This English version is provided for convenience. The German version (Datenschutzhinweise) is authoritative.
We, WTE Group GmbH ("WTE" or "we"), would like to inform you about how we process personal data.
Our privacy policy has a modular structure: it consists of general information applying to any processing of personal data and any processing situation (1.) and specific information whose content relates only to the processing situation stated there (2. et seq.).
- General information
- Additional information for the website
- Additional information for using the app
- Online presence on Instagram
- Online presence on LinkedIn
- Additional information for communicating with us
- Additional information for other contractual partners
1. General information
1.1 Data controller
The controller is
WTE Group GmbH
Leo-Leistikow-Allee 18
22081 Hamburg
Germany
Email: info@welcome-to-europe.com
1.2 Data Protection Officer
WTE's Data Protection Officer is
ARTANA Digital GmbH
Prof. Dr. Christian Rauda
Alstertwiete 3
20099 Hamburg
Germany
Email: dpo@welcome-to-europe.com
1.3 Legal bases for processing personal data
We process the personal data of a person ("data subject") on the basis of the following legal bases:
Consent of the data subject: Where we obtain the data subject's consent for specific purposes, Art. 6 (1) sentence 1 lit. a GDPR is the legal basis.
Performance of contractual obligations: Where the processing is necessary for the performance of a contract to which the data subject is party, Art. 6 (1) sentence 1 lit. b GDPR is the legal basis. This also applies to processing operations that are necessary to carry out pre-contractual measures.
Statutory requirements and obligations: Where the processing is necessary for compliance with a legal obligation to which we are subject, Art. 6 (1) sentence 1 lit. c GDPR is the legal basis.
Safeguarding legitimate interests: Where the processing is necessary to safeguard a legitimate interest of ours or of a third party, and the interests, fundamental rights and freedoms of the data subject do not override the former interest, Art. 6 (1) sentence 1 lit. f GDPR is the legal basis.
1.4 Storage period and erasure of personal data
Personal data is erased or blocked as soon as there is no longer a legal basis for the processing. We state specific storage periods for each individual processing situation.
1.5 Recipients of personal data
Internally, personal data is processed only by those units that need it to fulfil their processing purposes. The same applies to the processors, service providers and vicarious agents we use. All units and persons working with personal data are bound to data secrecy and have been made aware of the sensitive handling of such data. Personal data is passed on to third parties only where this is in line with data protection law. In particular, persons engaged in the conduct of our business (e.g. banks, tax advisers, providers of IT services) as well as state bodies and authorities may receive your personal data where this is necessary to fulfil a legal obligation.
1.6 Data processing in third countries
In some cases, our services require the processing of personal data in countries outside the EU/EEA ("third countries") by our processors. Transfers to the USA take place, where the recipient is certified under the EU-U.S. Data Privacy Framework, on the basis of the European Commission's adequacy decision (Art. 45 (3) GDPR). In addition, and for all other third-country transfers, we have concluded EU standard contractual clauses with the processors concerned to establish appropriate safeguards within the meaning of Art. 46 GDPR.
1.7 Data subject rights
Data subjects have the following rights under the GDPR vis-à-vis us as the controller:
Right of access: Under Art. 15 GDPR, there is a right to obtain information about the personal data we process. In particular, the data subject may request information about the processing purposes, the categories of data, the categories of recipients to whom the personal data has been or will be disclosed (including whether data is transferred to a third country or an international organisation; in this context, the data subject may request to be informed of the appropriate safeguards under Art. 46 GDPR), the envisaged storage period, the existence of a right to rectification, erasure, restriction of processing or objection, the existence of a right to lodge a complaint, the origin of the data where it was not collected from us, and the existence of automated decision-making including profiling under Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved and the significance and envisaged consequences of such processing.
Right to rectification: Under Art. 16 GDPR, there is a right to rectification and/or completion of personal data that is inaccurate or incomplete.
Right to restriction of processing: Under Art. 18 GDPR, there is a right to request the restriction of the processing of personal data where the accuracy of the personal data is contested by the data subject or the processing is unlawful. Where processing has been restricted, the data subject will be informed by us before the restriction is lifted.
Right to erasure: Under Art. 17 GDPR, there is a right to erasure of personal data, unless the processing is necessary for exercising the right of freedom of expression and information, for compliance with a legal obligation, for reasons of public interest, or for the establishment, exercise or defence of legal claims.
Right to notification: Where the data subject has asserted the right to rectification, erasure or restriction of processing against us, we are obliged to communicate the rectification, erasure or restriction of processing to all recipients to whom the personal data has been disclosed, unless this proves impossible or involves disproportionate effort.
