Protecting your privacy when processing personal data is important to us. When you visit our website, our web servers automatically store the IP address of your Internet service provider, the website from which you visit us, the web pages you visit, and the date and duration of your visit. This information is essential for the technical transmission of the websites and secure server operation. This data is not evaluated for any specific purpose.
If you send us data via the contact form, this data will be stored on our servers as part of our data backup process. We will use your data solely to process your request. Your data will be treated with the strictest confidence. It will not be passed on to third parties. When you use one of our services, we generally only collect the data necessary to provide you with our service. We may ask you for additional information, but this is voluntary. Whenever we process personal data, we do so to provide you with our service or to pursue our commercial goals.
1. Who is responsible for data processing and who can you contact?
Person responsible
Brendan & Connor Kratz GbR
Gustav-Cords-Straße 7
50733 Cologne, Germany
Email: support@inhumane.de
2. Personal data
Personal data is information about you. This includes your name, address, and email address. You do not have to disclose any personal information to visit our website. In some cases, we require your name and address, as well as other information, in order to provide you with the requested service.
The same applies if we provide you with informational material upon request or if we respond to your inquiries. In these cases, we will always inform you. Furthermore, we only store the data that you have provided to us automatically or voluntarily.
When you use one of our services, we generally only collect the data necessary to provide our service to you. We may ask you for additional information, but this is voluntary. Whenever we process personal data, we do so to provide our service to you or to pursue our commercial goals.
3. Visiting the website
3.1 General use
When you visit our website, our web servers store the IP address of your Internet service provider, the website from which you visit us, the web pages you visit on our site, and the date and duration of your visit. Processing this information is essential for the technical transmission of the websites, the convenient use of our services, and secure server operation. Our legitimate interest arises from Art. 6 (1) (f) GDPR.
3.2 Automatically saved data
Server log files
The website provider automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These include:
- Date and time of the request
- Name of the requested file
- Page from which the file was requested
- Access status (file transferred, file not found, etc.)
- Web browser and operating system used
- Full IP address of the requesting computer
- Amount of data transferred
This data will not be merged with other data sources. Processing is carried out in accordance with Art. 6 (1) (f) GDPR based on our legitimate interest in improving the stability and functionality of our website.
For reasons of technical security, particularly to prevent attempted attacks on our web server, we store this data temporarily. It is not possible for us to identify individuals based on this data. After seven days at the latest, the data is anonymized by shortening the IP address at the domain level, making it impossible to establish a connection to the individual user. In anonymized form, the data is also processed for statistical purposes; it is not compared with other databases or shared with third parties, even in excerpts.
3.3 Contact
When you contact us (e.g., via contact form, email, telephone, or social media), the information provided by the person making the inquiry will be processed to the extent necessary to respond to the contact inquiries and any requested measures. Responding to contact inquiries within the framework of contractual or pre-contractual relationships is done to fulfill our contractual obligations or to respond to (pre-)contractual inquiries, and otherwise based on our legitimate interest in responding to the inquiries.
- Types of data processed: inventory data (e.g. names, addresses), contact data (e.g. e-mail, telephone numbers), content data (e.g. entries in online forms).
- Data subjects: communication partners.
- Purpose of processing : contact requests and communication.
- Legal basis: Contractual performance and pre-contractual inquiries (Art. 6 (1) (b) GDPR), legitimate interests (Art. 6 (1) (f) GDPR).
3.4 Cookies
When you visit our website, we may store information on your computer in the form of cookies. Many cookies contain a so-called cookie ID. A cookie ID is a unique identifier for the cookie. It consists of a character string that allows websites and servers to associate the specific internet browser in which the cookie was stored. This enables the visited websites and servers to distinguish the individual browser of the data subject from other internet browsers that contain other cookies. A specific internet browser can be recognized and identified via the unique cookie ID.
By using session cookies, the controller can provide users of this website with a user-friendly service that would not be possible without the setting of cookies. Without consent, we only use technically necessary cookies on the legal basis of legitimate interest pursuant to Art. 6 (1) (f) GDPR.
