Data Privacy Policy of the trackSpace Suite

 

1. Controller

1.1. Controllership depending on your Controller’s Usage of this Service

Controllership means determining the purposes and means of the processing of personal data within this Service.

This service is intended for the use by organizations. Where the Service is made available to you through an organization (e.g. your employer), that organization is responsible for the Service’s sites/personal data input over which it has control. If this is the case, please direct your data privacy questions to your administrator/team lead/project lead/data protection officer, as your use of the Service shall be subject to that organization's policies.

Lufthansa Systems GmbH & Co. KG is not responsible for the privacy or security practices of your organization, which may be different than this policy.

1.2. Lufthansa Systems GmbH & Co. KG as Controller

We, Lufthansa Systems GmbH & Co. KG (Am Messeplatz 1, 65479 Raunheim, Germany), hereinafter also called “LSY”, “we”, “us”, wish to inform you how your personal data is processed when you use a trackSpace Suite service (e.g. trackSpace or docSpace), hereinafter also called “website” or referred to as “Services", provided by us.

If you have any further queries regarding data protection in connection with our website or the services offered, please contact our data protection officer or coordinator:

Group Data Protection Office for the Lufthansa Group:

Deutsche Lufthansa AG
FRA CJ/D
Airportring
60546 Frankfurt a. M.
Germany

E-Mail: datenschutz@dlh.de

Data Protection Officer at Lufthansa Systems GmbH & Co. KG:

E-Mail: dataprotection@lhsystems.com

2. Scope, purpose and legal basis of processing personal data

We collect and use personal data directly from our users and other sources (mentioned below) in the following situations:

2.1. Information you provide to us

We collect information about you when you input it into the Services or otherwise provide it directly to us.

2.1.1. Account and Profile Information

We collect information about you when you register for an account and providing your contacts, create or modify your profile, set preferences, sign-up for the Services. You also have the option of adding information about you (= data) such as display name (alias), profile photo, job title, and other details to your profile to be displayed in our Services. We keep track of your preferences when you select settings within the Services.

2.1.2. Content you provide through our Services

When you use our Services, we collect and store content that you post, send, receive and share. This content includes any information about you that you may choose to include. Examples of content we collect and store include: the summary and description added to a JIRA issue, the pages you create in Confluence, your repositories and pull requests in Bitbucket, comments you enter in connection with an incident in status pages, and any feedback you provide to us. Content also includes the files and links you upload to the Services.

2.1.3. Information you provide through our support channels

The Services also include our customer support, where you may choose to submit information regarding a problem you are experiencing with a Service. Whether you designate yourself as a technical contact, open a support ticket, speak to one of our representatives directly or otherwise engage with our support team, you will be asked to provide contact information, a summary of the problem you are experiencing, and any other documentation, screenshots or information that would be helpful in resolving the issue.

2.2. Information we collect automatically when you use the Services

We collect information about you when you use our Services, including browsing our websites and taking certain actions within the Services.   

2.2.1. Your use of the Services

We keep track of certain information about you when you visit and interact with any of our Services. This information includes the features you use; the links you click on; the type, size and filenames of attachments you upload to the Services; frequently used search terms; and content you create and update.

2.2.2. Device and Connection Information

We collect information about your computer, phone, tablet, or other devices you use to access the Services. This device information includes your connection type and settings when you install, access, update, or use our Services. We also collect information through your device about your operating system, browser type, IP address, URLs of referring/exit pages, device identifiers, and crash data. We use your IP address and/or country preference in order to approximate your location to provide you with a better Service experience. How much of this information we collect depends on the type and settings of the device you use to access the Services.

2.2.3. Cookies

Lufthansa Systems uses cookies to improve performance and your user experience, e.g. to allow you to access and use the Services without re-entering your username or password, or to determine the recent issues or pages you worked on.

2.2.3.1. How do we use them?

2.2.3.2. How can you opt-out?

To opt-out of our use of cookies, you can instruct your browser, by changing its options, to stop accepting cookies or to prompt you before accepting a cookie from websites you visit. If you do not accept cookies, however, you may not be able to use all aspects of our Services.

Many browsers include their own management tools for removing HTML5 local storage objects.

You will not be able to opt-out of any cookies or other technologies that are “strictly necessary” for the Services.

2.3. Information we receive from other sources

We receive information about you from other Service users, from third-party services, from our related companies, and from our business and channel partners.

