General information
The protection of your personal data is a high priority for. It is important to us to provide you with the following information about which personal data are collected, how they are used and what configuration options you have.
1. Where can I find the information that is important to me?
This privacy notice provides an overview of the issues which apply to Deutsche Telekom processing your data in this app. Further information, including information on data protection for specific products, is available at https://www.telekom.com/en/corporate-responsibility/data-protection-data-security/data-protection and https://www.telekom.com/en/deutsche-telekom/privacy-policy-1744.
2. Who is responsible for data processing? Who should I contact if I have any queries regarding data privacy at Deutsche Telekom?
Deutsche Telekom AG is the party responsible for data protection ("controller"). If you have any queries or concerns, please contact our Customer Services department or the Group Data Protection Officer, Dr. Claus D. Ulmer, Friedrich-Ebert-Allee 140, 53113 Bonn, Germany datenschutz@telekom.de.
3. What rights do I have?
You have the right
a) of access information on the categories of personal data concerning you, the purpose of the processing, any recipients or categories of recipient to whom the personal data have been or will be disclosed, the envisaged storage period (Art. 15 GDPR);
b) to request incorrect or incomplete data is rectified or supplemented (Art. 16 GDPR);
c) to withdraw consent at any time with effect for the future (Art. 7 (3) GDPR);
d) to object to the processing of data on the grounds of legitimate interests, on grounds relating to your particular situation (Art 21 (1) GDPR);
e) to request the erasure of data in certain cases under the provisions of Art. 17 GDPR (´right to be forgotten`) – especially if the data is no longer necessary in relation to the purposes for which it was collected, or is unlawfully processed, or you withdrew your consent according to (c) above or objected according to (d) above;
f) to demand under certain circumstances the restriction of data insofar the processing is not necessary any more or unlawful, but erasure is not demanded, or the erasure obligation is contested (Art. 18 GDPR);
g) to data portability, i.e. you can receive the data concerning you which you provided to us, in a commonly used and machine-readable format, such as CSV, and can, where necessary, transmit the data to another controller (Art. 20 GDPR);
h) to lodge a complaint with a supervisory authority regarding data processing (for telecommunications contracts: the German Federal Commissioner for Data Protection and Freedom of Information (Bundesbeauftragter für den Datenschutz und die Informationsfreiheit); for any other matters: State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia(Landesbeauftragter für den Datenschutz und die Informationsfreiheit Nordrhein-Westfalen) . You can also complain to any other supervisory authority within the European Union.
4. To whom does Deutsche Telekom transfer my data?
To processors, i.e. companies we commission to process data on our behalf within the scope provided by law, Art. 28 GDPR (service providers, agents). In this case, Deutsche Telekom also remains responsible for protecting your data. We engage companies particularly in the following areas of expertise: IT, sales, customer services, printing.
To cooperation partners who on their own responsibility, provide services for you or in connection to your Deutsche Telekom contract. This is the case if you commission services of such of our partners or if you consent to the incorporation of the partner or if we incorporate the partner on the basis of legal permission. The roaming service for wireless hotspots of the Global Corporate Access App is mainly governed and provided by our cooperation partner iPass Inc, a wholly owned subsidiary of Pareteum Corporation, 1185 Avenue of the Americas 2nd floor, New York, NY 10036, USA. .
Due to legal obligations: In certain cases we are legally obliged to transfer certain data to the requesting governmental authority. Example: Upon presentation of a court order, we are obliged under Sec. 101 of the German Act on Copyright and Related Rights (Urheberrechtsgesetz – UrhG) to provide information to owners of copyrights / ancillary copyrights about customers who have allegedly offered copyrighted works via Internet file sharing networks. We have therefore commissioned iPass Inc., a wholly owned subsidiary of Pareteum Corporation, 1185 Avenue of the Americas 2nd floor, New York, NY 10036, USA, on the basis of standard contractual clauses for data processing.
