DATA PROTECTION NOTICE

Dear User,

Thank you for your interest in our online presence. Your trust, the protection of your data, and your satisfaction are very important to us. Therefore, we kindly ask you to carefully read the following data protection notice, where we aim to inform you about how we protect your personal data.

1. GENERAL INFORMATION

GfDDE – Gesellschaft für Datenschutz und Datensicherheit in Europa GmbH operates this website and takes the protection of your personal data very seriously. Your personal data is handled confidentially and in accordance with statutory provisions. Regarding the terms used in this notice, such as “processing,” “controller,” or “consent,” we refer to the definitions provided in the General Data Protection Regulation (GDPR).

The following data protection notice is intended to inform you about the nature, scope, and purposes of processing your personal data (hereinafter referred to as “data”) within our online offering (hereinafter referred to as “online offering”). We also aim to inform you about your rights.

Using our online offering is generally possible without providing any personal data. However, we would like to point out that processing personal data may become necessary when you wish to utilize certain services through our website.

As the entity responsible for data processing, we have implemented numerous technical and organizational measures to ensure the most comprehensive protection of personal data processed via this website. However, internet-based data transmissions can always be subject to security vulnerabilities, meaning absolute protection cannot be guaranteed even with all measures in place. For this reason, you are, of course, free to transmit any necessary personal data to us via alternative means, such as by telephone.

Data Processing Controller

The controller for data processing under the GDPR and BDSG is:
GfDDE – Gesellschaft für Datenschutz und Datensicherheit in Europa GmbH
Unterer Schellberg 7
65812 Bad Soden/Ts.
Phone +49 (0) 174 9894140
Email:
info@gfdde.de
Website:
gfdde.de

You can contact the Data Protection Officer by emailing the above address with the subject line Data protection.

2. OVERVIEW OF PROCESSING AND RELEVANT LEGAL BASES

Below is an overview of the types of data processed, the categories of individuals affected, and the purposes of processing:

2.1 Data Processed / Categories of Data

We process the following categories of personal data: Basic data (e.g., first name, last name, email address, job title, company/employer), Usage data, Registration data, Meta and communication data

2.2 Purposes of Data Processing

The purposes of data processing include: Providing access to our online offering, Conducting direct marketing, Delivering contractual services and pre-contractual measures, Performing security measures, Responding to inquiries, Measuring reach and improving user-friendliness of our online offering.

2.3 Categories of Individuals Affected

The following groups of people are affected by data processing on our website: Customers, Clients, Interested parties, Communication partners, Users, Business and contractual partners.

2.4 Relevant Legal Bases

The processing of personal data, such as contact, usage, contractual, meta, or communication data, is conducted solely in accordance with the requirements of the GDPR, the Federal Data Protection Act (BDSG), and, where applicable, other specific data protection regulations.

Generally, we process your data based on the following legal bases:

  • Consent of the data subject under Art. 6 (1) Sentence 1 lit. a and Art. 7 GDPR
  • Fulfillment of our contractual obligations and pre-contractual measures (including responding to inquiries) under Art. 6 (1) Sentence 1 lit. b GDPR
  • Fulfillment of our legal obligations under Art. 6 (1) Sentence 1 lit. c GDPR
  • Necessity to safeguard our legitimate interests under Art. 6 (1) Sentence 1 lit. f GDPR

In addition to the GDPR, the BDSG applies, containing specific provisions regarding the rights of data subjects (e.g., rights to information, deletion, and objection) and the processing of special categories of personal data or data processing for other purposes. The provisions of the TDDG (Telecommunications-Telemedia Data Protection Act) also apply, particularly concerning the storage of information on your devices.

2.5 Security Measures

In accordance with legal requirements and considering the state of the art, implementation costs, nature, scope, circumstances, and purposes of processing, as well as the different likelihoods and severity of risks to the rights and freedoms of individuals, we take appropriate technical and organizational measures to ensure a level of protection appropriate to the risk.

