Privacy policy

Learn more about the processing of personal data on the websites of paychex.de

The protection of personal data is important to Paychex Deutschland GmbH. The following information gives you an overview of the data we collect and use when you visit our website.

Responsible party

The responsible party within the meaning of the data protection laws, in particular the EU basic data protection regulation
(DSGVO), is:

Paychex Deutschland GmbH
Holstenkamp 1
22525 Hamburg

Paychex Deutschland GmbH is registered in the Commercial Register of the Hamburg District Court under the number HR B 90249. Managing directors are John Gibson, Henrik Møller, and Tim Schütte. Further information can be found in our imprint.

When using our websites, we collect, process, and use personal data as described in the following sections:

  1. Purposes of collection, processing, and storage
  2. General information on the use of cookies and how to disable them
  3. Information on hosting and the employed content management system
  4. Tracking on the Internet pages of paychex.de
  5. Information on the collection, processing and storage of form data
  6. Rights of data subjects
  7. Contact our data protection officer

We reserve the right to modify this privacy policy (status: 06.24.2020) so that it always complies with current legal requirements or to implement changes to our services in the privacy policy, e.g. when introducing new services. When you visit this website again in the future, the respective current privacy policy applies.


Purposes of collection, processing, and storage

We process your personal data only for the purposes stated in this privacy policy. Your personal data will not be transferred to third parties for purposes other than those indicated. We only pass on your personal data to third parties if:

  1. You have given us your express consent to do so
  2. The processing is necessary for the execution of a contract with you
  3. The processing is necessary for the fulfilment of a legal obligation
  4. The processing is necessary to protect legitimate interests and there is no reason to assume that you have an overriding interest worthy of protection in not disclosing your data 


Form data

On our web pages you will find forms in which personal data is collected. Interested parties can use these forms to request offers*

  1. Register for events
  2. Subscribe to the newsletter
  3. Access further information (e.g. white papers, lecture recordings)
  4. Comment on blog posts


These data are processed and stored in different ways depending on the intended purpose. We provide detailed information below about the respective processing and storage.

Applications

We encourage applications to be submitted electronically. Please note, however, that applications sent to us by e-mail are not protected against access by third parties.

In all job advertisements that we publish on our website, you will find a link to a page on our application portal. Using this page, you can send your application to us securely.


Tracking information

In order to better tailor our content, including promotional offers, to the interests of our visitors, we use various tracking services, which are described in detail below.

General information on the use of cookies and how to disable them

Our content management system as well as some of the listed services for the purpose of recording your interactions with our websites use cookies - these are small text files that are stored on your computer when you visit our website. We use two types of cookies on our websites: session cookies and persistent cookies. Session cookies are always deleted when the browser is closed.

Persistent cookies remain stored in your browser and can be used again during your next visit. Cookies that are set by our websites are deleted at the latest two years after your last visit to one of our websites, unless you delete them first.

You can effectively prevent all records of your sessions on our websites if you deactivate the setting of cookies via the settings of your Internet browser, or authorize the setting of cookies only for specific purposes. These settings can be made very selectively, so that the functionality of the visited website can be maintained, while unwanted further tracking is prevented.

Your browser's documentation provides instructions for how to do this. This documentation is easily found by means of a search-engine search with the keywords "block cookies [your Internet browser]" (replace [your Internet browser] with the name of your browser, e.g. Firefox, Chrome, Internet Explorer, Safari, etc.).

Further information on the services used on our website and the options for deactivating cookies can be found in the relevant section.

Information on hosting and the employed content management system

In order to protect the security of your data during transmission, we use state-of-the-art encryption methods via HTTPS.

The storage of IP addresses in the logs of our content management system and in the logs of our hosting provider (Mittwald) has been switched off or is done anonymously.

Information about tracking on the Internet pages of paychex.de

Google Analytics

This website uses Google Analytics, a web analysis service of Google Inc (subsequently: Google). Google Analytics uses so-called "cookies," i.e. text files which are stored on your computer and which make it possible to analyze how you use the website. The information generated by the cookie about your use of this website is usually transferred to a Google server in the USA and stored there. However, due to the activation of IP anonymization on these websites, your IP address will be truncated by Google within member states of the European Union or in other states which are party to the Agreement on the European Economic Area. Only in exceptional cases is the full IP address transferred to a Google server in the USA and truncated there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, to compile reports on website activity, and to provide further services to the website operator in connection with website and Internet use. The IP address transmitted by your browser as part of Google Analytics is not merged with other data from Google.

