Name and contact of the Controller pursuant to Art. 4(7) GDPR
Phone: +49 (0)9571 / 929 970
Contact of Data Protection Officer: firstname.lastname@example.org
Security and protection of your Personal Data
Our top priority is to ensure the confidentiality of the Personal Data you provided, and to protect these data from unauthorized access. For this reason, we make every effort and use the most state-of-the-art security standards to ensure maximum protection of your Personal Data.
As a company under private law we are subject to the provisions of the European General Data Protection Regulation (GDPR) and the German Data Protection Act (Bundesdatenschutzgesetz – BDSG). We have taken all technical and organizational measures to make sure that all regulations regarding data protection are observed both by us and by our external service providers.
Definition of terms
The legislation requires Personal Data to be processed lawfully, fairly, and in a transparent manner in relation to the data subject (“lawfulness, fairness and transparency”). To ensure this, we inform you on the individual legal definitions of terms, which are also used in this Data Privacy Statement:
1. Personal Data
Personal Data means any information relating to an identified or identifiable natural person (hereinafter “Data Subject”); an identifiable person is a natural person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of such a natural person.
Processing means any operation or set of operations which is performed upon Personal Data, whether or not by automatic means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
3. Restriction of Processing
Restriction of Processing means the marking of stored Personal Data with the aim of limiting their Processing in future.
Profiling means any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements.
Pseudonymization means the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.
6. Filing System
Filing System means any structured set of Personal Data which is accessible according to specific criteria, whether centralized, decentralized, or dispersed on a functional or geographical basis.
Controller means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data; where the purposes and means of Processing are determined by Union or Member State law, the Controller or the specific criteria for their nomination may be provided for by Union or Member State law.
Processor means a natural or legal person, public authority, agency, or any other body which processes Personal Data on behalf of the Controller.
Recipient means a natural or legal person, public authority, agency, or any other body to whom Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the course of a particular inquiry in accordance with Union or Member State law shall not be regarded as Recipients; the Processing of those data by those public authorities shall be in compliance with the applicable data protection rules according to the purposes of the Processing.
10. Third Party
Third Party means a natural or legal person, public authority, agency, or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorized to process Personal Data.
Consent is any freely given, specific, informed and unambiguous indication of a Data Subject’s wishes by which he or she, by a statement or by clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.
Lawfulness of processing
The Processing of Personal Data will only be lawful if there is a legal basis for this Processing. The legal basis for Processing according to Article 6(1)(a–f) GDPR can be in particular:
a) the Data Subject has given Consent to the Processing of his or her Personal Data for one or more specific purposes;
b) Processing is necessary for the performance of a contract to which the Data Subject is party or in order to take steps at the request of the Data Subject prior to entering into a contract;
c) Processing is necessary for compliance with a legal obligation to which the Controller is subject;
d) Processing is necessary in order to protect the vital interests of the Data Subject or of another natural person;
e) Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller;
f) Processing is necessary for the purposes of the legitimate interests pursued by the Controller or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data, in particular where the Data Subject is a child.
Information regarding the collection of Personal Data
(1) In the following we are going to inform you about the collection of Personal Data when using our website. Personal Data include, for example, name, address, email addresses, user behavior
(2) If you contact us via email or a contact form, we will save the data you provided to us (your email address; your name and telephone number (if available)) to respond to your inquiries. We will delete the data acquired in this context as soon as their storage is no longer required, or their Processing will be restricted if they are subject to legal retention obligations.
Collecting Personal Data during the visit of our website
if the website is used for information only, i.e., you neither register nor otherwise transmit information to us, we will collect only the Personal Data transmitted by your browser to our server. If you wish to view our website, we collect the following data technically required to display the website to you as well as to ensure stability and security (the legal basis is Art. 6(1)(1)(f) GDPR):
• IP address
• Date and time of the request
• Time zone difference to Greenwich Mean Time (GMT)
• Access contents (concrete page)
• Access status/HTTP status code
• The respective data volume transmitted
• Website from which the request comes
• Operating system and its interface
• Language and version of the browser software
Purpose limitation of Personal Data Processing
(1) We process the data you provide in accordance with the principles of data minimization and purpose limitation. According to the principle of purpose limitation, Personal Data shall be collected for specified, explicit, and legitimate purposes and not be further processed in a manner that is incompatible with those purposes. Further Processing for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes shall not be considered to be incompatible with the initial purposes.
(2) We generally process your Personal Data for the purpose of replying to your requests, processing your orders, or providing access to certain information or offers. To maintain customer relationships it may also be necessary for us or a service provider commissioned by us to use these data to inform you about product offers or to conduct online surveys in order to better fulfill our customers' tasks and requests.
