PRIVACY POLICY

Inhaltsübersicht:

  • Verantwortlicher
  • Übersicht der Verarbeitungen
  • Maßgebliche Rechtsgrundlagen
  • Sicherheitsmaßnahmen
  • Übermittlung von personenbezogenen Daten
  • Internationale Datentransfers
  • Allgemeine Informationen zur Datenspeicherung und Löschung
  • Rechte der betroffenen Personen
  • Geschäftliche Leistungen
  • Bereitstellung des Onlineangebots und Webhosting
  • Einsatz von Cookies
  • Kontakt- und Anfrageverwaltung
  • Newsletter und elektronische Benachrichtigungen
  • Webanalyse, Monitoring und Optimierung
  • Präsenzen in sozialen Netzwerken (Social Media)

 

Verantwortlicher:

Maya – house of beauty
Shadi Alleabaei
Dürenerstraße 165a
50931 Köln

E-Mail-Adresse: kontakt@mayahouseofbeauty.de
Impressum: mayahouseofbeauty.de/impressum

 

Übersicht der Verarbeitungen

Die nachfolgende Übersicht fasst die Arten der verarbeiteten Daten und die Zwecke ihrer Verarbeitung zusammen und verweist auf die betroffenen Personen.

 

Arten der verarbeiteten Daten:

  • Bestandsdaten.
  • Zahlungsdaten.
  • Kontaktdaten.
  • Inhaltsdaten.
  • Vertragsdaten.
  • Nutzungsdaten.
  • Meta-, Kommunikations- und Verfahrensdaten.
  • Protokolldaten.

 

Kategorien betroffener Personen:

  • Leistungsempfänger und Auftraggeber.
  • Interessenten.
  • Kommunikationspartner.
  • Nutzer.
  • Geschäfts- und Vertragspartner.

 

Zwecke der Verarbeitung:

  • Erbringung vertraglicher Leistungen und Erfüllung vertraglicher Pflichten.
  • Kommunikation.
  • Sicherheitsmaßnahmen.
  • Direktmarketing.
  • Reichweitenmessung.
  • Büro- und Organisationsverfahren.
  • Organisations- und Verwaltungsverfahren.
  • Feedback.
  • Profile mit nutzerbezogenen Informationen.
  • Bereitstellung unseres Onlineangebotes und Nutzerfreundlichkeit.
  • Informationstechnische Infrastruktur.
  • Öffentlichkeitsarbeit.
  • Geschäftsprozesse und betriebswirtschaftliche Verfahren.

 

Maßgebliche Rechtsgrundlagen:

Maßgebliche Rechtsgrundlagen nach der DSGVO: 

Im Folgenden erhalten Sie eine Übersicht der Rechtsgrundlagen der DSGVO, auf deren Basis wir personenbezogene Daten verarbeiten. Bitte nehmen Sie zur Kenntnis, dass neben den Regelungen der DSGVO nationale Datenschutzvorgaben in Ihrem bzw. unserem Wohn- oder Sitzland gelten können. Sollten ferner im Einzelfall speziellere Rechtsgrundlagen maßgeblich sein, teilen wir Ihnen diese in der Datenschutzerklärung mit.

  • Einwilligung (Art. 6 Abs. 1 S. 1 lit. a) DSGVO) – Die betroffene Person hat ihre Einwilligung in die Verarbeitung der sie betreffenden personenbezogenen Daten für einen spezifischen Zweck oder mehrere bestimmte Zwecke gegeben.
  • Vertragserfüllung und vorvertragliche Anfragen (Art. 6 Abs. 1 S. 1 lit. b) DSGVO) – Die Verarbeitung ist für die Erfüllung eines Vertrags, dessen Vertragspartei die betroffene Person ist, oder zur Durchführung vorvertraglicher Maßnahmen erforderlich, die auf Anfrage der betroffenen Person erfolgen.
  • Rechtliche Verpflichtung (Art. 6 Abs. 1 S. 1 lit. c) DSGVO) – Die Verarbeitung ist zur Erfüllung einer rechtlichen Verpflichtung erforderlich, der der Verantwortliche unterliegt.
  • Berechtigte Interessen (Art. 6 Abs. 1 S. 1 lit. f) DSGVO) – die Verarbeitung ist zur Wahrung der berechtigten Interessen des Verantwortlichen oder eines Dritten notwendig, vorausgesetzt, dass die Interessen, Grundrechte und Grundfreiheiten der betroffenen Person, die den Schutz personenbezogener Daten verlangen, nicht überwiegen.

 

Nationale Datenschutzregelungen in Deutschland: 

Zusätzlich zu den Datenschutzregelungen der DSGVO gelten nationale Regelungen zum Datenschutz in Deutschland. Hierzu gehört insbesondere das Gesetz zum Schutz vor Missbrauch personenbezogener Daten bei der Datenverarbeitung (Bundesdatenschutzgesetz – BDSG). Das BDSG enthält insbesondere Spezialregelungen zum Recht auf Auskunft, zum Recht auf Löschung, zum Widerspruchsrecht, zur Verarbeitung besonderer Kategorien personenbezogener Daten, zur Verarbeitung für andere Zwecke und zur Übermittlung sowie automatisierten Entscheidungsfindung im Einzelfall einschließlich Profiling. Ferner können Landesdatenschutzgesetze der einzelnen Bundesländer zur Anwendung gelangen.

