Data protection

1. 1. Data protection at a glance

General notes

The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can be used to identify you personally. Detailed information on the subject of data protection can be found in the following text of this data protection notice.

Data collection on this website

Who is responsible for data collection on this website?

Data processing on this website is carried out by the website operator. You can find the operator's contact details in the legal notice of this website.

How we collect your data?

On the one hand, your data is collected when you provide it to us. This may, for example, be data that you enter in a contact form.

Other data is collected automatically or with your consent by our IT systems when you visit the website. This is primarily technical data (e.g. internet browser, operating system or time of page view). This data is collected automatically as soon as you access this website.

What we use your data for?

Some of the data is collected to ensure error-free provision of the website. Other data may be used to analyze your user behavior.

What rights do you have with regard to your data?

You have the right at any time to receive information free of charge about the origin, recipient and purpose of your stored personal data. You also have a right to request the correction or deletion of this data. If you have given your consent to data processing, you can revoke this consent at any time for the future. You also have the right to request the restriction of the processing of your personal data under certain circumstances. Furthermore, you have the right to lodge a complaint with the competent supervisory authority.

You can contact us at any time at the address given in the legal notice if you have further questions on the subject of data protection.

Analysis tools and third-party tools

When visiting this website, your surfing behavior can be statistically evaluated. This is done mainly with so-called analysis programs.

Detailed information on these points can be found in the following data protection information.

2. Hosting and Content Delivery Networks (CDN)

External hosting

This website is hosted by an external service provider (hoster). The personal data collected on this website is stored on the hoster's servers. This may include IP addresses, contact requests, meta and communication data, contract data, contact data, names, website accesses and other data generated via a website.

and in the interest of a secure, fast and efficient provision of our online offer by a professional provider (Art. 6 para. 1 lit. f GDPR).

Our hoster will only process your data to the extent necessary to fulfill its service obligations and will follow our instructions regarding this data.

Conclusion of a contract for order processing

To ensure data protection-compliant processing, we have concluded an order processing contract with our hoster.

3. General notes and mandatory information

Privacy policy

The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.

When you use this website, various personal data are collected. Personal data is data with which you can be personally identified. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this is done.

We would like to point out that data transmission over the Internet (e.g. when communicating by email) may be subject to security vulnerabilities. Complete protection of data against access by third parties is not possible.

Note on the responsible body

Responsible for data processing on this website is:

Hyla Sinau
SINGAPORE SINAU INTERNATIONAL PTE LTD. TAIWAN BRANCH
1 F., No. 497, Zhongming S. Rd., West Dist., Taichung City
Taiwan

Phone: +886 03-5519761
E-mail: info@hyla-germany.de

The controller is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data (e.g. names, email addresses, etc.).

Revocation of your consent to data processing

Many data processing operations are only possible with your express consent. You can revoke consent you have already given at any time. The legality of the data processing carried out until the revocation remains unaffected by the revocation.

Right to object to data collection in special cases and to direct marketing (Art. 21 DSGVO)

If your personal data are processed for the purpose of direct marketing, you have the right to object at any time to the processing of personal data concerning you for the purpose of such marketing; this also applies to profiling insofar as it is related to such direct marketing. if you object, your personal data will subsequently no longer be used for the purpose of direct marketing (objection pursuant to art. 21 para. 2 GDPR).

Right to lodge a complaint with the competent supervisory authority

In the event of breaches of the GDPR, data subjects shall have a right of appeal to a supervisory authority, in particular in the Member State of their habitual residence, their place of work or the place of the alleged breach. The right of appeal is without prejudice to other administrative or judicial remedies.

Right to confirmation

You have the right to request confirmation from the controller as to whether we are processing personal data concerning you. You can request confirmation at any time using the contact details above.

Right to data portability

You have the right to have data that we process automatically on the basis of your consent or in fulfillment of a contract handed over to you or to a third party in a common, machine-readable format. If you request the direct transfer of the data to another controller, this will only be done insofar as it is technically feasible.

Information, deletion and correction

Within the framework of the applicable legal provisions, you have the right at any time to free information about your stored personal data, its origin and recipient and the purpose of the data processing and, if necessary, a right to correction or deletion of this data. You can contact us at any time at the address given in the legal notice if you have further questions on the subject of personal data.

