1. DATA PROTECTION AT A GLANCE
The following notes provide a simple overview of what happens to your personal data when you visit our website. Personal data are all data with which you can be personally identified. For detailed information on the subject of data protection, please refer to our data protection declaration listed below this text.
DATA COLLECTION ON OUR WEBSITE
Who is responsible for data collection on this website?
The data processing on this website is carried out by the website operator. His contact details can be found in the imprint of this website.
How do we collect your data?
On the one hand, your data is collected when you provide it to us. This can be data that you enter in a contact form, for example.
Other data is automatically collected by our IT systems when you visit the website. These are mainly technical data (e.g. internet browser, operating system or time of the page call). This data is collected automatically as soon as you enter our website.
What do we use your data for?
Part of the data is collected to ensure that the website is provided without errors. Other data can be used to analyze your user behavior.
What rights do you have regarding your data?
You have the right to receive information free of charge about the origin, recipient and purpose of your stored personal data at any time. You also have the right to demand the correction, blocking or deletion of this data. For this purpose, as well as for further questions regarding data protection, you can contact us at any time at the address given in the imprint. Furthermore, you have a right of appeal to the responsible supervisory authority.
Furthermore, you have the right to demand under certain circumstances the restriction of the processing of your personal data. For details, please refer to the data protection declaration under “Right to limit processing”.
THIRD-PARTY ANALYSIS TOOLS AND TOOLS
When you visit our website, your surfing behavior can be statistically evaluated. This is mainly done with cookies and with so-called analysis programs. The analysis of your surfing behavior is usually anonymous; the surfing behavior cannot be traced back to you. You can object to this analysis or prevent it by not using certain tools. You will find detailed information on this in the following data protection declaration.
You can contradict this analysis. We will inform you about the possibilities of objection in this data protection declaration.
2. GENERAL NOTES AND MANDATORY INFORMATION
The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the legal data protection regulations and this data protection declaration.
We would like to point out that data transmission over the Internet (e.g. communication by e-mail) can have security gaps. A complete protection of data against access by third parties is not possible.
NOTE TO THE RESPONSIBLE OFFICE
The party responsible for data processing on this website is:
Márta Judit Vitális
Adress: Mariannenstraße 2 10997 Berlin, Germany
Phone: +49 (0) 163 1609753
Responsible party is the natural or legal person who, alone or jointly with others, decides on the purposes and means of processing personal data (e.g. names, e-mail addresses, etc.).
REVOCATION OF YOUR CONSENT TO DATA PROCESSING
Many data processing operations are only possible with your express consent. You can revoke any consent already given at any time. For this purpose, an informal notification by e-mail to us is sufficient. The legality of the data processing carried out up to the time of revocation remains unaffected by the revocation.
RIGHT TO OBJECT TO DATA COLLECTION IN SPECIAL CASES AND TO DIRECT ADVERTISING (ART. 21 GDPR)
If the data processing is carried out on the basis of Article 6. Paragraph 1 letter e) or f) GDPR, you have the right to object to the processing of your personal data at any time for reasons arising from your particular situation, including profiling based on these provisions. You will find the respective legal basis on which processing is based in this data protection declaration. If you object, we will no longer process your personal data unless we can demonstrate compelling reasons for processing which are worthy of protection and which outweigh your interests, rights and freedoms, or unless the processing serves the assertion, exercise or defense of legal claims (objection under Art. 21 para. 1 GDPR).
If your personal data are processed for the purpose of direct marketing, you have the right to object at any time to the processing of personal data concerning you for the purpose of such marketing, including profiling, insofar as it is connected with such direct marketing. If you object, your personal data will no longer be used for the purpose of direct marketing (objection under Art. 21 para. 2 GDPR).
RIGHT OF APPEAL TO THE COMPETENT SUPERVISORY AUTHORITY
In the case of infringements of the GDPRs, the persons concerned have a right of appeal to a supervisory authority, in particular in the Member State of their habitual residence, place of work or place of the suspected infringement. This right of appeal is without prejudice to other administrative or judicial remedies.
