Privacy Policy
We are delighted that you are interested in our company. Data protection is of particular importance to the management of widestripe. The use of widestripe’s website is generally possible without providing any personal data. However, if a data subject wishes to use specific services provided by our company via our website or app, the processing of personal data may become necessary. Where the processing of personal data is necessary and there is no legal basis for such processing, we generally obtain the data subject’s consent.
The processing of personal data, such as a data subject’s name, address, email address, telephone number, date of birth and measured foot dimensions, is always carried out in accordance with the General Data Protection Regulation (GDPR) and the country-specific data protection provisions applicable to widestripe. Through this Privacy Policy, our company would like to inform the public about the nature, scope and purpose of the personal data we collect, use and process. Furthermore, this Privacy Policy informs data subjects about their rights.
As the controller, widestripe has implemented numerous technical and organisational measures to ensure the most complete protection possible of personal data processed through this website. Nevertheless, internet-based data transmissions can generally have security gaps, meaning that absolute protection cannot be guaranteed. For this reason, every data subject is free to transmit personal data to us by alternative means, for example by telephone.
1. Definitions
widestripe’s Privacy Policy is based on the terminology used by the European legislator when adopting the General Data Protection Regulation (GDPR). Our Privacy Policy should be easy to read and understand for the public, our customers and our business partners. To ensure this, we would first like to explain the terminology used.
In this Privacy Policy, we use, among others, the following terms:
a) Personal data
Personal data means any information relating to an identified or identifiable natural person (hereinafter referred to as the “data subject”). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, online identifier or one or more factors specific to that person’s physical, physiological, genetic, mental, economic, cultural or social identity.
b) Data subject
A data subject is any identified or identifiable natural person whose personal data are processed by the controller.
c) Processing
Processing means any operation or set of operations performed on personal data, whether or not by automated means. This includes collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
d) Restriction of processing
Restriction of processing means the marking of stored personal data with the aim of limiting their future processing.
e) Profiling
Profiling means any form of automated processing of personal data consisting of the use of such personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s work performance, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.
f) Pseudonymisation
Pseudonymisation means the processing of personal data in such a way that the personal data can no longer be attributed to a specific data subject without additional information, provided that such additional information is kept separately and is subject to technical and organisational measures ensuring that the personal data are not attributed to an identified or identifiable natural person.
g) Controller
Controller means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of processing personal data. Where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its appointment may be provided for by Union or Member State law.
h) Processor
Processor means a natural or legal person, public authority, agency or other body that processes personal data on behalf of the controller.
i) Recipient
Recipient means a natural or legal person, public authority, agency or other body to which personal data are disclosed, whether or not it is a third party. Public authorities that may receive personal data in the context of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.
j) Third party
Third party means a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data.
k) Consent
Consent means any freely given, specific, informed and unambiguous indication of the data subject’s wishes, in the form of a statement or other clear affirmative action, by which they signify their agreement to the processing of personal data relating to them.
2. Name and address of the controller
The controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and other provisions relating to data protection is:
WideStripe
Peter Mayer
Kernerstraße 18
71679 Asperg
Germany
Telephone: +49 157 30355353
Email: info@wide-stripe.de
3. Cookies
The widestripe website uses cookies. Cookies are text files that are stored on a computer system via an internet browser.
Many websites and servers use cookies. Many cookies contain a so-called cookie ID. A cookie ID is a unique identifier for the cookie. It consists of a string of characters through which websites and servers can be assigned to the specific internet browser in which the cookie was stored. This allows visited websites and servers to distinguish the data subject’s individual browser from other internet browsers containing other cookies. A specific internet browser can be recognised and identified through its unique cookie ID.
By using cookies, widestripe can provide users of this website with more user-friendly services that would not be possible without cookies.
Cookies enable the information and offers on our website to be optimised in the interests of the user. As already mentioned, cookies allow us to recognise users of our website. The purpose of this recognition is to make it easier for users to use our website. For example, a user of a website that uses cookies does not have to enter their login details each time they visit the website, as these are stored by the website and the cookie placed on the user’s computer system. Another example is a shopping basket cookie in an online shop. The online shop remembers the items that a customer has placed in their virtual shopping basket through a cookie.
The data subject can prevent the use of cookies by our website at any time by adjusting the settings of the internet browser used and may therefore permanently object to the use of cookies. In addition, cookies that have already been set can be deleted at any time via an internet browser or other software programmes. This is possible in all commonly used internet browsers. If the data subject deactivates cookies in the internet browser used, not all functions of our website may be fully available.
