1. Controller and Data Protection Officer
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
eAces GmbH
Oettingenstraße 25
80538 Munich, Germany
Telephone: +49 (0) 89 189 1766 0
E-mail: info@e-aces.com
Managing Director: Horst Niederberger
Commercial Register: Munich Local Court HRB 169891
Data Protection Officer
eAces GmbH
E-mail: datenschutz@e-aces.com
If you have any questions about data protection or how to exercise your data protection rights, you can contact our data protection officer directly.
2. Scope and general principles
This privacy policy applies to the website of eAces GmbH, including the contact, appointment booking, application, candidate placement, and newsletter functions offered there. For external websites or services that are merely linked from our website, the privacy policies of the respective providers apply.
We process personal data only if there is a legal basis for doing so, and only to the extent necessary for the respective purpose. In doing so, we adhere in particular to the principles of purpose limitation, data minimization, storage limitation, integrity and confidentiality in accordance with the GDPR.
Insofar as we do not obtain personal data directly from you, but from third-party sources or publicly accessible sources – for example, in the context of active candidate sourcing or business acquisition – we will provide you with separate data protection information in accordance with Article 14 GDPR, as necessary.
3. Hosting and server log files
Our website is hosted by STRATO. When you access the website, technically necessary connection and access data is processed. This may include, in particular, the IP address or technical host information, the date and time of access, the page or file accessed, the referrer URL, browser type and version, operating system, and technical status information.
The processing of this data serves to ensure that our website is provided securely, reliably, and technically flawlessly, as well as to detect and prevent misuse and attacks. The legal basis for this processing is Article 6(1)(f) GDPR. Our legitimate interest lies in the secure and reliable operation of our online services.
The hosting provider is STRATO GmbH, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany. Technical log data is processed only as long as necessary for provisioning, error analysis, and security, and is subsequently deleted or anonymized according to the hosting configuration used.
Further information: STRATO Privacy Policy
4. Cookies, local storage technologies and consent management
Our website may use technically necessary cookies or similar technologies. Insofar as information is stored on or read from your device, Section 25 of the German Telemedia Act (TDDG) applies. For processes that do not fall under a legal exception, we obtain your prior consent in accordance with Section 25 Paragraph 1 TDDG in conjunction with Article 6 Paragraph 1 Letter a of the GDPR. Insofar as access is absolutely necessary to provide a digital service you have expressly requested, Section 25 Paragraph 2 Number 2 TDDG may apply.
We use a consent management interface to manage website services that require consent. Services that require consent will only be loaded after you have made your selection. You can revoke or change your consent at any time with effect for the future via the website's cookie or privacy settings.
The consent management system may process information necessary to document and respect your choices, such as consent status, selected categories, timestamps, and a technical consent identifier. The specific services involved and available settings are displayed in the website's consent interface.
5. Contact forms and direct email communication
When you contact us via a website form or email, we process the information you provide in order to handle your request. Depending on the form, this may include your first name, last name, email address, company name, your role or selection in an "I am" field, subject, and message. Providing additional information is voluntary unless marked as mandatory.
Inquiries submitted via the general contact form are generally forwarded to info@e-aces.com. If your inquiry relates to pre-contractual measures or the performance of a contract, processing is based on Article 6(1)(b) GDPR. We process other inquiries based on Article 6(1)(f) GDPR; our legitimate interest lies in the proper handling of inquiries and business communication.
Submitting a contact form does not automatically subscribe you to our newsletter or other promotional email communications. Newsletter subscriptions are handled separately.
5.1. Technical shipping via Brevo
For the technical transmission of messages from our website forms and emails, we use Brevo as our email/SMTP service provider. Brevo may process sender and recipient information, subject lines, message content, and technical delivery information. If a message to be transmitted contains an attachment, this will also be processed for the purpose of message transmission.
Brevo processes the necessary data on our behalf. Transaction logs are generally retained in our Brevo account for a short operational period of one month. We do not store full email previews for new transaction messages in Brevo. Data is only stored beyond this period to the extent necessary for delivery, error analysis, security, or due to legal obligations.
Insofar as Brevo uses sub-processors outside the European Economic Area (EEA), corresponding third-country transfers will be carried out in accordance with Chapter V of the GDPR.