In connection with Google Analytics, we use Google conversion tracking. This enables us to obtain more precise information about the behavioral patterns of our website visitors that we wish to obtain. For example, we can evaluate how often forms are sent and/or from which external sources and through which target paths visitors are led to our website (advertisements, social media, other internal pages, etc.).

The purposes of the data processing are to evaluate the use of the website and to compile reports on activities on the website. Based on the use of the website and the Internet, further related services may then be provided. The legal basis for the processing is Article 6 Paragraph 1 Clause 1 lit. a GDPR (consent).

You may refuse the use of cookies by selecting the appropriate settings on your browser; however, please note that if you do this you may not be able to use the full functionality of this website. You can also prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) to Google and the processing of this data by Google by downloading and installing the browser plug-in available at the following link: Browser add-on to deactivate Google Analytics.

In addition or as an alternative to the browser add-on, you can prevent tracking by Google Analytics on our pages by clicking this link. An opt-out cookie will then be installed on your device. This will prevent Google Analytics from recording data for this website and for this browser in the future as long as the cookie remains installed in your browser.

Further information on terms of use and data protection can be found at https://www.google.com/analytics/terms/de.html or https://www.google.de/intl/de/policies/

We also use Google Analytics to evaluate data from AdWords and the DoubleClick cookie for statistical purposes. If you do not want this to occur, it can be disabled via the Ads Preferences Manager (https://www.google.com/settings/ads/anonymous?hl=de).

Google Tag Manager

This website uses the Google Tag Manager. The Tag Manager does not collect any personal data. The tool triggers other tags, which in turn may collect data. Google Tag Manager does not access this data. If a deactivation has been made at the domain or cookie level, this remains in effect for all tracking tags that are implemented with Google Tag Manager. You can find Google's data protection information on this tool here: https://marketingplatform.google.com/about/analytics/tag-manager/use-policy/

Google Ads conversion tracking and remarketing

Our website uses Google conversion tracking. If you have reached our website via an advertisement placed by Google, Google Adwords will install a cookie on your computer. The conversion tracking cookie is set when a user clicks on an ad placed by Google. These cookies expire after 30 days and are not used for personal identification. If the user visits certain pages of our website and the cookie has not expired, we and Google will be able to recognize that the user clicked on the ad and was redirected to that page. Every Google AdWords customer receives a different cookie. Cookies can therefore not be tracked via the websites of AdWords customers. The information collected using the conversion cookie is used to generate conversion statistics for AdWords customers who have opted in to conversion tracking. Customers are told the total number of users who clicked on their ad and were redirected to a page with a conversion tracking tag. However, we do not receive any information from Google that could identify you personally as a user.

If you do not wish to participate in tracking, you can refuse the setting of a cookie that is required for this purpose - for example, by changing your browser settings to generally disable the automatic setting of cookies or to set your browser to block cookies from the domain "googleleadservices.com."

Please note that you may not delete the opt-out cookies as long as you do not wish measurement data to be recorded. If you have deleted all your cookies in your browser, you will have to set the respective opt-out cookie again.

This website uses the remarketing function of Google Inc. This function is used to present interest-based ads to website visitors within the Google advertising network. In the browser of the website visitor, a so-called "cookie" is stored on your computer which makes it possible to recognize the visitor when he or she visits websites belonging to the Google advertising network. On these pages, the visitor may be presented with advertisements relating to content that the visitor has previously viewed on websites that use Google's remarketing feature.

According to its own information, Google does not collect any personal data during this process. We ourselves do not collect and process any personal data in the aforementioned measures. If you still do not wish to use Google's remarketing function, you can deactivate it by selecting the appropriate settings at http://www.google.com/settings/ads. Alternatively, you can disable the use of cookies for interest-based advertising via the ad network initiative by following the instructions at http://www.networkadvertising.org/managing/opt_out.asp.

Further information about data processing by Google can be found in the Google privacy policy. There, you can also change your personal data privacy settings in the Privacy Centre.

You can find detailed instructions on how to manage your own data in connection with Google products here.

 

Use of Hotjar

This website uses Hotjar, a web analysis tool of Hotjar Ltd. based in Malta. It records interactions of randomly selected, individual visitors with the website in an anonymous form. In this way, a log of e.g. mouse movements and clicks is created with the aim of showing improvement possibilities for the respective website.