Right to restriction of processing

You have the right to request the restriction of the processing of your personal data. To do so, you can contact us at any time at the address given in the legal notice. The right to restriction of processing exists in the following cases:

  • If you dispute the accuracy of your personal data stored by us, we usually need time to verify this. For the duration of the review, you have the right to request the restriction of the processing of your personal data.

  • If the processing of your personal data happened/is happening unlawfully, you may request the restriction of data processing instead of erasure.

  • If we no longer need your personal data, but you need it to exercise, defend or enforce legal claims, you have the right to request restriction of the processing of your personal data instead of deletion.

  • If you have lodged an objection pursuant to Art. 21 (1) DSGVO, a balancing of your and our interests must be carried out. As long as it has not yet been determined whose interests prevail, you have the right to request the restriction of the processing of your personal data.

If you have restricted the processing of your personal data, this data - apart from its storage - may only be processed with your consent or for the establishment, exercise or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the European Union or of a Member State.

Right to effective judicial remedy

Without prejudice to any available administrative or extrajudicial remedy, including the right to lodge a complaint with a supervisory authority pursuant to Article 77 GDPR, you have the right to an effective judicial remedy if you consider that your rights under this Regulation have been infringed as a result of the processing of your personal data in non-compliance with this Regulation.

4. Data collection on this website

If you only use the website for informational purposes, i.e. if you do not register or otherwise provide us with information, we only collect the personal data that your browser transmits to our server. If you wish to view our website, we collect the following data, which is technically necessary for us to display our website to you and to ensure stability and security:

  • IP address

  • Date and time of the request

  • Time zone difference to Greenwich Mean Time (GMT)

  • Content of the request (specific page)

  • Access status/HTTP status code

  • amount of data transferred in each case

  • Website from which the request comes

  • Browser

  • Operating system and its interface

  • Language and version of the browser software

After a technical evaluation, this data is deleted immediately. This data collection serves to safeguard our legitimate interests in the correct presentation of our website offering, which are overriding in the context of a balancing of interests, and compliance with the EU General Data Protection Regulation in terms of security and confidentiality in accordance with Art. 6 para. 1 lit. f) GDPR.

SSL or TLS encryption

This site uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content, such as orders or inquiries that you send to us as the site operator. You can recognize an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in your browser line.

If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.

Contact form

If you send us inquiries via the contact form, your data from the inquiry form including the contact data you provided there will be stored by us for the purpose of processing the inquiry and in case of follow-up questions. We do not pass on this data without your consent.

This data is processed on the basis of Art. 6 para. 1 lit. b) GDPR if your request is related to the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective processing of the inquiries addressed to us (Art. 6 para. 1 lit. f) GDPR) or on your consent (Art. 6 para. 1 lit. a) GDPR) if this has been requested.

We store the data you enter in the contact form until you revoke your consent to storage or the purpose for data storage no longer applies (e.g. after your request has been processed). Mandatory statutory provisions - in particular retention periods - remain unaffected.

Request by e-mail, phone or fax

If you contact us by e-mail, telephone or fax, your inquiry including all resulting personal data (name, inquiry) will be stored and processed by us for the purpose of processing your request. We will not pass on this data without your consent.

This data is processed on the basis of Art. 6 para. 1 lit. b) GDPR if your request is related to the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective processing of the inquiries addressed to us (Art. 6 para. 1 lit. f) GDPR) or on your consent (Art. 6 para. 1 lit. a) GDPR) if this has been requested.

The data you send to us via contact requests will remain with us until you ask us to delete it, revoke your consent to storage or the purpose for data storage no longer applies (e.g. after your request has been processed). Mandatory statutory provisions - in particular statutory retention periods - remain unaffected.

5. WhatsApp

Zu Kommunikationszwecken nutzen wir den Nachrichtendienst WhatsApp und die damit verbundene technische Plattform von dem Anbieter WhatsApp, Inc., 1601 Willow Road, Menlo Park, California 94025, USA. Die Datenschutzerklärung ist abrufbar unter https://www.whatsapp.com/legal/#privacy-policy. WhatsApp is part of Meta Platforms Ireland Limited, 4 Grand Canal Square Grand Canal Harbour, Dublin 2, Ireland.

Wir sind diesem Kontext selbst nur Nutzer der Dienste und Funktionen, die WhatsApp zur Verfügung stellt. Wir haben keinerlei Einfluss auf die Bedingungen von WhatApp. Dies gilt auch und gerade in Bezug auf die datenschutzrechtlichen Rahmenbedingungen, die mit der Nutzung von WhatsApp verbunden sind. Wenn Sie mit uns über WhatsApp in Kontakt treten, bedeutet dies, dass nicht nur wir mit allen personenbezogenen Daten in Kontakt kommen, die Sie in diesem Kontext offenlegen, sondern auch WhatsApp.

