Skip to content

Commvault Datenschutzrichtlinie

Commvault Systems, Inc. and its affiliates and subsidiaries (collectively, “Commvault” “us” “we”) prioritize your data privacy and security. Our Solutions empower you to control the collection, use, and processing of your data. Any data collected, used, or shared on a limited basis as a result of your use of our Solutions, Websites, or Portals (as defined herein) will be in accordance with this “Privacy Policy”.

Welche Daten wir sammeln

We are provided with data when our products and services (together, the “Solutions”) and our websites or portals (either, “Websites” or “Portals”) are purchased, used, or accessed.

Arten von Daten

Data that identifies, or can reasonably be used to identify, a person or household, either directly or indirectly (“Personal Data”) including:

  • Name und Geschäftskontakte (E-Mail-Adresse, Postanschrift, Telefonnummer, Titel, Unternehmen)
  • Gespeicherte Daten durch unsere Lösungen geschützt
  • Transaktionsdaten, die wir benötigen, um Zahlungen zu tätigen und zu empfangen und die Lösungen zu liefern
  • Informationen, die uns durch das Ausfüllen von Formularen auf unseren Websites oder Portalen, durch die Teilnahme an einer Werbeaktion oder Umfrage, durch das Abonnieren, Kommentieren oder Herunterladen von Informationen von unseren Websites oder Portalen oder durch Bewerbungen von Bewerbern übermittelt werden
  • Einstellungsdaten, soweit gesetzlich zulässig, einschließlich Personenstand, Geburtsdatum, persönliche Kontaktinformationen, nationale ID-Nummer, Einwanderungsinformationen, Führerschein, gesprochene Sprachen, Informationen über nächste Angehörige/Abhängige/Notfallkontakte, Einzelheiten zu etwaigen Behinderungen, Lebensläufe, Daten zu Vorstellungsgesprächen und Beurteilungen, Überprüfungsinformationen (z. B. Kredit-, Ausbildungs-, Finanzsanktions- und Hintergrundprüfungen), das Ergebnis Ihrer Bewerbung, Einzelheiten zum Stellenangebot sowie sonstige informelle Daten (z. B. während des Bewerbungsprozesses geäußerte Meinungen)
  • Online-Verhalten und Präferenzen, die über Cookies und andere Tracking-Technologien erfasst werden
  • Technische Daten, einschließlich elektronischer Kennungen, Lizenzberechtigung, IP-Adressen, Art der Domänennamen und Betriebssysteme, Protokolle, Zeitstempel von Nutzungsaktivitäten, Metriken zur Kontomodifizierung und -authentifizierung, Gerätekennungen, Geolokalisierungsdaten, Browsertyp und -sprache, Zugriffszeiten, verschlüsselte Passwörter und Sicherheitsfragen, Kontoverlauf und andere eindeutige Kennungen
  • Demografische Daten wie Ihr Alter, Geschlecht, Land, Interessen und Vorlieben, einschließlich Vorlieben in Bezug auf Marketing und Kommunikation
  • Audiovisuelle Daten, soweit zutreffend und rechtlich zulässig, einschließlich CCTV-Aufnahmen unserer Büros oder Gesprächsaufzeichnungen

Warum wir Daten verwenden

Commvault verwendet Daten, einschließlich personenbezogener Daten, für eine Vielzahl von Zwecken, darunter:

  • Lieferung und Optimierung unserer Lösungen
  • Bereitstellung von erstklassigem Support für unsere Lösungen
  • Optimierung und Personalisierung der Nutzererfahrung
  • Sicherheit, Rechnungsprüfung und Marketing
  • Bearbeitung von Zahlungen, Rechnungsstellung und Inkasso
  • Einstellung und Einstellungspraktiken
  • Geschäftsanalytik
  • Mitteilungen über unsere Lösungen, wie z. B. Erneuerungsbenachrichtigungen oder Veranstaltungen
  • Mit Ihrer Zustimmung und wenn wir beabsichtigen, Ihre Daten für Zwecke zu verwenden, die nicht in den Anwendungsbereich dieser Datenschutzrichtlinie oder einer anderen anwendbaren Rechtsgrundlage fallen, werden wir Ihre Zustimmung einholen
  • Wenn dies zur Erfüllung oder Durchsetzung eines Vertrags oder zur Einhaltung von Gesetzen erforderlich ist
  • Unsere legitimen Geschäftsinteressen, zum Beispiel die Verbesserung unserer Lösungen. Bevor wir solche Maßnahmen ergreifen, führen wir eine Bewertung durch, um sicherzustellen, dass unsere Interessen Ihre Datenschutzrechte nicht überwiegen

