Privacy Policy

1. Overview and mandatory information

Data protection at a glance

The following notes give a simple overview of what happens to your personal data when you visit this website. Personal data is any data with which you can be personally identified. Detailed information can be found in the sections below.

Controller

The controller responsible for data processing on this website is:

SAFETEE GmbH, Wasserstraße 221, 44799 Bochum, Germany, phone +49 234 58885-0, e-mail info@safetee.eu, represented by its managing director Marc Riegel. Registered at the Local Court of Bochum, HRB 18360.

The controller is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data.

Data protection officer

We have appointed an external data protection officer: Andreas Reinke, arbeitgeber ruhr GmbH, phone +49 234 58877-27, e-mail reinke@datenschutzbeauftragter.ruhr.

How do we collect your data?

Some data is collected when you provide it to us – for example via a form on this website, by e-mail, as part of a job application or when registering for a training course. Other data is collected automatically, or after your consent, by our IT systems when you visit the website. This is mainly technical data such as your browser, operating system or the time of the page request.

What do we use your data for?

Part of the data is collected to ensure the website is provided without errors. Other data may be used – only with your consent – to analyse user behaviour or for advertising purposes. Data from enquiries and applications is used exclusively to process your request.

Legal bases at a glance

Where you have given consent, we process your data on the basis of Art. 6(1)(a) GDPR; where cookies are stored or information is accessed on your device, additionally on the basis of Section 25(1) of the German Telecommunications Digital Services Data Protection Act (TDDDG). Where your data is required to perform a contract or to take steps prior to entering into a contract, Art. 6(1)(b) GDPR applies. Processing to comply with a legal obligation is based on Art. 6(1)(c) GDPR. In all other cases processing may be based on our legitimate interest under Art. 6(1)(f) GDPR. The applicable legal basis is stated for each service below.

Data transfers to third countries

Some of the services we use are operated by providers based outside the EU/EEA, in particular in the USA and Singapore. For transfers to the USA we rely on the European Commission's adequacy decision on the EU-US Data Privacy Framework (DPF) where the respective provider is certified, and additionally on the European Commission's Standard Contractual Clauses. For transfers to other third countries we rely on the Standard Contractual Clauses (Art. 46(2)(c) GDPR). Where a third-country transfer takes place for a specific service, we state this in the respective section. The Standard Contractual Clauses are available at https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj; you can obtain a copy of the safeguards agreed with a provider on request using the contact details above.

Retention period

Unless a more specific retention period is stated in this policy, your personal data remains with us until the purpose of processing no longer applies. If you make a legitimate request for erasure or withdraw your consent, your data will be deleted unless there are other legally permissible reasons for retaining it (e.g. retention periods under tax or commercial law).

Recipients of personal data

We only pass personal data on to external parties where this is necessary to perform a contract, where we are legally obliged to do so, where we have a legitimate interest in the transfer, or where another legal basis permits it. Processors receive data exclusively on the basis of a contract under Art. 28 GDPR.

Provision of your data and automated decisions

You are not obliged by law or contract to provide us with personal data. However, without the information marked as required in a form we cannot process your enquiry, registration or application, and without the technically necessary connection data this website cannot be displayed. We do not make decisions based solely on automated processing within the meaning of Art. 22 GDPR.

2. Hosting

Webflow

The content of our website is hosted by Webflow, Inc., 398 11th Street, 2nd Floor, San Francisco, CA 94103, USA. When you visit our website, Webflow records log files including your IP address and sets cookies or similar technologies that are required to display the site, to provide certain functions and to ensure security (strictly necessary cookies). Images, videos, scripts and stylesheets of our website are delivered via Webflow's content delivery network (cdn.prod.website-files.com, Fastly and Amazon CloudFront); your IP address is transmitted to the respective delivery server in the process.

The legal basis is our legitimate interest in a reliable and secure presentation of our website (Art. 6(1)(f) GDPR). Strictly necessary cookies do not require consent under Section 25(2) no. 2 TDDDG.

The company is certified under the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards for data processing in the USA. In addition, the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR) have been agreed, so that the transfer remains safeguarded even if the DPF adequacy decision should cease to apply. Further information: DPF register entry. Webflow's privacy policy: https://webflow.com/legal/eu-privacy-policy.

We have concluded a data processing agreement (DPA) with the provider under Art. 28 GDPR. This ensures that the provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.

