Privacy Policy
This Privacy Policy explains the nature, scope and purpose of the processing of personal data (hereinafter referred to as ‘data’) in connection with the provision of our services, as well as within our online platform and the websites associated with it, features and content, as well as external online presences, such as our social media profiles (hereinafter collectively referred to as the ‘online offering’). With regard to the terms used, such as ‘processing’ or ‘controller’, we refer to the definitions in Article 4 of the General Data Protection Regulation (GDPR).
- Data controller
- Categories of data subjects
- Purpose of the processing
- Terminology used
- Relevant legal bases
- Safety measures
- Cooperation with data processors, joint controllers and third parties
- Transfers to third countries
- Rights of data subjects
- Right of withdrawal
- Right to object
- Cookies and the right to object to direct marketing
- Deletion of data
- Changes and updates to the privacy policy
- Business-related processing
- Order processing in the online shop and customer account
- External payment service providers
- Administration, financial accounting, office organisation, contact management
- Business Analysis and Market Research
- Microsoft Cloud Services
- Participation in affiliate programmes
- Affilinet Affiliate Programme
- Registration function
- Comments and posts
- Comment subscriptions
- Getting in touch
- Newsletter
- Newsletter – Mailchimp
- Newsletter – Measuring Success
- Web hosting and email services
- Collection of access data and log files
- Google Tag Manager
- Google Analytics
- Creating target audiences with Google Analytics
- Google AdWords and Conversion Tracking
- Google DoubleClick
- Online presence on social media
- Integration of third-party services and content
- YouTube
- Google Fonts
- Google reCAPTCHA
- Google Maps
- Use of Facebook Social Plugins
- Language versions
Data controller
Sana Swiss Services AG
Niedermattstrasse 8c
4528 Zuchwil
Email address: [email protected]
Chairman of the Board of Directors: Konstantin Satushev
Link to the legal notice: www.sanaservices.ch/imprint
Types of data processed
- Master data (e.g. personal master data, names or addresses).
- Contact details (e.g. email, telephone numbers).
- Content data (e.g. text entries, photographs, videos).
- Usage data (e.g. websites visited, interest in content, access times).
- Meta/communication data (e.g. device information, IP addresses).
Categories of data subjects
Visitors and users of the online service (hereinafter, we shall collectively refer to the data subjects as ‘users’).
Purpose of the processing
- To provide the online service, its functions and content.
- To respond to enquiries and communicate with users.
- Security measures.
- Audience measurement/marketing
Terminology used
‘Personal data’ means any information relating to an identified or identifiable natural person (hereinafter referred to as the ‘data subject’); a natural person is regarded as identifiable if they can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. a cookie) or one or more specific characteristics that reflect the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. ‘Processing’ means any operation or set of operations which is carried out on personal data, whether or not by automated means. The term is broad and covers virtually any handling of data. ‘Pseudonymisation’ means the processing of personal data in such a way that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures that ensure the personal data is not attributed to an identified or identifiable natural person. ‘Profiling’ means any form of automated processing of personal data consisting of the use of such personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s work performance, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements of that natural person. The term ‘controller’ refers to the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. ‘Data processor’ means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
Relevant legal bases
In accordance with Article 13 of the GDPR, we hereby inform you of the legal bases for our data processing activities. For users within the scope of the General Data Protection Regulation (GDPR), i.e. the EU and the EEC, the following applies unless the legal basis is specified in the privacy policy: The legal basis for obtaining consent is Article 6(1)(a) and Article 7 of the GDPR; The legal basis for processing carried out to fulfil our services, implement contractual measures and respond to enquiries is Article 6(1)(b) of the GDPR. The legal basis for processing to fulfil our legal obligations is Article 6(1)(c) of the GDPR. Where the vital interests of the data subject or another natural person necessitate the processing of personal data, Article 6(1)(d) of the GDPR serves as the legal basis. The legal basis for processing necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller is Article 6(1)(e) of the GDPR. The legal basis for processing to safeguard our legitimate interests is Article 6(1)(f) of the GDPR. The processing of data for purposes other than those for which it was collected is governed by the provisions of Article 6(4) of the GDPR. The processing of special categories of data (in accordance with Article 9(1) of the GDPR) is governed by the provisions of Article 9(2) of the GDPR.
Safety measures
We implement, in accordance with the statutory requirements and taking into account the state of the art, the costs of implementation and the nature, scope, circumstances and purposes of the processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, to ensure a level of protection appropriate to the risk. These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical access to the data, as well as access to, input of, disclosure of, and safeguarding the availability of the data, and ensuring its segregation. Furthermore, we have established procedures to ensure that data subjects’ rights are upheld, that data is deleted and that we respond to any data breaches. Furthermore, we take the protection of personal data into account right from the development and selection of hardware, software and procedures, in accordance with the principle of data protection by design and by default.
Cooperation with data processors, joint controllers and third parties
Where, in the course of our data processing, we disclose data to other individuals and organisations (data processors, joint controllers or third parties), transfer it to them or otherwise grant them access to the data, this is done solely on the basis of a legal authorisation (e.g. where the transfer of data to third parties, such as payment service providers, is necessary for the performance of a contract), where users have given their consent, where a legal obligation requires it, or on the basis of our legitimate interests (e.g. when using agents, web hosts, etc.). Where we disclose, transfer or otherwise grant access to data to other companies within our group, this is done in particular for administrative purposes as a legitimate interest and, beyond that, on a basis that complies with statutory requirements.