 

Hinweis auf Geltung DSGVO und Schweizer DSG: 

Diese Datenschutzhinweise dienen sowohl der Informationserteilung nach dem Schweizer DSG als auch nach der Datenschutzgrundverordnung (DSGVO). Aus diesem Grund bitten wir Sie zu beachten, dass aufgrund der breiteren räumlichen Anwendung und Verständlichkeit die Begriffe der DSGVO verwendet werden. Insbesondere statt der im Schweizer DSG verwendeten Begriffe „Bearbeitung“ von „Personendaten“, „überwiegendes Interesse“ und „besonders schützenswerte Personendaten“ werden die in der DSGVO verwendeten Begriffe „Verarbeitung“ von „personenbezogenen Daten“ sowie „berechtigtes Interesse“ und „besondere Kategorien von Daten“ verwendet. Die gesetzliche Bedeutung der Begriffe wird jedoch im Rahmen der Geltung des Schweizer DSG weiterhin nach dem Schweizer DSG bestimmt.

 

Sicherheitsmaßnahmen:

Wir treffen nach Maßgabe der gesetzlichen Vorgaben unter Berücksichtigung des Stands der Technik, der Implementierungskosten und der Art, des Umfangs, der Umstände und der Zwecke der Verarbeitung sowie der unterschiedlichen Eintrittswahrscheinlichkeiten und des Ausmaßes der Bedrohung der Rechte und Freiheiten natürlicher Personen geeignete technische und organisatorische Maßnahmen, um ein dem Risiko angemessenes Schutzniveau zu gewährleisten.

Zu den Maßnahmen gehören insbesondere die Sicherung der Vertraulichkeit, Integrität und Verfügbarkeit von Daten durch Kontrolle des physischen und elektronischen Zugangs zu den Daten als auch des sie betreffenden Zugriffs, der Eingabe, der Weitergabe, der Sicherung der Verfügbarkeit und ihrer Trennung. Des Weiteren haben wir Verfahren eingerichtet, die eine Wahrnehmung von Betroffenenrechten, die Löschung von Daten und Reaktionen auf die Gefährdung der Daten gewährleisten. Ferner berücksichtigen wir den Schutz personenbezogener Daten bereits bei der Entwicklung bzw. Auswahl von Hardware, Software sowie Verfahren entsprechend dem Prinzip des Datenschutzes, durch Technikgestaltung und durch datenschutzfreundliche Voreinstellungen.

Kürzung der IP-Adresse: Sofern IP-Adressen von uns oder von den eingesetzten Dienstleistern und Technologien verarbeitet werden und die Verarbeitung einer vollständigen IP-Adresse nicht erforderlich ist, wird die IP-Adresse gekürzt (auch als „IP-Masking“ bezeichnet). Hierbei werden die letzten beiden Ziffern, bzw. der letzte Teil der IP-Adresse nach einem Punkt entfernt, bzw. durch Platzhalter ersetzt. Mit der Kürzung der IP-Adresse soll die Identifizierung einer Person anhand ihrer IP-Adresse verhindert oder wesentlich erschwert werden.

 

Übermittlung von personenbezogenen Daten:

Im Rahmen unserer Verarbeitung von personenbezogenen Daten kommt es vor, dass diese an andere Stellen, Unternehmen, rechtlich selbstständige Organisationseinheiten oder Personen übermittelt beziehungsweise ihnen gegenüber offengelegt werden. Zu den Empfängern dieser Daten können z. B. mit IT-Aufgaben beauftragte Dienstleister gehören oder Anbieter von Diensten und Inhalten, die in eine Website eingebunden sind. In solchen Fällen beachten wir die gesetzlichen Vorgaben und schließen insbesondere entsprechende Verträge bzw. Vereinbarungen, die dem Schutz Ihrer Daten dienen, mit den Empfängern Ihrer Daten ab.

 

Internationale Datentransfers:

Datenverarbeitung in Drittländern: Sofern wir Daten in einem Drittland (d. h., außerhalb der Europäischen Union (EU), des Europäischen Wirtschaftsraums (EWR)) verarbeiten oder die Verarbeitung im Rahmen der Inanspruchnahme von Diensten Dritter oder der Offenlegung bzw. Übermittlung von Daten an andere Personen, Stellen oder Unternehmen stattfindet, erfolgt dies nur im Einklang mit den gesetzlichen Vorgaben. Sofern das Datenschutzniveau in dem Drittland mittels eines Angemessenheitsbeschlusses anerkannt wurde (Art. 45 DSGVO), dient dieser als Grundlage des Datentransfers. Im Übrigen erfolgen Datentransfers nur dann, wenn das Datenschutzniveau anderweitig gesichert ist, insbesondere durch Standardvertragsklauseln (Art. 46 Abs. 2 lit. c) DSGVO), ausdrückliche Einwilligung oder im Fall vertraglicher oder gesetzlich erforderlicher Übermittlung (Art. 49 Abs. 1 DSGVO). Im Übrigen teilen wir Ihnen die Grundlagen der Drittlandübermittlung bei den einzelnen Anbietern aus dem Drittland mit, wobei die Angemessenheitsbeschlüsse als Grundlagen vorrangig gelten. Informationen zu Drittlandtransfers und vorliegenden Angemessenheitsbeschlüssen können dem Informationsangebot der EU-Kommission entnommen werden: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en?prefLang=de.

