This English version is provided for convenience. In the event of any discrepancy, the German version shall prevail.

Privacy Policy

Last updated: 25 July 2026

1. Controller

The controller within the meaning of the General Data Protection Regulation and other applicable data protection laws is:

Azimut Search & Selection e.K.
trading as AZIMUT Recruitment Solutions
c/o SIRA Steuerberater und Rechtsanwälte
Veritaskai 8
21079 Hamburg
Germany

Proprietor: Stefan Schlatter

Telephone: +49 40 7529 2568
Email: info@azimut-rs.com

Any questions or requests relating to data protection may be addressed to us at any time using the contact details above.


2. General Information on Data Processing

The protection of personal data is important to us. We process personal data confidentially and exclusively in accordance with the applicable data protection laws.

Personal data means any information relating to an identified or identifiable natural person. This includes, for example, names, contact details, professional information, application documents, interview notes and online identifiers.

We process personal data only to the extent necessary to provide our website, communicate with prospective clients, clients and candidates, and perform our recruitment and consulting services, or where another legal basis applies.

In particular, we observe the principles of:

  • lawfulness, fairness and transparency;
  • purpose limitation;
  • data minimisation;
  • accuracy;
  • storage limitation;
  • integrity and confidentiality;
  • and accountability.

3. Legal Bases for Processing

Depending on the purpose of the processing, we process personal data in particular on the following legal bases:

Consent

Article 6(1)(a) GDPR, where the data subject has consented to a specific form of processing.

Consent may be withdrawn at any time with effect for the future. The lawfulness of the processing carried out before the withdrawal remains unaffected.

Contract and Pre-Contractual Measures

Article 6(1)(b) GDPR, where processing is necessary for the performance of a contract or in order to take steps at the request of the data subject prior to entering into a contract.

This may apply in particular to client enquiries, project proposals, applications and support provided to candidates in connection with professional career opportunities.

Legal Obligations

Article 6(1)(c) GDPR, where processing is necessary for compliance with a legal obligation, for example statutory commercial or tax retention requirements.

Legitimate Interests

Article 6(1)(f) GDPR, where processing is necessary for the purposes of the legitimate interests pursued by AZIMUT or a third party and such interests are not overridden by the interests, fundamental rights or freedoms of the data subject.

Our legitimate interests may include in particular:

  • initiating and carrying out recruitment and consulting projects;
  • identifying suitable candidates;
  • maintaining professional contacts;
  • ensuring secure and efficient business operations;
  • documenting business communications;
  • quality assurance and further development of our services;
  • and establishing, exercising or defending legal claims.

Employment-Related Processing

Where applicable in an individual case, processing may also be based on Section 26 of the German Federal Data Protection Act, Bundesdatenschutzgesetz, or BDSG.

Special Categories of Personal Data

We process special categories of personal data within the meaning of Article 9 GDPR only where this is necessary and legally permitted or where explicit consent has been provided.


4. Recipients of Personal Data

Within AZIMUT, access to personal data is limited to those persons who require the data in order to perform their responsibilities.

In addition, personal data may be disclosed in particular to the following categories of recipients:

  • clients and prospective employers in connection with a specific recruitment process;
  • providers of applicant tracking and recruitment software;
  • providers of email, calendar, video conferencing and communication services;
  • cloud, storage and collaboration service providers;
  • providers of artificial intelligence, analytics, automation and integration services;
  • IT, hosting, maintenance and support providers;
  • tax advisers, lawyers and other professional advisers;
  • banks, insurers and payment service providers;
  • public authorities, courts or other public bodies where disclosure is required by law.

Service providers that process personal data on our behalf are contractually engaged in accordance with the applicable legal requirements.

Candidate documents or identifiable candidate profiles are generally disclosed to a specific client only after the candidate has been informed about the relevant position and intended recipient and has agreed to the presentation.


5. Processing Outside the European Economic Area

Some of the providers used by us have their headquarters or affiliated companies outside the European Union or the European Economic Area.

It therefore cannot be completely excluded that personal data may be processed in a third country or accessed from a third country.

Where personal data is transferred to a country outside the European Union or the European Economic Area, this takes place only in accordance with the applicable legal requirements.