 

Wir haben keinen Einfluss auf die Art und den Umfang der durch den Anbieter verarbeiteten Daten, die Art der Verarbeitung und Nutzung oder die Weitergabe dieser Daten an Dritte, insbesondere in Länder außerhalb der Europäischen Union, in denen u. U. kein angemessenes Datenschutzniveau gewährleistet werden kann.

Angaben darüber, welche Daten durch den Anbieter verarbeitet und zu welchen Zwecken genutzt werden, finden Sie in der Datenschutzerklärung des Dienstes unter folgendem Link: www.whatsapp.com/legal/

These are essentially the following data:

  • Registration data, such as profile name and cell phone number

  • Phone numbers in the cell phone address book

  • Usage and log information (information on the use of the service)

  • Transaction data (e.g. payment receipts)

  • Connection data, such as details of the mobile network

  • Verbindungs- und Geräteinformationen, wie Betriebssystem, Geräte-ID, Geräte-Standort (sofern Standort-Funktionen genutzt werden), Mobilfunk- oder Internetanbieter, Browsertyp, IP-Adresse, Browsertyp

  • Status information ("Last online" status)

  • Your profile picture

  • Your messenger ID

  • The content of the messages sent

By sending the message to our mobile phone number, you consent to us processing your personal data in order to send you information about products and services, as well as for general communication with you.

6. Newsletter

This website uses the service provider sendinblue.com to send newsletters. The provider is Sendinblue GmbH, Köpenicker Straße 126, 10179 Berlin, Germany.

The newsletter contains news, offers and further information on products. By subscribing to the newsletter, you will receive personalized information about our products and services in accordance with your consent. We use this to evaluate your purchase and click behavior on our websites or within the newsletter in order to compile information that is relevant to you.

The newsletter is usually sent out once a month ("regularly"). In individual cases (e.g. in the case of special promotions), weekly contact may also occur.

We also use remarketing measures to show you relevant online advertising.

The data is forwarded to our customer management platform, to which service providers may also have access to support and implement the newsletter.

This collected data is automatically deleted after 24 months if you no longer respond to the newsletter, e.g. open it (inactivity). If you no longer wish to receive the newsletter, you can unsubscribe at any time. To do this, click on the link contained in each newsletter, you will then be guided through the unsubscribe process, or send us your revocation by e-mail.

Legal basis: Art. 6 para. 1 lit. a) GDPR

7. Cookies

Cookie Consent Tool

We use the cookie consent tool from cookiebot.com to obtain effective user consent for cookies and cookie-based applications that require consent. The provider of this technology is Cybot A/S, Havnegade 39, 1058 Copenhagen, Denmark (hereinafter cookiebot.com).

By integrating this tool, users are shown a banner when they access the website, in which they can give their consent for certain cookies and/or cookie-based applications by ticking a box. The tool blocks the setting of all cookies requiring consent until the respective user gives their consent by ticking the box. This ensures that such cookies are only set on your end device if you have given your consent. So that the cookie consent tool can clearly assign page views to individual users and individually record, log and store the consent settings you have made for a session duration, certain user information (including the IP address) is collected when our website is accessed by the cookie consent tool, transmitted to the server of the cookie consent tool provider and stored there. This data processing is carried out in accordance with Art. 6 para. 1 lit. f) GDPR on the basis of our legitimate interest in legally compliant, user-specific and user-friendly consent management for cookies and thus in a legally compliant design of our website. Another legal basis for the data processing described is Art. 6 para. 1 lit. c) GDPR. As the controller, we are subject to the legal obligation to make the use of technically unnecessary cookies dependent on the respective user consent.

By using our website, information (e.g. IP address) may be accessed or information (e.g. cookies) may be stored in your end devices. This access or storage may involve further processing of personal data within the meaning of the GDPR.

In cases where such access to information or such storage of information is absolutely necessary for the technically error-free provision of our services, this is done on the basis of Section 25 (1) sentence 1, (2) no. 2 of the GDPR.

Telecommunications Telemedia Data Protection Act (TTDSG)

The legal basis for the storage and retrieval of information in the end user's terminal equipment is consent, in accordance with Section 25 (1) sentence 1 TTDSG. This consent is requested when the website is accessed.

According to Section 25 (2) No. 2 TTDSG, consent is not required if the storage of information in the end user's terminal equipment or access to information already stored in the end user's terminal equipment is absolutely necessary for the provider of a telemedia service to provide a telemedia service expressly requested by the user. In the cookie settings, you can see which cookies are to be classified as absolutely necessary (often also referred to as "technically necessary cookies") and therefore fall under the exception rule of Section 25 (2) TTDSG and therefore do not require consent. Please note that the legal basis for the downstream processing of personal data then results from the GDPR. The relevant legal bases for the processing of personal data on this website can be found further on in this privacy policy.

Use of cookies

In addition to the aforementioned data, cookies or similar technologies such as pixels (hereinafter generally referred to as "cookies") are used on your computer when you use and visit our website. Cookies are either small databases that are stored by your browser on your end device to store certain information, or image files such as pixels. The next time you visit our website with the same end device, the information stored in cookies is subsequently sent back either to our website ("first party cookie") or to another website to which the cookie belongs ("third party cookie").

The stored and returned information enables the respective website to recognize that you have already accessed and visited it with the browser of your end device. We use this information to optimize the design and display of the website according to your preferences. Only the cookie itself is identified on your end device. Any further storage of personal data will only take place with your express consent or if this is absolutely necessary in order to be able to use the service offered and accessed by you accordingly.

This website uses the following types of cookies, the scope and function of which are explained below:

  • Strictly necessary cookies (type a)

  • Functional and performance cookies (type b)

  • Cookies requiring consent (type c)

Strictly necessary cookies (type a)

Strictly necessary cookies guarantee functions without which you cannot use our websites as intended. These cookies are used exclusively by us and are therefore first party cookies. This means that all information stored in the cookies is sent back to our website.

Strictly necessary cookies are used, for example, to ensure that you as a registered user always remain logged in when accessing various subpages of our website and thus do not have to re-enter your login data each time you access a new page.

The use of strictly necessary cookies on our website is possible without your consent. For this reason, strictly necessary cookies cannot be deactivated or activated individually. However, you have the option of generally deactivating cookies in your browser at any time (see below).

Functional and performance cookies (type b)

Functional cookies enable our website to save information you have already entered (such as your registered name or language selection) and to offer you improved and more personalized functions based on this. These cookies only collect and store anonymized information so that they cannot track your movements on other websites.

Performance cookies collect information about how our websites are used in order to improve their attractiveness, content and functionality. These cookies help us, for example, to determine whether and which subpages of our website are visited and what content users are particularly interested in. In particular, we record the number of visits to a page, the number of subpages accessed, the time spent on our website, the order of the pages visited, which search terms led you to us, the country, region and, if applicable, the city from which the access is made, as well as the proportion of mobile devices that access our websites. We also record movements, "clicks" and scrolling with the computer mouse in order to understand which areas of our website are of particular interest to users. As a result, we can tailor the content of our website more specifically to the needs of our users and optimize our offering. The IP address of your computer transmitted for technical reasons is automatically anonymized and does not allow us to draw any conclusions about the individual user.

You can object to the use of functional and performance cookies at any time by adjusting your cookie settings accordingly.

Legal basis: Art. 6 para. 1 lit. f) GDPR

Cookies requiring consent (type c)

Cookies that are neither strictly necessary (type a) nor functional or performance cookies (type b) will only be used with your consent.

We also reserve the right to use information that we have obtained by means of cookies from an anonymized analysis of the usage behavior of visitors to our websites in order to display specific advertising for certain of our products on our own websites. We believe that you as a user benefit from this because we display advertising or content that we assume, based on your surfing behavior, matches your interests and you are thus shown less randomly scattered advertising or certain content that may be of less interest to you.

Marketing cookies come from external advertising companies (third party cookies) and are used to collect information about the websites visited by the user in order to create targeted advertising for the user.

Legal basis: Art. 6 para. 1 lit. a) GDPR

Opt-out for marketing cookies

You can also use cookies that are used for online advertising via the tools developed in many countries as part of self-regulatory programs, such as the US-based https://www.aboutads.info/choices/ or the EU-based http://www.youronlinechoices.com/uk/your-ad-choices manage.

Legal basis: Art. 6 para. 1 lit. a) GDPR

Management and deletion of all cookies

In addition, you can set your Internet browser so that the storage of cookies is generally prevented on your end device or you are asked each time whether you agree to the setting of cookies. Once cookies have been set, you can also delete them at any time. You can find out how all this works in detail in the help function of your browser.

We use the following cookies described here for the following purposes:

Google Analytics

This website uses Google Analytics, a web analysis service of Google Inc ("Google"). Google Analytics uses so-called "cookies", small databases which are stored on your computer and which enable your use of the website to be analyzed. The information generated by the cookie about your use of this website is transmitted to a Google server in the USA and stored there. However, if IP anonymization is activated on this website, your IP address will be shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and truncated there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, to compile reports on website activity and to provide other services relating to website activity and internet usage to the website operator.

The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.

You may refuse the use of cookies by selecting the appropriate settings on your browser, however please note that if you do this you may not be able to use the full functionality of this website. You can also prevent the transmission of the data generated by the cookie and related to your use of the website (including your IP address) to Google and the processing of this data by Google by downloading and installing the browser plug-in available at the following link: http://tools.google.com/dlpage/gaoptout?hl=de.

This website uses Google Analytics with the extension "_anonymizeIp()". This means that IP addresses are further processed in abbreviated form, so that they cannot be linked to a specific person. If the data collected about you is personally identifiable, it is immediately excluded and the personal data is deleted immediately. We use Google Analytics to analyze and regularly improve the use of our website. We can use the statistics obtained to improve our offer and make it more interesting for you as a user. This website also uses Google Analytics for a cross-device analysis of visitor flows, which is carried out via a user ID. You can deactivate the cross-device analysis of your usage in your customer account under "My data", "Personal data".

The provider has signed the standard contractual clauses of the prevailing EU data protection regulations (https://ec.europa.eu/info/law/law-topic/data-protection/publications/standard-contractual-clauses-controllers-and-processors).

Information from the third-party provider: Google Dublin, Google Ireland Ltd, Gordon House, Barrow Street, Dublin 4, Ireland, Fax: +353 (1) 436 1001. user conditions:

http://www.google.com/analytics/terms/de.html, Overview of data protection: http://www.google.com/intl/de/analytics/learn/privacy.html, and the data protection information: http://www.google.de/intl/de/policies/privacy

Legal basis: Art. 6 para. 1 lit. a) GDPR

Google Analytics with advertising functions

If you consent to the use of the Google Analytics advertising functions, this website also uses the extended functions of Google Analytics in addition to the standard functions. The Google Analytics advertising features implemented on this website include the Google Analytics reports on performance by demographics and interests.

We use first-party cookies (e.g. Google Analytics cookies) and third-party cookies (e.g. DoubleClick cookies) together to evaluate the demographic characteristics and interests of visitors to our website in anonymized and aggregated form. We use this information to improve our web offerings.

You can prevent participation in this tracking process in various ways: a) by setting your browser software accordingly; b) via the Google ad settings on https://www.google.com/ads/preferences/?hl=de deactivate c) by means of the corresponding cookie setting [link to cookie settings page]. We would like to point out that in this case you may not be able to use all functions of this website to their full extent.

Legal basis: Art. 6 para. 1 lit. a) GDPR

Google Ads Conversion

We use the Google Ads Conversion service to draw attention to our attractive offers with the help of advertising material (so-called Google Ads) on external websites. We can determine how successful the individual advertising measures are in relation to the advertising campaign data. We are interested in showing you advertising that is of interest to you, making our website more interesting for you and achieving a fair calculation of advertising costs.

These advertisements are delivered by Google via so-called "ad servers". For this purpose, we use ad server cookies, through which certain parameters for measuring success, such as the display of ads or clicks by users, can be measured. If you access our website via a Google ad, Google Ads will store a cookie on your end device. These cookies generally lose their validity after 30 days and are not intended to identify you personally. The unique cookie ID, number of ad impressions per placement (frequency), last impression (relevant for post-view conversions) and opt-out information (marking that the user no longer wishes to be addressed) are usually stored as analysis values for this cookie.

These cookies enable Google to recognize your internet browser. If a user visits certain pages of an Ads customer's website and the cookie stored on their computer has not yet expired, Google and the customer can recognize that the user clicked on the ad and was redirected to this page. A different cookie is assigned to each Ads customer. Cookies can therefore not be tracked via the websites of Ads customers. We ourselves do not collect and process any personal data in the aforementioned advertising measures. We only receive statistical evaluations from Google. Based on these evaluations, we can recognize which of the advertising measures used are particularly effective. We do not receive any further data from the use of the advertising material; in particular, we cannot identify users on the basis of this information.