We only use personal cookies to improve our website or for marketing/advertising purposes with your consent. On your first visit, you can voluntarily consent to tracking or analysis via the cookie banner displayed. Your data may be shared with partners or third-party providers. These cookies will only be stored if you explicitly consent; the legal basis is your consent in accordance with Art. 6 (1) (a) GDPR. You can change your cookie settings at any time here: https://inhumane.de/pages/cookie-einstellungen
3.5 Consent Management
GDPR Legal Cookie
We use the consent management tool GDPR/DSGVO Legal Cookie from Pandectes OÜ, (Harju maakond, Kuusalu vald, Pudisoo küla, Männimäe/1, 74626, Estonia) on our website.
The tool enables you to grant consent to data processing via the website, in particular the use of cookies, as well as to exercise your right to withdraw consent previously granted. Data processing serves the purpose of obtaining and documenting required consent to data processing and thus complying with legal obligations. Cookies may be used for this purpose. The following information, among others, may be collected and transmitted to Pandectes: anonymized IP address, date and time of consent, URL from which the consent was sent, anonymous, random, encrypted key, consent status. This data will not be passed on to other third parties. Data processing is carried out to fulfill a legal obligation based on Art. 6 (1) (c) GDPR. Further information on Pandectes' terms of use and data protection can be found at: https://pandectes.io/privacy-policy/ and at https://pandectes.io/regulations/gdpr/
4. Service optimization
4.1 Platform
Shopify
We host our website with Shopify International Limited, Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland (hereinafter "Shopify"). Shopify is a tool for creating and hosting websites. When you visit our website, Shopify collects your IP address, as well as information about the device you are using and your browser. Shopify is also used to analyze visitor numbers, visitor sources, and customer behavior, as well as to compile user statistics. When you make a purchase on our website, Shopify also collects your name, email address, shipping and billing addresses, payment details, and other data related to the purchase (e.g., phone number, H amount of sales made , etc. ). Shopify stores cookies in your browser for analysis purposes .
For details, please see Shopify's privacy policy: https://www.shopify.de/legal/datenschutz
The use of Shopify is based on Art. 6 (1) (f) GDPR. We have a legitimate interest in presenting our website as reliably as possible. If consent has been requested, processing will be carried out exclusively on the basis of Art. 6 (1) (a) GDPR and Section 25 (1) TDDDG applies, provided that the consent covers the storage of cookies or access to information on the user's terminal device (e.g., device fingerprinting) within the meaning of the TDDDG. Consent can be revoked at any time.
We have concluded a data processing agreement (DPA) pursuant to Art. 28 GDPR with the above-mentioned provider. This is a contract required by data protection law that guarantees that the provider will only process the personal data of our website visitors in accordance with our instructions and in compliance with the GDPR.
Google Tag Manager
We use Google Tag Manager, provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Google Tag Manager is a tool that allows us to integrate tracking or statistical tools and other technologies on our website. Google Tag Manager itself does not create user profiles, stores cookies, or perform independent analyses. It is used solely to manage and display the tools integrated through it. However, Google Tag Manager records your IP address, which may also be transmitted to Google's parent company in the United States.
The use of Google Tag Manager is based on Art. 6 (1) (f) GDPR.
4.2 Data processing for order processing
4.3 Newsletter
On our website we offer the option of signing up for our newsletter. After registration, we will regularly inform you about news via email. Furthermore, after a certain period of time you will be reminded by email of the items you have placed in your shopping cart and whose order you had to interrupt or whose purchase you were unable to complete. A valid email address is required to register for the newsletter. To verify your email address, you will first receive a registration email, which you must confirm via the link. If you subscribe to the newsletter on our website, we process personal data such as your email address based on your consent. The legal basis for the processing is Art. 6 (1) (a) GDPR. You can unsubscribe from our newsletter at any time, for example by contacting us via the corresponding link in the email you received or by writing an email to support@inhumane.de.
Klaviyo
This website uses the services of Klaviyo to send newsletters. The provider is Klaviyo, 225 Franklin St, Boston, MA 02110, USA.
Klaviyo is a service that, among other things, can be used to organize and analyze the distribution of newsletters. If you enter data for the purpose of subscribing to the newsletter (e.g., email address), this data will be stored on Klaviyo's servers in the USA.