4. Collection of general data and information
Each time the widestripe website is accessed by a data subject or an automated system, the website collects a range of general data and information. This general data and information is stored in the server log files. The following may be collected: (1) the browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system reaches our website (known as the referrer), (4) the subpages accessed via an accessing system on our website, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used to protect against threats in the event of attacks on our IT systems.
When using this general data and information, widestripe does not draw any conclusions about the data subject. Rather, this information is required to (1) deliver the content of our website correctly, (2) optimise the content of our website and its advertising, (3) ensure the long-term functionality of our IT systems and the technology of our website and (4) provide law enforcement authorities with the information necessary for prosecution in the event of a cyberattack. These anonymously collected data and information are therefore evaluated by widestripe both statistically and with the aim of increasing data protection and data security within our company, ultimately ensuring the best possible level of protection for the personal data we process. The anonymous data in the server log files are stored separately from all personal data provided by a data subject.
4.1 Visitors
This website uses the visitor and access counter “Visitors” by Glen Langer (BugBuster). Visitors is an extension for the Contao content management system (CMS).
Unlike most other visitor statistics tools, Visitors does not store raw data and analyse it later. The necessary evaluations are performed immediately. This means that only the completed statistical data are stored, with the exception of the IP address, as explained below. This achieves the objectives of data avoidance and data minimisation as effectively as possible.
Data collection
IP address
Only the IP address is used to identify different visitors. No JavaScript and no cookies are used.
Browser agent and referrer
For additional statistics, the browser agent and, where available, the referrer are read. Both are stored separately from the IP address and cannot therefore be linked to it.
Data storage
IP address
The visitor’s IP address is not stored. Except for the identification of bots, crawlers and spiders, the IP address is not used for any further analytical purposes.
A pseudonym in the form of a hash value is generated from the IP address and other internal data. Reverse calculation is conceivable, but only with considerable effort. The hash value is not linked to any other statistical evaluation.
Browser agent and referrer
For the browser agent, only combinations of browser, language and operating system are stored together with a count; the complete agent string is not stored.
For the referrer, the URL is stored along with a count and timestamp of the most recent occurrence, without any link to the IP address or browser agent.
Data retention
The hash values used to identify different visitors are checked each time the website is accessed, and expired values are deleted. The retention period corresponds to the blocking period; the default value is 1,800 seconds, i.e. 30 minutes.
The number of visitors/accesses per day is stored permanently, and the other displays are generated from this. This storage can be deleted via the Contao backend, after which the counter starts again at 0.
Further information can be found on the Visitors developer’s website: Visitors documentation.
5. Registration on our website
The data subject has the option of registering on the website or app of the controller by providing personal data. The personal data transmitted to the controller in this process is determined by the respective registration form used. The personal data entered by the data subject are collected and stored exclusively for internal use by the controller and for its own purposes. The controller may arrange for the transfer of the data to one or more processors, for example a parcel delivery service, which will likewise use the personal data exclusively for internal purposes attributable to the controller.
When registering on the controller’s website, the IP address assigned by the data subject’s internet service provider (ISP), as well as the date and time of registration, are also stored. This data is stored because this is the only way to prevent misuse of our services and, if necessary, to investigate criminal offences. In this respect, the storage of this data is necessary to safeguard the controller. As a rule, this data is not passed on to third parties unless there is a legal obligation to do so or the transfer serves law enforcement purposes.
The registration of the data subject, with the voluntary provision of personal data, enables the controller to offer the data subject content or services that can, by their nature, only be offered to registered users. Registered persons are free to amend the personal data provided during registration at any time or to have it completely deleted from the controller’s records.
Upon request, the controller shall provide every data subject at any time with information about which personal data relating to them is stored. Furthermore, the controller shall correct or delete personal data at the request or upon notice of the data subject, provided that no statutory retention obligations prevent this. All employees of the controller are available to the data subject as contact persons in this regard.
6. Business services
We process the personal data of our contractual and business partners, including customers, clients, prospective customers, suppliers and other cooperation partners (collectively, “contractual partners”), for the initiation, performance and handling of contractual relationships and comparable legal relationships. This also includes pre-contractual measures taken in response to enquiries, as well as communication related to the respective contractual relationship.
