Privacy Policy
Last updated: August, 2021
1. An overview of data protection
General information
On our website carracta we,
Tomas Golabski, doing business as „carracta.com“, Willibald-Alexis-Str. 26, 10965 Berlin, Germany
E-mail: info@carracta.com
offer a free job-platform on which potential employers, principals and/or independent contractors (hereinafter also referred to as „Leader“) can get connected with „Candidates“, such as potential employees by making job-information accessible on our platform to interested candidates (hereinafter also referred to as „our service“). We solely provide the online-platform and the technical possibilities for a first contact between potential parties of an emloyment contract, which are to be entered into by the parties themselves without any direct or indirect participation or involvement in such contracts from our side. The following information will provide you with an easy to navigate overview of what will happen with your personal data when you visit this website or when you register for or make use of our service, either as a leader or a candidate. The term “personal data” comprises all data that can be used to personally identify you.
Data recording on this website
Who is the responsible party for the recording of data on this website (i.e. the “controller”)?
The data on this website is processed by us as the operator of the website, whose contact information is available above under No. 1 General Information as well as under section “Legal Notices” on this website.
How do we record your data?
We collect your data as a result of you sharing of your data with us. This may, for instance be information you enter into our contact form, information or data we process when you register for our service or information or data you make accessible on our platform as a leader looking for suitable candidates in the course of a job-advertisement or posting for the purposes described in this Privacy Policy.
Other data will be recorded by our IT systems automatically or after you consent to its recording during your website visit. This data comprises primarily technical information (e.g. web browser, operating system or time the site was accessed). This information is recorded automatically when you access this website.
What are the purposes we use your data for?
A portion of the information is generated to guarantee the error free provision of the website. Other data may be used to analyze your user patterns or to provide and fulfill our services in a customary manner.
What rights do you have as far as your information is concerned?
You have i.a. the right to receive information about the source, recipients and purposes of your archived personal data at any time without having to pay a fee for such disclosures. You also have the right to demand that your data are rectified or deleted. If you have consented to data processing, you have the right to revoke this consent at any time, which shall affect all future data processing. Moreover, you have the right to demand that the processing of your data may be restricted under certain circumstances. Furthermore, you have the right to lodge a complaint with the competent supervising agency.
Please do not hesitate to contact us at any time under the address disclosed under No. 1 General Information of this Privacy Policy, if you have questions about your data, your rights or any other data protection related issues or if you want to exercise your rights.
Analysis tools and tools provided by third parties
There is a possibility that your browsing patterns will be statistically analyzed when you visit this website. Such analyses are performed primarily with what we refer to as analysis programs.
For detailed information about these analysis programs please consult the respective clauses in this Privacy Policy below.
2. General information and mandatory information
Data protection
The operators of this website and its pages take the protection of your personal data very seriously. Hence, we handle your personal data as confidential information and in compliance with the statutory data protection regulations, such as the GDPR (General Data Protection Regulation of the EU).
Whenever you use this website, personal data will be collected. Personal data comprises data that can be used to personally identify you. This Privacy Policy explains which data we process, collect, save, store, transfer or use as well as the purposes we use this data for.
We herewith advise you that the transmission of data via the Internet (i.e. through e-mail communications) may be prone to security gaps. Despite all organisational and technicsl measures we have taken in order to ensure the security of your personal data when you are using our platform, it is not possible to completely protect data against abusive third-party access.
Information about the responsible party (referred to as the “controller” in the GDPR)
The data processing controller on this website is:
Tomas Golabski, doing business as „carracta.com“, Willibald-Alexis-Str. 26, 10965 Berlin, Germany
E-mail: info@carracta.com
The controller is the natural person or legal entity that single-handedly or jointly with others makes decisions as to the purposes of and resources for the processing of personal data (e.g. names, e-mail addresses, etc.).
Storage duration
Unless a more specific storage period has been specified in this Privacy Policy or unless such is mandatory under applicable laws, regulations or administrative orders or a valid court order, your personal data will remain with us until the purpose for which it was collected no longer applies. If you assert a justified request for deletion or revoke your consent to data processing, your data will be deleted with future effect, unless we have other legally permissible reasons or obligations for storing your personal data (e.g. tax or commercial law retention periods); in the latter case, the deletion will take place after these reasons cease to apply.