Right to data portability: Under Art. 20 GDPR, there is a right to receive the personal data that the data subject has provided to us in a structured, commonly used and machine-readable format, or to request its transmission to another controller.
Right to object: Under Art. 21 GDPR, there is a right to object to processing where the processing is based on Art. 6 (1) sentence 1 lit. e or lit. f GDPR.
Right to withdraw consent under data protection law: Under Art. 7 (3) GDPR, there is a right to withdraw a declaration of consent under data protection law at any time. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
Right to lodge a complaint with a supervisory authority: Under Art. 77 GDPR, there is a right to lodge a complaint with a data protection supervisory authority about our processing of personal data. The supervisory authority responsible for us is:
Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit
(Hamburg Commissioner for Data Protection and Freedom of Information,
HmbBfDI)
Ludwig-Erhard-Straße 22
20459 Hamburg
Germany
https://datenschutz-hamburg.de
2. Additional information for the website
We are responsible for our website wte-companion.com and its subpages ("website"). Personal data is processed when you use our website.
2.1 Provision of the website and creation of log files
When you access our website, we automatically collect data and information from your device (so-called log files).
Processor: To provide our website, we use the services of Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, USA, with whom we have concluded a data processing agreement. Vercel is certified under the EU-U.S. Data Privacy Framework; in addition, we have agreed EU standard contractual clauses. The contents and images of our blog are delivered via our processor Supabase (data processing within the EU, Ireland region; see section 3); when you access blog pages, your device's IP address is transmitted to Supabase for this purpose.
Information processed and duration of processing: The log files store, in particular, information about the browser type and version used, the device's operating system, the user's internet service provider, the device's IP address, and the date and time of access to the website. The log files are deleted within 7 days for IT security reasons.
Purpose of processing and legal basis: The data is needed to display the website on the user's device, to ensure its functionality and to analyse any malfunctions. The data also serves to optimise the website and to ensure the security of our IT systems. The legal basis is Art. 6 (1) sentence 1 lit. f GDPR. The collection of log files is strictly necessary for the operation of the website; there is therefore no possibility for the user to object.
2.2 Use of strictly necessary cookies and similar technologies
We use strictly necessary cookies and comparable storage technologies (local storage) on our website to provide our website. Cookies are text files stored in or by the internet browser on the user's device; each cookie contains a characteristic character string that enables the browser to be uniquely identified on the next access. We use the following necessary storage operations:
| Name | Type | Purpose | Storage period |
|---|---|---|---|
| wte_consent | Cookie | Stores whether and with which status you have granted or declined consent to consent-based services | 12 months |
| wte_consent_v1 | Local storage | Stores the details of your consent decision (categories, time, version) | until deleted by you |
The legal basis for storing the strictly necessary cookies is Section 25 (2) no. 2 of the German Telecommunications Digital Services Data Protection Act (TDDDG). The legal basis for processing the personal data arising in this context is Art. 6 (1) sentence 1 lit. f GDPR. The use of these cookies is strictly necessary for the operation of the website; there is therefore no possibility for the user to object.
2.3 Consent manager
We use our own consent manager on our website to manage any required consents to data processing on our website. For this purpose, the storage operations listed in section 2.2 are carried out on your device, enabling us to take your granted consents and preferences into account.
Purpose of processing, legal basis and storage period: We use the storage operations and your consent details to be able to take your consents into account appropriately. The legal basis for the storage is Section 25 (2) no. 2 TDDDG; the legal basis for processing the personal data arising in this context is Art. 6 (1) sentence 1 lit. f GDPR. The use is strictly necessary for the operation of the website.
The consent manager also contains all information on the consent-based services (cookies etc.). You can access and manage your consent preferences at any time via the "Cookie Settings" link in the page footer, allowing you to withdraw any consents given at any time with effect for the future.
2.4 Company visit recognition (Leadfeeder)
We use Leadfeeder, a service of Dealfront Group GmbH, Durlacher Allee 73, 76131 Karlsruhe, Germany. The service processes your device's IP address and information about the pages visited, and matches visits to our website to companies. This allows us to understand which companies are interested in our offerings. We do not identify individual visitors, only companies. The provider's cookies are stored on your device (in particular "_lfa", storage period up to 24 months).
The processing takes place exclusively on the basis of your consent (Art. 6 (1) sentence 1 lit. a GDPR; Section 25 (1) TDDDG), which you can withdraw at any time with effect for the future via the consent manager. We have concluded a data processing agreement with the provider.
