Last updated: February 26, 2026
This privacy policy (“Policy”) describes how Partium Technologies GmbH (“Company,” “we,” and “our”) collects, uses and shares Personal Data (as defined below) when using this website (the “Website”). This notification is solely relevant when Partium acts as the Controller of personal data. For example, this pertains to personal data of Partium website visitors, job candidates or business-to-business contact information. When Partium processes personal data on behalf of its customers, Partium functions as a Processor; that processing is not covered by this Policy. If you have inquiries concerning how Partium's customers use our solutions to process your personal data, please reach out to the IT administrators and privacy department of your organization directly.
We collect information about you in a range of forms, including Personal Data. As used in this Policy, “Personal Data” is as defined in the European Data Protection Directive 95/46/EC/General Data Protection Regulation 2018 and any successor legislation, this includes any information which, either alone or in combination with other information we hold about you, identifies you as an individual, including, for example, your name, postal address, email address and telephone number.
If you used our Website, you may have been asked to agree to provide Personal Data. We will only process your Personal Data in accordance with applicable data protection and privacy laws. Your consent provides us with the legal basis we require under applicable law to process your data. You maintain the right to withdraw such consent at any time. If you do not agree to our use of your Personal Data in line with this Policy, do not use our Website.
We may use your Personal Data as follows:
We collect information about you in the following ways:
Information you give us voluntarily. This includes the Personal Data you provide when you opt to use our Website Forms.
Information automatically collected. We also automatically collect some technical and navigational information from your visit to our Website. The purpose of the information is for administering the Website, tracking visitors’ journey on the Website, and gathering demographic information.
The information collected includes:
Use of cookies. In the context of our Website, cookies and tracking mechanisms may be used. Cookies are small text files that may be stored on your device when visiting our Website. Tracking is possible using different technologies. In particular, we process information using pixel technology.
When visiting our Website, you will be asked in a cookie layer whether you consent to our using of any marketing cookies or tracking mechanisms, respectively.
In our privacy settings, you may withdraw the consent with effect for the future or grant your consent at a later point in time.
Third-party Service Providers. The Website incorporates content and services from other providers (e.g., YouTube, Google) who, in turn, may use cookies and active components. Partium has no influence on the processing of Personal Data by these providers. The Website may provide links to the websites and/or services of Third-party Service Providers. The option provided by Partium to configure settings for cookies used has no effect on cookies and active components from other providers (e.g., YouTube, Google).
Refer to the respective provider‘s privacy policies for information about how your data is handled by them.
Google Analytics
Youtube
LinkedIn
Hubspot
Factorial HR
https://policies.google.com/privacy
https://policies.google.com/privacy
https://www.linkedin.com/legal/privacy-policy
https://legal.hubspot.com/privacy-policy
https://factorialhr.com/privacy
Automated Decision Making and Profiling. We may use your personal image data for the purposes of automated decision-making, profiling, and visual search results. We may also use this data to fulfill obligations imposed by law, in which case we will inform you of any such processing and provide you with an opportunity to object.
Website Forms. We use the HubSpot service to provide the following online forms. For this we forward your data to HubSpot, which process the data exclusively on our behalf. See privacy policy for “HubSpot”.
We may share your Personal Data as follows:
“Anonymous Data” means data and information that does not permit you to be identified or identifiable, either alone or when combined with any other information available to a third party. We may create Anonymous Data from the Personal Data we receive about you and other individuals whose Personal Data we collect.
Your information, including Personal Data that we collect from you, may be transferred to, stored at, and processed by us and our affiliates outside the country in which you reside, including, but not limited to the United States, where data protection and privacy regulations may not offer the same level of protection as in other parts of the world. By using our services, you agree to this transfer, storing, or processing. We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Policy.
We seek to use reasonable organizational, technical and administrative measures to protect Personal Data within our organization (see Partium's Technical and Organizational Security Measures for more details).
Unfortunately, no transmission or storage system can be guaranteed to be completely secure, and transmission of information via the internet is not completely secure. If you have reason to believe that your interaction with us is no longer secure (for example, if you feel that the security of any account you might have with us has been compromised), please immediately notify us of the problem by contacting us using the details in Section 12 below.
We will retain your Personal Data indefinitely unless you choose to revoke access.
Our service is not directed to children under 16. If a parent or guardian becomes aware that his or her child has provided us with information without their consent, he or she should contact us using the details in Section 12 below. We will delete such information from our files as soon as reasonably practicable.
Subject to the following paragraph, we ask that you not send us, and you not disclose, any sensitive Personal Data (e.g., photographs of social security numbers, information related to racial or ethnic origin, political opinions, religion or other beliefs, health, biometrics or genetic characteristics, criminal background or trade union membership) (the "Sensitive Personal Data") on or through the Website or otherwise to us.