RIGHT TO DATA PORTABILITY
You have the right to have data, which we process automatically on the basis of your consent or in fulfilment of a contract, handed over to you or to a third party in a common, machine-readable format. If you request the direct transfer of the data to another responsible party, this will only take place to the extent that it is technically feasible.
INFORMATION, BLOCKING, DELETION AND CORRECTION
Within the framework of the applicable legal provisions, you have the right to obtain information free of charge at any time about your stored personal data, its origin and recipients and the purpose of the data processing and, if applicable, a right to correct, block or delete this data. For this purpose, as well as for further questions regarding personal data, you can contact us at any time at the address given in the imprint.
RIGHT TO LIMITATION OF PROCESSING
You have the right to request the restriction of the processing of your personal data. To do so, you can contact us at any time at the address given in the imprint. The right to restrict processing exists in the following cases:
If you dispute the correctness of your personal data stored with us, we usually need time to check this. For the duration of the review, you have the right to demand the restriction of the processing of your personal data.
If the processing of your personal data was/is unlawful, you can demand the restriction of data processing instead of deletion.
If we no longer need your personal data, but you do need it to exercise, defend or assert legal claims, you have the right to demand restriction of the processing of your personal data instead of deletion.
If you have lodged an objection in accordance with Art. 21 para. 1 GDPR, a balance must be struck between your interests and ours. As long as it is not yet clear whose interests outweigh the interests of the parties concerned, you have the right to demand that the processing of your personal data be restricted.
If you have restricted the processing of your personal data, these data – apart from their storage – may only be processed with your consent or for the purpose of asserting, exercising or defending legal claims or protecting the rights of another natural or legal person or for reasons of an important public interest of the European Union or a Member State.
3. DATA COLLECTION ON OUR WEBSITE
The Internet pages partly use so-called cookies. Cookies do not damage your computer and do not contain viruses. Cookies serve to make our offer more user-friendly, effective and safer. Cookies are small text files that are stored on your computer and saved by your browser.
Most of the cookies we use are so-called “session cookies”. They are automatically deleted at the end of your visit. Other cookies remain stored on your end device until you delete them. These cookies enable us to recognize your browser the next time you visit us.
You can set your browser to inform you about the setting of cookies and to allow cookies only in individual cases, to exclude the acceptance of cookies for certain cases or in general, and to activate the automatic deletion of cookies when closing the browser. If you deactivate cookies, the functionality of this website may be limited.
Cookies that are required to carry out the electronic communication process or to provide certain functions that you have requested (e.g. shopping basket function) are stored on the basis of Art. 6 para. 1 let. f) GDPR. The website operator has a legitimate interest in the storage of cookies for the technically error-free and optimized provision of his services. Insofar as other cookies (e.g. cookies for analyzing your surfing behavior) are stored, these are treated separately in this data protection declaration.
INQUIRY BY E-MAIL, TELEPHONE OR FAX
If you contact us by e-mail, telephone or fax, your inquiry including all personal data (name, inquiry) will be stored and processed by us for the purpose of processing your request. We will not pass on this data without your consent.
This data is processed on the basis of Art. 6 para. 1 let. b GDPR, provided that your inquiry is related to the fulfilment of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, processing is based on your consent (Art. 6 para. 1 let. a) GDPR) and / or on our legitimate interests (Art. 6 para. 1 let. f) GDPR), as we have a legitimate interest in the effective processing of the inquiries addressed to us.
The data sent to us by you via contact enquiries will remain with us until you request us to delete it, revoke your consent to its storage or the purpose for which it was stored ceases to apply (e.g. after your request has been processed). Mandatory statutory provisions – in particular statutory retention periods – remain unaffected.
COMMENT FUNCTION ON THIS WEBSITE
For the comment function on this page, in addition to your comment, information on the time of the comment’s creation, your e-mail address and, if you are not posting anonymously, the user name you have chosen are stored.
Storage of the IP address
Our comment function stores the IP addresses of users who post comments. Since we do not check comments on our site before they are activated, we need this data to be able to take action against the author in case of legal violations such as insults or propaganda.