(3) We will only use the Personal Data you provide online for the purposes we informed you about. Your Personal Data will not be forwarded to Third Parties unless you have expressly given your Consent. Personal Data are collected and transferred to the respective entitled national institutions and authorities in strict accordance with the relevant legislation and/or as per court order.
(4) If you choose not to have your data used to support our customer relationship (especially direct marketing or market research), we will, of course, respect your choice. We shall neither sell your Personal Data to Third Parties nor shall we otherwise market them, unless you have granted us your Consent to do so.
Data erasure and storage
(1) Your data will only be stored until the purpose for which they were collected has been achieved and they are not subject to any other legal retention obligations (e.g., retention obligations relating to tax and commercial law).
(2) If you have granted us your Consent, we will store your data until you revoke your Consent, provided that there is no other legal basis for the Processing of your data, and no statutory retention periods stand in the way of the erasure.
(3) Moreover, a longer retention may be necessary in individual cases, e.g., for evidential purposes for the defense against/enforcement of claims under civil or public law.
(1) In addition to the above mentioned data, cookies will be stored on your computer when you use our website. Cookies are small text files that are stored on your hard drive allocated to the browser you use, and with the help of which the body that places the cookie obtains certain information. Cookies cannot run programs or deliver viruses to your computer. They are aimed at making the website generally more user-friendly and more efficient.
(2) This website uses the following types of cookies; their scope and function will be explained in the following:
• Transient cookies (see a.)
• Persistent cookies (see b.).
a) Transient cookies will be deleted automatically as soon as you close your browser. This group includes session cookies in particular. They store a so-called session ID that allows for the allocation of different requests from your browser to the common session. Due to this, your computer can be recognized when you return to our website. The session cookies will be deleted as soon as you log out or close your browser.
b) Persistent cookies will be deleted automatically after a specified period that can differ depending on the cookie. You can delete the cookies at any time in the security settings of your browser.
c) You can configure your browser settings as desired, i.e., to block third-party cookies. “Third-party cookies” are cookies that have been placed by a Third Party, i.e., not by the website you are actually visiting. Please note that if you disable cookies, you may no longer be able to use all of the features of this website to their full extent.
Other functions and offers of our website
1) Along with the use of our website for information purposes only, you have a number of different services at your disposal. If you wish to make use of these, you normally have to indicate additional Personal Data that will be used to provide the respective service and that will be treated in accordance with the previously specified principles of data Processing.
(2) We partly use external service providers for Processing your data. These service providers have been carefully selected and commissioned, are bound by our instructions, and are subject to regular checks.
(3) Furthermore, we can pass on your Personal Data to Third Parties if campaigns, sweepstakes, contract conclusions, or similar activities are provided by us jointly with our partners. You will obtain further relevant information when you submit your Personal Data or in the description of the offer below.
(4) If our service providers or partners are based in a country outside the European Economic Area (EEA), we will inform you about the consequences of this circumstance in the description of the offer.
Our websites contain so-called embeddings of YouTube videos. However, they only allow the connection to YouTube. YouTube is a service of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; in the European Economic Area and in Switzerland, the service is provided by Google Ireland Limited based in Gordon House, Barrow Street, Dublin 4, Ireland (in the following referred to as “Google”).
In this context, we use the “extended data protection mode” option provided by YouTube. f you access an embedded video, a connection will be established to the YouTube servers and, in doing so, the contents will be displayed on the website via the notification to your browser.
According to YouTube, if the “extended data protection mode” is used, your data (e.g., IP address) will be transmitted to the YouTube server in the USA only if you watch the video. By clicking on the video, you give your Consent to such transmission.
If you are logged into YouTube at the same time, this information can be associated with your YouTube member account. You can prevent this by logging out of your YouTube account before accessing our website.
By embedding YouTube, we aim to show you different videos that you can watch directly on our website.
The legal basis for the Processing of Personal Data as described here is Art. 6(1)(1)(f) GDPR. Our legitimate interest required in this regard consists in the significant benefit offered by YouTube. By embedding external videos, we reduce the load on our servers and can use the respective resources for other purposes. This can, among others, increase the stability of our servers. YouTube and/or Google additionally has a legitimate interest in the (Personal) data collected to improve its own services.
If a respective Consent to using and/or saving cookies has been requested and provided, the Processing will take place exclusively on the basis of Art. 6(1)(1)(a) GDPR. You can withdraw your Consent at any time with effect for the future by clicking on the cookie settings. In this case, an opt-out cookie that prevents the collection of your data during future visits of this website will be set.
Notes on the privacy settings of Google are provided here: https://privacy.google.com/take-control.html?categories_activeEl=sign-in