Soweit dies nach geltendem Recht zulässig ist, kann Commvault Ihre Daten in anonymisierter, automatisierter und aggregierter Form nutzen, verarbeiten, übertragen und weitergeben. Wir können diese Daten mit anderen erhobenen Informationen kombinieren, einschließlich Informationen aus Quellen Dritter. Durch die Nutzung der Lösungen erkennen Sie an, dass wir anonymisierte und aggregierte Daten für Benchmarking, Analysen, Metriken, Forschung, Berichterstattung, maschinelles Lernen und andere berechtigte geschäftliche Zwecke erheben, nutzen, weitergeben und speichern dürfen.

Wie wir Cookies, Web Beacons und andere Technologien verwenden

Our Websites and Portals use cookies, web beacons, and other similar technologies to improve the user experience. Cookies are small text files placed on a computer by a web server when browsing online and are used to store user preference data so a web server doesn’t have to repeatedly request this information. You can review and modify your cookie preferences by clicking on ‘Cookie Preferences’ at the footer of the page. However, you may not be able to access all or parts of our Solutions, Websites, or Portals if you block certain cookies. A web beacon is a small pixel incorporated into a web page or email to keep track of activity on the page or email and helps us manage the content of our Websites by informing us of what content is effective. For additional details on how Commvault uses cookies and other technologies, please refer to our Cookie-Erklärung.

Wie wir generative AI-Technologien einsetzen

Commvault setzt generative KI-Technologien ein, um interne Abläufe und unsere Lösungen zu verbessern. Intern nutzen wir generative KI, um Besprechungsnotizen und Erkenntnisse zu transkribieren, Diskussionen zusammenzufassen und Maßnahmen zur Effizienzsteigerung zu identifizieren. Außerdem nutzen wir generative KI zur Unterstützung der Erstellung von Inhalten, darunter technische Dokumentationen, Knowledge-Base-Artikel und Produkt-Support-Materialien, um Konsistenz und Genauigkeit zu gewährleisten. In unseren Lösungen bildet generative KI die Grundlage für Features wie Arlie, unseren KI-Assistenten, der Echtzeit-Fehlerbehebung und Lösungen für Betriebsstörungen, Unterstützung bei der Automatisierung sowie kontextsensitive Anleitungen bietet, um die Benutzererfahrung und die betriebliche Effizienz zu verbessern. Commvault verwendet keine Kundendaten zum Trainieren generativer KI-Modelle. Alle Daten, die im Rahmen dieser KI-gestützten Funktionen verarbeitet werden, werden unter strikter Einhaltung unserer Datenschutzrichtlinien und der geltenden Datenschutzbestimmungen behandelt, um Sicherheit, Transparenz und Benutzerkontrolle zu gewährleisten.

Nicht verfolgen

Commvault does not change its practices in response to Nicht verfolgen signals from web browsers.

When & Why We Share Your Personal Data

We do not and will not sell Personal Data to marketers or other vendors and we do not access the data protected by our Solutions for marketing or other purposes outside the scope of our Commvault’s Master Terms & Conditions and the applicable Datenvereinbarungen. Commvault may share data in the following categories: identifiers, customer records information, commercial information, internet or other network or device activity, and geolocation data. Commvault may share data or categories of data for the reasons set forth hierin with:

