SAP.iO Privacy Statement

Protecting the individual’s privacy on the Internet is crucial to the future of Internet-based business and the move toward a true Internet economy. We have created this Privacy Statement to demonstrate our firm commitment to the individual’s right to data protection and privacy. This Privacy Statement outlines how we handle information that can be used to directly or indirectly identify an individual (“Personal Data”) that is provided to SAP in connection with SAP.iO programs, events or engagements.

A. General Information

When does this Privacy Statement apply? This Privacy Statement applies to Personal Data that you provide to SAP in connection with SAP.iO (including, SAP.iO programs and events, the SAP.IO website, or other engagements with SAP.iO) or which is derived from the Personal Data as outlined below.

Data Controller. The data controller of the SAP.iO website is SAP America, Inc., 3999 West Chester Pike, Newtown Square, PA 19073, USA (“SAP”). Where a registration form is presented on this website, the data controller may vary depending on the actual offering or the purpose of the data collection but it is in any case displayed on the individual registration form’s privacy statement. The SAP Group’s data protection officer is Mathias Cellarius (privacy@sap.com). 

What does SAP do with my Personal Data? SAP will process the Personal Data provided hereunder only as set out in this Privacy Statement. Further information can be found in Sections B. and C. below. Where the processing of your Personal Data is based on a statutory permission, you can find information on which Personal Data SAP is processing or using for which purposes in Section B below. Where consent for the processing of your Personal Data is required you can find further information in Section C. below.

Duration of processing of Personal Data. Where SAP is processing and using your Personal Data as permitted by law (see B. below) or under your consent (see C. below), SAP will store your Personal Data (i) only for as long as is required to fulfil the purposes set out below or (ii) until you object to SAP’s use of your Personal Data (where SAP has a legitimate interest in using your Personal Data), or (iii) until you withdraw your consent (where you consented to SAP using your Personal Data). However, where SAP is required by mandatory law to retain your Personal Data longer or where your Personal Data is required for SAP to assert or defend against legal claims, SAP will retain your Personal Data until the end of the relevant retention period or until the claims in question have been settled.

Why am I required to provide Personal Data? As a general principle, your granting of any consent and your provision of any Personal Data hereunder is entirely voluntary; there are generally no detrimental effects on you if you choose not to consent or to provide Personal Data. However, there are circumstances in which SAP cannot take action without certain Personal Data, for example because this Personal Data is required to process your orders or provide you with access to a web offering or newsletter. In these cases, it will unfortunately not be possible for SAP to provide you with what you request without the relevant Personal Data.

Where will my Personal Data be processed? As part of a global group of companies, SAP has affiliates and third-party service providers within as well as outside of the European Economic Area (the “EEA”). As a consequence, whenever SAP is using or otherwise processing your Personal Data for the purposes set out in this Privacy Statement, SAP may transfer your Personal Data to countries outside of the EEA including to such countries in which a statutory level of data protection applies that is not comparable to the level of data protection within the EEA. Whenever such transfer occurs, it is based on the Standard Contractual Clauses (according to EU Commission Decision 87/2010/EC or any future replacement) in order to contractually provide that your Personal Data is subject to a level of data protection that applies within the EEA. You may obtain a redacted copy (from which commercial information and information that is not relevant has been removed) of such Standard Contractual Clauses by sending a request to privacy@sap.com.

Data subjects’ rights. You can request from SAP at any time information about which Personal Data SAP processes about you and the correction or deletion of such Personal Data. Please note, however, that SAP can delete your Personal Data only if there is no statutory obligation or prevailing right of SAP to retain it. Kindly note that if you request that SAP delete your Personal Data, you will not be able to continue to use any SAP service that requires SAP’s use of your Personal Data.

If SAP uses your Personal Data based on your consent or to perform a contract with you, you may further request from SAP a copy of the Personal Data that you have provided to SAP. In this case, please contact the email address below and specify the information or processing activities to which your request relates, the format in which you would like this information, and whether the Personal Data is to be sent to you or another recipient. SAP will carefully consider your request and discuss with you how it can best fulfill it.

Furthermore, you can request from SAP that SAP restricts your Personal Data from any further processing in any of the following events: (i) you state that the Personal Data SAP has about you is incorrect, (but only for as long as SAP requires to check the accuracy of the relevant Personal Data), (ii) there is no legal basis for SAP processing your Personal Data and you demand that SAP restricts your Personal Data from further processing, (iii) SAP no longer requires your Personal Data but you claim that you require SAP to retain such data in order to claim or exercise legal rights or to defend against third party claims or (iv) in case you object to the processing of your Personal Data by SAP (based on SAP’s legitimate interest as further set out in B. below) for as long as it is required to review as to whether SAP has a prevailing interest or legal obligation in processing your Personal Data.

