Privacy notice for the use of Microsoft Teams

Who is responsible for data processing?

The responsible party in terms of data protection law is
CaderaDesign GmbH | Frankfurter Str. | 87Bürgerbräu | 02 Sudhaus | 97082 Würzburg and Microsoft Corporation One Microsoft Way Redmond WA 98052-6399 USA

Terms of use:

When you access the Microsoft Teams website, the Microsoft Teams provider is responsible for data processing. However, you only need to download the website once to download the application.
If you do not wish to download the application, the use of the program is only possible through your browser via the website of Microsoft Teams.

What data is processed by the data controllers? And for what purposes?
Various data are stored by the responsible parties. This also depends on what information you provide when participating in the online session.

CaderaDesign Ltd:

Content data: CADERADESIGN stores the chat history as a text file, insofar as these are used during the session, shared data that you provide during the online session, as well as screenprints, video and call recordings, if applicable, after prior consent by you.
CADERADESIGN does not use automated decision-making in the sense of Art. 22 DSGVO.

Microsoft Cooperation

As part of providing the service, Microsoft Teams stores different types of personal data.

  • Content data: Meetings, chats, voicemails, shared files, recordings, and transcripts.
  • Meeting metadata: e.g., date, time, meeting ID, phone numbers (for audio participation), location.
  • Profile data: Data you provide when you sign in to Microsoft Teams, such as the sign-in name, email address, your profile picture, and phone number. The input is controlled by you.
  • Call history: A detailed history of the phone calls you make allows you to search your own call records at a later time.
  • Call quality data: Details of meetings and call data are available to your system administrators. This allows your administrators to diagnose issues related to poor call quality and service usage.
  • Support/feedback data: Information related to troubleshooting tickets or feedback sent to Microsoft.
  • Diagnostic and Service Data Diagnostic data related to service usage. This personal data enables Microsoft to provide the Service (troubleshooting, securing and updating the product, and monitoring performance) and to perform some internal business operations, such as
    o Develop metrics
    o Determine service usage
    o Perform product and capacity planning.

What is the legal basis for this?
The primary legal basis for processing data is Section 6(1)(a) of the GDPR. According to this, the processing of data is permitted if you have given your consent. There is a right of revocation for you at any time.
Independently of this, data processing also takes place on the basis for the fulfillment of a contract according to § 6 para. 1 lit. b) DSGVO. According to this, the processing of data is permissible insofar as the meetings are held within the framework of contractual relationships (e.g. projects).
As far as personal data of employees of CADERADESIGN GmbH are processed, § 26 BDSG is the legal basis for data processing.
If no contractual relationship exists, the legal basis is Art. 6 para. 1 lit. f) DSGVO. Here, too, our interest is in the effective conduct of "online meetings."

How long is the data stored?

CADERADESIGN GmbH

We generally delete personal data when there is no need for further storage. A requirement exists if the data is needed for the fulfillment of contractual obligations or for the examination of warranty and, if applicable, guarantee claims.
In the case of statutory retention obligations, deletion is only considered after the expiry of the respective retention obligation.

Microsoft Cooperation

Microsoft Teams will retain your data for the minimum period necessary to provide the service.
Because this data is necessary to provide the service, this generally means that personal data will be retained until the user stops using Microsoft Teams or when the user deletes personal data.  If a user (or an administrator on behalf of the user) deletes the data, Microsoft will ensure that all copies of the personal data are deleted within 30 days.
If an organization discontinues use of the Service provided by Microsoft, the corresponding Personal Data will be deleted between 90 and 180 days after the discontinuation of the Service.
In certain circumstances, local laws require Microsoft Teams to retain phone records (for billing purposes) for a specified period of time. In these circumstances, Microsoft Teams will follow the laws of the relevant region or country.
In addition, if a company requests that Microsoft Teams retain a user's data to support a legal obligation, Microsoft will comply with the company administrator's request.

To which recipients will the data be shared?

CADERADESIGN Ltd.
CADERADESIGN does not share data with third parties.

Microsoft Cooperation

The data can be passed on to third parties as far as it is necessary for the fulfillment of the contractual relationship. The recipient depends on the contractual relationship and cannot be named in general.
Further information can be viewed at https://docs.microsoft.com/de-de/microsoftteams/teams-privacy.

Where is the data processed?

CADERADESIGN GmbH
In case of data storage as described above, the data will be stored on the file server of CADERADESIGN.

Microsoft Cooperation

Further information can be viewed at https://docs.microsoft.com/de-de/microsoftteams/teams-privacy.

Your rights as a "data subject

You have the right to information about your personal data processed by us.
In the case of a request for information that is not made in writing, we ask for your understanding that we may then require evidence from that proves that you are the person you claim to be.
Furthermore, you have a right to rectification or deletion or to restriction of processing, insofar as you are entitled to this by law.
Furthermore, you have a right to object to processing within the scope of the law. The same applies to a right to data portability.

Our data protection officer

We have appointed a data protection officer in our company. You can reach him under the following contact options:
CaderaDesign GmbH - Data Protection Officer - Frankfurter Str. 87 | Bürgerbräu | 02 Sudhaus| 97082 Würzburg, Germany.
E-mail: datenschutz@caderadesign.de

Right of appeal

In case of data protection concerns, you have the right to complain to any supervisory authority. The supervisory authority for data protection issues is, for example, the state data protection commissioner of the federal state in which our company is based. A list of the supervisory authorities and their contact details can be found at the following link: https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html.

gez. MHZ, signed. 29.4.2021