Further information: Brevo Privacy Policy
6. Appointment booking via Microsoft Bookings
Our website includes an appointment booking function via Microsoft Bookings. When you use this function, we process the information you enter to schedule, confirm, and conduct the appointment. This may include, in particular, your name, email address, company name and/or other contact details, the desired date and time, the booked service, and any optional messages.
Microsoft Bookings is part of Microsoft 365. Booking information is processed and stored within the Microsoft 365/Exchange environment. If the appointment relates to pre-contractual or contractual matters, the legal basis is Article 6(1)(b) GDPR. In other cases, processing is based on Article 6(1)(f) GDPR; our legitimate interest lies in efficient appointment scheduling and communication.
When loading or accessing the embedded booking interface, a connection to Microsoft may be established. If consent is required for this in accordance with Section 25 of the German Telemedia Act (TMG), the booking interface will only be loaded after the corresponding consent has been given or after an active request for the booking function within the framework of the website's technical configuration.
Further information: Microsoft Privacy Statement
7. Applications for positions at eAces
You can apply for open positions at eAces via our website. The application form processes, in particular, your full name, email address, telephone number, the position you are applying for, your cover letter, your uploaded CV, and any other application documents you voluntarily provide.
The application will initially be processed via our WordPress-based application function (HireZoot) and sent to bewerbung@e-aces.com. The data required for the application process can then be transferred to our internal candidate management system e-Expert and stored on secure internal systems.
The legal basis for processing your application for employment with eAces is Section 26 Paragraph 1 of the German Federal Data Protection Act (BDSG). If, in exceptional cases, special categories of personal data within the meaning of Article 9 of the GDPR are processed, this will only occur if permitted under Section 26 Paragraph 3 of the BDSG in conjunction with Article 9 Paragraph 2 of the GDPR or based on another applicable exception under Article 9 Paragraph 2 of the GDPR. Please only submit special categories of personal data if this is necessary for your application.
The application copy stored in WordPress/HireZoot is configured to be automatically deleted six months after receipt. In the case of unsuccessful applications, the data held for the application process will only be stored for as long as necessary to complete the selection process and to assert, exercise, or defend potential legal claims. As a rule, this data will be deleted no later than six months after the selection process is completed, unless another legal basis permits or requires longer storage.
If an employment relationship is established, the data required for this will be transferred to the personnel administration and processed in accordance with the legal and internal retention rules applicable to employee data.
8. Applications for client positions and candidate placement
You can also apply for positions or projects through our website where eAces acts as a recruitment or project placement agency for a client. Open positions may be displayed in a shared job listing; however, internally eAces distinguishes between positions at eAces and client positions.
For client positions, we process your application and profile data to review your application, compare your qualifications with the requirements of the respective position, communicate with you and, if necessary, carry out the placement process with the respective client.
The following data may be processed: identification and contact information, professional background, education, knowledge, qualifications, certificates, project and professional experience, availability, location or mobility information, salary or fee expectations, communication content, and the application documents you provide. If documents contain special categories of personal data, we will only process them if there is a legal basis for doing so under Article 9 of the GDPR.
Depending on the specific circumstances, processing is based on Article 6(1)(b) GDPR, insofar as it is necessary for the performance of an existing placement or service agreement with you or for taking steps at your request prior to entering into a contract. Otherwise, processing may be based on Article 6(1)(f) GDPR. Our legitimate interests lie in particular in professional personnel and project placement, the review of potentially suitable profiles, communication with candidates and clients, and the documentation of the placement process.
8.1. Transmission of candidate profiles to clients
If you are being considered for a specific client position or project, eAces can create a standardized eAces candidate profile based on your application documents and make this available to the relevant potential client or project partner to assess your suitability.
Before any personal data is transferred, we ensure that a legal basis exists. We generally inform you in advance about the client in question or the specific opportunity and obtain your confirmation. If you have already given eAces a sufficiently specific placement order or a corresponding general authorization for suitable opportunities, data can be transferred within the scope of this order without requiring further individual confirmation for each recipient. Data will not be shared beyond the specific application or placement purpose.