With the help of Klaviyo, we can analyze our newsletter campaigns. When you open an email sent with Klaviyo, a file contained in the email (a so-called web beacon) connects to Klaviyo's servers in the USA. This allows us to determine whether a newsletter message has been opened and, if applicable, which links have been clicked. Technical information is also recorded (e.g., time of retrieval, IP address, browser type, and operating system). This information cannot be assigned to the respective newsletter recipient. It is used exclusively for the statistical analysis of newsletter campaigns. The results of these analyses can be used to better tailor future newsletters to the interests of the recipients.
If you do not want Klaviyo to analyze your data, you must unsubscribe from the newsletter. We provide a link for this purpose in every newsletter message. Data processing is based on your consent (Art. 6 (1) (a) GDPR). You can revoke this consent at any time by unsubscribing from the newsletter. The legality of the data processing operations already carried out remains unaffected by the revocation.
The data you provide us with for the purpose of subscribing to the newsletter will be stored by us or the newsletter service provider until you unsubscribe from the newsletter. Once you unsubscribe from the newsletter, the data will be deleted from the newsletter distribution list. Data stored by us for other purposes remains unaffected.
Data transfer to the USA is based on the EU Commission's standard contractual clauses. Details can be found here: https://www.klaviyo.com/legal/dpa
After you unsubscribe from the newsletter distribution list, your email address may be stored on a blacklist by us or the newsletter service provider if this is necessary to prevent future mailings. The data from the blacklist will be used only for this purpose and will not be merged with other data. This serves both your interest and our interest in complying with legal requirements when sending newsletters (legitimate interest within the meaning of Art. 6 (1) (f) GDPR). Storage on the blacklist is not time-limited. You can object to storage if your interests outweigh our legitimate interest.
For more information, please see Klaviyo’s privacy policy at:
https://www.klaviyo.com/legal/privacy-notice
We have concluded a data processing agreement (DPA) pursuant to Art. 28 GDPR with the above-mentioned provider. This is a contract required by data protection law that guarantees that the provider will only process the personal data of our website visitors in accordance with our instructions and in compliance with the GDPR.
5. Tools and services for analysis, statistics and marketing
5.1 Analysis and statistics
Google Analytics (4)
This website uses features of the web analysis service Google Analytics. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
Google Analytics enables website operators to analyze the behavior of website visitors. This provides the website operator with various usage data, such as page views, length of stay, operating systems used, and user origin. This data is summarized in a user ID and assigned to the respective device of the website visitor.
Furthermore, Google Analytics allows us to record your mouse and scroll movements, clicks, and more. Furthermore, Google Analytics uses various modeling approaches to supplement the collected data sets and employs machine learning technologies for data analysis.
Google Analytics uses technologies that enable user recognition for the purpose of analyzing user behavior (e.g., cookies or device fingerprinting). The information collected by Google about the use of this website is generally transferred to a Google server in the USA and stored there. The use of this service is based on your consent in accordance with Art. 6 (1) (a) GDPR and Section 25 (1) TDDDG. This consent can be revoked at any time.
Data transfer to the USA is based on the EU Commission's standard contractual clauses. Details can be found here: https://privacy.google.com/businesses/controllerterms/mccs/
For the United States, the European Commission has issued an adequacy decision, provided that companies are certified under the Data Privacy Framework program. Google is certified accordingly and thus meets the EU Commission's requirements.
Google Signals
We use Google Signals. When you visit our website, Google Analytics records, among other things, your location, search history, YouTube history, and demographic data (visitor data). This data can be used for personalized advertising with the help of Google Signal. If you have a Google Account, Google Signal's visitor data is linked to your Google Account and used for personalized advertising messages. The data is also used to compile anonymized statistics on our users' behavior.
Google Analytics E-Commerce Measurement
This website uses the "E-Commerce Measurement" feature of Google Analytics. E-Commerce Measurement allows the website operator to analyze the purchasing behavior of website visitors to improve their online marketing campaigns. Information such as orders placed, average order values, shipping costs, and the time from viewing to purchasing a product is collected. Google can aggregate this data under a transaction ID that is assigned to the respective user or their device.
5.2 Advertising and Marketing
Facebook Custom Audiences
We use Facebook Custom Audiences. This service is provided by Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland.
