Skip to main content

Processing of (personal) data by the entity in charge of the online application process

Privacy notice for applicants pursuant to Art. 13 GDPR

Protecting your personal data is our highest priority. Below we inform you about the processing of your data in the application procedure. Processing is carried out in accordance with the General Data Protection Regulation (GDPR).

Roles at a glance (for easier orientation):

  • Part A – Application process / application documents: Controller is Greenbone AG.
  • Part B – Online application portal (technical provision): The application portal is technically provided by the recruiting platform Personio SE & Co. KG. In doing so, Personio may carry out certain technical processing operations (e.g., log data/cookies) in its own responsibility; however, the processing of your application content is carried out on behalf of Greenbone AG.


Part A – Application process (Greenbone AG)

1. Name and address of the controller

Greenbone AG
Neumarkt 12
49074 Osnabrück
Represented by the Management Board: Elmar Geese
Phone: +49 541 760278-0
Email: info@greenbone.net

2. Contact details of the Data Protection Officer

C&S Consulting
Data Protection Officer Matthias Wöstemeyer
Mittelheide 11
49124 Georgsmarienhütte
Website: https://datenschutz-gmh.de/
E-Mail: datenschutz@greenbone.net

3. Purposes and legal basis of data processing

Your personal data are processed for the purpose of conducting the application procedure. The legal basis for this is Art. 6(1) lit. b GDPR (pre-contractual measures). In individual cases, processing may also be based on our legitimate interest (Art. 6(1) lit. f GDPR), e.g. to defend against legal claims.
Where, in individual cases, special categories of personal data (e.g., health data) are processed, this takes place only insofar as this is permissible under Art. 9 GDPR and the processing is necessary for the purposes of the employment relationship.

4. Data sources

As a rule, we process only the personal data that you provide to us directly as part of your application. In individual cases, we may also receive data from other sources, for example from recruitment agencies or from publicly accessible profiles on professional networks, insofar as this is related to your application and/or the filling of the position.

5. Storage period of application data

We store your personal data for the duration of the application procedure.
If you are hired, the application documents required for carrying out the employment relationship will be added to your personnel file. The retention period is based on statutory retention obligations and the necessity for the employment relationship; individual documents may be subject to different retention periods.
If you are not hired, we store your application documents for up to six months from receipt of the rejection or from completion of the application procedure in order to be able to defend against possible legal claims (Art. 6(1) lit. f GDPR). Your data will then be deleted or anonymised, provided no statutory retention obligations prevent this.
Longer storage (e.g., inclusion in an applicant pool for future positions) takes place only on the basis of your voluntary consent (Art. 6(1) lit. a GDPR). You can revoke your consent at any time with effect for the future; processing carried out up to the time of revocation remains lawful.

6. Recipients or categories of recipients of the data

Your personal data are processed within our company by the responsible specialist departments.
In addition, we use external service providers for certain processing activities (e.g., IT support, email service providers, applicant management systems) as processors within the meaning of Art. 28 GDPR. They process your data exclusively on our instructions and in compliance with data protection requirements.
Any further disclosure to third parties or transfer to third countries as part of the application procedure (Part A) does not currently take place.

7. Your rights as a data subject

You have the right to:

  • Obtain information about the processing of your personal data (Art. 15 GDPR).
  • Request rectification of incorrect or incomplete data (Art. 16 GDPR).
  • Request deletion of your personal data, provided no statutory retention obligations prevent this (Art. 17 GDPR).
  • Request restriction of the processing of your data (Art. 18 GDPR).
  • Receive the data concerning you in a structured, commonly used format or have it transferred to another controller (Art. 20 GDPR).
  • Object to the processing of your data insofar as processing is based on legitimate interests (Art. 21 GDPR).
  • Withdraw consent you have given at any time with effect for the future (Art. 7(3) GDPR).
  • Lodge a complaint with a data protection supervisory authority if you believe that the processing of your data is not lawful (Art. 77 GDPR).

8. Transfer of data to third countries

As part of the application procedure (Part A), no transfer of data to third countries takes place.

9. Voluntary nature and obligation to provide personal data

Within the application procedure, certain personal data are required in order to review your application and carry out the selection process. Without these data, your application cannot be considered. Voluntary information may be provided—where offered—optionally.

10. Automated decision-making

There is no automated decision-making or profiling within the meaning of Art. 22 GDPR.


Part B – Online application portal (technical provision)

11. Purpose and distinction

For the use of the online application portal, the recruiting platform from Personio is used.

  • Application content (form entries, uploads, communication in the application process): Processing on behalf of Greenbone AG (processing under Art. 28 GDPR).
  • Technical portal operation (provision, security, error analysis, if applicable cookie functions): For this purpose, additional data are processed when using the portal; these technical processing operations may—depending on the type of processing—be carried out in its own responsibility by Personio.

12. Contact for portal-related matters

For data protection matters that exclusively concern the technical operation of the application portal (e.g., log data/cookies), you can also contact Personio additionally:
Personio SE & Co. KG, Seidlstraße 3, 80335 Munich
Data protection contact / Data Protection Officer: privacy@personio.com

13. Which technical data are typically processed?

When accessing and using the application portal, the following in particular may be processed:

  • IP address (or network/connection data), timestamp
  • Browser/device information (e.g., browser type/version, operating system)
  • Access and error logs (server/error logs)
  • Cookies or similar technologies (e.g., language settings, session functions; depending on portal configuration, possibly also performance functions)

14. Legal bases (portal operation)

Insofar as technical portal operation processes personal data, this is regularly done to ensure operation and security on the basis of legitimate interests (Art. 6(1) lit. f GDPR).
Insofar as information is stored or read on your end device in the portal (e.g., cookies), permissibility is governed by § 25 TDDDG (consent, unless technically strictly necessary).

