ITM Consulting

Focus Areas

EA Practices & MethodsOperating model, meta-model, governance Business Process ManagementProcess Landscapes, Modeling, and Governance AI for EA & BPMAgents, skills, orchestration, and tooling

Platforms

SAP LeanIXEnterprise Architecture Management SAP SignavioBusiness Process Transformation Bizzdesign Alfabet & UnifyIT Portfolio & Visual Collaboration
Services Insights
About UsWho We Are and How We Work CareersWorking at ITM
EN DE
Talk to us

Focus Areas

EA Practice & Methods Business Process Management AI for EA & BPM

Platforms

SAP LeanIX SAP Signavio Bizzdesign Alfabet & Unify
Services Insights

Company

About us Careers
Talk to us

Legal

Privacy Policy

Introduction

Whether you are a customer, a prospective customer, or a visitor to our website, we protect your privacy and consider it a matter of great importance when processing your data. We therefore comply with the provisions of the General Data Protection Regulation (GDPR).

This Privacy Policy explains what data we process. It applies to ITM Beratungsgesellschaft mbH, hereinafter referred to as ITM.

It also provides information about the processing of your data in accordance with applicable legal requirements (Articles 13 et seq. of the GDPR). It gives you a quick and straightforward overview of the personal data we collect from you and how we use it. We also inform you about your rights under applicable data protection laws and who you can contact if you have any questions.

Controller

ITM Beratungsgesellschaft mbH
Meitnerstraße 8
70563 Stuttgart
Germany
Phone: +49 711 45129-0
Email: info[at]itm.net

Contact information for the Data Protection Officer

You can contact our Data Protection Officer at:
Phone: +49 711 45129-15
Email: compliance+dsb[at]itm.net

Purposes and Legal Bases for Data Processing

We process your personal data exclusively in accordance with applicable data protection laws, in particular the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG). This Privacy Policy explains what personal data we collect, how we use it, and what rights you have.

Collection and Storage of Personal Data, and the Nature and Purpose of Their Use

When visiting the website

When you visit our website, the browser on your device automatically sends information to our web server. This information is temporarily stored in a log file. The following information is recorded and stored until it is automatically deleted:

  • IP address of the requesting device
  • Date and time of access
  • Name and URL of the accessed file
  • Website from which the access originated (referrer URL)
  • Browser used and, if applicable, your device's operating system

We process the data specified above for the following purposes:

  • Ensuring that a smooth connection to the website is established
  • Ensuring a convenient user experience on our website
  • Evaluating System Security and Stability

We cannot link this data to specific individuals. This data is not combined with other data sources. The legal basis for the processing is Article 6(1)(f) of the GDPR.

SSL or TLS encryption

For security reasons and to protect the transmission of confidential information that you send to us as the website operator, our website uses SSL or TLS encryption. This means that third parties cannot read the data you transmit through this website. You can recognize an encrypted connection by the “https://” address in your browser and the padlock icon in the browser bar.

Website hosting and delivery

Our website is hosted by Amazon Web Services (AWS). The provider is Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg. The pages are delivered via the Amazon CloudFront content delivery network; the access data specified above are processed by AWS in this context.

Because CloudFront uses a global network of points of presence, processing outside the EU—particularly in the United States—cannot be ruled out. AWS is certified under the EU-U.S. Data Privacy Framework (Article 45 of the GDPR); the EU Standard Contractual Clauses also apply (Article 46(2)(c) of the GDPR). The legal basis is Article 6(1)(f) of the GDPR; our legitimate interest lies in providing the website securely, quickly, and reliably. For more information, see the AWS Privacy Notice.

Use of Cookies and Tracking Technologies

Our website uses cookies, which are small text files that your web browser stores on your device to make your visit to our website more convenient and to enable the use of certain features. You can prevent cookies from being stored on your device by changing the appropriate settings in your browser. However, this may limit the functionality of our website.

You can adjust or withdraw your consent to the use of non-essential cookies at any time using our cookie consent tool on the website. To do so, click the corresponding icon in the lower-left corner of the website or open the settings in the cookie banner. Alternatively, you can delete or block stored cookies in your browser settings.

The processing is based on your consent (Article 6(1)(a) of the GDPR) or our legitimate interests (Article 6(1)(f) of the GDPR).

We use cookies and similar technologies sparingly. Without your consent, we use only cookies and similar technologies that are strictly necessary (Section 25(2), No. 2 of the German Telecommunications and Digital Services Data Protection Act, TDDDG):

  • CookieConsent (cookie, duration 12 months): stores your selection in the cookie banner so that we don't have to ask you again every time you visit.
  • itm-lang (local storage, no expiration): remembers the language you selected using the language switcher. The entry is created only if you actively change the language and does not leave your browser.

