Privacy Policy
Data Protection
This privacy policy explains the nature, scope, and purpose of the processing of personal data (hereinafter referred to briefly as “data”) in connection with the provision of our services, as well as within our online offering and the associated websites, functions, and content, and external online presences, such as our social media profiles (hereinafter collectively referred to as the “online offering”). With regard to the terminology used, such as “processing” or “controller,” we refer to the definitions in Art. 4 of the General Data Protection Regulation (GDPR).
Controller
Elisabeth Clancy
Los Riscos Alto 11, 35580 Playa Blanca,
Lanzarote, Canary Islands (Spain)
Phone: 0034 679 728 351
Email: elisabeth@elisabeth-concept.com
Controller: Elisabeth Clancy
Types of Data Processed
Categories of Data Subjects
Visitors to and users of the online offering (hereinafter, we also collectively refer to the data subjects as “users”).
Purpose of Processing
Terminology Used
“Personal data” means any information relating to an identified or identifiable natural person (hereinafter “data subject”); an identifiable natural person is one who can be identified directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g., cookie), or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
“Processing” means any operation or set of operations performed on personal data, whether or not by automated means. The term is broad and covers virtually any handling of data.
“Pseudonymization” means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures that ensure that the personal data are not attributed to an identified or identifiable natural person.
“Profiling” means any form of automated processing of personal data consisting of the use of such personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that natural person’s work performance, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements.
“Controller” refers to the natural or legal person, public authority, agency, or other body that, alone or jointly with others, determines the purposes and means of the processing of personal data.
“Processor” means a natural or legal person, public authority, agency, or other body that processes personal data on behalf of the controller.
Applicable Legal Bases
In accordance with Art. 13 GDPR, we inform you of the legal bases for our data processing activities. For users within the scope of the General Data Protection Regulation (GDPR), i.e. the EU and the EEA, the following applies unless the legal basis is specified in the Privacy Policy:
The legal basis for obtaining consent is Art. 6(1)(a) and Art. 7 GDPR;
The legal basis for processing for the performance of our services, the implementation of contractual measures, and responding to inquiries is Art. 6(1)(b) GDPR;
The legal basis for processing to comply with our legal obligations is Art. 6(1)(c) GDPR;
Where the vital interests of the data subject or another natural person require the processing of personal data, Art. 6(1)(d) GDPR serves as the legal basis.
The legal basis for processing necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller is Art. 6(1)(e) GDPR.
The legal basis for processing to safeguard our legitimate interests is Art. 6(1)(f) GDPR.
The processing of data for purposes other than those for which they were collected is governed by the provisions of Art. 6(4) GDPR.
The processing of special categories of data (in accordance with Art. 9(1) GDPR) is governed by the provisions of Art. 9(2) GDPR.
Security Measures
We take appropriate technical and organizational measures in accordance with legal requirements, taking into account the state of the art, implementation costs, and the nature, scope, circumstances, and purposes of the processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, in order to ensure a level of protection appropriate to the risk.
These measures include, in particular, safeguarding the confidentiality, integrity, and availability of data by controlling physical access to the data, as well as access to, entry, disclosure, ensuring the availability of, and separation of the data. Furthermore, we have established procedures that ensure the exercise of data subject rights, the deletion of data, and responses to threats to the data. We also take the protection of personal data into account when developing or selecting hardware, software, and procedures, in accordance with the principles of data protection by design and data protection-friendly default settings.
Cooperation with processors, joint controllers, and third parties
If, as part of our processing, we disclose data to other persons and companies (processors, joint controllers, or third parties), transmit it to them, or otherwise grant them access to the data, this is done only on the basis of legal authorization (e.g., if the transmission of data to third parties, such as payment service providers, is necessary for the performance of a contract), if users have given their consent, if a legal obligation requires it, or on the basis of our legitimate interests (e.g., when using agents, web hosts, etc.).
If we disclose or transmit data to other companies in our group of companies or otherwise grant them access, this is done in particular for administrative purposes as a legitimate interest and, beyond that, on a basis that complies with legal requirements.