Information on data transfer to the USA
Our website uses, in particular, tools from companies with headquarters and/or servers in the USA. When these tools are active, your personal information may be transferred to the US servers of these companies. We must point out that the USA is deemed not to be a safe third country within the meaning of EU data protection law. US companies may be required to release personal data to security authorities without your or our consent and without you as the data subject being able to take legal action or to object against this. The possibility cannot therefore be excluded that US authorities (e.g. secret services) may process, evaluate and permanently store your data on US servers for monitoring purposes. We have no influence over these processing activities.
Revocation of your consent to the processing of data
A wide range of data processing transactions are possible only subject to your express consent. You can also revoke at any time any consent you have already given us. This shall be without prejudice to the lawfulness of any data collection that occurred prior to your revocation.
Right to object to the collection of data in special cases; right to object to direct advertising (Art. 21 GDPR)
IN THE EVENT THAT DATA ARE PROCESSED ON THE BASIS OF ART. 6 SECT. 1 LIT. E OR F GDPR, YOU HAVE THE RIGHT TO AT ANY TIME OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA BASED ON GROUNDS ARISING FROM YOUR UNIQUE SITUATION. THIS ALSO APPLIES TO ANY PROFILING BASED ON THESE PROVISIONS. TO DETERMINE THE LEGAL BASIS, ON WHICH ANY PROCESSING OF DATA IS BASED, PLEASE CONSULT THIS PRIVACY POLICY. IF YOU LODGE AN OBJECTION, WE WILL NO LONGER PROCESS YOUR AFFECTED PERSONAL DATA, UNLESS WE ARE IN A POSITION TO PRESENT COMPELLING PROTECTION WORTHY GROUNDS FOR THE PROCESSING OF YOUR DATA, THAT OUTWEIGH YOUR INTERESTS, RIGHTS AND FREEDOMS OR IF THE PURPOSE OF THE PROCESSING IS THE CLAIMING, EXERCISING OR DEFENCE OF LEGAL ENTITLEMENTS (OBJECTION PURSUANT TO ART. 21 SECT. 1 GDPR).
IF YOUR PERSONAL DATA IS BEING PROCESSED IN ORDER TO ENGAGE IN DIRECT ADVERTISING, YOU HAVE THE RIGHT TO AT ANY TIME OBJECT TO THE PROCESSING OF YOUR AFFECTED PERSONAL DATA FOR THE PURPOSES OF SUCH ADVERTISING. THIS ALSO APPLIES TO PROFILING TO THE EXTENT THAT IT IS AFFILIATED WITH SUCH DIRECT ADVERTISING. IF YOU OBJECT, YOUR PERSONAL DATA WILL SUBSEQUENTLY NO LONGER BE USED FOR DIRECT ADVERTISING PURPOSES (OBJECTION PURSUANT TO ART. 21 SECT. 2 GDPR).
Right to lodge a complaint with the competent supervisory agency
In the event of violations of the GDPR, data subjects are entitled to lodge a complaint with a supervisory agency, in particular in the member state where they usually maintain their domicile, place of work or at the place where the alleged violation occurred. The right to lodge a complaint is in effect regardless of any other administrative or court proceedings available as legal recourses.
Right to data portability
You have the right to demand that we hand over any data we automatically process on the basis of your consent or in order to fulfil a contract be handed over to you or a third party in a commonly used, machine readable format. If you should demand the direct transfer of the data to another controller, this will be done only if it is technically feasible.
SSL and/or TLS encryption
For security reasons and to protect the transmission of confidential content, such as purchase orders or inquiries you submit to us as the website operator, this website uses either an SSL or a TLS encryption program. You can recognize an encrypted connection by checking whether the address line of the browser switches from “http://” to “https://” and also by the appearance of the lock icon in the browser line.
If the SSL or TLS encryption is activated, data you transmit to us cannot be read by third parties.