All other technologies are loaded only with your consent (Article 6(1)(a) of the GDPR, Section 25(1) of the TDDDG).

Cookiebot (consent management)

We use the Cookiebot consent management platform to obtain and document your consent. The provider is Usercentrics A/S, Havnegade 39, 1058 Copenhagen, Denmark. When you visit our website, the provider’s script is loaded and the following data are processed:

  • Your consent choice or its withdrawal, including the date, time, and version of consent
  • A randomly generated consent ID
  • The address of the page accessed, the previously visited page, language settings, and approximate geographic information
  • Your IP address and information about your browser, operating system, and device

Cookiebot stores your selection in the CookieConsent cookie in your browser and maintains a consent log so that we can demonstrate that consent was given. End-user data are deleted on an ongoing basis 12 months after they are recorded.

The processing is necessary to comply with our legal obligation to obtain and demonstrate consent (Article 6(1)(c) in conjunction with Article 7(1) of the GDPR) and to pursue our legitimate interest in legally compliant consent management (Article 6(1)(f) of the GDPR). The strictly necessary CookieConsent cookie is stored in accordance with Section 25(2), No. 2 of the TDDDG. For more information, visit: https://www.cookiebot.com/en/privacy-policy/.

Analytics tools and advertising

Google Tag Manager

This website uses Google Tag Manager. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland. Google Tag Manager is used to centrally manage and trigger website tags. It does not set cookies or create its own user profiles. However, when Tag Manager is loaded, a connection to Google is established, and, in particular, your IP address and technical connection data are transmitted. According to Google, the standard HTTP log data generated in this process are deleted within 14 days; Google may also process aggregated diagnostic data related to the triggering of tags.

Google Tag Manager and the analytics tags it manages are loaded only after you have consented to the “Statistics” category in the cookie banner. No connection to Google is established without this consent. The legal basis is your consent (Article 6(1)(a) of the GDPR, Section 25(1) of the TDDDG). You may withdraw your consent at any time by clicking the cookie icon in the bottom-left corner of the page. The data processed by the services integrated via Tag Manager is described in the relevant sections of this Privacy Policy.

Google Analytics 4

This website uses features of the Google Analytics 4 web analytics service. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics enables the website operator to analyze the behavior of website visitors. In doing so, the website operator receives various usage data, such as page views, time spent on the website, operating systems used, and the user’s location.

According to Google, the IP addresses of users from the European Union or other states party to the Agreement on the European Economic Area are not logged or stored. The IP address is used on servers in the EU solely to determine approximate location data and is then discarded.

On behalf of the operator of this website, Google will use this information to evaluate your use of the website, compile reports on website activity, and provide the website operator with other services related to website and Internet use.

Google Analytics 4 is loaded only after you have consented to the “Statistics” category in the cookie banner. The cookies _ga and _ga_* are then set with a duration of up to two years. The retention period for user-level and event-level data in our Google Analytics account is set to 14 months. Processing is based exclusively on your consent (Article 6(1)(a) of the GDPR, Section 25(1) of the TDDDG); you may withdraw your consent at any time by clicking the cookie icon in the lower-left corner of the page.

Google may transfer the data to the United States. Google LLC is certified under the EU-U.S. Data Privacy Framework; the EU Standard Contractual Clauses also apply. For more information, visit https://policies.google.com/privacy.

Plugins and tools

YouTube

Our website uses YouTube plugins to integrate and display video content. The service provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland. We use YouTube in enhanced privacy mode. Videos are loaded only after you have consented to the corresponding category in the cookie banner or have explicitly activated the respective video. No connection to YouTube is established beforehand.

As soon as you play a YouTube video on this website, a connection to YouTube's servers is established. This tells YouTube which of our pages you have visited. If you are logged in to your YouTube account, YouTube may link your browsing activity directly to your personal profile. You can prevent this by logging out beforehand.

After a video starts playing, YouTube may also store various cookies on your device or use similar recognition technologies, such as device fingerprinting. This allows YouTube to obtain information about visitors to this website. This information is used, among other things, to collect video statistics, improve the user experience, and prevent attempted fraud.

The legal basis is your consent (Article 6(1)(a) of the GDPR, Section 25(1) of the TDDDG). You may withdraw your consent at any time by clicking the cookie icon in the lower-left corner of the page. Google may transfer the data to the United States. Google LLC is certified under the EU-U.S. Data Privacy Framework; the EU Standard Contractual Clauses also apply. Details about how Google handles user data can be found in Google’s Privacy Policy: https://policies.google.com/privacy.

