Privacy policy (September 8, 2025)
We take the protection of your personal information seriously. This privacy policy explains what personal information we collect and how we use it. If you provide us with personal information about other people (e.g. employees, etc.), please ensure that they are aware of this Privacy Policy and that they only provide us with their personal information if they are permitted to do so and if the personal information is accurate.
1. Responsible party and contact
If you have any questions about this privacy policy or our handling of personal data, please address your request to
EXCO Consulting GmbH
D4 Business Village Lucerne, Platz 5
CH-6039 Root Längenbold
Switzerland
E-mail: info@exco-group.com
Phone: +41 78 216 76 11
2. Collection and processing of personal data
As a matter of principle, we only collect and process personal data from you that is necessary for the fulfilment of the tasks with which you have entrusted us. We primarily process personal data that we receive from our customers and other business partners as part of our business relationship with them and other interested parties, or that we collect as part of the application process. The personal data we process depends on your relationship with us and the purpose for which we process it. In some circumstances, it may be particularly sensitive personal data. Personal information also includes information about your use of our website. In this context, we collect the following personal information from you Information about your visits to our site, such as the amount of data transferred, the location from which you access our site, and other connection information and sources that you access. This is usually done through the use of log files and cookies. See below for more information about log files and cookies.
3. Categories of personal data
The personal data of our customers includes, in particular, the following information:
Contact information (e.g. name, first name, address, telephone number, email, other contact information)
Any other information about you that you provide to us. As part of the application process, this personal information may include particularly sensitive personal information such as date and place of birth, etc.
Information relating to the provision of the website/server log files. This information may include your IP address, type of web browser, operating system used or similar.
4. Purpose of data processing and legal basis
In particular, we process personal data for the following purposes:
- Conclusion or performance of a contract with the data subject
- Protection of legitimate interests (e.g. for administrative purposes, to improve our quality, to ensure security, to manage risks, to enforce our rights, to defend ourselves against claims or to check possible conflicts of interest)
- Provide and develop our products, services and websites, applications and other platforms on which we are present
- To ensure the operation of our business, in particular our IT, websites, applications and other platforms.
When you contact us (e.g. by phone, email, Microsoft Teams, Zoom, etc.) or we contact you, we process the personal information necessary to do so. We also process this personal information when you visit us. We store this information for a period of time to protect our infrastructure and information.
The collection and use of personal information in the course of our business and for the provision of our services may be legally justified as follows:
- Order: Personal data may be processed by us if this is necessary to fulfil our order/contractual obligations.
- Consent: Personal data may be processed by us if you have voluntarily consented to the processing at the time you provided your personal data.
- Legitimate interests: Personal data may be processed by us if it serves our legitimate interests and we have previously determined that the processing is appropriate, reasonable and proportionate. These interests include the provision of services and products, marketing and recruitment.
5. Who receives your personal data for processing and how it is transmitted
We will only share your information with third parties if this is necessary for the provision of our services, if these third parties provide a service to us, if we are required to do so by law or governmental authority, or if we have an overriding interest in sharing the personal information. We will also share personal information with third parties if you have given us your consent or have asked us to do so.
6. Information collected on our website
Your information is collected when you provide it to us. For example, this may be information that you provide to us when making a contact request, placing an order, registering for an event or as part of an application process.
Other information is collected automatically by our IT systems when you visit the website. This is primarily technical data (e.g. Internet browser, operating system or time of page view). This information is collected automatically when you enter our website. This website does not use any tracking technologies and does not set any third party cookies.
7. Google Analytics
7.1. We use Google Analytics, a web analytics service provided by Google Ireland Ltd. ("Google"), on our website. Google Analytics uses cookies that are stored on your device and enable analysis of your use of the website. The information collected by the cookies about your use of our site is usually transferred to a Google server in the USA and stored there. However, if IP anonymisation is activated, Google will truncate your IP address within the member states of the European Union or other signatory states to the EEA Agreement. Only in exceptional cases will the full IP address be transferred to a Google server in the USA and truncated there.
7.2. The IP address of your browser transmitted within the scope of Google Analytics is not merged with other Google data.
7.3. The data is only collected if you have given your consent in the consent banner. You can prevent the storage of cookies by adjusting your browser settings accordingly. Please note, however, that this may mean that not all functions of our website will be available to you without restriction.
7.4. The statistics obtained help us to better understand the use of our website and to continuously optimise our offering.
7.5. Provider information: Google Dublin, Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland, Fax: +353 (1) 436 1001
Terms of use: http://www.google.com/analytics/terms/de.html
Privacy policy: http://www.google.com/intl/de/analytics/learn/privacy.html
Privacy policy: http://www.google.de/intl/de/policies/privacy
8. Google Tag Manager
We also use Google Tag Manager. This tool allows us to control various website tags via a central interface. Tag Manager itself does not use cookies and does not process any personal data. It merely ensures that other tags are triggered, which in turn can collect data. Google Tag Manager does not access this data. Any deactivations already made (e.g. at cookie or domain level) remain in place for all tags implemented via Tag Manager.