These measures include safeguarding the confidentiality, integrity, and availability of data by controlling physical and electronic access to the data, as well as access rights, input, transmission, availability, and separation of data. We have also implemented procedures to ensure the exercise of data subject rights, data deletion, and responses to data threats. We integrate data protection into the development and selection of hardware, software, and processes based on the principle of data protection by design and default.

To protect the data transmitted via our online offering, we use SSL encryption. You can recognize such encrypted connections by the prefix "https://" in your browser's address bar. We have also implemented additional security measures such as a Referrer Policy and a Content Security Policy.

2.6 Data Recipients / Categories of Recipients, Data Transfers

We may transmit your personal data to other parties, companies, legally independent organizational units, or individuals in the course of processing, or disclose your data to them. Recipients of this data may include IT service providers, event managers, or service providers that embed content on a website. In such cases, we adhere to legal requirements and conclude agreements to protect your data with these recipients. Within our company, only individuals and departments that need your data to fulfill their tasks will have access to it.

If, in the course of our processing, we disclose data to other persons or companies (processors or third parties), transfer it to them, or otherwise grant them access to the data, this will only occur based on a legal authorization (e.g., if the transfer of data to third parties is necessary for contract fulfillment under Art. 6 (1) Sentence 1 lit. b GDPR), your consent, a legal obligation, or based on our legitimate interests (e.g., when engaging agents, web hosts, etc.).

Our website may include external links to third-party websites. Please note that we are not responsible for the operation of these websites, including the data processing that occurs in connection with visiting these sites. If you click on one of these links, you may send information to or through these third-party websites to the operator and the services they use. Therefore, we recommend that you review the privacy notices of these websites in advance before visiting them, as you may provide information about yourself that can be personally attributed to you.

2.7 Transfer of Personal Data to Third Countries

A transfer of your personal data to third countries or international organizations is not planned. However, should such processing occur, it will be in compliance with legal requirements, including processing in countries with recognized data protection levels or through EU standard contractual clauses.

Subject to your explicit consent or if contractually or legally required, we process or allow data to be processed only in third countries with a recognized level of data protection. This occurs under the condition of compliance with contractual obligations through so-called standard contractual clauses of the EU Commission, or in the presence of certifications or binding internal data protection regulations.

As part of the so-called "Data Privacy Framework" (DPF), the EU Commission has also recognized the data protection level as secure for certain companies from the USA. The list of certified companies and further information about the DPF can be found on the U.S. Department of Commerce website at https://www.dataprivacyframework.gov .

2.8 Retention, Deletion, and Blocking of Data

We adhere to the principle of data minimization. The data we process is deleted in accordance with legal regulations as soon as you revoke your consent to the processing or other legal permissions cease to apply. If the data is not deleted because it is required for other legally permissible purposes, its processing will be restricted to those purposes. This means the data will be locked and not processed for other purposes. This applies, for example, to data that must be retained for commercial or tax-related reasons or whose storage is necessary for asserting, exercising, or defending legal claims or for protecting the rights of another natural or legal person. In Germany, retention is specifically governed by legal requirements, including 6 years under Section 257(1) of the German Commercial Code (HGB) and 10 years under Section 147(1) of the German Fiscal Code (AO).

3. INDIVIDUAL PROCESSES

We process data from our contractual and business partners, customers, clients, and prospects as explained above in the context of performing pre-contractual measures or contractual relationships and related activities, as well as in the communication with contracting parties, for example, in response to inquiries directed at us. Furthermore, we process your data to protect our rights and for administrative tasks associated with these duties and business organization. In addition, we process the data based on our legitimate interests in proper and economic business management and security measures to protect our contract partners and business operations from misuse, threats to their data, secrets, information, and rights (e.g., involving telecommunications, transport, and other auxiliary services as well as subcontractors, banks, tax and legal advisors, payment service providers, or financial authorities). In accordance with applicable law, we only disclose the data of contract partners to third parties to the extent necessary for the aforementioned purposes or to fulfill legal obligations. Other forms of processing, e.g., for marketing purposes, will be communicated to the contract partners as part of this privacy policy.