Google reCAPTCHA

Our primary goal is to make our website secure and user-friendly for both you and us. To prevent automated access—such as by bots—and protect us against spam attacks, we use Google reCAPTCHA Enterprise. The provider of this service is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.

reCAPTCHA allows us to determine whether an entry is made by a human or is being misused through automated processing. Various data are collected and transmitted to Google during this process, including the IP address, mouse movements, time spent on the website, browser and device characteristics, and, where applicable, existing Google cookies. This data is used exclusively to protect our website.

reCAPTCHA is loaded only after you have given your consent, either through the “Preferences” section in the cookie banner or for the specific request by checking the designated box in the contact form. reCAPTCHA may set the _GRECAPTCHA cookie during this process. Processing in the United States cannot be ruled out; Google LLC is certified under the EU-U.S. Data Privacy Framework, and the EU Standard Contractual Clauses also apply.

We use Google reCAPTCHA to maintain the integrity of our website, protect against automated attacks, and ensure a user-friendly experience for genuine visitors. The legal basis for this processing is your consent (Article 6(1)(a) of the GDPR, Section 25(1) of the TDDDG). The form cannot be submitted without reCAPTCHA; in this case, you can contact us by email at info[at]itm.net or by phone. For more information, visit https://cloud.google.com/recaptcha/docs/faq.

Contact us by email or through the contact form

If you send us inquiries via the contact form or by email, the information you provide—including the contact details you enter—will be stored by us for the purpose of processing the inquiry and in case of follow-up questions. We do not disclose this information without your consent.

The following personal data may be processed in this context:

  • Name
  • Email address
  • Company (if provided)
  • Phone number (if provided)
  • Message content

This data is processed pursuant to Article 6(1)(b) of the GDPR if your inquiry relates to the performance of a contract or is necessary to take steps prior to entering into a contract. In all other cases, the processing is based on our legitimate interest in effectively handling inquiries addressed to us (Article 6(1)(f) of the GDPR).

Applications

If you apply to us, we process your personal data in order to carry out the application process. Your application documents are treated confidentially and used solely for the purpose of processing your application. The data processed include:

  • Master data, such as name, address, and contact information
  • Application documents, such as a resume, references, and credentials
  • Any other information you voluntarily provide as part of your application

Your data are used only internally and are not disclosed to third parties.

The legal basis for processing your application data is Section 26 of the German Federal Data Protection Act (BDSG) in conjunction with Article 6(1)(b) of the General Data Protection Regulation (GDPR). If you are not hired, your application documents will be deleted no later than six months after the application process has been completed, unless you have consented to a longer retention period.

Visitors and outside companies

For visitors and employees of outside companies who enter our premises, we collect personal data such as:

  • Name
  • Contact Information
  • Company affiliation
  • Time of visit

This data is used for security purposes, to protect our employees, and to comply with legal requirements. The legal basis for this processing is Article 6(1)(c) of the GDPR (legal obligation) and our legitimate interest pursuant to Article 6(1)(f) of the GDPR.

Data Retention Period and Data Deletion

Personal data are stored for as long as necessary for the respective processing purposes or for as long as statutory retention requirements apply. The data are deleted once they are no longer needed or the statutory retention periods have expired.

Data Processing for Business Partners, External Companies, and Business Contacts

What data do we process?

As part of our business relationships with customers, suppliers, service providers, and other business partners, we collect the following personal data:

  • Last name, first name, and title
  • Company affiliation and position
  • Business address
  • Contact information (email, phone, and fax)
  • Contract and billing information
  • Payment information (bank details and invoice details)
  • Communications within the business relationship, such as emails, inquiries, meetings, and contracts

Purpose of Data Processing

This data is processed for the following purposes:

  • Establishing, conducting, and managing business relationships
  • Processing inquiries and contract negotiations
  • Processing Orders and Payments
  • Compliance with statutory requirements, such as tax withholding obligations
  • Communicating with business partners and external companies
  • Improving Our Business Processes

Legal Bases for Processing

The personal data of business partners is processed on the following legal grounds:

  • Article 6(1)(b) of the GDPR (steps taken prior to entering into a contract and the performance of a contract)
  • Article 6(1)(c) of the GDPR (legal obligations, such as tax withholding obligations)
  • Article 6(1)(f) of the GDPR (legitimate interest in maintaining business relationships, quality assurance, and security)

Retention Period and Deletion of Business Partner Data

Contract-related data and personal data are stored for as long as necessary for the respective business relationship or for as long as statutory retention requirements apply. The data are deleted once they are no longer needed or the statutory retention periods have expired.

