Privacy Policy
As of: 28 June 2026
Preamble
With the following privacy policy, we would like to inform you about the types of your personal data (hereinafter also referred to as "data") that we process, for what purposes, and to what extent. This privacy policy applies to all processing of personal data carried out by us, both on our website and within external online presences, such as our social media profiles (hereinafter collectively referred to as the "online offering").
The terms used are not gender-specific.
Table of Contents
- Preamble
- Controller
- Contact for the Data Protection Officer
- Overview of Processing Operations
- Relevant Legal Bases
- Security Measures
- Transmission of Personal Data
- International Data Transfers
- General Information on Data Storage and Erasure
- Rights of Data Subjects
- Provision of the Online Offering and Web Hosting
- Web Analytics, Monitoring, and Optimization
- Contact and Inquiry Management
- Newsletter and Electronic Notifications
- Promotional Communication via Email, Post, Fax, or Telephone
- Application Procedure
- Amendment and Updating
- Definitions of Terms
Controller
Fairfield & Archer GmbH
Neuer Wall 48
20354 Hamburg
Germany
Authorized representative(s): Prof. Dr. Frank Passing
Email address: datenschutz@fairfield-archer.com
Legal notice (Impressum): https://fairfield-archer.com/legal
Contact for the Data Protection Officer
datenschutz@fairfield-archer.com
Overview of Processing Operations
Types of data processed
- Master data
- Contact data
- Content data
- Usage data
- Meta, communication, and procedural data
- Applicant data
- Log data
Categories of data subjects
- Communication partners
- Users
- Applicants
- Business and contractual partners
Relevant Legal Bases
Relevant legal bases under the GDPR: Below you will find an overview of the legal bases of the GDPR on which we process personal data. Please note that, in addition to the provisions of the GDPR, national data protection requirements may apply in your or our country of residence or domicile. Should more specific legal bases be relevant in individual cases, we will inform you of these in the privacy policy.
- Consent (Article 6(1)(a) GDPR) – The data subject has given consent to the processing of their personal data for one or more specific purposes.
- Performance of a contract and pre-contractual inquiries (Article 6(1)(b) GDPR) – Processing is necessary for the performance of a contract to which the data subject is a party, or in order to take steps at the request of the data subject prior to entering into a contract.
- Legitimate interests (Article 6(1)(f) GDPR) – Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, provided that the interests, fundamental rights, and freedoms of the data subject that require the protection of personal data do not override such interests.
- Application procedure as a pre-contractual or contractual relationship (Article 6(1)(b) GDPR) – Insofar as special categories of personal data within the meaning of Article 9(1) GDPR (e.g., health data, such as severe-disability status or ethnic origin) are requested from applicants in the course of the application procedure, their processing is carried out pursuant to Article 9(2)(b) GDPR, or, for the purposes of preventive healthcare or occupational medicine, pursuant to Article 9(2)(h) GDPR. Where special categories of data are communicated on the basis of voluntary consent, their processing is carried out on the basis of Article 9(2)(a) GDPR.
National data protection regulations in Germany
In addition to the data protection regulations of the GDPR, national data protection regulations apply in Germany. These include, in particular, the Act on Protection against the Misuse of Personal Data in Data Processing (Federal Data Protection Act – BDSG). The BDSG contains, in particular, special provisions on the right of access, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, and transmission as well as automated decision-making in individual cases, including profiling. Furthermore, the data protection laws of the individual federal states (Länder) may apply.
Security Measures
In accordance with the legal requirements, and taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we take appropriate technical and organizational measures to ensure a level of protection appropriate to the risk.
- Safeguarding the confidentiality, integrity, and availability of data by controlling physical and electronic access to the data, as well as access to, input, disclosure, and securing of the availability of the data, and their separation.
- Establishing procedures that ensure the exercise of data subjects' rights, the erasure of data, and responses to threats to the data.
- Taking the protection of personal data into account as early as the development or selection of hardware, software, and procedures, in accordance with the principle of data protection by design and by default.
Securing online connections using TLS/SSL encryption technology (HTTPS)
To protect the data of users transmitted via our online services from unauthorized access, we rely on TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the internet. These technologies encrypt the information transmitted between the website or app and the user's browser (or between two servers), thereby protecting the data from unauthorized access.
TLS, as the further developed and more secure version of SSL, ensures that all data transmissions meet the highest security standards. When a website is secured by an SSL/TLS certificate, this is indicated by the display of HTTPS in the URL. This serves as an indicator to users that their data is being transmitted securely and in encrypted form.
