Privacy policy

Data protection information in accordance with Articles 13 and 14 of the EU General Data Protection Regulation (GDPR)

The following data protection information is intended to explain to you in a clear, transparent and understandable way how we, PwC Strategy& (Germany) GmbH (hereinafter: "PwC Strategy&"), process your personal data in connection with your use of our websites, applications ("Apps") and online services. However, if you have questions of understanding or other queries about data protection at PwC, you are welcome to contact our data protection officer DE_Datenschutz@pwc.com or using the other contact details provided below.

Controller

The controller within the meaning of Art 4 No 7 Var 1 EU General Data Protection Regulation (GDPR) responsible for the processing of your personal data is:

PwC Strategy& (Germany) GmbH
Bernhard-Wicki-Straße 8
80636 München
Email: webkontakt_anfragen@de.pwc.com
Switchboard: +49-89-545 250
Fax: +49-89-545 25 500

Registered office of the company:
Goltsteinstraße 14
40211 Düsseldorf

Data Protection Officer

PwC Strategy& has designated a data protection officer pursuant to Art 37 GDPR. You can contact PwC's data protection officer, Dr Tobias Gräber, via the following channels:

Email: DE_Datenschutz@pwc.com
Telephone: +49 69 9585-0

Postal address:
PwC Strategy& (Germany) GmbH
Dr. Tobias Gräber, Datenschutzbeauftragter
Goltsteinstraße 14
40211 Düsseldorf

Rights of data subjects/your rights under data protection law

You have the following rights under applicable data protection law with regard to personal data concerning you.

Right of access: You may obtain information from us at any time about whether and which personal data we store about you. The provision of information is free of charge for you.

The right of access does not exist or is subject to limitations if and to the extent that confidential information, such as information that is subject to professional secrecy, is disclosed.

Right to rectification: If your personal data stored with us is inaccurate or incomplete, you have the right to obtain the rectification of this data from us at any time.

Right to erasure: You have the right to obtain from us the erasure of your personal data if and to the extent that the data are no longer needed for the purposes for which they were collected or, if processing is based on your consent, you have withdrawn your consent. In this case, we must stop processing your personal data and remove it from our IT systems and databases.

You do not have a right to erasure if

  • the data may not be erased due to a legal obligation or must be processed due to a legal obligation;
  • the processing of data is necessary for the establishment, exercise or defence of legal claims.

Right to restriction of processing: You have the right to obtain from us the limitation of the processing of your personal data.

Right to data portability: You have the right to receive from us the data you provide in a structured, commonly used and machine-readable format and the right to have this data transferred to another controller. This right exists only if

  • you have made this data available to us on basis of consent or an agreement entered into with you;
  • the processing is carried out by automated means.

Right to object to processing

If the processing of your data is based on Art 6 Para 1 lit f) GDPR, you may object to the processing at any time.

You may assert all of the above-described data subject rights against PwC Strategy& by addressing your specific request to the following contact details:

By E-Mail: DE_Datenschutz@pwc.com

By Post:
PwC Strategy& (Germany) GmbH
Dr. Tobias Gräber, Datenschutzbeauftragter
Goltsteinstraße 14
40211 Düsseldorf

Right to lodge a complaint with a data protection supervisory authority

In accordance with Art 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data infringes data protection law.

Description of data processing on the website/app and legal basis for the processing

Categories of recipients of the data
To fulfil the processing purposes listed below, data is occasionally transferred to third parties. In particular, this may include the transfer of personal data to European and non-European countries and the storage of data outside the EU or the European Economic Area.

We pass on your data to service providers who are bound by our instructions, both within the PwC Network and to other third parties, such as IT service providers, who support us in our activities, e.g. in the administration and maintenance of the websites and related systems and/or for other internal or administrative purposes. PwC Strategy& is a member firm of the global PwC Network, consisting of individual legally separate and independent PwC companies. Within the scope of our activities, we use other German or foreign member firms of the PwC Network as instruction-bound, network-internal IT service providers who assist in the operation, maintenance and servicing of the IT systems and applications used by PwC Network companies. In addition to PricewaterhouseCoopers GmbH Wirtschaftsprüfungsgesellschaft based in Germany, this includes in particular PwC IT Services Ltd. based in the United Kingdom (UK). If we transfer data to service providers who are bound by instructions, we do not require a separate legal basis for this.