Transfers to Third Countries
If we process data in a third country (i.e., outside the European Union (EU), the European Economic Area (EEA), or the Swiss Confederation), or if this occurs in connection with the use of third-party services or the disclosure or transmission of data to other persons or companies, this is done only if it is necessary to fulfill our (pre-)contractual obligations, on the basis of your consent, due to a legal obligation, or on the basis of our legitimate interests. Subject to legal or contractual permissions, we process data or have data processed in a third country only if the legal requirements are met. This means that processing takes place, for example, on the basis of special safeguards, such as an officially recognized determination of a level of data protection equivalent to that of the EU, or compliance with officially recognized specific contractual obligations.
Rights of Data Subjects
You have the right to request confirmation as to whether relevant data is being processed and to obtain information about this data, as well as further information and a copy of the data in accordance with legal requirements.
You have, in accordance with the statutory requirements, the right to request the completion of data concerning you or the rectification of inaccurate data concerning you.
In accordance with the statutory requirements, you have the right to request that data concerning you be deleted without delay or, alternatively, to request that the processing of the data be restricted.
You have the right to receive, in accordance with the statutory requirements, the data concerning you that you have provided to us and to request that it be transmitted to other controllers.
Furthermore, in accordance with the statutory requirements, you have the right to lodge a complaint with the competent supervisory authority.
Right of withdrawal
You have the right to withdraw consent that you have given, with effect for the future.
Right to object
You may object at any time to the future processing of data concerning you in accordance with the statutory requirements. In particular, you may object to processing for direct marketing purposes.
Cookies and the right to object to direct marketing
“Cookies” are small files that are stored on users’ computers. Different types of information can be stored in cookies. A cookie is primarily used to store information about a user (or the device on which the cookie is stored) during or after their visit to an online service. Temporary cookies, also known as “session cookies” or “transient cookies,” are cookies that are deleted after a user leaves an online service and closes their browser. Such a cookie may, for example, store the contents of a shopping cart in an online shop or a login status. Cookies that remain stored even after the browser is closed are referred to as “permanent” or “persistent.” For example, the login status can be stored if users return after several days. Such a cookie can also store users’ interests, which are used for audience measurement or marketing purposes. “Third-party cookies” are cookies provided by providers other than the controller operating the online service (otherwise, if only the controller’s cookies are involved, they are referred to as “first-party cookies”).
We may use temporary and permanent cookies and provide information about them in our Privacy Policy.
If users do not want cookies to be stored on their computers, they are asked to disable the corresponding option in their browser’s system settings. Stored cookies can be deleted in the browser’s system settings. Disabling cookies may result in limitations to the functionality of this online service.
A general objection to the use of cookies for online marketing purposes can be declared for many of the services, particularly in the case of tracking, via the US website http://www.aboutads.info/choices/ or the EU website http://www.youronlinechoices.com/. Furthermore, cookies can be prevented from being stored by disabling them in the browser settings. Please note that in this case, some functions of this online service may not be fully available.
Deletion of Data
The data we process will be deleted or its processing restricted in accordance with statutory requirements. Unless expressly stated otherwise in this Privacy Policy, the data stored by us will be deleted as soon as it is no longer required for its intended purpose and provided that no statutory retention obligations prevent its deletion.
If the data is not deleted because it is required for other legally permissible purposes, its processing will be restricted. This means that the data will be blocked and not processed for other purposes. This applies, for example, to data that must be retained for commercial or tax law reasons.
Changes and Updates to the Privacy Policy
We ask you to regularly review the contents of our Privacy Policy. We will amend the Privacy Policy whenever changes to the data processing we carry out make this necessary. We will inform you as soon as the changes require action on your part (e.g., consent) or any other individual notification.
Business-Related Processing
In Addition, We Process
of our customers, prospective customers and business partners for the purpose of providing contractual services, support and customer care, marketing, advertising and market research.
Order Processing in the Online Shop and Customer Account
We process our customers’ data as part of the ordering process in our online shop to enable them to select and order their chosen products and services, as well as to pay for and receive them or have them performed.
