Skip to content

Privacy Policy

Information about the processing of your personal data

Last updated:

This Privacy Policy provides information pursuant to Articles 13 and 14 of the General Data Protection Regulation (GDPR) about how Transport Talent International GmbH processes personal data when you visit this website and use its functions.

1. Controller and privacy contact

Controller:

Transport Talent International GmbH, Bernstorffstraße 120, 22767 Hamburg, Germany

Contact for privacy enquiries and exercising data subject rights: Michel Rothgaenger, email: michel.rothgaenger@transporttalent.com

The person named above is the controller's privacy contact. This does not state that the person has been formally appointed as a data protection officer under Article 37 GDPR.

2. Website delivery and server logs

When you access this website, the web server processes connection data that is technically required. This may include the IP address, date and time, requested resource, amount of data transferred, HTTP status, referrer, browser and operating system details. IP addresses are generally personal data and are therefore not described as “anonymous”.

We process these data to deliver the website, ensure stability, diagnose errors, prevent attacks and, where necessary, investigate specific misuse. The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are the secure and reliable operation of our digital services and the establishment, exercise or defence of legal claims.

Server logs must not be used to create general user profiles. Complete form content, passwords, secrets and access tokens contained in URL parameters must not be logged. Access is restricted to authorised persons.

Regular server access logs are erased after no more than seven days. Log extracts needed to investigate a specific security incident may be retained separately, with restricted access, until the investigation ends or relevant limitation or evidentiary requirements expire. Token-bearing sensitive routes are excluded from regular access logging or effectively redacted before storage.

If you use the website search, the application temporarily evaluates no more than 200 characters of the search term to display relevant content. The application does not create a separate search profile. A raw value entered directly in the URL can be longer before the application applies this limit. The search parameter forms part of the requested URL and may therefore appear in your browser history and in upstream or regular server access logs until those logs are erased. Search-result pages are not cached and do not send a referrer to subsequent pages. Please do not enter confidential data or personal data that are unnecessary for the search. The legal basis is Article 6(1)(f) GDPR; our legitimate interests are making our content easy to find and operating the website securely.

3. Security and CSP reports

If our Content Security Policy (CSP) is violated, your browser may send a technically minimised security report to our server. Only details needed to detect errors and attacks are processed, such as the time, the directive violated and a resource or page category limited to what is necessary. Complete query parameters, form content, access or invitation tokens, and storage of the IP address or complete user agent in this CSP log are not intended.

The legal basis is Article 6(1)(f) GDPR; the legitimate interest is detecting and correcting security defects and attacks. Minimised CSP reports are erased after no more than seven days unless they are exceptionally required to investigate a specific security incident. In that case, they are erased once the investigation has ended or relevant limitation or evidentiary requirements have expired.

4. Consent management and technically necessary storage

If optional analytics have been enabled after a documented backend and operational review, your browser's local storage may contain the entry tt_privacy_choice. It contains a version, the choice “necessary” or “analytics” and its technical expiry time, but no random user identifier; it becomes invalid after no more than 180 days and is removed on the next check. A positive analytics choice is not sent with website requests as a cookie. If you select “necessary”, we additionally set the technically necessary, host-bound first-party cookie tt_privacy_denied with the sole value 1 for no more than 180 days. It is sent to our own web server so that rejection or withdrawal continues to take precedence across tabs even if a browser-storage error prevents removal of an old local analytics value. In such an error case, the session storage of the same browser tab may also hold the marker tt_privacy_session_deny=1 until that tab session ends. These storage operations are necessary to implement your choice reliably and avoid asking again on every page view. Access to your device is based on section 25(2)(2) TDDDG (German Telecommunications Digital Services Data Protection Act). To the extent that personal data are processed, the legal basis is Article 6(1)(f) GDPR; our legitimate interest is reliably implementing your choice. While analytics have not been enabled, these entries are not created anew and existing choice, rejection and analytics cookies are deleted.

Where analytics have been enabled, they are loaded only after your active consent. “Reject” and “Allow analytics” are offered as equivalent choices. You can change your choice at any time via “Privacy settings” in the footer. If the browser cannot store the choice, analytics remain off as a precaution and the prompt may appear again on a later visit. Withdrawal applies for the future and does not affect the lawfulness of prior processing.