When you visit or use our websites and apps, take advantage of our free or paid offers, transmit data to us, or interact with our company's Facebook content, we collect your personal data. If you give us your consent to use Facebook Custom Audiences, we will transmit this data to Facebook, which Facebook can use to display relevant advertising to you. Furthermore, your data can be used to define target groups (lookalike audiences).
Facebook processes this data as our data processor. Details can be found in Facebook's user agreement:
https://www.facebook.com/legal/terms/customaudience
The use of this service is based on your consent in accordance with Art. 6 (1) (a) GDPR and Art. 25 (1) TDDDG. This consent can be revoked at any time.
Data transfer to the USA is based on the EU Commission's standard contractual clauses. Facebook is also certified according to the Data Privacy Framework.
Details can be found here:
https://www.facebook.com/legal/terms/customaudience
https://www.facebook.com/legal/terms/dataprocessing
Google Ads Customer Match
We use Google Ads Customer Match lists as part of our Google advertising activities. To use Customer Match, lists containing encrypted user data (e.g., names, email addresses, addresses, customer-specific identifiers) are uploaded to Google. Google then compares whether the submitted user data matches existing Google customers. This data can then be used to create target groups that can be used to target ads/campaigns. After the Customer Match lists are created, the encrypted customer data is automatically deleted. This prevents providers from obtaining new addresses.
The recipient of the data is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google LLC, based in California, USA, and possibly US authorities may access the data stored by Google.
The use of this service is based on your consent in accordance with Art. 6 (1) (a) GDPR and Art. 25 (1) TDDDG. This consent can be revoked at any time. Data transfer to the USA is based on the EU Commission's standard contractual clauses. Details can be found here:
https://policies.google.com/privacy/frameworks
https://privacy.google.com/businesses/controllerterms/mccs/
Pinterest Ads
This website uses Pinterest Ads, a marketing service provided by Pinterest Inc., 651 Brannan Street, San Francisco, CA, 94107, USA
This allows website users to be shown interest-based advertisements ("Pinterest ads") when they visit the Pinterest network or other websites that also use the process. Pinterest ads placed by us are intended to be shown only to users who have shown an interest in our offerings or who have certain characteristics/interests transmitted by us to Pinterest (so-called "ActALike Audiences"). In addition, the use of the Pinterest tag serves statistical and market research purposes, as it gives us the opportunity to track whether a user was redirected to our website after clicking on a Pinterest ad (so-called "conversion"). In doing so, we pursue the interest of showing you advertising that is of interest to you in order to make our website more interesting for you. Furthermore, the use serves the purpose of market research.
When you visit our website, the Pinterest tag will save a so-called cookie on your device (see also "Cookies" above in this privacy policy). If you subsequently log in to Pinterest or visit Pinterest while logged in, your visit to our website will be recorded in your profile.
The data collected by “Pinterest” does not allow us to draw any conclusions about your identity.
If a corresponding consent has been requested, the processing will be carried out exclusively on
Basis of Art. 6 (1) (a) GDPR and Section 25 (1) TDDDG applies, provided that the consent covers the storage of cookies or access to information on the user's terminal device (e.g., device fingerprinting) within the meaning of the TDDDG. Consent can be revoked at any time.
For more information about data processing by Pinterest, please visit
https://policy.pinterest.com/en/privacy-policy
5.3 Social Media and Communication
Instagram plugin
This website incorporates features of the Instagram service. These features are offered by Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.
If you are logged into your Instagram account, you can link the content of this website to your Instagram profile by clicking the Instagram button. This allows Instagram to associate your visit to this website with your user account. We would like to point out that, as the provider of these pages, we have no knowledge of the content of the transmitted data or how it is used by Instagram.
Since a corresponding consent was requested, the processing is carried out exclusively on the basis of Art. 6 (1) (a) GDPR and Section 25 (1) TDDDG applies, provided that the consent covers the storage of cookies or access to information on the user's terminal device (e.g., device fingerprinting) within the meaning of the TDDDG. Consent can be revoked at any time.
