ADE / Lisa

PRIVACY INFORMATION

Public employer and job sources

Information under Article 14 GDPR · Version 1.6 · 15 August 2026
This information covers limited measurement of publicly accessible job sources and a time-limited depth analysis. Applicant and user data are not part of this processing.

1. Controller and privacy contact

Stephan Popp, sole proprietor (ADE), Peterssteinweg 14–16, 04107 Leipzig, Germany

Email for data-protection rights and objections: optout@ade.international

Data protection officer – functional contact: data@ade.international

Current online version: https://datenschutz.ade.international

2. Processing covered by this information

ADE conducts limited source measurement on publicly accessible employer and job sources. The purposes are to discover and perform technical and legal pre-checks on eligible sources, count publicly offered jobs, and measure coverage and data quality. A separately approved, time-limited depth analysis may also structure published information about work, requirements and working conditions.

This information applies only where processed information may relate to a natural person, particularly sole traders, self-employed professionals or person-linked business names. Information concerning legal persons is generally not personal data as such. Application forms, CVs, applicant profiles and applicant contact data are not collected in this source measurement.

3. Purposes and legal basis

Where personal data are involved, processing is based on Article 6(1)(f) GDPR. ADE's legitimate interests are to:

ADE limits processing to the publicly apparent business and job context. Personal designations are detected only transiently and then suppressed where they are not necessary. Private characteristics are not evaluated and no personal profile is created.

4. Sources and categories of data

The data originate from publicly accessible sources, including:

Depending on the measurement stage, the following categories are processed:

Applicant documents, private contact details and additional information about owners, partners, employees or contact persons are neither intentionally extracted nor stored in structured form. Information carried incidentally in job text is not enriched and is removed no later than that text under section 6; uncertain classifications remain open.

5. Recipients and transfers

Access is limited to authorised internal roles and contractually bound service providers for hosting, database operation, backups, technical administration, email and domain operation, insofar as required for the stated purposes. These service providers are selected and controlled by function, safeguards and processing location within Germany or the EU/EEA.

Personal data covered by this information are not transferred to recipients outside the EU or EEA in the described measurement path and are not published as a public source or person directory. On request, the actual relevant recipients are provided to the data subject in accordance with Article 15 GDPR.

6. Retention

Data categoryPeriod / criterion
Source, route and classification datano more than 12 months from creation or the most recent documented review; earlier where the purpose ends or a prevailing rectification, erasure, restriction or objection ground applies
Transient job textwithout undue delay after analysis and no later than 72 hours after completion of the relevant analysis pass
Job-level depth-analysis results30 days after sample review and no later than 90 days after the relevant pass begins
Technical security logsnormally 7 days; justified incident extracts for no more than 30 days
Minimal blocking or objection recordfor as long as needed to honour an effective block or objection, subject to periodic necessity review

Only demonstrably non-personal, sufficiently aggregated measurement results may be used for business assessment and expansion planning beyond these periods. Low counts and the risk of re-identification are taken into account.

7. Automated decisions

Source measurement does not make a solely automated decision producing legal or similarly significant effects on natural persons (Article 22 GDPR) and does not create a profile of natural persons.

8. Your rights

Where data can be linked to you, you may request access, rectification, erasure and restriction subject to the statutory conditions. You may also object under Article 21(1) GDPR on grounds relating to your particular situation. You do not need to provide a special justification for an access request. Data portability applies only where its statutory conditions are met.

A domain, host name, public URL, job reference or another plausible link will normally be sufficient to locate a record. Additional identity evidence is requested only where there are reasonable doubts about identity. In response to an access request we provide the personal data actually concerned and the required information on their source and recipients; unrelated internal system knowledge or the complete general data schema is not part of an individual access response.

Separately from the rights of natural persons, source operators may use the same contact route for technical, licensing or organisational review, blocking and removal requests.

You may lodge a complaint with a data protection supervisory authority. In Saxony, this is the Saxon Commissioner for Data Protection and Transparency; you may also contact any other competent supervisory authority.

9. Public information instead of collecting additional contact data

ADE generally does not hold separate contact data for potentially affected sole traders or self-employed professionals in the measurement path. Individual notice would therefore often require collecting additional personal contact data solely for notification. ADE records separately for each affected processing class whether the conditions of Article 14(5)(b) GDPR are met. Where they are met, this continuously accessible notice is one safeguard. Where the exception does not apply, the timing requirements of Article 14(3) GDPR apply.

10. Security, language and updates

ADE applies appropriate technical and organisational measures, including role-based access, data minimisation, separation of review and content data, erasure and blocking processes, and periodic controls. The German version is the controlling master; this English version is intended to be substantively equivalent. Material changes to purposes, categories of data, recipients, transfers or retention are reflected in this information before activation.