Information about, rectification and deletion of data
Within the scope of the applicable statutory provisions, you have the right to at any time demand information about your archived or stored personal data, their source and recipients as well as the purpose of the processing of your data. You may also have a right to have your data rectified or deleted. If you have questions about this subject matter or any other questions about personal data, please do not hesitate to contact us at any time at the address provided in this Privacy Policy above under No. 1 General Information.
Right to demand processing restrictions
You have the right to demand the imposition of restrictions as far as the processing of your personal data is concerned. To do so, you may contact us at any time at the address provided in this Privacy Policy above under No. 1 General Information. The right to demand restriction of processing applies in the following cases:
- In the event that you should dispute the correctness of your data archived by us, we will usually need some time to verify this claim. During the time that this investigation is ongoing, you have the right to demand that we restrict the processing of your personal data.
- If the processing of your personal data was/is conducted in an unlawful manner, you have the option to demand the restriction of the processing of your data in lieu of demanding the deletion of this data.
- If we do not need your personal data any longer and you need it to exercise, defend or claim legal entitlements, you have the right to demand the restriction of the processing of your personal data instead of its deletion.
- If you have raised an objection pursuant to Art. 21 Sect. 1 GDPR, your rights and our rights will have to be weighed against each other. As long as it has not been determined whose interests prevail, you have the right to demand a restriction of the processing of your personal data.
If you have restricted the processing of your personal data, these data – with the exception of their archiving and storage – may be processed only subject to your consent or to claim, exercise or defend legal entitlements or to protect the rights of other natural persons or legal entities or for important public interest reasons cited by the European Union or a member state of the EU.
3. Recording of data on this website
Server log files
The provider of this website and its pages automatically collects and stores information in so-called server log files, which your browser communicates to us automatically. The information comprises:
- The type and version of browser used
- The used operating system
- Referrer URL
- The hostname of the accessing computer
- The time of the server inquiry
- The IP address
These data are not merged with other data sources.
These data are collected and recorded on the basis of Art. 6 Sect. 1 lit. f GDPR. The operator of the website has a legitimate interest in the technically error free depiction and the optimization of the operator’s website. In order to achieve this, server log files must be recorded but will be routinely deleted after 30 days.
4. Registration on our platform/Use of our service
Leader
When registering on our platform, when creating a profile on our platform or when using our service as a leader, i.e. a person or legal entity that is planning to seek or is seeking suitable candidates for a vacant job on our online platform we process, collect and use your personal data according to the following provisions:
a) Registration
In order to use our service you respectively the person or legal entity you are representing have to register on our online platform. When doing so you have to provide and submit the following mandatory data to us:
first and last name of the natural person who is registering on our online-platform on one‘s own behalf, respectively first and last name of the contact person of a legal entity, if you register on behalf of such
email address
password (to be chosen by you - in order to prevent the misuse of your registered account by unauthorised third parties we highly recommend you to chose a secure password and to keep your password strictly confidential by not sharing it with others and by instantly informing us and changing your password if you suspect any unauthorised use of your registered account)
your jobtitle
company name
company URL
full company address including street, street-number, zip-code, country
company type
company size
We use these personal data to verify your access and log-in information, to secure your registered user account against misuse, to recognise and identify you, when using our service as well as to properly and customarily perform our service to you. Your contact information will be accessible to the candidates who consider to apply for the job(s) you are offering through your registered account.
The legal basis for us to collect, process, store and use these personal data is Art. 6 Sect. 1 lit. b) and f) GDPR, i.e. lit b): processing is neccessary for the performance of the platform user agreement between you/your company and us or in order to take steps at the request of the data subject prior to entering into a contract or lit f): processing is neccessary for the purpose of the legitimate interest pursued by us or by a third party. Our legitimate interest results from our aim to flawlessly and securely providing our service to all of our users.
We transfer your data to the extent neccessary solely if you explicitly consented to such a data transfer, if this is neccessary for us to customarily fulfill and perform our service, if we are obligated by law, regulation or any administrative or judicial order to transfer such data to the competent authorities (e.g. tax office) or to enforce claims that arise out of or in connection with an existing agreement between us and the user.