The data processed includes inventory data, communication data, contract data and payment data, and the persons affected by the processing include our customers, prospective customers and other business partners. Processing is carried out for the purpose of providing contractual services in connection with the operation of an online shop, billing, delivery and customer services. We use session cookies to store the contents of the shopping cart and persistent cookies to store the login status.
Processing is carried out for the performance of our services and the implementation of contractual measures (e.g., processing orders) and insofar as it is required by law (e.g., legally required archiving of business transactions for commercial and tax purposes). The information marked as required is necessary for entering into and fulfilling the contract. We disclose the data to third parties only in connection with delivery, payment, or within the scope of statutory permissions and obligations, as well as where this is done on the basis of our legitimate interests, about which we inform you in this Privacy Policy (e.g., to legal and tax advisors, financial institutions, freight companies, and public authorities).
Users may optionally create a user account through which, in particular, they can view their orders. During registration, users are informed of the required mandatory information. User accounts are not public and cannot be indexed by search engines. If users have terminated their user account, their data relating to the user account will be deleted, unless its retention is necessary for reasons of commercial or tax law. Information in the customer account remains there until it is deleted, followed by archiving in the event of a legal obligation or our legitimate interests (e.g., in the event of legal disputes). Users are responsible for backing up their data before the end of the contract once termination has taken place.
During registration and subsequent logins, as well as when our online services are used, we store the IP address and the time of the respective user action. Storage is based on our legitimate interests, as well as those of users, in protection against misuse and other unauthorized use. As a rule, this data is not disclosed to third parties unless this is necessary to pursue our legal claims as a legitimate interest or there is a legal obligation to do so.
Deletion takes place after the expiry of statutory warranty rights and other contractual rights or obligations (e.g., payment claims or performance obligations arising from contracts with customers), with the necessity of retaining the data reviewed every three years; where data is retained due to statutory archiving obligations, it is deleted upon expiry of those obligations.
Agency Services
We process our customers’ data as part of our contractual services, which include conceptual and strategic consulting, campaign planning, software and design development/consulting or maintenance, implementation and handling of campaigns and processes, server administration, data analysis/consulting services, and training services.
In this context, we process inventory data (e.g., customer master data such as names or addresses), contact data (e.g., email, telephone numbers), content data (e.g., text entries, photographs, videos), contract data (e.g., subject matter of the contract, term), payment data (e.g., bank details, payment history), usage data and metadata (e.g. in connection with the evaluation and performance measurement of marketing measures). As a rule, we do not process special categories of personal data unless they form part of commissioned processing. Data subjects include our customers, prospective customers and their customers, users, website visitors or employees, as well as third parties. The purpose of processing is to provide contractual services, billing and customer service. The legal bases for processing are Art. 6 para. 1 lit. b GDPR (contractual services), Art. 6 para. 1 lit. f GDPR (analysis, statistics, optimization, security measures). We process data required for establishing and fulfilling the contractual services and indicate that its provision is necessary. Disclosure to external parties takes place only if required within the scope of an assignment. When processing data entrusted to us within the scope of an assignment, we act in accordance with the instructions of the clients and the statutory requirements for commissioned processing pursuant to Art. 28 GDPR and do not process the data for any purposes other than those specified in the assignment.
We delete the data after the expiry of statutory warranty obligations and comparable obligations. The necessity of retaining the data is reviewed every three years; in the case of statutory archiving obligations, deletion takes place after their expiry (6 years pursuant to Section 257 para. 1 HGB, 10 years pursuant to Section 147 para. 1 AO). In the case of data disclosed to us by the client within the scope of an assignment, we delete the data in accordance with the requirements of the assignment, generally after the assignment has ended.
Therapeutic Services and Coaching
We process the data of our clients and prospective clients and other customers or contractual partners (collectively referred to as “clients”) in accordance with Art. 6 para. 1 lit. b) GDPR in order to provide them with our contractual or pre-contractual services. The data processed in this context, the nature, scope and purpose of processing, and the necessity of such processing are determined by the underlying contractual relationship. The data processed generally includes the clients’ inventory and master data (e.g., name, address, etc.), as well as contact data (e.g., email address, telephone, etc.), contract data (e.g., services used, fees, names of contact persons, etc.) and payment data (e.g., bank details, payment history, etc.).