Appropriate safeguards may include in particular:

  • an adequacy decision of the European Commission;
  • a valid certification of the recipient under a recognised data protection framework;
  • standard contractual clauses adopted by the European Commission;
  • binding corporate rules;
  • and supplementary technical and organisational safeguards.

6. Storage Period and Deletion

We store personal data only for as long as it is required for the respective purpose.

The specific storage period depends in particular on:

  • the duration of a recruitment or consulting project;
  • the progress of an application or placement procedure;
  • any consent provided;
  • existing contractual relationships;
  • statutory retention obligations;
  • and potential limitation periods and legal defence requirements.

Where the purpose of the processing no longer applies and no statutory or contractual basis exists for further storage, the data will be deleted or anonymised.

Specific rules relating to applicant, candidate and active-sourcing data are set out in the following sections.


Processing When Using Our Website

7. Website Hosting and Server Log Files

Our website is hosted by the following service provider:

IONOS SE
Elgendorfer Straße 57
56410 Montabaur
Germany

IONOS provides us with the technical infrastructure, storage capacity and server services required to operate this website.

According to IONOS, its web hosting services are provided using geo-redundant, ISO-certified infrastructure in European data centres. Due to this geo-redundant structure, data and technical backups may be distributed across several data-centre locations within Europe. The specific data-centre location used for this website may change depending on the technical and operational configuration of the hosting service.

When our website is accessed, IONOS automatically collects data and information from the accessing device and stores it in server log files.

The following data may be processed in particular:

  • the IP address of the accessing device;
  • the date and time of access;
  • the page or file accessed;
  • the previously visited website or referrer URL;
  • browser type and browser version;
  • the operating system used;
  • the hostname of the accessing device;
  • the volume of data transferred;
  • access status and HTTP status code;
  • and technical device and connection information.

The processing takes place in order to:

  • make the website technically available;
  • enable the website to be displayed and used correctly;
  • ensure the stability and functionality of the systems;
  • identify and resolve technical errors;
  • detect attacks, misuse and security incidents;
  • and protect the security of the website and the underlying IT systems.

The legal basis for this processing is Article 6(1)(f) GDPR. Our legitimate interest lies in providing a secure, stable and economically efficient website.

IONOS processes the personal data generated in connection with the hosting services on our behalf. Where required, such processing is governed by a data processing agreement in accordance with Article 28 GDPR.

Server log data is deleted as soon as it is no longer required for the purposes described above. It may be stored for a longer period where this is necessary to investigate a specific security incident, defend against attacks or comply with statutory obligations.

Further information on the processing of personal data by IONOS is available in the IONOS Privacy Policy.


8. Encrypted Transmission

Our website uses an encrypted SSL or TLS connection.

An encrypted connection can be recognised by “https://” in the browser address bar and usually by a padlock symbol.

The purpose of encryption is to prevent data transmitted between the user’s device and our website from being read or altered by unauthorised third parties.


9. Cookies and Comparable Technologies

Our website may use cookies and comparable technologies.

Cookies are small files or pieces of information that may be stored on or read from a user’s device.

Technically Necessary Cookies

Technically necessary cookies may be used to provide basic website functions, for example:

  • page navigation;
  • security;
  • saving language preferences;
  • managing consent;
  • protecting against abusive requests;
  • or controlling the activation of external content.

The storage of or access to technically necessary information takes place on the basis of Section 25(2) of the German Telecommunications Digital Services Data Protection Act, Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz, or TDDDG. Any subsequent processing of personal data is based on Article 6(1)(f) GDPR.

Optional Cookies and Services

Cookies that are not technically necessary, as well as analytics, marketing or external media services, are used only where valid consent has been provided.

The legal basis is Section 25(1) TDDDG in conjunction with Article 6(1)(a) GDPR.

Consent may be withdrawn at any time with effect for the future through the settings provided on the website.

 


10. External Links and Content

Our website contains links to websites operated by external providers.

As a rule, data is transferred to the respective external provider only once the user clicks an external link or actively enables blocked external content.

From that point onwards, the external provider’s own privacy policy applies to its processing activities.

We have no control over what data an external provider collects after its website has been accessed or how such data is processed.