EU-US Trans-Atlantic Data Privacy Framework: Im Rahmen des sogenannten „Data Privacy Framework“ (DPF) hat die EU-Kommission das Datenschutzniveau ebenfalls für bestimmte Unternehmen aus den USA im Rahmen der Angemessenheitsbeschlusses vom 10.07.2023 als sicher anerkannt. Die Liste der zertifizierten Unternehmen als auch weitere Informationen zu dem DPF können Sie der Website des Handelsministeriums der USA unter https://www.dataprivacyframework.gov/ (in Englisch) entnehmen. Wir informieren Sie im Rahmen der Datenschutzhinweise, welche von uns eingesetzten Diensteanbieter unter dem Data Privacy Framework zertifiziert sind.

 

Allgemeine Informationen zur Datenspeicherung und Löschung:

Wir löschen personenbezogene Daten, die wir verarbeiten, gemäß den gesetzlichen Bestimmungen, sobald die zugrundeliegenden Einwilligungen widerrufen werden oder keine weiteren rechtlichen Grundlagen für die Verarbeitung bestehen. Dies betrifft Fälle, in denen der ursprüngliche Verarbeitungszweck entfällt oder die Daten nicht mehr benötigt werden. Ausnahmen von dieser Regelung bestehen, wenn gesetzliche Pflichten oder besondere Interessen eine längere Aufbewahrung oder Archivierung der Daten erfordern.

Insbesondere müssen Daten, die aus handels- oder steuerrechtlichen Gründen aufbewahrt werden müssen oder deren Speicherung notwendig ist zur Rechtsverfolgung oder zum Schutz der Rechte anderer natürlicher oder juristischer Personen, entsprechend archiviert werden.

Unsere Datenschutzhinweise enthalten zusätzliche Informationen zur Aufbewahrung und Löschung von Daten, die speziell für bestimmte Verarbeitungsprozesse gelten.

Bei mehreren Angaben zur Aufbewahrungsdauer oder Löschungsfristen eines Datums, ist stets die längste Frist maßgeblich.

Beginnt eine Frist nicht ausdrücklich zu einem bestimmten Datum und beträgt sie mindestens ein Jahr, so startet sie automatisch am Ende des Kalenderjahres, in dem das fristauslösende Ereignis eingetreten ist. Im Fall laufender Vertragsverhältnisse, in deren Rahmen Daten gespeichert werden, ist das fristauslösende Ereignis der Zeitpunkt des Wirksamwerdens der Kündigung oder sonstige Beendigung des Rechtsverhältnisses.

Daten, die nicht mehr für den ursprünglich vorgesehenen Zweck, sondern aufgrund gesetzlicher Vorgaben oder anderer Gründe aufbewahrt werden, verarbeiten wir ausschließlich zu den Gründen, die ihre Aufbewahrung rechtfertigen.

 

Weitere Hinweise zu Verarbeitungsprozessen, Verfahren und Diensten:

  • Aufbewahrung und Löschung von Daten: Die folgenden allgemeinen Fristen gelten für die Aufbewahrung und Archivierung nach deutschem Recht:
    • 10 Jahre – Aufbewahrungsfrist für Bücher und Aufzeichnungen, Jahresabschlüsse, Inventare, Lageberichte, Eröffnungsbilanz sowie die zu ihrem Verständnis erforderlichen Arbeitsanweisungen und sonstigen Organisationsunterlagen, Buchungsbelege und Rechnungen (§ 147 Abs. 3 i. V. m. Abs. 1 Nr. 1, 4 und 4a AO, § 14b Abs. 1 UStG, § 257 Abs. 1 Nr. 1 u. 4, Abs. 4 HGB).
    • 6 Jahre – Übrige Geschäftsunterlagen: empfangene Handels- oder Geschäftsbriefe, Wiedergaben der abgesandten Handels- oder Geschäftsbriefe, sonstige Unterlagen, soweit sie für die Besteuerung von Bedeutung sind, z. B. Stundenlohnzettel, Betriebsabrechnungsbögen, Kalkulationsunterlagen, Preisauszeichnungen, aber auch Lohnabrechnungsunterlagen, soweit sie nicht bereits Buchungsbelege sind und Kassenstreifen (§ 147 Abs. 3 i. V. m. Abs. 1 Nr. 2, 3, 5 AO, § 257 Abs. 1 Nr. 2 u. 3, Abs. 4 HGB).
    • 3 Jahre – Daten, die erforderlich sind, um potenzielle Gewährleistungs- und Schadensersatzansprüche oder ähnliche vertragliche Ansprüche und Rechte zu berücksichtigen sowie damit verbundene Anfragen zu bearbeiten, basierend auf früheren Geschäftserfahrungen und üblichen Branchenpraktiken, werden für die Dauer der regulären gesetzlichen Verjährungsfrist von drei Jahren gespeichert (§§ 195, 199 BGB).

