DATA PRIVACY POLICY WITH REGARD TO SERVICE
GENERAL GDPR POLICY SUMMARY
This data privacy policy explains to users of the website, www.panattonieurope.com, how their data are processed when visiting the website and the using the services on the website. With regard to data privacy legal terms, the definitions in the EU General Data Protection Regulation (GDPR) apply in this data privacy policy.
1. RESPONSIBLE PARTY
1.1. RESPONSIBLE PARTY Panattoni Germany Properties GmbH, Am Sandtorkai 54, 20457 Hamburg is the responsible for the processing of personal data on this website. You can reach the responsible party at the following email address: deinfo@panattoni.com.
1.2. DATA PROTECTION OFFICER The responsible party has appointed a data protection officer who can be contacted via email regarding all matters pertaining to the processing of personal data at gdpr-de@panattoni.com.
2. WHAT DATA ARE PROCESSED ON THE WEBSITE
2.1. TECHNICAL DATA When visiting the website, technical data are automatically sent to the website’s server by the user’s browser. This information is temporarily stored in log files. The following technical information is collected:
- IP address of the requesting end device
- Date and time of access
- Name and URL of the visited site
- Transmitted data volume
- Access status (file transmitted, file not found, etc.)
- ID data of the browser and operating system used on the user’s end device and additional information about the browser like set language,
- Name of the user’s Internet provider
- Website from which the user was referred.
2.2. ANALYTICAL DATA If the user has consented to the use of the relevant cookies, the responsible party also analyses the user’s behaviour on the website.
2.3. DATA TRANSMITTED BY THE USER In several areas of the website, users can provide information about themselves to the responsible party which the responsible party then processes accordingly.
3. PURPOSE AND LEGAL BASIS OF THE DATA PROCESSING ON THE WEBSITE
3.1. PROCESSING OF TECHNICAL DATA Personal data of all persons who use the website (in particular, the automatically transmitted technical data) are processed by the responsible party:
3.1.1. To provide electronic services in the framework of providing the content compiled for the users on the website; in this case, the legal basis for the processing is the responsible party’s need to fulfil the agreement (Art. 6 (1) (b) of the GDPR)
3.1.2. For analytical and statistical purposes; in this case, the legal basis for the processing, to the extent the data were collected by cookies to which the placement of which the user has previously consented, is the consent of the users pursuant to Art. 6 (1) (a) of the GDPR (the user can revoke this consent at any time with future effect) and, if the data were obtained in another manner, the legal basis is the legitimate interest of the responsible party (Art. 6 (1) (f) of the GDPR) in analysing the user’s activities and preferences in order to improve the used functions and provided services
3.1.3. To assert and pursue any and all potential claims or to defend against such claims, the legal basis for processing the data is the responsible party’s legitimate interest (Art. 6 (1) (f) of the GDPR) in preserving its rights.
3.2. ANALYSIS The user’s activities on the website, including their personal data, are recorded in system logs (special computer program used by the responsible party to provide the services which is used to store chronological records with information about events and activities related to the IT system). The information collected in the logs are primarily processed for purposes associated with providing services.
3.3. IT SECURITY The responsible party will also process the data for technical and administrative purposes in order to ensure the security of the IT systems and manage this system and for analytical and statistical purposes; in this respect, the legal basis for the processing is the responsible party’s legitimate interest (Art. 6 (1) (f) of the GDPR).
3.4. CONTACT FORM With the help of the electronic form, the responsible party offers the option to contact the website operator. The use of the form requires the provision of personal data which are required to contact the user and respond to the request. To make contact or processing the request easier, the user can provide additional information. The provision of data marked as required fields is required for the acceptance and processing of the data, otherwise, the request cannot be processed. The provision of the data is voluntary. The responsible party processes the personal data provided in the contact form on the basis of the consent from the user provided on transmission pursuant to Art. 6 (1) (a) of the GDPR. The user can revoke this consent from the responsible party at any time with future effect. Insofar as contact is made to initiate or execute a contract, the responsible party will process the data for this purpose on the basis of Art. 6 (1) (b) of the GDPR. In addition, the responsible party processes the personal data of users who submit requests for analytical and statistical purposes. The legal basis for the processing is the responsible party’s legitimate interest (Art. 6 (1) (f) of the GDPR) in conjunction with the keeping of statistics about the requests submitted by users via the website with the objective of improving functionality.