To the extent that personal data is collected on our website using the tool described here and forwarded to Facebook or Instagram, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland are jointly responsible for this data processing (Art. 26 GDPR). Joint responsibility is limited exclusively to the collection of the data and its forwarding to Facebook or Instagram. Any processing carried out by Facebook or Instagram after forwarding is not part of the joint responsibility. Our joint obligations have been set out in a joint processing agreement. The wording of the agreement can be found at: https://www.facebook.com/legal/controller_addendum
According to this agreement, we are responsible for providing data protection information when using the Facebook or Instagram tool and for implementing the tool on our website in compliance with data protection law. Facebook is responsible for the data security of Facebook or Instagram products. You can assert your data subject rights (e.g., requests for information) regarding the data processed by Facebook or Instagram directly with Facebook. If you assert your data subject rights with us, we are obligated to forward them to Facebook.
Data transfer to the USA is based on the EU Commission’s standard contractual clauses.
Details can be found here:
https://www.facebook.com/legal/EU_data_transfer_addendum
https://help.instagram.com/519522125107875
https://de-de.facebook.com/help/566994660333381
Meta is also certified according to the Data Privacy Framework.
For more information, please see Instagram’s privacy policy:
https://instagram.com/about/legal/privacy/ .
6. Customer account
Contractual partners can create an account within our online offering (e.g., a customer or user account, referred to as "customer account"). If registration of a customer account is required, contractual partners will be informed of this, as well as the information required for registration. Customer accounts are not public and cannot be indexed by search engines. During registration, as well as subsequent logins and use of the customer account, we store the customers' IP addresses along with the access times in order to verify registration and prevent any misuse of the customer account.
Once customers have canceled their customer account, the data relating to the customer account will be deleted, unless retention is required for legal reasons. It is the customer's responsibility to back up their data after the customer account has been canceled. The legal basis for data processing is therefore Art. 6 (1) (b) GDPR.
6.1 Shop and e-commerce
We process our customers' data to enable them to select, purchase, or order the selected products, goods, and related services, as well as to pay for and deliver them or execute them. If necessary to execute an order, we use service providers, in particular postal, forwarding, and shipping companies, to carry out the delivery or execution for our customers. We use the services of banks and payment service providers to process payment transactions. The required information is marked as such within the order or similar purchase process and includes the information needed for delivery, provision, and billing, as well as contact information for any follow-up questions.
- Types of data processed: Inventory data (e.g. names, addresses), payment data (e.g. bank details, invoices, payment history), contact data (e.g. e-mail, telephone numbers), contract data (e.g. subject of the contract, term, customer category), usage data (e.g. websites visited, interest in content, access times), meta/communication data (e.g. device information, IP addresses).
- Data subjects : interested parties, business and contractual partners, customers.
- Purposes of processing: Provision of contractual services and customer service, contact requests and communication, office and organizational procedures, administration and response to inquiries, security measures, conversion measurement (measurement of the effectiveness of marketing measures), interest-based and behavioral marketing, profiling (creation of user profiles).
- Legal basis: Contractual performance and pre-contractual inquiries (Art. 6 (1) (b) GDPR), legal obligation (Art. 6 (1) (c) GDPR), legitimate interests (Art. 6 (1) (f) GDPR).
6.2 Economic analyses and market research
For business reasons and in order to be able to identify market trends and the wishes of contractual partners and users, we analyze the data available to us on business transactions, contracts, inquiries, etc., whereby the group of data subjects may include contractual partners, interested parties, customers, visitors and users of our online offering.
The analyses are carried out for the purposes of business evaluations, marketing, and market research (e.g., to identify customer groups with different characteristics). We may, where available, consider the profiles of registered users, including their information, e.g., regarding services used. The analyses serve our sole purpose and are not disclosed externally, unless they are anonymous analyses with aggregated, i.e., anonymized values. Furthermore, we respect the privacy of users and process the data for analysis purposes pseudonymously wherever possible and, where feasible, anonymously (e.g., as aggregated data).
6.3 Processing of personal data for advertising purposes
Unless you have opted out, we will use the email address you provided when purchasing goods or services to electronically send you advertisements for our own goods or services similar to those you have previously purchased or used from us. We will use your email address, name, and order history to send you information about products that may be of interest to you based on your recent orders.
The legal basis for data processing is Art. 6 (1) (f) GDPR and Section 7 (3) UWG (German Unfair Competition Act). You can object to this processing at any time in accordance with Art. 21 (2) GDPR, for example, by contacting us via the corresponding link in the email you received or by sending an email to support@inhumane.de.