 

Rechte der betroffenen Personen:

Rechte der betroffenen Personen aus der DSGVO: Ihnen stehen als Betroffene nach der DSGVO verschiedene Rechte zu, die sich insbesondere aus Art. 15 bis 21 DSGVO ergeben:

  • Widerspruchsrecht: Sie haben das Recht, aus Gründen, die sich aus Ihrer besonderen Situation ergeben, jederzeit gegen die Verarbeitung der Sie betreffenden personenbezogenen Daten, die aufgrund von Art. 6 Abs. 1 lit. e oder f DSGVO erfolgt, Widerspruch einzulegen; dies gilt auch für ein auf diese Bestimmungen gestütztes Profiling. Werden die Sie betreffenden personenbezogenen Daten verarbeitet, um Direktwerbung zu betreiben, haben Sie das Recht, jederzeit Widerspruch gegen die Verarbeitung der Sie betreffenden personenbezogenen Daten zum Zwecke derartiger Werbung einzulegen; dies gilt auch für das Profiling, soweit es mit solcher Direktwerbung in Verbindung steht.
  • Widerrufsrecht bei Einwilligungen: Sie haben das Recht, erteilte Einwilligungen jederzeit zu widerrufen.
  • Auskunftsrecht: Sie haben das Recht, eine Bestätigung darüber zu verlangen, ob betreffende Daten verarbeitet werden und auf Auskunft über diese Daten sowie auf weitere Informationen und Kopie der Daten entsprechend den gesetzlichen Vorgaben.
  • Recht auf Berichtigung: Sie haben entsprechend den gesetzlichen Vorgaben das Recht, die Vervollständigung der Sie betreffenden Daten oder die Berichtigung der Sie betreffenden unrichtigen Daten zu verlangen.
  • Recht auf Löschung und Einschränkung der Verarbeitung: Sie haben nach Maßgabe der gesetzlichen Vorgaben das Recht, zu verlangen, dass Sie betreffende Daten unverzüglich gelöscht werden, bzw. alternativ nach Maßgabe der gesetzlichen Vorgaben eine Einschränkung der Verarbeitung der Daten zu verlangen.
  • Recht auf Datenübertragbarkeit: Sie haben das Recht, Sie betreffende Daten, die Sie uns bereitgestellt haben, nach Maßgabe der gesetzlichen Vorgaben in einem strukturierten, gängigen und maschinenlesbaren Format zu erhalten oder deren Übermittlung an einen anderen Verantwortlichen zu fordern.
  • Beschwerde bei Aufsichtsbehörde: Sie haben unbeschadet eines anderweitigen verwaltungsrechtlichen oder gerichtlichen Rechtsbehelfs das Recht auf Beschwerde bei einer Aufsichtsbehörde, insbesondere in dem Mitgliedstaat ihres gewöhnlichen Aufenthaltsorts, ihres Arbeitsplatzes oder des Orts des mutmaßlichen Verstoßes, wenn Sie der Ansicht sind, dass die Verarbeitung der Sie betreffenden personenbezogenen Daten gegen die Vorgaben der DSGVO verstößt.

 

Geschäftliche Leistungen:

Wir verarbeiten Daten unserer Vertrags- und Geschäftspartner, z. B. Kunden und Interessenten (zusammenfassend als „Vertragspartner“ bezeichnet), im Rahmen von vertraglichen und vergleichbaren Rechtsverhältnissen sowie damit verbundenen Maßnahmen und im Hinblick auf die Kommunikation mit den Vertragspartnern (oder vorvertraglich), etwa zur Beantwortung von Anfragen.

We use this data to fulfill our contractual obligations. This includes, in particular, the obligations to provide the agreed services, any update obligations, and remedies for warranty and other service disruptions. In addition, we use the data to safeguard our rights and for the administrative tasks associated with these obligations and for corporate organization. Furthermore, we process the data on the basis of our legitimate interests both in proper and business management and in security measures to protect our contractual partners and our business from misuse, endangerment of their data, secrets, information, and rights (e.g., for the involvement of telecommunications, transport, and other auxiliary services as well as subcontractors, banks, tax and legal advisors, payment service providers, or tax authorities). Within the framework of applicable law, we only pass on data of contractual partners to third parties insofar as this is necessary for the aforementioned purposes or to fulfill legal obligations. Contractual partners will be informed about other forms of processing, for example for marketing purposes, within the framework of this privacy policy.

We will inform the contractual partners about which data is required for the aforementioned purposes before or during the data collection, e.g., in online forms, by special marking (e.g., colors) or symbols (e.g., asterisks or similar), or personally.

We delete the data after the expiry of statutory warranty and comparable obligations, i.e., generally after four years, unless the data is stored in a customer account, e.g., as long as it has to be kept for legal reasons of archiving (e.g., for tax purposes usually ten years). We delete data that has been disclosed to us by the contractual partner within the scope of an order in accordance with the specifications and generally after the end of the order.