To document the recruitment process, application and candidate documents can be stored in e-Expert as well as on secure internal servers in candidate- and project-specific storage areas. Access is granted only to authorized employees who require the data for their respective tasks.
9. Unsolicited applications and candidate pool
If you submit an unsolicited application to us, we will first process your information to check whether suitable positions or projects are currently available or will be available in the foreseeable future.
If you would like your profile to remain available in our candidate pool for future opportunities beyond the original application or placement purpose, we request your separate, voluntary consent. The initial six-month period in the candidate pool only begins after you have given your consent via the individual confirmation link sent to you by email. This confirmation is separate from simply submitting an application via the website. The legal basis for storing your data in the candidate pool is Article 6(1)(a) GDPR.
Candidate pool retention in e-Expert is managed in six-month periods. Shortly before or around the end of a period, we will contact you to ask if eAces may continue to store and use your profile for future job or placement opportunities. Renewal is granted via a personal confirmation link. Once you confirm the renewal, e-Expert will start a new six-month period.
If the period expires without renewal, the profile will be marked as expired and will not be used for new matching with new job or project requirements or new client profiles until a brief reminder and deletion process is completed. If you request deletion, we will immediately delete the active candidate profile from e-Expert and from the associated candidate and project repositories under our control, unless another legal basis requires or permits the retention of certain information. If there is no confirmation of the renewal request and subsequent reminder, and no other legal basis exists, the active candidate profile and the associated candidate documents will be deleted.
You can revoke your consent for the candidate pool at any time with effect for the future, in particular by email to datenschutz@e-aces.com or bewerbung@e-aces.com.
10. AI-supported extraction and structuring of CV data
To process applications and candidate documents more efficiently, we can use AI-supported services. Information from resumes can be automatically extracted, structured, and transferred to defined fields in our e-Expert candidate management system. This can include contact details, education, professional experience, skills, qualifications, certificates, and other information contained in the resume.
For this technical data extraction, we use services via Microsoft Azure AI/Azure OpenAI and, in some cases, the OpenAI API. The AI serves solely to extract and structure information already contained in the application documents. It does not independently decide whether a person is hired, rejected, shortlisted, presented to a client, or placed. The professional evaluation and all selection and placement decisions are made by our employees.
The same legal basis applies to AI-supported technical processing as to the respective application or placement process. For applications for employment with eAces, this is in particular Section 26 Paragraph 1 of the German Federal Data Protection Act (BDSG); for placement processes, depending on the specific design, Article 6 Paragraph 1 Letter b or f of the GDPR may apply. Separate consent is not required solely for the technical extraction of data, provided that this processing is necessary for the respective legitimate application or placement purpose.
Our current Azure deployment type is "Global Standard." Although the associated Azure resource is located in Germany, the technical processing by the model (inference) may therefore also take place in Azure data centers outside the EEA. Similarly, when using the OpenAI API directly, processing may occur outside the EEA unless the respective API configuration specifies European data residency. Where data is transferred to a third country, we implement the safeguards required under Chapter V of the GDPR.
Further information from Microsoft: Microsoft Privacy Statement
Further information from OpenAI: Data Processing Agreement (DPA) Supplement
11. Protection against automated access with Cloudflare Turnstile
To protect our forms from automated access, spam, and abuse, we use Cloudflare Turnstile. Turnstile performs technical checks in the browser and processes signals from the browser and device environment to distinguish human users from automated traffic. This can include, in particular, IP address, TLS fingerprint, user-agent header, site key, and associated origin information. After successful verification, a short-lived token is generated and validated server-side.
Turnstile is configured in "invisible" mode, so the check is usually performed without any visible interaction. This processing serves the purpose of ensuring the security of our website and forms. The legal basis for processing personal data is Article 6(1)(f) GDPR; our legitimate interest lies in protecting our IT systems, forms, and communication channels from misuse and automated attacks. If Turnstile accesses or stores information on your device, this is done – insofar as it is absolutely necessary for the secure provision of the form function you have expressly requested – on the basis of Section 25(2)(2) TDDDG; if these conditions are not met, we will obtain your prior consent in accordance with Section 25(1) TDDDG.