Please direct any such request to sapio@sap.com.

Right to lodge a complaint. If you believe that SAP is not processing your Personal Data in accordance with the requirements set out herein or applicable EEA data protection laws, you can at any time lodge a complaint with the data protection authority of the EEA country in which you live or with the data protection authority of the country or state in which SAP has its registered seat.

Use of this website by children. This website is not intended for anyone under the age of 16 years. If you are younger than 16, you may not register with or use this website.

Links to other websites. This website may contain links to foreign (meaning non-SAP Group companies) websites. SAP is not responsible for the privacy practices or the content of websites outside the SAP Group of companies. Therefore, we recommend that you carefully read the privacy statements of such foreign sites.

Use of Google Analytics. The Website uses Google Analytics, a web analytics service provided by Google, Inc. (“Google”). Google Analytics uses “cookies,” which are text files placed on your computer to help the website analyze how users use the site. The information generated by the cookie about your use of the website (including your IP address) will be transmitted to and stored by Google on servers in the United States. Google will use this information for the purpose of evaluating your use of the website, compiling reports on website activity for website operators and providing other services relating to website activity and internet usage. Google may also transfer this information to third parties where required to do so by law, or where such third parties process the information on Google’s behalf. Google will not associate your IP address with any other data held by Google. You can see more information about how Google uses your data and opt-out options by visiting www.google.com/policies/privacy/partners.

B. Where SAP uses My Personal Data based on the Law

In the following cases, SAP is permitted to process your Personal Data under the applicable data protection law.

Providing the requested programs or events. If you have requested to participate in an SAP.iO program or event, SAP will use the Personal Data that you provide to process your request and provide the program or event if your request is accepted by SAP (this may include your name, (email) address, telephone number, company name and address, your job title and role, and other information relevant to your participation in the program or event).

Ensuring compliance. SAP and its products, technologies, and services are subject to the export laws of various countries including, without limitation, those of the European Union and its member states, and of the United States of America. You acknowledge that, pursuant to the applicable export laws, trade sanctions, and embargoes issued by these countries, SAP is required to take measures to prevent entities, organizations, and parties listed on government-issued sanctioned-party lists from accessing certain products, technologies, and services through SAP’s websites or other delivery channels controlled by SAP. This may include (i) automated checks of any user registration data as set out herein and other information a user provides about his or her identity against applicable sanctioned-party lists; (ii) regular repetition of such checks whenever a sanctioned-party list is updated or when a user updates his or her information; (iii) blocking of access to SAP’s services and systems in case of a potential match; and (iv) contacting a user to confirm his or her identity in case of a potential match.

Furthermore, you acknowledge that any information required to track your choices regarding the processing or use of your Personal Data or receipt of marketing materials (that is to say, depending on the country in which the relevant SAP Group company operates, whether you have expressly consented to or opted out of receiving marketing materials) may be stored and exchanged between members of the SAP Group as required to ensure compliance.

SAP’s legitimate interest. Each of the use cases below constitutes a legitimate interest of SAP to process or use your Personal Data. If you do not agree with this approach, you may object against SAP’s processing or use of your Personal Data as set out below.

Questionnaires and surveys. SAP may invite you to participate in questionnaires and surveys. These questionnaires and surveys will be generally designed in a way that they can be answered without any Personal Data. If you nonetheless enter Personal Data in a questionnaire or survey, SAP may use such Personal Data to improve its products and services.

Creation of anonymized data sets. SAP may anonymize Personal Data provided under this Privacy Statement to create anonymized data sets, which will then be used to improve its and its affiliates’ products and services.

In order to keep you up-to-date/request feedback. Within an existing business relationship between you and SAP, SAP may inform you, where permitted in accordance with local laws, about its programs or events (including seminars and webinars) which are similar or relate to such programs or events that you have already participated. Furthermore, where you have participated in a program or event, SAP may contact you for feedback regarding the improvement of the relevant program or event.

Right to object. You may object to SAP using Personal Data for the above purposes at any time by delivering Your objection to sapio@sap.com. If you do so, SAP will cease using your Personal Data for the above purposes (that is to say, under a legitimate interest set out above) and remove it from its systems unless SAP is permitted to use such Personal Data for another purpose set out in this Privacy Statement or SAP determines and demonstrates a compelling legitimate interest to continue processing your Personal Data. 