3.5. DIRECT MARKETING The user’s personal data can also be used by the responsible party to send marketing content to the user via various channels (email, MMS/SMS, telephone). The responsible party shall only utilise such measures if the user has consented. The legal basis for this is the user’s consent pursuant to Art. 6 (1) (a) of the GDPR which can be revoked at any time with future effect.
3.6. MARKETING VIA POST In some cases, the responsible party can also carry out direct marketing via conventional post. The user will be informed separately about the intention of executing this kind of marketing. The legal basis for this is the responsible party’s legitimate interest in marketing its products pursuant to Art. 6 (1) (f) of the GDPR. The user is entitled to object to this kind of marketing.
4. COOKIES AND SIMILAR TECHNOLOGIES
The responsible party uses a number of cookies on the website for a variety of purposes. Users can find more information about the stored cookies and the respective processing purposes of the data generated by the cookies in the Cookies Policy which users can open here.
5. ANALYSIS AND MARKETING TOOLS
5.1. GOOGLE ANALYTICS The responsible party uses Google Analytics on the website, a web analytics tool from Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) (“Google”). Google Analytics uses cookies (more information can be found in the Cookie Policy).
The information generated by the cookie about a user’s use of the website is generally transferred to a Google server in the USA and stored there. The responsible party has expanded Google Analytics to include the code “gat._anonymizeIp();” in order to ensure IP addresses are recorded in an anonymised format (IP masking). These means that IP addresses of Google users within member states of the European Union or in other states party to the Convention on the European Economic Zone are truncated. As a result, only in exceptional cases is the full IP address transmitted to a Google server in the USA and truncated there. In these cases, Google secures the data transfer via concluded EU standard contractual clauses.
Google uses the information to evaluate the use of the website by the users in order to compile reports on the website activities and to provide additional services associated with the website and Internet use to the responsible party. The IP addresses transmitted by your browser in the framework of Google Analytics is not combined with other data from Google, according to statements from Google. However, the responsible party does not have precise insight into how Google processes its data.
The data processing by Google Analytics is justified by the issued consent to store the corresponding cookies pursuant to Art. 6 (1) (a) of the GDPR. The user can revoke their previously issued consent to the storage of Google Analytics cookies at any time with future effect by using the opt-out option in the Cookie Policy.
More information about the terms of use and data protection can be found under Google Analytics Terms of Use or Google Analytics Overview or in Google’s Data Privacy Policy.
5.2. GOOGLE ADS This website uses the Google AdWords Conversion Tracking function from Google (see the previous item for information about Google). Google AdWords Conversion Tracking uses cookies that analyse the use of the website by the user if the user clicks on a Google ad. The cookies are valid for a maximum of 90 days. Users can find detailed information about the cookies in the Cookie Policy.
Personal data will not be stored. As long as the cookie is valid, Google and the responsible party can see that a user has clicked on an ad and been directed to a specific target site. These cookies cannot be tracked across multiple websites from different AdWords participants Conversion statistics are generated in Google AdWords by the cookie. The number of users that clicked on an ad is recorded in these statistics. The number of users directed to a target site with a conversion tag is also counted.
The outlined processing is carried out on the basis of the consent issued by the user in the cookie banner, pursuant to Art. 6 (1) (a) of the GDPR, if the user has issued this consent. The user can revoke this consent in the Cookie Policy with future effect. Users can find additional information about how Google Conversion data are used here, about Google Ads here, as well as about data processing by Google in Google’s Data Privacy Policy.
5.3. LEADFEEDER The responsible party uses the LeadFeeder service on this website, which is operated by von Liidio Oy, Mikonkatu 17, 0100 Helsinki, Finland (“LeadFeeder”). LeadFeeder processes the truncated IP addresses of the website visitors provided by Google Analytics and links the list of IP addresses to information about the companies found online under these IP addresses. In addition, LeadFeeder stores its own cookies in order to monitor the behaviour of users on the website. Users can find detailed information about the cookies in the Cookie Policy. Based on the collected data in the form of IP addresses (IP addresses that are allocated to companies will be collected while IP addresses allocated to individual persons will be automatically declined), data on the visited sites, the origin of the user and the time spent on the website, LeadFeeder determines the location of the person visiting the website.