Transfers to third countries
Where we process data in a third country (i.e. outside the European Union (EU), the European Economic Area (EEA) or the Swiss Confederation), or where this occurs in connection with the use of third-party services, disclosure, or transfer of data to other individuals or organisations, this will only take place if it is necessary to fulfil our (pre-)contractual obligations, on the basis of your consent, due to a legal obligation, or on the basis of our legitimate interests. Subject to your express consent or where the transfer is contractually required, we shall only process or allow the data to be processed in third countries with a recognised level of data protection, which includes US processors certified under the ‘Privacy Shield’, or on the basis of specific safeguards, such as contractual obligations through the European Commission’s so-called Standard Data Protection Clauses, the existence of certifications or binding internal data protection policies (Articles 44 to 49 of the GDPR, European Commission information page).
Rights of data subjects
You have the right to request confirmation as to whether the data in question is being processed, and to request access to this data, as well as further information and a copy of the data, in accordance with the statutory requirements. In accordance with the statutory provisions, you have the right to request that the data relating to you be completed or that any inaccurate data relating to you be rectified. You have the right, in accordance with the statutory provisions, to request that the relevant data be erased without delay or, alternatively, in accordance with the statutory provisions, to request a restriction on the processing of the data. You have the right to request that the data concerning you, which you have provided to us, be returned to you in accordance with the statutory provisions and to request that it be transferred to other data controllers. You also have the right, in accordance with the statutory provisions, to lodge a complaint with the relevant supervisory authority.
Right of withdrawal
You have the right to withdraw any consent you have given with effect from now on.
Right to object
You may object at any time to the future processing of your personal data in accordance with the relevant legal provisions. In particular, you may object to the processing of your data for the purposes of direct marketing.
Cookies and the right to object to direct marketing
‘Cookies’ are small files that are stored on users’ computers. Various types of information can be stored within cookies. A cookie is primarily used to store information about a user (or the device on which the cookie is stored) during or after their visit to a website. Temporary cookies, also known as ‘session cookies’ or ‘transient cookies’, are cookies that are deleted once a user leaves an online service and closes their browser. Such a cookie may, for example, store the contents of a shopping basket in an online shop or a login status. Cookies that remain stored even after the browser is closed are referred to as ‘permanent’ or ‘persistent’. For example, this allows the login status to be stored so that users can log in again after several days. Similarly, such a cookie may store users’ interests, which are used for audience measurement or marketing purposes. ‘Third-party cookies’ are cookies provided by providers other than the data controller operating the online service (whereas, if only the data controller’s own cookies are used, these are referred to as ‘first-party cookies’). We may use temporary and permanent cookies and provide information about this in our privacy policy. If users do not wish to have cookies stored on their computer, they are asked to disable the relevant option in their browser’s system settings. Stored cookies can be deleted via the browser’s settings. On the following pages, you will find instructions on how to configure cookie settings for the most common browsers:
- Microsoft’s Windows Internet Explorer
- Microsoft's Windows Internet Explorer Mobile
- Mozilla Firefox
- Google Chrome for desktop
- Google Chrome for mobile
- Apple Safari for desktop
- Apple Safari for Mobile
Disabling cookies may result in this website not functioning properly. A general objection to the use of cookies for online marketing purposes can be lodged for a wide range of services – particularly in the case of tracking – via the US website http://www.aboutads.info/choices/ or the EU website http://www.youronlinechoices.com/. Furthermore, you can prevent cookies from being stored by disabling them in your browser settings. Please note that, in this case, you may not be able to use all the features of this website.
List of cookies we collect
The table below shows the cookies we collect in our shop and their contents:
| Cookie name | Cookie description |
|---|---|
| FORM_KEY | Stores a randomly generated key, which is used to prevent forged requests. |
| PHPSESSID | Your session ID on the server. |
| GUEST-VIEW | Allows guests to view and edit their orders. |
| PERSISTENT_SHOPPING_CART | A link to information about your shopping basket and your viewing history, if you have requested this. |
| STF | Information about products you have sent to friends by email. |
| STORE | The shop view or language you have selected |
| USER_ALLOWED_SAVE_COOKIE | Specifies whether a customer is permitted to use cookies. |
Deletion of data
The data we process will be deleted or its processing restricted in accordance with statutory requirements. Unless expressly stated otherwise in this privacy policy, the data stored by us will be deleted as soon as it is no longer required for its intended purpose and there are no statutory retention obligations preventing its deletion. Where data is not deleted because it is required for other, legally permissible purposes, its processing will be restricted. This means that the data will be blocked and not processed for any other purposes. This applies, for example, to data that must be retained for commercial or tax law reasons.
Changes and updates to the privacy policy
We ask that you check the content of our privacy policy regularly. We will update the privacy policy as soon as changes to the data processing activities we carry out make this necessary. We will inform you as soon as the changes require any action on your part (e.g. consent) or any other individual notification.
Business-related processing
In addition, we process: - Contract data (e.g. subject matter of the contract, term, customer category). - payment data (e.g. bank details, payment history) from our customers, prospective customers and business partners for the purposes of providing contractual services, customer service and support, marketing, advertising and market research.