Technically necessary session and security cookies may be used for protected administration areas and, where applicable, appointment booking that you actively start. They enable authentication, session assignment, abuse prevention and the function you requested. Device access is based on section 25(2)(2) TDDDG; the related data processing is based on Article 6(1)(b) GDPR where necessary for a service you requested, and otherwise on Article 6(1)(f) GDPR. Session cookies expire on logout or when the session ends; security-relevant events are retained only for their stated purpose and according to the periods defined for security logs.

5. Audience measurement using self-hosted Matomo

Matomo is disabled in the technical default state. Analytics can be offered only after the production privacy, erasure, authorisation and operational configuration has been reviewed and approved in documented form. If it has been enabled and you expressly consent, we use Matomo to statistically analyse use of this website. Matomo is operated at analytics.ttalent.eu as an internally controlled application on our own infrastructure. Transmission to this application is therefore not disclosure to an independent analytics provider. If a hosting, data-centre, support or maintenance provider can obtain technical access, section 13 also applies. It does not set analytics cookies and does not create cross-site user profiles. “Do Not Track” signals are respected.

Data processed may include pages viewed, time, referrer, device, browser and display characteristics and technically generated connection data. Your IP address is technically transmitted to our own analytics infrastructure when the connection is made; it must not be used there to identify you or combined with other systems.

The legal bases are your consent under section 25(1) TDDDG for access to device information that is not strictly necessary and Article 6(1)(a) GDPR for the subsequent processing of personal data. Analytics begin only after you select “Allow analytics” and stop for future visits after withdrawal.

Non-aggregated Matomo event data are erased after no more than 90 days. Aggregated statistics may be stored for longer if they no longer relate to an identifiable person.

6. Contact enquiries

When you contact us through a form or by email, we process the contact and content data you provide, in particular your name, email address, and, where applicable, telephone number, company, subject and message. Technically necessary abuse-prevention data are limited to what is required; for rate limiting, IP addresses are processed only in a secret-key pseudonymised form and for a short period.

We process the data to respond to and handle your enquiry. If the enquiry concerns a contract or pre-contractual measures initiated by you, the legal basis is Article 6(1)(b) GDPR. For other enquiries it is Article 6(1)(f) GDPR; our legitimate interest is appropriate communication and handling of business matters.

Form data are first stored in an encrypted temporary queue on our infrastructure and then transferred to our internally controlled CRM at crm.ttalent.eu. Transmission to this application is not disclosure to an independent CRM provider. If a hosting, data-centre, support or maintenance provider can obtain technical access, section 13 also applies. Successfully processed queue entries are erased; unprocessed entries are erased after no more than seven days and failed entries after no more than 14 days. Pure blocking or error events without form content are retained for no more than seven days.

Once a contact enquiry has been completed, we generally erase its data after no more than six months unless it results in a contractual relationship or statutory retention or evidentiary obligations, or the defence of specific legal claims, require longer retention. Contractual and billing records in the CRM are retained for the applicable commercial and tax law periods and are then erased or anonymised.

7. Applications, recruitment services and talent pool

If you apply or request recruitment services, we process, depending on the information you provide, master and contact data, professional preferences, education, qualifications, employment and remuneration information, career history, communications and application documents such as your CV, certificates, references and, where applicable, a photograph. Please provide special categories of personal data under Article 9 GDPR only if they are required for the specific process or we expressly request them.

For an application for a position at Transport Talent, processing for the decision on entering into an employment relationship is based on Articles 6(1)(b) and 88 GDPR in conjunction with section 26(1) BDSG (German Federal Data Protection Act). Recruitment services that you request are based on Article 6(1)(b) GDPR. Where processing is exceptionally based on consent, Article 6(1)(a) GDPR applies and, for expressly included special categories of personal data, Article 9(2)(a) GDPR may apply.

Where special categories of personal data are actually necessary, their processing in the employment context takes place only under the conditions of section 26(3) BDSG and Article 9(2)(b) GDPR. Article 9(2)(f) GDPR applies where specific information is needed for the establishment, exercise or defence of legal claims. Merely confirming that you have read this Privacy Policy is not consent to process special categories of personal data.

If your documents contain data about referees or other contact persons, we receive those data from you. We use them only where necessary for the specific process and legally permitted. Please inform the person beforehand. We provide the information required by Article 14 GDPR or document why a statutory exception applies in the individual case.

Your data are transferred through the encrypted temporary queue to our internally operated CRM. Access is restricted to staff involved in recruitment and placement. Disclosure to a specific prospective employer or client takes place only as part of a specific placement process, after you have been informed and, where required, with your separate consent. The recipient then processes the data under its own data protection responsibility.