Storage period of the comments
The comments and the associated data (e.g. IP address) are saved and remain on our website until the commented content has been completely deleted or the comments have to be deleted for legal reasons (e.g. insulting comments).
The storage of comments is based on your consent (Art. 6 para. 1 let. a) GDPR). You can revoke any consent you have given at any time. All you need to do is send us an informal message by e-mail. The legality of the data processing operations already carried out remains unaffected by the revocation.
PROCESSING OF DATA (CUSTOMER AND CONTRACT DATA)
We collect, process and use personal data only to the extent that they are necessary for the establishment, content or modification of the legal relationship (inventory data). This is done on the basis of Art. 6 para. 1 let. b) GDPR, which permits the processing of data for the fulfilment of a contract or pre-contractual measures. We collect, process and use personal data on the use of our Internet pages (usage data) only to the extent necessary to enable or charge the user for the use of the service.
The collected customer data will be deleted after completion of the order or termination of the business relationship. Legal retention periods remain unaffected.
4. SOCIAL MEDIA
ERECHT24 SAFE SHARING TOOL
The content on our pages can be shared in social networks such as Instagram, LinkedIn or Twitter in accordance with data protection regulations. This site uses the eRecht24 Safe Sharing Tool for this purpose. This tool establishes direct contact between the networks and users only when the user actively clicks on one of these buttons. The click on the button represents consent in the sense of Art. 6 para. 1 let. a) GDPR. This consent can be revoked at any time with effect for the future.
This tool does not automatically transfer user data to the operators of these platforms. If the user is registered with one of the social networks, an information window appears when using the social buttons of Facebook, LinkedIn, Twitter & Co. in which the user can confirm the text before sending it.
Our users can share the contents of this page in social networks in compliance with data protection regulations without having to create complete surfing profiles by the operators of the networks.
5. ANALYSIS TOOLS AND ADVERTISING
This website uses functions of the web analysis service Google Analytics. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
Google Analytics uses so-called “cookies”. These are text files which are stored on your computer and which enable an analysis of your use of the website. The information generated by the cookie about your use of this website is usually transferred to a Google server in the USA and stored there.
The storage of Google Analytics cookies and the use of this analysis tool are based on Art. 6 para. 1 let. f) GDPR. The website operator has a legitimate interest in the analysis of user behavior in order to optimize both his website and his advertising.
We have activated the IP anonymization function on this website. This means that your IP address will be truncated by Google within member states of the European Union or in other signatory states to the Agreement on the European Economic Area before it is transmitted to the USA. Only in exceptional cases will the full IP address be transferred to a Google server in the USA and shortened there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, to compile reports on the website activities and to provide further services to the website operator in connection with the use of the website and the Internet. The IP address transmitted by your browser within the framework of Google Analytics is not combined with other data from Google.
Objection to data collection
You can prevent the collection of your data by Google Analytics by clicking on the following link. An opt-out cookie is set to prevent the collection of your information on future visits to this site: Disable Google Analytics.
We have concluded a contract with Google for order processing and fully implement the strict requirements of the German data protection authorities when using Google Analytics.
Demographic characteristics in Google Analytics
This website uses the “demographic features” function of Google Analytics. This allows reports to be generated that contain information about the age, gender and interests of the site visitors. This data comes from interest-based advertising by Google as well as from visitor data from third parties. This data cannot be attributed to any specific person. You can disable this feature at any time by changing the ad settings in your Google Account, or generally prohibit Google Analytics from collecting your information as described in the “Opting out of data collection” section.
User-level and event-level data stored by Google that is linked to cookies, user IDs (e.g., User ID) or advertising IDs (e.g., DoubleClick cookies, Android advertising ID) is anonymized or deleted after 26 months. Please see the following link for details: https://support.google.com/analytics/answer/7667196?hl=de
This website uses the WordPress Tool Stats to statistically evaluate visitor access. The provider is Automattic Inc, 60 29th Street #343, San Francisco, CA 94110-4929, USA.
“WordPress-Stats” cookies remain on your terminal until you delete them.