2.5 Website usage analytics (Google Analytics 4)
We use Google Analytics 4, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The service enables an analysis of how our website is used (e.g. pages viewed, origin of visits, devices used) and stores cookies or comparable identifiers on your device for this purpose. IP addresses are processed in truncated form only. We have deactivated advertising features (Google Signals), data sharing with other Google services is switched off, and the storage period is limited to 14 months.
The processing takes place exclusively on the basis of your consent (Art. 6 (1) sentence 1 lit. a GDPR; Section 25 (1) TDDDG), which you can withdraw at any time with effect for the future via the consent manager. We have concluded a data processing agreement with the provider. Where data is transferred to Google LLC in the USA, Google LLC is certified under the EU-U.S. Data Privacy Framework.
2.6 Reach measurement (Vercel Web Analytics)
For cookieless reach measurement, we use Vercel Web Analytics, a service of Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, USA. Vercel is also the hosting provider of this website. The service counts page views and visits in aggregated form; no cookies are set, no information is stored on your device, and no cross-site tracking takes place. Visitors are distinguished only by an anonymised identifier that is discarded after 24 hours.
Purpose of processing and legal basis: The legal basis is our legitimate interest in measuring and improving our web offering (Art. 6 (1) sentence 1 lit. f GDPR). Vercel is certified under the EU-U.S. Data Privacy Framework; in addition, we have concluded a data processing agreement including EU standard contractual clauses.
2.7 Contact form and online withdrawal form
We provide a contact form and an online withdrawal form on our website. When you use them, we process the data you enter (in particular your name, email address and your request) to handle your enquiry or to receive and document your withdrawal.
Purpose of processing and legal basis: If your enquiry is aimed at the conclusion or performance of a contract, or concerns a withdrawal, the legal basis is Art. 6 (1) sentence 1 lit. b GDPR; otherwise, Art. 6 (1) sentence 1 lit. f GDPR.
Processor: For the technical dispatch of confirmation and notification emails, we use the service Resend (Resend, Inc., San Francisco, USA) as a processor. We have agreed EU standard contractual clauses with the provider.
3. Additional information for using the app
We are responsible for our app "WTE Companion" ("app") insofar as your personal data is processed in your capacity as a registered user of the app. This covers both use as a web app via the browser and use via an app on a mobile device.
To provide and operate our app, we use the processor Supabase for backend, database and data hosting. We have concluded a data processing agreement; the data processing takes place exclusively within the EU (Ireland region).
3.1 Downloading the app
This section only concerns the use of the app on a mobile device.
Our app is made available via the platforms of Google and Apple. We have no influence on their data processing, and the respective platform operator is the data controller. Their respective terms of use and privacy policies apply.
You can find the privacy policy of the Google Play Store here: https://policies.google.com/privacy
You can find the privacy policy of the Apple App Store here: https://support.apple.com/en-gb/HT211970
3.2 Using the app
Using our app requires registration and subsequent logins. In addition, we process personal data to provide our services, in particular the arrangement, preparation and performance of contracts with insurance companies, banks, telecommunications and service partners, as well as our own services (e.g. visa service, relocation, home search).
Information processed and duration of processing: All information you provide is processed to deliver our services, in particular: name, email address, login data (or Google single sign-on), contact details, date of birth, address and residence data, and uploaded documents (e.g. passport, visa, employment contract, tax and insurance documents). The data is generally processed for as long as it is required to fulfil our contractual relationship with you, or until you withdraw a consent you have given. As a rule, the data is deleted within the following periods:
- Account data: 12 months after inactivity or termination
- Communication data: 6 months after the matter is closed
- Tax and accounting data: 10 years (Section 147 of the German Fiscal Code, AO)
- Technical app logs: 30 days
- Backups: 30 days
Purpose of processing and legal basis: The data is processed for the performance of the contract (Art. 6 (1) sentence 1 lit. b GDPR). Where data is provided on the basis of consent, it is processed only to the extent stated there (Art. 6 (1) sentence 1 lit. a GDPR or, for special categories of personal data, Art. 9 (2) lit. a GDPR). In addition, as a company we are bound by legal obligations, in particular retention obligations under tax law; in this respect, the legal basis is Art. 6 (1) sentence 1 lit. c GDPR.
3.3 Document management with AI assistance (Google Vertex AI)
We use automated data extraction (OCR) via Google Vertex AI (Gemini) to read information from your uploaded documents and to pre-fill application forms for our partners without errors. This processing takes place in a protected enterprise environment in the EU; your data is not used to train public AI models. The legal basis is the performance of the contract (Art. 6 (1) sentence 1 lit. b GDPR) and, for special categories of data, your consent (Art. 9 (2) lit. a GDPR).