If you send or disclose any Sensitive Personal Data through our Website or otherwise to us, you consent to our processing and use of such sensitive Personal Data in accordance with this Policy. If you do not consent to our processing and use of such Sensitive Personal Data, you must not submit it.
If you wish to exercise any of these rights, contact us using the details in Section 12 below.
We are committed to resolving any complaints about our collection or use of your Personal Data. If you would like to make a complaint regarding this Policy or our practices in relation to your Personal Data, contact us using the details in Section 12 below. We will reply to your complaint as soon as we can and in any event, within 45 days. We hope to resolve any complaint brought to our attention. However, if you feel that your complaint has not been adequately resolved, you reserve the right to contact your local data protection supervisory authority.
You may contact us in writing at legal@partium.io.
Privacy laws in the European Union (“EU”) give individuals certain rights in respect of their personal information. This policy provides a framework for responding to requests to exercise those rights. It is the Company’s policy to ensure that requests by individuals covered by this policy to exercise their rights in respect of their personal information are handled in accordance with applicable law.
This policy applies to all individuals based in the EU (“EU Individuals”). EU Individuals may be employees or former employees, contractors, consumers, end-users, employees of customers, service providers, employees of service providers and any other person based in the EU whose personal information the Company processes.
For the purposes of this policy, “EU Personal Data” means any information relating to an identified or identifiable EU Individual. An identifiable EU Individual is one who can be identified, directly or indirectly, by reference to an identifier, such as a name, identification number or online identifier. “Processing” means any operation or set of operations which is performed on EU Personal Data or sets of EU Personal Data, such as collection, use, storage, dissemination and destruction.
This policy only applies to the EU Personal Data Processed by the Company. Other individuals may also have rights regarding their personal information but they are not covered by this policy.
EU Individuals have the right to request access to their EU Personal Data Processed by the Company. Such requests are called subject access requests (“SARs”). EU Individuals can make SARs to find out what EU Personal Data the Company has about them.
When an EU Individual makes a SAR the Company must, unless there is an exemption under applicable law (see Section 13.8 "Exemptions" below), take the following steps.
If the Company is not going to respond to the request, it shall inform the EU Individual of the reasons for not taking action and of the possibility of lodging a complaint with the data protection authority in their country.
EU Individuals have the right, in certain circumstances, to request that the Company erases their EU Personal Data. Where such a request is made, the Company must, unless there is an exemption under applicable law (see Section 13.8 "Exemptions" below), erase the EU Personal Data without undue delay if:
When an EU Individual makes a request for erasure in the circumstances set out above, the Company must, unless there is an exemption under applicable law (see remainder of this section and Section 13.8 "Exemptions" below), take the following steps.
If the Company is not going to respond to the request, it shall inform the EU Individual of the reasons for not taking action and of the possibility of lodging a complaint with the data protection authority in their country.
In addition to the exemptions in Section 13.8 "Exemptions" below, the Company can also refuse to erase the EU Personal Data to the extent Processing is necessary:
EU Individuals have the right, in certain circumstances, to receive their EU Personal Data which they have provided to the Company in a structured, commonly used and machine-readable format which they can then transmit to another Company. Where such a request is made, the Company must, unless there is an exemption under applicable law (see Exemptions below), provide the EU Personal Data without undue delay if:
When an EU Individual makes a request for portability in the circumstances set out above, the Company must take the following steps.
If the Company is not going to respond to the request, it shall inform the EU Individual of the reasons for not taking action and of the possibility of lodging a complaint with the data protection authority in their country.
EU Individuals have the right to have their inaccurate EU Personal Data rectified. Rectification can include having incomplete EU Personal Data completed, e.g. by the EU Individual providing a supplementary statement regarding the data. Where such a request is made, the Company must, unless there is an exemption under applicable law (see Section 13.8 "Exemptions" below), rectify the EU Personal Data without undue delay.
The Company must communicate the rectification of the EU Personal Data to each recipient to whom the EU Personal Data have been disclosed, unless this is impossible or involves disproportionate effort. The Company shall also inform the EU Individual about those recipients if the EU Individual requests it.
EU Individuals have the right, unless there is an exemption under applicable law (see Section 13.8 "Exemptions" below), to restrict the Processing of their EU Personal Data if:
Where Processing has been restricted, the Company must only Process the EU Personal Data (excluding storing them) with the EU Individual’s consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another person or for reasons of important public interest.
Prior to lifting the restriction, the Company must inform the EU Individual of the lifting of the restriction.