5. Where is my data processed?
Your data will first be processed in Germany and in other countries within the European Union. If your data will also be processed in countries outside the European Union (i.e. in third countries) by way of exception, this is done only if you have explicitly given your consent or it is required so we can provide you with services or it is provided for by law (Art. 49 GDPR). Furthermore, your data is only processed in third countries if it is ensured by certain measures that an adequate level of data protection exists for this purpose (e.g., EU Commission’s adequacy decision or appropriate safeguards, Art. 44 et sec. GDPR).
6. What data is collectedhow is it used and how long is it stored?
a) At registrationTo register for the app, please enter your first name, surname, e-mail address, user name and password. This information is required to log in to the HotSpots and will be stored on our servers to fulfill the contract for as long as you are able to use the service (Art. 6 (1) b GDPR).
When using the app: When you use the app, our servers temporarily record the IP address of your device and other technical features, such as radio accessible Wi-Fi access points and the location of the device(Art. 6 (1) b GDPR). In this app you have the possibility to the dictate text in addition to the entries via keyboard. The voice input (Google) or dictation function (Apple) is a functionality provided by the operating system of our app. When used, the speech is processed by a third party (e.g. Apple or Google) as a controller and the result will be delivered to our app and output it in the input field. For details about the functionality and how to enable or disable usage. Please contact the respective operating system vendor.
The App will collect data necessary for the provision of the service. For the best possible connection establishment and service quality, as well as for troubleshooting, usage profiles of all app users will be evaluated. (Legal ground is Art. 49 (1) b GDPR).. For this purpose, the following data will be collected by the Global Corporate Access App, and, into encrypted form, transferred to iPass Inc., a wholly owned subsidiary of Pareteum Corporation, 1185 Avenue of the Americas 2nd floor, New York, NY 10036, USA, during the time when you are using the app:
a. Identifying device data (e.g., Android ID)
b. Technical specifications of the smartphone
c. Technology used (2G, 3G, 4G, Wi-Fi)
d. Geolocation of the smartphone
e. Data rate measured in both download and upload
f. Package runtime measured
g. Number of hops between measuring client and measuring server
h. Date/time
i. Spatial sector allocation cell ID and cell LAN
j. RSSI, RSRP, and RSRQ signal strength
k. Transferred data volume measured
l. User name and password for authentication to the HotSpot
7. Authorizations
To use the app on your device, the app must have access to various functions and data on your device. This requires you to grant certain authorizations (Art. 6 (1) a GDPR).
The authorization categories are programmed differently by the various manufacturers. With Android, for example, individual authorizations are combined into authorization categories and you can only agree to the authorization category as a whole.
Please note, however, that in the case of revocation you may not have access to the full range of functions of our app.
If you have granted permissions, we will only use them to the extent described below:
Location data
The app requires information on your current location for the following purpose:
Localizing the user in order to use the HotSpot finder
Internet communication
The app requires access to the Internet via Wi-Fi or mobile communications for the following purposes:
Establishing Wi-Fi access through authentication
Downloading profile data
Uploading data on quality
To establish secure encrypted connections via VPN, certificates are used. The VPN Servers outside of Germany are operated by iPass Inc., a wholly owned subsidiary of Pareteum Corporation, 1185 Avenue of the Americas 2nd floor, New York, NY 10036, USA. The German VPN servers are operated by TWENTY 20 GmbH & Co. KG (Hausinger Straße 6, 40764 Langenfeld, Germany). Apart from the data described above for the purpose of establishing VPN connections , no further data is being recorded when making use of a VPN connection.
8. Does the app send push notifications?
Push notifications are messages that are sent form the app to your device and that are displayed with top priority. This app uses push notifications by default, provided you have given your consent when installing the app or when using it for the first time (Art. 6 (1) a GDPR).
You can deactivate the reception of push notifications at any time in settings of your device.
9. Services from companies that do not process data on our behalf and provide their services on their own responsibility
Google
Incorporation of Google Maps: On our individual pages we use Google Maps to display maps, locations and for route planning. Google Maps is operated by Google Inc. (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA). By embedding Google Maps, your IP address is transferred to Google and a cookie is stored. You can obtain information and opt out at any time from data processing by Google at http://www.google.de/intl/de/policies/privacy.