Order processing in the online shop and customer account
We process our customers’ data as part of the ordering process in our online shop to enable them to select and order the products and services of their choice, as well as to facilitate payment, delivery and fulfilment. The data processed includes personal details, communication data, contractual data and payment data, and the data subjects affected by this processing include our customers, prospective customers and other business partners. The processing is carried out for the purpose of providing contractual services in connection with the operation of an online shop, billing, delivery and customer services. In doing so, we use session cookies to store the contents of the shopping basket and persistent cookies to store the login status. The processing is carried out to fulfil our services and implement contractual measures (e.g. processing orders) and to the extent required by law (e.g. the legally required archiving of business transactions for commercial and tax purposes). The information marked as ‘required’ is necessary for the conclusion and fulfilment of the contract. We disclose data to third parties only in connection with delivery, payment or in accordance with statutory permissions and obligations, as well as where this is based on our legitimate interests, about which we inform you in this privacy policy (e.g. to legal and tax advisers, financial institutions, freight forwarders and public authorities). Users may optionally create a user account, which allows them, in particular, to view their orders. During registration, users are informed of the mandatory details required. User accounts are not public and cannot be indexed by search engines. Once users have closed their user account, their data relating to that account will be deleted, unless retention is necessary for commercial or tax law reasons. Information in the customer account remains until it is deleted, after which it is archived in the event of a legal obligation or to safeguard our legitimate interests (e.g., in the event of legal disputes). It is the users’ responsibility to back up their data prior to the end of the contract following cancellation. When users register, log in again or use our online services, we store their IP address and the time of the respective user action. This data is stored on the basis of our legitimate interests, as well as the users’ interest in protection against misuse and other unauthorised use. As a general rule, this data is not disclosed to third parties, unless such disclosure is necessary to pursue our legal claims as a legitimate interest or there is a legal obligation to do so. The data is deleted once statutory warranty periods and other contractual rights or obligations have expired (e.g. payment claims or performance obligations arising from contracts with customers), with the necessity of retaining the data being reviewed every three years; in the case of retention due to statutory archiving obligations, the data will be deleted once these obligations have expired.
External payment service providers
We use external payment service providers through whose platforms both users and we can carry out payment transactions. These payment service providers may include the following, each with a link to their privacy policy: PayPal ( https://www.paypal.com/de/webapps/mpp/ua/privacy-full ), Klarna ( https://www.klarna.com/de/datenschutz/ ), Skrill (https://www.skrill.com/de/fusszeile/datenschutzrichtlinie/), Giropay (https://www.giropay.de/rechtliches/datenschutz-agb/), Visa (https://www.visa.de/datenschutz), Mastercard (https://www.mastercard.de/de-de/datenschutz.html), Stripe (https://stripe.com/de/privacy). We use these payment service providers in the context of fulfilling contracts on the basis of Article 6(1)(b) of the GDPR. Furthermore, we use external payment service providers on the basis of our legitimate interests pursuant to Article 6(1)(f) of the GDPR in order to offer our users effective and secure payment options. The data processed by the payment service providers includes personal details, such as name and address; bank details, such as account numbers or credit card numbers; passwords, TANs and checksums; as well as information relating to the contract, amounts and recipients. This information is required to carry out the transactions. However, the data entered is processed and stored solely by the payment service providers. This means that we do not receive any account- or credit card-related information, but only information confirming the payment or indicating that it has been declined. In some circumstances, the data may be passed on by the payment service providers to credit reference agencies. The purpose of this transfer is to verify identity and creditworthiness. In this regard, we refer you to the terms and conditions and privacy policies of the payment service providers. Payment transactions are governed by the terms and conditions and privacy policies of the respective payment service providers, which are available on their respective websites or within the transaction applications. We also refer you to these for further information and for exercising your rights of withdrawal, access and other data subject rights.
Administration, financial accounting, office organisation, contact management
We process data in connection with administrative tasks, the organisation of our business, financial accounting and compliance with legal obligations, such as archiving. In doing so, we process the same data that we process in the course of providing our contractual services. The legal bases for processing are Article 6(1)(c) of the GDPR and Article 6(1)(f) of the GDPR. This processing affects customers, prospective customers, business partners and website visitors. The purpose of, and our interest in, the processing lies in administration, financial accounting, office organisation and the archiving of data – in other words, tasks that serve to maintain our business activities, fulfil our duties and provide our services. The erasure of data relating to contractual services and contractual communication is in accordance with the information provided in relation to these processing activities. In this context, we disclose or transfer data to the tax authorities, advisers such as tax advisers or auditors, as well as other fee-charging bodies and payment service providers. Furthermore, based on our business interests, we store information on suppliers, event organisers and other business partners, e.g. for the purpose of contacting them at a later date. We generally store this data, which is predominantly company-related, on a permanent basis.
Business Analysis and Market Research
In order to run our business efficiently and to identify market trends and the requirements of our contractual partners and users, we analyse the data available to us relating to business transactions, contracts, enquiries, etc. In doing so, we process master data, communication data, contract data, payment data, usage data and metadata on the basis of Article 6(1)(f) of the GDPR, whereby the data subjects include contractual partners, prospective customers, customers, visitors and users of our online services. The analyses are carried out for the purposes of business evaluation, marketing and market research. In doing so, we may take into account the profiles of registered users, including details such as the services they have used. The analyses help us to improve user-friendliness, optimise our services and enhance operational efficiency. The analyses are used solely by us and are not disclosed externally, unless they are anonymous analyses based on aggregated data. Where these analyses or profiles contain personal data, they will be deleted or anonymised upon termination of the user’s account, or otherwise after two years from the date the contract was concluded. Furthermore, overall business analyses and general trend assessments are carried out anonymously wherever possible.
Microsoft Cloud Services
We use the cloud services provided by Microsoft and its cloud-based software services (known as Software as a Service, e.g. Microsoft Office) for the following purposes: document storage and management, calendar management, sending emails, spreadsheets and presentations, sharing documents, content and information with specific recipients, or publishing web pages, forms or other content and information, as well as chatting and participating in audio and video conferences. In doing so, users’ personal data is processed insofar as it forms part of the documents and content processed within the services described, or forms part of communication processes. This may include, for example, users’ master data and contact details, as well as data relating to transactions, contracts, other processes and their content. Microsoft also processes usage data and metadata, which Microsoft uses for security purposes and to optimise its services. When users access publicly available documents, web pages or other content, Microsoft may store cookies on their computers for the purposes of web analytics or to remember their settings. We use Microsoft Cloud Services on the basis of our legitimate interests pursuant to Article 6(1)(f) of the GDPR in efficient and secure administrative and collaborative processes. Furthermore, the processing is carried out on the basis of a data processing agreement with Microsoft. Further information can be found in Microsoft’s Privacy Statement (https://privacy.microsoft.com/de-de/privacystatement) and the security information on Microsoft Cloud Services (https://www.microsoft.com/de-de/trustcenter). You may object to the processing of your data in the Microsoft Cloud in accordance with the statutory provisions. Furthermore, the deletion of data within Microsoft’s cloud services is governed by the other processing procedures under which the data is processed (e.g. deletion of data no longer required for contractual purposes, or retention of data required for tax purposes). The Microsoft Cloud Services are provided by Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA. Where data is processed in the USA, we refer to Microsoft’s certification under the Privacy Shield (https://www.privacyshield.gov/participant?id=a2zt0000000KzNaAAK&status=Active).