Further information: https://marketingplatform.google.com/about/analytics/tag-manager/use-policy/
9. Duration of storage of personal data
We process and store your personal data for as long as is necessary to fulfil our contractual and legal obligations or otherwise for the purposes pursued with the processing, i.e., for example, for the duration of the entire business relationship (from initiation, execution to termination of a contract) as well as beyond that in accordance with statutory retention and documentation obligations. It is possible that personal data may be stored for as long as claims may be asserted against our company and insofar as we are otherwise legally obliged to do so or legitimate business interests require it (e.g. for evidence and documentation purposes).
10. Security of your data
We will only store your personal data for as long as is necessary for the purposes for which it was collected, unless there is a legal obligation to retain it. We take appropriate technical and organisational security precautions to protect your personal data from unauthorised access and misuse, such as IT and network security solutions, access controls and restrictions, encryption of data carriers and transmissions and checks.
11. Your rights as a data subject
When we process personal data about you, you have the rights listed below.
- Access: You have the right to obtain confirmation as to whether or not we are processing personal data about you and, if we are, more detailed information about the use of your data.
- Rectification: You have the right to have your data rectified by us if you believe that it contains inaccurate or incomplete information about you.
- Deletion: You have the right to have your personal data deleted by us if you withdraw your consent to its processing or if we no longer need the data for the original purpose of its use and are not obliged to retain it.
- Restrictions on processing: You have the right to temporarily restrict the processing of your personal data by us if you dispute the accuracy of the personal data or wish to restrict the use of the data rather than have it deleted.
- Data portability: You may have the right to request that certain personal data be transferred to another entity. Where technically possible, we will transfer this personal information to you electronically.
- Right to withdraw consent: You have the right to withdraw your previously given consent to the processing of your personal data for one or more specific purposes. This does not affect the lawfulness of any processing that took place before you withdrew your consent. If you withdraw your consent, we may not be able to provide you with certain services or products and we will advise you of this.
12. Handling of applicant data
We offer you the opportunity to apply for a job with us (e.g. by e-mail, post or via the online application form at https://jobboard.online/exco/). Below we inform you about the scope, purpose and use of your personal data collected during the application process. We assure you that your data will be collected, processed and used in accordance with the applicable Data Protection Act and all other statutory provisions and that your data will be treated as strictly confidential.
Scope and purpose of data collection
If you send us an application, we process your associated personal data (e.g. contact and communication data, application documents, notes taken during job interviews, etc.) insofar as this is necessary to decide on the establishment of an employment relationship. The legal basis for this is § 26 BDSG under German law (initiation of an employment relationship), Art. 6 para. 1 lit. b GDPR (general contract initiation) and - if you have given your consent - Art. 6 para. 1 lit. a GDPR. Consent can be revoked at any time. Your personal data will only be passed on within our company to persons who are involved in processing your application.
If the application is successful, the data submitted by you will be stored in our data processing systems on the basis of § 26 BDSG and Art. 6 para. 1 lit. b GDPR for the purpose of implementing the employment relationship.
Retention period for applicant data
If we are unable to make you a job offer, if you reject a job offer or if you withdraw your application, we reserve the right to retain the data you have provided on the basis of our legitimate interests (Art. 6 para. 1 lit. f GDPR) for up to 6 months from the end of the application process (rejection or withdrawal of the application). The data will then be deleted and the physical application documents destroyed. In particular, the data will be retained as evidence in the event of litigation. If it is evident that the data will be needed after the 6 month period has expired (e.g. due to an imminent or pending legal dispute), the data will only be deleted when the purpose for further storage no longer applies.
The data may also be stored for a longer period if you have given your consent (Art. 6 para. 1 lit. a GDPR) or if deletion is prevented by legal retention obligations.
Inclusion in the applicant pool
If we do not make you a job offer, you may be added to our pool of candidates. If you are accepted, all documents and information from your application will be added to the pool so that we can contact you when suitable vacancies arise.
Inclusion in the applicant pool is based solely on your express consent (Art. 6 para. 1 lit. a GDPR). Consent is voluntary and not related to the current application process. You may withdraw your consent at any time. In this case, the data will be irrevocably deleted from the applicant pool, unless there are legal grounds for retaining the data.
The data will be irrevocably deleted from the applicant pool no later than two years after consent has been given.
Use of the jobboard.online applicant platform (StaffITPro)
We use the services of the StaffITPro recruitment platform from third party provider audeoSoft GmbH:
Company contact details:
AudeoSoft GmbH
Mainzer Str. 75, 65189 Wiesbaden, Germany
+49 611 / 262 486-40
Contact details of the Data Protection Officer:
Anke Termoellen
audeoSoft GmbH
Mainzer Str. 75, 65189 Wiesbaden, Germany
+49 611 / 262 486-40
Details entnehmen Sie der Datenschutzerklärung von audeosoft: https://staffitpro.com/datenschutz/
Order Processing
A Data Processing Agreement (DPA) has been concluded for the use of the above-mentioned service. This is a contract required by the Data Protection Act, which guarantees that the personal data of visitors to our website will only be processed in accordance with our instructions and in compliance with the GDPR.
11. Changes to the Privacy Policy
We may amend this Privacy Policy at any time without prior notice. The current version published on our website will apply. If the Privacy Policy is part of an agreement with you, we will notify you of the change by email or other appropriate means when the Privacy Policy is updated.