated Decision-Making

We do not use automated decision-making, including profiling, within the meaning of Art. 22 GDPR, in our application procedure.

Provision of Data

The provision of your data is neither required by law nor by contract. However, without the data indicated as necessary, we are unable to assess your application or to enter into an employment relationship with you.

Your Rights

The rights set out under “Rights of Data Subjects” apply to applicants without restriction. The supervisory authority responsible for us is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Kavalleriestr. 2–4, 40213 Düsseldorf.

Marketing Communication

We process personal data for marketing via:

  • Email
  • Phone
  • Mail

Users can withdraw consent at any time.

Data may be retained up to 3 years for legal purposes.

Social Media Presence

We maintain profiles on social networks to:

  • Communicate with users
  • Share information

Data may be processed outside the EU.

Example: LinkedIn

Data is processed jointly with LinkedIn Ireland for analytics (“Page Insights”). A summary of this joint controllership arrangement, including the allocation of responsibilities under Art. 26 GDPR, is published by LinkedIn and available at linkedin.com/legal/l/pages-joint-controller-addendum.

Changes and Updates

We regularly update this privacy policy.
Users are advised to review it periodically.