Processing serves, in particular, to fulfil our primary and ancillary contractual obligations. This includes the provision of agreed services, any update and information obligations, the handling of warranty claims and other service disruptions, the processing of withdrawals, termination of continuing obligations, reversals, reimbursements and other contract-related declarations and enquiries. Both one-off contracts and ongoing contractual relationships are covered.
In particular, we process master data such as names, addresses and, where applicable, company names; contact details such as email addresses and telephone numbers; contract and service data such as the subject matter and duration of the contract, order or transaction number; usage and performance data; payment and billing data; as well as communication content and history. Where necessary, we also process data disclosed or transmitted to us in connection with the performance of an order.
In addition, we process data to protect our rights and to fulfil legal obligations. This includes, in particular, retention obligations under commercial and tax law, documentation obligations and, where applicable, verification and accountability obligations. Processing also takes place on the basis of our legitimate interests in proper business management, internal administration, risk management and IT security, as well as in protecting our business operations and contractual partners from misuse, threats to data, confidential information and other legal interests. This may also include the involvement of external service providers, such as IT and telecommunications providers, transport and logistics companies, payment service providers, banks, tax advisers, legal advisers or other agents, where necessary for contract performance or compliance with legal obligations.
Personal data is only disclosed to third parties where this is necessary for the performance of the contract, the implementation of pre-contractual measures, the protection of legitimate interests or the fulfilment of legal obligations. We provide separate information in this Privacy Policy about any additional processing, particularly for marketing purposes.
We inform contractual partners which data is required in each individual case during data collection, for example through appropriate labelling in online forms or during personal contact.
Data is deleted as soon as it is no longer required for the above-mentioned purposes and no statutory retention obligations prevent its deletion. Statutory retention periods, particularly under commercial and tax law, may require longer storage. Data transmitted in connection with a specific order is deleted after completion of the order and expiry of any retention periods, provided that no further legal or contractual obligations to retain the data exist.
The legal basis for processing is Article 6(1)(b) GDPR for the performance of pre-contractual measures and fulfilment of the respective contractual relationship, as well as Article 6(1)(c) GDPR for compliance with legal obligations. Where processing is based on legitimate interests, it is carried out on the basis of Article 6(1)(f) GDPR. Where processing is based on Article 6(1)(f) GDPR, it serves to protect our legitimate interests in proper and efficient business organisation, internal administration and documentation of business processes, the assertion and defence of legal claims, ensuring IT and data security, preventing misuse and fraud, and the economic management and further development of our business operations. These interests exist in particular to ensure secure and legally compliant business operations and to safeguard our ability to act as a business.
Types of data processed: Master data (e.g. full name, residential address, contact information, customer number); payment data (e.g. bank details, invoices, payment history); contact data (e.g. postal and email addresses or telephone numbers); contract data (e.g. subject matter of the contract, term, customer category); usage data (e.g. page views and time spent on pages, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); meta, communication and procedural data (e.g. IP addresses, time details, identification numbers, persons involved).
Data subjects: Service recipients and clients; prospective customers; business and contractual partners.
Purposes of processing and legitimate interests: Provision of contractual services and fulfilment of contractual obligations; security measures; communication; office and organisational procedures; organisational and administrative procedures; business processes and operational business procedures.
Retention and deletion: Deletion in accordance with the information in the section “General information on data storage and deletion”.
Legal bases: Performance of contracts and pre-contractual enquiries (Article 6(1), first sentence, point (b) GDPR); legal obligation (Article 6(1), first sentence, point (c) GDPR); legitimate interests (Article 6(1), first sentence, point (f) GDPR).
Further information on processing operations, procedures and services:
Online shop, order forms, e-commerce and service fulfilment: We process our customers’ data to enable them to select, purchase or order the chosen products, goods and related services, as well as to enable payment for and provision, delivery or fulfilment of these. Where necessary for the fulfilment of an order, we use service providers, in particular postal, forwarding and shipping companies, to carry out delivery or fulfilment for our customers. For payment processing, we use the services of banks and payment service providers. The required information is identified as such in the order process or comparable purchase process and includes the information required for delivery, provision and invoicing, as well as contact information for any necessary communication.
