Data protection policy
This data protection notice applies to the “Bosch Business Innovations” website of Bosch Business Innovations GmbH published at “www.bosch-business-innovations.com”.
We welcome you to our website and thank you for your interest in our company and our products.
The protection of your privacy when processing personal data as well as the security of all business data are important issues to us, which we consider in our business processes.
1. General information
Bosch Business Innovations is the controller responsible for the processing of your data; exceptions are outlined in this data protection notice.
Our contact details are as follows:
Bosch Business Innovations GmbH, Groenerstraße 9, 71636 Ludwigsburg
Telephone: +49 (0)711 811 0
E-Mail: business.innovations@bosch.com
Please note that this website is not intended for children.
We process the following categories of personal data:
- Communication data (e.g., name, telephone, e-mail, address, IP address)
- Contract master data (contractual relationship, product or contractual interest)
- Customer history
- Contract billing, payment, and disbursement information, including data related to refunds
- Log files
- Location data
We store your data for as long as is necessary to provide our website and the associated services or for as long as we have a legitimate interest in continuing to store your data (e.g., we may still have a legitimate interest in postal marketing even after a contract has been fulfilled). In all other cases we delete your personal data except for such data that we are obliged to store in order to fulfill legal obligations (e.g., we are obliged to retain documents such as contracts and invoices for a certain period due to retention periods under tax and commercial law).
In general, your personal data will only be transferred to other controllers if this is necessary for the fulfillment of a contract, if we or the third party have a legitimate interest in the transfer, or if you have given your consent. For details on the legal basis and the recipients or categories of recipients, please refer to the section “2. Processing purposes and legal bases”.
Additionally, data may be transferred to other controllers if we are obliged to do so by law or by enforceable official or court order.
We involve external service providers with tasks such as sales and marketing services, contract management, payment handling, programming, data hosting, and hotline services. We have carefully selected these service providers and monitor them regularly, in particular their careful handling and safeguarding of the data stored with them. All service providers are obliged to maintain confidentiality and to comply with the statutory provisions. Service providers may also be other companies from the Bosch Group.
We may transfer personal data to recipients located outside the EEA into third countries. In such cases, we ensure before the transfer that either the data recipient provides an adequate level of data protection or that your consent to the transfer has been obtained.
You can obtain a copy of the appropriate or suitable safeguards. Please use the information mentioned in the “10. Contact” section for this purpose.
2. Processing purposes and legal bases
Personal data consists of all information related to an identified or identifiable natural person, this includes, e.g. names, addresses, phone numbers, email addresses, contractual master data, contract accounting and payment data, which is an expression of a person's identity.
We collect, process and use personal data (including IP addresses) only when there is either a statutory legal basis to do so or if you have given your consent to the processing or use of personal data concerning this matter, e.g. by means of registration.
We and service providers contracted by us process your personal data for the following processing purposes:
- If you use our website solely for information purposes, that is, without registering or otherwise sending us information, we process your personal data to provide this website based on our legitimate interest to present us and to ensure stability and security.
- In order to optimize the loading times of our website, we use “Azure Content Delivery Network (CDN) Services.” Providers are Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA and Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18 D18, Ireland.
The CDN helps to provide the content of our website — especially large media files such as graphics, text, or scripts — more quickly with the help of a network of geographically distributed servers, thereby reducing loading times.
The use of the CDN services is based on our overriding legitimate interest within the meaning of article 6 section 1 lit. f GDPR in the efficient provision of our website.
In context of this processing, personal data is transmitted to the USA. The transmission is based on European Standard Contractual Clauses in which Microsoft guarantees to comply with the European data protection law for its provided services.
Further information on privacy in connection with Microsoft’s CDN service is available here: https://azure.microsoft.com/en-us/support/legal/. Microsoft’s privacy policy can be found here: https://privacy.microsoft.com/en-us/privacystatement.
Contact: You can contact us via a provided contact form or by other channels, such as e-mail or telephone. We store and use your personal data, such as name, e-mail, address, and telephone number, to communicate with you. We process your personal data based on our legitimate interest in customer support and to improve our products and services.
In reply to user inquiries in the framework of a contact form
Legal basis: Predominantly, justified interest in direct marketing on our part and in the enhancement of our products and services, as long as this is carried out in compliance with data protection regulations and competition law regulations resp. contractual performance resp. consent
Contact in case of event registration
Legal basis: For the performance of a contract to which the data subject is partly or in order to take steps at the request of the data subject prior to entering into a contract.
Determination of malfunctions and for safety reasons
Legal basis: Fulfilment of our legal obligations in the field of data security and predominantly, justified interest in the rectification of malfunctions and the security of our offers.
Our own and third party advertising as well as market research and reach measurement in accordance with the legally permissible extent resp. consent-based
We use HubSpot, a service by HubSpot Germany GmbH, Am Postbahnhof 17, 10243 Berlin, as a secure and GDPR-compliant platform to manage stakeholder relationships, including contact management, marketing, and engagement tracking.