  • Types of data processed: Inventory data (e.g., full name, residential address, contact information, customer number, etc.); payment data (e.g., bank details, invoices, payment history); contact data (e.g., postal and e-mail addresses or telephone numbers); contract data (e.g., subject matter of the contract, term, customer category); usage data (e.g., page views and duration of stay, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions). Meta, communication, and procedural data (e.g., IP addresses, time stamps, identification numbers, involved persons).
  • Affected persons: Service recipients and clients; interested parties. Business and contractual partners.
  • Purposes of processing: Provision of contractual services and fulfillment of contractual obligations; security measures; communication; office and organizational procedures; organizational and administrative procedures. Business processes and business administration procedures.
  • Retention and deletion: Deletion according to the information in the section "General information on data storage and deletion".
  • Legal bases: Fulfillment of contract and pre-contractual inquiries (Art. 6 (1) S. 1 lit. b) GDPR); Legal obligation (Art. 6 (1) S. 1 lit. c) GDPR). Legitimate interests (Art. 6 (1) S. 1 lit. f) GDPR).

 

Further information on processing processes, procedures and services:

  • Online shop, order forms, e-commerce and delivery: We process the data of our customers to enable them to select, purchase, or order the chosen products, goods, and associated services, as well as their payment and delivery, or execution. If required for the execution of an order, we use service providers, in particular postal, freight, and shipping companies, to carry out the delivery or execution for our customers. For the processing of payment transactions, we use the services of banks and payment service providers. The required information is identified as such within the scope of the order or comparable purchase process and includes the information necessary for delivery, provision, and billing, as well as contact information to enable any necessary communication; Legal bases: Fulfillment of contract and pre-contractual inquiries (Art. 6 (1) S. 1 lit. b) GDPR).

 

Provision of the online offer and web hosting:

We process user data to provide our online services to them. For this purpose, we process the user's IP address, which is necessary to transmit the content and functions of our online services to the user's browser or end device.

  • Types of data processed: Usage data (e.g., page views and duration of stay, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions); Meta, communication, and procedural data (e.g., IP addresses, time stamps, identification numbers, involved persons). Log data (e.g., log files regarding logins or the retrieval of data or access times).
  • Affected persons: Users (e.g., website visitors, users of online services).
  • Purposes of processing: Provision of our online offer and user-friendliness; information technology infrastructure (operation and provision of information systems and technical devices (computers, servers, etc.)). Security measures.
  • Retention and deletion: Deletion according to the information in the section "General information on data storage and deletion".
  • Legal bases: Legitimate interests (Art. 6 (1) S. 1 lit. f) GDPR).

 

Further information on processing processes, procedures and services:

  • Collection of access data and log files: Access to our online offer is logged in the form of so-called "server log files". Server log files can include the address and name of the accessed web pages and files, date and time of access, transferred data volumes, notification of successful access, browser type and version, the user's operating system, referrer URL (the previously visited page), and generally IP addresses and the requesting provider. Server log files can be used for security purposes, e.g., to avoid overloading the servers (especially in the case of abusive attacks, so-called DDoS attacks), and on the other hand, to ensure the utilization of the servers and their stability; Legal bases: Legitimate interests (Art. 6 (1) S. 1 lit. f) GDPR). Deletion of data: Log file information is stored for a maximum of 30 days and then deleted or anonymized. Data whose further retention is necessary for evidentiary purposes is excluded from deletion until the final clarification of the respective incident.
  • ALL-INKL: Services in the field of providing IT infrastructure and related services (e.g., storage space and/or computing capacities); Service provider: ALL-INKL.COM – Neue Medien Münnich, Owner: René Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany; Legal bases: Legitimate interests (Art. 6 (1) S. 1 lit. f) GDPR); Website: https://all-inkl.com/; Privacy Policy: https://all-inkl.com/datenschutzinformationen/. Data Processing Agreement: Provided by the service provider.

 

Use of cookies:

Cookies are small text files or other storage notes that store and read information on end devices. For example, to store the login status in a user account, shopping cart contents in an e-shop, accessed content, or used functions of an online offer. Cookies can also be used for various purposes, such as for the functionality, security, and convenience of online offers, as well as for creating analyses of visitor flows.

 

Notes on consent: 

We use cookies in accordance with legal regulations. Therefore, we obtain prior consent from users, unless it is not required by law. Permission is particularly not necessary if the storage and reading of information, including cookies, are absolutely necessary to provide users with a telemedia service (i.e., our online offer) explicitly requested by them. The revocable consent is clearly communicated to them and contains information about the respective cookie usage.

 

Notes on legal bases under data protection law: 

The legal basis under data protection law on which we process users' personal data using cookies depends on whether we ask them for consent. If users accept, the legal basis for using their data is the consent given. Otherwise, data processed with the help of cookies is processed on the basis of our legitimate interests (e.g., in the economic operation of our online offer and the improvement of its usability) or, if this occurs within the framework of fulfilling our contractual obligations, if the use of cookies is necessary to fulfill our contractual obligations. We will clarify the purposes for which we use cookies in the course of this privacy policy or within the framework of our consent and processing processes.