Participation in affiliate programmes
Within our online service, we use industry-standard tracking measures on the basis of our legitimate interests (i.e. our interest in the analysis, optimisation and commercial operation of our online service) in accordance with Article 6(1)(f) of the GDPR, insofar as these are necessary for the operation of the affiliate system. Below, we explain the technical background to users. The services offered by our contractual partners may also be advertised and linked to on other websites (so-called affiliate links or ‘after-buy’ systems, where, for example, links or third-party services are offered following the conclusion of a contract). The operators of the respective websites receive a commission if users follow the affiliate links and subsequently take up the offers. In summary, it is necessary for our online service that we are able to track whether users who are interested in affiliate links and/or the offers available on our site subsequently take up those offers as a result of the affiliate links or our online platform. To this end, the affiliate links and our offers are supplemented with certain values, which may form part of the link or be set elsewhere, e.g. in a cookie. These values include, in particular, the referring website (referrer), the time, an online identifier for the operator of the website on which the affiliate link was located, an online identifier for the relevant offer, an online identifier for the user, as well as tracking-specific values such as advertising material ID, partner ID and categorisations. The users’ online identifiers that we use are pseudonymous values. This means that the online identifiers themselves do not contain any personal data such as names or email addresses. They merely help us to determine whether the same user who clicked on an affiliate link or expressed an interest in an offer via our online platform has taken up the offer, i.e. has, for example, entered into a contract with the provider. However, the online identifier is personal insofar as both the partner company and we have access to the online identifier alongside other user data. Only in this way can the partner company inform us whether the user in question has taken up the offer and we can, for example, pay out the bonus.
Affilinet Affiliate Programme
On the basis of our legitimate interests (i.e. our interest in the commercial operation of our online service within the meaning of Article 6(1)(f) of the GDPR), we participate in the affiliate programme run by affilinet GmbH, Sapporobogen 6–8, 80637 Munich, Germany, which is designed to provide a platform for websites through which advertising revenue can be earned by placing advertisements and links to Affilinet (the so-called affiliate system). Affilinet uses cookies to track the origin of the contract conclusion. Among other things, Affilinet can recognise that you clicked on the affiliate link on this website and subsequently concluded a contract with or via Affilinet. Further information on Affilinet’s use of data and your options to object can be found in the company’s privacy policy: https://www.affili.net/de/footeritem/datenschutz .
Registration function
Users can create a user account. During the registration process, users are informed of the required mandatory details, which are processed on the basis of Article 6(1)(b) of the GDPR for the purpose of providing the user account. The data processed includes, in particular, login details (name, password and an email address). The data entered during registration is used for the purposes of using the user account and in accordance with its intended purpose. Users may be notified by email of information relevant to their user account, such as technical changes. Once users have terminated their user account, their data relating to that account will be deleted, subject to any statutory retention obligations. It is the users’ responsibility to back up their data prior to the termination of the contract. We are entitled to irrevocably delete all user data stored during the term of the contract. When users make use of our registration and login functions, as well as when using their user account, we store the IP address and the time of the respective user action. This data is stored on the basis of our legitimate interests, as well as the users’ interests in protection against misuse and other unauthorised use. This data is not, as a matter of principle, disclosed to third parties, unless this is necessary to pursue our claims or there is a legal obligation to do so in accordance with Article 6(1)(c) of the GDPR. IP addresses are anonymised or deleted after 7 days at the latest.
Comments and posts
When users leave comments or other posts, their IP addresses may be stored for 7 days on the basis of our legitimate interests within the meaning of Article 6(1)(f) of the GDPR. This is for our own protection in the event that someone posts unlawful content in comments or contributions (insults, prohibited political propaganda, etc.). In such cases, we ourselves may be held liable for the comment or contribution and are therefore interested in the author’s identity. Furthermore, we reserve the right, on the basis of our legitimate interests pursuant to Article 6(1)(f) of the GDPR, to process users’ data for the purpose of spam detection. On the same legal basis, we reserve the right, in the case of surveys, to store users’ IP addresses for the duration of the survey and to use cookies to prevent multiple votes. The personal information provided in comments and posts, including any contact and website details, as well as the content itself, will be stored permanently by us until the user objects.
Comment subscriptions
Users may subscribe to subsequent comments with their consent in accordance with Article 6(1)(a) of the GDPR. Users will receive a confirmation email to verify that they are the owners of the email address provided. Users may unsubscribe from existing comment subscriptions at any time. The confirmation email will contain information on how to withdraw consent. For the purposes of providing evidence of users’ consent, we store the time of registration together with the user’s IP address and delete this information when users unsubscribe. You may cancel your subscription to our service at any time, i.e. withdraw your consent. We may store unsubscribed email addresses for up to three years on the basis of our legitimate interests before deleting them, in order to be able to provide evidence of consent previously given. The processing of this data is limited to the purpose of potentially defending against claims. An individual request for erasure may be made at any time, provided that the prior existence of consent is confirmed at the same time.