Embedded applications on Vercel

On individual pages we embed our own web applications that run on the Vercel platform: the registration form for SAFETEE Academy training courses (registration page for the contractor coordinator course under DGUV Regulation 1) and the application form for freelancers (page "HSE Freelancers"). The platform provider is Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, USA.

When you open these pages, the respective application is loaded in an embedded frame (iframe). Your browser connects to Vercel's servers; your IP address and technical access data (time, requested resource, browser) are processed. The applications do not set cookies. What you enter in the forms is forwarded by the applications via Vercel servers in the USA to our systems at Microsoft (Microsoft Azure and Microsoft 365 with data centres in the EU; the provider is Microsoft Ireland Operations Limited, see section 7): for training registrations, company, contact person and participant data; for freelancer applications, your contact details, information on qualifications, language skills, work permit, availability and terms, and your CV. Details on purpose, scope and retention period can be found in the privacy notices linked in the respective application.

The legal basis for loading the applications is our legitimate interest in reliably providing the forms you have requested (Art. 6(1)(f) GDPR). We process your input for training registrations to perform the contract or take steps prior to entering into it (Art. 6(1)(b) GDPR), and for freelancer applications on the basis of the consent you give in the portal (Art. 6(1)(a) GDPR).

Vercel also processes data in the USA. The company is certified under the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards for data processing in the USA. In addition, the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR) have been agreed, so that the transfer remains safeguarded even if the DPF adequacy decision should cease to apply. Further information: https://www.dataprivacyframework.gov/list (entry "Vercel Inc."). Vercel's privacy policy: https://vercel.com/legal/privacy-policy.

We have concluded a data processing agreement (DPA) with the provider under Art. 28 GDPR. This ensures that the provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.

3. General data collection

Server log files

The hosting provider automatically collects and stores information in server log files that your browser transmits: browser type and version, operating system used, referrer URL, host name of the accessing computer, time of the server request and IP address. This data is not combined with other data sources. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in the technically error-free presentation and the security of the website. The log data is deleted as soon as it is no longer required for these purposes.

SSL/TLS encryption

This website uses SSL/TLS encryption for the secure transmission of confidential content. You can recognise an encrypted connection by the "https://" in the address bar and the lock symbol in your browser.

Contact form

If you send us enquiries via the contact form, the details you enter, including the contact data you provide, are stored by us for the purpose of processing the enquiry and for follow-up questions. We do not pass this data on without your consent. The form data is transmitted via our hosting provider Webflow and stored in our account there (see section 2). For spam protection, see section 5.

The legal basis is Art. 6(1)(b) GDPR where your enquiry relates to the performance of a contract or is necessary to take steps prior to entering into a contract; in all other cases our legitimate interest in the effective handling of enquiries (Art. 6(1)(f) GDPR). The data remains with us until you ask us to delete it or the purpose of storage no longer applies; statutory retention periods remain unaffected.

Self-check market entry Germany

On the page "Market entry Germany" we offer a self-check. Your answers are evaluated exclusively in your browser. As long as you do not request a report, neither your answers nor the result are transmitted to us or to third parties. For the PDF report, your browser loads a program library, fonts and our logo from our hosting provider Webflow (see section 2). The report is generated in your browser and is not stored on our servers.

If you request the report, we transmit your name, your company, your e-mail address, optionally your country, as well as your answers and the result via a form to our hosting provider Webflow. There the details are stored in our account and we are notified by e-mail. We use the details to process your request and to contact you for an initial consultation. The legal basis is the consent you give in the form (Art. 6(1)(a) GDPR); you may withdraw it at any time with effect for the future. Where the contact serves to prepare a contract, Art. 6(1)(b) GDPR also applies. We store the details until you withdraw your consent or the purpose no longer applies, at the latest two years after the last contact if no contract results; statutory retention periods remain unaffected. The result of the self-check is a self-assessment; it does not involve an automated decision within the meaning of Art. 22 GDPR.

Enquiries by e-mail or telephone

If you contact us by e-mail or telephone, your enquiry including all personal data resulting from it is stored by us for the purpose of processing your request. The legal basis and retention period correspond to those stated for the contact form. Our e-mail communication runs via Microsoft 365 (see section 7).

4. Cookies and consent management

Cookies

Our website uses cookies. Cookies are small data packets stored on your device – either temporarily for the duration of a session (session cookies) or permanently (persistent cookies). Cookies may originate from us (first-party) or from third-party companies (third-party).