Purposes and Legal Bases:
- Managing stakeholder contact data and business-relevant information
→ Art. 6(1)(f) GDPR – legitimate interest in maintaining business relationships, and where applicable, Art. 6(1)(b) GDPR (performance of a contract or steps prior to entering into a contract) - Documenting interactions with stakeholders (e.g. emails, meetings, notes, event participation)
→ Art. 6(1)(f) GDPR – legitimate interest in communication transparency and accountability, and where applicable, Art. 6(1)(b) GDPR (performance of a contract or steps prior to entering into a contract) - Tracking and improving stakeholder engagement and marketing campaigns
→ Art. 6(1)(f) GDPR – legitimate interest; and where applicable, Art. 6(1)(b) GDPR (performance of a contract or steps prior to entering into a contract), Art. 6(1)(a) GDPR – consent (if tracking cookies or analytics involved) - Sending newsletters and tracking their performance
→ Art. 6(1)(a) GDPR – consent via double opt-in; § 7(2)(3) UWG - Connecting with new stakeholders via website forms or newsletters
→ Art. 6(1)(a) GDPR – consent via double opt-in (web forms); Art. 6(1)(f) GDPR – legitimate interest (offline contacts) - Attracting stakeholders via SEO and website analytics
→ Art. 6(1)(a) GDPR – consent (via cookie consent banner)
Categories of Data Processed in HubSpot:
- Contact Information: Name, email address, phone number, LinkedIn profile, employer, role, record source (e.g. event, web form)
- Associations & Relationship Context: Newsletter subscription status, legal basis for communication, associated startups, companies and contacts, contact owner, lifecycle stage, internal notes, interactions (emails, calls, meetings), task allocation
- Mentor Volunteers (if applicable): Acting region, industry/business/product/functional expertise
- Marketing and Engagement Data: Newsletter performance (delivery, opens, clicks, unsubscribes, replies), campaign engagement, user journey (ads, forms), event participation
- Logging Data: Timestamped interaction records (e.g. form submissions, event check-ins, system notes)
Data Subjects involved:
- Business partners (e.g. investors, partners, mentors, startup teams)
- Website visitors and form users
- Newsletter subscribers
- Event participants
- Volunteer mentors
- We may also process your personal data to investigate service disruptions and for security reasons to comply with our legal obligations in the area of data security, as well as on the basis of our legitimate interest in the elimination of service disruptions and the security of our offers.
- We may process your personal data to protect and defend our rights. This purpose also constitutes our legitimate interest.
3. Log files
Every time you use the internet, certain information is automatically transmitted by your internet browser and stored in log files.
Log files are stored by us for the purpose of investigating service disruptions and for security reasons (e.g., to clarify attempted attacks) for a period of 90 days. Log files whose further storage is necessary for the purpose of evidence are exempt from deletion until the final clarification of the respective incident and may be passed on to investigative authorities in individual cases.
The following information is stored in the log files:
- IP address (internet protocol address) of the end device from which our website is accessed;
- Internet address of the website from which our website was accessed (origin or referrer URL);
- name of the service provider used to access the website;
- name of the files or information retrieved;
- date and time as well as duration of the retrieval;
- amount of data transferred;
- operating system and information on the Internet browser used, including installed add-ons (e.g., for Flash Player);
- HTTP status code (e.g., “request successful” or “requested file not found”).
4. Information storage and access
In the course of providing our website, cookies and other technologies may be used that either store information on your terminal equipment or gain access to information stored on your terminal equipment.
Cookies are small text files that can be stored on your end device when you visit a website.
The use of our website is generally possible without cookies that are not technically necessary.
By technically necessary cookies, we mean cookies without which the technical provision of the website cannot be guaranteed. This includes, for example, cookies that store data in order to ensure the interference-free playback of video or audio content.
These cookies are deleted at the end of your visit.
We only use technically not necessary cookies and tracking mechanisms if you have given us your prior consent. The only exception to this is the cookie that stores the current status of your privacy settings (“selection cookie”).
We use third-party tools to integrate technically not necessary cookies and mechanisms. These tools ensure that technically not necessary cookies and mechanisms are only set with your consent.
We use the following tool:
Name: Google Tag Manager
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Function: Management of website tags via an interface, integration of program codes on our websites
Cookies and mechanisms, which are assigned to this category, facilitate the operation and thus enable a more comfortable surfing on our website. For example, your language settings can be stored in these cookies.
The use of marketing cookies and tracking mechanisms such as web beacons enables us to show you personalized offers based on an analysis of your interests and usage behavior.
Below we explain which mechanisms and which providers we use on this website.