We inform the contract partners before or during data collection, for example, in online forms, through symbols (e.g., asterisks, etc.), or personally, which data is required for the aforementioned purposes. If we use third-party providers or platforms to provide our services, the terms and conditions and privacy notices of the respective third-party providers or platforms apply in the relationship between users and providers.

3.1 Hosting

To provide our online offer securely and efficiently, we use the services of web hosting providers, from whose servers (or managed servers) the online offer can be accessed. For this purpose, we may use infrastructure and platform services, computing capacity, storage space, database services, security services, and technical maintenance services, which we use for the operation of this website. In this process, we, or our hosting provider, process master data, contact data, content data, contract data, usage data, meta- and communication data from customers, prospects, and visitors of this online offer to pursue our legitimate interests in efficiently and securely providing this offer in accordance with Art. 6 Para. 1 S. 1 lit. f GDPR.

  • Types of processed data: content data (e.g., entries in online forms); usage data (e.g., visited websites, interest in content, access times); meta/communication data (e.g., retrieval information, IP addresses).
  • Affected persons: users (e.g., website visitors, users of online services).
  • Purpose of processing: providing our online offer and user-friendliness.
  • Legal basis: legitimate interests (Art. 6 Para. 1 S. 1 lit. f GDPR), your consent (Art. 6 Para. 1 S. 1 lit. a GDPR).

The provider we use is Mittwald CM Service GmbH & Co. KG, Königsberger Str. 4-6, 32339 Espelkamp. Information about data protection can be found here: https://www.mittwald.de/datenschutz.

3.2 Collection of Access Data

With every access to our website, our website collects a series of general data and information to pursue our legitimate interests according to Art. 6 Para. 1 S. 1 lit. f GDPR. This general data and information is stored in the server's log files. The data collected includes (1) the types and versions of browsers used, (2) the operating system used by the accessing system, (3) the date and time of access to the website, (4) the IP address, (5) the Internet service provider of the accessing system, (6) protocols, status codes, and data volume; (7) directory protection users, and (8) other similar data and information that serve to prevent hazards in the event of attacks on our IT systems.

When using this general data and information, no conclusions about the affected person are drawn. This information is needed to (1) deliver the content of our website correctly, (2) optimize the content of our website and the advertising for it, (3) ensure the permanent functionality of our IT systems and the technology of our website, (4) enable responses to contact inquiries and communication with users, and (5) provide law enforcement authorities with the necessary information for prosecution in the event of an attack. These anonymized data and information are statistically analyzed to improve data protection and data security, ensuring the highest level of protection for the personal data we process. The anonymous data in the server log files are stored separately from all personal data provided by the affected person.

3.3 Use of Web Analysis Tools

We do not use web analysis or tracking tools on our website.

4. RIGHTS OF THE AFFECTED PERSON

The GDPR provides a series of rights for data subjects, which we would like to inform you about below.

4.1 Right to Confirmation

You have the right to request a statement as to whether personal data concerning you is being processed. To exercise this right, please contact our above-mentioned data protection officer.

4.2 Right to Access

You also have the right to receive free information about the personal data stored about you, as well as further information and a copy of the data in accordance with Art. 15 GDPR. Furthermore, you have the right to obtain information about the following:

  • the purposes ofprocessing
  • the categories of personal data being processed
  • the recipients or categories of recipients to whom the personal data has been or will be disclosed, particularly if recipients are in third countries or international organizations
  • if possible, the planned duration, for which the personal data will be stored, or, if this is not possible, the criteria used to determine that duration
  • the existence of the right to rectification or erasure of personal data concerning you, or the right to restriction of processing or opposition to such processing
  • the existence of the right to lodge a complaint with a supervisory authority
  • if the personal data was not collected from you as the data subject: all available information about the source of the data
  • the existence of automated decision-making, including profiling according to Art. 22 Para. 1 and 4 GDPR, and — at least in these cases — meaningful information about the logic involved, as well as the significance and consequences of such processing for the data subject.

