Legal

Privacy notice

Preamble

The following privacy notice is intended to inform you about the types of personal data (hereinafter also briefly referred to as “data”) we process, for which purposes and to what extent. This privacy notice applies to all processing of personal data carried out by us, both in the context of providing our services and in particular on our websites, in mobile applications and within external online presences, such as our social media profiles (hereinafter collectively referred to as “online offering”).

The terms used are not gender-specific.

Updated: June 2026

Controller

Amfelio
Arshak Ovsepyan
Leutkircher Straße 7
80939 Munich, Germany

Email:

Phone:

Legal notice: amfelio.de/en/impressum

Overview of processing activities

The following overview summarises the types of data processed and the purposes of their processing.

Types of data processed

  • Master data (e.g. names, addresses)
  • Application data (e.g. CV, references, qualifications)
  • File and upload data (e.g. CVs, job descriptions, requirement profiles)
  • Professional data (e.g. professional experience, salary expectations)
  • Contact data (e.g. email, telephone numbers)
  • Contract data (e.g. subject matter of the contract, term)
  • Content data (e.g. messages, form entries)
  • Usage data (e.g. page views, access times)
  • Meta, communication and procedural data (e.g. IP addresses, timestamps)
  • Log data (e.g. server log files)
  • Analytics data (pseudonymised/anonymised)

Categories of data subjects

  • Applicants and candidates
  • Corporate clients and their employees
  • Interested parties
  • Communication partners
  • Website visitors
  • Business and contractual partners

Purposes of processing

  • Recruitment and placement services
  • Provision of contractual services and fulfilment of contractual obligations
  • Communication
  • Security measures
  • Office and organisational procedures
  • Feedback
  • Provision of our online offering and user-friendliness
  • Information technology infrastructure
  • Website analysis and optimisation
  • Business processes and administrative procedures

Legal bases

Relevant legal bases under the GDPR: The following provides an overview of the legal bases of the GDPR on which we process personal data. Please note that in addition to the provisions of the GDPR, national data protection requirements may apply.

  • Consent (Article 6(1)(a) GDPR) – The data subject has given consent to the processing of their personal data for a specific purpose.
  • Performance of a contract and pre-contractual enquiries (Article 6(1)(b) GDPR) – Processing is necessary for the performance of a contract or for the implementation of pre-contractual measures.
  • Legal obligation (Article 6(1)(c) GDPR) – Processing is necessary for compliance with a legal obligation to which the controller is subject.
  • Legitimate interests (Article 6(1)(f) GDPR) – Processing is necessary for the purposes of the legitimate interests pursued by the controller or a third party, provided that the interests, fundamental rights and freedoms of the data subject do not prevail.

National data protection regulations in Germany: In addition to the data protection regulations of the GDPR, national data protection provisions apply in Germany, in particular the German Federal Data Protection Act (Bundesdatenschutzgesetz, BDSG).

Security measures

In accordance with the statutory requirements and taking into account the state of the art, we take appropriate technical and organisational measures to ensure a level of protection appropriate to the risk.

The measures include in particular safeguarding the confidentiality, integrity and availability of data, as well as procedures for the exercise of data subject rights, the erasure of data and the response to data threats.

TLS/SSL encryption (HTTPS): All data transmissions on our website are secured by TLS/SSL encryption. This protects your data from unauthorised access during transmission.

Transfers of personal data

In the course of our processing of personal data, data may be transferred to other parties, companies or persons. Recipients of this data may include, for example, service providers commissioned with IT tasks (such as hosting providers) as well as providers of services and content integrated into our website. In such cases, we comply with the statutory requirements and in particular conclude corresponding data processing agreements (DPAs) in accordance with Article 28 GDPR with the recipients.

International data transfers

If we process data in a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)) or if processing takes place in the course of using third-party services, this only happens in compliance with the statutory requirements.

Where the level of data protection in the third country has been recognised by an adequacy decision (Article 45 GDPR), this serves as the basis for the data transfer. Otherwise, data transfers only take place if the level of data protection is secured by other means, in particular through standard contractual clauses (Article 46(2)(c) GDPR) or explicit consent. We point out any third-country transfers in respect of the respective services within this privacy notice.

Data retention and deletion

We erase the personal data we process in accordance with the statutory provisions as soon as the underlying consents are revoked or no further legal grounds for processing exist. Exceptions apply where statutory obligations require a longer retention period.

General retention periods under German law:

  • 10 years – Books and records, annual financial statements, booking vouchers and invoices (Section 147 AO, Section 257 HGB).
  • 6 years – Other business documents, commercial and business letters received and sent (Section 147 AO, Section 257 HGB).
  • 3 years – Data for asserting warranty and damages claims (Sections 195, 199 BGB).
  • 6 months – Application documents after conclusion of the placement process (unless consent has been given for longer storage).