We retain data for the duration of an ongoing application or placement process. Data that are no longer needed are generally erased when the process ends. To the extent necessary to defend potential claims, we retain the required parts for no more than six months on the basis of Article 6(1)(f) GDPR; our legitimate interest is the defence of legal claims. Longer statutory periods or a specific legal dispute remain unaffected.

Inclusion in a general talent pool takes place only with separate, voluntary consent. Talent-pool data are retained for no more than 24 months and then erased unless you provide renewed consent beforehand. You may withdraw consent at any time with effect for the future. The six- and 24-month periods also apply to storage in the CRM.

8. Direct Contact and Active Sourcing

As part of our recruitment consulting, we also research potentially suitable people in publicly accessible professional sources for specific recruitment mandates and may contact them directly. Initial research and contact are generally based on our legitimate interests under Article 6(1)(f) GDPR. Further information about data sources, data categories, purposes, retention periods and your right to object is available in our Privacy Information for Direct Contact and Active Sourcing.

9. Price calculator, website retrieval, PDF and quotation

When you use the price calculator, we process the calculation parameters you enter, a website URL you provide, the publicly accessible content needed from that website for the calculation, result data and, if you request a result, PDF or quotation, your company and contact details. Only provide URLs that you are authorised to have analysed and do not use this function to transmit unnecessary personal data of other people.

We process these data to provide the calculation, PDF or quotation you requested. The legal basis is Article 6(1)(b) GDPR. Technical safeguards, rate limiting and prevention of abusive requests are based on Article 6(1)(f) GDPR. Our legitimate interest is the secure and economical operation of the function. For rate limiting, an IP address is processed only in a secret-key pseudonymised form and for a short period.

Temporary calculation results are erased no later than after 48 hours. Generated PDF files are read into working memory for the requested response and removed from the temporary file system before the CRM request is made; if this immediate deletion fails, no CRM request is made. If immediate deletion fails or the processing PHP/worker process terminates unexpectedly, an independent hourly fallback run, while the host remains operational, removes any residual PDF after a five-minute safety period and no later than within 65 minutes. Following an outage of the entire host, clean-up takes place without undue delay during the next automatic run after service resumes. If you request business contact or a quotation, the required data are transferred to the internally controlled CRM and retained according to the rules under “Contact enquiries”. An automated calculation is only a non-binding technical estimate and is not a solely automated decision with legal or similarly significant effects.

10. tik Zeiterfassung

The tik Zeiterfassung product page has moved to its dedicated product website. transporttalent.com no longer offers tik trial registrations, restorations or backup imports. The previous registration dialog and its API connection have been removed. This website therefore does not transfer tik registration data or backup archives to the tik API.

11. Prepared appointment booking

Integrated appointment booking is disabled in the technical default state by both a feature gate and a separate compliance gate. In that state, the public entry route displays only an internal contact option and does not transmit booking data to a booking system. Before activation, the operator role, data processed, recipients and infrastructure, storage location, legal bases, separate periods for business booking data, technical logs and access tokens, and data-subject rights will be conclusively documented and this Privacy Policy will be updated. Technical approval prerequisites include a narrowly restricted separate HTTPS origin, a restricted browser frame, suitable cookie and CORS rules, no-store, no-referrer, exclusion from audience measurement, secure token lifecycles and redacted short-term logs.

12. Internal editorial tools

The external editorial DeepL, OpenAI and Tavily functions are technically disabled by default through both a feature gate and a separate compliance gate and are not triggered by visiting the website. If enabled after documented approval, only explicitly configured editorial fields or general research topics are transferred; form entries, application data, CRM data and access logs are excluded from the automated transfer path. Editorial text and research results may nevertheless contain published names, roles, quotations or references. Such content may be transferred only where a legal basis exists and after the processor, storage-location and international-transfer review has been completed. Personal visitor data must not be manually entered into these processes. Automatically generated articles are saved as drafts and undergo editorial review before publication.

13. Public profiles, images, quotations and references

For company presentation, author attribution, team introductions, customer and project communications, and recruitment, the website may publish names, professional roles and biographies, photographs, professional contributions or quotations, references and links to professional profiles. This may concern in particular current and former staff, authors, contacts at customers or partners, and people providing quotations or references. Information may come directly from the person concerned or from the relevant professional project or contractual context. Where we do not obtain information from the person concerned, we provide the information required by Article 14 GDPR or document a statutory exception.