You also have the right to inquire whether personal data has been transferred to a third country or to an international organization. If this is the case, you have the right to obtain information about the appropriate safeguards related to the transfer. To exercise your right of access, please contact our above-mentioned data protection officer.

4.3 Right to Rectification

Under Art. 16 GDPR, you have the right to request the completion or rectification of personal data concerning you. Furthermore, you have the right, taking into account the purposes of the processing, to request the completion of incomplete personal data. If you wish to exercise this right of rectification, please contact our above-mentioned data protection officer.

4.4 Right to Erasure (Right to be Forgotten)

In accordance with Art. 17 GDPR, you also have the right to request that personal data concerning you be erased immediately, or alternatively, under the conditions of Art. 18 GDPR, to request the restriction of processing if one of the following reasons applies and processing is not necessary:

  • The personal data was collected or otherwise processed for purposes for which they are no longer necessary.
  • The data subject withdraws their consent on which the processing was based according to Art. 6 Para. 1 lit. a GDPR or Art. 9 Para. 2 lit. a GDPR, and there is no other legal basis for the processing.
  • The data subject objects to the processing under Art. 21 Para. 1 GDPR, and there are no overriding legitimate grounds for the processing, or the data subject objects to the processing under Art. 21 Para. 2 GDPR.
  • The personal data has been unlawfully processed.
  • The erasure of personal data is necessary to fulfill a legal obligation under Union law or the law of Member States to which the controller is subject.
  • The personal data was collected in relation to offered information society services according to Art. 8 Para. 1 GDPR.

If one of the aforementioned reasons applies and you wish to request the deletion of personal data stored with us, please contact our data protection officer.

4.5 Right to Restriction of Processing

You also have the right to request the restriction of processing by us if one of the following conditions is met:

  • You dispute the accuracy of the personal data, for a period that allows us to verify the accuracy of the personal data
  • The processing is unlawful, but you oppose the erasure of the personal data and instead request the restriction of its use
  • We no longer need the personal data for the purposes of processing, but you need them for the establishment, exercise, or defense of legal claims
  • You have objected to processing under Art. 21 Para. 1 GDPR, but it is not yet clear whether our legitimate grounds override yours.

If one of the above conditions is met and you wish to request the restriction of personal data stored with us, please contact our above-mentioned data protection officer.

4.6 Right to Data Portability

Furthermore, you have the right to obtain the personal data concerning you that you have provided to us in a structured, commonly used, and machine-readable format. You also have the right to request the transfer of this data by us to another data controller, provided that the processing is based on consent pursuant to Article 6(1)(a) or Article 9(2)(a) of the GDPR, or on a contract pursuant to Article 6(1)(b) of the GDPR, and the processing is carried out by automated means, and provided that the processing is not necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in us, and that the rights and freedoms of others are not impaired. To exercise your right to data portability, please contact our above-mentioned Data Protection Officer.

4.7 Right to Object

Finally, you have the right to object at any time to the processing of your personal data that is carried out based on Article 6(1)(e) or (f) of the GDPR. This also applies to profiling based on these provisions. In the event of your objection, we will no longer process personal data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or if the processing is necessary for the establishment, exercise, or defense of legal claims. If we process personal data for direct marketing purposes, you have the right to object at any time to the processing of personal data for such marketing purposes. This also applies to profiling, insofar as it is related to such direct marketing. Furthermore, you have the right to object to the processing of your personal data for scientific, historical research, or statistical purposes under Article 89(1) of the GDPR, unless the processing is necessary for the performance of a task carried out in the public interest. To exercise your right to object, please contact our data protection officer directly.

4.8 Automated Decisions in Individual Cases, Including Profiling

We do not make decisions based solely on automated processing – including profiling – that have legal effects on you or similarly significantly affect you.

4.9 Right to Withdraw Consent

You also have the right to withdraw your consent to the processing of personal data at any time. To exercise this right to withdraw consent, please contact our aforementioned data protection officer.

4.10 Right to Lodge a Complaint with a Supervisory Authority

Furthermore, under Article 77 of the GDPR, you have the right to lodge a complaint with a supervisory authority. The supervisory authority responsible for us is the Hessian Commissioner for Data Protection and Freedom of Information.