Due to the marketing tools used, your browser automatically establishes a direct connection with the Google server. We have no influence on the scope and further use of the data collected by Google through the use of this tool and therefore inform you according to our level of knowledge: Through the integration of Ads Conversion, Google receives the information that you have accessed the corresponding part of our website or clicked on an advertisement from us. If you are registered with a Google service, Google can assign the visit to your account. Even if you are not registered with Google or have not logged in, there is a possibility that the provider will find out and store your IP address.

Information from the third-party provider: Google Dublin, Google Ireland Ltd, Gordon House, Barrow Street, Dublin 4, Ireland, Fax: +353 (1) 436 1001.

Legal basis: Art. 6 para. 1 lit. a) GDPR

Google Remarketing

We use the Google Remarketing application. This is a procedure with which we would like to address you again within 24 months. This application allows our advertisements to be displayed to you when you continue to use the Internet after visiting our website. This is done by means of cookies stored in your browser, which are used by Google to record and evaluate your usage behavior when you visit various websites. This enables Google to determine your previous visit to our website. According to its own statements, Google does not merge the data collected in the context of remarketing with your personal data, which may be stored by Google. In particular, according to Google, pseudonymization is used in remarketing.

You can prevent participation in this tracking process in various ways: a) by setting your browser software accordingly; in particular, the suppression of third-party cookies means that you will not receive any ads from third-party providers; b) by installing the plug-in provided by Google under the following link: https://www.google.com/settings/ads/plugin; c) by deactivating the interest-based ads of providers that are part of the "About Ads" self-regulation campaign via the link http://www.aboutads.info/choices, whereby this setting is deleted when you delete your cookies; d) by permanently deactivating them in your Firefox, Internet Explorer or Google Chrome browsers under the link http://www.google.com/settings/ads/plugin, e) by means of a corresponding cookie setting. We would like to point out that in this case you may not be able to use all functions of this website to their full extent.

Information from the third-party provider: Google Dublin, Google Ireland Ltd, Gordon House, Barrow Street, Dublin 4, Ireland, Fax: +353 (1) 436 1001.

Further information on data protection at Google can be found here: http://www.google.com/intl/de/policies/privacy and https://services.google.com/sitestats/de.html. Alternatively, you can visit the website of the Network Advertising Initiative (NAI) at http://www.networkadvertising.org visit.

Legal basis: Art. 6 para. 1 lit. a) GDPR

Facebook fan page

We have integrated a component of the Facebook service on our website, which is a link to our Facebook fan page. We use the technical platform of Meta Platforms Ireland Limited, 4 Grand Canal Square Grand Canal Harbour, Dublin 2, Ireland (hereinafter: Facebook) for the information service offered here.

According to the ECJ, there is joint responsibility within the meaning of Art. 26 GDPR between Facebook and the operator of a Facebook fan page for the personal data processed via the Facebook fan page. For this reason, Facebook and we have concluded an agreement on joint responsibility, which you can access here. We provide you with the following information on data processing on our Facebook fan page:

The processing of your personal data on the Facebook fan page is carried out under joint responsibility with Meta Platforms Ireland Limited, 4 Grand Canal Square Grand Canal Harbour, Dublin 2, Ireland

When you access a Facebook fan page, the IP address of your end device is transmitted to Facebook. According to Facebook, this IP address is anonymized and deleted after 90 days, at least if it is a German IP address. In addition, Facebook stores further information about the end devices of its users, e.g. the Internet browser used. This may enable Facebook to assign IP addresses to individual users. If you are logged into your Facebook account while visiting our fan page, a cookie with your Facebook ID will be stored on your device. This cookie enables Facebook to understand that you have visited our fan page and how you have used it. Facebook uses this information to present you with customized content or advertising. If you do not want this, you should log out of your Facebook account or deactivate the "stay logged in" function. We also recommend deleting the cookies on your device and closing and restarting your browser. This process deletes Facebook information that Facebook can use to establish a link to you. However, if you wish to use the interactive functions of our fan page, you will have to log in to Facebook again using your Facebook login information. This will also allow Facebook to create a link to you again. How Facebook uses the data from visits to Facebook pages for its own purposes, to what extent activities on the Facebook page are assigned to individual users, how long Facebook stores this data and whether data from a visit to the Facebook page is passed on to third parties is not conclusively and clearly stated by Facebook and is not known to us. In this respect, we can only refer you as a user of our fan page to Facebook's privacy policy. The data collected about you in this context is processed by Facebook and may be transferred to countries outside the European Union.