Transmission of Personal Data
In the course of our processing of personal data, it may occur that the data is transmitted to, or disclosed to, other bodies, companies, legally independent organizational units, or persons. Recipients of this data may include, for example, service providers commissioned with IT tasks, or providers of services and content embedded in a website. In such cases, we comply with the legal requirements and, in particular, conclude appropriate contracts or agreements with the recipients of your data that serve to protect your data.
Data transmission within the organization
We may transmit personal data to, or grant access to such data to, other departments or units within our organization. Where such data sharing is carried out for administrative purposes, it is based on our legitimate business and operational interests, or it is carried out where it is necessary for the fulfillment of our contractual obligations, or where the consent of the data subjects or a legal authorization exists.
International Data Transfers
Insofar as we process data in a third country (i.e., outside the European Union (EU) or the European Economic Area (EEA)), or insofar as the processing takes place in the context of the use of third-party services or the disclosure or transmission of data to other persons, bodies, or companies, this is carried out solely in accordance with the legal requirements. Where the level of data protection in the third country has been recognized by means of an adequacy decision (Article 45 GDPR), this serves as the basis for the data transfer. Otherwise, data transfers only take place where the level of data protection is otherwise ensured, in particular through standard contractual clauses (Article 46(2)(c) GDPR), express consent, or in the case of a contractually or legally required transfer (Article 49(1) GDPR). Where applicable, we will inform you of the bases for the third-country transfer for the individual third-country providers, with adequacy decisions taking precedence as the basis. Information on third-country transfers and applicable adequacy decisions can be found in the information provided by the EU Commission: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en.
General Information on Data Storage and Erasure
We erase personal data that we process in accordance with the statutory provisions as soon as the underlying consents are withdrawn or there are no further legal bases for the processing. This applies to cases in which the original purpose of the processing ceases to apply or the data is no longer required. Exceptions to this rule exist where statutory obligations or particular interests require longer retention or archiving of the data. In particular, data that must be retained for commercial or tax-law reasons, or whose storage is necessary for legal action or to protect the rights of other natural or legal persons, must be archived accordingly. Where there are multiple indications of storage duration or erasure periods for a single piece of data, the longest period is always decisive.
Further notes on processing operations, procedures, and services
The following general periods apply to retention and archiving under German law:
- 10 years – Retention period for books and records, annual financial statements, inventories, management reports, opening balance sheets, and the working instructions and other organizational documents required to understand them (Section 147(1) no. 1 in conjunction with (3) AO [German Fiscal Code], Section 14b(1) UStG [German VAT Act], Section 257(1) no. 1 in conjunction with (4) HGB [German Commercial Code]).
- 8 years – Accounting vouchers, such as invoices and cost receipts (Section 147(1) no. 4 and 4a in conjunction with (3) sentence 1 AO, as well as Section 257(1) no. 4 in conjunction with (4) HGB).
- 6 years – Other business documents: received commercial or business letters, reproductions of dispatched commercial or business letters, and other documents insofar as they are of relevance for taxation (Section 147(1) no. 2, 3, 5 in conjunction with (3) AO, Section 257(1) no. 2 and 3 in conjunction with (4) HGB).
- 3 years – Data required to take into account potential warranty and damage claims or similar contractual claims and rights (Sections 195, 199 BGB [German Civil Code]).
Rights of Data Subjects
As a data subject, you have various rights under the GDPR, which arise in particular from Articles 15 to 21 GDPR:
- Right to object: You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you which is carried out on the basis of Article 6(1)(e) or (f) GDPR; this also applies to profiling based on these provisions. Where personal data concerning you is processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for the purposes of such marketing; this also applies to profiling insofar as it is related to such direct marketing.
- Right to withdraw consent: You have the right to withdraw consent given at any time.
- Right of access: You have the right to request confirmation as to whether data concerning you is being processed, and to obtain information about such data, as well as further information and a copy of the data in accordance with the legal requirements.
- Right to rectification: You have the right, in accordance with the legal requirements, to request the completion of data concerning you or the rectification of inaccurate data concerning you.
- Right to erasure and restriction of processing: You have the right, in accordance with the legal requirements, to request that data concerning you be erased without delay, or, alternatively, in accordance with the legal requirements, to request a restriction of the processing of the data.
- Right to data portability: You have the right, in accordance with the legal requirements, to receive data concerning you that you have provided to us in a structured, commonly used, and machine-readable format and/or to request its transmission to another controller.
- Complaint to a supervisory authority: You also have the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of personal data concerning you infringes the GDPR.