  • Commvault Affiliates. Commvault may share data with its affiliates whier necessary for administrative purposes or to deliver our Solutions.
  • Partners. Partners provide us with theirs and their customers’ data as part of marketing, sale and delivery of the Solutions.   Partner represents and warrants they have authorization or the required legal basis to obtain and share such data, including Personal Data, with us
  • Contractors and Service Providers. Commvault may share data, including Personal Data, with contracted third-party service providers (“Service Providers”). These Service Providers include business partners, payment services, advertising networks, IT and security service providers, auditors and consultants, customer survey companies, staffing and recruiting agencies, and cloud solutions and storage providers. Service Providers with whom we share Personal Data are contractually bound to use and disclose such Personal Data only for the permitted purposes and to provide the same level of protections as required by the relevant Data Privacy Framework (including onward transfer provisions). We require all our Service Providers to use reasonable security measures to protect Personal Data from unauthorized access and use.
  • Legal Purposes. Commvault may share data, including Personal Data, as necessary to comply with applicable laws, court orders, governmental agencies, or other lawful requests by public authorities, and to protect our security or integrity and that of our customers and partners, or to take precautions against legal liability.
  • Sale. In the event of a merger, consolidation, or acquisition of all, substantially all or a portion of Commvault’s business or assets, you acknowledge and agree that data may be securely shared, disclosed, and transferred to such successor or assignee.

Aufbewahrung von Daten

Wir können Daten, einschließlich personenbezogener Daten, so lange aufbewahren, wie dies zur Bereitstellung der Lösungen erforderlich ist oder für andere rechtmäßige Zwecke notwendig ist. Wenn Ihre Daten nicht mehr benötigt werden, stellen wir sicher, dass sie auf sichier Weise vernichtet werden. Wir können anonymisierte oder aggregierte Daten auf unbestimmte Zeit oder in dem nach geltendem Recht zulässigen Umfang aufbewahren.

Globales Datenmanagement

Commvault Systems, Inc. is located in the U.S. and has global offices. We act as: (i) a data controller when we collect and process Personal Data for our legitimate business interests, and (ii) a data processor when we provide certain of our Solutions to you as the data controller, joint-data controller, or joint-data processor. Commvault Systems International BV located at Papendorpseweg 75-79, 3528 BJ Utrecht, Netherlands serves as our main establishment for the European Union (“E.U.”). Commvault manages your data in compliance with the E.U.’s General Data Protection Regulation (“GDPR”) and other applicable data privacy and security laws. By using the Solutions, Websites or Portals or by providing Personal Data to us, you acknowledge that Personal Data may be sent to and processed in countries outside your country of residence. For individuals residing in the European Economic Area (“EEA”) and for Personal Data subject to GDPR, this may include transfers outside of the EEA. Some of these countries may not have data protection laws that provide an equivalent level of data protection as the laws in your country of residence, however we take steps to ensure Personal Data is handled in accordance with this al Data subject to GDPR, this may include transfers outside of the EEA. Some of these countries may not have data protection laws that provide an equivalent level of data protection as the laws in your country of residence, however we take steps to ensure Personal Data is handled in accordance with this Privacy Policy and all applicable laws. Commvault transfers data from the EEA pursuant to Standard Contractual Clauses, as approved by the European Commission (Art. 46 GDPR). If you are located in the EEA and would like to execute Standard Contractual Clauses with Commvault, please visit Datenvereinbarungen.

Erklärungen zur Einhaltung des Datenschutzrahmens

To learn more about Data Privacy Frameworks (“DPF”) program in detail, please visit https://www.dataprivacyframework.gov.

Commvault hält sich an das EU-US-Datenschutz-Rahmenwerk (EU-US-DPF), die britische Erweiterung des EU-US-DPF und das Schweizer-US-Datenschutz-Rahmenwerk (Swiss-US-DPF), wie sie vom US-Handelsministerium festgelegt wurden. Commvault hat gegenüber dem US-Handelsministerium bestätigt, dass es die Grundsätze des EU-US-Datenschutzrahmens (EU-US-DPF-Grundsätze) bei der Verarbeitung personenbezogener Daten einhält, die aus der Europäischen Union auf der Grundlage des EU-US-DPF sowie aus dem Vereinigten Königreich (und Gibraltar) auf der Grundlage der britischen Erweiterung des EU-US-DPF übermittelt werden. Commvault hat gegenüber dem US-Handelsministerium bestätigt, dass es die Grundsätze des Schweizer-US-Datenschutzrahmens (Swiss-U.S. DPF Principles) bei der Verarbeitung personenbezogener Daten einhält, die aus der Schweiz im Rahmen des Schweizer-US-Datenschutzrahmens (Swiss-U.S. DPF) übermittelt werden. Sollte es zu Widersprüchen zwischen den Bestimmungen dieser Datenschutzerklärung und den Grundsätzen des EU-US-DPF und/oder den Grundsätzen des Schweizer-US-DPF kommen, sind die Grundsätze maßgebend.