2.3.1. Other users of the Services

Other users of our Services may provide information about you when they submit content through the Services. For example, you may be mentioned in a JIRA issue opened by someone else. We also receive your email address from other Service users when they provide it in order to invite you to the Services. Similarly, an administrator may provide your contact information when they designate you as the billing or technical contact on your company's account.

2.3.2. Other services you link to your account

We receive information about you when you or your administrator integrate or link a third-party service with our Services. You or your administrator may also integrate our Services with other services you use, such as to allow you to access, store, share and edit certain content from a third-party through our Services. For example, you may authorize our Services to access, display and store files from a third-party document-sharing service within the Services interface. Or you may authorize our Services to connect with a third-party calendaring service so that your meetings and connections are available to you through the Services. You may authorize our Services to sync a contact list or address book so that you can easily connect with those contacts within the Services or invite them to collaborate with you on our Services. The information we receive when you link or integrate our Services with a third-party service depends on the settings, permissions and privacy policy controlled by that third-party service. You should always check the privacy settings and notices in these third-party services to understand what data may be disclosed to us or shared with our Services.

2.3.3. LSY Companies

We may receive information about you from companies that are owned or operated by LSY, in accordance with their terms and policies.

2.3.4. Other Partners

We receive information about you and your activities on and off the Services from third-party partners, such as advertising and market research partners who provide us with information about your interest in and engagement with, our Services and online advertisements.

3. Use of your personal data

How we use the information collected depends partly on the Services you use how you use them, based on any preferences or settings you have communicated to us. Below are the specific purposes for which we use the information we collect about you.

3.1. To provide the Services and personalize your experience

We use information about you to provide the Services to you, including to process transactions with you, authenticate you when you log in, provide customer support, and operate and maintain the Services. For example, we use the name and picture you provide in your account to identify you to other Service users. Our Services also include tailored features that personalize your experience, enhance your productivity, and improve your ability to collaborate effectively with others by automatically analyzing the activities of your team to provide search results, activity feeds, notifications, connections and recommendations that are most relevant for you and your team. For example, we may use your stated job title and activity to return search results we think are relevant to your job function. We also use information about you to connect you with other team members seeking your subject matter expertise. We may use your email domain to infer your affiliation with a particular organization or industry to personalize the content and experience you receive on our websites. Where you use multiple Services, we combine information about you and your activities to provide an integrated experience, such as to allow you to find information from one Service while searching from another or to present relevant product information as you travel across our websites.  

3.2. For research and development

We are always looking for ways to make our Services smarter, faster, secure, integrated, and useful to you. We use collective learnings about how people use our Services and feedback provided directly to us to troubleshoot and to identify trends, usage, activity patterns and areas for integration and improvement of the Services. For example, to improve the @mention feature, we automatically analyze recent interactions among users and how often they @mention one another to surface the most relevant connections for users. We automatically analyze and aggregate frequently used search terms to improve the accuracy and relevance of suggested topics that auto-populate when you use the search feature. In some cases, we apply these learnings across our Services to improve and develop similar features or to better integrate the services you use. We also test and analyze certain new features with some users before rolling the feature out to all users.

3.3. To communicate with you about the Services

We use your contact information to send transactional communications via email and within the Services, including confirming your purchases, reminding you of subscription expirations, responding to your comments, questions and requests, providing customer support, and sending you technical notices, updates, security alerts, and administrative messages. We send you email notifications when you or others interact with you on the Services, for example, when you are @mentioned on a page or ticket or when a task if assigned to you. We also provide tailored communications based on your activity and interactions with us. For example, certain actions you take in the Services may automatically trigger a feature or third-party app suggestion within the Services that would make that task easier. We also send you communications as you onboard to a particular Service to help you become more proficient in using that Service. These communications are part of the Services and in most cases you cannot opt out of them. If an opt-out is available, you will find that option within the communication itself or in your account settings.  

3.4. Customer support

We use your information to resolve technical issues you encounter, to respond to your requests for assistance, to analyze crash information, and to repair and improve the Services.

3.5. For safety and security

We use information about you and your Service use to verify accounts and activity, to monitor suspicious or fraudulent activity and to identify violations of Service policies.

3.6. To protect our legitimate business interests and legal rights

Where required by law or where we believe it is necessary to protect our legal rights, interests and the interests of others, we use information about you in connection with legal claims, compliance, regulatory, and audit functions, and disclosures in connection with the acquisition, merger or sale of a business.

3.7. With your consent

We use information about you where you have given us consent to do so for a specific purpose not listed above. For example, we may publish testimonials or featured customer stories to promote the Services, with your permission. 