Hotjar uses "cookies," text files placed on your computer to help the website analyze how users use the site. In order to exclude the possibility of direct personal references, IP addresses are only stored and processed anonymously. In addition, information on the operating system, browser, incoming and outgoing references (links), geographical origin, as well as resolution and type of device are evaluated for statistical purposes. This information is not personal and will not be passed on to third parties by us or by Hotjar. The data is stored in the Amazon Virtual Private Cloud on servers in Ireland. Click here for more information about data storage by Hotjar

If you do not wish your activity to be recorded, you can deactivate the recording on all Internet sites that use Hotjar by setting the DoNotTrack header in your browser. To do this, click here:  Disable Hotjar
 

Visable tracking pixel

For analysis and marketing purposes, the website uses products and services that are provided in cooperation with Visable GmbH (www.visable.com). For this purpose, tracking pixels technology is used to collect and process data to create at least pseudonymized, and where possible and meaningful, completely anonymous user profiles. The processing takes place for the purpose of collecting company-relevant information such as the company name. The data collected, which may initially contain personal data, is transmitted to Visable or collected directly by Visable and used there to create the usage profiles. Personal identification of visitors to this website does not take place, and no other personal data is merged with the usage profiles. If IP addresses are identified as personal, they will be deleted immediately.
This analysis tool is used based on your consent. The legal basis for this is Article 6 (1) (a) GDPR. The consent can be revoked at any time with effect for the future.

Visable GmbH's data protection declaration can be found here: https://www.visable.com/de_de/datenschutz-20200409.

 

Use of script libraries (Google Fonts)

In order to display our content correctly and in a graphically appealing manner across all browsers, we use script libraries and font libraries on this website such as Fonts. Google Fonts are transferred to your browser's cache to avoid repeated loading. If the browser does not support Google Fonts or prevents access, content will be displayed in a default font.

The retrieval of script libraries or font libraries automatically triggers a connection to the operator of the library. It is theoretically possible - although it is currently unclear whether and for what purposes - that operators of such libraries collect data.

The privacy policy of the library operator Google can be found here: https://www.google.com/policies/privacy/

Social plug-ins

On our websites and within the signatures or our emails, we use social plug-ins from the providers listed below. You can recognize the plug-ins by the fact that they are indicated with the corresponding logo.

These plug-ins may be used to send information, which could include personal data, to the service provider and may be used by the latter. We prevent the unknowing and unwanted collection and transmission of data to the service provider by means of a 2-click solution. In order to activate a particular social plug-in, it must first be activated by clicking on the corresponding button. The collection of information and its transmission to the service provider is only triggered when the plug-in is activated.

By activating the plug-in, your personal data is transferred to the respective plug-in provider and stored there (in the case of US providers in the USA). We do not ourselves collect any personal data by means of the social plug-ins or through their use. Via the plug-ins, we offer you the possibility to interact with social networks and other users. In this manner, we would like to improve our offer and make it more interesting for you as a user. The processing is based on the legitimate interest of the website operator in accordance with Art. 6 (1) sentence 1 lit. f GDPR.

We have no influence on the data an activated plug-in collects and how this data is used by the provider. At present, it is to be assumed that a direct connection to the provider's services is established and at least the IP address and device-related information is collected and used. It is also possible that the service providers try to store cookies on the computer being used. To find out which specific data is collected and how it is used, please refer to the data protection information of the respective service provider.

The data is transmitted regardless of whether you have an account with the plug-in provider and are logged in with this provider. If you are logged in with the plug-in provider, the data we collect from you will be immediately linked to your existing account with the plug-in provider.

We have integrated the social media buttons of the following companies on our website and within the signatures of our emails:

Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbor, Dublin 2, Ireland
The Facebook social plug-ins are marked with the Facebook logo
Website: https://www.facebook.com
Privacy policy: https://www.facebook.com/policy.php
Opposition option (opt-out): https://www.facebook.com/ds/preferences/?entry_product=ad_settings_screen.

Twitter Inc., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA
The Twitter social plug-ins are marked with the Twitter logo
Data protection declaration: https://twitter.com/de/privacy
Settings: https://twitter.com/personalization

LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland
The LinkedIn social plug-ins are marked with the LinkedIn logo and allow interesting content to be shared directly via our website.
Website: https://www.linkedin.com
Data protection declaration: https://www.linkedin.com/legal/privacy-policy
Opposition option (opt-out): https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.