We store and process the collected personal data for as long as you are using our service, which can be terminated by you anytime by simply de-registering from our online-platform or to inform us of your decision to terminate our service, unless we are obligated to store personal data under applicable law, especially, but not limited to the duration of mandatory retention periods under applicable tax or trade law regulations.
We explicitly point out to your sole responsibility for the collection, processing, storage and any other use of personal data of candidates who contact you or apply for a job through our online platform. We do not store any personal data of the candidates. It is therefore the sole responsibility of the leader to comply with mandatory data protection laws when personal data of a candidate is submitted to the leader.
b) Creating your Profile
Once you have registered for our online-platform you are able to create your own profile in order to facilitates the use of our service by voluntarily and optionally adding further profile data which you deem appropriate, such as:
user image, user cover image, links to your social media accounts, such as linkedin, xing, github, stackoverflow, twitter, steam, etc.
The data you provide on your profile is voluntary and optional information and is not mandatory or required from us to use our service. Such data will be accessible by other users of our online platform who can use it to learn more on you resp. the company or legal entity you are representing and to get in touch with you concerning job applications or general inuiries. By providing such additional information you consent that this information is being stored and collected by us as long as you are ussing our service which can be terminated anytime by simply deleting such additional information from your profile or by informing us on your decision to terminate our service. The legal basis for us to collect, process, store and use these personal data is Art. 6 Sect. 1 lit. a) GDPR, i.e. your consent which can be revoked anytime without giving reasons by simply deleting such information from your profile.
Candidate
As a candidate, i.e. a natural person using our service in order to apply for jobs that are offered by leaders on our online platform it is neither required to register on our platform nor to set up or maintain a profile on our online platform. If you want to apply for a job that is offered by one of the registered leaders through our online platform you can either send your application directly to that leader, in which case no personal data are submitted to us, or you can submit your application through our online platform in which case you have to provide and submit the following mandatory data:
first and last name, email address and cv (to be uploaded by you)
Upon your free choice you can add the following voluntary and optional data in order to facilitate the the leader‘s reply to your application:
social links, additional text message
We use these personal data solely to forward your application. The data is neccessary for the registered leader to reply to your application and, at best, to invite you to a personal interview or to negotiate conditions of a potential employment contract with you. We do not store any of the data of the candidate listed herewithin. We solely direct and transfer these data (mandatory and optional information) to the leader who has advertised a job on our online platform.
The legal basis for us to process and transfer these personal data is Art. 6 Sect. 1 lit. a) and b) GDPR i.e. lit a): your consent or lit b): processing is neccessary in order to take steps at the request of the data subject prior to entering into a contract.
5. Analysis tools and advertising
Google Analytics
This website uses functions of the web analysis service Google Analytics. The provider of this service is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
Google Analytics enables the website operator to analyze the behavior patterns of website visitors. To that end, the website operator receives a variety of user data, such as pages accessed, time spent on the page, the utilized operating system and the user’s origin. Google may consolidate these data in a profile that is allocated to the respective user or the user’s device.
Google Analytics uses technologies that make the recognition of the user for the purpose of analyzing the user behavior patterns (e.g. cookies or device fingerprinting). The website use information recorded by Google is, as a rule transferred to a Google server in the United States, where it is stored.
This analysis tool is used on the basis of Art. 6 Sect. 1 lit. f GDPR. The operator of this website has a legitimate interest in the analysis of user patterns to optimize both, the services offered online and the operator’s advertising activities. If a corresponding agreement has been requested (e.g. an agreement to the storage of cookies), the processing takes place exclusively on the basis of Art. 6 para. 1 lit. a GDPR; the agreement can be revoked at any time.
IP anonymization
On this website, we have activated the IP anonymization function. As a result, your IP address will be abbreviated by Google within the member states of the European Union or in other states that have ratified the Convention on the European Economic Area prior to its transmission to the United States. The full IP address will be transmitted to one of Google’s servers in the United States and abbreviated there only in exceptional cases. On behalf of the operator of this website, Google shall use this information to analyze your use of this website to generate reports on website activities and to render other services to the operator of this website that are related to the use of the website and the Internet. The IP address transmitted in conjunction with Google Analytics from your browser shall not be merged with other data in Google’s possession.
