Data Privacy

Data protection notice for UNITED

1. General Information

a) Introduction

The following data protection notice is intended to inform you about the processing of your personal data as part of METRO’s internal social network UNITED (hereinafter referred to as UNITED) and your rights regarding this processing.

b) Data Controller

The METRO Company, where you are employed (“METRO”), is the data controller according to GDPR, and thus for the outlined data processing. Details about the company and the corresponding contact details can be found in the general data protection notices that are made available to you by your employer.

d) Data Protection Officer

You can contact our data protection officer at any time. Details about the corresponding contact details can be found in the general data protection notices that are made available to you by your employer.

2. Information Regarding the Processing

UNITED is METRO’s group-wide social network/intranet. UNITED intends, through its functionalities, to be the central internal communication, information and knowledge platform of the METRO Group. UNITED offers the possibility to network and exchange information across national, department and company borders.

a) Validity of the Data Protection Notice
You get access to the active voluntary functions of UNITED with your approval to the Terms of Use. Currently the voluntary functions include:

  • additional information about you, e.g. profile picture, interests, professional competencies, date of birth and languages, which you can add to your profile
  • active use of the noticeboard
  • use of the chat function
  • comments
  • use of the “following”, “share” and “like” function
  • participation in surveys

b) Data Categories and Purposes of the Processing

UNITED collects, processes and stores personal data only if you voluntarily provide it during your use, if the data is transmitted from a previous METRO system (address book of user contact management/Active directory) or if they are created during the active use of UNITED. The collected data will only be used internally in the METRO group.

Data which is processed in UNITED are in particular your personal profile with name, contact data, organisation information and additional data provided voluntarily, especially your posts and actions. The personal data will be stored in a database. This data will not be evaluated.

When operating UNITED, personal data on the use of UNITED as well as individual components/functions arises. In UNITED an administrator can see the number of logins and the date of the last login for error analysis. There is no further evaluation of personal data.

In addition, the following anonymous data is evaluated via the system’s statistical functions: active Users, weekly visitors, weekly pageviews, weekly posts, weekly comments, weekly “likes”.

Purpose of the processing of the personal data is the daily collaboration and communication in the company, the description of the individual user profile, error analysis and future development of UNITED.

c) Legal Basis for the Processing

Given the fact that UNITED is used as a central communication, information and knowledge platform within METRO and you, as an employee, should be reachable via these communication means, the data processing is necessary for implementing the employment relationship and is carried out legally based on Art. 88 (1S)(1) GDPR in association with the applicable national legal basis (in Germany: Section 26 (1)(1) BDSG) or Art. 6 (1)(1)(b) GDPR as far as UNITED is used for business purposes.

As far as you add voluntary information to your personal profile or use UNITED’s functions for unofficial purposes, the data processing is carried out legally based on Art. 6 (1)(1) (a) GDPR. By adding the voluntary information you agree with the data processing by METRO.

The collection of data with the system’s statistical function and the control of the logins take place to update and improve UNITED. This processing is necessary to pursue our legitimate interests in system security and system maintenance respectively the optimization of the functions and is carried out legally based on Art. 6 (1)(1)(f) GDPR.

d) Voluntary/Mandatory Provision of Data

The provision of some personal data is voluntary, e.g. comments, shares, likes, etc. You are not obligated to provide us with this personal data, nor is it required to fulfil legal or contractual obligations. If you do not provide us with this personal data, there will be no consequences to you, except that we will not be able to take this data into account for the purposes of data processing.

If you do not agree with transferring personal data from the active directory to your user profile, you cannot use UNITED with all functions. You will only get a read-only access. With read-only access it will be possible to access public information in UNITED without however being able to use further functions (e.g. through comments, blog posts, creating pages or workspaces). The provision of your personal data transmitted from the Active Directory to access UNITED (with User Account or read-only access) is obligatory and necessary for the fulfilment of the employment contract concluded with you.

e) Retention period

You can edit and delete posts and data created by you at any time.