As part of our services, we may also process special categories of data pursuant to Art. 9(1) GDPR, in particular information concerning clients’ health, possibly relating to their sex life or sexual orientation, ethnic origin, or religious or philosophical beliefs. For this purpose, where necessary, we obtain the clients’ explicit consent pursuant to Art. 6(1)(a), Art. 7, Art. 9(2)(a) GDPR and otherwise process the special categories of data for preventive healthcare purposes on the basis of Art. 9(2)(h) GDPR, Section 22(1) No. 1(b) BDSG.
Where required for the performance of the contract or by law, we disclose or transmit clients’ data in the course of communication with other professionals, to third parties necessarily or typically involved in the performance of the contract, such as billing offices or comparable service providers, provided that this serves the provision of our services pursuant to Art. 6(1)(b) GDPR, is required by law pursuant to Art. 6(1)(c) GDPR, serves our interests or those of the clients in efficient and cost-effective healthcare as a legitimate interest pursuant to Art. 6(1)(f) GDPR, or is necessary pursuant to Art. 6(1)(d) GDPR to protect the vital interests of the clients or another natural person, or within the scope of consent pursuant to Art. 6(1)(a), Art. 7 GDPR.
The data will be deleted when it is no longer required for the fulfilment of contractual or statutory duties of care or for handling any warranty and comparable obligations, whereby the necessity of retaining the data is reviewed every three years; otherwise, the statutory retention obligations apply.
Contractual Services
We process the data of our contractual partners and prospective clients as well as other principals, customers, clients, service recipients or contractual partners (collectively referred to as “contractual partners”) in accordance with Art. 6(1)(b) GDPR in order to provide them with our contractual or pre-contractual services. The data processed in this context, the nature, scope and purpose of the processing, and the necessity thereof are determined by the underlying contractual relationship.
The data processed includes the master data of our contractual partners (e.g., names and addresses), contact data (e.g. email addresses and telephone numbers), as well as contract data (e.g., services used, contract contents, contractual communication, names of contact persons) and payment data (e.g., bank details, payment history).
As a general rule, we do not process special categories of personal data unless they form part of commissioned or contractual processing.
We process data that is necessary for establishing and performing the contractual services and indicate when its provision is required, insofar as this is not evident to the contractual partners. Disclosure to external persons or companies takes place only if it is necessary within the framework of a contract. When processing data entrusted to us within the framework of an order, we act in accordance with the principals’ instructions and statutory requirements.
When using our online services, we may store the IP address and the time of the respective user action. The storage is based on our legitimate interests as well as the users’ interests in protection against misuse and other unauthorized use. As a rule, this data is not disclosed to third parties unless this is necessary to pursue our claims pursuant to Art. 6 para. 1 lit. f. GDPR or there is a legal obligation to do so pursuant to Art. 6 para. 1 lit. c. GDPR.
The data is deleted when it is no longer required for the fulfillment of contractual or statutory duties of care or for dealing with any warranty and comparable obligations, whereby the necessity of retaining the data is reviewed every three years; otherwise, the statutory retention obligations apply.
External payment service providers
We use external payment service providers whose platforms enable users and us to carry out payment transactions (e.g., in each case with a link to the privacy policy, Paypal (https://www.paypal.com/de/webapps/mpp/ua/privacy-full), Klarna (https://www.klarna.com/de/datenschutz/), Skrill (https://www.skrill.com/de/fusszeile/datenschutzrichtlinie/), Giropay (https://www.giropay.de/rechtliches/datenschutz-agb/), Visa (https://www.visa.de/datenschutz), Mastercard (https://www.mastercard.de/de-de/datenschutz.html), American Express (https://www.americanexpress.com/de/content/privacy-policy-statement.html)
For the performance of contracts, we use payment service providers on the basis of Art. 6 para. 1 lit. b. GDPR. In addition, we use external payment service providers on the basis of our legitimate interests pursuant to Art. 6 para. 1 lit. f. GDPR in order to offer our users effective and secure payment options.
