Personal data (usually referred to just as "data" below) will only be processed by us to the extent necessary and for the purpose of providing a functional and user-friendly website, including its contents, and the services offered there.
Per Art. 4 No. 1 of Regulation (EU) 2016/679, i.e. the General Data Protection Regulation (hereinafter referred to as the "GDPR"), "processing" refers to any operation or set of operations such as collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment, or combination, restriction, erasure, or destruction performed on personal data, whether by automated means or not.
I. Information about us as controllers of your data
The party responsible for this website (the "controller") for purposes of data protection law is:
BMC Strategy Consultants GmbH
Taunus Tor 1
60310 Frankfurt am Main
Telephone: 069 50 50 60 4-586
The controller's data protection officer is:
BMC Strategy Consultants GmbH
Taunus Tor 1
60310 Frankfurt am Main
Telephone: 069 50 50 60 4-586
II. The rights of users and data subjects
With regard to the data processing to be described in more detail below, users and data subjects have the right
In addition, the controller is obliged to inform all recipients to whom it discloses data of any such corrections, deletions, or restrictions placed on processing the same per Art. 16, 17 Para. 1, 18 GDPR. However, this obligation does not apply if such notification is impossible or involves a disproportionate effort. Nevertheless, users have a right to information about these recipients.
Likewise, under Art. 21 GDPR, users and data subjects have the right to object to the controller's future processing of their data pursuant to Art. 6 Para. 1 lit. f) GDPR. In particular, an objection to data processing for the purpose of direct advertising is permissible.
III. Information about the data processing
Your data processed when using our website will be deleted or blocked as soon as the purpose for its storage ceases to apply, provided the deletion of the same is not in breach of any statutory storage obligations or unless otherwise stipulated below.
For technical reasons, the following data sent by your internet browser to us or to our server provider will be collected, especially to ensure a secure and stable website: These server log files record the type and version of your browser, operating system, the website from which you came (referrer URL), the webpages on our site visited, the date and time of your visit, as well as the IP address from which you visited our site.
The data thus collected will be temporarily stored, but not in association with any other of your data.
The basis for this storage is Art. 6 Para. 1 lit. f) GDPR. Our legitimate interest lies in the improvement, stability, functionality, and security of our website.
The data will be deleted within no more than seven days, unless continued storage is required for evidentiary purposes. In which case, all or part of the data will be excluded from deletion until the investigation of the relevant incident is finally resolved.
a) Session cookies
This processing makes our website more user-friendly, efficient, and secure, allowing us, for example, to display our website in different languages or to offer a shopping cart function.
The legal basis for such processing is Art. 6 Para. 1 lit. b) GDPR, insofar as these cookies are used to collect data to initiate or process contractual relationships.
If the processing does not serve to initiate or process a contract, our legitimate interest lies in improving the functionality of our website. The legal basis is then Art. 6 Para. 1 lit. f) GDPR.
When you close your browser, these session cookies are deleted.
b) Third-party cookies
Please refer to the following information for details, in particular for the legal basis and purpose of such third-party collection and processing of data collected through cookies.
c) Disabling cookies
If you prevent or restrict the installation of cookies, not all of the functions on our site may be fully usable.
Online job applications / publication of job advertisements
We offer you the opportunity to apply for a job with us via our website. With these digital applications, your applicant and application data will be collected and processed electronically by us for the purpose of handling the application procedure.
The legal basis for this processing is § 26 para. 1 p. 1 BDSG in conjunction with Art. 88 para. 1 DSGVO.
If a contract of employment is concluded after the application procedure, we will store the data you provide during the application process in your personnel file for the purpose of the usual organisational and administrative process - this is, of course, in compliance with the more extensive legal obligations.
The legal basis for this processing is also § 26 para. 1 sentence 1 BDSG in conjunction with Art. 88 para. 1 DSGVO.
If an application is rejected, we automatically delete the data transmitted to us two months after notification of the rejection. However, the data will not be deleted if the data requires longer storage of up to four months or until the conclusion of legal proceedings due to legal provisions, e.g. due to the obligation to produce evidence under the AGG.