Facebook describes in general terms what information Facebook receives and how it is used in its data usage guidelines. There you will also find information on how to contact Facebook and the settings options for advertisements. The data usage guidelines are available at the following link: http://de-de.facebook.com/about/privacy. You can find Facebook's complete data policy here: https://de-de.facebook.com/full_data_use_policy. Facebook's privacy policy contains further information on data processing: https://www.facebook.com/about/privacy/ Objection options (so-called opt-out) can be set here: https://www.facebook.com/settings?tab=ads and here http://www.youronlinechoices.com

The transfer and further processing of users' personal data to third countries, such as the USA, and the associated potential risks for you as a user cannot be assessed by us as the operator of the Facebook fan page.

Insight function

Facebook also provides a range of statistical data for fan page operators as part of the "Insights" function. These statistics are generated and provided by Facebook. As the operator of the fan page, we have no influence on the generation of this data and, in particular, we cannot prevent this function. As part of the "Insights" function, we are shown the following information for the categories "Fans", "Subscribers", "People reached" and "People interacting" for a selectable period of time: Page activities such as page views, page previews, actions on the page; reach activities such as "likes", people reached and recommendations, post activities such as post interactions, video views, comments, shared content. In addition, we are provided with statistical information about the Facebook groups that are linked to our fan page. In accordance with the Facebook terms of use, which every user has agreed to when creating a Facebook profile, we can also identify the subscribers and fans of the page and view their profiles and other information shared by them. Facebook provides more information on this under the following link: http://de-de.facebook.com/help/pages/insights.

We use this data, which is available in aggregated form, to make posts and activities on the fan page more attractive to users, e.g. to plan the content and timing of posts.

We store the information transmitted by Facebook at most as long as your interest in deletion or anonymization does not prevail. If you no longer wish the data processing described here to take place in the future, please remove the link between your user profile and our fan page by using the functions "No longer like this page" and/or "No longer subscribe to this page".

We recommend that you address any requests for information or other questions regarding your rights listed at the end of this privacy policy directly to Facebook, as only Facebook has full access to user data. Should you nevertheless address your request to us, it will of course still be processed and also forwarded to Facebook.

Facebook Pixel

We use the Facebook advertising function. Meta Platforms Ireland Limited, Hanover Reach, 5-7 Hanover Quay, Dublin 2, Ireland is responsible for the German website facebook.de.

The website uses the remarketing function "Custom Audiences" of Facebook Inc. ("Facebook") in order to be able to address you again within 6 months. This allows users of the website to be shown interest-based advertisements ("Facebook ads") when they visit the Facebook social network or other websites that also use the process. We are interested in showing you advertisements that are of interest to you in order to make our website more interesting for you.

Due to the marketing tools used, your browser automatically establishes a direct connection with the Facebook server. We have no influence on the scope and further use of the data collected by Facebook through the use of this tool and therefore inform you according to our state of knowledge: Through the integration of Facebook Custom Audiences, Facebook receives the information that you have accessed the corresponding website of our Internet presence or have clicked on an advertisement from us. If you are registered with a Facebook service, Facebook can assign the visit to your account. Even if you are not registered with Facebook or have not logged in, there is a possibility that the provider will find out and store your IP address and other identifying features.

The provider has signed the standard contractual clauses of the prevailing EU data protection regulations (https://ec.europa.eu/info/law/law-topic/data-protection/publications/standard-contractual-clauses-controllers-and-processors).

We have concluded an agreement with Facebook on joint responsibility for the collection and processing of personal data within the meaning of Art. 26 GDPR. Further information can be found in the link Agreement on joint processing of personal data. You can find the privacy policy here: https://www.facebook.com/about/privacy/

You can deactivate the "Facebook Custom Audiences" function here and for logged-in users at https://www.facebook.com/settings/?tab=ads#_ possible.

Further information on data processing by Facebook can be found at https://www.facebook.com/about/privacy

Legal basis: Art. 6 para. a) GDPR.