Getting in touch
When users contact us (e.g. via the contact form, email, telephone or social media), their details are processed for the purpose of handling the contact enquiry and its follow-up in accordance with Article 6(1)(b) (in the context of contractual or pre-contractual relationships), Article 6(1)(f) (other enquiries) of the GDPR. Users’ details may be stored in a Customer Relationship Management system (“CRM system”) or a comparable enquiry management system. We delete enquiries once they are no longer required. We review the necessity of retention every two years; furthermore, statutory archiving obligations apply.
Newsletter
The following information explains the content of our newsletter, as well as the procedures for subscription, distribution and statistical analysis, and your rights to object. By subscribing to our newsletter, you agree to receive it and to the procedures described. Content of the newsletter: We send out newsletters, emails and other electronic communications containing promotional information (hereinafter ‘newsletters’) only with the consent of the recipients or where permitted by law. Where the content of the newsletter is specifically described as part of the subscription process, this content is decisive for the user’s consent. In addition, our newsletters contain information about our services and our organisation. Double opt-in and logging: Subscription to our newsletter takes place via a so-called double opt-in procedure. This means that, after subscribing, you will receive an email asking you to confirm your subscription. This confirmation is necessary to ensure that no one can subscribe using someone else’s email address. Subscriptions to the newsletter are logged so that we can provide evidence of the subscription process in accordance with legal requirements. This includes storing the time of subscription and confirmation, as well as the IP address. Any changes to your data stored with the mailing service provider are also logged. Subscription details: To subscribe to the newsletter, you simply need to provide your email address. We also ask you, on an optional basis, to provide a name so that we can address you personally in the newsletter. The sending of the newsletter and the associated performance measurement are carried out on the basis of the recipients’ consent in accordance with Article 6(1)(a), Article 7 of the GDPR in conjunction with Section 7(2)(3) of the UWG; or, where consent is not required, on the basis of our legitimate interests in direct marketing pursuant to Article 6(1)(f) GDPR in conjunction with Section 7(3) of the UWG. The logging of the registration process is carried out on the basis of our legitimate interests in accordance with Article 6(1)(f) of the GDPR. Our interest lies in the use of a user-friendly and secure newsletter system that both serves our business interests and meets users’ expectations, whilst also enabling us to provide evidence of consent. Cancellation/Withdrawal – You may cancel your subscription to our newsletter at any time, i.e. withdraw your consent. A link to unsubscribe from the newsletter can be found at the end of every newsletter. We may store unsubscribed email addresses for up to three years on the basis of our legitimate interests before deleting them, in order to be able to provide evidence of consent previously given. The processing of this data is limited to the purpose of potentially defending against claims. An individual request for erasure may be made at any time, provided that the prior existence of consent is confirmed at the same time.
Newsletter – Mailchimp
The newsletters are sent via the mailing service provider ‘MailChimp’, a newsletter distribution platform operated by the US provider Rocket Science Group, LLC, 675 Ponce De Leon Ave NE #5000, Atlanta, GA 30308, USA. You can view the mailing service provider’s privacy policy here: https://mailchimp.com/legal/privacy/. The Rocket Science Group LLC, trading as MailChimp, is certified under the Privacy Shield Framework and thereby guarantees compliance with European data protection standards ( https://www.privacyshield.gov/participant?id=a2zt0000000TO6hAAG&status=Active ). The mailing service provider is engaged on the basis of our legitimate interests pursuant to Article 6(1)(f) of the GDPR and a data processing agreement pursuant to Article 28(3), first sentence, of the GDPR. The delivery service provider may use the recipients’ data in pseudonymous form – i.e. without linking it to a specific user – to optimise or improve its own services, e.g. for the technical optimisation of the dispatch and presentation of the newsletters, or for statistical purposes. However, the mailing service provider does not use the data of our newsletter recipients to contact them directly or to pass the data on to third parties.
Newsletter – Measuring Success
The newsletters contain a so-called ‘web beacon’, i.e. a file the size of a single pixel, which is retrieved from our server – or, if we use a mailing service provider, from their server – when the newsletter is opened. As part of this retrieval, technical information – such as details about your browser and system – as well as your IP address and the time of retrieval are initially collected. This information is used to improve our services technically on the basis of the technical data, or to analyse target groups and their reading behaviour based on their location (which can be determined using the IP address) or the times at which the newsletter is accessed. The statistical analysis also includes determining whether newsletters are opened, when they are opened and which links are clicked. Although this information can, for technical reasons, be attributed to individual newsletter recipients, However, it is neither our intention, nor – where applicable – that of the mailing service provider, to monitor individual users. Rather, the analyses serve to help us identify our users’ reading habits and adapt our content accordingly, or to send different content based on our users’ interests. Unfortunately, it is not possible to opt out of performance tracking separately; in this case, the entire newsletter subscription must be cancelled.
Web hosting and email services
The hosting services we use are intended to provide the following: infrastructure and platform services, computing capacity, storage space and database services, email delivery, security services and technical maintenance services, which we utilise for the purpose of operating this online service. In doing so, we, or our hosting provider, process personal data relating to customers, including master data, contact details, content data, contractual data, usage data, metadata and communication data, prospective customers and visitors to this online service on the basis of our legitimate interests in the efficient and secure provision of this online service in accordance with Article 6(1)(f) of the GDPR in conjunction with Article 28 of the GDPR (conclusion of a data processing agreement).