Rights of data subjects

As a data subject, you have various rights under the GDPR, arising in particular from Articles 15 to 21 GDPR:

  • Right to object: You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data based on Article 6(1)(e) or (f) GDPR.
  • Right to withdraw consent: You have the right to withdraw consent granted at any time.
  • Right of access (Article 15 GDPR): You have the right to obtain confirmation as to whether the data concerned is being processed, as well as access to such data.
  • Right to rectification (Article 16 GDPR): You have the right to obtain the completion or rectification of inaccurate data.
  • Right to erasure and restriction of processing (Articles 17, 18 GDPR): You have the right to request that data concerning you be erased without undue delay or that processing be restricted.
  • Right to data portability (Article 20 GDPR): You have the right to receive the data concerning you in a structured, commonly used and machine-readable format.
  • Right to lodge a complaint with a supervisory authority (Article 77 GDPR): You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence or of the place of the alleged infringement.

Recruitment & jobs portal

As a recruitment agency, we process data of applicants, candidates and corporate clients in the context of filling positions and providing recruitment services.

Applicant data

If you apply via our jobs portal or by contacting us directly, or if you provide us with your data for placement purposes, we process the data you submit (e.g. contact data, CV, references, qualifications, professional experience, salary expectations) for the purpose of recruitment. This includes in particular:

  • Recording and storing application documents
  • Analysing qualifications and professional experience
  • Matching against current job requirements
  • Communicating with applicants about the status of the process
  • Sharing your documents with suitable employers (only with your consent)
  • Organising and accompanying interviews

Legal bases: Performance of a contract and pre-contractual enquiries (Article 6(1)(b) GDPR); consent (Article 6(1)(a) GDPR).

Retention: Application documents are stored for the duration of the placement process and up to 6 months after its conclusion. With your explicit consent, we may keep your documents in our candidate pool for longer to inform you about suitable job offers.

Jobs portal

On our jobs portal we publish job offers from our corporate clients. When job listings are accessed, technically necessary data (e.g. IP address, time of access) is processed as part of regular server operation.

Types of data processed: Usage data; meta, communication and procedural data; log data.

Data subjects: Applicants, interested parties, website visitors.

Legal bases: Legitimate interests (Article 6(1)(f) GDPR); performance of a contract (Article 6(1)(b) GDPR).

Location filter

Our jobs portal offers the option to filter job listings by postal code and radius. The entered postal code is converted server-side into geographic coordinates to enable a radius search.

In addition, the “Find current location” button is available. When activated, your browser queries your GPS position via the Geolocation API and transmits the coordinates to our server. There, they are used exclusively for the one-time determination of the associated postal code (reverse geocoding) and are not stored.

Legal basis: Consent (Article 6(1)(a) GDPR). You grant consent by activating the location button; you can refrain from location determination at any time by simply not using it.

Corporate clients

We process data of our corporate clients (e.g. contact persons, requirement profiles for positions) for the purpose of providing our recruitment services.

Types of data processed: Master data; contact data; contract data.

Legal bases: Performance of a contract and pre-contractual enquiries (Article 6(1)(b) GDPR); legal obligation (Article 6(1)(c) GDPR); legitimate interests (Article 6(1)(f) GDPR).

Provision of the online service

We process the data of users in order to be able to provide them with our online services. For this purpose, we process the user’s IP address, which is necessary to transmit the contents and functions of our online services to the user’s browser or end device.

Hosting – IONOS SE

This website is hosted on servers of IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany. When the site is visited, technically necessary data (e.g. IP address, time of access) is stored in server logs. IONOS processes your data on our behalf; a data processing agreement (DPA) in accordance with Article 28 GDPR is in place. IONOS is a provider based in Germany and processes the data exclusively within the EU. Further information can be found in the IONOS privacy notice.

Access data and log files

Access to our online offering is logged in the form of “server log files”. The server log files may contain the address and name of the websites and files accessed, date and time of access, data volumes transferred, browser type and version, the user’s operating system, referrer URL and IP addresses. Log file information is stored for a maximum of 30 days and is then deleted or anonymised.

Types of data processed: Usage data; meta, communication and procedural data; log data.

Data subjects: Users (e.g. website visitors, users of online services).

Legal bases: Legitimate interests (Article 6(1)(f) GDPR).

Contact and enquiry management

When you contact us and in the context of existing user and business relationships, the details of the enquiring persons are processed to the extent necessary to answer the contact enquiries and any requested measures.