3.4 Biometric authentication
Where you use your device's native security features (e.g. Face ID), this data remains exclusively on your device. WTE merely receives confirmation of successful authentication (Art. 9 (2) lit. a GDPR).
3.5 Push notifications
With your consent, we send push notifications to your device, for example about status changes to your applications, new messages or important deadlines. You grant consent via your device's system prompt and by activating notifications in the app; the legal basis is Art. 6 (1) sentence 1 lit. a GDPR.
For delivery, we use the Expo Push Service (Expo, Inc., USA) as a dispatch service provider, which forwards the notifications to the push services of the respective platform operator (Apple Push Notification Service, Firebase Cloud Messaging by Google). In this process, a pseudonymous push token of your device is processed and stored by us together with the platform and app version. We have agreed EU standard contractual clauses with Expo. You can deactivate push notifications at any time in the app or in your device settings; the push token will then no longer be used.
3.6 Deleting your account
You can delete your user account at any time directly in the app (Profile → Delete account) or request deletion by email to info@welcome-to-europe.com. Upon deletion, we remove the personal data stored for your account from our active systems, in particular profile and contact data, uploaded documents including data extracted from them, push tokens, and login and session data. Data that we still need due to statutory retention obligations (e.g. Section 147 AO) or for the establishment, exercise or defence of legal claims is blocked from further processing and deleted after the respective periods expire.
3.7 Opening an account with bunq
Via the app, you can apply to open a current account with bunq B.V., Naritaweg 131-133, 1043 BS Amsterdam, Netherlands ("bunq"). For this purpose, we collect the details required for opening the account (in particular name, email address, telephone number, date of birth, place and country of birth, nationality, residence status and address) and transmit them to bunq at your instruction, so that bunq can provide you with a pre-filled onboarding. Identity verification and account opening then take place exclusively at bunq; bunq is an independent controller for this processing (privacy policy: https://www.bunq.com/privacy). The legal basis for the transmission is Art. 6 (1) sentence 1 lit. b GDPR.
To settle our brokerage remuneration and to set up follow-up services you have requested (e.g. direct debits), we receive status information about your account opening from bunq for a period of up to 180 days (in particular registration and verification status, chosen account type and, after the account has been opened, your IBAN). The legal bases are Art. 6 (1) sentence 1 lit. b and lit. f GDPR (settlement of the brokerage service).
3.8 Transfer of data to third parties
Within the app, you can have data transmitted directly to third parties, in particular to our product partners DAK-Gesundheit, HanseMerkur Krankenversicherung AG, Interlloyd Versicherungs-AG, bunq B.V. and Vodafone GmbH. Such a data transfer constitutes a transfer between two controllers: we are responsible only for the transmission of the data, not for the subsequent processing by the third party, which takes place under its sole responsibility. The transmission takes place exclusively on the basis of your consent (Art. 6 (1) sentence 1 lit. a or Art. 9 (2) lit. a GDPR).
3.9 Invitation by your organisation (enterprise access)
Employers, universities and other organisations can invite you to use the app via our enterprise portal. In this case, the inviting organisation can see your name, your email address, the status of your registration and the processing status of the services initiated via the app (e.g. "in progress" or "completed" for health insurance, SIM card, bank account or liability insurance). The contents of your contracts, uploaded documents and application data are not made accessible to the organisation.
Purpose of processing and legal basis: The status display enables your organisation to accompany your relocation progress; it is part of the offering arranged through your organisation. The legal basis is Art. 6 (1) sentence 1 lit. b GDPR and our legitimate interest in operating the enterprise offering (Art. 6 (1) sentence 1 lit. f GDPR). We point out this visibility to you when you register via an invitation link from your organisation.
3.10 Support requests within the app
The provisions on communicating with us apply (section 6).
4. Online presence on Instagram
Instagram is an online service for sharing photos and videos, operated by Meta Platforms Ireland Ltd., Merrion Road, Dublin 4, D04 X2K5, Ireland ("Meta"), a subsidiary of Meta Platforms Inc., 1601 Willow Road, Menlo Park, CA 94025, USA.
Please note that you use the Instagram page and its functions at your own responsibility. This applies in particular to the use of interactive functions (e.g. commenting, rating).
4.1 Data processing by Meta
When you visit this Instagram page, Meta collects, among other things, your IP address and further information present on your device in the form of cookies. This information is used to provide us, as the operator of the Instagram pages, with anonymised statistical information about how the Instagram page is used.
The data collected about you in this context is processed by Meta and may be transferred to countries outside the European Union. Meta describes which information it receives and how it is used in its privacy policy. There you will also find information on how to contact Meta and on the settings for advertisements: https://help.instagram.com/519522125107875.