Additionally, in individual cases we may pass on your data both within the PwC Network and to other third parties who use your data on their own responsibility as controllers. For example, in individual cases we may transfer personal data to other companies in the PwC Network in order to support and improve the effectiveness of our business procedures (including coordinated marketing activities). Where such a transfer is made to a PwC member firm outside the European Economic Area, an adequate level of protection is ensured for the international transfer. Inter alia, in compliance with the EU Commission Standard Contractual Clauses pursuant to Art 46 Para 2 lit c) GDPR, the member firms of the PwC Network have concluded an internal data protection agreement applying to the transfer of personal data from EU/EEA countries to other member firms. If you have any questions regarding this internal data protection agreement and other security mechanisms, please feel free to contact our data protection officer, e.g. via DE_Datenschutz@pwc.com. In addition, we will also pass on your data to other third parties in individual cases, such as authorities, courts or other bodies, if we are obliged by law or ordered by an authority or court of an EU Member State to release personal data to these bodies. These bodies also use the data on their own responsibility as controllers.

Insofar as we are legally obliged to disclose the data, the legal basis for the data transfer is Art 6 Para 1 lit c) GDPR. If, on the other hand, the disclosure is intended to fulfil a contractual or pre-contractual measure with you as a natural person, Art 6 Para 1 lit b) GDPR is the legal basis. Otherwise, the disclosure is based on our legitimate interests and the legal basis is Art 6 Para 1 lit f) GDPR. We and the other member firms in the PwC Network have an interest in conducting our work procedures efficiently and in distributing business processes within the PwC Network for this purpose.

Processing of personal data when visiting the website
When you visit our website, we collect the data that is technically necessary to display the website to you. This involves the following personal data, which are automatically transmitted to our server by your browser:

  • IP address
  • Date and time of your request/access to the website (the app)
  • Time zone difference to Greenwich Mean Time (GMT)
  • Content of the request (information about which specific webpage you have visited)HTTP status code
  • Transferred data volume
  • Website requesting the access
  • Browser (information about the browser you use)
  • Operating system and its interface (operating system of the computer you used to access the website or app)
  • Language and version of the browser software

The processing of this personal data is based on Art 6 Para 1 lit f) GDPR. The website cannot be accessed and offered to users without using such data; there is a legitimate interest in making the access and use of the website technically possible.

The log files are stored for seven days and then deleted.

This website is hosted by a service provider [Hercules Merger Parent Limited, 1 Embankment Place, London, England, WC2N6RQ - registered number 8747197], and the data collected on our website is therefore stored on the servers of that service provider. These servers are located in Germany and in other EU countries.

Data is transferred abroad, but only to countries of the European Union or the European Economic Area.

Contact form and contact by e-mail

A contact form is available on our website, which you can use to contact us with questions about PwC, our website and other enquiries. You can also contact us by e-mail.

When you contact us via the contact form or by e-mail, the data you provide (in particular your e-mail address, your name and surname, the text of your enquiry and any other details you may have provided in the contact form or by e-mail) will be stored by us in order to process your enquiry and answer your questions.

The data processing is based on Art 6 Para 1 lit f) GDPR. We have an interest in contacting you via the website upon your request. Insofar as your enquiry is aimed at the fulfilment of a contractual or pre-contractual measure with you as a natural person, Art 6 Para 1 lit b) GDPR serves as legal basis for the processing of data.

We will delete the data generated in the course of your enquiry as soon as it is no longer necessary for processing that enquiry. To the extent that the data is subject to statutory retention requirements, it will be stored for the duration of the prescribed statutory retention period.

The use of the contact form is voluntary for you and is not a prerequisite for using the website.

Processing activities for marketing purposes and partially joint controllers
PwC Strategy& determines the means and purposes of some of the data processing for marketing activities described in more detail below, either on its own or together with other member firms of the German-speaking PwC Network mentioned here (hereinafter jointly referred to as "PwC DE"). PwC Strategy& and these other listed PwC DE companies of the PwC Network therefore process your data as joint controllers in accordance with Art 4 No 7 Var 2, 26 GDPR.

Name Address Contact address
PricewaterhouseCoopers GmbH Wirtschaftsprüfungsgesellschaft Friedrich-Ebert-Anlage 35-37, 60327 Frankfurt am Main DE_Kontakt@pwc.com
PricewaterhouseCoopers Legal AG Rechtsanwaltsgesellschaft Friedrich-Ebert-Anlage 35-37, 60327 Frankfurt am Main DE_Kontakt@pwc.com
Fachverlag Moderne Wirtschaft GmbH Friedrich-Ebert-Anlage 35-37, 60327 Frankfurt am Main de_fachverlag_publikationen@pwc.com
INTES Akademie für Familienunternehmen GmbH Kron­prin­zen­stra­ße 31, 53173 Bonn-Bad Go­des­berg info@in­tes-aka­de­mie.de
PwC Strategy& (Germany) GmbH Bernhard-Wicki-Straße 8, 80636 München info@strategyand.de.pwc.com
PwC Strategy& (Austria) GmbH Donau-City-Straße 7, A - 1220 Wien info@strategyand.de.pwc.com
PwC Cyber Security Services GmbH Kapelle-Ufer 4, 10117 Berlin DE_Kontakt@pwc.com
PwC Certification Services GmbH Kapelle-Ufer 4, 10117 Berlin DE_Kontakt@pwc.com
PwC Solutions GmbH Friedrich-Ebert-Anlage 35-37, 60327 Frankfurt am Main DE_Kontakt@pwc.com

Individualized electronic approach by PwC DE
PwC DE companies process your personal data and will contact you by e-mail for marketing purposes if you have provided consent to direct marketing activities. To this end, we process the data you have provided in connection with your declaration of consent (in particular your first and last name, your e-mail address, if applicable the name and address of your company and, if applicable, other information you have provided with your declaration of consent).

This direct marketing by PwC DE companies includes PwC DE information on the latest consultancy advice and service information, news from your industry, notifications about upcoming events, information on PwC studies (including those of other PwC Network companies) and other marketing information.

On basis of your consent, PwC DE can tailor and individualise marketing communication to your interests. PwC DE does this by analysing your interests that you have expressly communicated (e.g. via a preference center on a PwC DE website) and your usage behaviour (e.g. retrieved content access, clicks and reading time) with regards to newsletters and similar communications and via linked PwC DE websites using cookies, web beacons and similar technologies, and may store this information in a personal profile.

Based on your consent, PwC DE may also add your personal contact details (e.g. name, title, company and role/position) to this profile, which you have entered yourself on a PwC DE website and/or which are already stored in the customer relationship management systems operated by PwC DE. Based on your consent, PwC DE may also add public information about the company you work for to this profile.

The processing is carried out on basis of your consent, which is a legal permission according to Art 6 Para 1 lit a) GDPR. You can withdraw your consent at any time with effect for the future without additional costs, e.g. by e-mail to info@strategyand.de.pwc.com.

Your data will be stored for this purpose as long as the data is required for direct advertising and you have not revoked your consent. Insofar as there is a legal obligation to retain data, the data will be stored for the duration of the legally required retention period.

Newsletter by PwC Strategy& and/or PwC DE
If you order a newsletter via our website, depending on the scope of your consent, we and/or companies of PwC DE will store and further process your e-mail address for the purpose of sending you the newsletter which you have subscribed to.

This data processing is carried out on basis of your consent, which is a legal permission according to Art 6 Para 1 lit a) GDPR. Your data will be stored for this purpose as long as the data is necessary for sending newsletters to you and as long as you have not withdrawn your consent. Insofar as statutory storage obligations exist, the data will be stored for the duration of the legally required retention period.

You can withdraw this consent at any time without additional costs with effect for the future. We will provide a link for the withdrawal in every newsletter message.

Postal communication and marketing to existing customers
The companies of PwC DE will also use your data (in particular name and address) to send you postal marketing information on further offers or events.

We use your contact data (in particular your first and last name, e-mail address, name and address of your company, if applicable, as well as any other information you may have provided) received in connection with the sale of a service for the purpose of direct advertising for similar services via electronic mail, unless you have objected to such use. You can object to this use at any time without incurring any costs other than the transmission costs according to the basic tariffs.

This processing is carried out on basis of our legitimate interests within the meaning of Art 6 Para 1 lit f) GDPR. We have a legitimate economic interest in informing interested parties, customers and clients about further own offers and events in order to establish and maintain a long-term customer relationship.

Your data will be stored for this purpose for as long as the data is necessary for postal marketing communication as well as existing customer marketing and as long as you have not effectively objected to the data processing. Insofar as statutory retention obligations exist, the data will be stored for the duration of the legally required retention period.

Use of cookies

We use so-called cookies on our website. Cookies are small text files with configuration information that are sent to your browser by our web servers when you visit our website and are stored on your computer for when you re-visit our website at a later time.

Cookies allow our website to access or store information from your browser. This can be information about you, your settings or your device. They are mainly used to ensure the website’s expected functionality. As a rule, cookies do not contain any information that could identify you directly. They do, however, make it possible to offer you a more personalised web experience.

Session cookies (transient cookies)
We use so-called session cookies (also referred to as temporary or transient cookies) on our website. These session cookies are only stored for the duration of your visit to our website. The session cookies used by us serve solely to identify you as long as you are logged on to our website and are erased at the end of each session. They are not used for any other purposes.

These cookies are required for the functionality of our website and cannot be disabled on our systems. As a rule, these cookies are only set as a response to an action taken by you constituting a service request, such as setting your privacy preferences, logging in or filling out forms. You can set your browser to block cookies or notify you about of them. However, this may impair the functionality of the website in some areas.

The use of these session cookies is permitted on basis of Art 6 Para 1 lit f) GDPR. If we did not use these cookies, you would not be able to technically access or use the website’s content and services.

Permanent cookies (persistent cookies)
In addition, we use other cookies on our website that allow us to recognise your browser the next time you visit our website so that we can offer you an optimised user experience.

These cookies are automatically deleted after a specific period, which may vary depending on the cookie. Persistent cookies remain stored on your terminal device until they expire or you delete them.

Performance cookies
These cookies allow us to count visits and trace sources of access to measure and improve the performance of our website. They help us determine which pages are most popular, which are least used and how visitors navigate the website. All information collected by these cookies is aggregated and therefore anonymous. If you do not accept these cookies, we have no way of knowing when you visited our website.

Our use of performance cookies is based on legitimate interest within the meaning of Art 6 Para 1 lit f) GDPR. We have a legitimate interest in analysing the use of our website as a whole by means of aggregated and anonymous data in order to improve our website’s content and services.

The categories of cookies we use and information on the exact expiration period of the individual cookies can be found in our cookie information.

Disabling the cookie settings
Most browsers are pre-set to accept cookies automatically. You can object to the creation of cookies by disabling cookies in your browser’s system settings. Please note, however, that some of the cookies are strictly necessary for the functionality of our website, otherwise the page cannot be requested and displayed. Disabling cookies may limit your ability to use the website (without restriction).

Cookies, which are not strictly necessary for the functionality of our website, are only used with your prior express consent.

You can also control the installation of cookies yourself at any time by changing your browser settings and/or deleting all cookies.

Link to social media

Our website currently contains links to the following social media providers: Facebook, Twitter, LinkedIn and Google+ via the relevant social media buttons. In order to avoid unwanted transfer of your usage data (e.g. address of the currently visited page) to these services, you will only be able to access them by clicking on the link (social media button "Shariff"). The aforementioned social networks may themselves collect usage and possibly user data. We have no control over the data collected and data processing activities, nor are we aware of how much data is collected, the purposes of processing or the storage periods. Nor do we have any information on the erasure of the data collected by the plugin provider.

Therefore, the information we provide is to the best of our knowledge at the present time:
Your browser may not establish a direct connection to the servers of the aforementioned services until you click on the links. This means that the information that you have visited our website is indirectly (referrer) forwarded to these services. If you are already logged in to the service with your personal user account during your visit to our website, you can usually click on the social media buttons to “share” the content or leave a comment, etc. If you do not wish any such data transfer, we advise against clicking on the social media buttons.

The purpose and scope of data collection by social media services, as well as the further processing and use of your data there and your rights and options for setting your privacy preferences can be found in the privacy policies for these services.

YouTube integration

We have included YouTube videos in our online services, which are stored at https://www.YouTube.com and can be played directly from our website. These are all included in "priavacy-enhanced mode", which means that no data about you as a user will be transferred to YouTube, unless you play the videos. Only when you play the videos, the data mentioned in Paragraph 2 will be communicated. We have no influence on this data transmission.

By visiting the website, YouTube receives the information that you have accessed the corresponding subpage of our website. In addition, the following data are transmitted, which are listed in the section "Description of data processing on the website/app and legal basis for the processing". This occurs regardless of whether YouTube provides a user account that you are logged in to, or whether no user account exists. When you’re logged in to Google, your information will be directly associated with your account. If you do not want your profile to be associated with YouTube, you must log out before activating the button. YouTube stores your data as a user profile and uses them for the purpose of advertising, market research and/or the design of its website to meet your needs. Such evaluation is carried out in particular (even for users who are not logged in) in order to provide demand-oriented advertising and to inform other users of the social network about your activities on our website. You have the right to object to the creation of these user profiles, and you must contact YouTube to exercise this right.

Further information on the purpose and scope of data collection and processing by YouTube, can be found in the Privacy Policy. There you will also find further information about your rights and settings to protect your privacy: https://www.google.de/intl/de/policies/privacy. Google also processes your personal data in the USA and has submitted to the EU-US Privacy Shield, https://www.privacyshield.gov/EU-US-Framework.

Last update: 03.04.2019