Deletion of personal data after a user departs:

Since the social network will be used as a central knowledge database of the Group, generally no content will be deleted. If you leave the METRO Group, withdraw your consent to the Terms of Use or get your individual METRO account deleted you were provided with as an external, your profile will be set to inactive within three working days. The profile is thereby not visible to other Users. You can access UNITED on a read-only basis. Your posts will be kept, but will only be shown as anonymous, this means your name will not be shown in connection with the post. Your profile will be deleted 30 days following your departure or the revocation.

If there is a change in employer within the METRO Group and your e-mail address changes, you will receive a new User Account. The old User Account will be deactivated at the time you leave your old employer. If you rejoin UNITED within 30 days, all the anonymised content will be reassigned to you. If however you rejoin after 30 days, no reassignment of your anonymised content can take place.

In addition, we retain your data longer than for the above-mentioned period, where we are legally obliged to transmit the stored data to authorities in the event of a request. The retention and transmission of your personal data to authorities for the purpose of fulfilling a legal obligation is carried out legally based on Art. 6 (1)(1)(c) GDPR.

f) Cookies and Tracking

To make your visit more attractive at UNITED, we use so-called “cookies”. A “cookie” is a small text file that is used to collect information about website activity. We use necessary cookies as well as analyse cookies. Necessary cookies are required for operability of UNITED. If you decide to decline the use of cookies, the personalization functions are limited. Within UNITED the following types of cookies are used:

  • Session ID: the session ID is an identification number that is created on the server to detect several related user requests and is subsequently assigned to a session. This identification number is stored locally on the user’s computer and will be used again at a later visit to UNITED.
  • Flash cookie: a flash cookie collects user-related data and stores it locally on the user’s computer so that on a subsequent visit to UNITED user-specific information is displayed to the user.
  • Security tokens: A security token is used to provide protection against attacks or infiltration by third parties.

All major web browsers can be configured to allow incoming cookies to be accepted only after confirmation by the user or they can generally be declined.

This website features Google Analytics, a web analytics service provided by Google LLC (“Google”). Google Analytics uses so-called “cookies”, text files, that are stored on your computer and allow us to analyse your use of our website. The cookie-generated data regarding your use of this website will generally be forwarded to a Google server in the USA and stored there. In case of activation of the IP anonymisation on this website, your IP address will, however, be previously truncated by Google within Member States of the European Union or other states which are parties to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be sent to a Google server in the USA and truncated there. Google will use this information on behalf of the operator of this website to evaluate your use of the website, to compile reports on website activity and to provide other services related to website and internet use to the website operator.

The IP address transmitted by your browser as part of Google Analytics is not merged with other data held by Google. The data sent by us and linked to cookies, user identifications (e.g. user ID) or advertising IDs are automatically deleted after 14 months. Data whose retention period has been reached is automatically deleted once a month.

You may block the storage of cookies by selecting the appropriate settings on your browser. Please be aware, however, that this may prevent you from using the full range of features of this website. Furthermore, you may prevent the tracking and processing of cookie-generated data regarding your use of this website (including your IP address) by Google by downloading and installing the browser plugin available at the following link: http://tools.google.com/dlpage/gaoptout?hl=de.

You can opt out of tracking by Google Analytics by clicking on the following link. An opt out cookie will be set which prevents the tracking of your data in the future when you visit this website: Disable Google Analytics

This website uses Google Analytics with the extension “_anonymizeIp()”. IP addresses are, therefore, further processed in shortened form. Tracing to a specific user can, therefore, be prevented. If the data collected concerning yourself has a personal reference, this will, therefore, be excluded immediately and the personal data immediately erased.

We use Google Analytics to enable us to analyse and regularly improve the use of our website. The statistics obtained allow us to improve our website and to make its design more interesting for you as user. Legal basis for the use of Google Analytics is Art. 6 (1)(1)(f) GDPR.

g) Recipient

UNITED uses the product Coyo of the company COYO GmbH as a basic software. The data is stored exclusively on the Group’s own servers in Germany. Since UNITED is a group-wide communication platform that is also used by METRO companies abroad, the data you enter can be accessed abroad, including in countries outside the European Union or the European Economic Area, insofar as METRO companies use United there. Your personal data will be transmitted to internal service providers (METRO Digital GmbH, METRO AG and possibly other internal service providers such as Shared Service Center) for the purpose of administration, support and system maintenance. Internal access to your data is regulated by a strict authorisation concept.