5. USE OF COOKIES AND COMPARABLE TECHNIQUES

We only use one cookie or data in web storage on our website. Cookies are files that are placed and stored on a computer system via an internet browser.

By using cookies and storing data in web storage, we are able to provide users of our website with more user-friendly services that would not be possible otherwise. With the help of a cookie, the information and offers on our website can be optimized in the user's interest. As mentioned, cookies enable us to recognize the users of our website. The purpose of this recognition is to make it easier for users to use the site. For example, a user of a website that uses cookies does not need to enter their login credentials each time they visit the site because this is taken over by the website and the cookie stored on the user's computer system.

You can prevent the use of cookies on our website at any time by adjusting the settings of the internet browser you use, thus permanently objecting to the placement of cookies. Furthermore, cookies already set can be deleted at any time via an internet browser or other software programs. This is possible in all common internet browsers. If the data subject deactivates the placement of cookies in the internet browser used, it is possible that not all features of our website will be fully functional.

We use cookies in accordance with legal requirements. Therefore, we obtain consent before using them, unless this is not legally required, particularly when storing and reading the information is absolutely necessary to provide a service expressly requested by the users. If you consent, the legal basis for processing your data is your consent as declared by the checkbox. Otherwise, the data processed by cookies is processed based on our legitimate interests (e.g., in the economic operation of our online offer and improvement of its usability) or, if this occurs within the framework of fulfilling our contractual obligations, when the use of cookies is necessary to fulfill our contractual obligations.

Please refer to the explanations in the Consent Tool for the cookies used on our site.

6. INTEGRATION OF SERVICES AND CONTENT FROM THIRD PARTIES

6.1 Use of jQuery

In order to provide you, as a user, with our website efficiently and quickly across different devices, we use the services of the jQuery CDN from OpenJS Foundation. jQuery is distributed via the Content Delivery Network of the American software company Fastly, Inc. (475 Brannan St, Suite 300, San Francisco, CA 94107, USA). Through this service, personal data is processed.

  • Processed data types: IP address of users
  • Affected persons: Users, i.e., website visitors.
  • Purposes of processing: Faster delivery of our online offer, increasing user-friendliness.
  • Legal basis: Our legitimate interest according to Art. 6 (1) sentence 1 lit. f GDPR.

For information on data protection and the handling of user data, please visit Fastly's website at their Data Protection Terms: https://www.fastly.com/privacy/. We would like to point out that Fastly is an active participant in the EU-US Data Privacy Framework, which regulates the correct and secure transfer of personal data.

7. CONTACT AND INQUIRY MANAGEMENT

When you contact us (e.g., via contact form, email, phone, or social media) or within the framework of existing usage and business relationships, the details of the inquiring persons are processed as far as necessary to respond to the inquiries and, if applicable, any requested actions.

The response to contact inquiries and the management of contact and inquiry data within the framework of contractual or pre-contractual relationships is carried out to fulfill our contractual obligations or to respond to (pre-)contractual inquiries, and otherwise based on legitimate interests in answering the inquiries and maintaining user or business relationships.

  • Types of processed data: Master data (e.g., names, addresses); Contact information (e.g., email, phone numbers); Content data (e.g., entries in online forms)
  • Affected persons: Communication partners.
  • Purposes of processing: Contact inquiries and communication.
  • Legal basis: Your consent (Art. 6 (1) sentence 1 lit. a GDPR), contract fulfillment and pre-contractual inquiries (Art. 6 (1) sentence 1 lit. b GDPR); legitimate interests (Art. 6 (1) sentence 1 lit. f GDPR)

PLEASE SHARE YOUR OPINION WITH US

We aim to respect your privacy. You can help us improve our privacy policy by sharing your opinion with us. We are always open to your suggestions. If we need to make changes to our privacy policy, we will publish them on this page. You will always find information here about the data we collect, how we use this data, and under what circumstances we may collect it. Please check this page from time to time to stay informed about any changes and our current privacy policy.