 

Storage period:

With regard to the storage period, the following types of cookies are distinguished:

  • Temporary cookies (also: session cookies): Temporary cookies are deleted at the latest after a user has left an online offer and closed their end device (e.g., browser or mobile application).
  • Permanent cookies: Permanent cookies remain stored even after the end device is closed. For example, the login status can be saved and preferred content can be displayed directly when the user revisits a website. Likewise, the user data collected with the help of cookies can be used for reach measurement. If we do not provide users with explicit information on the type and storage period of cookies (e.g., when obtaining consent), they should assume that these are permanent and the storage period can be up to two years.

 

General information on revocation and objection (opt-out):

Users can revoke their consent at any time and also object to the processing in accordance with legal requirements, also via the privacy settings of their browser.

  • Types of data processed: Meta, communication, and procedural data (e.g., IP addresses, time stamps, identification numbers, involved persons).
  • Affected persons: Users (e.g., website visitors, users of online services).
  • Legal bases: Legitimate interests (Art. 6 (1) S. 1 lit. f) GDPR). Consent (Art. 6 (1) S. 1 lit. a) GDPR).

 

Further information on processing processes, procedures and services:

  • Processing of cookie data based on consent: We use a consent management solution that obtains users' consent to the use of cookies or to the procedures and providers mentioned in the consent management solution. This procedure serves to obtain, record, manage, and revoke consents, particularly with regard to the use of cookies and similar technologies that are used to store, read, and process information on users' end devices. Within the framework of this procedure, users' consents for the use of cookies and the associated processing of information, including the specific processing operations and providers mentioned in the consent management procedure, are obtained. Users also have the option to manage and revoke their consents. The declarations of consent are stored to avoid repeated queries and to be able to provide proof of consent in accordance with legal requirements. Storage takes place server-side and/or in a cookie (so-called opt-in cookie) or by means of comparable technologies to be able to assign the consent to a specific user or their device. If no specific information about the providers of consent management services is available, the following general notes apply: The duration of the storage of consent is up to two years. A pseudonymous user identifier is created, which is stored together with the time of consent, information about the scope of consent (e.g., relevant categories of cookies and/or service providers) and information about the browser, the system and the end device used; Legal bases: Consent (Art. 6 (1) S. 1 lit. a) GDPR).

 

Contact and inquiry management:

When contacting us (e.g., by mail, contact form, e-mail, telephone, or via social media) and within the framework of existing user and business relationships, the data of the inquiring persons are processed insofar as this is necessary to answer the contact inquiries and any requested measures.

  • Types of data processed: Inventory data (e.g., full name, residential address, contact information, customer number, etc.); contact data (e.g., postal and e-mail addresses or telephone numbers); content data (e.g., textual or visual messages and contributions and information related to them, such as authorship or time of creation); usage data (e.g., page views and duration of stay, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions). Meta, communication, and procedural data (e.g., IP addresses, time stamps, identification numbers, involved persons).
  • Affected persons: Communication partners.
  • Purposes of processing: Communication; organizational and administrative procedures; feedback (e.g., collecting feedback via online form). Provision of our online offer and user-friendliness.
  • Retention and deletion: Deletion according to the information in the section "General information on data storage and deletion".
  • Legal bases: Legitimate interests (Art. 6 (1) S. 1 lit. f) GDPR). Fulfillment of contract and pre-contractual inquiries (Art. 6 (1) S. 1 lit. b) GDPR).

 

Further information on processing processes, procedures and services:

  • Contact form: When contacting us via our contact form, by e-mail or other means of communication, we process the personal data transmitted to us to answer and process the respective request. This usually includes information such as name, contact information and, if applicable, further information that is communicated to us and is necessary for proper processing. We use this data exclusively for the stated purpose of contact and communication; Legal bases: Fulfillment of contract and pre-contractual inquiries (Art. 6 (1) S. 1 lit. b) GDPR), Legitimate interests (Art. 6 (1) S. 1 lit. f) GDPR).

 

Newsletter and electronic notifications:

We send newsletters, e-mails, and other electronic notifications (hereinafter "newsletter") exclusively with the consent of the recipients or on the basis of a legal basis. If the content of a newsletter is specified during registration, this content is decisive for the user's consent. To subscribe to our newsletter, providing your e-mail address is usually sufficient. However, to provide you with a personalized service, we may ask for your name for a personal address in the newsletter or for further information, if this is necessary for the purpose of the newsletter.

Deletion and restriction of processing: We can store the unsubscribed e-mail addresses for up to three years on the basis of our legitimate interests before deleting them, in order to be able to prove a formerly given consent. The processing of this data will be limited to the purpose of a potential defense against claims. An individual deletion request is possible at any time, provided that the former existence of a consent is confirmed at the same time. In the case of obligations to permanently observe contradictions, we reserve the right to store the e-mail address for this purpose alone in a blocking list (so-called "blocklist").

The logging of the registration process is based on our legitimate interests for the purpose of demonstrating its proper functioning. If we commission a service provider to send emails, this is done on the basis of our legitimate interests in an efficient and secure dispatch system.