XING AG, Dammtorstrasse 29-32, 20354 Hamburg, Germany
Website: https://www.xing.de
Data protection declaration: https://privacy.xing.com/de/datenschutzerklaerung

Information on the collection, processing, and storage of form data

If you contact us via the forms on our website, we will use the personal data you provide exclusively for the purpose of your enquiry. Unless indicated otherwise below, your form entries will be stored in the enquiry databases of our content management system for up to 3 months and then automatically deleted.

Our forms can also contain fields that are not absolutely necessary for the enquiry, but often allow for improved processing and minimize the need for further enquiries (in the case of our offer request form, for example, the information "number of employees" for which payroll accounting is required and the comment field "Further information").

In the case of the contact form and the offer forms, we ask for an e-mail address and a telephone number so that we are able to contact you in case of typing mistakes.

Before a qualified offer can be made, a brief discussion on the scope of our services is still necessary.

If you provide us with data that enables us to contact you - e.g. an e-mail address or a telephone number - you agree that we may contact you via this means of communication to process your request. You will receive a confirmation of your request by e-mail. In the case of the contact form and offer forms, we process the necessary information in order to be able to address you in a personalized manner.

The processing of your data takes place on the basis of your consent in accordance with Art. 6 (1) sentence 1 lit. a GDPR as well as according to Art. 6 (1) sentence 1 lit. b GDPR, insofar as they are carried out for the performance of a contract of which you are the contracting party or for the implementation of pre-contractual measures at your request.

In addition, your data will be collected, processed, and stored in accordance with the following guidelines:
 

Offer enquiry

The data provided in the context of an offer enquiry is automatically transferred to our sales database (Salesforce Marketing Cloud) of Salesforce.com for the purpose of in-house processing and deleted after 12 months.

The operating company of Salesforce.com is Salesforce.com Germany GmbH, Erika-Mann-Str. 63, 80636 Munich, Germany.

We use Salesforce to get in touch with our customers and inform interested parties and potential customers about our services. The data at Salesforce.com is stored on servers within the EU Salesforce.com acts as a processor for Paychex and processes data only as instructed by Paychex. Corresponding contractual agreements have been concluded in order to meet the legal requirements.  However, we cannot rule out that data will be transmitted to a third country (e.g. Salesforce.com, Inc. is: Salesforce Tower, 415 Mission Street, 3rd Floor, San Francisco, CA 94105, USA). Appropriate safeguards: Salesforce has submitted to the European Commission's Standard Contractual Clauses for the transfer of personal data to processors in third countries under the Standard Contractual Clauses pursuant to Regulation (EU) 2016/679.

In general, before preparing an offer, we conduct a short discussion to define the needs of the interested party. After an interested party has received an offer, our sales representatives actively enquire about any decision until the interest in the offer is established.

Upon notification by interested parties, all data from requests for quotations and subsequent sales processing will be deleted immediately from the sales database, even before the expiry of the 12-month deletion period.

Notes on the scope of the mandatory disclosures:
In addition to your telephone number, we also ask for your e-mail address in order to be able to contact you in case entered phone numbers are incomplete.

Our sales staff process the enquiries according to representative areas. The postcode is a mandatory field in the offer form in order to allocate the enquiries to the responsible employee.

Contact requests

The data transmitted via the contact form will be automatically transferred to our sales database (Salesforce Marketing Cloud - further information on Salesforce.com above) for in-house processing and deleted after 3 months.

Upon notification of the interested parties, all data from the contact forms and the subsequent processing will of course also be deleted immediately from the database before expiry of the 3-month deletion period.
 

Event registration

In the case of paid events, we ask directly in the registration form for all the information we need for invoicing. After receipt of your registration, we will send you an invoice, which can also serve as confirmation of your registration. A refund for no-shows is unfortunately not possible. However, in this case you are welcome to send a replacement from your company. We also use your transmitted data to send you further organizational information before and after the event if necessary.

With your registration you accept that we may, if necessary, inform you by e-mail about news and changes in content on this specific topic in the follow-up to our event. This will be of importance to you if our speakers inform us about important changes or further information offers. For this purpose, we will keep your registration data for a maximum of 12 months after the event. The legal basis for further data processing is Article 6, Paragraph 1, Letter f of the GDPR. You do not register to receive a newsletter or a regular e-mail from our company. You can also have your data deleted before this period expires. For further information, please refer to the section "Information and deletion requests."