Communication and Appointment Scheduling

11. Contact by Email, Telephone or Contact Form

Where you contact us by email, telephone or contact form, we process the data you provide for the purpose of handling your enquiry.

This may include in particular:

  • name;
  • email address;
  • telephone number;
  • company and position;
  • content and time of the enquiry;
  • files and documents provided;
  • and subsequent communications.

Where the enquiry concerns a contract, proposal, application or possible placement, processing is based on Article 6(1)(b) GDPR.

For other business or general enquiries, processing is based on Article 6(1)(f) GDPR. Our legitimate interest lies in properly handling and documenting communications.

Where a statutory retention obligation applies, processing is additionally based on Article 6(1)(c) GDPR.


12. Microsoft 365

We use Microsoft 365 for business communications, email, calendar functions, document processing, collaboration and, where applicable, video conferencing.

The provider is Microsoft Ireland Operations Limited or an affiliated Microsoft company.

When communicating with us, the following data may in particular be processed within the Microsoft 365 environment:

  • names and contact details;
  • email content;
  • appointment and calendar information;
  • call and meeting data;
  • documents and file attachments;
  • communication metadata;
  • and technical log data.

Depending on the context, processing is based on Article 6(1)(b), Article 6(1)(c) or Article 6(1)(f) GDPR.

To the extent that Microsoft processes personal data on our behalf, Microsoft is engaged on the basis of appropriate contractual arrangements.


13. Microsoft Bookings

Our website contains a link that enables users to schedule appointments through Microsoft Bookings.

Microsoft Bookings forms part of the Microsoft 365 environment. The service is accessed only when the user clicks the appointment-booking link.

The following data may be processed when an appointment is booked:

  • name;
  • email address;
  • telephone number, where provided;
  • preferred appointment time;
  • selected meeting type;
  • messages entered by the user;
  • time zone;
  • and technical connection and log data.

The data is used to coordinate the appointment, send confirmations and reminders, and prepare for the meeting.

The legal basis is Article 6(1)(b) GDPR where the appointment serves to initiate a contract, recruitment process or career-related consultation. In other cases, processing is based on Article 6(1)(f) GDPR.

Our legitimate interest lies in the efficient and reliable organisation of appointments.


Applicant Tracking and Job Portal

14. Coveto Applicant Tracking System

We use the Coveto applicant tracking software to manage job advertisements, applications and candidate processes.

The provider is:

coveto ATS GmbH
Alois-Thums-Straße 11
63667 Nidda
Germany

On the “Current Positions” page, external content from the AZIMUT job portal hosted on a Coveto domain is loaded only after the visitor clicks the designated button.

When the job portal is loaded, technical connection data, including the IP address, browser information and time of access, may be transmitted to Coveto.

Where you apply through the job portal or enter data there, the following information may be processed in particular:

  • name and contact details;
  • curriculum vitae;
  • cover letter;
  • certificates and other application documents;
  • professional history;
  • education and qualifications;
  • salary expectations and other framework conditions;
  • availability;
  • answers to application-related questions;
  • communication and processing history;
  • assessments and interview notes;
  • and technical usage data.

The processing serves in particular to:

  • display current positions;
  • receive and manage applications;
  • communicate with applicants and candidates;
  • document the selection process;
  • assign candidates to specific client projects;
  • comply with deletion and retention periods;
  • and assure the quality of the process.

Depending on the circumstances, processing is based on Article 6(1)(b) GDPR, Article 6(1)(f) GDPR or, where applicable, consent under Article 6(1)(a) GDPR.

Coveto is engaged as a processor.


Recruitment, Applicant and Candidate Processes

15. General Information on Our Recruitment Processes

AZIMUT Recruitment Solutions provides recruitment consulting services in the areas of search and selection, active sourcing, direct approach, personnel placement and embedded recruitment.

We process personal data in order to:

  • identify candidates for specific positions;
  • assess professional qualifications and experience;
  • discuss career interests and framework conditions;
  • evaluate potential suitability for a position;
  • prepare interviews and selection processes;
  • create candidate profiles;
  • present candidates to clients following their consent;
  • coordinate communication between candidates and clients;
  • and document recruitment and consulting projects.

Participation in a recruitment process does not mean that a specific position will be offered or that employment is guaranteed.