Disclosure of Business Partner Data

We disclose personal data to third parties only when necessary to fulfill contractual or legal obligations or to protect legitimate interests. These third parties include, for example:

  • Tax advisors, auditors, and banks for processing payments
  • Authorities and public bodies subject to statutory reporting requirements
  • Insurance companies in connection with liability matters

Data Security for Business Partners

We use technical and organizational measures to protect personal data against unauthorized access, loss, or misuse. These include access controls, encryption technologies, and regular security reviews. The measures include:

  • Access restrictions and role-based permissions
  • Encryption of Sensitive Data
  • Secure Transmission Technologies for Electronic Communications
  • Regular security audits and data protection training

Your rights as a data subject

If we process your personal data, you have the following rights under the GDPR:

Right of access pursuant to Article 15 of the GDPR

You have the right to obtain information about the personal data we process. This includes, in particular:

  • Purposes of the processing
  • Categories of Data Processed
  • Recipients or categories of recipients to whom your data have been or will be disclosed
  • Intended storage period or the criteria used to determine that period
  • Your rights to rectification, erasure, restriction of processing, or objection
  • The existence of automated decision-making, including profiling, and, where applicable, meaningful information about its details
  • Information regarding any transfer of personal data to third countries and the appropriate safeguards

Right to rectification under Article 16 of the GDPR

If the personal data being processed are inaccurate or incomplete, you have the right to have your data corrected or completed without undue delay.

Right to erasure (“right to be forgotten”) pursuant to Article 17 of the GDPR

You may request the erasure of your personal data if:

  • the data are no longer necessary for the original purposes;
  • you have withdrawn your consent and there is no other legal basis for the processing;
  • you object to the processing and there are no overriding legitimate grounds for the processing;
  • the data have been processed unlawfully; or
  • Erasure is necessary to comply with a legal obligation.

Right to restriction of processing pursuant to Article 18 of the GDPR

You have the right to request that the processing of your personal data be restricted if any of the following applies:

  • You are disputing the accuracy of the data, and we need time to verify its accuracy.
  • The processing is unlawful, but you object to the erasure of the data.
  • We no longer need your data, but you need them to establish, exercise, or defend legal claims.
  • You have objected to the processing, and it has not yet been determined whether our legitimate interests override yours.

Right to object under Article 21 of the GDPR

You have the right to object at any time to the processing of your personal data based on Article 6(1)(e) or (f) of the GDPR. This applies in particular to direct marketing. In this case, your data will no longer be processed for these purposes.

Right to withdraw consent pursuant to Article 7(3) of the GDPR

You have the right to withdraw your consent at any time. Withdrawing your consent does not affect the lawfulness of any processing carried out before the withdrawal. You can withdraw your consent at any time by emailing compliance+dsb[at]itm.net.

Right to file a complaint with a supervisory authority pursuant to Article 77 of the GDPR

Pursuant to Article 77 of the GDPR, you have the right to file a complaint with a supervisory authority. You can generally contact the supervisory authority for your habitual residence, place of work, or our registered office. The supervisory authority responsible for ITM Beratungsgesellschaft mbH is:

The State Commissioner for Data Protection and Freedom of Information Baden-Württemberg
(The State Commissioner for Data Protection and Freedom of Information Baden-Württemberg)
P.O. Box 10 29 32
70025 Stuttgart
Germany
Phone: 0711/615541-0
Fax: 0711/615541-15
Email: Poststelle@lfdi.bwl.de

Contact Options & Compliance Inquiries

We have established central points of contact for inquiries regarding data protection, information security, and security incidents. Please use the appropriate email address to ensure that your inquiry can be handled more quickly.

Primary Contact

  • Email: compliance[at]itm.net
  • ITM hotline: +49 711 45129-0
  • Website & further information: www.itm.net

Additional contacts:

Email Topics
compliance[at]itm.net General compliance inquiries and audits
compliance+dsb[at]itm.net Data Protection & GDPR
compliance+isb[at]itm.net Information Security & IT Security
compliance+security[at]itm.net Reporting Security Incidents

Current Status and Changes to This Privacy Policy

This Privacy Policy is currently in effect. It may become necessary to amend this Privacy Policy as our website evolves or due to changes in legal requirements. The current Privacy Policy can be viewed on our website at any time.

ITM
+49 711 451 29-0 info@itm.net LinkedIn

Consulting

EA Practice & Methods Business Process Management AI for EA & BPM Service Packages

Platforms & Reports

SAP LeanIX SAP Signavio Bizzdesign Alfabet & Unify Subscription Manager

Company

Insights About us Careers Contact
© 2026 ITM Beratungsgesellschaft mbH Legal Notice Privacy
Certified SAP & Bizzdesign Partner