 

Newsletter subscriptions

Paychex Deutschland GmbH offers newsletters that inform recipients about specialized topics relating to payroll accounting and about free and paid events organized by the company.

To receive our newsletter, we require a valid e-mail address. The indication of salutation and last name is optional and will be used - if available - to personalize our newsletter in the greeting.

The registration for the newsletter proceeds according to the double-opt-in procedure (verification and consent to receive the newsletter after first-time entry of the e-mail address on the registration pages of our website).

The newsletter is sent using the e-mail marketing software of CleverReach GmbH & Co KG in Rastede, Germany. The recipient's data is also stored and processed on their server. We use CleverReach in such a way that openings and clicks in our newsletters are not recorded in a personally identifiable way. An agreement has been concluded on contract data processing.

You can revoke your consent to receive the newsletter at any time; you will then be removed from the distribution list (inactivated). An automated deletion of inactive recipients is currently not yet offered by our commissioned processor. If you would like your data (e-mail address, if applicable salutation, name) to be completely deleted from the server of CleverReach GmbH & Co KG, please contact us using the options given in the section "Information and deletion requests."


Obtaining further information

On some pages of our website, you may request access to protected contents of our web pages (videos, lecture notes) or to have whitepapers or forms sent to you via e-mail.

In all cases, we only use the data collected for this purpose (e-mail address - optional specification of salutation and first name) to provide you with the requested information via e-mail. No further processing will be carried out.


Commenting on blog posts

The comments on our website are moderated. We ask users who want to comment on blog posts for their name and e-mail address. The e-mail address will not be published and serves our legitimate interest in ensuring that users cannot anonymously post illegal content on our website, as well as to notify the commenter of new comments (if desired). The name will be published above the comment and we accept abbreviated names and acronyms.

You can have a submitted comment removed from our website at any time. For further information, please refer to the section "Information and deletion requests."
 The processing of your data is based on Art. 6 (1) sentence 1 lit. f GDPR.

Rights of data subjects

In the following section "Information and deletion requests," you can exercise the following rights at any time using the contact details provided:

Obtain information about your data stored with us and their processing

  1. Rectify inaccurate personal data
  2. Delete your data stored with us
  3. Restrict data processing, provided that we are not yet allowed to delete your data due to legal obligations
  4. Object to our processing of your data
  5. Transfer your data, if you have consented to data processing or have concluded a contract with us

If you have given us your consent, you can revoke it at any time with future effect. Revocation shall not affect the lawfulness of the processing carried out on the basis of the consent given until the point of revocation.

You can contact your competent supervisory authority at any time with a complaint. Your particular supervisory authority will vary according to the state of your residence, employment or the alleged violation. A list of the supervisory authorities (for the non-public sector) with their addresses can be found at: https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html

Information and deletion requests

Upon request/notice, we will delete your data stored with us, if this is legally required and possible. For information requests or requests to delete your data, please contact us by telephone at +49 (0)40 670 470 or by e-mail at info@paychex.de (with a clear subject) so that we can receive and examine your request.


Contact details of data protection officer

If you have any questions regarding data privacy, you can contact our data protection officer, Mr. André Krug (akrug@paychex.de; 040-32530951; Randstr. 34b, 22525 Hamburg).


Source reference

Parts of the privacy policy declaration have been created with the help of activeMind AG's privacy policy generator.


Subcontractors used for payroll customers:
  • KEOS Software Service GmbH, Geleitstraße 66, 63456 Hanau: payroll services - customers are advised of this before the consultation
  • FAS Business Services GmbH, Walter-Köhn-Strasse 4d, 04356 Leipzig: payroll services - customers are advised of this before the consultation
  • aov IT.Services GmbH, Bartholomäusweg 32, 33334 Gütersloh: Hosting of i-DOS (primary application of Paychex portal) and the archival component (i-DOS clients managed by customers) of the Digital Personnel Office
  • Wolters Kluwer Service und Vertriebs GmbH, Hindenburgstrasse 46, 71638 Ludwigsburg: Hosting of the ADDISON OneClick software used by the commissioned processor for the purpose of transmitting notifications to social insurance agencies
  • TeamViewer Germany GmbH, Bahnhofsplatz 2, 73033 Göppingen: Provider of a remote access software which gives remote control and maintenance of end device (concerns software customers)