Strictly necessary cookies that are required to provide the website are stored on the basis of Art. 6(1)(f) GDPR and Section 25(2) no. 2 TDDDG. We use all other cookies and comparable technologies – in particular for analysis or advertising purposes – exclusively with your consent under Art. 6(1)(a) GDPR and Section 25(1) TDDDG. You can withdraw your consent at any time with effect for the future by reopening the settings via the consent icon at the bottom left of the pages of this website (labelled in German: "Cookie-Zustimmung ändern").

You can set your browser to inform you about the setting of cookies, to allow cookies only in individual cases, or to exclude them altogether. If cookies are deactivated, the functionality of this website may be restricted.

Consent management with CCM19

This website uses the consent tool CCM19 to obtain, manage and document in a data-protection-compliant manner your consent to the storage of certain information on your device or the use of certain technologies. The provider is Papoo Software & Media GmbH, Auguststraße 4, 53229 Bonn, Germany. We obtain CCM19 through eRecht24 GmbH & Co. KG, Lietzenburger Straße 93–95, 10719 Berlin, Germany.

When you open our website, your browser loads the tool from the provider's servers in Germany; your IP address, information about your browser and device and the time of access are processed. CCM19 logs your decision (consent, refusal or withdrawal) with a random identifier, a timestamp and an anonymised IP address. So that your decision can be recognised on later visits, it is stored in your browser's local storage under the key "ccm_consent". The data is stored until you ask us to delete it, delete the entry in your browser, or the purpose of storage no longer applies; statutory retention obligations remain unaffected.

CCM19 is used to obtain and document the legally required consents. The legal basis is Art. 6(1)(c) GDPR in conjunction with Art. 7(1) GDPR. Storing your decision in your browser is permitted without consent under Section 25(2) no. 2 TDDDG.

We have concluded a data processing agreement (DPA) under Art. 28 GDPR for the use of CCM19. This ensures that the personal data of our website visitors is processed only in accordance with our instructions and in compliance with the GDPR.

5. Web analytics and form protection

We do not use advertising trackers or session-recording tools on this website. For audience measurement we use exclusively a cookieless analytics service (Ahrefs Web Analytics), and only with your consent. We protect our forms against spam with Cloudflare Turnstile.

Ahrefs Web Analytics

We use Ahrefs Web Analytics, a web analytics service of Ahrefs Pte. Ltd., 16 Raffles Quay, #33-03 Hong Leong Building, Singapore 048581. According to Ahrefs, Ahrefs Web Analytics does not set cookies.

When a page is opened, the following data is transmitted to Ahrefs and evaluated in aggregated form: the page opened (URL), the referring page (referrer), browser type and version, operating system, device type and your IP address. Your IP address is not stored: Ahrefs creates a hash value from it, your browser details and a key that changes daily; the key is deleted after 24 hours, so visits cannot be linked across several days. The data is not combined with other data and you are not identified personally.

The purpose of the processing is to analyse the use of our website in order to improve content and reach. Measurement only takes place once you have consented to the "Statistik" (statistics) category in our consent tool. The legal basis is your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG); you may withdraw it at any time with effect for the future.

Ahrefs Pte. Ltd. is based in Singapore, a third country without an adequacy decision of the European Commission; according to Ahrefs, personal data is stored in the USA. The transfer is based on the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR). Further information: https://ahrefs.com/privacy-policy.

We have concluded a data processing agreement (DPA) with the provider under Art. 28 GDPR. This ensures that the provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.

Form protection with Cloudflare Turnstile

To protect our forms (contact, applications and self-check report) against automated input and spam, we use the bot protection of our hosting provider Webflow. It is based on the Turnstile service of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. In addition, Webflow automatically checks the content of incoming form submissions for typical spam characteristics.

For this purpose, your browser loads a script from Cloudflare servers (challenges.cloudflare.com) when you visit our website. Turnstile evaluates technical characteristics in the background to distinguish humans from automated programs, including your IP address, information about your browser and device (such as the user agent and characteristics of the encrypted connection) and signals about how the page is used, such as input and mouse movements. As a rule, you do not have to solve a puzzle. If the service detects an automated submission, it is not accepted. According to Cloudflare, this data is processed on behalf of the website operator to protect the website and is additionally used by Cloudflare under its own responsibility to improve bot detection.