Meta provides information on its use of cookies in its cookie policy for the Instagram service: https://help.instagram.com/1896641480634370. Please note that the cookies used enable Meta to track your user behaviour (across devices for logged-in users) beyond the Instagram service on other websites as well. This applies both to data subjects registered with Instagram and to those who are not.
According to its own statements, Meta stores data until it is no longer needed to provide its services and products, or until the respective user account is deleted, whichever occurs first. This depends on the circumstances of the individual case, in particular the type of data and the relevant legal or operational storage needs.
4.2 Page Insights
Page Insights are aggregated, anonymised statistics. As the page operator, we have no access to the personal data processed in this context, only to the aggregated, anonymised Page Insights. Further information is available at: https://www.facebook.com/help/instagram/788388387972460.
4.3 Communicating with us via Instagram
Where we handle messages or enquiries via this platform, the provisions on communicating with us apply (section 6).
5. Online presence on LinkedIn
On the LinkedIn platform of the provider LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland ("LinkedIn"), we operate a company page in joint responsibility with LinkedIn, on which we provide information about ourselves.
5.1 Data processing and legal basis
LinkedIn uses cookies and similar technologies (e.g. web beacons, pixels, ad tags and device identifiers) to collect information that enables LinkedIn to recognise users and to comprehensively analyse user behaviour. LinkedIn provides us with corresponding information for analysing the user behaviour of our online presence in anonymised form. This enables us to statistically evaluate the use of our LinkedIn page and to manage our activities in a targeted manner. The data processing takes place on the basis of our legitimate interest under Art. 6 (1) sentence 1 lit. f GDPR.
5.2 Agreement under Art. 26 GDPR
We have concluded an agreement with LinkedIn under Art. 26 GDPR, which allocates between us and LinkedIn the data protection obligations arising from the operation of our company page. LinkedIn has assumed the majority of the data protection obligations, such as fulfilling data subject rights under Art. 12 et seq. GDPR, the obligation to provide technical and organisational measures, and reporting and notification obligations in the event of a data breach. If you contact us regarding your data subject rights, we will forward your request to LinkedIn without delay.
Further information on the agreement between us and LinkedIn is available at: https://legal.linkedin.com/pages-joint-controller-addendum.
5.3 Transfer of data and third-country transfers
Please note that we cannot trace all processing operations on LinkedIn. We can neither influence nor rule out that information is transferred by LinkedIn to a third country and stored there, in particular to servers of LinkedIn Corporation in the USA. In such cases, the information is transferred on the basis of EU standard contractual clauses.
5.4 Data subject rights and further information
You can assert your data subject rights under data protection law both against us and against LinkedIn. However, please note that these can be asserted most effectively with LinkedIn, since only LinkedIn, as the provider, has access to users' data and can take direct action and provide information. Further information is available at:
- https://www.linkedin.com/legal/privacy-policy (privacy policy)
- https://www.linkedin.com/legal/cookie-policy (cookie policy)
- https://www.linkedin.com/psettings/guest-controls (opt-out)
6. Additional information for communicating with us
To get in touch and handle enquiries, we communicate with users via chat, email, telephone or messenger (WhatsApp via Superchat). We use the service provider SuperX GmbH ("Superchat") from Berlin, with whom we have concluded a data processing agreement.
When you contact us, the personal data of the enquirer is processed by us exclusively for the purpose of handling the enquiry and in case of follow-up questions. If the communication is aimed at the conclusion of a contract, the legal basis is Art. 6 (1) sentence 1 lit. b GDPR. In all other cases, the legal basis is Art. 6 (1) sentence 1 lit. f GDPR; since the enquirer contacts us, responding is also in their interest. The data is deleted as soon as the matter has been resolved and no legal basis remains.
7. Additional information for other contractual partners
The following information applies in addition where a contractual relationship (in particular B2B) exists.
Information processed and duration of processing: Which personal data is processed in detail depends on the tasks within the contractual relationship. We use the data exclusively for the purpose for which it was provided to us, for example personal details (name, address, contact details) as well as order data (e.g. payment orders) or information about the financial situation. The data is deleted as soon as the contractual relationship has ended and no other reason for processing (e.g. statutory periods) remains.
Purpose of processing and legal basis: The processing is carried out predominantly to establish and perform the contractual relationship (Art. 6 (1) sentence 1 lit. b GDPR) and on the basis of legitimate interests for contact and communication management, contract and project management, and ensuring the operation of IT systems (Art. 6 (1) sentence 1 lit. f GDPR). In addition, processing is carried out to comply with statutory requirements, in particular retention obligations under tax law (Art. 6 (1) sentence 1 lit. c GDPR).