 

Content:

Information about us, our services, promotions and offers:

  • Types of data processed: Inventory data (e.g., full name, residential address, contact information, customer number, etc.); Contact data (e.g., postal and email addresses or telephone numbers); Meta, communication and procedural data (e.g., IP addresses, times, identification numbers, involved persons). Usage data (e.g., page views and dwell time, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions).
  • Affected persons: Communication partners.
  • Purposes of processing: Direct marketing (e.g., by email or post).
  • Retention and deletion: 3 years – Contractual claims (AT) (Data necessary to consider potential warranty and compensation claims or similar contractual claims and rights, as well as to process related inquiries, based on prior business experience and common industry practices, are stored for the duration of the regular statutory limitation period of three years (§§ 1478, 1480 ABGB)). 10 years – Contractual claims (CH) (Data necessary to consider potential claims for damages or similar contractual claims and rights, as well as to process related inquiries, based on prior business experience and common industry practices, are stored for the period of the statutory limitation period of ten years, unless a shorter period of 5 years is applicable in certain cases (Art. 127, 130 OR)).
  • Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR).
  • Right to object (Opt-Out): You can cancel the receipt of our newsletter at any time, i.e., revoke your consents or object to further receipt. You can find a link to cancel the newsletter either at the end of each newsletter or you can use one of the contact options listed above, preferably email, for this purpose.

 

Further information on processing processes, procedures and services:

  • Measurement of opening and click rates: Newsletters contain a so-called "web beacon", i.e., a pixel-sized file that is retrieved from our server or that of our shipping service provider when the newsletter is opened. As part of this retrieval, technical information, such as browser and system details, as well as your IP address and the time of retrieval, are collected. This information is used for the technical improvement of our newsletter based on technical data or target groups and their reading behavior based on their retrieval locations (which can be determined using the IP address) or access times. This analysis also includes determining whether and when the newsletters are opened and which links are clicked. The information is assigned to the individual newsletter recipients and stored in their profiles until deleted. The evaluations serve to recognize the reading habits of our users and to adapt our content to them or to send different content according to the interests of our users. The measurement of opening and click rates and the storage of the measurement results in the user profiles. 

    Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR).

                                                                                 

 

Web analysis, monitoring and optimization:

Web analysis (also referred to as "reach measurement") serves to evaluate the visitor flows of our online offering and can include behavior, interests or demographic information about visitors, such as age or gender, as pseudonymized values. With the help of reach analysis, we can, for example, identify at what time our online offering or its functions or content are most frequently used, or invite reuse. We can also understand which areas need optimization.

In addition to web analysis, we can also use test procedures to test and optimize different versions of our online offering or its components.

Unless otherwise stated below, profiles, i.e., data summarized for a usage process, can be created for these purposes and information stored in a browser or in an end device and then read out. The collected data includes in particular visited websites and elements used there, as well as technical information, such as the browser used, the computer system used, and information on usage times. If users have consented to the collection of their location data by us or by the providers of the services we use, the processing of location data is also possible.

In addition, the IP addresses of users are stored. However, we use an IP masking procedure (i.e., pseudonymization by shortening the IP address) to protect users. In general, no clear data of users (such as email addresses or names) are stored within the framework of web analysis, A/B testing and optimization, but pseudonyms. This means that neither we nor the providers of the software used know the actual identity of the users, but only the information stored in their profiles for the purpose of the respective procedures.

 

Information on legal bases:                                                                             

If we ask users for their consent to the use of third-party providers, the legal basis for data processing is consent. Otherwise, user data is processed on the basis of our legitimate interests (i.e., interest in efficient, economical and user-friendly services). In this context, we would also like to draw your attention to the information on the use of cookies in this privacy policy.

  • Types of data processed: Usage data (e.g., page views and dwell time, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions). Meta, communication and procedural data (e.g., IP addresses, times, identification numbers, involved persons).
  • Affected persons: Users (e.g., website visitors, users of online services).
  • Purposes of processing: Reach measurement (e.g., access statistics, recognition of recurring visitors); Profiles with user-related information (creation of user profiles). Provision of our online offering and user-friendliness.
  • Retention and deletion: Deletion according to the information in the section "General information on data storage and deletion". Storage of cookies for up to 2 years (Unless otherwise stated, cookies and similar storage methods can be stored on users' devices for a period of two years.).
  • Security measures: IP masking (pseudonymization of the IP address).
  • Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR). Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).