Provision of the Online Offering and Web Hosting
We process users' data in order to be able to provide them with our online services.
- Types of data processed: Usage data (e.g., page views and time spent, click paths, intensity and frequency of use); meta, communication, and procedural data (e.g., IP addresses).
- Data subjects: Users (e.g., website visitors, users of online services).
- Purposes of processing: Provision of our online offering and user-friendliness.
- Retention and erasure: Erasure in accordance with the information provided in the section "General Information on Data Storage and Erasure".
- Legal bases: Legitimate interests (Article 6(1)(f) GDPR).
Further notes on processing operations, procedures, and services
- Provision of the online offering on rented storage space: For the provision of our online offering, we use storage space, computing capacity, and software that we obtain from a corresponding server provider (web host).
- Collection of access data and log files: Access to our online offering is logged in the form of so-called "server log files". Server log files may include the address and name of the retrieved web pages and files, the date and time of retrieval, the amount of data transferred, notification of successful retrieval, browser type and version, the user's operating system, the referrer URL (the previously visited page), and, as a rule, IP addresses and the requesting provider.
- Functional cookie for language selection: We store the language you have selected (German/English) in a functional first-party cookie ("FAIRFIELD_LOCALE") so that the website is displayed in your chosen language. This cookie is set only when you actively choose a language and is technically necessary to honor that choice; it is therefore used without consent in accordance with Section 25(2) no. 2 TDDDG. No analysis of user behavior takes place.
- Netlify (hosting & content delivery): Services in the field of providing information-technology infrastructure and related services (e.g., hosting and content delivery).
- Service provider: Netlify, Inc., 2325 3rd Street, Suite 215, San Francisco, California 94107, USA
- Legal bases: Legitimate interests (Article 6(1)(f) GDPR)
- Website: https://www.netlify.com — Privacy policy: https://www.netlify.com/privacy/
- Data processing agreement: provided by the service provider
- Basis for third-country transfers: Data Privacy Framework (DPF). Netlify, Inc. is certified under the EU-U.S. Data Privacy Framework; in addition, standard contractual clauses (Article 46(2)(c) GDPR) are in place as a further safeguard.
Web Analytics, Monitoring, and Optimization
Web analytics (also referred to as "reach measurement") serves to evaluate the visitor traffic to our online offering. With the help of reach analysis, we can, for example, recognize when our online offering or its content are used most frequently, or which content invites reuse, and thereby identify which areas require optimization. For this purpose, we use a privacy-friendly service that operates without cookies and does not store any personal data that would allow individual users to be identified.
- Types of data processed: Usage data (e.g., page views and time spent, click paths, intensity and frequency of use); meta, communication, and procedural data (e.g., IP addresses).
- Data subjects: Users (e.g., website visitors, users of online services).
- Purposes of processing: Reach measurement (e.g., access statistics); understanding of the language versions (German/English) preferred by our visitors.
- Retention and erasure: Erasure in accordance with the information provided in the section "General Information on Data Storage and Erasure".
- Legal bases: Legitimate interests (Article 6(1)(f) GDPR).
Further notes on processing operations, procedures, and services
- Plausible (cookieless web analytics): We use Plausible to measure the usage of our online offering. Plausible does not use cookies, local storage, or comparable techniques for storing information on users' terminal devices, and it does not create persistent identifiers or cross-site or cross-device user profiles. IP addresses are processed only transiently in order to derive an approximate, non-personal geographic location and a daily-rotating, anonymous visitor count, and they are not stored. The analytics script and the measurement data are served and collected via our own domain (reverse proxy); the data is processed on servers located within the European Union.
- Service provider: Plausible Insights OÜ, Västriku tn 2, 50403 Tartu, Estonia
- Legal bases: Legitimate interests (Article 6(1)(f) GDPR)
- Website: https://plausible.io — Data policy: https://plausible.io/data-policy
Contact and Inquiry Management
When you contact us (e.g., by post, contact form, email, telephone, or via social media), as well as in the context of existing user and business relationships, the information of the inquiring persons is processed to the extent necessary to respond to the contact inquiries and any requested measures.
- Types of data processed: Master data (e.g., full name, residential address, contact information, customer number, etc.); contact data (e.g., postal and email addresses or telephone numbers); content data (e.g., text or image messages and contributions); usage data (e.g., page views and time spent, click paths); meta, communication, and procedural data (e.g., IP addresses, time stamps, identification numbers).
- Data subjects: Communication partners; users (e.g., website visitors, users of online services); business and contractual partners.