The storage of “WordPress Stats” cookies and the use of this analysis tool are based on Art. 6 para. 1 let. f GDPR. The website operator has a legitimate interest in the anonymized analysis of user behavior in order to optimize both his website and his advertising.
You can set your browser to inform you about the setting of cookies and to allow cookies only in individual cases, to exclude the acceptance of cookies for certain cases or in general, and to activate the automatic deletion of cookies when closing the browser. If you deactivate cookies, the functionality of our website may be limited.
You can object to the collection and use of your data for the future by setting an opt-out cookie in your browser by clicking on this link: https://www.quantcast.com/opt-out/.
If you delete the cookies on your computer, you will need to set the opt-out cookie again.
GOOGLEADS AND GOOGLE CONVERSION TRACKING
This website uses GoogleAds is an online advertising program of Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
As part of GoogleAds, we use what is known as conversion tracking. When you click on an ad placed by Google, a conversion tracking cookie is set. Cookies are small text files that the web browser places on the user’s computer. These cookies expire after 30 days and are not used to personally identify users. If the user visits certain pages of this website and the cookie has not expired, Google and we may recognize that the user clicked on the ad and was redirected to that page.
Each GoogleAds customer receives a different cookie. The cookies cannot be tracked through the websites of GoogleAds customers. The information collected through the conversion cookie is used to compile conversion statistics for GoogleAds customers who have opted in to conversion tracking. Customers are told the total number of users who clicked on their ad and were redirected to a page with a conversion tracking tag. However, they do not receive any information that can be used to personally identify users. If you don’t want to participate in tracking, you can opt-out of this use by slightly disabling the Google Conversion Tracking cookie on your web browser under User Preferences. You will then not be included in the conversion tracking statistics.
The storage of “conversion cookies” and the use of this tracking tool are based on Art. 6 para. 1 let. f) GDPR. The website operator has a legitimate interest in the analysis of user behavior in order to optimize both his website and his advertising.
More information on GoogleAds and Google Conversion Tracking can be found in the Google data protection regulations: https://policies.google.com/privacy?hl=de.
You can set your browser to inform you when cookies are set and to allow cookies only in individual cases, to exclude the acceptance of cookies for specific cases or in general, and to activate the automatic deletion of cookies when the browser is closed. If you deactivate cookies, the functionality of this website may be limited.
Our website uses the visitor action pixel of Facebook, Facebook Inc. 1601 S. California Ave, Palo Alto, CA 94304, USA (“Facebook”) to measure conversion.
This allows us to track the behavior of site visitors after they have clicked on a Facebook ad to be directed to the provider’s website. This allows the effectiveness of the Facebook Ads to be evaluated for statistical and market research purposes and to optimize future advertising efforts.
The collected data is anonymous to us as the operator of this website, we cannot draw any conclusions about the identity of the users. However, the data is stored and processed by Facebook, so that a connection to the respective user profile is possible and Facebook can use the data for its own advertising purposes, in accordance with the Facebook Data Usage Policy. This allows Facebook to enable the placement of advertisements on pages of Facebook and outside of Facebook. This use of the data cannot be influenced by us as a site operator.
The use of Facebook pixels is based on Art. 6 para. 1 let. f GDPR. The website operator has a legitimate interest in effective advertising measures, including social media.
You can also deactivate the remarketing function “Custom Audiences” in the Advertising Settings section at https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen. You must be logged in to Facebook to do this.
If you do not have a Facebook account, you can disable usage-based advertising from Facebook on the European Interactive Digital Advertising Alliance website: http://www.youronlinechoices.com/de/praferenzmanagement/.
For further details, please see the ‘about Hotjar’ section of Hotjar’s support site.
This website uses the services of MailChimp for sending newsletters. Provider is Rocket Science Group LLC, 675 Ponce De Leon Ave NE, Suite 5000, Atlanta, GA 30308, USA.
MailChimp is a service to organize and analyze the sending of newsletters. If you enter data for the purpose of receiving newsletters (e.g. e-mail address), this data is stored on the servers of MailChimp in the USA.
MailChimp is certified according to the “EU-US-Privacy-Shield”. The “Privacy-Shield” is an agreement between the European Union (EU) and the USA, which is intended to ensure compliance with European data protection standards in the USA.
With the help of MailChimp we can analyze our newsletter campaigns. When you open an e-mail sent with MailChimp, a file contained in the e-mail (so-called web-beacon) connects to the servers of MailChimp in the USA. This way it can be determined whether a newsletter message has been opened and which links have been clicked on. Furthermore, technical information is collected (e.g. time of retrieval, IP address, browser type and operating system). This information cannot be assigned to the respective newsletter recipient. It is used exclusively for statistical analysis of newsletter campaigns. The results of these analyses can be used to better adapt future newsletters to the interests of the recipients.
If you do not want to be the subject of any analysis by MailChimp, you have to unsubscribe from the newsletter. For this purpose, we provide a corresponding link in every newsletter message. Furthermore, you can unsubscribe the newsletter directly on the website.
The data processing is based on your consent (Art. 6 para. 1 let. a) GDPR). You can revoke this consent at any time by unsubscribing the newsletter. The legality of the data processing operations already carried out remains unaffected by the revocation.
The data that you provide us with for the purpose of subscribing to the newsletter will be stored by us until you unsubscribe from the newsletter and will be deleted from our servers as well as from the servers of MailChimp after the cancellation of the newsletter. Data, which were stored for other purposes remain unaffected.
7. PLUGINS AND TOOLS
GOOGLE WEB FONTS
This site uses so-called web fonts, which are provided by Google, for the uniform display of fonts. When you call up a page, your browser loads the required web fonts into its browser cache in order to display texts and fonts correctly.
To do this, the browser you are using must connect to Google’s servers. This enables Google to know that our website has been accessed via your IP address. The use of Google Web Fonts is in the interest of a uniform and attractive presentation of our online offers. This represents a legitimate interest in the sense of Art. 6 para. 1 let. f) GDPR.
If your browser does not support web fonts, a standard font from your computer will be used.
This site uses the map service Google Maps via an API. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
To use the functions of Google Maps it is necessary to store your IP address. This information is usually transferred to a Google server in the USA and stored there. The provider of this site has no influence on this data transfer.
The use of Google Maps is in the interest of an attractive presentation of our online offers and to make it easy to find the places we have indicated on the website. This represents a legitimate interest in the sense of Art. 6 para. 1 let. f) GDPR.
We use “Google reCAPTCHA” (hereinafter “reCAPTCHA”) on our websites. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
The purpose of reCAPTCHA is to check whether the data input on our websites (e.g. in a contact form) is done by a human being or by an automated program. For this purpose, reCAPTCHA analyses the behavior of the website visitor based on various characteristics. This analysis starts automatically as soon as the website visitor enters the website. For analysis purposes, reCAPTCHA evaluates various information (e.g. IP address, time spent on the website or mouse movements made by the user). The data collected during the analysis is forwarded to Google.
The reCAPTCHA analyses run completely in the background. Website visitors are not informed that an analysis is taking place.
The data processing is based on Art. 6 para. 1 let. f) GDPR. The website operator has a legitimate interest in protecting his web offers from abusive automated spying and from SPAM.
8. PAYMENT PROVIDERS AND RESELLERS
On our website we offer payment via PayPal among other things. The provider of this payment service is PayPal (Europe) S.à.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter “PayPal”).
If you choose to pay via PayPal, the payment data you enter will be transmitted to PayPal.
The transmission of your data to PayPal is based on art. 6 para. 1 let. a) GDPR (consent) and art. 6 para. 1 let. b) GDPR (processing for the performance of a contract). You have the possibility to revoke your consent to data processing at any time. Revocation does not affect the effectiveness of data processing operations carried out in the past.
INSTANT BANK TRANSFER
On our website we offer among other things the payment by “Sofortüberweisung” (Instant bank transfer). The provider of this payment service is Sofort GmbH, Theresienhöhe 12, 80339 Munich, Germany (hereinafter “Sofort GmbH”).
With the help of the “Sofortüberweisung” (Instant bank transfer) procedure, we receive a payment confirmation from Sofort GmbH in real time and can immediately begin to fulfill our obligations.