16. Categories of Data in Recruitment Processes

Depending on the process, we may process the following personal data in particular:

Master Data and Contact Details

  • name;
  • academic titles;
  • address;
  • email address;
  • telephone number;
  • professional online profiles;
  • and preferred communication channels.

Professional Information

  • current and former employers;
  • positions and areas of responsibility;
  • periods of employment;
  • education and academic studies;
  • vocational training;
  • certificates and further training;
  • professional expertise;
  • leadership and project experience;
  • industry, product and market knowledge;
  • language skills;
  • publications, patents or publicly documented professional contributions;
  • and publicly visible activity in professional networks.

Application and Career Data

  • curriculum vitae and application documents;
  • professional interests;
  • motivation for changing roles;
  • location and mobility preferences;
  • willingness to travel;
  • availability and notice period;
  • working-time and contractual preferences;
  • salary expectations and other framework conditions;
  • and information relating to ongoing selection processes.

Process and Assessment Data

  • interview and call notes;
  • interview results;
  • answers to technical or role-related questions;
  • internal assessments;
  • alignment with defined requirements;
  • open or unresolved points;
  • communication history;
  • project and processing status;
  • and feedback from clients.

We process only information that is relevant to the respective recruitment or consulting purpose.


17. Direct Applications and Unsolicited Approaches

Where you apply for a specific position, send us your curriculum vitae or contact us on your own initiative, we process your data in order to handle your enquiry and assess possible professional opportunities.

The legal basis is generally Article 6(1)(b) GDPR.

Where you expressly consent to being included in our candidate pool or considered for future positions, this further processing is based on Article 6(1)(a) GDPR.


18. Active Sourcing and Direct Approach

As part of our active-sourcing activities, we research professional information about potentially suitable candidates and may contact them directly.

The data does not always originate directly from the data subject.

Potential sources include in particular:

  • professional networks such as LinkedIn or XING;
  • company websites;
  • publicly accessible professional profiles;
  • specialist directories;
  • industry and event directories;
  • trade-fair, conference and association information;
  • publications, specialist articles and patents;
  • publicly available vacancy and project information;
  • recommendations from professional networks;
  • and existing business contacts stored lawfully.

As a rule, we research only information that is clearly professional in nature and relevant to assessing a specific or foreseeable career opportunity.

The legal basis is Article 6(1)(f) GDPR.

Our legitimate interests include:

  • performing our contractually agreed recruitment consulting services;
  • identifying suitable specialists and executives;
  • contacting individuals for whom a specific professional opportunity may be relevant;
  • and supporting our clients in filling vacant positions.

When balancing the respective interests, we take into account in particular:

  • the professional nature of the information;
  • the type of source;
  • the expected use of professional networks;
  • the relevance of the position concerned;
  • the scope of the information processed;
  • and the impact of the contact on the data subject.

We inform the data subject about the processing and the source of the data no later than at the time of the first contact or within the statutory period.

A person who has been contacted may object to further processing and communication at any time.


19. Disclosure to Clients

An identifiable presentation to a client does not take place solely on the basis of an internal search or AI-assisted assessment.

Before we disclose a curriculum vitae, candidate profile or other identifiable information to a specific client, we generally inform the candidate about:

  • the position concerned;
  • the company or intended recipient;
  • the principal framework conditions;
  • and the scope of the intended disclosure.

The information is transmitted only after consultation with and approval by the candidate.

Depending on the structure of the recruitment process, the disclosure is based on Article 6(1)(a) or Article 6(1)(b) GDPR.

The client subsequently processes the data received under its own data protection responsibility.


20. Embedded Recruitment and Work Within Client Systems

As part of embedded-recruitment or interim-recruitment projects, we may be integrated directly into a client’s processes and systems.

Depending on the contractual and organisational structure, AZIMUT may act:

  • as an independent controller;
  • as a processor acting on behalf of the client;
  • or under another agreed allocation of responsibilities.

Where data is processed exclusively within the client’s systems and in accordance with the client’s instructions, the client’s privacy information will additionally apply.

The specific allocation of responsibilities is determined on a project-by-project basis.


21. Candidate Pool

With the candidate’s consent, we may store professional information beyond an individual recruitment process in order to contact the candidate about suitable future positions.