The provider is Cloudflare, Inc., USA. To the extent that Cloudflare processes signals on our behalf to secure our website, Cloudflare acts as a data processor in this respect. To the extent that Cloudflare processes signals on its own responsibility to improve its own bot detection capabilities, Cloudflare's privacy policy also applies. For transfers to third countries, we comply with the requirements of Articles 44 et seq. GDPR.
Further information: Cloudflare Turnstile Privacy Addendum
12. Newsletters and email marketing
When you subscribe to our newsletter, we process your email address and, if provided, your name, as well as technical evidence of registration. Newsletter registration is separate from contact and application forms. The newsletter is sent based on your consent pursuant to Art. 6 para. 1 lit. a GDPR. We also comply with the requirements of Section 7 of the German Unfair Competition Act (UWG) for electronic advertising communication.
We use a double opt-in procedure: After registering, you will receive a confirmation message; the newsletter will only be sent after your confirmation. The logging of registration and confirmation serves to prove that consent has been given. The legal basis for this documentation is Article 6(1)(f) GDPR; our legitimate interest lies in proving valid consent and preventing misuse.
We use Brevo for the technical distribution of our newsletters. Brevo processes, in particular, email addresses, and optionally names, as well as shipping and delivery information and the technical data necessary for sending the newsletter, on our behalf. Personalized analysis of newsletter opens and link clicks is not currently planned. If Brevo provides aggregated or anonymized distribution statistics, these are not linked to individual recipients. Should personalized performance tracking of newsletter opens or link clicks be implemented in the future, this will only occur after a review of the data protection and consent requirements and after a corresponding update to our privacy policy.
You can withdraw your newsletter consent at any time with effect for the future, in particular via the unsubscribe link in each newsletter or by email to datenschutz@e-aces.com. After withdrawal, your address will be removed from the active mailing list. Minimal proof of blocking or consent may be retained insofar as this is necessary to prevent further mailings or to assert, exercise, or defend legal claims.
13. Recipients and processors
Within eAces, only those employees who need access to personal data for their respective tasks have access to it. External recipients only receive personal data to the extent necessary for the respective purpose, if there is a legal obligation, or if another valid legal basis exists.
Possible categories of recipients include, in particular:
– IT, hosting, email and website service providers, in particular STRATO and Brevo;
– Microsoft for Microsoft 365/Bookings and Azure-based AI services;
– OpenAI, insofar as the OpenAI API is used for the technical extraction of CV data;
– Cloudflare for Turnstile and website protection;
– eAces customers and project partners, insofar as the transfer is necessary for a specific application or placement process;
– Lawyers, tax advisors and other professional consultants, authorities, courts or other bodies, insofar as disclosure is required by law or is necessary for the establishment, exercise or defense of legal claims.
Insofar as service providers process personal data exclusively on our behalf, they are engaged as data processors in accordance with Art. 28 GDPR.
14. Transfers to third countries
Individual technical service providers or their sub-processors may process personal data outside the European Union or the European Economic Area. This can be the case, in particular, with globally deployed cloud and AI services. A transfer to a third country only takes place if the requirements of Articles 44 et seq. of the GDPR are met, for example, on the basis of an adequacy decision by the European Commission or suitable safeguards such as the European Commission's standard contractual clauses.
For globally deployed AI services, technical model processing may take place outside the EEA. We take this into account when selecting, configuring, and contractually securing the services used.
Further information on the transfer safeguards used for a specific service, and – where necessary – on how you can obtain a copy of the relevant safeguards, can be requested from our Data Protection Officer at datenschutz@e-aces.com.
15. Storage period and deletion
We only store personal data for as long as is necessary for the respective purpose or as long as legal retention obligations or the establishment, exercise, or defense of legal claims justify further storage. Afterwards, the data is deleted or – if immediate deletion is temporarily not possible – blocked for other purposes or its processing is restricted.
The following principles apply in particular to the essential processes of our website:
1. Contact and appointment data: until the request has been fully processed or the appointment has been carried out, and beyond that only insofar as the data is required for a contractual relationship, legal retention obligations or legal defense.
2. Application copy in WordPress/HireZoot: automatic deletion six months after receipt according to the current configuration.