- Purposes of processing: Communication; organizational and administrative procedures; feedback (e.g., collecting feedback via an online form); provision of our online offering and user-friendliness.
- Retention and erasure: Erasure in accordance with the information provided in the section "General Information on Data Storage and Erasure".
- Legal bases: Legitimate interests (Article 6(1)(f) GDPR); performance of a contract and pre-contractual inquiries (Article 6(1)(b) GDPR).
Further notes on processing operations, procedures, and services
- Contact form: When you contact us via our contact form, by email, or by other means of communication, we process the personal data transmitted to us in order to respond to and handle the respective matter.
- Microsoft cloud services: Cloud storage, cloud infrastructure services, and cloud-based application software.
- Service provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland
- Website; privacy policy; data processing agreement
- Basis for third-country transfers: Data Privacy Framework (DPF)
- Outlook: Sending and receiving emails, storing contacts in the address book, filter rules for sorting incoming emails, spam and virus protection, cloud storage for attachments and other content.
- Service provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland
- Website; privacy policy
Newsletter and Electronic Notifications
We send newsletters, emails, and other electronic notifications (hereinafter "newsletters") solely with the consent of the recipients or on a legal basis. Insofar as the contents of a newsletter are specified in the context of a registration, these contents are decisive for the users' consent.
To register for our newsletter, it is usually sufficient to provide your email address. However, in order to be able to offer you a personalized service, we may ask you to provide your name for a personal salutation in the newsletter, or for further information if this is necessary for the purpose of the newsletter.
Erasure and restriction of processing
We may store the unsubscribed email addresses for up to three years on the basis of our legitimate interests before erasing them, in order to be able to provide proof of consent that was previously given. The processing of this data is restricted to the purpose of a potential defense against claims. An individual request for erasure is possible at any time, provided that the former existence of consent is confirmed at the same time.
In the case of obligations to permanently observe objections, we reserve the right to store the email address solely for this purpose in a block list (so-called "blocklist").
Contents
Information about us, our services, promotions, and offers.
- Types of data processed: Master data (e.g., full name, residential address, contact information, customer number, etc.); contact data (e.g., postal and email addresses or telephone numbers); meta, communication, and procedural data (e.g., IP addresses, time stamps, identification numbers, persons involved); usage data (e.g., page views and time spent, click paths, intensity and frequency of use, device types and operating systems used).
- Data subjects: Communication partners; users (e.g., website visitors, users of online services).
- Purposes of processing: Direct marketing (e.g., by email or post); provision of contractual services and fulfillment of contractual obligations; reach measurement (e.g., access statistics, recognition of returning visitors); conversion measurement (measuring the effectiveness of marketing measures); creation of user profiles.
- Legal bases: Consent (Article 6(1)(a) GDPR); legitimate interests (Article 6(1)(f) GDPR).
- Right to object (opt-out): You can cancel the receipt of our newsletter at any time, i.e., withdraw your consent. You will find a link to cancel the newsletter at the end of each newsletter, or you can use one of the contact options provided above (preferably by email).
Further notes on processing operations, procedures, and services
- Measurement of open and click rates: The newsletters contain a so-called "web beacon" (a pixel-sized file) that is retrieved when the newsletter is opened. In the process, technical information such as browser data, operating system, IP address, and time of retrieval is recorded. This information serves to technically improve our newsletter and to adapt our content to the interests of the recipients. Legal basis: Consent (Article 6(1)(a) GDPR).
- Condition for the use of free services: Consent to the sending of newsletters may be made a condition for the use of free services (e.g., access to certain content or participation in promotions). If you wish to use the free service without subscribing to the newsletter, please contact us directly.
- Brevo (email dispatch & automation): Email dispatch and automation services for the sending and analysis of our newsletters.
- Service provider: Brevo GmbH (operating under the brand "Brevo"), Köpenicker Str. 126, 10179 Berlin, Germany; registered in the commercial register of the Local Court of Charlottenburg (Berlin) under HRB 133191; a subsidiary of Sendinblue SAS, 17 rue de Salneuve, 75017 Paris, France
- Legal bases: Consent (Article 6(1)(a) GDPR)
- Website: https://www.brevo.com — Privacy policy: https://www.brevo.com/legal/privacypolicy/
- Data processing agreement: part of the Brevo Terms of Service (https://www.brevo.com/legal/termsofuse/)
Promotional Communication via Email, Post, Fax, or Telephone
We process personal data for the purposes of promotional communication, which may take place via various channels, such as email, telephone, post, or fax, in accordance with the legal requirements.
Recipients have the right to withdraw consent given at any time or to object to promotional communication at any time.