The Federal Trade Commission has jurisdiction over Commvault’s compliance with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF).

In Übereinstimmung mit der EU-U.S. DPF und der UK-Erweiterung der EU-U.S. DPF und der Swiss-U.S. DPF, verpflichtet sich Commvault zu:

  • Commvault stellt Einzelpersonen klare, auffällige und leicht zugängliche Mechanismen zur Verfügung, mit denen sie ihre persönlichen Daten frei wählen können. Commvault stellt Einzelpersonen einen Mechanismus zur Verfügung, mit dem sie die Weitergabe von Daten an Dritte oder die Verwendung persönlicher Daten für einen Zweck ablehnen können, der sich wesentlich von dem Zweck/den Zwecken unterscheidet, für den/die sie ursprünglich gesammelt und von der Einzelperson genehmigt wurden.
  • Wenn Commvault personenbezogene Daten, die wir im Vertrauen auf diesen Rahmen erhalten haben, an Dritte weitergibt, werden wir von diesen verlangen, dass sie in Übereinstimmung mit den Grundsätzen der DSGVO handeln. Commvault ist verantwortlich und kann für die Verarbeitung personenbezogener Daten, die wir erhalten und anschließend an Dritte weitergegeben haben, haftbar gemacht werden, es sei denn, wir können nachweisen, dass wir für das Ereignis, das den Schaden verursacht hat, nicht verantwortlich sind.
  • to cooperate and comply respectively with the advice of the panel established by the EU data protection authorities (DPAs), and the UK Information Commissioner’s Office (ICO), and the Gibraltar Regulatory Authority (GRA) and the Swiss Federal Data Protection and Information Commissioner (FDPIC) with regard to unresolved complaints concerning our handling of Personal Data received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF.
  • resolve DPF Principles-related complaints about our collection and use of your Personal Data. EU, UK and Swiss individuals with inquiries or complaints regarding our handling of Personal Data,  received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF should first contact us on the details indicated in the “Kontakt zu Commvault” section below.

If your complaint cannot be resolved through the above channels, under certain conditions, you may invoke binding arbitration for some residual claims not resolved by other redress mechanisms. Further information on arbitration can be found hier.

Sicherheit

Commvault maintains administrative, physical, and technical safeguards and security measures designed to protect data. Details of our data privacy and security program can be found in Annex II of the applicable Datenverarbeitungsvereinbarung. Wir können jedoch keine absolute Sicherheit für personenbezogene Daten garantieren oder gewährleisten, die über das Internet an uns oder einen Dritten offengelegt oder übermittelt werden, und wir glauben nicht, dass dies irgendjemandem möglich ist.

Opt-Out

Sie können den Erhalt von Marketing- und Werbemitteilungen von Commvault ablehnen, indem Sie die in einer solchen Mitteilung enthaltenen Anweisungen zur Abmeldung befolgen oder sich wie unten beschrieben an Commvault Systems, Inc. wenden. Wir werden weiterhin personenbezogene Daten verarbeiten, um betriebliche und dienstleistungsbezogene Mitteilungen in Bezug auf unsere Lösungen oder Richtlinien zu übermitteln, sowie für andere Zwecke, die gesetzlich zulässig sind.

Ihre Rechte

You may have certain rights with respect to Commvault’s handling of Personal Data depending on your geolocation, including without limitation:

  • Access. You have the right to access your Personal Data held by us. Consumers who reside in California may also request the categories of Personal Data we collect or disclose, the categories of sources of such Personal Data, the business or commercial purpose for collecting that Personal Data, and the categories of third parties with whom we share that Personal Data
  • Rectification. You have the right to request correction of your Personal Data that is incomplete, incorrect, unnecessary, or outdated
  • Right to be Forgotten. You have the right to request erasure of all your Personal Data that is incomplete, incorrect, unnecessary, or outdated within a reasonable period of time. We will do everything possible to erase your Personal Data if you so request. However, we cannot erase all your Personal Data if it is technically impossible due to limitations of existing technology or for legal reasons, such as legal mandates to retain Personal Data
  • Restriction of Processing. You have the right to request restriction of processing your Personal Data for certain reasons, provided we do not have an overriding, legitimate interest to continue processing
  • Data Portability. If requested, we will provide your Personal Data in a structured, secure, commonly used, and machine-readable format.
  • Right to Withdraw Consent. If your Personal Data is processed solely based on consent, and not based on any other legal basis, you can withdraw consent at any time.
  • Contact Data Protection Regulators. You have the right to contact data protection regulator(s) regarding our handling of Personal Data.