The legal basis is Article 6(1)(a) GDPR.

Consent is voluntary and may be withdrawn at any time with effect for the future.

Unless a different period is specified in the consent, we generally store candidate-pool data for up to 24 months from the last material contact or update.

Before the end of this period, the candidate may be asked to renew or update the consent.

Unless the consent is renewed, the data will subsequently be deleted or anonymised unless another legal basis applies.


22. Storage Period for Applicant and Candidate Data

Data relating to a specific position or recruitment project is generally processed for the duration of the selection and placement process.

Where no placement or recruitment takes place, the data will be deleted no later than six months after completion of the relevant process, unless:

  • consent to further storage has been provided;
  • inclusion in the candidate pool has been agreed;
  • another specific professional opportunity is being pursued;
  • or statutory or legal reasons require continued storage.

Temporary continued storage may be necessary in particular to establish, exercise or defend legal claims.

In the event of a successful placement, project-related evidence, correspondence and billing information may be stored for a longer period in accordance with statutory and contractual retention obligations.

Pure active-sourcing research data is deleted or anonymised where:

  • the research proves to be incorrect;
  • the person is not relevant to the search concerned;
  • no contact is initiated;
  • the person is not interested in further communication;
  • or the person has objected to the processing.

Where necessary, we may retain minimal contact information in a suppression list following an objection in order to ensure that the objection is respected permanently and to prevent renewed unwanted contact.


23. Special Categories of Personal Data

We do not intentionally collect or analyse:

  • health data;
  • information concerning racial or ethnic origin;
  • political opinions;
  • religious or philosophical beliefs;
  • trade union membership;
  • genetic or biometric data;
  • or information concerning sexual orientation.

Where such information is exceptionally included in documents provided voluntarily, it will be processed only if this is necessary for the specific purpose and legally permitted.

The processing may in particular be based on explicit consent under Article 9(2)(a) GDPR.

We recommend that application documents do not include information that is not necessary for the professional assessment.


Use of Artificial Intelligence

24. Our Principles for the Use of AI

AZIMUT uses artificial intelligence and automated systems as supporting tools in recruitment, search-and-selection and consulting processes.

AI systems support our recruitment consultants in structuring information, preparing search and selection processes and assuring the quality of our work.

They do not replace personal assessment by a human being or the professional responsibility of the respective recruitment consultant.

AI-generated content, recommendations and assessments are generally reviewed by us before they are:

  • used in a recruitment process;
  • used to approach a person;
  • included in a candidate profile;
  • or transmitted to a client.

Our objective is not to replace human recruitment consulting. AI is intended to support administrative and analytical work so that more time is available for personal communication, professional assessment and responsible decision-making.


25. Areas in Which Artificial Intelligence May Be Used

AI systems may be used in particular for the following tasks:

  • analysing job descriptions and project briefings;
  • preparing structured requirement, competency and skill profiles;
  • developing target-candidate profiles and candidate personas;
  • developing search strategies and target-company lists;
  • supporting market, company and candidate research;
  • structuring and summarising professional information;
  • analysing curricula vitae and professional online profiles;
  • comparing qualifications and experience with defined job requirements;
  • identifying possible matches, deviations and points requiring clarification;
  • preparing candidate-specific interview questions;
  • drafting candidate approaches and other communications;
  • preparing candidate profiles and professional summaries;
  • supporting documentation and quality assurance;
  • and automating administrative and technical process steps.

Where AI systems generate matching scores, assessments, prioritisation or rankings, these are used solely as working aids and do not constitute a final assessment of an individual.


26. Data Processed When AI Is Used

Depending on the task, the following data may in particular be processed with the support of AI:

  • job and project requirements;
  • professional master data;
  • publicly available professional information;
  • information from curricula vitae and professional profiles;
  • education, qualifications and professional experience;
  • professional expertise and project experience;
  • location, mobility and availability;
  • motivation for changing roles and professional interests;
  • salary expectations and other framework conditions;
  • interview and call notes;
  • interview information;
  • communication content;
  • and internal professional assessments.

We limit the processing to the data required for the respective task.

Where sufficient for the intended purpose, we use reduced, abstracted, anonymised or pseudonymised information.