The specific legal basis is documented for each item before publication. Depending on the circumstances, this is voluntary consent under Article 6(1)(a) GDPR, performance of a contract or steps taken before entering into a contract under Article 6(1)(b) GDPR, or Article 6(1)(f) GDPR following a documented balancing exercise. Our legitimate interests may be transparent professional author attribution and a factual presentation of our company and projects actually carried out. For staff, the requirements of section 26 BDSG and the particular need for voluntary consent in the employment context are also assessed. Image, copyright, trade mark and personality rights are assessed separately.

Published content can be accessed worldwide. Search engines and linked platforms may collect it under their own data-protection responsibility; however, an external professional-profile link is contacted only when you click it. We review published personal and reference content regularly and when a role changes, a person leaves, the purpose ceases, an objection is raised or consent is withdrawn. Where the legal basis or purpose no longer applies, we remove the content from the website, structured data, our own media derivatives, caches and search index unless another statutory basis continues to apply. Copies held by external search engines or platforms are not fully within our control; within our legal and technical means, we assist with legitimate removal requests.

14. Recipients, internal systems and international transfers

Within Transport Talent, access is limited to staff who need it for the purposes described above. analytics.ttalent.eu and crm.ttalent.eu are internally controlled applications on our own infrastructure. A transfer to these applications is not disclosure to an independent analytics or CRM provider. Hosting, data-centre, support or maintenance providers may nevertheless be processors if they can technically access personal data. In that case, they must be contractually bound under Article 28 GDPR and documented in the processor and service-provider register.

Depending on the individual case, external recipients may include:

  • specific prospective employers or clients in a placement process that you request,
  • public authorities, courts, tax advisers or other professionally bound parties where disclosure is legally required or needed to pursue legal claims,
  • carefully selected technical service providers, to the extent they are actually engaged as processors for operations, maintenance or communications and are bound by an agreement under Article 28 GDPR.

A transfer of visitor data to countries outside the European Economic Area is not intended during ordinary use of this website. If a specific placement you request or a service used in the future requires an international transfer, we will inform you in advance about the recipient, country and the applicable safeguard under Articles 44 et seq. GDPR, such as an adequacy decision or EU Standard Contractual Clauses. The actual hosting locations and subprocessors of all production infrastructure components must be regularly verified in the processor and service-provider register.

15. External links

External services such as LinkedIn, X, WhatsApp or other linked websites are not embedded automatically. Only when you click an external link does your browser connect to the relevant provider. That provider processes data under its own responsibility and its privacy information applies. Depending on the provider, this may result in a transfer to a third country. We technically limit the referrer as far as possible, but it may still contain origin information depending on your browser and the destination.

16. Requirement to provide data

As a rule, you are neither legally nor contractually required to provide data through this website. Required fields are, however, necessary to process the relevant enquiry, application, calculation, registration or session. Without them, we may not be able to provide the requested function. Talent-pool information and all data marked as optional are voluntary.

17. No legally significant automated decisions

We do not make solely automated decisions within the website functions described here that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR. In particular, the price calculator does not decide on a contract and neither an analytics nor a CRM function decides on an application.

18. Your rights

Subject to the statutory conditions, you have the right of access (Article 15 GDPR), rectification (Article 16 GDPR), erasure (Article 17 GDPR), restriction of processing (Article 18 GDPR) and data portability (Article 20 GDPR). You may withdraw consent at any time with effect for the future (Article 7(3) GDPR).

Where we rely on Article 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation (Article 21 GDPR). We will then stop processing the data unless we can demonstrate compelling legitimate grounds or the processing is required for the establishment, exercise or defence of legal claims. You may object to direct marketing at any time without giving reasons; no direct marketing without a separate legal basis is currently intended on the basis of the website processes described here.

To exercise your rights, send a message to the privacy contact stated above. We may request additional information where needed to verify your identity securely.

You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, place of work or the alleged infringement. The authority generally responsible for us is:

The Hamburg Commissioner for Data Protection and Freedom of Information, Ludwig-Erhard-Str. 22, 20459 Hamburg, Germany, telephone: +49 40 428 54-4040, email: mailbox@datenschutz.hamburg.de, website: https://datenschutz-hamburg.de/

19. Data security and changes

We use risk-appropriate technical and organisational measures in accordance with Articles 25 and 32 GDPR. These include transport encryption, access restrictions, data minimisation, encrypted temporary form storage, secure session management, and deletion and authorisation concepts. However, no transmission or storage system can guarantee absolute security.

We update this Policy if the law, our processing or our technical systems change. The version published on this page is the applicable version.

Last updated: 11 September 2026