3. Additional Notes for the UNITED App

After two-factor authentication, UNITED is also available via the corresponding UNITED App. The UNITED App can be downloaded from the App Stores of the most popular providers. The following provisions inform you of the nature, scope and purpose of the processing of personal data in the context of your use of the UNITED App:

What data will be transferred to the App Store when you download the App?

When you download the App, the information necessary for this shall be transferred to the respective App Store, i.e. in particular your user name, your email address, the customer details relating to your account, the time of the downloading, any payment information and the individual identifiers of your terminal device. However, we have no influence over this data processing and are not responsible for it. In this respect, only the data protection policy for use of the respective App Store, which you can access there, shall be applicable.

What data will be collected by METRO when you download the App?

No personal data shall be collected by METRO or be transmitted by the respective App Store to METRO merely as a result of downloading of the App from the respective App Store to your smartphone. No data shall be collected by METRO or transmitted to METRO before the App is first used.

What data from you will be processed when you use the App?

If you have declared your consent hereto by setting the App accordingly or by means of the system settings of your terminal device, the App shall access the following data in order to facilitate individual services of the App (e.g. upload content) or to optimise these services:

  • camera data (for taking pictures to directly upload them to UNITED, e.g. for your profile picture)
  • images from your terminal device's picture gallery (for uploading pictures to UNITED, e.g. for your profile picture)

You shall not be obliged to give your consent. However, we shall not use these data if you do not give your consent. You may then be unable to use all features of our App.

The legal basis of this processing lies in Art. 6 (1)(1)(a) GDPR insofar as you have given us your consent. You may revoke this consent at any time by means of the corresponding settings in the App or in the system settings of your terminal device.

How can you monitor the use of your data?

You may revoke at any time with effect for the future any consent that you have given us. You can do so by contacting the contacts laid down in this Data Protection Notice or - insofar as your smartphone has this technical capability - by means of direct settings in your terminal device offering such capabilities.

4. Your Rights

As the data subject, you can contact our data protection officer at any time by sending an informal communication to exercise your rights according to GDPR. These rights are as follows:

  • The right to receive information about the data processing and a copy of the processed data (Right of access Art. 15 GDPR)
  • The right to demand the rectification of inaccurate data or the completion of incomplete data (Right to rectification, Art. 16 GDPR)
  • The right to demand the erasure of personal data and, if the personal data has been made public, the information to other controllers about the request of erasure (Right to erasure, Art. 17 GDPR)
  • The right to demand the restriction of the data processing (Right to restriction of processing, Art. 18 GDPR)
  • The right to receive the personal data concerning the data subject in a structured, commonly used and machine-readable format and to request the transmittance of this data to another controller (Right of data portability, Art. 20 GDPR)
  • The right to object to the data processing in order to stop it (Right to object, Art. 21 GDPR)
  • The right to withdraw a given consent at any time in order to stop a data processing that is based on your consent. The withdrawal does not affect the lawfulness of the processing based on the consent before the withdrawal (Right of withdrawal, Art. 7 GDPR)
  • The right to lodge a complaint with a supervisory authority if you consider the data processing to be an infringement of the GDPR (Right to lodge a complaint with a supervisory authority, Art. 77 GDPR).

Information on your right to object under 21 GDPR

You shall have the right to object at any time, on grounds relating to your particular situation, to any processing of your data that takes place on the basis of Art. 6 (1)(1)(f) GDPR (data processing on the basis of a balancing of interests). This shall also apply to any profiling, as defined by Art. 4, no. 4 GDPR, based on this provision. If you lodge an objection, we shall no longer process your personal data, unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the assertion, exercise or defence of legal claims. Such objection may be lodged informally and should, if possible, be addressed to your Data Protection Officer.

We reserve the right to make changes to this Data Protection Notice and will inform you about any changes accordingly.

Data protection notice for this website

Thank you for your interest in our website and our services. For us, data is the basis for excellent service. However, our most important asset is the trust of our customers. Protecting customer data and using it only in the way our customers expect, is our number one priority. The following privacy notice is therefore intended to inform you about the processing of your personal data and your rights in this processing in accordance with the European General Data Protection Regulation ("GDPR") and other applicable data protection regulations.