Contact forms

When you use one of our contact forms, we process the submitted details to handle your enquiry, to prepare pre-contractual measures and to document the respective process. Transmission is encrypted. Form data is processed server-side and stored in a database for enquiry management; optionally uploaded documents are additionally stored in a separate file storage. Access is restricted to internally authorised persons.

Applicant contact form

With the “Place your profile” form we process in particular first and last name, email address, telephone number, current position, roles or areas sought, availability, location and mobility, a free-text message and, optionally, the uploaded CV. This information is stored in order to review your enquiry, contact you and prepare or carry out the placement process.

Types of data processed: Master data; contact data; application data; professional data; content data; file and upload data; meta, communication and procedural data.

Data subjects: Applicants and candidates.

Retention and erasure: We store information from the applicant form for the duration of the placement process and generally up to 6 months after its conclusion, unless a longer statutory retention obligation or separate consent for longer inclusion in our candidate pool applies.

Legal bases: Performance of a contract and pre-contractual enquiries (Article 6(1)(b) GDPR); consent (Article 6(1)(a) GDPR), insofar as you submit voluntary additional information or documents or agree to longer storage.

Company contact form

With the company form we process in particular the name of the contact person, business email address, telephone number, company name, positions or specialist areas sought, location, a free-text message and, optionally, uploaded job descriptions or requirement profiles. This information is stored in order to handle your enquiry, prepare pre-contractual measures and provide our recruitment services.

Types of data processed: Master data; contact data; contract data; content data; file and upload data; meta, communication and procedural data.

Data subjects: Corporate clients, interested parties and communication partners.

Retention and erasure: We store information from company enquiries for the duration of processing and thereafter only insofar as statutory retention obligations or legitimate interests in following up business and contractual contacts exist.

Legal bases: Performance of a contract and pre-contractual enquiries (Article 6(1)(b) GDPR); legitimate interests (Article 6(1)(f) GDPR) in the efficient handling and documentation of enquiries.

Communication

We are available through various communication channels. Please note the following information on the processing of personal data depending on the channel used.

Email

When communicating by email, the data you submit (e.g. name, email address, message content) is stored and processed to handle your request. Emails may be intercepted during transmission; we cannot guarantee complete data security for this channel. For confidential information, we therefore recommend using our contact forms with secure HTTPS transmission.

WhatsApp

We offer the option of contacting us via WhatsApp (Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland). If you contact us via WhatsApp, your message content and metadata (e.g. time of the message, telephone number) are processed. WhatsApp uses end-to-end encryption for the message content. Please note that WhatsApp may collect metadata even without sent messages and share it with the Facebook group of companies. Please read the WhatsApp privacy policy.

Phone

When you contact us by phone, we process your telephone number as well as the personal data mentioned during the conversation, insofar as this is necessary to handle your request. Conversations are not recorded by us.

Data subjects: Communication partners.

Purposes of processing: Communication.

Legal bases: Consent (Article 6(1)(a) GDPR); performance of a contract and pre-contractual enquiries (Article 6(1)(b) GDPR); legitimate interests (Article 6(1)(f) GDPR).

Website analytics (Umami)

We use the privacy-friendly open-source tool Umami to analyse the use of our website. This helps us better understand visitor behaviour in aggregated form and continuously improve our offering.

Umami was developed specifically for privacy-compliant use:

  • No cookies: Umami does not set any cookies and does not create persistently stored user profiles. Tracing individual users across multiple sessions or websites is not possible.
  • Anonymised data: Your IP address is hashed and anonymised before storage, so no direct reference to your person can be established.
  • Minimal data collection: Only aggregated statistical information is collected, such as the pages accessed, time on site, the device used (browser, operating system) and the approximate geographic location (country).
  • Own infrastructure: Umami is operated entirely on our own servers at IONOS SE in Germany. The data remains exclusively within our area of responsibility and is not transferred to third parties outside the EU/EEA.

The processing of this data is based on our legitimate interests in accordance with Article 6(1)(f) GDPR. Our legitimate interest lies in the statistical analysis of website usage for the optimisation and needs-based design of our online offering.

Objection (opt-out)

You can deactivate collection by Umami at any time. The switch below sets an entry in the local storage (localStorage) of your browser that prevents further data collection. This entry is only valid for this browser and this device.

Umami Tracking aktiviert

Anonymisierte Daten zu Ihrer Websitenutzung werden erfasst.

Alternatively, you can also deactivate tracking by enabling the “Do Not Track” function in your browser, provided your browser supports this function.

Prepared with the Datenschutz-Generator.de by Dr. Thomas Schwenke. Adapted for Amfelio.

Updated: June 2026