Following a withdrawal or objection, we store the data required to demonstrate the previous authorization to make contact or send communications for up to three years after the end of the year of the withdrawal or objection, on the basis of our legitimate interests. The processing of this data is restricted to the purpose of a possible defense against claims. On the basis of the legitimate interest in permanently observing the users' withdrawal or objection, we also store the data required to avoid renewed contact (e.g., depending on the communication channel, the email address, telephone number, name).
- Types of data processed: Master data (e.g., full name, residential address, contact information, customer number, etc.); contact data (e.g., postal and email addresses or telephone numbers); content data (e.g., text or image messages and contributions, as well as the information concerning them, such as details of authorship or time of creation).
- Data subjects: Communication partners.
- Purposes of processing: Direct marketing (e.g., by email or post); marketing; sales promotion.
- Retention and erasure: Erasure in accordance with the information provided in the section "General Information on Data Storage and Erasure".
- Legal bases: Consent (Article 6(1)(a) GDPR); legitimate interests (Article 6(1)(f) GDPR).
Application Procedure
The application procedure requires applicants to provide us with the data necessary for their assessment and selection. The information required follows from the job description or, in the case of online forms, from the information provided there.
In principle, the required information includes information about the person, such as name, address, a means of contact, and evidence of the qualifications necessary for a position. Upon request, we are also happy to inform you which information is required.
Processing of special categories of data
Insofar as special categories of personal data (Article 9(1) GDPR) are requested from applicants or communicated by them in the course of the application procedure, their processing is carried out so that the controller or the data subject can exercise the rights arising from employment law and the law on social security and social protection and fulfill their respective obligations in this regard.
Erasure of data
The data provided by applicants may be further processed by us for the purposes of the employment relationship in the event of a successful application. Otherwise, if the application for a job offer is not successful, the applicants' data will be erased.
Inclusion in an applicant pool
Inclusion in an applicant pool, where offered, is carried out on the basis of consent. Applicants are informed that their consent to inclusion in the talent pool is voluntary.
- Types of data processed: Master data (e.g., full name, residential address, contact information, customer number, etc.); contact data (e.g., postal and email addresses or telephone numbers); content data (e.g., text or image messages and contributions); applicant data (e.g., cover letter, CV, references/certificates).
- Data subjects: Applicants.
- Purposes of processing: Application procedure (establishment and any subsequent performance, as well as possible subsequent termination, of the employment relationship).
- Retention and erasure: Erasure in accordance with the information provided in the section "General Information on Data Storage and Erasure".
- Legal bases: Application procedure as a pre-contractual or contractual relationship (Article 6(1)(b) GDPR).
Amendment and Updating
We ask you to inform yourself regularly about the content of our privacy policy. We adapt the privacy policy as soon as changes to the data processing we carry out make this necessary. We will inform you as soon as the changes require an act of cooperation on your part (e.g., consent) or another individual notification.
Insofar as we provide addresses and contact information of companies and organizations in this privacy policy, please note that the addresses may change over time, and we ask you to check the details before making contact.
Supervisory authority responsible for us:
Hamburg Commissioner for Data Protection and Freedom of Information (Hamburgische Beauftragte für Datenschutz und Informationsfreiheit)
Ludwig-Erhard-Str. 22
20459 Hamburg
Email: mailbox@datenschutz-hamburg.de
Definitions of Terms
- Master data: Master data comprises essential information necessary for the identification and administration of contractual partners, user accounts, profiles, and similar assignments.
- Content data: Content data comprises information generated in the course of the creation, editing, and publication of content of all kinds.
- Contact data: Contact data is essential information that enables communication with persons or organizations.
- Conversion measurement: Conversion measurement (also referred to as "visit-action analysis") is a procedure used to determine the effectiveness of marketing measures.
- Meta, communication, and procedural data: Meta, communication, and procedural data are categories that contain information about the manner in which data is processed, transmitted, and managed.
- Usage data: Usage data refers to information that records how users interact with digital products, services, or platforms.
- Personal data: "Personal data" means any information relating to an identified or identifiable natural person.
- Profiles with user-related information: The processing of "profiles with user-related information" encompasses any kind of automated processing of personal data.
- Log data: Log data is information about events or activities that have been logged in a system or network.
- Reach measurement: Reach measurement (also referred to as web analytics) serves to evaluate the visitor flows of an online offering.
- Controller: A "controller" is the natural or legal person that decides on the purposes and means of the processing of personal data.
- Processing: "Processing" means any operation or set of operations performed on personal data, whether or not by automated means.