1. General information

1.1 Responsible for the operation of this website is METRO AG, Metro-Straße 1, 40235 Duesseldorf, Germany (hereinafter "METRO", "we" or "us"). METRO attaches great importance to the protection of your personal data.

1.2 If you have any questions about privacy and data protection, you can contact our data protection officer using the following contact details: METRO AG, Data Protection Officer, Metro-Straße 1, 40235 Duesseldorf, Germany, email: datenschutz@metro.de.

1.3 This privacy policy explains how we collect, process and use personal data in connection with the provision of our website. Personal data are individual details about your personal or factual circumstances. We process your personal data that we collect, store and use exclusively within the framework of the applicable legal regulations.

2. Processing of Personal Data and Transfer to Third Parties

2.1 Some personal data is collected automatically via your device (computer, mobile phone, tablet, etc.) when you use our website. The IP address currently used by your device, date and time, the typ of browser and operating system of your device and the pages accessed are recorded. This is done for the purposes of data security and to optimise our offer as well as to improve our website. Any other analysis, with the exception of statistical purposes, and that always in anonymous form, is only carried out within the scope of this privacy policy. This personal data is processed on the basis of Article 6(1), first sentence, letter f) GDPR. The protection of our website and the optimisation of our services constitute a legitimate interest of METRO.

2.2 If you contact us (for example via an enquiry at datenschutz@metro.de), we only collect, process and use the personal data that you have made available to us and that is necessary to process and respond to your enquiry.

2.3 You can register for our information service using a separate form. After you have filled out the relevant registration form and, by doing so, sent us your personal data supplied therein as well as your consent to the use of your data for the purposes selected by you, we will send you a confirmation email. The sending of our information takes place only with your consent and is based on Article 6(1), first sentence, letter a) GDPR. You can opt out of receiving the information at any time via the respective link at the bottom of each message that you receive from us.

2.4 In order to enable the data processing procedures mentioned in this privacy policy, we use service providers as data processors within the meaning of Art. 28 GDPR, for example service providers for sending e-mails, maintenance and other services. These are both external service providers and service providers within METRO located in countries within and outside the European Union (EU) and the European Economic Area (EEA). Through contractual arrangements, we ensure that these service providers process personal data in accordance with the GDPR in order to guarantee a high level of privacy, even if personal data is transferred to a country with a different level of data protection for which no adequacy decision by the EU Commission exists. No further transmission of personal data to other recipients takes place unless we are legally obliged to do so. For more information on appropriate security measures for international data transfer or a copy thereof, please contact our data protection officer: datenschutz@metro.de.

3. Cookies

3.1 We use so-called cookies to make our services attractive to visitors and to enable the use of certain functions. These are small text files that are stored on your device. Some of the cookies we use are deleted after the end of the browser session, i.e. after closing your browser (so-called session cookies). Other cookies remain on your device and enable us to recognise your browser on your next visit (persistent cookies). You can configure your browser so that you are notified when you receive a cookie and you can decide on an individual basis if you want to accept them; you can also refuse cookies for certain cases or generally refuse them. For more information, see the help section of your web browser. If you do not accept cookies, the functionality of our website may be limited. By accepting our "cookie banner", you agree to the processing of your personal data through cookies. This personal data is processed on the basis of Article 6(1), first sentence, letter a) GDPR. To learn more about cookies and other possible web tracking tools and the choices you have in this regard, please visit: http://youronlinechoices.eu/ (for users in the European Union). The following section takes a closer look at specific cookies.

3.2 On this website, we use Siteimprove Analytics, a web analysis service of Siteimprove GmbH, Kurfürstendamm 56, 10707 Berlin, Germany. We use Siteimprove Anlaytics to analyse website use by users in order to monitor the functionality of our websites (e.g. accessibility of our texts, functionality of links, etc.) and to provide our visitors with the most pleasant and useful experience possible. For example, your anonymised IP address, your browser and operating system, the URL visited, page title, length of stay and other statistical data are temporarily collected, which are used exclusively for quality checks. Their evaluation helps us to continuously improve our services for you.