Additionally, California law provides California consumer residents with the right to not be discriminated against (as provided for in applicable law) for exercising rights thierunder. Further, under California’s “Shine the Light” law California consumer residents have the right, twice in a calendar year, to request and obtain from Commvault information about Personal Data Commvault has shared, if any, with other businesses for their own direct marketing uses. This information, if applicable, would include the categories of Personal Data and the names and addresses of those businesses with which Commvault shared Personal Data for the immediately prior calendar year (e.g., requests made in 2022 will receive information regarding 2021 sharing activities).

Third Party Linking & Content

The Solutions, Websites and Portals may contain links to third-party websites that Commvault does not control or maintain. We are not responsible for the privacy practices employed by these third-party websites and encourage you to read the privacy statements of such other websites before submitting any Personal Data. Our Website may contain third-party content which may include statements, opinions, advice, criticisms, offers or other information (collectively, “Third-Party Content”). Any Third-Party Content solely reflects the opinion and belief of the respective third party and not that of Commvault. We make no endorsement, guarantee or other statement, express or implied, about Third-Party Content. You must independently evaluate any Third-Party Content if you intend to rely on it in any way.

In Bezug auf Kinder

Commvault does not knowingly collect or distribute any Personal Data from children under 13 years old. If a child under 13 has provided Commvault with Personal Data, the parent or guardian of that child should contact Commvault immediately at privacy@commvault.com to delete this Personal Data.

Changes to Commvault’s Privacy Policy

As laws and best practices evolve, this Privacy Policy will change. At times we may provide privacy notices within our Solutions, Websites or Portals. By continuing to access our Websites and Portals or use our Solutions, you acknowledge and accept the Privacy Policy as updated. We encourage you to periodically review this Privacy Policy to stay informed about how we manage data. If we update this Privacy Policy, the new Privacy Policy will be posted to the website fifteen (15) days prior to the changes taking effect.  If we make a material change to the Privacy Policy, you will be provided with appropriate notice in accordance with legal requirements. At such time, your continued use of the Solutions, or access to our Websites and Portals after notice of posting or notice of such changes, constitutes your agreement to the latest version of this Privacy Policy.

Kontakt zu Commvault

Commvault’s Global Privacy Team can be contacted at privacy@commvault.com.

Bei Fragen, Beschwerden oder zur Ausübung Ihrer Rechte wenden Sie sich bitte an Commvault unter privacy@commvault.com. Wir ergreifen angemessene Maßnahmen zur Überprüfung Ihrer Identität, wenn Sie Ihre Rechte ausüben. Bitte stellen Sie sicher, dass Ihre Kontaktdaten aktuell und korrekt sind, damit wir Ihre Anfragen gemäß geltendem Recht und innerhalb einer angemessenen Frist bearbeiten können.

Sie können uns auch auf dem Postweg kontaktieren:

USA und internationale Regionen außerhalb des EWR, des Vereinigten Königreichs, der Schweiz oder Indiens:
Commvault Systeme, Inc.
z. Hd.: Rechtsabteilung/Global Data Governance Officer
Der Commvault-Weg
Tinton Falls, New Jersey 07724

EWR, Vereinigtes Königreich und Schweiz:
Commvault Systems International BV
z. Hd.: Rechtsabteilung/Global Data Governance Officer
Papendorpseweg 75–79, 3528 BJ
Utrecht, Niederlande

Indien:

Indisches Entwicklungszentrum

10. Etage, Atria, The V IT Park,
Grundstück Nr. 17, Software Units Layout,
Hitech City, Madhapur Hyderabad – 500081, Telangana

Zuletzt aktualisiert: Mai 2026