Analysis:
We use analysis tools to improve our products and services. We measure, for example, the number of page views or your behavior on our website. This may also include the evaluation of log files.
Statistics:
By using statistical tools, we measure e.g. the number of your page views.
Conversion tracking:
Our conversion tracking partners place a cookie on your computer ("conversion cookie") if you have reached our website via an advertisement of the respective partner.
If you visit certain websites of ours, we and the respective conversion-tracking provider can recognize that a certain user clicked on the ad and was thus redirected to our site. This may also take place across devices.
The information collected using the conversion cookie is used to create conversion statistics and to record the total number of users who clicked on the relevant ad and were redirected to a page tagged with a conversion tracking tag.
Retargeting:
These tools create user profiles by means of advertising cookies or third-party advertising cookies so called "web beacons" (invisible graphics that are also called pixels or tracking pixels), or by means of comparable technologies. These are used for interest-based advertising and to control the frequency with which the user looks at certain advertisements. The relevant provider is the controller responsible for the processing of data in connection with the tool. The providers of the tools might disclose information also to third parties for the purposes mentioned above. Please note the data protection notices of the relevant provider in this context.
Please note that using the tools might include transfer of your data to recipients outside of the EEA where there is no adequate level of data protection pursuant to the GDPR (e.g. the USA). For more details in this respect please refer to the following description of the individual marketing tools.
We use the following tools:
Name: Google Analytics
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Function: Analyze user behavior (page views, number of visitors and visits, downloads), create pseudonymous user profiles based on cross-device information of logged-in Google users (cross-device tracking), enrich pseudonymous user data with target group-specific information provided by Google, retargeting, UX testing, conversation tracking and retargeting.
Additional information:
- We use the “anonymize IP” function, which anonymizes your IP address before writing it to disc.
- We use the paid version of Google Analytics, in which the data collected on our website via Google Analytics is stored on own Google servers. Google may not use this data for its own purposes or mix it with other data that Google collects about you in other ways, such as when you are logged into your Google account on your browser while visiting our website.
Name: HubSpot
Provider: HubSpot Germany GmbH, Am Postbahnhof 17 10243 Berlin
Function: Analysis & marketing purposes.
Legal basis: The processing of your personal data takes place only with your consent (Art. 6 para. 1 lit. a GDPR), which you may grant or revoke at any time via our cookie consent management tool.
Data storage and transfer: Data is primarily stored within Germany and the European Economic Area (EEA). However, in some cases, data may also be transferred to HubSpot servers in the United States. To ensure adequate protection of your personal data in these cases, Standard Contractual Clauses (SCCs) in accordance with Art. 46 GDPR have been concluded with HubSpot.
Further information: HubSpot Privacy Policy; HubSpot Data Processing Agreement (DPA); HubSpot Privacy Shield information (legacy)
- In the browser and/or in our “Privacy settings”, you can manage your cookie and tracking mechanism settings.
Please note: The settings you make each apply only to the browser you are using. - Switch off all cookies
If you would like to disable all cookies, please go to your browser settings and disable the setting of cookies. Please note that this may affect the functionality of this website.
5. Plugins
We offer the use of plugins from various social and other networks on our website.
Further processing of data by the providers
Plugins represent extensions of the providers of the social networks. We therefore have no influence on the further processing of the data collected and stored via the plugins by the providers of the respective networks.
For information on the purpose and scope of the collection, further processing and deletion of the data by the respective provider, as well as your rights in this regard and setting options for protecting your privacy, please refer to the privacy policy of the respective provider.
Social Plugins
Social plugins with 2-click solution
With a so-called 2-click solution, we protect you from having your visits to our websites recorded and evaluated by social network providers as standard. When you access a page of our internet offer, which contains such plugins, these are initially deactivated. The plugins are not activated until you click the provided button.
Plugins are inactive by default.
To increase the protection of your data when visiting our website, the plugins are integrated into the page by means of a "2-click solution". With this 2-click solution, we protect you from having your visit to our websites recorded by default and possibly evaluated by providers of the respective plugin.
If you do not want the providers of the respective networks to receive data about your use of this website and possibly store or further use it, you should not activate the respective plugins.
Activating the plugin
You can decide for yourself whether you want to interact with the network of the respective provider and whether your data should be transmitted to the respective provider or not. Only with your click on the provided button, the plugins are activated and integrated into the page by transmitting the content of the respective plugin from the server of the associated provider directly to your browser. Subsequently, you can perform the desired interaction with the network with another click. If you decide to activate a plugin, we process your data based on your consent.
Collection of data by the providers
When a plugin is activated, your browser establishes a direct connection to the servers of the respective provider. Through this, the respective provider receives the information that your browser has called up the corresponding page of our website; even if you do not have a user account with the provider or are not currently logged in to it.
If you already have a user account with a provider of a network and you are already logged in while visiting our websites, the operator of the respective network may be able to assign the visit to your personal user account as soon as you activate the plugins. This may enable the provider to analyze your usage behavior and store it in a profile.