Browser plug-in
You can prevent the recording and processing of your data by Google by downloading and installing the browser plugin available under the following link: https://tools.google.com/dlpage/gaoptout?hl=en.
For more information about the handling of user data by Google Analytics, please consult Google’s Data Privacy Declaration at: https://support.google.com/analytics/answer/6004245?hl=en.
Demographic parameters provided by Google Analytics
This website uses the “demographic characteristics” function of Google Analytics, to be able to display to the website visitor compatible ads within the Google advertising network. This allows reports to be created that contain information about the age, gender and interests of the website visitors. The sources of this information are interest-related advertising by Google as well as visitor data obtained from third-party providers. This data cannot be allocated to a specific individual. You have the option to deactivate this function at any time by making pertinent settings changes for advertising in your Google account or you can generally prohibit the recording of your data by Google Analytics as explained in section “Objection to the recording of data”.
Archiving period
Data on the user or incident level stored by Google linked to cookies, user IDs or advertising IDs (e.g. DoubleClick cookies, Android advertising ID) will be anonymized or deleted after 14 month. For details please click the following link: https://support.google.com/analytics/answer/7667196?hl=en.
LinkedIn Insight Tag
This website uses the Insight tag from LinkedIn. This service is provided by LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA.
Data processing by LinkedIn Insight tag
We use the LinkedIn Insight tag to obtain information about visitors to our website. Once a website visitor is registered with LinkedIn, we can analyze the key occupational data (e.g., career level, company size, country, location, industry, job title) of our website visitors to help us better target our site to the relevant audience. We can also use LinkedIn Insight tags to measure whether visitors to our websites make a purchase or perform other actions (conversion measurement). Conversion measurement can also be carried out across devices (e.g. from PC to tablet). LinkedIn Insight Tag also features a retargeting function that allows us to display targeted advertising to visitors to our website outside of the website. According to LinkedIn, no identification of the advertising addressee takes place.
LinkedIn itself also collects log files (URL, referrer URL, IP address, device and browser characteristics and time of access). The IP addresses are shortened or (if they are used to reach LinkedIn members across devices) hashed (pseudonymized). The direct identifiers of LinkedIn members are deleted by LinkedIn after seven days. The remaining pseudonymized data will then be deleted within 180 days.
The data collected by LinkedIn cannot be assigned by us as a website operator to specific individuals. LinkedIn will store the personal data collected from website visitors on its servers in the USA and use it for its own promotional activities. For details, please see LinkedIn's privacy policy at https://www.linkedin.com/legal/privacy-policy#choices-oblig.
Legal basis
The use of LinkedIn Insight is based on Art. 6(1)(f) GDPR. The website operator has a legitimate interest in effective advertising measures, including social media. If a corresponding consent has been requested (e.g. consent to the storage of cookies), the processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR; the consent can be revoked at any time.
Objection to the use of LinkedIn Insight Tag
You can object to LinkedIn's analysis of user behavior and targeted advertising at the following link: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
In addition, LinkedIn members can control the use of their personal information for promotional purposes in the account settings. To prevent LinkedIn from linking information collected on our site to your LinkedIn account, you must log out of your LinkedIn account before you visit our site.
6. Newsletter
Newsletter data
If you would like to subscribe to the newsletter offered on this website, we will need from you an e-mail address as well as information that allows us to verify that you are the owner of the e-mail address provided and consent to the receipt of the newsletter. No further data shall be collected or shall be collected only on a voluntary basis. We shall use such data only for the sending of the requested information and shall not share such data with any third parties.
The processing of the information entered into the newsletter subscription form shall occur exclusively on the basis of your consent (Art. 6 Sect. 1 lit. a GDPR). You may revoke the consent you have given to the archiving of data, the e-mail address and the use of this information for the sending of the newsletter at any time, for instance by clicking on the “Unsubscribe” link in the newsletter. This shall be without prejudice to the lawfulness of any data processing transactions that have taken place to date.