The data Siteimprove collects and processes from European customers is stored in the EU. The dedicated data centres are located in Germany and Denmark.

3.3. We also work with the following external service providers, who use cookies themselves but do not receive any personal data from us:

  • Pingdom Monitoring – monitors the technical functions and availability of our website.
  • Taleo – job portal, where we publish our job offers, which you can also access via our website
  • Investis – display of the stock ticker and a mini chart on our website in the Investor Relations section
  • SOLR instances (internal search services) – a powerful full-text search technology within our website

Cookies - Information and Settings

Cookies - Information and Settings

This website uses cookies to provide you with the best possible service. If you do not wish to use certain cookies, you can activate or deactivate them at any time on this page. Further information on the use of cookies can be found below. Some cookies are necessary for the operation of the website and cannot be disabled.

You can activate or deactivate cookies yourself below. We offer you the possibility to make settings in order to agree to this use, to revoke your consent or to object to the use.

In accordance with Art. 49 para. 1 lit. a) GDPR, your consent also includes the transfer of data to recipients in third countries without an adequate level of data protection, such as the USA in particular, as described in detail in the cookie information. There is a risk that your transmitted data may be accessed by authorities in these third countries for control and monitoring purposes and that no effective legal remedies are available against this.

4. Provision of personal data and retention periods

The provision of your personal data is voluntary. You are not legally obliged to make your personal data available to us. If you choose not to make your personal data available to us, this has no consequences for you, except that you cannot use our services. Personal data that you make available to us via our website will only be stored until the purpose for which it was processed has been fulfilled or until you tell us to delete your data. We allow you to inspect, modify and delete your data stored with us via a safe procedure, by following the references that you receive from us in all correspondence. Deviating retention periods may, however, result from a legitimate interest of METRO (e.g. to guarantee data security and to prevent misuse). Personal data that we have to store due to legal or contractual retention obligations will be blocked.

5. Social media

Our website contains simple links to the following social media networks:

  • Facebook (operated by: Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA)
  • Twitter (operated by: Twitter Inc., 795 Folsom St., Suite 600, San Francisco, CA 94107, USA)
  • Google Plus (operated by: Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA)
  • XING (operated by: XING SE, Dammtorstraße 30, 20354 Hamburg, Germany)
  • LinkedIn (operated by: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland)
  • Youtube (operated by: Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA)

In these cases, a transfer of data to the social media operators mentioned only takes place if the corresponding icon (e.g. the "f" of Facebook, the bird symbol of Twitter, the "g+" symbol of Google Plus) is clicked. If you click on one of these icons, a page of the corresponding social media operator opens in a popup window. There, you can publish information about our products according to the regulations of the social media operator.

Furthermore, on some of the sites offered by us freely accessible content from the third-party providers Youtube or Twitter is displayed. We do not transmit personal information to these third parties to display the content. YouTube and Twitter have their own cookie and privacy policies which we do not control. Please inform yourself about the data collected by third-party providers from the respective provider.

6. Your rights

to exercise your rights under the GDPR to

  • obtain information about the processing of your personal data and a copy of this data (Art. 15 GDPR),
  • rectification of inaccurate and completion of incomplete personal data (Art. 16 GDPR),
  • erasure of your personal data and, if these have been made public, that METRO informs other controllers about the erasure request (Art. 17 GDPR),
  • restriction of processing of your personal data (Art. 18 GDPR),
  • data portability, so that your personal data is transmitted to you in a structured, commonly used and machine-readable format and the right to transmit this data to another controller without any hindrance from METRO (Art. 20 GDPR),
  • withdrawal of consent given; the withdrawal does not affect the lawfulness of processing based on consent before its withdrawal (Art. 7 GDPR) and
  • object to processing of your data (Art. 21 GDPR), you can contact METRO’s Data Protection Officer (datenschutz@metro.de) at any time. You also have the right to lodge a complaint with the competent supervisory authority if you consider the data processing to be incompatible with the GDPR (Art. 77 GDPR).

Data protection notice for this website
METRO AG
Corporate Communications
Last amended: May 2018