The legal basis in this case is Art. 6 para. 1 lit. f) DSGVO and Art. 24 para. 1 no. 2 BDSG. Our legitimate interest lies in legal defence or enforcement.
If you expressly consent to a longer storage of your data, e.g. for your inclusion in a database of applicants or interested parties, the data will be processed further on the basis of your consent. The legal basis is then Art. 6 para. 1 lit. a) DSGVO. However, you can of course revoke your consent at any time in accordance with Art. 7 Para. 3 DSGVO by making a declaration to us with effect for the future.
We maintain an online presence on LinkedIn to present our company and our services and to communicate with customers/prospects. LinkedIn is a service of LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Irland, a subsidiary of LinkedIn Corporation, 1000 W. Maude Avenue, Sunnyvale, CA 94085, USA.
We would like to point out that this might cause user data to be processed outside the European Union, particularly in the United States. This may increase risks for users that, for example, may make subsequent access to the user data more difficult. We also do not have access to this user data. Access is only available to LinkedIn. LinkedIn Corporation is certified under the Privacy Shield and committed to comply with European privacy standards.
We have no influence on the type and scope of the data processed by XING, the way this data is processed and used, or the transfer of this data to third parties. We also have no effective means of control in this respect. When you use or visit the XING service, data is automatically collected from you during your use or visit. This is done using various tracking technologies.
On the XING servers, data from users and third parties, which is primarily required for the provision and maintenance of the security of the XING service, is used. On your end device, data from users and third parties are used by means of cookies, pixels and similar tracking technologies to provide the services and to evaluate user behavior, to measure and optimize advertising, and for statistical purposes. In addition, if your e-mail program allows HTML, for example, it is determined whether and when you have opened an e-mail. Within the scope of tracking, access data (e.g. date and time of the visit, IP address, cookie ID, location data, product and version information of the browser or app used, device IDs or device data) as well as interaction data (e.g. pages viewed or search queries carried out) are processed. So-called session cookies are used to identify you as a user during your visit to XING. These session cookies are automatically deleted at the end of each session. These cookies are required in order to use XING. In addition, a very rough geo-localization is carried out with regard to your person at the level of the cities you visit. For this purpose, your abbreviated and anonymized IP address and, if you have agreed to this in your mobile device, your geocoordinates are stored. It is not stored where exactly they are located. Concrete addresses or geocoordinates are not stored.
Further information on how your data is processed on XING can be found here:
Information, for what purpose and to whom your personal data will be forwarded can be found here:
To advertise our products and services as well as to communicate with interested parties or customers, we have a presence on the Facebook platform.
On this social media platform, we are jointly responsible with Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbor, Dublin 2, Ireland.
The data protection officer of Facebook can be reached via this contact form:
We have defined the joint responsibility in an agreement regarding the respective obligations within the meaning of the GDPR. This agreement, which sets out the reciprocal obligations, is available at the following link:
The legal basis for the processing of the resulting and subsequently disclosed personal data is Art. 6 para. 1 lit. f GDPR. Our legitimate interest lies in the analysis, communication, sales, and promotion of our products and services.
The legal basis may also be your consent per Art. 6 para. 1 lit. a GDPR granted to the platform operator. Per Art. 7 para. 3 GDPR, you may revoke this consent with the platform operator at any time with future effect.
When accessing our online presence on the Facebook platform, Facebook Ireland Ltd. as the operator of the platform in the EU will process your data (e.g. personal information, IP address, etc.).
This data of the user is used for statistical information on the use of our company presence on Facebook. Facebook Ireland Ltd. uses this data for market research and advertising purposes as well as for the creation of user profiles. Based on these profiles, Facebook Ireland Ltd. can provide advertising both within and outside of Facebook based on your interests. If you are logged into Facebook at the time you access our site, Facebook Ireland Ltd. will also link this data to your user account.
If you contact us via Facebook, the personal data your provide at that time will be used to process the request. We will delete this data once we have completely responded to your query, unless there are legal obligations to retain the data, such as for subsequent fulfillment of contracts.
Facebook Ireland Ltd. might also set cookies when processing your data.