7. Subscription to our newsletter
On the widestripe website, users are given the opportunity to subscribe to our company newsletter. The personal data transmitted to the controller when subscribing to the newsletter is determined by the input form used for this purpose.
widestripe regularly informs its customers and business partners about company offers by means of a newsletter. In principle, the data subject may only receive our company newsletter if (1) the data subject has a valid email address and (2) the data subject has registered for the newsletter. For legal reasons, a confirmation email is sent to the email address first entered by the data subject for newsletter delivery using the double opt-in procedure. This confirmation email serves to verify whether the owner of the email address, as the data subject, has authorised receipt of the newsletter.
When subscribing to the newsletter, we also store the IP address assigned by the internet service provider (ISP) to the computer system used by the data subject at the time of registration, as well as the date and time of registration. The collection of this data is necessary in order to be able to trace the possible misuse of a data subject’s email address at a later date and therefore serves the controller’s legal protection.
The personal data collected when subscribing to the newsletter is used exclusively for sending our newsletter. In addition, newsletter subscribers may be informed by email where this is necessary for the operation of the newsletter service or registration in relation to it, for example in the event of changes to the newsletter offer or changes in technical circumstances. Personal data collected as part of the newsletter service is not passed on to third parties. The data subject may cancel their newsletter subscription at any time. Consent to the storage of personal data given to us by the data subject for the purpose of sending the newsletter may be withdrawn at any time. Every newsletter contains a corresponding link for withdrawing consent. It is also possible to unsubscribe from the newsletter at any time directly on the controller’s website or to notify the controller of this in another way.
8. Newsletter tracking
widestripe newsletters contain so-called tracking pixels. A tracking pixel is a miniature graphic embedded in emails sent in HTML format in order to enable log file recording and log file analysis. This allows a statistical analysis of the success or failure of online marketing campaigns. Based on the embedded tracking pixel, widestripe can identify whether and when an email was opened by a data subject and which links contained in the email were accessed by the data subject.
Such personal data collected through the tracking pixels contained in newsletters is stored and evaluated by the controller in order to optimise newsletter delivery and adapt the content of future newsletters even more effectively to the data subject’s interests. This personal data is not passed on to third parties. Data subjects are entitled to withdraw their separate declaration of consent provided through the double opt-in procedure at any time. Following withdrawal, this personal data will be deleted by the controller. widestripe automatically interprets unsubscribing from the newsletter as a withdrawal of consent.
9. Contact options via the website
Due to legal requirements, the widestripe website contains information that enables users to contact our company quickly by electronic means and communicate with us directly, including a general address for electronic mail (email address). If a data subject contacts the controller by email or via a contact form, the personal data transmitted by the data subject is automatically stored. Personal data voluntarily transmitted by a data subject to the controller is stored for the purpose of processing the enquiry or contacting the data subject. This personal data is not passed on to third parties.
10. Comment function in the blog on the website
widestripe offers users the opportunity to leave individual comments on individual blog posts in a blog located on the controller’s website. A blog is a publicly accessible portal maintained on a website in which one or more persons, known as bloggers or web bloggers, publish articles or record thoughts in so-called blog posts. Blog posts can generally be commented on by third parties.
If a data subject leaves a comment in the blog published on this website, in addition to the comment left by the data subject, information regarding the time the comment was entered and the username (pseudonym) chosen by the data subject will be stored and published. In addition, the IP address assigned by the data subject’s internet service provider (ISP) is logged. This IP address is stored for security reasons and in case the data subject infringes third-party rights or posts unlawful content through a submitted comment. The storage of this personal data is therefore in the controller’s own interest, so that the controller may be exonerated in the event of a legal violation. This personal data is not passed on to third parties unless such disclosure is required by law or serves the controller’s legal defence.
11. Subscription to comments in the blog on the website
Comments made in widestripe’s blog can generally be subscribed to by third parties. In particular, a commenter may subscribe to the comments following their own comment on a specific blog post.
If a data subject chooses to subscribe to comments, the controller will send an automatic confirmation email in order to verify, using the double opt-in procedure, that the owner of the email address provided has actually chosen this option. The option to subscribe to comments may be terminated at any time.
12. Routine deletion and blocking of personal data
The controller shall process and store the data subject’s personal data only for the period necessary to achieve the purpose of storage or where this is provided for by the European legislator or another legislator in laws or regulations to which the controller is subject.
If the purpose of storage no longer applies, or if a retention period prescribed by the European legislator or another competent legislator expires, personal data will be routinely blocked or deleted in accordance with statutory provisions.
13. Rights of the data subject
a) Right to confirmation
Every data subject has the right granted by the European legislator to obtain confirmation from the controller as to whether personal data concerning them is being processed. If a data subject wishes to exercise this right of confirmation, they may contact an employee of the controller at any time.
b) Right of access
Every data subject affected by the processing of personal data has the right granted by the European legislator to obtain, at any time and free of charge, information from the controller about the personal data stored concerning them and a copy of this information. Furthermore, the European legislator has granted the data subject access to the following information:
The purposes of processing;
The categories of personal data being processed;
The recipients or categories of recipients to whom the personal data has been or will be disclosed, particularly recipients in third countries or international organisations;
Where possible, the planned period for which the personal data will be stored or, where this is not possible, the criteria used to determine that period;
The existence of a right to rectification or erasure of personal data concerning them, a right to restriction of processing by the controller or a right to object to such processing;
The existence of a right to lodge a complaint with a supervisory authority;
Where personal data is not collected from the data subject: all available information about the source of the data;
The existence of automated decision-making, including profiling, pursuant to Article 22(1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and envisaged consequences of such processing for the data subject.
The data subject also has the right to know whether personal data has been transferred to a third country or international organisation. Where this is the case, the data subject shall also have the right to receive information about the appropriate safeguards relating to the transfer.
If a data subject wishes to exercise this right of access, they may contact an employee of the controller at any time.
c) Right to rectification
Every data subject affected by the processing of personal data has the right granted by the European legislator to request the immediate rectification of inaccurate personal data concerning them. Furthermore, taking into account the purposes of processing, the data subject has the right to request the completion of incomplete personal data, including by means of a supplementary statement.
If a data subject wishes to exercise this right to rectification, they may contact an employee of the controller at any time.
d) Right to erasure (“right to be forgotten”)
Every data subject affected by the processing of personal data has the right granted by the European legislator to require the controller to erase personal data concerning them without undue delay, where one of the following grounds applies and processing is not necessary:
The personal data was collected or otherwise processed for purposes for which it is no longer necessary.
The data subject withdraws consent on which processing is based pursuant to Article 6(1)(a) GDPR or Article 9(2)(a) GDPR, and there is no other legal ground for the processing.
The data subject objects to processing pursuant to Article 21(1) GDPR and there are no overriding legitimate grounds for processing, or the data subject objects to processing pursuant to Article 21(2) GDPR.
The personal data has been processed unlawfully.
Erasure of personal data is necessary for compliance with a legal obligation under Union or Member State law to which the controller is subject.
The personal data has been collected in relation to the offer of information society services pursuant to Article 8(1) GDPR.
Where one of the above reasons applies and a data subject wishes to arrange for the erasure of personal data stored by widestripe, they may contact an employee of the controller at any time. The widestripe employee will arrange for the erasure request to be complied with without delay.
Where widestripe has made personal data public and is obliged pursuant to Article 17(1) GDPR to erase the personal data, widestripe shall, taking account of available technology and the costs of implementation, take reasonable steps, including technical measures, to inform other controllers processing the published personal data that the data subject has requested the erasure by such controllers of all links to, copies of or replications of that personal data, insofar as processing is not required. The widestripe employee will take the necessary steps in each individual case.
e) Right to restriction of processing
Every data subject affected by the processing of personal data has the right granted by the European legislator to request that the controller restrict processing where one of the following conditions applies:
The accuracy of the personal data is contested by the data subject, for a period enabling the controller to verify the accuracy of the personal data.
The processing is unlawful, the data subject opposes the erasure of the personal data and requests the restriction of its use instead.
The controller no longer needs the personal data for processing purposes, but the data subject requires it for the establishment, exercise or defence of legal claims.
The data subject has objected to processing pursuant to Article 21(1) GDPR, pending verification of whether the controller’s legitimate grounds override those of the data subject.
Where one of the above conditions applies and a data subject wishes to request the restriction of personal data stored by widestripe, they may contact an employee of the controller at any time. The widestripe employee will arrange for the restriction of processing.
f) Right to data portability
Every data subject affected by the processing of personal data has the right granted by the European legislator to receive the personal data concerning them, which was provided by the data subject to a controller, in a structured, commonly used and machine-readable format. They also have the right to transmit this data to another controller without hindrance from the controller to whom the personal data was provided, where processing is based on consent pursuant to Article 6(1)(a) GDPR or Article 9(2)(a) GDPR, or on a contract pursuant to Article 6(1)(b) GDPR, and processing is carried out by automated means, provided that processing is not necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.
Furthermore, when exercising their right to data portability pursuant to Article 20(1) GDPR, the data subject has the right to have personal data transmitted directly from one controller to another where technically feasible and where this does not adversely affect the rights and freedoms of others.
To exercise the right to data portability, the data subject may contact a widestripe employee at any time.
g) Right to object
Every data subject affected by the processing of personal data has the right granted by the European legislator to object, on grounds relating to their particular situation, at any time to the processing of personal data concerning them that is based on Article 6(1)(e) or (f) GDPR. This also applies to profiling based on those provisions.
In the event of an objection, widestripe shall no longer process the personal data unless we can demonstrate compelling legitimate grounds for processing that override the interests, rights and freedoms of the data subject, or where processing serves the establishment, exercise or defence of legal claims.
Where widestripe processes personal data for direct marketing purposes, the data subject has the right to object at any time to the processing of personal data for such marketing. This also applies to profiling insofar as it is related to such direct marketing. If the data subject objects to widestripe processing for direct marketing purposes, widestripe will no longer process the personal data for these purposes.
In addition, the data subject has the right, on grounds relating to their particular situation, to object to the processing of personal data concerning them carried out by widestripe for scientific or historical research purposes or statistical purposes pursuant to Article 89(1) GDPR, unless such processing is necessary for the performance of a task carried out in the public interest.
To exercise the right to object, the data subject may contact any widestripe employee or another employee directly. In the context of using information society services, and notwithstanding Directive 2002/58/EC, the data subject is also free to exercise their right to object by automated means using technical specifications.
h) Automated individual decision-making, including profiling
Every data subject affected by the processing of personal data has the right granted by the European legislator not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them, provided that the decision (1) is not necessary for entering into or performing a contract between the data subject and the controller, (2) is not authorised by Union or Member State law to which the controller is subject and which also lays down suitable measures to safeguard the data subject’s rights, freedoms and legitimate interests, or (3) is not based on the data subject’s explicit consent.
Where the decision (1) is necessary for entering into or performing a contract between the data subject and the controller, or (2) is based on the data subject’s explicit consent, widestripe shall implement suitable measures to safeguard the data subject’s rights, freedoms and legitimate interests, including at least the right to obtain human intervention on the part of the controller, to express their point of view and to contest the decision.
If the data subject wishes to exercise rights relating to automated decisions, they may contact an employee of the controller at any time.
i) Right to withdraw data protection consent
Every data subject affected by the processing of personal data has the right granted by the European legislator to withdraw their consent to the processing of personal data at any time.
If the data subject wishes to exercise their right to withdraw consent, they may contact an employee of the controller at any time.
14. Data protection provisions regarding the use of Instagram
The controller has integrated components of the Instagram service into this website. Instagram is a service that qualifies as an audiovisual platform and enables users to share photos and videos, as well as to redistribute such data on other social networks.
The operating company of Instagram is Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.
Each time an individual page of this website operated by the controller and containing an Instagram component (Instagram button) is accessed, the internet browser on the data subject’s IT system is automatically prompted by the respective Instagram component to download a display of the corresponding component from Instagram. As part of this technical process, Instagram becomes aware of which specific subpage of our website is visited by the data subject.
If the data subject is logged in to Instagram at the same time, Instagram recognises, each time the data subject accesses our website and throughout the duration of their stay on our website, which specific subpage of our website the data subject visits. This information is collected by the Instagram component and assigned by Instagram to the data subject’s respective Instagram account. If the data subject clicks one of the Instagram buttons integrated into our website, the data and information transmitted in this way are assigned to the data subject’s personal Instagram user account and stored and processed by Instagram.
Instagram always receives information through the Instagram component that the data subject has visited our website if the data subject is logged in to Instagram at the time of accessing our website; this takes place regardless of whether the data subject clicks the Instagram component. If the data subject does not wish this information to be transferred to Instagram, they can prevent the transfer by logging out of their Instagram account before accessing our website.
Further information and Instagram’s applicable privacy policy can be found at Instagram Help Centre and Instagram Privacy Policy.
