1. Responsible for data processing
The controller for data processing in accordance with the provisions of the General Data Protection Regulation (GDPR) is:
Tel.: +49 6221 6559300
2. Contact details of our data protection officer
3. General information on data processing
We process data as part of our business and website operations.
This also includes disclosure by transmission to third parties and, where applicable, to so-called third countries outside the European Union ("EU") and the European Economic Area ("EEA"). Where we transfer data outside the EU or the EEA, we have marked this accordingly below.
4. Data processing
The individual data concerned, processing purposes, legal bases, recipients and, where applicable, transfers to third countries are listed below:
a) Log file when visiting the website
We log your website visit. In doing so, we process:
- Name(s) of our accessed website(s),
- Date and time of retrieval,
- the amount of data transferred,
- the browser type and version,
- the operating system you are using,
- the referrer URL (the previously visited website),
- Your IP address,
- the requesting provider.
The legal basis for data processing is our overriding legitimate interest in the ongoing provision and security of our website in accordance with Art. 6 (1) f) GDPR.
The log file is erased after seven days, unless it is needed to prove or clarify specific legal violations that have become known within the retention period.
To provide our online presence, we use the services of web hosting providers who process the above-mentioned data and all data to be processed in connection with the operation of this website (log file when visiting the website) on our behalf.
The legal basis for data processing is our overriding legitimate interest in the provision of our website in accordance with Art. 6 (1) f) GDPR.
For our hosting we use Netlify Inc. , 2325 3rd Street, Suite 29, San Francisco, CA 94104, USA.
There is no adequacy decision by the EU Commission for data transfers to the USA. Netlify ensures an adequate level of data protection via the EU standard contractual clauses. We will provide a copy of the contractual clauses upon request. For this purpose, please contact firstname.lastname@example.org.
If you contact us, we process the following data from you for the purpose of processing and handling your enquiry: Name, contact details -if provided by you- and your message.
The legal basis of the data processing is our obligation to fulfil the contract and/or to fulfil our pre-contractual obligations pursuant to Art. 6 (1) b) GDPR and/or our overriding legitimate interest in processing your enquiry pursuant to Art. 6 (1) f) GDPR.
d) Use of functional cookies
We use so-called cookies on our website. Cookies are small text files that are stored on your respective end device (PC, smartphone, tablet, etc.) and saved by your browser.
We only use technically necessary session cookies on our website.
In order to document your selection of certain data processing procedures, to obtain your consent where necessary, and to fulfill our obligations under data protection law, we use a consent banner that asks for your preferences. We then set a technically required cookie in which data on consent given or revoked is stored. The data processing is carried out to fulfill our legal obligations according to Art 6 (1) c) GDPR.
In order to provide you with regular information about our company and our offers, we offer the dispatch of an e-mail newsletter. With your newsletter registration, we process the data you entered during registration (e-mail address and other voluntary information). In order to prevent misuse, we will send you an e-mail after your registration in which we ask you to confirm your registration (double opt-in procedure). In order to be able to prove the registration process in a legally compliant manner, your registration is logged. This concerns the time of registration and confirmation as well as your IP address.
The legal basis for sending the newsletter is your consent in accordance with Art. 6 (1) a) GDPR. The data processing in connection with the sending of the confirmation email for your registration and the associated data logging is carried out in accordance with Art. 6 (1) f) GDPR due to our legitimate interest in proving your proper registration.
For sending the newsletter, we use a service provider as a processor with headquarters and server location in Germany, with whom we have concluded a processing contract.
5. Duration of data storage
We only store personal data for as long as it is necessary for the purposes for which it is processed or if you have withdrawn your consent. Insofar as statutory retention obligations must be observed, the storage period for certain data can be up to 10 years, irrespective of the processing purposes.
6. Your data subject rights
Upon request, we will provide you with information on all personal data we have stored about you at any time and free of charge.
b) Rectification, deletion, restriction of processing (blocking), objection
If you no longer agree to the storage of your personal data or if it has become incorrect, we will arrange for the deletion or blocking of your data or make the necessary corrections (insofar as this is possible under the applicable law) upon instruction to do so. The same applies if we are only to process data in a restrictive manner in the future. You have the right to object in particular in cases where your data is required for the performance of a task that is in the public interest or the data processing is carried out on the basis of our legitimate interest, as well as profiling based on this. You also have such a right to object in the event of data processing for the purpose of direct marketing.
c) Right of revocation for consents with effect for the future
You can revoke any consent you have given at any time with effect for the future. Your revocation does not affect the lawfulness of the processing until the time of revocation.
d) Data portability
If data processing is based on a contract, pre-contractual negotiations, consent or automated procedures, you have the right to data portability. Upon request, we will provide you with your data in a common, structured and machine-readable format so that you can transfer the data to another controller upon request.
e) Restriction of processing
Data for which we are not able to identify the data subject, e.g. if it has been anonymised for analysis purposes, is not covered by the above rights. Information, deletion, blocking, correction or transfer to another enterprise may be possible in relation to this data if you provide us with additional information that allows us to identify you.
f) Exercising your data protection rights and right of appeal
If you have any questions regarding the processing of your personal data, if you wish to obtain information, rectification, blocking, objection or deletion of data or if you wish to transfer the data to another enterprise, please contact email@example.com.
You also have the possibility to complain to a supervisory authority about your data protection rights.