Represented by:
Benedikt Preker, M.Sc. (Eng.), Detlef Löwe, M.Sc. (Eng.)
Contact
Phone: +49 2366-9344-0
Fax: +49 2366-9344-111
Email: info@lambda.de
Registration
Entry in the Commercial Register.
Register court: Recklinghausen
Local Court Register number: HRB 6679
Sales Tax
VAT identification number pursuant to Section 27a of the German VAT Act: 121097923
Data Protection Officer
Dr. Ralf Schadowski
Phone: +49 241 4468825
Email: datenschutz@agr.de
Dispute Resolution
We are neither willing nor obligated to participate in dispute resolution proceedings before a consumer arbitration board.
Liability for Content
As a service provider, we are responsible for our own content on these pages in accordance with Section 7(1) of the German Telemedia Act (TMG) and general laws. However, pursuant to Sections 8 through 10 of the TMG, we are not obligated as a service provider to monitor transmitted or stored third-party information or to investigate circumstances that indicate illegal activity.
Obligations to remove or block the use of information under general laws remain unaffected by this. However, liability in this regard is only possible from the time we become aware of a specific legal violation. Upon becoming aware of such legal violations, we will remove this content immediately.
Liability for Links
Our website contains links to external third-party websites over whose content we have no influence. Therefore, we cannot assume any liability for this third-party content. The respective provider or operator of the linked pages is always responsible for their content. The linked pages were checked for possible legal violations at the time the links were created. No illegal content was identifiable at the time the links were created.
However, permanent monitoring of the content of the linked pages is not reasonable without concrete evidence of a legal violation. Upon becoming aware of any legal violations, we will remove such links immediately.
Copyright
The content and works on these pages created by the site operators are subject to German copyright law. The reproduction, editing, distribution, and any form of use outside the scope of copyright law require the written consent of the respective author or creator. Downloads and copies of this site are permitted only for private, non-commercial use.
Insofar as the content on this site was not created by the operator, the copyrights of third parties are respected. In particular, third-party content is identified as such. Should you nevertheless become aware of a copyright infringement, please notify us accordingly. Upon becoming aware of any infringements, we will remove such content immediately.
Guideline on the Classification of Information in the AGR Group
– Summary –
Application and Scope
This document is binding for all recipients of confidential information from the AGR Group (AGR).
Purpose of this Document
Various types of information are processed within AGR.
These different types of information each have different protection requirements and are classified accordingly.
This summary of the classification policy describes the various types of information and the secure handling of this information by the responsible recipient.
General Handling of Information
The “need-to-know” principle must be observed.
This means that information requiring protection may only be made available to those who need it to perform the tasks assigned to them.
Security Classification at AGR
Based on the need for protection of information, the following three categories are defined:
“SK-0” (- public -)
- applies only to information that is freely accessible outside AGR and therefore does not require special protection.
This refers to information whose modification, loss, or misuse is not expected to cause any particular harm, or where AGR or its employees do not need to demonstrate a legitimate interest in its disclosure, and where its disclosure has little or no impact.
This includes, for example, publicly available information, marketing information, and similar data. It also includes all information that is published due to laws or other regulations.
“SK-1” (- confidential -)
- This refers to information pertaining to normal business operations. The majority of AGR’s information is either actively classified as SK-1 or is considered SK-1 classified if no active classification has been assigned.
This data may only be made available to third parties if they have entered into an NDA (Non-Disclosure Agreement) with AGR or if this summary of the policy is provided to them in addition to the document for their information.
Recipients must treat this information with care and may only disclose it to fulfill the assigned task. In doing so, they must refer to this document and the guidelines for handling the information.
“SK-2” (- strictly confidential -)
- includes information intended for directly affected (and clearly identified) individuals or groups of individuals. Disclosure of this information could cause significant harm to individual business units, project implementations, or work processes.
This confidential information may not be disclosed to third parties by the recipient without AGR’s consent. This information must be communicated in encrypted form whenever possible
Additional requirements for the processing of personal data / special categories of personal data
The processing of personal data and/or special categories of personal data must be carried out in compliance with applicable laws. In general, processing is based on local laws, a data processing agreement, or the consent of the data subject. The legal basis must be verified by the local data protection officer(s).
In addition, the following specific points must be observed:
- The processing of special categories of personal data in a cloud service not approved by the IT organization is not permitted.
- Every new cloud environment must be centrally assessed by the IT organization and the data protection officers with regard to its interfaces with the global network.
Handling Information
|
Classification |
Public |
Confidential |
Strictly Confidential |
|
Document Marking |
Required ("SK-0" visible in or on the document) |
Required ("SK-0" visible in or on the document) |
Required ("SK-2" visible in or on the document) |
|
Processing of information |
No restrictions |
Processing in public areas with privacy protection |
Processing with privacy protection |
|
Printing / Copying |
No restrictions |
No restrictions |
Avoid duplication |
|
Storage on AGR storage services |
No requirement |
Access protection (met with a personal user account and password) |
Access protection (met with a personal user account and password) |
|
Storage on mobile data storage devices |
No requirement |
Encrypted |
Encrypted |
|
Storage of paper documents |
No requirement |
Not in publicly accessible areas |
Locked, e.g., in a filing cabinet |
|
Destruction of paper documents |
Use of normal waste disposal |
Shredder, data bin |
Shredder, data bin |
|
Deletion of data storage media |
No requirement |
Secure deletion by IT |
Secure deletion by IT |
|
Destruction of data storage media |
No restriction |
Physical destruction by IT |
Physical destruction by IT |
|
Disclosure of documents to third parties |
No restrictions |
Non-disclosure agreement or transmission of a summary of the policy |
Non-disclosure agreement |
|
Face-to-face meetings / telephone or video conferences |
No restrictions |
Only for authorized recipients |
Note regarding confidentiality |
|
Chat and collaboration |
No restrictions |
Use of cloud services approved by AGR |
Use of cloud services approved by AGR with appropriate access restrictions |
|
Sending via email |
No encryption required |
Transport encryption (occurs automatically when sent from AGR infrastructure) |
Password-protected attachment if necessary |
|
Sending by mail |
Standard envelope |
Standard envelope |
Standard envelope marked “Personal” |