15. Data protection provisions regarding the use of LinkedIn
The controller has integrated components of LinkedIn Corporation into this website. LinkedIn is an internet-based social network that enables users to connect with existing business contacts and make new business contacts. More than 400 million registered users use LinkedIn in over 200 countries. LinkedIn is currently the largest platform for business contacts and one of the most visited websites in the world.
The operating company of LinkedIn is LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA. For data protection matters outside the United States, LinkedIn Ireland, Privacy Policy Issues, Wilton Plaza, Wilton Place, Dublin 2, Ireland, is responsible.
Each time our website, which is equipped with a LinkedIn component (LinkedIn plug-in), is accessed, this component prompts the browser used by the data subject to download a corresponding display of the LinkedIn component. Further information about LinkedIn plug-ins is available at LinkedIn Developer Network. As part of this technical process, LinkedIn becomes aware of which specific subpage of our website is visited by the data subject.
If the data subject is logged in to LinkedIn at the same time, LinkedIn recognises, each time the data subject accesses our website and throughout the duration of their stay on our website, which specific subpage of our website the data subject visits. This information is collected by the LinkedIn component and assigned by LinkedIn to the data subject’s respective LinkedIn account. If the data subject clicks a LinkedIn button integrated into our website, LinkedIn assigns this information to the data subject’s personal LinkedIn user account and stores this personal data.
LinkedIn always receives information through the LinkedIn component that the data subject has visited our website if the data subject is logged in to LinkedIn at the time of accessing our website; this takes place regardless of whether the data subject clicks the LinkedIn component. If the data subject does not wish this information to be transferred to LinkedIn, they can prevent the transfer by logging out of their LinkedIn account before accessing our website.
LinkedIn provides options to unsubscribe from email messages, SMS messages and targeted advertising, as well as to manage advertising preferences, at LinkedIn Guest Controls. LinkedIn also uses partners such as Quantcast, Google Analytics, BlueKai, DoubleClick, Nielsen, Comscore, Eloqua and Lotame, which may set cookies. Such cookies can be rejected at LinkedIn Cookie Policy. LinkedIn’s applicable privacy policy is available at LinkedIn Privacy Policy.
16. Data protection provisions regarding the use of YouTube
The controller has integrated components of YouTube into this website. YouTube is an internet video portal that allows video publishers to upload video clips free of charge and enables other users to view, rate and comment on them free of charge. YouTube permits the publication of all types of videos, which is why complete films and television programmes, music videos, trailers and videos created by users themselves can be accessed through the internet portal.
The operating company of YouTube is Google Ireland Limited, Gordon House, Barrow Street, Dublin, D04 E5W5, Ireland.
Each time an individual page of this website operated by the controller and containing a YouTube component (YouTube video) is accessed, the internet browser on the data subject’s IT system is automatically prompted by the respective YouTube component to download a display of the corresponding YouTube component from YouTube. Further information about YouTube is available at About YouTube. As part of this technical process, YouTube and Google become aware of which specific subpage of our website is visited by the data subject.
If the data subject is logged in to YouTube at the same time, YouTube recognises which specific subpage of our website the data subject visits when accessing a subpage containing a YouTube video. This information is collected by YouTube and Google and assigned to the data subject’s respective YouTube account.
YouTube and Google always receive information through the YouTube component that the data subject has visited our website if the data subject is logged in to YouTube at the time of accessing our website; this takes place regardless of whether the data subject clicks a YouTube video. If the data subject does not wish this information to be transferred to YouTube and Google, they can prevent the transfer by logging out of their YouTube account before accessing our website.
The privacy policy published by YouTube, available at Google Privacy Policy, provides information about the collection, processing and use of personal data by YouTube and Google.
17. Payment method: data protection provisions regarding PayPal as a payment method
The controller has integrated PayPal components into this website. PayPal is an online payment service provider. Payments are processed through so-called PayPal accounts, which are virtual private or business accounts. PayPal also offers the option of processing virtual payments via credit cards if a user does not maintain a PayPal account. A PayPal account is managed through an email address, which is why there is no traditional account number. PayPal enables users to initiate online payments to third parties and receive payments. PayPal also performs trustee functions and offers buyer protection services.
PayPal’s European operating company is PayPal (Europe) S.à.r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg.
If the data subject selects “PayPal” as the payment option during the ordering process in our online shop, the data subject’s data will be automatically transmitted to PayPal. By selecting this payment option, the data subject consents to the transfer of personal data required for payment processing.