Collection of access data and log files
We, or rather our hosting provider, collect data on every access to the server on which this service is hosted (so-called server log files) on the basis of our legitimate interests within the meaning of Article 6(1)(f) of the GDPR. The access data includes the name of the webpage accessed, the file, the date and time of access, the volume of data transferred, confirmation of successful access, the browser type and version, the user’s operating system, the referrer URL (the previously visited page), IP address and the requesting provider. Log file information is stored for a maximum of 7 days for security reasons (e.g. to investigate cases of misuse or fraud) and is subsequently deleted. Data which must be retained for further evidence purposes is exempt from deletion until the relevant incident has been fully clarified.
Google Tag Manager
Google Tag Manager is a solution that enables us to manage so-called website tags via a user interface (and thus, for example, integrate Google Analytics and other Google marketing services into our online offering). The Tag Manager itself (which implements the tags) does not process any of the users’ personal data. With regard to the processing of users’ personal data, please refer to the following information on Google’s services. Terms of Service: https://www.google.com/intl/de/tagmanager/use-policy.html .
Google Analytics
On the basis of our legitimate interests (i.e. our interest in the analysis, optimisation and commercial operation of our online service within the meaning of Article 6(1)(f) of the GDPR), we use Google Analytics, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (‘Google’). Google uses cookies. The information generated by the cookie regarding users’ use of the online service is usually transmitted to a Google server in the USA and stored there. Google is certified under the Privacy Shield Agreement and thereby provides a guarantee of compliance with European data protection law (https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active). Google will use this information on our behalf to analyse how users use our website, to compile reports on activity within the website, and to provide us with other services relating to the use of the website and internet usage. In doing so, pseudonymous user profiles may be created from the processed data. We only use Google Analytics with IP anonymisation enabled. This means that users’ IP addresses are truncated by Google within Member States of the European Union or in other signatory states to the Agreement on the European Economic Area. Only in exceptional cases is the full IP address transmitted to a Google server in the USA and truncated there. The IP address transmitted by the user’s browser is not merged with other data held by Google. Users can prevent the storage of cookies by adjusting the settings in their browser software accordingly; users may also prevent Google from collecting the data generated by the cookie and relating to their use of the online service, as well as the processing of this data by Google, by downloading and installing the browser plug-in available via the following link: http://tools.google.com/dlpage/gaoptout?hl=de. Further information on Google’s use of data, as well as options for settings and opting out, can be found in Google’s Privacy Policy ( https://policies.google.com/privacy ) and in the settings for the display of Google adverts (https://adssettings.google.com/authenticated). Users’ personal data will be deleted or anonymised after 14 months.
Creating target audiences with Google Analytics
We use Google Analytics to ensure that adverts displayed via Google’s advertising services and those of its partners are shown only to users who have demonstrated an interest in our online offering or who exhibit certain characteristics (e.g. interests in specific topics or products, determined on the basis of the web pages visited), which we transmit to Google (so-called ‘remarketing’ or ‘Google Analytics audiences’). We also use Remarketing Audiences to ensure that our adverts match users’ potential interests.
Google AdWords and Conversion Tracking
On the basis of our legitimate interests (i.e. our interest in the analysis, optimisation and commercial operation of our online service within the meaning of Article 6(1)(f) of the GDPR), we use the services of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, (‘Google’). Google is certified under the Privacy Shield Framework and thereby provides a guarantee of compliance with European data protection law (https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active). We use Google’s online marketing service ‘AdWords’ to place adverts on the Google advertising network (e.g. in search results, in videos, on websites, etc.) so that they are shown to users who are likely to be interested in the adverts. This enables us to display adverts for and within our online service in a more targeted manner, so as to present users only with adverts that potentially match their interests. If, for example, a user is shown adverts for products they have previously shown an interest in on other websites, this is referred to as ‘remarketing’. For these purposes, when our website or other websites on which the Google advertising network is active are accessed, a Google code is executed directly by Google and so-called (re)marketing tags (invisible graphics or code, also known as ‘web beacons’) are embedded in the website. With the help of these, an individual cookie – i.e. a small file – is stored on the user’s device (comparable technologies may also be used instead of cookies). This file records which web pages the user has visited, what content they are interested in and which offers the user has clicked on, as well as technical information about the browser and operating system, referring web pages, time of visit and further details regarding the use of the online service. We also receive an individual ‘conversion cookie’. The information collected via this cookie is used by Google to generate conversion statistics for us. However, we are only provided with the anonymous total number of users who clicked on our advert and were redirected to a page tagged with a conversion tracking tag. We do not, however, receive any information that could be used to personally identify users. User data is processed pseudonymously within the Google advertising network. This means that Google does not, for example, store or process users’ names or email addresses, but instead processes the relevant data on a cookie-by-cookie basis within pseudonymous user profiles. This means that, from Google’s perspective, the adverts are not managed and displayed for a specifically identified individual, but for the cookie holder, regardless of who that cookie holder is. This does not apply if a user has expressly authorised Google to process the data without this pseudonymisation. The information collected about users is transmitted to Google and stored on Google’s servers in the USA. Further information on Google’s use of data, as well as options for adjusting settings and opting out, can be found in Google’s Privacy Policy ( https://policies.google.com/technologies/ads ) and in the settings for the display of Google adverts (https://adssettings.google.com/authenticated).