3. Unsuccessful applications for employment with eAces: generally no later than six months after the conclusion of the selection process, unless another legal basis applies.
4. Candidate Pool: e-Expert manages the retention of profiles in six-month periods. The first period only begins after separate confirmation from the individual concerned. Shortly before or at the end of a period, we ask whether an extension is desired. Without an extension, the profile is deactivated for new matching with job or project requirements and client expectations and deleted after the brief reminder process described above, unless another legal basis exists.
5. Candidate-related emails and internal copies: If an active candidate profile is deleted because the relevant legal basis no longer applies, the associated candidate documents and application-related email correspondence will be included in the deletion process under our control, unless an independent legal basis requires or permits the further retention of individual documents.
6. Placement and project documents: for the duration of the respective placement or project process and subsequently only to the extent that a legal basis permits or requires further retention. In the event of successful hiring or placement, in particular contract and billing documents as well as documents for asserting, exercising or defending legal claims may be retained in accordance with the respective applicable statutory or limitation periods.
7. Newsletter: until consent is withdrawn; minimal verification or blocking data may be retained beyond this to the extent legally required.
To be able to prove that a deletion request or scheduled deletion has been carried out, we may retain minimal proof of deletion for a limited period, generally up to three years. The legal basis for this is Article 6(1)(f) GDPR; our legitimate interest lies in documenting the proper deletion and for potential legal defense. This proof is kept separately from the active candidate database and is not used for recruiting, placement, or marketing purposes. It may include an internal candidate/reference ID, the full name, the deletion date, the reason for deletion, and the systems or storage areas from which the deletion was carried out. An email address is only stored to the extent necessary for unambiguous identification or for a separate blocking or non-contact purpose. Resumes, qualifications, recruiter notes, or other content from the active candidate profile are not retained solely for this proof-of-deletion purpose.
16. Provision of personal data
The information marked as mandatory in our forms is required so that we can process your inquiry, appointment booking, or application. Providing additional information is voluntary unless specifically required for the individual process. If necessary information is not provided, we may be unable to respond to your inquiry, schedule your appointment, or process your application.
Inclusion in an optional candidate pool and registration for the newsletter are voluntary. If you do not grant your consent for this or subsequently withdraw it, this will not affect the processing of any separate application or inquiry, provided that it is based on a different legal basis.
17. Your rights
Subject to the legal requirements, you are entitled to the following rights in particular:
1. Information about your personal data (Art. 15 GDPR);
2. Correction of inaccurate or completion of incomplete data (Art. 16 GDPR);
3. Deletion of your data (Art. 17 GDPR);
4. Restriction of processing (Art. 18 GDPR);
5. Data portability, insofar as the legal requirements are met (Art. 20 GDPR);
6. Objection to processing based on Article 6(1)(e) or (f) GDPR (Article 21 GDPR);
7. Withdrawal of consent at any time with effect for the future (Art. 7 para. 3 GDPR).
To exercise your rights, please contact datenschutz@e-aces.com. Withdrawing your consent does not affect the lawfulness of processing based on consent before its withdrawal.
18. Right to object to direct marketing
If your personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of your personal data for such marketing. Following such an objection, your personal data will no longer be processed for direct marketing.
19. Right to lodge a complaint with a supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority. For non-public bodies based in Bavaria, the following supervisory authority is particularly responsible:
Bavarian State Office for Data Protection Supervision (BayLDA)
Promenade 18
91522 Ansbach, Germany
Website: www.lda.bayern.de
20. No exclusively automated decision-making in the application process
In the application and placement processes described in this privacy policy, we do not make any decisions based solely on automated processing within the meaning of Article 22 GDPR that have legal effect on you or similarly significantly affect you. AI-supported functions are currently used exclusively for the technical extraction and structuring of resume data. Selection and placement decisions are made by humans.
21. Data security
We take appropriate technical and organizational measures to protect personal data from loss, manipulation, unauthorized access, and other risks. The website uses encrypted HTTPS/TLS connections. Access rights to internal application and candidate systems are granted on a need-to-know basis.
22. Update of this privacy policy
We update this privacy policy when our website, the services we use, or relevant legal requirements change. The version published on our website is always the authoritative one.
As of August 2026