The outlined processing is carried out on the basis of the consent issued by the user in the cookie banner, pursuant to Art. 6 (1) (a) of the GDPR, if the user has issued this consent. The user can revoke this consent in the Cookie Policy with future effect.
5.4. LINKEDIN MARKETING SOLUTIONS The responsible party uses the service offered by LinkedIn Ireland Unlimited Company, Wilton Plaza, Dublin 2, Dublin, Ireland (“LinkedIn”) on the website. LinkedIn Marketing Solutions stores and processes information about the user behaviour on the website and uses, among other things, cookies to do this. Users can find detailed information about the cookies in the Cookie Policy. The responsible party uses the service for marketing and optimisation purposes, in particular, to analyse the use of the website and to be able to continuously improve individual functions and offers and the user experience.
The outlined processing is carried out on the basis of the consent issued by the user in the cookie banner, pursuant to Art. 6 (1) (a) of the GDPR, if the user has issued this consent. The user can revoke this consent in the Cookie Policy with future effect. Users can find information about data processing by LinkedIn in LinkedIn’s Data Privacy Policy. In addition, users can manage cookies and marketing from LinkedIn in the Settings options on LinkedIn.
5.5. SALESVIEWER On this website, the SalesViewer® technology from SalesViewer® GmbH is used on the basis of the legitimate interest of the website operator (Art. 6 (1) (f) of the GDPR) to collect and store information for marketing, market research and optimisation purposes.
To this end, a javascript-based code is used which is used to collect company-specific data and for the corresponding use thereof. The data collected using this collected data are encrypted via a reverse computational one-way function (hashing). The data are immediately pseudonymised and are not used to identify the site visitor.
The data stored by SalesViewer® are deleted as soon as they are no longer required for the intended purpose and the deletion does not violate any statutory retention periods.
The transmission and storage can objected to at any time with future effect by clicking this link https://www.salesviewer.com/opt-out to prevent SalesViewer® from recording within this website in the future. The opt-out cookie for this website will be stored on your device. If you delete the cookies in this browser, you will have to click this link again.
6. INTEGRATED SERVICES
6.1. YOUTUBE On this website, the responsible party links to videos on the platform, YouTube operated by YouTube, LLC, a company belonging to Google (see Section 5.1 above for information about Google). The videos and connection to YouTube will not be activated until the user clicks on the corresponding symbol.
The data collected about the user while using the service are processed by Google and may be transmitted to countries outside the European Union. These data include, among other things, the IP addresses, the application used, information about the end device used (including device ID and application ID), information about visited websites, the location, the mobile data provider and other information that are available on the user’s PC in the form of cookies.
The use of YouTube is justified by the user’s consent which they provide by clicking on the corresponding symbol, pursuant to Art. 6 (1) (a) of the GDPR. The user can revoke the previously issued consent at any time with future effect.
Google outlines, in a general form, which information Google collects and processes in its Data Privacy Policy. Users can find more information in the General information about data privacy settings when using Google services and with specific reference to individual services including those from YouTube).
6.2. VIMEO On the website, the responsible party links to videos on the platform, Vimeo, operated by Vimeo der Vimeo LLC, 555 West 18th Street, New York, New York 10011, US (“Vimeo”). The videos and connection to Vimeo will not be activated until the user clicks on the corresponding symbol.
The data collected about the user while using the service are processed by Vimeo and may be transmitted to countries outside the European Union. These data include, among other things, the IP addresses, the application used, information about the end device used (including device ID and application ID), information about visited websites, the location, the mobile data provider and other information that are available on the user’s PC in the form of cookies.
The use of Vimeo is justified by the user’s consent which they provide by clicking on the corresponding symbol, pursuant to Art. 6 (1) (a) of the GDPR. The user can revoke the previously issued consent at any time with future effect. Users can find more information about the processing of data by Vimeo in Vimeo’s Data Privacy Policy.
7. SOCIAL MEDIA
If profiles on the responsible party’s social media refer to this Data Privacy Policy, the responsible party will process these user data from the profiles in compliance with the following provisions. This applies to the following platforms: YouTube, LinkedIn, Vimeo, Xing, Instagram, Facebook and Twitter.