If you have chosen the payment method “Sofortüberweisung” (Instant bank transfer), please send the PIN and a valid TAN to Sofort GmbH, with which it can log into your online banking account. Sofort GmbH automatically checks your account balance after logging in and carries out the transfer to us with the help of the TAN you have transmitted. Afterwards, it immediately sends us a transaction confirmation. After logging in, your turnover, the credit limit of the overdraft facility and the existence of other accounts and their balances are also checked automatically.
In addition to the PIN and the TAN, the payment data entered by you as well as personal data will be transmitted to Sofort GmbH. The data about your person are first and last name, address, telephone number(s), email address, IP address and possibly other data required for payment processing. The transmission of this data is necessary to determine your identity beyond doubt and to prevent fraud attempts.
The transmission of your data to Sofort GmbH takes place on the basis of art. 6 para. 1 let. a) GDPR (consent) and art. 6 para. 1 let. b) GDPR (processing to fulfill a contract). You have the possibility to revoke your consent to data processing at any time. Revocation does not affect the effectiveness of data processing operations carried out in the past.
9. OUR SOCIAL-MEDIA APPEARANCES
DATA PROCESSING THROUGH SOCIAL NETWORKS
We maintain publicly accessible profiles in social networks. You can find the social networks we use in detail below.
Social networks such as Facebook, LinkedIn etc. can usually analyze your user behavior comprehensively when you visit their website or a website with integrated social media content (e.g. like buttons or advertising banners). Visiting our social media sites triggers numerous data protection-relevant processing procedures. In detail:
If you are logged in to your social media account and visit our social media presence, the operator of the social media portal can assign this visit to your user account. However, your personal data may also be collected if you are not logged in or do not have an account with the respective social media portal. In this case, this data is collected, for example, via cookies that are stored on your end device or by recording your IP address.
With the help of the data collected in this way, the operators of the social media portals can create user profiles in which your preferences and interests are stored. In this way, interest-related advertising can be displayed to you both inside and outside the respective social media presence. If you have an account with the respective social network, interest-based advertising can be displayed on all devices on which you are or were logged in.
Our social media appearances are designed to ensure the most comprehensive presence possible on the Internet. This is a legitimate interest within the meaning of Art. 6 para. 1 let. f) GDPR. The analysis processes initiated by the social networks may be based on different legal bases, which must be stated by the operators of the social networks (e.g. consent within the meaning of Art. 6 para. 1 let. a) GDPR).
Responsibility and assertion of rights
If you visit one of our social media sites (e.g. Facebook), we are jointly responsible with the operator of the social media platform for the data processing operations triggered during this visit. You can assert your rights (information, correction, deletion, restriction of processing, data transferability and complaint) against us as well as against the operator of the respective social media portal (e.g. against Facebook).
Please note that despite the joint responsibility with the social media portal operators, we do not have full influence on the data processing procedures of the social media portals. Our possibilities are largely determined by the corporate policy of the respective provider.
The data collected directly by us via the social media presence will be deleted from our systems as soon as the purpose for storing them no longer applies, you request us to delete them, revoke your consent to storage or the purpose for storing the data no longer applies. Stored cookies remain on your end device until you delete them. Mandatory legal provisions – in particular retention periods – remain unaffected.
SOCIAL NETWORKS IN DETAIL
We have a profile on Facebook. The provider is Facebook Inc, 1 Hacker Way, Menlo Park, California 94025, USA. Facebook is certified according to the EU-US Privacy Shield.
We have concluded a joint processing agreement (Controller Addendum) with Facebook. This agreement defines the data processing operations for which we or Facebook are responsible when you visit our Facebook page. You can view this Agreement by clicking on the following link: https://www.facebook.com/legal/terms/page_controller_addendum.
You can adjust your advertising settings independently in your user account. To do so, click on the following link and log in: https://www.facebook.com/settings?tab=ads.
We have a profile on LinkedIn. The provider is LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland. LinkedIn is certified according to the EU-US Privacy Shield. LinkedIn uses advertising cookies.
If you want to disable LinkedIn advertising cookies, please use the following link: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.