The data processed by the payment service providers includes master data, such as the name and address, bank details, such as account numbers or credit card numbers, passwords, TANs and checksums, as well as contract-related, amount-related and recipient-related information. This information is required to carry out the transactions. However, the data entered is processed and stored solely by the payment service providers. This means that we do not receive any account- or credit-card-related information, but only information confirming or rejecting the payment. Under certain circumstances, the payment service providers may transmit the data to credit agencies. The purpose of this transmission is to verify identity and creditworthiness. In this regard, we refer to the terms and conditions and privacy notices of the payment service providers.
The terms and conditions and privacy notices of the respective payment service providers, which can be accessed on the respective websites or transaction applications, apply to payment transactions. We also refer to these for further information and for exercising rights of withdrawal, access and other data-subject rights.
Administration, financial accounting, office organization, contact management
We process data in the course of administrative tasks as well as the organization of our operations, financial accounting and compliance with legal obligations, such as archiving. In this context, we process the same data that we process in the course of providing our contractual services. The legal bases for processing are Art. 6 para. 1 lit. c. GDPR, Art. 6 para. 1 lit. f. GDPR. The processing affects customers, prospective customers, business partners and website visitors. The purpose of and our interest in the processing lies in administration, financial accounting, office organization and the archiving of data, i.e. tasks that serve to maintain our business activities, perform our duties and provide our services. The deletion of data with regard to contractual services and contractual communication corresponds to the information specified for these processing activities.
In this context, we disclose or transmit data to the financial authorities, consultants, such as tax advisors or auditors, as well as other fee-collecting bodies and payment service providers.
Furthermore, on the basis of our business interests, we store information about suppliers, organizers and other business partners, e.g. for the purpose of contacting them at a later date. We generally store this predominantly business-related data permanently.
Business Analyses and Market Research
In order to operate our business economically and identify market trends and the wishes of contractual partners and users, we analyze the data available to us concerning business transactions, contracts, inquiries, etc. We process master data, communication data, contract data, payment data, usage data and metadata on the basis of Art. 6 para. 1 lit. f. GDPR, whereby the data subjects include contractual partners, prospective customers, customers, visitors and users of our online services.
The analyses are conducted for the purposes of business evaluations, marketing and market research. In doing so, we may take into account the profiles of registered users together with information, e.g. regarding the services they have used. The analyses help us improve user-friendliness, optimize our services and increase cost-effectiveness. The analyses are for our use alone and are not disclosed externally unless they are anonymous analyses containing aggregated values.
Insofar as these analyses or profiles contain personal data, they are deleted or anonymized when the users terminate their accounts, otherwise two years after conclusion of the contract. In all other respects, the overall business analyses and general trend assessments are prepared anonymously wherever possible.
Participation in Affiliate Partner Programs
Within our online services, on the basis of our legitimate interests (i.e. our interest in the analysis, optimization and economic operation of our online services) pursuant to Art. 6 para. 1 lit. f GDPR, we use tracking measures customary in the industry insofar as these are necessary for the operation of the affiliate system. Below, we inform users about the technical background.
The services offered by our contractual partners may also be advertised and linked on other websites (so-called affiliate links or after-buy systems, where, for example, third-party links or services are offered after a contract has been concluded). The operators of the respective websites receive a commission if users follow the affiliate links and subsequently take advantage of the offers.
In summary, our online offering requires us to be able to track whether users who are interested in affiliate links and/or the offers available from us subsequently take advantage of the offers as a result of the affiliate links or our online platform. For this purpose, certain values are added to the affiliate links and our offers, which may form part of the link or be set in another way, e.g. in a cookie. These values include, in particular, the originating website (referrer), time, an online identifier of the operators of the website on which the affiliate link was located, an online identifier of the respective offer, an online identifier of the user, as well as tracking-specific values such as advertising material ID, partner ID and categorizations.
The online identifiers of users that we use are pseudonymous values. This means that the online identifiers themselves do not contain any personal data such as names or email addresses. They only help us determine whether the same user who clicked on an affiliate link or expressed interest in an offer via our online offering took advantage of the offer, i.e. for example, concluded a contract with the provider. However, the online identifier constitutes personal data insofar as the partner company and we have access to the online identifier together with other user data. Only in this way can the partner company inform us whether the user in question took advantage of the offer and we can, for example, pay out the bonus.