15. Storage period (portal operation)

Technical log data are generally stored only for as long as this is necessary for security purposes and error analysis; cookies are stored depending on their type until the end of the session or for a limited period.

16. Exercising your rights

For the processing operations described in Part A (application procedure), please contact Greenbone AG or the Data Protection Officer (contact details above).
For matters that exclusively concern the technical portal operation, you can also contact Personio directly (privacy@personio.com).


If you have any questions about this privacy notice, please contact us using the contact details provided.
 

Version: 17/02/2026

Processing of (personal) data by the operator of the recruitment website

General information

This recruitment website is operated by Personio SE & Co. KG, which offers a human resource and candidate management software solution (https://www.personio.com/legal-notice/). Data transmitted as part of your application will be transferred using TLS encryption and stored in a database. The sole controller of this data within the meaning of article 24 of the GDPR is the enterprise carrying out this online application process. Personio’s role is limited to operating the software and this recruitment website and, in this context, being a processor under article 28 of the GDPR. In this case, the processing by Personio is based on an agreement for the processing of orders between the controller and Personio. In addition, Personio SE & Co. KG processes further data, some of which may be personal data, to provide its services, in particular for operating this recruitment website. We will refer to this in more detail below.

The controller

The controller under data protection law is:
Personio SE & Co. KG
Seidlstraße 3
80335 München
Tel.: +49 (89) 1250 1004
Entry in the commercial register
Commercial register entry number: HRA 115934
Registration Court: Amtsgericht München
Data Protection Officer contact: privacy@personio.com

Access logs (“server logs”)

Each access to this recruitment website automatically causes general protocol data, so-called server logs, to be collected. As a rule, this data is a pseudonym and thus does not allow for inferences about the identity of an individual. Without this data, it would, in some cases, be technically impossible to deliver or display the contents of the software. In addition, processing this data is absolutely necessary under security aspects, in particular for access, input, transfer, and storage control. Furthermore, this anonymous information can be used for statistical purposes and for optimizing services and technology. In addition, the log files can be checked and analyzed retrospectively when unlawful use of the software is suspected. The legal basis for this is §25 subsection 2 Sentence 2 TDDDG. Generally, data such as the domain name of the website, the web browser and web-browser version, the operating system, the IP address, as well as the timestamp of the access to the software is collected. The scope of this log process does not exceed the common log scope of any other site on the web. These access logs are stored for a period of up to 7 days. There is no right to object to this.

Error logs

So-called error logs are generated for the purpose of identifying and fixing bugs. This is absolutely necessary to ensure we can react as quickly as possible to possible problems with displaying and implementing content (legitimate interest). As a rule, this data is a pseudonym and thus does not allow for inferences about the identity of an individual. The legal basis for this is §25 subsection 2 Sentence 2 TDDDG. When an error message occurs, general data such as the domain name of the website, the web browser and web-browser version, the operating system, the IP address, as well as the timestamp upon occurrence of the respective error message and/or specification is collected. These error logs are stored for a period of up to 7 days. There is no right to object to this.

Use of cookies

So-called cookies are used on parts of this recruitment website. They are small text files which are stored on the device with which you access this recruitment website. As a general rule, cookies serve the purpose of ensuring secure access to a website (“absolutely necessary”), implementing certain functionalities such as standard-language settings (“functional”), improving the user experience or the performance of the website (“performance”), or placing targeted advertisements (“marketing”). On this recruitment website, we generally use only cookies that are absolutely necessary, functional or performance-related, in particular for implementing certain default settings such as language, for identifying the job advertising channel, or for analyzing the performance of a job advert via which a user accessed this recruitment website. The use of cookies is absolutely necessary for providing our services and thus for the performance of the contract (article 6 (1) b) of the GDPR). Period of storage: up to 1 month or until the end of the browser session Right to object: You can determine via your browser settings whether you allow or object to the use of cookies. Please note that deactivating cookies may result in limited or completely blocked functionalities of this recruitment website.

Rights of data subjects

If Personio SE & Co. KG as the controller processes personal data, you as the data subject have certain rights under Chapter III of the EU General Data Protection Regulation (GDPR), depending on the legal basis and the purpose of the processing, in particular the right of access (article 15 of the GDPR) and the rights to rectification (article 16 of the GDPR), erasure (article 17 of the GDPR), restriction of processing (article 18 of the GDPR), and data portability (article 20 of the GDPR), as well as the right to object (article 21 of the GDPR). If the personal data is processed with your consent, you have the right to withdraw this consent under article 7 III of the GDPR. To assert your rights as a data subject in relation to the data processed for the purpose of operating this recruitment website, please refer to Personio SE & Co. KG’s Data Protection Officer (see item B).

Concluding provisions

Personio reserves the right to adjust this data privacy statement at any point in time to ensure that it is in line with the current legal requirements at all times, or in order to accommodate changes in the services offered, for example when new services are introduced. In this case, the new data privacy statement applies to any later visit of this recruitment website or any later job application.