6.4 Trustpilot review requests
We participate in the rating process of the provider Trustpilot A/S, Pilestræde 58, 5, 1112 Copenhagen, Denmark.
If you have ordered a product from our store, we will contact you by email to ask about your satisfaction with your order and the products, unless you have previously objected. We will use the email address you provided to send you this request. We will also process your name, your IP address, the IP geolocation used, and information about your order. The customer satisfaction survey and the described data processing are based on the legal basis of Section 7 (3) of the German Unfair Competition Act (UWG) in conjunction with Article 6 (1) (f) of the GDPR. This processing serves the purpose of direct advertising.
You can object to the processing and in particular the use of your e-mail address for this purpose at any time in accordance with Art. 21 (2) GDPR by using the objection option in our e-mails or by e-mail to the e-mail address provided in our imprint, without incurring any costs other than the transmission costs according to the basic rates.
Users can find further information about the processing of their data by Trustpilot as well as their rights of objection and other data subject rights in Trustpilot's privacy policy: de.legal.trustpilot.com/end-user-privacy-terms.
6.5 Payment service providers
Within the framework of contractual and other legal relationships, due to legal obligations or otherwise on the basis of our legitimate interests, we offer the data subjects efficient and secure payment options and, in addition to banks and credit institutions, we use other payment service providers (collectively "payment service providers").
The data processed by the payment service providers includes inventory data such as name and address, bank details such as account numbers or credit card numbers, passwords, TANs and checksums as well as contract, amount and recipient-related information. This information is required to carry out the transactions. However, the data entered is only processed and stored by the payment service providers. This means that we do not receive any account- or credit card-related information, but only information confirming or rejecting the payment. Under certain circumstances, the payment service providers will transmit the data to credit agencies. This transmission is for the purpose of identity and credit checks. For more information, please refer to the terms and conditions and the privacy policy of the payment service providers.
Payment transactions are subject to the terms and conditions and privacy policy of the respective payment service providers, which are available on the respective websites or transaction applications. We also refer to these for further information and to assert your rights of withdrawal, information, and other data subjects.
6.6 Transport service providers
For the purpose of delivering ordered goods, we work with logistics service providers/transport companies and/or shipping partners to whom the following data is transmitted for the purpose of delivering the ordered goods or for the purpose of notifying the shipment: first name, last name, postal address, and, if applicable, the email address and telephone number. The legal basis for processing is Art. 6 (1) (b) GDPR.
7. Online presence on social media
If you have given your consent to this in accordance with Art. 6 (1) (a) GDPR to the respective social media operator, when you visit our online presence on our social media channels your data will be automatically collected and stored for market research and advertising purposes, from which user profiles will be created using pseudonyms. These can be used, for example, to place advertisements within and outside the platforms that presumably correspond to your interests. Cookies are generally used for this purpose. Detailed information on the processing and use of data by the respective social media operator as well as a contact option and your related rights and setting options to protect your privacy can be found in the respective data protection notices linked to the providers' websites. If you still need help in this regard, you can contact us.
8. Security
We have taken technical and administrative security measures to protect your personal data against loss, destruction, manipulation, and unauthorized access. All our employees and service providers are obligated to comply with applicable data protection laws.
Whenever we collect and process personal data, it is encrypted before transmission. This means your data cannot be misused by third parties. Our security measures are subject to continuous improvement, and our privacy policies are constantly being revised. Please ensure you have the most up-to-date version.
9. What data is processed and from which sources does this data come?
We process the data that we have received from you in the context of initiating or processing a contract, based on consent or as part of your application to us or as part of your employment with us.
Personal data includes:
Your master/contact data, for customers this includes e.g. first and last name, address, contact details (email address, telephone number, fax), bank details.
For competition participants, this includes first and last name, email address, and postal address.
For what purposes and on what legal basis is the data processed?
We process your data in accordance with the provisions of the General Data Protection Regulation (GDPR) and the Federal Data Protection Act 2018 in its currently valid version:
- To fulfill (pre-)contractual obligations (Article 6 (1) (b) GDPR): Your data is processed online for contract processing. The data is processed in particular when initiating business transactions and when executing contracts with you.
- to fulfill legal obligations (Article 6 (1) (c) GDPR): Processing of your data is necessary for the purpose of fulfilling various legal obligations, e.g. from the Commercial Code or the Tax Code.
- To protect legitimate interests (Article 6 (1) (f) GDPR): Based on a balancing of interests, data processing may be carried out beyond the actual fulfillment of the contract to protect the legitimate interests of us or third parties. Data processing to protect legitimate interests occurs, for example, in the following cases:
- Advertising or marketing
- Measures for business management and further development of services and products;
- in the context of legal proceedings
- within the scope of your consent (Art. 6 para. 1 lit. a GDPR):
If you have given us your consent to process your data, e.g. to send you our newsletter, publish photos, etc.
Who receives my data?
If we use a service provider for contract processing, we remain responsible for protecting your data. All contract processors are contractually obligated to treat your data confidentially and to process it only within the scope of providing the service. The contract processors we commission will receive your data if they need it to perform their respective services. These include, for example, IT service providers we need for the operation and security of our IT system, as well as advertising and address publishers for our own advertising campaigns.
If there is a legal obligation or in the context of legal proceedings, authorities, courts and external auditors may be recipients of your data.
In addition, insurance companies, banks, credit agencies and service providers may be recipients of your data for the purpose of initiating and fulfilling contracts.
How long will my data be stored?
We will process your data until the end of the business relationship or until the expiry of the applicable statutory retention periods (e.g., those stipulated in the German Commercial Code, the Tax Code, or the Working Hours Act); and furthermore, until the end of any legal disputes in which the data is required as evidence.
Unless there is a statutory retention period, your data will be deleted after the purpose has expired. If the processing is based on consent, it will be processed until you revoke your consent.
10. What data protection rights do I have?
You have the right to information, correction, deletion or restriction of the processing of your stored data at any time, the right to object to the processing as well as the right to data portability and to lodge a complaint in accordance with the requirements of data protection law.
Right to information:
You can request information from us as to whether and to what extent we process your data.
Right to rectification:
If we process your data that is incomplete or incorrect, you can request that we correct or complete it at any time.
Right to erasure:
You can request that we delete your data if we process it unlawfully or if the processing disproportionately interferes with your legitimate interests. Please note that there may be reasons that prevent immediate deletion, e.g., in the case of statutory retention periods.
Regardless of whether you exercise your right to erasure, we will delete your data immediately and completely, unless there is a contractual or statutory obligation to retain it.
Right to restriction of processing:
You can request that we restrict the processing of your data if
- You contest the accuracy of the data for a period enabling us to verify the accuracy of the data.
- the processing of the data is unlawful, but you refuse to delete it and instead request a restriction of data use,
- we no longer need the data for the intended purpose, but you still need this data to assert or defend legal claims, or
- You have objected to the processing of your data.
Right to data portability:
You can request that we provide you with the data you have provided to us in a structured, common and machine-readable format and that you can transmit this data to another controller without hindrance from us, provided that
- we process this data on the basis of your consent, which can be revoked, or to fulfil a contract between us, and
- this processing is carried out using automated procedures.
If technically feasible, you can request that we transmit your data directly to another controller.
Right of objection:
If we process your data based on legitimate interests, you can object to this data processing at any time; this would also apply to profiling based on these provisions. We will then no longer process your data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or unless the processing serves to assert, exercise, or defend legal claims. You can object to the processing of your data for direct marketing purposes at any time without giving reasons.
Right to complain:
If you believe that we are violating German or European data protection law in the processing of your data, please contact us so that we can clarify any questions. You also have the right to contact the supervisory authority responsible for you, the relevant state data protection authority.
If you wish to exercise any of the aforementioned rights, please contact our data protection officer. If in doubt, we may request additional information to confirm your identity.
Am I obliged to provide data?
The processing of your data is necessary to conclude or fulfill the contract you have entered into with us. If you do not provide us with this data, we will generally have to refuse to conclude the contract or will no longer be able to perform an existing contract and will therefore have to terminate it. However, you are not obligated to consent to data processing that is not relevant for the fulfillment of the contract or is not required by law.
11. Changes to this Privacy Policy
We reserve the right to change our privacy policies as new technologies require. Please ensure you have the most recent version. If we make material changes to this privacy policy, we will post them on our website.