YouTube

We have integrated videos from the provider Youtube, Google Ireland Limited Gordon House, Barrow Street Dublin 4, Ireland, into our online offer, which are available on http://www.YouTube.com and can be played directly from our website. These are all integrated in "extended data protection mode", i.e. no data about you as a user is transferred to YouTube if you do not play the videos. Only when you play the videos will the data mentioned in the next paragraph be transmitted. We have no influence on this data transfer. The purpose of the processing is for marketing purposes.

When you visit the website, YouTube receives the information that you have accessed the corresponding subpage of our website. This occurs regardless of whether YouTube provides a user account through which you are logged in or whether no user account exists. If you are logged in to Google, your data will be assigned directly to your account. If you do not wish your data to be associated with your YouTube profile, you must log out before activating the button. YouTube stores your data as usage profiles and uses them for the purposes of advertising, market research and/or the needs-based design of its website. Such an evaluation is carried out in particular (even for users who are not logged in) to provide needs-based advertising and to inform other users of the social network about your activities on our website. You have the right to object to the creation of these user profiles, whereby you must contact YouTube to exercise this right.

Further information on the purpose and scope of data collection and its processing by YouTube can be found in YouTube's privacy policy. There you will also find further information on your rights and setting options to protect your privacy:
https://policies.google.com/privacy

In order to establish an adequate level of security, your consent may serve as the legal basis for the transfer to third countries in accordance with Art. 49 para. 1 lit. a) GDPR.

To protect your rights and personal data, we have integrated YouTube with a so-called two-click solution, which only transmits data to Google after you have explicitly activated the video function.

Furthermore, Google offers a range of options for objecting to the collection of personal data by Google: https://policies.google.com/privacy#infochoices

Legal basis: Art. 6 para. 1 lit. a) GDPR

8. Data protection information for applicants

We are pleased that you are interested in us and that you are applying or have applied for a position in our company. We would like to provide you with the following information on the processing of your personal data in connection with your application.

Which of your data do we process? And for what purposes?

We process the data that you have sent us in connection with your application in order to check your suitability for the position (or any other open positions in our company) and to carry out the application process.

What is the legal basis for this?

The legal basis for the processing of your personal data in this application procedure is primarily Section 26 BDSG. This permits the processing of data required in connection with the decision on the establishment of an employment relationship.

Should the data be required for legal prosecution after completion of the application process, data processing may be carried out on the basis of the requirements of Art. 6 GDPR, in particular to safeguard legitimate interests in accordance with Art. 6 para. 1 lit. f) GDPR. Our interest then lies in the assertion of or defense against claims.

How long will the data be stored?

Applicants' data will be deleted after 6 months in the event of rejection.

In the event that you have consented to further storage of your personal data, we will transfer your data to our applicant pool. There the data will be deleted after two years.

If you have been accepted for a position as part of the application process, the data from the applicant data system will be transferred to our personnel information system.

To which recipients is the data forwarded?

Your application data will be reviewed by the HR department after receipt of your application. Suitable applications are then forwarded internally to the department managers responsible for the respective open position. The next steps are then agreed. Within the company, only those persons have access to your data who need it for the proper course of our application procedure.

Where is the data processed?

The data is processed exclusively in data centers in the Federal Republic of Germany.

9. Definition

The legislator requires that personal data be processed lawfully, fairly and in a manner that is comprehensible to the data subject ("lawfulness, fairness and transparency"). To ensure this, we inform you about the individual legal definitions that are also used in this data protection notice:

Personal data

"Personal data" means any information relating to an identified or identifiable natural person (hereinafter referred to as "data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

Processing

"Processing" means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

Restriction of processing

"Restriction of processing" is the marking of stored personal data with the aim of restricting its future processing.

Profiling

"Profiling" means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location or movements.

Pseudonymization

"Pseudonymization" means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the personal data are not attributed to an identified or identifiable natural person.

File system

"File system" means any structured collection of personal data that is accessible according to specific criteria, regardless of whether this collection is managed centrally, decentrally or according to functional or geographical aspects.

Responsible

"Controller" means a natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.

Processor

"Processor" means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.

Recipient

"Recipient" means a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients; the processing of those data by those public authorities shall be in compliance with the applicable data protection rules according to the purposes of the processing.

Third

"Third party" means a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorized to process personal data.

Data Privacy Consent

Consent" of the data subject is any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.

10. Children

Our services are generally aimed at adults. Persons under the age of 18 should not transmit any personal data to us without the consent of their parents or legal guardians.

11. Legal effectiveness

If sections or individual terms of this statement are not legal or correct, the content or validity of the other parts remain uninfluenced by this fact.