Google DoubleClick
On the basis of our legitimate interests (i.e. our interest in the analysis, optimisation and commercial operation of our online service within the meaning of Article 6(1)(f) of the GDPR), we use the services of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (‘Google’). Google is certified under the Privacy Shield Agreement and thereby guarantees compliance with European data protection law (https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active). We use Google’s online marketing service ‘DoubleClick’ to place adverts on the Google Display Network (e.g. in search results, in videos, on websites, etc.). DoubleClick is characterised by the fact that adverts are displayed in real time based on users’ presumed interests. This allows us to display adverts for and within our online service in a more targeted manner, so as to present users only with adverts that potentially match their interests. If, for example, a user is shown adverts for products they have previously shown an interest in on other websites, this is referred to as ‘remarketing’. For these purposes, when our website or other websites on which the Google advertising network is active are accessed, a Google code is executed directly by Google and so-called (re)marketing tags (invisible graphics or code, also known as ‘web beacons’) are embedded in the website. With the help of these, an individual cookie – i.e. a small file – is stored on the user’s device (comparable technologies may also be used instead of cookies). This file records which websites the user has visited, what content they are interested in and which offers the user has clicked on, as well as technical information about the browser and operating system, referring websites, the time of the visit and further details regarding the use of the online service. The user’s IP address is also collected; within Member States of the European Union or in other signatory states to the Agreement on the European Economic Area, this address is truncated, and only in exceptional cases is the full address transmitted to a Google server in the USA, where it is then truncated. Google may also combine the aforementioned information with data from other sources. When the user subsequently visits other websites, they may be shown personalised adverts based on their presumed interests, as determined by their user profile. Users’ data is processed pseudonymously within the Google advertising network. This means that Google does not, for example, store or process users’ names or email addresses, but instead processes the relevant data on a cookie-by-cookie basis within pseudonymous user profiles. In other words, from Google’s perspective, the adverts are not managed and displayed for a specifically identified individual, but for the cookie holder, regardless of who that cookie holder is. This does not apply if a user has expressly authorised Google to process the data without this pseudonymisation. The information collected by Google Marketing Services about users is transmitted to Google and stored on Google’s servers in the USA.
For further information on Google’s use of data, as well as options for adjusting settings and opting out, please refer to Google’s Privacy Policy ( https://policies.google.com/technologies/ads ) and the settings for the display of Google adverts (https://adssettings.google.com/authenticated).
Online presence on social media
We maintain an online presence on social networks and platforms in order to communicate with customers, prospective customers and users active on these platforms and to inform them about our services. Please note that this may involve the processing of users’ data outside the European Union. This may entail risks for users, as it could, for example, make it more difficult to enforce their rights. With regard to US providers certified under the Privacy Shield, we would like to point out that they are thereby obliged to comply with EU data protection standards. Furthermore, users’ data is generally processed for market research and advertising purposes. For example, usage profiles may be created based on users’ behaviour and the resulting interests. These user profiles may in turn be used, for example, to display adverts both within and outside the platforms that are presumed to correspond to users’ interests. For these purposes, cookies are usually stored on users’ computers, in which their usage behaviour and interests are recorded. Furthermore, data may also be stored in the user profiles regardless of the devices used by users (in particular where users are members of the respective platforms and are logged in to them). The processing of users’ personal data is carried out on the basis of our legitimate interests in effectively informing users and communicating with them in accordance with Article 6(1)(f) of the GDPR. If users are asked by the respective platform providers to consent to the data processing described above, the legal basis for the processing is Article 6(1)(a) and Article 7 of the GDPR. For a detailed description of the respective processing activities and the options for objecting (opt-out), please refer to the information provided by the platform providers via the links below. We would also like to point out that, in the case of requests for information and the exercise of users’ rights, these can most effectively be exercised with the platform providers. Only the platform providers have access to users’ data and can take appropriate measures and provide information directly. Should you nevertheless require assistance, please do not hesitate to contact us. - Facebook, -Pages, -Groups, (Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland) on the basis of a agreement on the joint processing of personal data – Privacy Policy: https://www.facebook.com/about/privacy/, specifically for Pages: https://www.facebook.com/legal/terms/information_about_page_insights_data, opt-out: https://www.facebook.com/settings?tab=ads and http://www.youronlinechoices.com, Privacy Shield: https://www.privacyshield.gov/participant?id=a2zt0000000GnywAAC&status=Active.
- Google/YouTube (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland)
- Privacy policy: https://policies.google.com/privacy , Opt-out: https://adssettings.google.com/authenticated, Privacy Shield: https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active.
- Instagram (Instagram Inc., 1601 Willow Road, Menlo Park, CA, 94025, USA)
- Privacy Policy / Opt-out: http://instagram.com/about/legal/privacy/.
- Twitter (Twitter Inc., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA)
- Privacy Policy: https://twitter.com/de/privacy, opt-out: https://twitter.com/personalization, Privacy Shield: https://www.privacyshield.gov/participant?id=a2zt0000000TORzAAO&status=Active .
- Pinterest (Pinterest Inc., 635 High Street, Palo Alto, CA, 94301, USA)
- Privacy policy/opt-out: https://about.pinterest.com/de/privacy-policy .
- LinkedIn (LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland)
- Privacy policy https://www.linkedin.com/legal/privacy-policy, Opt-out: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out, Privacy Shield: https://www.privacyshield.gov/participant?id=a2zt0000000L0UZAA0&status=Active .
- Xing (XING AG, Dammtorstrasse 29-32, 20354 Hamburg, Germany)
- Privacy policy/opt-out: https://privacy.xing.com/de/datenschutzerklaerung .
- Wakalet (Wakelet Limited, 76 Quay Street, Manchester, M3 4PR, United Kingdom)
- Privacy policy/opt-out: https://wakelet.com/privacy.html .
- SoundCloud (SoundCloud Limited, Rheinsberger Str. 76/77, 10115 Berlin, Germany)
- Privacy policy/opt-out: https://soundcloud.com/pages/privacy .