 

Further information on processing processes, procedures and services:

  • Google Analytics: We use Google Analytics to measure and analyze the use of our online offering based on a pseudonymized user identification number. This identification number does not contain unique data such as names or email addresses. It serves to assign analysis information to an end device to recognize which content users have accessed within one or different usage processes, which search terms they have used, have accessed again or have interacted with our online offering. The time of use and its duration, as well as the sources of users who refer to our online offering and technical aspects of their end devices and browsers, are also stored.
    In this process, pseudonymized user profiles are created with information from the use of various devices, whereby cookies can be used. Google Analytics does not log and store individual IP addresses for EU users. However, Analytics provides coarse geographical location data by deriving the following metadata from IP addresses: city (and the derived latitude and longitude of the city), continent, country, region, sub-continent (and ID-based counterparts). For EU traffic, IP address data is used exclusively for this derivation of geolocation data before being immediately deleted. They are not logged, are not accessible and are not used for further purposes. When Google Analytics collects measurement data, all IP queries are performed on EU-based servers before traffic is forwarded to Analytics servers for processing; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); Website: https://marketingplatform.google.com/intl/de/about/analytics/; Security measures: IP masking (pseudonymization of the IP address); Privacy policy: https://policies.google.com/privacy; Order processing agreement: https://business.safety.google/adsprocessorterms/; Basis for third country transfers: Data Privacy Framework (DPF); Right to object (Opt-Out): Opt-Out plugin: https://tools.google.com/dlpage/gaoptout?hl=de, Settings for displaying advertisements: https://myadcenter.google.com/personalizationoff. Further information: https://business.safety.google/adsservices/ (types of processing and processed data).

 

Presences on social networks (Social Media):

We maintain online presences within social networks and process user data in this context to communicate with the active users there or to offer information about us.

We point out that user data may be processed outside the European Union. This may result in risks for users, for example, because the enforcement of user rights could be made more difficult.

Furthermore, user data within social networks is generally processed for market research and advertising purposes. For example, usage profiles can be created based on user behavior and resulting interests. The latter may in turn be used to place advertisements within and outside the networks that presumably correspond to the interests of the users. Therefore, cookies are generally stored on the users' computers, in which user behavior and user interests are stored. In addition, data independent of the devices used by the users can also be stored in the usage profiles (especially if they are members of the respective platforms and are logged in there).

For a detailed description of the respective processing forms and the objection options (opt-out), we refer to the privacy policies and information of the operators of the respective networks.

Even in the case of information requests and the assertion of data subject rights, we point out that these can be asserted most effectively with the providers. Only the latter have access to the user data and can directly take appropriate measures and provide information. Should you still need help, you can contact us.

  • Types of data processed: Contact data (e.g., postal and email addresses or telephone numbers); Content data (e.g., textual or pictorial messages and contributions as well as related information, such as authorship or time of creation). Usage data (e.g., page views and dwell time, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions).
  • Affected persons: Users (e.g., website visitors, users of online services).
  • Purposes of processing: Communication; Feedback (e.g., collecting feedback via online form). Public relations.
  • Retention and deletion: Deletion according to the information in the section "General information on data storage and deletion".
  • Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).

 

Further information on processing processes, procedures and services:

  • Instagram: Social network, enables sharing of photos and videos, commenting and liking posts, sending messages, subscribing to profiles and pages; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://www.instagram.com; Privacy policy: https://privacycenter.instagram.com/policy/. Basis for third country transfers: Data Privacy Framework (DPF).
  • Facebook Pages: Profiles within the social network Facebook – We are jointly responsible with Meta Platforms Ireland Limited for the collection (but not the further processing) of data from visitors to our Facebook page (so-called "Fanpage"). This data includes information on the types of content that users view or interact with, or the actions they take (see "Things you and others do and provide" in the Facebook Data Policy: https://www.facebook.com/privacy/policy/), as well as information about the devices used by users (e.g., IP addresses, operating system, browser type, language settings, cookie data; see "Device Information" in the Facebook Data Policy: https://www.facebook.com/privacy/policy/). As explained in the Facebook Data Policy under "How do we use this information?", Facebook also collects and uses information to provide analytical services, so-called "Page Insights", to page operators, so that they gain insights into how people interact with their pages and with the content associated with them. We have concluded a special agreement with Facebook ("Page Insights Information", https://www.facebook.com/legal/terms/page_controller_addendum), which regulates in particular which security measures Facebook must observe and in which Facebook has agreed to fulfill the rights of data subjects (i.e., users can, for example, address information or deletion requests directly to Facebook). The rights of users (in particular to information, deletion, objection and complaint to the competent supervisory authority) are not restricted by the agreements with Facebook. Further information can be found in the "Page Insights Information" (https://www.facebook.com/legal/terms/information_about_page_insights_data). The joint responsibility is limited to the collection by and transmission of data to Meta Platforms Ireland Limited, a company based in the EU. The further processing of the data is the sole responsibility of Meta Platforms Ireland Limited, which particularly concerns the transmission of data to the parent company Meta Platforms, Inc. in the USA; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) DSGVO); Website: https://www.facebook.com; Privacy policy: https://www.facebook.com/privacy/policy/. Basis for third country transfers: Data Privacy Framework (DPF).
  • X: Social Network; Dienstanbieter: Twitter International Company, One Cumberland Place, Fenian Street, Dublin 2 D02 AX07, Irland; Rechtsgrundlagen: Berechtigte Interessen (Art. 6 Abs. 1 S. 1 lit. f) DSGVO); Website: https://x.com. Datenschutzerklärung: https://twitter.com/de/privacy.
  •  

    Erstellt mit kostenlosem Datenschutz-Generator.de von Dr. Thomas Schwenke

    Stand: 14. Mai 2024