Processing of (personal) data by the entity in charge of the online application process
Privacy notice for applicants pursuant to Art. 13 GDPR
Protecting your personal data is our highest priority. Below we inform you about the processing of your data in the application procedure. Processing is carried out in accordance with the General Data Protection Regulation (GDPR).
Roles at a glance (for easier orientation):
- Part A – Application process / application documents: Controller is Greenbone AG.
- Part B – Online application portal (technical provision): The application portal is technically provided by the recruiting platform Personio SE & Co. KG. In doing so, Personio may carry out certain technical processing operations (e.g., log data/cookies) in its own responsibility; however, the processing of your application content is carried out on behalf of Greenbone AG.
Part A – Application process (Greenbone AG)
1. Name and address of the controller
Greenbone AG
Neumarkt 12
49074 Osnabrück
Represented by the Management Board: Elmar Geese
Phone: +49 541 760278-0
Email: info@greenbone.net
2. Contact details of the Data Protection Officer
C&S Consulting
Data Protection Officer Matthias Wöstemeyer
Mittelheide 11
49124 Georgsmarienhütte
Website: https://datenschutz-gmh.de/
E-Mail: datenschutz@greenbone.net
3. Purposes and legal basis of data processing
Your personal data are processed for the purpose of conducting the application procedure. The legal basis for this is Art. 6(1) lit. b GDPR (pre-contractual measures). In individual cases, processing may also be based on our legitimate interest (Art. 6(1) lit. f GDPR), e.g. to defend against legal claims.
Where, in individual cases, special categories of personal data (e.g., health data) are processed, this takes place only insofar as this is permissible under Art. 9 GDPR and the processing is necessary for the purposes of the employment relationship.
4. Data sources
As a rule, we process only the personal data that you provide to us directly as part of your application. In individual cases, we may also receive data from other sources, for example from recruitment agencies or from publicly accessible profiles on professional networks, insofar as this is related to your application and/or the filling of the position.
5. Storage period of application data
We store your personal data for the duration of the application procedure.
If you are hired, the application documents required for carrying out the employment relationship will be added to your personnel file. The retention period is based on statutory retention obligations and the necessity for the employment relationship; individual documents may be subject to different retention periods.
If you are not hired, we store your application documents for up to six months from receipt of the rejection or from completion of the application procedure in order to be able to defend against possible legal claims (Art. 6(1) lit. f GDPR). Your data will then be deleted or anonymised, provided no statutory retention obligations prevent this.
Longer storage (e.g., inclusion in an applicant pool for future positions) takes place only on the basis of your voluntary consent (Art. 6(1) lit. a GDPR). You can revoke your consent at any time with effect for the future; processing carried out up to the time of revocation remains lawful.
6. Recipients or categories of recipients of the data
Your personal data are processed within our company by the responsible specialist departments.
In addition, we use external service providers for certain processing activities (e.g., IT support, email service providers, applicant management systems) as processors within the meaning of Art. 28 GDPR. They process your data exclusively on our instructions and in compliance with data protection requirements.
Any further disclosure to third parties or transfer to third countries as part of the application procedure (Part A) does not currently take place.
7. Your rights as a data subject
You have the right to:
- Obtain information about the processing of your personal data (Art. 15 GDPR).
- Request rectification of incorrect or incomplete data (Art. 16 GDPR).
- Request deletion of your personal data, provided no statutory retention obligations prevent this (Art. 17 GDPR).
- Request restriction of the processing of your data (Art. 18 GDPR).
- Receive the data concerning you in a structured, commonly used format or have it transferred to another controller (Art. 20 GDPR).
- Object to the processing of your data insofar as processing is based on legitimate interests (Art. 21 GDPR).
- Withdraw consent you have given at any time with effect for the future (Art. 7(3) GDPR).
- Lodge a complaint with a data protection supervisory authority if you believe that the processing of your data is not lawful (Art. 77 GDPR).
8. Transfer of data to third countries
As part of the application procedure (Part A), no transfer of data to third countries takes place.
9. Voluntary nature and obligation to provide personal data
Within the application procedure, certain personal data are required in order to review your application and carry out the selection process. Without these data, your application cannot be considered. Voluntary information may be provided—where offered—optionally.
10. Automated decision-making
There is no automated decision-making or profiling within the meaning of Art. 22 GDPR.
Part B – Online application portal (technical provision)
11. Purpose and distinction
For the use of the online application portal, the recruiting platform from Personio is used.
- Application content (form entries, uploads, communication in the application process): Processing on behalf of Greenbone AG (processing under Art. 28 GDPR).
- Technical portal operation (provision, security, error analysis, if applicable cookie functions): For this purpose, additional data are processed when using the portal; these technical processing operations may—depending on the type of processing—be carried out in its own responsibility by Personio.
12. Contact for portal-related matters
For data protection matters that exclusively concern the technical operation of the application portal (e.g., log data/cookies), you can also contact Personio additionally:
Personio SE & Co. KG, Seidlstraße 3, 80335 Munich
Data protection contact / Data Protection Officer: privacy@personio.com
13. Which technical data are typically processed?
When accessing and using the application portal, the following in particular may be processed:
- IP address (or network/connection data), timestamp
- Browser/device information (e.g., browser type/version, operating system)
- Access and error logs (server/error logs)
- Cookies or similar technologies (e.g., language settings, session functions; depending on portal configuration, possibly also performance functions)
14. Legal bases (portal operation)
Insofar as technical portal operation processes personal data, this is regularly done to ensure operation and security on the basis of legitimate interests (Art. 6(1) lit. f GDPR).
Insofar as information is stored or read on your end device in the portal (e.g., cookies), permissibility is governed by § 25 TDDDG (consent, unless technically strictly necessary).
15. Storage period (portal operation)
Technical log data are generally stored only for as long as this is necessary for security purposes and error analysis; cookies are stored depending on their type until the end of the session or for a limited period.
16. Exercising your rights
For the processing operations described in Part A (application procedure), please contact Greenbone AG or the Data Protection Officer (contact details above).
For matters that exclusively concern the technical portal operation, you can also contact Personio directly (privacy@personio.com).
If you have any questions about this privacy notice, please contact us using the contact details provided.
Version: 17/02/2026