Amazon Partner Program
On the basis of our legitimate interests (i.e. our interest in the commercial operation of our online offering within the meaning of Art. 6 para. 1 lit. f GDPR), we participate in the Amazon EU Partner Program, which was designed to provide a medium for websites through which advertising fees can be earned by placing advertisements and links to Amazon.de (so-called affiliate system). This means that, as an Amazon partner, we earn from qualifying purchases.
Amazon uses cookies to track the origin of orders. Among other things, Amazon can recognize that you clicked on the affiliate link on this website and subsequently purchased a product from Amazon.
Further information on the use of data by Amazon and options for objection can be found in the company’s privacy policy: https://www.amazon.de/gp/help/customer/display.html?nodeId=201909010.
Note: Amazon and the Amazon logo are trademarks of Amazon.com, Inc. or one of its affiliated companies.
Digistore24 Partner Program
We are, on the basis of our legitimate interests (i.e. our interest in the commercial operation of our online offering within the meaning of Art. 6(1)(f) GDPR), participants in the affiliate program of Digistore24 GmbH, St.-Godehard-Straße 32, 31139 Hildesheim, Deutschland, which was designed to provide a medium for websites through which advertising reimbursements can be earned by placing advertisements and links to Digistore24 (so-called affiliate system). Digistore24 uses cookies to track the origin of the conclusion of the contract. Among other things, Digistore24 can recognize that you clicked the affiliate link on this website and subsequently concluded a contract with or via Digistore24.
Further information on data use by Digistore24 and options for objection can be found in the company’s privacy policy: https://www.digistore24.com/page/privacyl.
Privacy information for the application process
We process applicant data only for the purpose of and within the scope of the application process in accordance with the statutory requirements. Applicant data is processed to fulfill our (pre-)contractual obligations within the application process pursuant to Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR where data processing is necessary for us, e.g. in connection with legal proceedings (in Deutschland, Section 26 BDSG also applies).
The application process requires applicants to provide us with applicant data. Where we provide an online form, the required applicant data is indicated; otherwise, it is specified in the job descriptions and generally includes personal details, postal and contact addresses, and application documents such as a cover letter, résumé, and certificates. Applicants may also voluntarily provide us with additional information.
By submitting their application to us, applicants consent to the processing of their data for the purposes of the application process in accordance with the nature and scope set out in this privacy policy.
Where special categories of personal data within the meaning of Art. 9(1) GDPR are voluntarily disclosed during the application process, such data is additionally processed pursuant to Art. 9(2)(b) GDPR (e.g. health data, such as severe disability status, or ethnic origin). Where special categories of personal data within the meaning of Art. 9(1) GDPR are requested from applicants during the application process, such data is additionally processed pursuant to Art. 9(2)(a) GDPR (e.g. health data where required for the performance of the occupation).
If made available, applicants may submit their applications to us using an online form on our website. The data is transmitted to us in encrypted form using state-of-the-art technology.
Furthermore, applicants may submit their applications to us by email. However, please note that emails are generally not sent in encrypted form and applicants must ensure encryption themselves. We therefore cannot accept any responsibility for the transmission of the application between the sender and its receipt on our server and consequently recommend using an online form or sending it by post instead. Applicants may still send us their application by post instead of applying via the online form or email.
The data provided by applicants may, in the event of a successful application, be further processed by us for the purposes of the employment relationship. Otherwise, if the application for a vacancy is unsuccessful, the applicants’ data will be deleted. Applicants’ data will also be deleted if an application is withdrawn, which applicants are entitled to do at any time.
Subject to a legitimate objection by the applicants, deletion will take place after a period of six months so that we can answer any follow-up questions regarding the application and comply with our obligations to provide evidence under the Equal Treatment Act. Invoices relating to any reimbursement of travel expenses will be archived in accordance with tax law requirements.
Registration function
Users can create a user account. During registration, users will be informed of the required mandatory information, which will be processed on the basis of Art. 6 para. 1 lit. b GDPR for the purpose of providing the user account. The processed data includes, in particular, login information (name, password, and an email address). The data entered during registration will be used for the purposes of using the user account and its intended purpose.
