Privacy notice ShareFile/fileBOX

Information pursuant to Art. 13, 14 of the GDPR about the use of your personal data


Responsible entity and contact information

The responsible entity within the meaning of data protection law is

Nexia GmbH
Wirtschaftsprüfungsgesellschaft | Steuerberatungsgesellschaft
Georg-Glock-Str. 4, 40474 Düsseldorf, Germany

You will find further information about our company, details of the persons authorized to represent us and also further contact options in our Legal Notice on our website.
https://www.nexia.de/legal-notice

Contact details of the data protection officer:
datenschutz@nexia.de
 

Purpose and legal bases of the processing

The purpose of the processing is the secure exchange of files for companies. We provide our customers with files in a virtual data room to meet legal requirements and to enable customer-oriented and secure processing. We use ShareFile/fileBOX from Schuster & Walther IT-Business GmbH (Schuster & Walther). The location of the servers used for this purpose is operated by Schuster & Walther exclusively in Germany. The entire infrastructure and storage space is located in the DATEV data center.

Insofar as personal data is processed, it is collected, stored and forwarded in accordance with Art. 6 (1) b, Art. 6 (1) f GDPR.

We process your personal data based on your consent, a contractual relationship or to fulfill a legal obligation. The legal basis for this is Art. 6 (1) a, b, c GDPR.
 

Which data is processed?

Various types of data are processed when files are exchanged using virtual data rooms. The scope and content of the data depends on which information is relevant for the file content and which agreements exist with the clients.

Typical files for file exchange are, for example, invoices with special information, contracts or M&A documents.
 

Scope of processing

ShareFile/fileBOX is a cloud-based exchange and collaboration platform, the central components of which are document exchange and platform and device-independent access to files. ShareFile/fileBOX offers you the option of making extensive documents available to one or more people; in addition, older processing statuses of a file can optionally be displayed by activating file versioning.

Automated decision-making within the meaning of Art. 22 GDPR is not used.
 

Data transfer

Your personal data will not be transferred to third parties. Exceptions to this only apply if this is necessary for the processing of contractual relationships with you. This includes in particular the transfer to service providers commissioned by us (so-called processors) or other third parties whose activities are necessary for the execution of the contract (e.g. shipping companies or banks). The data passed on may only be used by the third parties for the stated purposes.
 

Data processing outside the European Union

Data processing outside the European Union (EU) does not take place, as we have limited our storage location to data centers in the European Union. The data is encrypted during transport via the Internet and thus protected against unauthorized access by third parties.
 

Your rights as a data subject

You have the right to obtain information about the personal data concerning you. You can contact us for information at any time.

In the case of a request for information that is not made in writing, we ask for your understanding that we may require proof from you that you are the person you claim to be.

Furthermore, you have a right to rectification or deletion or to restriction of processing, insofar as you are entitled to this by law.

Finally, you have a right to object to processing within the scope of legal requirements.

A right to data portability also exists within the framework of data protection law.
 

Deletion of data

We generally delete personal data when there is no need for further storage. A requirement may exist in particular if the data is still needed to fulfill contractual services, to check and grant or defend against warranty and guarantee claims. In the case of statutory retention obligations, deletion will only be considered after expiry of the respective retention obligation if we are obliged to store the data for a longer period of time due to tax or commercial law retention obligations.

Deletion will not take place if you have consented to further storage.
 

Right of complaint to a supervisory authority

You have the right to complain about the processing of personal data by us to a data protection supervisory authority.
 

Modification of this privacy notice

We revise this data privacy notice in the event of changes to data processing or other occasions that make this necessary. You will always find the current version on this page.
 

Further information on SchuWa, Citrix and DATEV data privacy

https://www.citrix.com/about/trust-center/privacy-compliance/
https://www.schuwa.de/datenschutz
https://www.datev.de/web/de/m/ueber-datev/datenschutz/

 

Date Privacy policy: 02/2024