In addition, your IP address and other data about your browser settings are transmitted by your browser directly to a server of the respective provider and may be stored there.
Deactivating the plugin
If you no longer wish to use an activated plugin, you can also deactivate the plugin using the button provided. Please note that data already transmitted will not be affected by this.
LinkedIn is provided by LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA (“LinkedIn”). You will find an overview of the plugins from LinkedIn and their appearance here: https://developer.linkedin.com/plugins; you will find information on data protection at LinkedIn here: https://www.linkedin.com/legal/privacy-policy
In our online offer, we use so-called social plugins of different social networks; these will be described individually in this section.
On application of the plugins, your Internet browser will establish a direct connection to the servers of the respective social network. Hereby the relevant provider obtains the information that your Internet browser has called up the corresponding page of our online offer, even if you do not possess a user account with the provider or are not currently logged in with the provider. Log files (including the IP address) are directly transmitted from your Internet browser to a server of the relevant provider where they are stored if necessary. The headquarters of the provider or his/her server could be located outside the EU or the EEA (e.g. in the USA).
The plugins are independent extensions of the providers of social networks. Therefore, we have no influence on the extent of the data collected and stored by the social network providers via the plugins.
The purpose and extent of the collection, the further processing of the data by the social network as well as your associated rights and setting options for the protection of your private sphere can be taken from the data protection notice of the respective social network.
You should not use the respective plugins if you do not want social network providers to obtain data concerning this online offer or to continue to use this data.
This website uses videos from the video platform YouTube. YouTube is a platform that enables the playback of video files. It is operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland and its parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
To increase the protection of your data when visiting our website, the YouTube content is integrated into the page in “privacy enhanced mode.”
This way, a connection to YouTube, including a transmission of log data to YouTube, is only established when you perform an interaction with the player.
When you interact with the active YouTube player, data is also transmitted to YouTube as controller and contact is made with the Google DoubleClick advertising network, which may trigger further data processing operations over which we have no control.
For more information, please see YouTube’s privacy policy.
This website uses map services from Google Maps. Google Maps is operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland and its parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
When you interact with Google Maps, data is also transmitted to Google as controller and contact is made with the Google DoubleClick advertising network, which may trigger further data processing operations over which we have no control.
For more information, please see Google’s privacy policy.
6. Obligation to provide personal data
It is necessary to provide those personal data that are required for the establishment and implementation of a business relationship and for the fulfillment of the associated contractual obligations or for the processing of which we are legally obligated.
We mark such personal data in the respective forms or functions with an “*”.
Please note that without the provision of such personal data, we will not be able to enter into or perform a contract with you. In this case, certain services (see “2. Processing purposes and legal basis”) cannot be used.
7. External links
Our websites may contain links to internet pages of third parties, in particular providers who are not related to us. Upon clicking on the link, we have no influence on the collecting, processing, and use of personal data possibly transmitted by clicking on the link to the third party (such as the IP address or the URL of the site on which the link is located) as the conduct of third parties is beyond our control. We do not assume responsibility for the processing of personal data by third parties.
8. Data subject rights
Please use the information in the “10. Contact” section to assert your rights. When doing so, please ensure that we can clearly identify you.
You have the right to request access to the personal data concerning you, as well as the right to rectification, the right to erasure, the right to restriction of processing, and the right to data portability. Insofar as you have given us consent to process your personal data, you may revoke this consent at any time with future effect.
You can object to the processing of your personal data for advertising purposes (“advertising objection”) at any time. Please note that, for organizational reasons, there may be an overlap between your objection and the use of your data in the context of an already ongoing campaign.
If the processing of your personal data is based on “legitimate interest”, you also have the right to object to the processing of your personal data at any time on grounds relating to your particular situation. The reasons shall be stated.
We will then terminate processing your data unless we can prove — in accordance with the legal requirements — compelling legitimate grounds for the processing which override your rights.
9. Right to lodge complaint with supervisory authority
Right to lodge complaint with supervisory authority
You have the right to lodge a complaint with a supervisory authority.
10. Contact
If you wish to contact us, please find us at the address stated in the “1.1 Controller” section.
To assert your rights and to notify data protection incidents please use the following link: https://request.privacy-bosch.com/
For suggestions and complaints regarding the processing of your personal data we recommend that you contact our data protection officer:
Data Protection Officer
Information Security and Privacy (C/ISP)
Robert Bosch GmbH
Postfach 30 02 20
70442 Stuttgart
GERMANY
or
E-mail to: DPO@bosch.com
11. Changes to the Data protection notice
We reserve the right to change our security and data protection measures. In such cases, we will amend our data protection notice accordingly. Therefore, please note the current version of our data protection notice, as it is subject to change.
Published: June 2025