Users may be informed by email about information relevant to their user account, such as technical changes. If users have terminated their user account, their data relating to the user account will be deleted, subject to any statutory retention obligation. Users are responsible for securing their data before the end of the contract upon termination. We are entitled to irretrievably delete all user data stored during the term of the contract.
When users make use of our registration and login functions and use their user account, we store the IP address and the time of the respective user action. This storage is based on our legitimate interests, as well as those of the users, in protection against misuse and other unauthorized use. This data is generally not disclosed to third parties unless this is necessary to pursue our claims or there is a legal obligation to do so pursuant to Art. 6 para. 1 lit. c. GDPR. The IP addresses will be anonymized or deleted after no more than 7 days.
Contact
When you contact us (e.g. via contact form, email, telephone or social media), the user’s details are processed for the purpose of handling and responding to the contact request in accordance with Art. 6 para. 1 lit. b. GDPR (within the scope of contractual/pre-contractual relationships) and Art. 6 para. 1 lit. f. GDPR (other enquiries). The user’s details may be stored in a customer relationship management system ("CRM System") or a comparable enquiry management system.
We delete enquiries when they are no longer required. We review their necessity every two years; statutory archiving obligations also apply.
Newsletter
The following information explains the content of our newsletter, the registration, dispatch and statistical evaluation procedures, as well as your rights to object. By subscribing to our newsletter, you consent to receiving it and to the procedures described.
Newsletter content: We send newsletters, emails and other electronic notifications containing promotional information (hereinafter referred to as the “Newsletter”) only with the recipients’ consent or where legally permitted. If the content of the newsletter is specifically described during registration, that content is decisive for the users’ consent. Otherwise, our newsletters contain information about us and our services.
Double opt-in and logging: Registration for our newsletter uses a double opt-in procedure. This means that after registering, you will receive an email asking you to confirm your registration. This confirmation is necessary to prevent anyone from registering using someone else’s email address. Newsletter registrations are logged so that the registration process can be demonstrated to comply with legal requirements. This includes storing the time of registration and confirmation, as well as the IP address. Any changes to your data stored by the mailing service provider are also logged.
Registration details: To subscribe to the newsletter, you only need to provide your email address. Optionally, we ask you to provide a name so that we can address you personally in the newsletter.
The newsletter is sent and its performance is measured on the basis of the recipients’ consent in accordance with Art. 6 para. 1 lit. a and Art. 7 GDPR in conjunction with Section 7 para. 2 no. 3 UWG or, where consent is not required, on the basis of our legitimate interests in direct marketing in accordance with Art. 6 para. 1 lit. f. GDPR in conjunction with Section 7 para. 3 UWG.
The registration procedure is logged on the basis of our legitimate interests in accordance with Art. 6 para. 1 lit. f GDPR. Our interest lies in using a user-friendly and secure newsletter system that serves our business interests, meets users’ expectations and also allows us to provide evidence of consent.
Unsubscribe/Withdrawal – You may unsubscribe from receiving our newsletter at any time, i.e. withdraw your consent. You will find a link to unsubscribe from the newsletter at the end of each newsletter. We may store unsubscribed email addresses for up to three years on the basis of our legitimate interests before deleting them, in order to be able to demonstrate that consent was previously given. The processing of this data will be restricted to the purpose of potentially defending against claims. An individual request for deletion may be made at any time, provided that the former existence of consent is confirmed at the same time.
Newsletter – Mailing Service Provider
The newsletters are sent using the mailing service provider FunnelCockpit GbR, represented by Denis Hoeger Caballero, Just Viral GmbH & Co. KG and Marius Gebhardt. You can view the mailing service provider’s privacy policy here: https://funnelcockpit.com/datenschutz/. The mailing service provider is engaged on the basis of our legitimate interests pursuant to Art. 6 para. 1 lit. f GDPR and a data processing agreement pursuant to Art. 28 para. 3 sentence 1 GDPR.