The legal basis is our legitimate interest in protecting our forms against misuse and in the security of our website (Art. 6(1)(f) GDPR). Where information is stored on or read from your device in the process, this is strictly necessary for sending a form at your request (Section 25(2) no. 2 TDDDG). If you prefer not to use a form, you can also reach us by e-mail or telephone.

Cloudflare also processes data in the USA. Cloudflare, Inc. is certified under the "EU-US Data Privacy Framework" (DPF); in addition, Cloudflare relies on the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR). Turnstile privacy notice: https://www.cloudflare.com/turnstile-privacy-policy/. Cloudflare's privacy policy: https://www.cloudflare.com/privacypolicy/.

6. Fonts and videos

Fonts

For a uniform display we use typefaces, including some from the Google Fonts collection. On the pages of this website we deliver them ourselves via our hosting provider Webflow (see section 2); no connection to Google servers is established. The embedded applications on Vercel (training registration and freelancer application, see section 2) currently still load their fonts from Google servers (Google Fonts; the provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland); Google thereby learns your IP address. Google Fonts does not set cookies. The legal basis is our legitimate interest in a uniform presentation (Art. 6(1)(f) GDPR); for transfers to the USA, the information on Google in the following subsection applies.

YouTube videos

On individual pages, including "Films", "Career", "SAFETEE Academy", "Behaviour Based Safety" and our job pages, we show videos from our YouTube channel. The provider of YouTube is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

When you open these pages, you first only see a preview image or a button that we provide ourselves; no data is transmitted to YouTube. The video is only loaded once you have consented to YouTube in our consent tool and click on the preview image. For this we use YouTube's privacy-enhanced mode (address youtube-nocookie.com). When the video loads, your browser connects to YouTube's servers; YouTube learns your IP address, the page visited and browser and device information and may store or read information in your browser. If you are logged in to YouTube, YouTube can assign the request to your account. According to Google, playback in privacy-enhanced mode is not used to personalise YouTube or advertising.

The legal basis is your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG); you may withdraw it at any time with effect for the future. Google may also process data in the USA. The parent company Google LLC is certified under the "EU-US Data Privacy Framework" (DPF); in addition, the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR) apply. Further information: https://www.dataprivacyframework.gov/participant/5780. Google's privacy policy: https://policies.google.com/privacy.

7. Communication and conferencing tools

For communication with customers, prospects and applicants we use Microsoft 365 (e-mail, calendar, Teams). If you communicate with us via video or audio conference, your personal data is processed by us and by the provider of the respective tool: the data you provide (name, e-mail address, telephone number), metadata of the conference (duration, start and end, number of participants) and technical data (IP address, device IDs, operating system, client version). Content you share in a conference (chat, files, recordings) is also stored on the provider's servers.

The tools are used to communicate with contractual partners or to provide services (Art. 6(1)(b) GDPR) and to generally simplify communication (Art. 6(1)(f) GDPR). Data collected by us is deleted as soon as you ask us to delete it or the purpose no longer applies; we have no influence on the retention period at the provider.

Microsoft 365 and Microsoft Teams

The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. Privacy statement: https://privacy.microsoft.com/en-gb/privacystatement.

Microsoft Corporation (USA) is certified under the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards for data processing in the USA. In addition, the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR) have been agreed, so that the transfer remains safeguarded even if the DPF adequacy decision should cease to apply. Further information: DPF register entry.

We have concluded a data processing agreement (DPA) with the provider under Art. 28 GDPR. This ensures that the provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.

8. Application process

You can apply to us via the application form on our careers page, via our job advertisements on Personio, as a freelancer via our application portal, or by e-mail or post. Below we inform you about the scope, purpose and use of the personal data collected in the application process.

Scope and purpose of data collection

If you send us an application, we process the associated personal data (contact and communication data, application documents, notes from interviews) to the extent necessary to decide on the establishment of an employment relationship. The legal basis is Section 26 of the German Federal Data Protection Act (BDSG) (initiation of an employment relationship), Art. 6(1)(b) GDPR and – where you have given consent – Art. 6(1)(a) GDPR. Within our company, your data is passed on only to persons involved in processing your application. If your application is successful, the data is stored in our systems for the purpose of carrying out the employment relationship.

Application form on our website

If you apply via the form on our careers page, your details (name, contact details, desired position, message) and the documents you upload are transmitted via our hosting provider Webflow and stored in our account there (see section 2). The legal basis and retention period stated in this section apply.