The Company must communicate the restriction of Processing of the EU Personal Data to each recipient to whom the EU Personal Data have been disclosed, unless this is impossible or involves disproportionate effort. The Company shall also inform the EU Individual about those recipients if the EU Individual requests it.
EU Individuals have the right, in certain circumstances, to object to the Processing of their EU Personal Data. Where such an objection is made, the Company must, unless there is an exemption under applicable law (see Section 13.8 "Exemptions" below), no longer Process the EU Personal Data:
Where EU Personal Data are processed for direct marketing purposes, EU Individuals have the right to object at any time to the Processing of their EU Personal Data for such marketing. If an EU Individual makes such a request, the Company must stop Processing the EU Personal Data for such purposes.
Where EU Personal Data are Processed for scientific or historical research purposes, EU Individuals have the right to object to such Processing, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.
EU Individuals have the right, in certain circumstances, not to be subject to a decision based solely on the automated Processing of their EU Personal Data, if such decision produces legal effects concerning them or similarly significantly affects them. Where such a request is made, the Company must, unless there is an exemption under applicable law (see Section 13.8 "Exemptions" below), no longer make such a decision unless it:
EU Individuals who are subject to automated decision-making must be notified at the time their EU Personal Data of the fact that they will be subject to automated decision-making and informed of the logic involved and the envisaged consequences of such Processing.
Before responding to any request, the Company should check whether there are any exemptions under applicable law which apply to the EU Personal Data which are the subject of the request. Exemptions may apply under applicable law where it is necessary and proportionate not to comply with the requests described above to safeguard:
Partium complies with the EU-US Privacy Shield Framework as set forth by the US Department of Commerce regarding the collection, use, and retention of personal information from European Union member countries transferred to the United States pursuant to Privacy Shield. Partium has certified that it adheres to the Privacy Shield Principles with respect to such data. If there is any conflict between the policies in this privacy policy and data subject rights under the Privacy Shield Principles, the Privacy Shield Principles shall govern. To learn more about the Privacy Shield program, and to view our certification page, please visit https://www.privacyshield.gov/
With respect to Personal Data received or transferred pursuant to the Privacy Shield Frameworks, Partium is subject to the regulatory and enforcement powers of the U.S. Federal Trade Commission.
Pursuant to the Privacy Shield Frameworks, EU individuals have the right to obtain our confirmation of whether we maintain personal information relating to you in the United States. Upon request, we will provide you with access to the personal information that we hold about you. You may also correct, amend, or delete the personal information we hold about you. An individual who seeks access, or who seeks to correct, amend, or delete inaccurate data transferred to the United States under Privacy Shield, should direct their query to us using the details in Section 12 above. If requested to remove data, we will respond within a reasonable timeframe.
We will provide an individual opt-out choice, or opt-in for sensitive data, before we share your data with third parties other than our agents, or before we use it for a purpose other than which it was originally collected or subsequently authorized. To request to limit the use and disclosure of your personal information, submit a written request to us using the details in Section 12 above.
In certain situations, we may be required to disclose Personal Data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
Partium’s accountability for Personal Data that it receives in the United States under the Privacy Shield and subsequently transfers to a third party is described in the Privacy Shield Principles. In particular, Partium remains responsible and liable under the Privacy Shield Principles if third-party agents that it engages to process the Personal Data on its behalf do so in a manner inconsistent with the Principles, unless Partium proves that it is not responsible for the event giving rise to the damage.
In compliance with the Privacy Shield Principles, Partium commits to resolve complaints about your privacy and our collection or use of your personal information transferred to the United States pursuant to Privacy Shield. European Union individuals with Privacy Shield inquiries or complaints should first contact us using the details in Section 12 above.
Partium has further committed to refer unresolved privacy complaints under the Privacy Shield Principles to an independent dispute resolution mechanism, the BBB EU PRIVACY SHIELD, operated by the Council of Better Business Bureaus. If you do not receive timely acknowledgment of your complaint, or if your complaint is not satisfactorily addressed, please visit www.bbb.org/EU-privacy-shield/for-eu-consumers for more information and to file a complaint. This service is provided free of charge to you.
Contact details for the EU data protection authorities can be found at http://ec.europa.eu/justice/data-protection/bodies/authorities/index_en.htm
If your Privacy Shield complaint cannot be resolved through the above channels, under certain conditions, you may invoke binding arbitration for some residual claims not resolved by other redress mechanisms. See Privacy Shield Annex 1 at https://www.privacyshield.gov/article?id=ANNEX-I-introduction.
We will post any modifications or changes to the Policy in the Website. We reserve the right to modify the Policy at any time, so we encourage you to review it frequently. The “Last updated” legend above indicates when this Policy was last changed. If we make any material change(s) to the Policy, we will notify you by posting the revised Privacy Policy on our Website.