Integration of third-party services and content
Within our online offering, we rely on our legitimate interests (i.e. our interest in the analysis, optimisation and commercial operation of our online offering within the meaning of Article 6(1)(f) of the GDPR) to incorporate content or services from third-party providers in order to integrate their content and services, such as videos or fonts (hereinafter collectively referred to as ‘content’). This always requires the third-party providers of this content to collect users’ IP addresses, as they would be unable to send the content to users’ browsers without the IP address. The IP address is therefore necessary for the display of this content. We endeavour to use only such content where the respective providers use the IP address solely for the purpose of delivering the content. Third-party providers may also use so-called pixel tags (invisible graphics, also known as ‘web beacons’) for statistical or marketing purposes. These ‘pixel tags’ enable information, such as visitor traffic on the pages of this website, to be analysed. This pseudonymous information may also be stored in cookies on the user’s device and may include, amongst other things, technical information about the browser and operating system, referring websites, time of visit and further details regarding the use of our online service, as well as being linked to such information from other sources.
YouTube
We embed videos from the “YouTube” platform provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Privacy policy: https://www.google.com/policies/privacy/ , Opt-out: https://adssettings.google.com/authenticated .
Google Fonts
We incorporate fonts (“Google Fonts”) provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. According to Google, users’ data is used solely for the purpose of displaying the fonts in the user’s browser. This integration is based on our legitimate interests in the technically secure, maintenance-free and efficient use of fonts, their consistent display, and compliance with any licence restrictions relating to their integration. Privacy policy: https://www.google.com/policies/privacy/ .
Google reCAPTCHA
We incorporate the bot detection feature, e.g. for entries in online forms (“reCAPTCHA”), provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Privacy policy: https://www.google.com/policies/privacy/ , Opt-out: https://adssettings.google.com/authenticated .
Google Maps
We incorporate maps from the “Google Maps” service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The data processed may include, in particular, users’ IP addresses and location data; however, this data is not collected without their consent (which is usually given via the settings on their mobile devices). The data may be processed in the USA. Privacy policy: https://www.google.com/policies/privacy/, opt-out: https://adssettings.google.com/authenticated.
Use of Facebook Social Plugins
We use, on the basis of our legitimate interests (i.e. our interest in the analysis, optimisation and commercial operation of our online service within the meaning of Article 6(1)(f) of the GDPR) social plugins (“plugins”) from the social network facebook.com, which is operated by Facebook Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (“Facebook”). These may include, for example, content such as images, videos or text, as well as buttons that allow users to share content from this online service on Facebook. The list and appearance of the Facebook social plugins can be viewed here: https://developers.facebook.com/docs/plugins/ . Facebook is certified under the Privacy Shield Agreement and thereby guarantees compliance with European data protection law ( https://www.privacyshield.gov/participant?id=a2zt0000000GnywAAC&status=Active ).
When a user accesses a feature of this online service that contains such a plugin, their device establishes a direct connection to Facebook’s servers. The content of the plugin is transmitted directly from Facebook to the user’s device and integrated into the online service. In the process, user profiles may be created from the data processed. We therefore have no influence over the scope of the data that Facebook collects via this plugin and are therefore informing users in accordance with our current knowledge. By embedding the plugins, Facebook receives the information that a user has accessed the relevant page of the online service. If the user is logged into Facebook, Facebook can associate the visit with their Facebook account. When users interact with the plugins – for example, by clicking the ‘Like’ button or posting a comment – the relevant information is transmitted directly from their device to Facebook and stored there. Even if a user is not a member of Facebook, it is still possible for Facebook to obtain and store their IP address. According to Facebook, only an anonymised IP address is stored in Germany. Users can find out about the purpose and scope of data collection, as well as the further processing and use of the data by Facebook, and their rights and settings options regarding the protection of their privacy, in Facebook’s privacy policy: https://www.facebook.com/about/privacy/. If a user is a Facebook member and does not wish Facebook to collect data about them via this online service and link it to their membership data stored on Facebook, they must log out of Facebook and delete their cookies before using our online service. Further settings and the option to object to the use of data for advertising purposes are available within the Facebook profile settings: https://www.facebook.com/settings?tab=ads or via the US website http://www.aboutads.info/choices/ or the EU site http://www.youronlinechoices.com/ . These settings apply across all platforms, i.e. they are applied to all devices, such as desktop computers or mobile devices.
Our online service may incorporate features and content from Instagram, a service provided by Instagram Inc., 1601 Willow Road, Menlo Park, CA, 94025, USA. This may include, for example, content such as images, videos or text, as well as buttons that allow users to share content from this website on Instagram. If users are members of the Instagram platform, Instagram may associate their access to the aforementioned content and features with their Instagram profiles. Instagram’s Privacy Policy: http://instagram.com/about/legal/privacy/ .
Our online service may incorporate features and content from the Xing service, provided by XING AG, Dammtorstrasse 29–32, 20354 Hamburg, Germany. This may include, for example, content such as images, videos or text, as well as buttons that allow users to share content from this online service within Xing. Where users are members of the Xing platform, Xing may associate access to the aforementioned content and features with the users’ profiles on that platform. Xing’s privacy policy: https://privacy.xing.com/de/datenschutzerklaerung .
Our online service may incorporate features and content from LinkedIn, provided by LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland. This may include, for example, content such as images, videos or text, as well as buttons that allow users to share content from this online service on LinkedIn. If users are members of the LinkedIn platform, LinkedIn may associate their access to the aforementioned content and features with their profiles on that platform. LinkedIn’s privacy policy: https://www.linkedin.com/legal/privacy-policy. . LinkedIn is certified under the Privacy Shield Agreement and thereby guarantees compliance with European data protection law ( https://www.privacyshield.gov/participant?id=a2zt0000000L0UZAA0&status=Active ). Privacy policy: https://www.linkedin.com/legal/privacy-policy , Opt-out: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out .
Created using Datenschutz-Generator.de by Dr Thomas Schwenke, solicitor
Language versions
This privacy policy is available in several languages. In the event of any contradictions, questions of interpretation or ambiguities between the different language versions, the German version shall prevail.
The foreign-language versions are provided solely to aid understanding and have no legal effect in their own right.