27. AI, Cloud and Automation Services Used

Depending on the process and technical configuration, we may use systems provided by the following providers in particular:

OpenAI

We may use OpenAI services, including ChatGPT and, where applicable, API-based models.

Potential processing purposes include:

  • text analysis;
  • structuring information;
  • preparing drafts;
  • matching competencies and requirements;
  • developing search strategies;
  • preparing interview questions;
  • and supporting documentation and quality assurance.

Microsoft

We may use Microsoft services, including:

  • Microsoft 365;
  • Azure;
  • Copilot or other AI functions;
  • and cloud-based storage, analysis and automation services.

Google

We may use Google Workspace and Gemini, particularly for:

  • document processing;
  • spreadsheets and structured project data;
  • file storage;
  • collaboration;
  • analysis and summarisation;
  • and AI-assisted functions.

Make

We may use Make as an automation and integration platform to manage defined process steps and data transfers between the systems we use.

The data processed may include in particular:

  • project identifiers;
  • status information;
  • structured requirement data;
  • candidate and company identifiers;
  • documents;
  • communication drafts;
  • and technical event and log data.

Automations are configured for defined purposes and are intended to transmit only the data required for the respective process step.

Other Services

Depending on client requirements and project configurations, additional AI, cloud, applicant-tracking, research or integration services may be used.

Before processing personal data in a new service, we review in particular:

  • the intended purpose;
  • the data required;
  • the contractual arrangements;
  • access options;
  • storage and deletion functions;
  • technical security settings;
  • potential transfers to third countries;
  • and the available options for preventing use for general model-training purposes.

28. Use of Data for Model Training

AZIMUT does not knowingly make personal candidate, applicant or client data available for the training of generally available AI foundation models.

Where available, we use business subscriptions, API access or administrative settings under which business data entered into the system is not used for the general training or improvement of publicly available models.

Optional settings allowing business content to be used for general model improvement are not enabled by us where personal candidate, applicant or client data may be affected.

Before using an AI service to process personal data, we review the respective account settings and applicable data protection conditions.

 


29. No Decisions Based Solely on Automated Processing

AZIMUT does not make decisions based solely on automated processing that produce legal effects concerning a candidate or similarly significantly affect that person.

In particular, an AI system does not independently decide:

  • whether a person is contacted;
  • whether an application is accepted or rejected;
  • whether a candidate is presented to a client;
  • whether a person is invited to an interview;
  • whether a person is prioritised or excluded from a process;
  • or whether employment or engagement takes place.

The professional assessment and decision regarding further processing are made by an AZIMUT recruitment consultant.

The final selection and hiring decision is made by the respective client.


30. No Emotion Recognition or Biometric Assessment

We do not use AI systems to:

  • infer emotions from voice, facial expression or behaviour;
  • categorise individuals based on biometric characteristics;
  • infer personality traits from facial images or speech patterns;
  • or automatically estimate sensitive characteristics.

Photographs are not used to automatically assess suitability, personality or performance.


31. Human Oversight and Quality Control

Our recruitment consultants are responsible for:

  • defining the purpose of the AI use;
  • reviewing whether the data used is necessary;
  • distinguishing between verifiable facts and assessments;
  • critically reviewing AI-generated results;
  • identifying possible errors and incorrect conclusions;
  • considering potential bias or discrimination;
  • verifying information with the data subject where appropriate;
  • and making material decisions themselves.

AI systems may generate incorrect, outdated or incomplete results. AI output is therefore not treated as factual information without review.

Candidates may contact us at any time if they would like further information about the use of AI in their specific recruitment process or wish to request human review of an AI-assisted assessment.


Clients, Prospective Clients and Business Partners

32. Processing of Client and Contact-Person Data

In connection with the initiation and performance of client and consulting projects, we process in particular:

  • names;
  • business contact details;
  • company and position;
  • communication content;
  • proposal, contractual and billing data;
  • project requirements;
  • job and competency profiles;
  • appointment and meeting data;
  • and project-related documentation.

The processing serves in particular to:

  • handle enquiries;
  • prepare proposals;
  • perform contracts;
  • manage projects;
  • communicate with clients;
  • issue invoices;
  • document project activities;
  • and maintain existing business relationships.