Personal data of the user will be processed by the responsible party solely in conjunction with the maintenance of the profile, in order to, among other things, inform the user about the activities of the responsible party and to market various kinds of events, services and products. In addition, the responsible party regularly receives analysis data from the respective social medium on the use of its profile and on the interaction of the users with the responsible party’s profile. The legal basis for the processing of personal data by the responsible party for this purpose is its legitimate interest (Art. 6 (1) (f) of the GDPR) which is in the promotion of its own brand and communication with existing and potential new clients and business partners. Users can find more information about the respective processed personal data on the social medium in the linked data privacy policy on the website of the respective provider.
On the LinkedIn and Facebook platforms, the responsible party has also concluded a contract with the platform regarding mutual responsibility. Users can find more information about this for LinkedIn here and for Facebook here. If other mutual responsibilities exist with the providers of other social media, the users can find more information in the respective terms of use and data privacy policies of the providers.
8. STORAGE OF PERSONAL DATA
8.1. The retention period for the personal data processed by the responsible party is based on the nature of the services provided and the purpose of the processing. In general, the data are processed for the duration of the service or the execution of the order, until consent is revoked or an effective objection to the legitimate interest of the responsible party has been filed. The responsible store personal data only for as long as it has a legal basis to do so or is subject to a statutory retention period.
8.2. The data processing period can be extended if the processing is required to establish and pursue claims or defence against such claims and, after that, only if and insofar as it is required by law. After the processing period has elapsed, the data will be irrevocably deleted or anonymised.
9. USER’S RIGHTS
9.1. If the user’s data are processed on the basis of consent, this consent can be revoked at any time with future effect.
9.2. The user has the right to obtain information about the processing of the data and to the correction or deletion of the data in accordance with the requirements in Art. 17 of the GDPR and to the limitation of the processing of their personal data, the right to data portability and the right to object to the processing of the data and the right to submit a complaint to the supervisory authority responsible for the protection of personal data.”
9.3. The user has the right to object to the use of personal data for marketing purposes if the processing is carried out in conjunction with the legitimate interest of the responsible party and, for reasons associated with the user’s specific situation, in other cases in which the legal basis of the data processing is the legitimate interest of the responsible party (e.g., in conjunction with carrying out analyses and statistical purposes).”
10. DATA RECIPIENTS
10.1. In conjunction with the provision of services, personal data is forwarded to external bodies, in particular, providers responsible for the operation of IT systems, bodies like banks and payment service provider, bodies that provide accounting services, couriers (in conjunction with the execution of the order), marketing agencies (in the context of marketing services) and bodies that are affiliated with the responsible party, including members of its corporate group.
10.2. With the consent of the user, these data can also be made available to other bodies for their own purposes, e.g., marketing.
10.3. If the responsible party is legally obligated or entitled, it shall also pass on personal data to courts, authorities or other public bodies.
11. DATA TRANSMISSION ACROSS BORDERS
11.1. Personal data outside the European Economic Zone (EEZ) shall be assigned a different protection level than required by European law. Therefore, the responsible party only transmits personal data outside the EEZ if it is required and a reasonable degree of security has been ensured, primarily by
11.1.1. cooperating with bodies that process personal data in countries for which a corresponding resolution has been passed by the European Commission on ensuring an adequate level of protection for personal data
11.1.2. the use of standard contractual clauses issued by the European Commission
11.1.3. the use of binding corporate regulations that have also been approved by the competent authority
11.2. The responsible party shall always inform the user, at the time of the collection of personal data, about the intent to transmit it across borders to outside the EEZ.
12. PERSONAL DATA SECURITY
12.1. The responsible party carries out an ongoing risk analysis to ensure that personal data are processed in a secure manner; to this end, it ensures, in particular, that only authorised persons have access to data and only in the scope required to execute their duties. The responsible party shall ensure that all processes associated with personal data are documented and carried out only by authorised employees and partners.
12.2. The responsible party shall take all necessary measures to ensure that its subcontractors and other cooperating bodies ensure, at all times, that adequate security measures are used if they process personal data on behalf of the responsible party.
13. AMENDMENTS TO THE DATA PROTECTION GUIDELINE
13.1. This policy is continuously reviewed and revised as needed.
13.2. The current version of the policy has been valid since 22 September 2025.