The data submitted to us for the purpose of subscribing to the newsletter will be stored by us until you unsubscribe from the newsletter or the newsletter service provider and will be deleted thereafter. Data stored for other purposes remain unaffected hereby.
After you unsubscribe from the newsletter distribution list, your e-mail address may be stored by us or the newsletter service provider in a blacklist to prevent future mailings. The data from the blacklist is used only for this purpose and not merged with other data. This serves both your interest and our interest in complying with the legal requirements when sending newsletters (legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR). The storage in the blacklist is indefinite. You may object to the storage if your interests outweigh our legitimate interest.
MailChimp
This website uses the services of MailChimp to send out its newsletters. The provider is the Rocket Science Group LLC, 675 Ponce De Leon Ave NE, Suite 5000, Atlanta, GA 30308, USA.
Among other things, MailChimp is a service that can be deployed to organize and analyze the sending of newsletters. Whenever you enter data for the purpose of subscribing to a newsletter (e.g. your e-mail address), the information is stored on MailChimp servers in the United States.
With the assistance of the MailChimp tool, we can analyze the performance of our newsletter campaigns. If you open an e-mail that has been sent through the MailChimp tool, a file that has been integrated into the e-mail (a so-called web-beacon) connects to MailChimp’s servers in the United States. As a result, it can be determined whether a newsletter message has been opened and which links the recipient possibly clicked on. Technical information is also recorded at that time (e.g. the time of access, the IP address, type of browser and operating system). This information cannot be allocated to the respective newsletter recipient. Their sole purpose is the performance of statistical analyses of newsletter campaigns. The results of such analyses can be used to tailor future newsletters to the interests of their recipients more effectively.
If you do not want to permit an analysis by MailChimp, you must unsubscribe from the newsletter. We provide a link for you to do this in every newsletter message.
The data is processed based on your consent (Art. 6 Sect. 1 lit. a GDPR). You may revoke any consent you have given at any time by unsubscribing from the newsletter. This shall be without prejudice to the lawfulness of any data processing transactions that have taken place prior to your revocation.
The data submitted to us for the purpose of subscribing to the newsletter will be stored by us until you unsubscribe from the newsletter or the newsletter service provider and will be deleted thereafter. Data stored for other purposes remain unaffected hereby.
After you unsubscribe from the newsletter distribution list, your e-mail address may be stored by us or the newsletter service provider in a blacklist to prevent future mailings. The data from the blacklist is used only for this purpose and not merged with other data. This serves both your interest and our interest in complying with the legal requirements when sending newsletters (legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR). The storage in the blacklist is indefinite. You may object to the storage if your interests outweigh our legitimate interest.
For more details, please consult the Data Privacy Policies of MailChimp at: https://mailchimp.com/legal/terms/.
7. Plug-ins and Tools
Google Web Fonts (local embedding)
This website uses so-called Web Fonts provided by Google to ensure the uniform use of fonts on this site. These Google fonts are locally installed so that a connection to Google’s servers will not be established in conjunction with this application.
For more information on Google Web Fonts, please follow this link: https://developers.google.com/fonts/faq and consult Google’s Data Privacy Declaration under: https://policies.google.com/privacy?hl=en.
Font Awesome
This page uses Font Awesome for the uniform representation of fonts and symbols. Provider is Fonticons, Inc. 6 Porter Road Apartment 3R, Cambridge, Massachusetts, USA.
When you call up a page, your browser loads the required fonts into its browser cache to display texts, fonts and symbols correctly. For this purpose, the browser you use must connect to the servers of Font Awesome. This allows Font Awesome to know that your IP address has been used to access this website. The use of Font Awesome is based on Art. 6(1)(f) GDPR. We have a legitimate interest in the uniform presentation of the typeface on our website. If consent has been requested (e.g. consent to the storage of cookies), processing will be carried out exclusively on the basis of Art. 6(1)(a) GDPR; consent may be revoked at any time.
If your browser does not support Font Awesome, a standard font from your computer will be used.
Further information about Font Awesome can be found in the Font Awesome privacy policy at: https://fontawesome.com/privacy.