The legal basis is Article 6(1)(b) GDPR.

Where a contact person at a company is not personally a party to the contract, processing is generally based on Article 6(1)(f) GDPR.

Our legitimate interest lies in efficiently managing and maintaining business relationships.

Business records subject to statutory retention requirements are stored for the duration of the applicable commercial and tax-law retention periods.


Professional Networks and Social Media

33. LinkedIn, XING and Comparable Professional Platforms

AZIMUT uses professional networks such as LinkedIn and XING in particular for:

  • corporate communications;
  • professional networking;
  • publishing vacancies;
  • candidate research;
  • active sourcing;
  • direct approach;
  • and maintaining professional contacts.

Where you visit our company profile or communicate with us through such a platform, the respective platform operator initially processes personal data in accordance with its own privacy policy.

Where you send us a message through a platform or interact with our content, we may process in particular:

  • profile name;
  • professional profile information;
  • content and time of the message;
  • reactions and comments;
  • and subsequent communications.

Depending on the context, AZIMUT processes this data on the basis of Article 6(1)(b) or Article 6(1)(f) GDPR.

Where information from professional networks is used for active sourcing, the provisions in the section entitled “Active Sourcing and Direct Approach” additionally apply.


Data Security and Data Subject Rights

34. Technical and Organisational Measures

We implement appropriate technical and organisational measures to protect personal data against:

  • loss;
  • destruction;
  • alteration;
  • unauthorised disclosure;
  • unauthorised access;
  • and other unlawful processing.

Such measures may include in particular:

  • role-based and permission-based access;
  • strong password policies;
  • multi-factor authentication;
  • encryption;
  • secured end devices;
  • regular software updates;
  • backups;
  • logging;
  • data processing agreements;
  • data minimisation;
  • and internal policies governing candidate, client and AI data.

Security measures are reviewed and further developed in line with the state of the art and the respective level of risk.


35. Rights of Data Subjects

Subject to the applicable legal requirements, data subjects have the following rights in particular:

Right of Access

You may request information as to whether and which personal data relating to you is processed by us.

Right to Rectification

You may request the correction of inaccurate data and the completion of incomplete data.

Right to Erasure

You may request the erasure of your personal data where the statutory requirements are met.

Right to Restriction of Processing

You may request that the processing of your data be restricted where the statutory requirements are met.

Right to Data Portability

Where the statutory requirements are met, you may receive data that you have provided to us in a structured, commonly used and machine-readable format or request that the data be transmitted to another controller.

Right to Withdraw Consent

Consent may be withdrawn at any time with effect for the future.

Right to Lodge a Complaint

You have the right to lodge a complaint with a data protection supervisory authority.

You may in particular contact a supervisory authority at your habitual residence, your place of work or the place of the alleged data protection infringement.


36. Right to Object Under Article 21 GDPR

Where we process personal data on the basis of Article 6(1)(f) GDPR, you have the right to object to the processing at any time on grounds relating to your particular situation.

We will then no longer process the data concerned unless:

  • we demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms;
  • or the processing is required for the establishment, exercise or defence of legal claims.

Where personal data is processed for direct marketing purposes, you may object to such processing at any time without stating any reasons.

An objection may be submitted informally to info@azimut-rs.com.


37. Requirement to Provide Data

The provision of personal data is generally voluntary.

Without certain information, however, we may be unable to:

  • handle an enquiry;
  • coordinate an appointment;
  • assess an application;
  • discuss a professional opportunity with you;
  • or perform a contract or recruitment project.

We collect only the data required for the respective purpose.


38. Updates to This Privacy Policy

We review this Privacy Policy regularly.

An update may become necessary in particular as a result of:

  • changes in legislation;
  • new regulatory or judicial guidance;
  • changes to our website;
  • new recruitment processes;
  • new AI or cloud services;
  • or changes to our technical infrastructure.

The current version published on this website applies.


39. Objection to Unsolicited Advertising

The use of the contact details published in the legal notice or this Privacy Policy for the purpose of sending unsolicited advertising or information materials is hereby objected to.

We reserve the right to take legal action in the event of unsolicited advertising, in particular spam emails.