IMPORTANT: Unsubscribe requests that you provide to SAP.iO will only be applied to SAP.iO related communications. Please submit unsubscribe requests for general SAP communications to https://www.sap.com/profile/unsubscribe.html. In addition, SAP.iO does not receive and will not apply any unsubscribe requests that you make for general SAP communications. Please send all unsubscribe requests relating to SAP.iO communications to sapio@sap.com.

C. Where SAP uses My Personal Data based on My Consent

In the following cases SAP will only use your Personal Data as further detailed below after you have granted your prior consent.

News about SAP.iO programs and events. Subject to your consent, SAP may use your name, email and postal address, telephone number, job title and basic information about your employer (name, address, and industry) as well as an interaction profile based on prior interactions with SAP (prior participation in programs or events) in order to keep you up to date on SAP.iO programs and events.

Program and event promotional materials.  SAP may produce materials from programs and events that you participate in to promote its programs and events, such as videos, photographs, advertisements, and other media and materials (collectively, “Materials”). Subject to your consent, SAP may use the Materials, and transfer them for respective use to other entities in the SAP Group, including your name, likeness, photograph, voice, words, and any other information provided by you during the program or event (collectively, “Your Content”). Subject to your consent, SAP and other entities in the SAP Group may use, reproduce, publish, broadcast and distribute Your Content in whole or in part, worldwide and in translated form on the SAP intranet and the worldwide web, on SAP social media platforms and channels (such as Twitter, YouTube, Facebook, Instagram, LinkedIn), and in printed materials to promote SAP, its brand, products or services.

Program and event profiling. If you register for a program or event of SAP, SAP may share basic participant information (your name, job title, company, and email address) with other participants of the same program or event for the purpose of communication and the exchange of ideas.

Special categories of Personal Data. In connection with the registration for and provision of access to a program or event, SAP may ask for information about your health for the purpose of identifying and being considerate of individuals who have disabilities or special dietary requirements throughout the event. Any such use of information is based on the consent you grant hereunder.

Kindly note that if you do not provide any such information about disabilities or special dietary requirements, SAP will not be able to take any respective precautions.

Forwarding your Personal Data to other SAP companies. SAP may transfer your Personal Data to other entities in the SAP Group. The current list of SAP Group entities can be found here. In such cases, these entities will then use the Personal Data for the same purposes and under the same conditions as outlined in this Section C. above.

Revocation of a consent granted hereunder. You may at any time withdraw a consent granted hereunder by delivering Your withdrawal to direct any such request to sapio@sap.com. In case of withdrawal, SAP will not process Personal Data subject to this consent any longer unless legally required to do so. In case SAP is required to retain your Personal Data for legal reasons your Personal Data will be restricted from further processing and only retained for the term required by law. However, any withdrawal has no effect on past processing of personal data by SAP up to the point in time of your withdrawal.

IMPORTANT: Unsubscribe requests that you provide to SAP.iO will only be applied to SAP.iO related communications. Please submit unsubscribe requests for general SAP communications to https://www.sap.com/profile/unsubscribe.html. In addition, SAP.iO does not receive and will not apply any unsubscribe requests that you make for general SAP communications. Please send all unsubscribe requests relating to SAP.iO communications to sapio@sap.com.

D. U.S.-Specific Provisions

Where SAP is subject to U.S. privacy requirements, the following also applies:

Do Not Track. Your browser may allow you to set a “Do not track” preference. Unless otherwise stated, our sites do not honor “Do not track” requests. However, you may elect not to accept cookies by changing the designated settings on your web browser. Cookies are small text files placed on your computer while visiting certain sites on the Internet used to identify your computer. Please note that if you do not accept cookies, you may not be able to use certain functions and features of our site. This site does not allow third parties to gather information about you over time and across sites. 

Requirements to Protect Children’s Privacy. We do not intend for our websites or online services to be used by anyone under the age of 13. If you are a parent or guardian and believe we may have collected information about a child, please contact at privacy@sap.com.

E. Russia-Specific Provisions

The following applies to users who are resident in the Russian Federation:

The services hereunder are not intended for use by citizens of the Russian Federation who are resident in Russia. If you are a Russian citizen residing in Russia, you are hereby notified that any Personal Data that you input into the services will be solely at your own risk and responsibility, that you expressly agree that SAP may gather your Personal Data and will process this data in the United States and in other countries, and that you will not hold SAP accountable for any potential non-observance of legislation of the Russian Federation.

Revised and posted as of April 3, 2019