4. Duration of the data processing

Your personal data are deleted as soon as they are no longer needed for the specified purposes. In certain circumstances, personal data are kept for the period of time during which claims against the Lufthansa Systems GmbH & Co. KG may be enforced (statutory limitation period of three to thirty years). Personal data are also saved to the extent that and for so long as LSY is legally obliged to do so. Corresponding burdens of proof and duties of retention arise from, among others, the Commercial Code, Tax Code and Money Laundering Act. These prescribe retention periods up to ten years.

5. Legal basis for processing (for EEA users)

If you are an individual in the European Economic Area (EEA), we collect and process information about you only where we have legal bases for doing so under applicable EU laws. The legal bases depend on the Services you use and how you use them. This means we collect and use your information only where:

If you have consented to our use of information about you for a specific purpose, you have the right to change your mind at any time, but this will not affect any processing that has already taken place. Where we are using your information because we or a third party (e.g. your employer) have a legitimate interest to do so, you have the right to object to that use though, in some cases, this may mean no longer using the Services.

6. Rights of the data subject

We are committed to ensuring fair and transparent processing. That is why it is important to us that data subjects can exercise the following rights where the respective legal requirements are satisfied:

Right of Access by the Data Subject (Art. 15 GDPR): You shall have the right to receive/access information from us regarding the processing of your personal data.

Right to Rectification (Art. 16 GDPR): You shall have the right to demand that we correct your personal data which are incorrect, outdated and/or incomplete.

Right to Erasure (Art. 17 GDPR): You shall have the right to demand the deletion of your personal data in accordance with the requirements of Article 17 GDPR.

Right to Restriction of Processing (Art. 18 GDPR): You shall have the right to demand the restriction of the processing of your personal data in accordance with the requirements of Article 18 GDPR.

Right to Data Portability (Art. 20 GDPR): Insofar as the data processing undertaken is based upon a consent (Art. 6(1)(a) or Art. 9(2)(a)) or a fulfilment of a contractual agreement (Art. 6(1)(b)) and it makes use of an automated processing system, you shall have the right to receive your data in a structured, commonplace and machine-readable format and to transfer these data to another data processing service provider.

Right to Object (Art. 21 GDPR): Insofar as the processing is based upon an overriding interest or your data are used for the purposes of direct advertising, you shall have the right to object to the processing of your data. An objection shall be permissible if the processing either is carried out in the public interest or in the exercising of official authority or owing to a justified interest of LSY or of a third party. In the event that you object, we request that you state your reasons to us regarding why you are objecting to the data processing. In addition, you shall have the right to object to the data processing for the purposes of direct advertising. This shall also be valid for profiling insofar as this is undertaken in conjunction with the direct advertising.

Right of Withdrawal (Art. 7(3) GDPR): If you give your consent to us for processing your personal data, please note that you may withdraw this consent at any time. To exercise your right, please email one of the contacts named under “1. Controller”. In order to process your request and for identification purposes, please note that we will process your personal data in accordance with Art. 6(1)(c) GDPR. Please also note that your consent can only be withdrawn with future effect and such a withdrawal does not have any influence on the lawfulness of past processing. In some cases, we may be entitled in spite of your withdrawal to continue to process your personal data on a different legal basis – e.g. to perform a contract.

Right to Complain (Art. 77 GDPR): You also have the right to lodge a complaint with a supervisory authority. The relevant supervisory authority for the Lufthansa Systems GmbH & Co. KG is:

Landesbeauftragter für Datenschutz und Informationsfreiheit des Landes Hessen

P. O. box 3163
65021 Wiesbaden
Gustav-Stresemann-Ring 1
2nd floor
65189 Wiesbaden

phone: +49 611 1408 - 0
fax: +49 611 1408 - 611
e-mail: Poststelle@datenschutz.hessen.de

To exercise your rights please contact us via e-mail: dataprotection@lhsystems.com.

7. Our policy towards children

The Services are not directed to individuals under 16. We do not knowingly collect personal information from children under 16. If we become aware that a child under 16 has provided us with personal information, we will take steps to delete such information. If you become aware that a child has provided us with personal information, please contact our support services or an administrator.

8. Changes to our Privacy Policy

We may change this privacy policy from time to time. We will post any privacy policy changes on this page and, if the changes are significant, we will provide a more prominent notice. We will also keep prior versions of this Privacy Policy in an archive for your review. We encourage you to review our privacy policy whenever you use the Services to stay informed about our information practices and the ways you can help protect your privacy.

If you disagree with any changes to this privacy policy, you will need to stop using the Services and deactivate your account(s).