Application portal for freelancers

As a freelancer you can apply via our application portal, which is embedded on the "HSE Freelancers" page (for its technical provision see section 2). We process your details and your CV to review your application and to contact you about suitable projects. For pre-selection we rate your details internally with a points score, for example based on qualifications, professional experience and availability. The score only serves as guidance; whether we contact you is always decided by a person on our team. We do not use artificial intelligence for this. The legal basis is the consent you give in the portal (Art. 6(1)(a) GDPR). In derogation from the "Retention period" subsection, the retention periods stated in the portal's privacy notice apply to the portal; you will also find further details there.

Applicant management with Personio

For applicant management we use the software Personio of Personio SE & Co. KG, Seidlstraße 3, 80335 Munich, Germany. Personio processes applicant data on our behalf; the servers are located in the European Union. Applications via our job advertisements on Personio are recorded directly in Personio, where scheduling, correspondence and application documents are also managed. Personio's privacy notice: https://www.personio.com/privacy-policy/.

We have concluded a data processing agreement (DPA) with the provider under Art. 28 GDPR. This ensures that the provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.

Retention period

If we do not make you a job offer, if you decline an offer or withdraw your application, we retain your data on the basis of our legitimate interest (Art. 6(1)(f) GDPR) for up to six months after the end of the application process, in particular for evidentiary purposes under the German General Equal Treatment Act (AGG). The data is then deleted and physical documents destroyed. If it is foreseeable that the data will be required beyond this (e.g. in the event of an impending legal dispute), deletion takes place only once the purpose no longer applies.

Inclusion in the applicant pool

If we do not make you a job offer, we may include you in our applicant pool in order to contact you about suitable vacancies. Inclusion is based exclusively on your express consent (Art. 6(1)(a) GDPR); it is voluntary and unrelated to the current process. You may withdraw your consent at any time; your data will then be irrevocably deleted. Data is deleted from the applicant pool no later than two years after consent was given.

9. Social networks and external links

Our website links to our company profiles on LinkedIn, Xing, Instagram, Facebook and YouTube. These are plain links; no data is transmitted to these networks when you visit our website. Only when you follow a link do the privacy policies of the respective provider apply. For our company profiles we are jointly responsible with the respective network operator; details are governed by the providers' agreements (e.g. LinkedIn Page Insights Joint Controller Addendum, Meta Page Insights Addendum).

We also link to external services, such as our job advertisements on Personio, the map service Google Maps for directions to our locations, the employer review platform kununu and our application SAFETEE LMRA. Here too, data is only transmitted when you follow a link; the privacy notices of the respective service then apply. Embedded YouTube videos are described in section 6.

10. Your rights

Access, rectification, erasure, restriction, data portability

Within the scope of the statutory provisions you have the right at any time to obtain free information about your stored personal data, its origin and recipients and the purpose of processing (Art. 15 GDPR), to rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR) and data portability (Art. 20 GDPR). To exercise these rights, contact the controller named above or our data protection officer.

Withdrawal of your consent

You may withdraw consent you have given at any time with effect for the future. The lawfulness of processing carried out until withdrawal remains unaffected. Cookie consents can be withdrawn via the consent icon at the bottom left of the pages of this website (labelled in German: "Cookie-Zustimmung ändern").

Right to object (Art. 21 GDPR)

Where data processing is based on Art. 6(1)(e) or (f) GDPR, you have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data; this also applies to profiling based on these provisions. We will then no longer process your data unless we can demonstrate compelling legitimate grounds that override your interests, or the processing serves the establishment, exercise or defence of legal claims. Where your data is processed for direct marketing purposes, you may object at any time; your data will then no longer be used for this purpose.

Right to lodge a complaint with a supervisory authority

In the event of infringements of the GDPR you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement. The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW), Kavalleriestraße 2–4, 40213 Düsseldorf, Germany, www.ldi.nrw.de.

Objection to advertising e-mails

We hereby object to the use of contact data published in accordance with our legal notice obligations for the purpose of sending unsolicited advertising. We reserve the right to take legal action in the event of unsolicited advertising, such as spam e-mails.


This privacy policy was last updated: 6 October 2026

We update this policy whenever the legal situation or our processing activities change. The version published on this website applies. This English version is provided for convenience; in case of discrepancies, the German version (www.safetee.eu/datenschutz) prevails.