The personal data transmitted to PayPal generally includes first name, surname, address, email address, IP address, telephone number, mobile phone number or other data necessary for payment processing. Personal data required for the execution of the purchase agreement also includes data connected with the respective order.
The purpose of the transmission of data is payment processing and fraud prevention. The controller will transmit personal data to PayPal in particular where there is a legitimate interest in the transfer. Personal data exchanged between PayPal and the controller may be transmitted by PayPal to credit reference agencies. The purpose of this transmission is identity and creditworthiness checks.
PayPal may disclose personal data to affiliated companies, service providers or subcontractors where this is necessary to fulfil contractual obligations or where the data is to be processed on PayPal’s behalf.
The data subject may withdraw their consent to PayPal’s handling of personal data at any time. A withdrawal does not affect personal data that must necessarily be processed, used or transmitted for the contractual processing of payments.
PayPal’s applicable privacy policy can be found at PayPal Privacy Policy.
18. Payment method: data protection provisions regarding credit card payments
One or more online payment methods from the following provider are available in the online shop: Mollie B.V., Keizersgracht 313, 1016 EE Amsterdam, Netherlands.
If you select a payment method offered by the provider under which you make advance payment, such as payment by credit card, the payment data provided by you during the ordering process—including name, address, bank and card payment information, currency and transaction number—as well as information about the contents of your order, will be passed on to the provider in accordance with Article 6(1)(b) GDPR. In this case, your data will only be disclosed for the purpose of payment processing with the provider and only to the extent necessary for that purpose.
19. Legal basis for processing
Article 6(1)(a) GDPR serves as the legal basis for processing operations for which we obtain consent for a specific processing purpose. Where the processing of personal data is necessary for the performance of a contract to which the data subject is party, such as in processing operations required for the delivery of goods or the provision of any other service or consideration, processing is based on Article 6(1)(b) GDPR. The same applies to processing operations necessary to take pre-contractual measures, for example in the case of enquiries about our products or services.
Where our company is subject to a legal obligation requiring the processing of personal data, such as to fulfil tax obligations, processing is based on Article 6(1)(c) GDPR. In rare cases, the processing of personal data may be necessary to protect the vital interests of the data subject or another natural person. This would be the case, for example, if a visitor were injured at our premises and their name, age, health insurance details or other vital information had to be passed on to a doctor, hospital or other third party. Processing would then be based on Article 6(1)(d) GDPR.
Finally, processing operations may be based on Article 6(1)(f) GDPR. This legal basis applies to processing operations not covered by any of the aforementioned legal bases where processing is necessary for the purposes of the legitimate interests pursued by our company or a third party, except where such interests are overridden by the interests, fundamental rights and freedoms of the data subject. Such processing operations are permitted in particular because they have been specifically mentioned by the European legislator. In this respect, the legislator considered that a legitimate interest could be assumed where the data subject is a customer of the controller (Recital 47, sentence 2 GDPR).
20. Legitimate interests pursued by the controller or a third party
Where the processing of personal data is based on Article 6(1)(f) GDPR, our legitimate interest is to carry out our business activities for the benefit of all our employees and shareholders.
21. Period for which personal data is stored
The criterion for the duration of storage of personal data is the respective statutory retention period. After this period has expired, the relevant data is routinely deleted, provided it is no longer necessary for the performance or initiation of a contract.
22. Statutory or contractual requirements for providing personal data; necessity for entering into a contract; obligation of the data subject to provide personal data; possible consequences of failure to provide such data
We inform you that the provision of personal data is partly required by law, for example under tax regulations, or may also arise from contractual provisions, for example information about the contracting party. In some cases, entering into a contract may require a data subject to provide us with personal data that must subsequently be processed by us. For example, the data subject is obliged to provide us with personal data where our company enters into a contract with them. Failure to provide personal data would mean that the contract with the data subject could not be concluded.
Before providing personal data, the data subject must contact one of our employees. Our employee will explain to the data subject on a case-by-case basis whether the provision of personal data is required by law or contract, or is necessary for entering into a contract; whether there is an obligation to provide personal data; and what consequences would result from failure to provide personal data.
23. Existence of automated decision-making
As a responsible company, we do not use automated decision-making or profiling.
This Privacy Policy was created using the privacy policy generator of DGD Deutsche Gesellschaft für Datenschutz GmbH, which acts as an external data protection officer in the Upper Palatinate region, in cooperation with data protection lawyer Christian Solmecke.