The mailing service provider may use recipients’ data in pseudonymous form, i.e. without associating it with a user, to optimize or improve its own services, e.g. for the technical optimization of the mailing and presentation of newsletters or for statistical purposes. However, the mailing service provider does not use the data of our newsletter recipients to contact them directly or to disclose the data to third parties.
Newsletter – Performance Measurement
The newsletters contain a so-called “web beacon”, i.e. a pixel-sized file that is retrieved from our server when the newsletter is opened or, if we use a mailing service provider, from its server. As part of this retrieval, technical information, such as information about the browser and your system, as well as your IP address and the time of retrieval, is initially collected.
This information is used for the technical improvement of the services based on the technical data or of the target groups and their reading behavior based on their retrieval locations (which can be determined with the aid of the IP address) or access times. The statistical surveys also include determining whether the newsletters are opened, when they are opened, and which links are clicked. For technical reasons, this information can be associated with individual newsletter recipients. However, neither we nor, where applicable, the mailing service provider aim to monitor individual users. Rather, the analyses help us identify our users’ reading habits and tailor our content to them or send different content according to our users’ interests.
Unfortunately, it is not possible to withdraw consent separately for performance measurement; in this case, the entire newsletter subscription must be canceled.
Hosting and Email Delivery
The hosting services we use serve to provide the following services: infrastructure and platform services, computing capacity, storage space and database services, email delivery, security services, and technical maintenance services, which we use for the purpose of operating this online offering.
In this context, we and our hosting provider process master data, contact data, content data, contract data, usage data, metadata and communications data of customers, prospective customers and visitors to this online offering on the basis of our legitimate interests in the efficient and secure provision of this online offering pursuant to Art. 6(1)(f) GDPR in conjunction with Art. 28 GDPR (conclusion of a data processing agreement).
Collection of Access Data and Log Files
We and our hosting provider collect data on every access to the server on which this service is hosted (so-called server log files) on the basis of our legitimate interests within the meaning of Art. 6(1)(f) GDPR. The access data includes the name of the website accessed, file, date and time of access, amount of data transferred, notification of successful access, browser type and version, the user’s operating system, referrer URL (the previously visited page), IP address and the requesting provider.
Log file information is stored for security reasons (e.g. to investigate misuse or fraudulent activities) for a maximum of 7 days and then deleted. Data whose continued retention is required for evidentiary purposes is exempt from deletion until the respective incident has been conclusively resolved.
Google Analytics
On the basis of our legitimate interests (i.e. our interest in the analysis, optimization and economic operation of our online offering within the meaning of Art. 6(1)(f) GDPR), we use Google Analytics, a web analytics service provided by Google LLC (“Google”). Google uses cookies. The information generated by the cookie about users’ use of the online offering is generally transmitted to and stored on a Google server in the USA.
Google is certified under the Privacy Shield Framework and thereby guarantees compliance with European data protection law (https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active).
Google will use this information on our behalf to evaluate users’ use of our online offering, to compile reports on activities within this online offering and to provide us with other services relating to the use of this online offering and the use of the internet. Pseudonymous user profiles may be created from the processed data.
We use Google Analytics only with IP anonymization enabled. This means that users’ IP addresses are truncated by Google within member states of the European Union or in other states party to the Agreement on the European Economic Area. Only in exceptional cases is the full IP address transmitted to a Google server in the USA and truncated there.
The IP address transmitted by the user’s browser is not merged with other Google data. Users can prevent cookies from being stored by selecting the appropriate settings in their browser software; users can also prevent Google from collecting the data generated by the cookie and relating to their use of the online offering, as well as the processing of this data by Google, by downloading and installing the browser plugin available at the following link: http://tools.google.com/dlpage/gaoptout?hl=de.
Further information about Google’s use of data, settings and opt-out options can be found in Google’s privacy policy (https://policies.google.com/privacy) and in the settings for the display of advertisements by Google (https://adssettings.google.com/authenticated).
Users’ personal data is deleted or anonymized after 14 months.
Google Adsense with personalized ads
[output truncated at 50000 of 55478 characters. Pass a larger max_chars (default 50000) to see more, or use read_page with a ref_id to focus on a smaller section.]