Facebook Ireland Ltd. might also set cookies when processing your data. If you do not agree to this processing, you have the option of preventing the installation of cookies by making the appropriate settings in your browser. Cookies that have already been saved can be deleted at any time. The instructions to do this depend on the browser and system being used. For Flash cookies, the processing cannot be prevented by the settings in your browser, but instead by making the appropriate settings in your Flash player. If you prevent or restrict the installation of cookies, not all of the functions of Facebook may be fully usable.
It cannot be excluded that the processing by Facebook Ireland Ltd. will also take place in the United States by Facebook Inc., 1601 Willow Road, Menlo Park, California 94025.
Facebook Inc. has submitted to the EU-US Privacy Shield, thereby complying with the data protection requirements of the EU when processing data in the USA.
Social media links via graphics
We also integrate the following social media sites into our website. The integration takes place via a linked graphic of the respective site. The use of these graphics stored on our own servers prevents the automatic connection to the servers of these networks for their display. Only by clicking on the corresponding graphic will you be forwarded to the service of the respective social network.
Once you click, that network may record information about you and your visit to our site. It cannot be ruled out that such data will be processed in the United States.
Initially, this data includes such things as your IP address, the date and time of your visit, and the page visited. If you are logged into your user account on that network, however, the network operator might assign the information collected about your visit to our site to your personal account. If you interact by clicking Like, Share, etc., this information can be stored your personal user account and possibly posted on the respective network. To prevent this, you need to log out of your social media account before clicking on the graphic. The various social media networks also offer settings that you can configure accordingly.
The following social networks are integrated into our site by linked graphics:
Facebook Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland, a subsidiary of Facebook Inc., 1601 S. California Ave., Palo Alto, CA 94304, USA.
EU-US Privacy Shield https://www.privacyshield.gov/participant?id=a2zt0000000GnywAAC&status=Active
LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Irland, a subsidiary of LinkedIn Corporation, 1000 W. Maude Avenue, Sunnyvale, CA 94085 USA.
EU-US Privacy Shield https://www.privacyshield.gov/participant?id=a2zt0000000L0UZAA0&status=Active
XING SE, Dammtorstraße 30, 20354 Hamburg, Deutschland.
EU-US Privacy Shield https://privacy.xing.com/en/privacy-policy/information-you-provide-us-with
Our website uses Google Fonts to display external fonts. This is a service provided by Google Inc., Gordon House, Barrow Street, Dublin 4, Irland (hereinafter: Google).
Through certification according to the EU-US Privacy Shield
Google guarantees that it will follow the EU's data protection regulations when processing data in the United States.
To enable the display of certain fonts on our website, a connection to the Google server in the USA is established whenever our website is accessed.
The legal basis is Art. 6 Para. 1 lit. f) GDPR. Our legitimate interest lies in the optimization and economic operation of our site.
When you access our site, a connection to Google is established from which Google can identify the site from which your request has been sent and to which IP address the fonts are being transmitted for display.
Google offers detailed information at
in particular on options for preventing the use of data.
GOOGLE Custom Search Engine ("CSE")
For full-text search on the website, we use the Google Custom Search Engine (CSE). CSE is a service of Google LLC, 1600 Amphitheater Parkway, Mountain View, CA 94043 USA, hereinafter Google.
Google is certified under the EU-US Privacy Shield, thereby ensuring compliance with EU data protection regulations when processing data in the US.
CSE makes it possible to do a full-text search for content on our website. Access to this search function is via the Google Custom Search search box.
The legal basis for this processing of data is Art. 6 para. 1 lit. f GDPR. Our legitimate interest is in the user-friendliness of the website. Art. 6 Abs. 1 lit. f DSGVO. Unser berechtigtes Interesse besteht in der Anwenderfreundlichkeit der Website.
The feature is integrated into website without modification as a software module from Google.
If the search is activated by entering a search term, Google uses a plug-in to load the information you are looking for. At the same time, the search terms you enter and your IP address are transmitted to Google in order to perform the search and display the search results.
If you are logged into your existing Google Account at the time of the search, Google may associate the collected information with your user profile.
Google offers further information, in particular your options to prevent this use of your data, at the following links: