Privacy Policy
Table of contents
- Preamble
- Data controller
- Overview of data processing
- Relevant legal bases
- Security Measures
- Transfer of Personal Data
- Data Processing in Third Countries
- Deletion of Data
- Use of Cookies
- Providers and Services Used in the Course of Business Activities
- Payment Methods
- Provision of the online service and web hosting
- Contact and enquiry management
- Newsletters and electronic notifications
- Marketing communications via email, post, fax or telephone
- Prize draws and competitions
- Web analytics, monitoring and optimisation
- Online marketing
- Customer reviews and rating procedures
- Plugins, embedded functions and content
- Amendments and updates to the privacy policy
- Rights of data subjects
- Definitions of terms
Data controller
Manuela Pieper-Meißner and Dominik MeißnerAnnastraße 15
66663 Merzig
Saarland
Email: management@saar-apartments.com
Legal notice: https://www.saar-apartments.com/en/impressum.php
Overview of data processing activities
The following overview summarises the types of data processed and the purposes of such processing, and refers to the data subjects.Types of data processed
- Personal details.
- Payment details.
- Contact details.
- Content data.
- Contract details.
- Usage data.
- Meta, communication and procedural data.
Categories of data subjects
- Customers.
- Prospective customers.
- Communication partners.
- Users.
- Participants in prize draws and competitions.
- Business and contractual partners.
Purposes of processing
- Provision of contractual services and customer service.
- Enquiries and communication.
- Security measures.
- Direct marketing.
- Audience measurement.
- Tracking.
- Office and organisational procedures.
- Conversion measurement.
- Target group segmentation.
- Managing and responding to enquiries.
- Running prize draws and competitions.
- Feedback.
- Marketing.
- Profiles containing user-related information.
- Provision of our online services and user-friendliness.
- IT infrastructure.
Relevant legal bases
Below you will find an overview of the legal bases under the GDPR on which we process personal data. Please note that, in addition to the provisions of the GDPR, national data protection regulations in your or our country of residence or registered office may apply. Should more specific legal bases apply in individual cases, we will inform you of these in the privacy policy.- Consent (Article 6(1), first sentence, point (a) of the GDPR) – The data subject has given their consent to the processing of personal data relating to them for a specific purpose or several specific purposes.
- Performance of a contract and pre-contractual enquiries (Art. 6( 1(1)(b) of the GDPR) – The processing is necessary for the performance of a contract to which the data subject is a party, or for the implementation of pre-contractual measures taken at the data subject’s request.
- Legitimate interests (Art. 6(1), first sentence, point (f) of the GDPR) – Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.
Security measures
In accordance with statutory requirements, and taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing, as well as the varying likelihood and severity of threats to the rights and freedoms of natural persons, we implement appropriate technical and organisational measures to ensure a level of protection appropriate to the risk. These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data, as well as the access, input, disclosure, availability and segregation of such data. Furthermore, we have established procedures to ensure that data subjects’ rights are upheld, that data is deleted, and that appropriate action is taken in the event of a data breach. We also take the protection of personal data into account right from the development or selection of hardware, software and procedures, in accordance with the principle of data protection by design and by default. IP address truncation: Where IP addresses are processed by us or by the service providers and technologies we use, and the processing of a full IP address is not necessary, the IP address is truncated (also referred to as ‘IP -masking”). In this process, the last two digits, or the last part of the IP address following a full stop, are removed or replaced with placeholders. The purpose of truncating the IP address is to prevent or make it significantly more difficult to identify an individual on the basis of their IP address. TLS encryption (https): To protect the data you transmit via our online service, we use TLS encryption. You can recognise such encrypted connections by the prefix https:// in your browser’s address bar.Transfer of personal data
As part of our processing of personal data, the data may be transferred to other bodies, companies, legally independent organisational units or individuals or disclosed to them. Recipients of this data may include, for example, service providers commissioned with IT tasks or providers of services and content integrated into a website. In such cases, we comply with the statutory requirements and, in particular, conclude appropriate contracts or agreements with the recipients of your data to ensure the protection of your data.Data processing in third countries
Where we process data in a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)), or where processing takes place in connection with the use of third-party services or the disclosure or transfer of data to other individuals, bodies or organisations, this is done solely in accordance with the legal requirements. Subject to express consent or where transfer is required by contract or law, we process or arrange for the processing of data only in third countries with a recognised level of data protection, contractual obligations through the European Commission’s so-called standard data protection clauses, where certifications are in place, or where binding internal data protection regulations apply (Articles 44 to 49 of the GDPR; European Commission information page: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection_de).Deletion of data
The data we process is deleted in accordance with statutory requirements as soon as the consent permitting its processing is withdrawn or other authorisations cease to apply (e.g. if the purpose for which the data is being processed no longer applies or if the data is no longer required for that purpose). Where the data is not deleted because it is required for other, legally permissible purposes, its processing is restricted to those purposes. D. i.e. the data will be blocked and not processed for any other purposes. This applies, for example, to data which must be retained for commercial or tax law reasons, or where storage is necessary to establish, exercise or defend legal claims, or to protect the rights of another natural or legal person. Our privacy policy may also contain further details regarding the retention and deletion of data, which take precedence over the provisions set out here for the respective processing operations.Use of cookies
Cookies are small text files or other storage markers that store information on end devices and retrieve information from them. For example, to store the login status in a user account, the contents of a shopping basket in an e shop, the content accessed or the functions used on an online service. Cookies may also be used for various purposes, such as ensuring the functionality, security and convenience of online services, as well as for analysing visitor traffic. Information on consent: We use cookies in accordance with statutory provisions. We therefore obtain prior consent from users, unless this is not required by law. In particular, consent is not necessary if the storage and retrieval of information – including cookies – are strictly necessary to provide users with a telemedia service (i.e. our online service). The revocable consent is clearly communicated to users and contains information on the respective use of cookies. Information on legal bases under data protection law: The legal basis under data protection law on which we process users’ personal data using cookies depends on whether we ask users for their consent. If users give their consent, the legal basis for the processing of their data is that expressed consent. Otherwise, the data processed using cookies is processed on the basis of our legitimate interests (e.g. e.g. the efficient operation of our online service and improving its usability) or, where this takes place in the context of fulfilling our contractual obligations, where the use of cookies is necessary to fulfil our contractual obligations. We explain the purposes for which we process cookies in the course of this privacy policy or as part of our consent and processing procedures. Retention period: With regard to the retention period, a distinction is made between the following types of cookies:- Temporary cookies (also known as session cookies): Temporary cookies are deleted at the latest once a user has left an online service and closed their device (e.g. browser or mobile application).
- Persistent cookies: Persistent cookies remain stored even after the device has been closed. This allows, for example, the login status to be saved or preferred content to be displayed directly when the user visits a website again. Similarly, user data collected via cookies may be used for audience measurement. Unless we provide users with explicit information regarding the type and storage duration of cookies (e.g. when seeking consent), users should assume that cookies are permanent and may be stored for up to two years.
- Types of data processed: Usage data (e.g. websites visited, interest in content, access times); meta, communication and process data (e.g. IP addresses, timestamps, identification numbers, consent status).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing: Provision of our online services and user-friendliness.
- Legal bases: Legitimate interests (Art. 6(1), first sentence, point (f) of the GDPR).
- Cookie opt-out: In the footer of our website, you will find a link allowing you to change your cookie settings and withdraw your consent; Legal bases: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).
- Real Cookie Banner: Cookie consent management; Service provider: devowl.io GmbH, Tannet 12, 94539 Grafling, Germany; Legal basis: Legitimate interests (Art. 6(1) sentence 1(f) GDPR); Website:https://devowl.io/de/wordpress-real-cookie-banner/; Privacy policy: https://devowl.io/de/datenschutzerklaerung/.
Providers and services used in the course of our business activities
In the course of our business activities, we use additional third-party services, platforms, interfaces or plug-ins (hereinafter referred to as “services”) in compliance with legal requirements. Their use is based on our interests in the proper, lawful and efficient management of our business operations and our internal organisation.- Types of data processed: Master data (e.g. names, addresses); payment data (e.g. bank details, invoices, payment history); contact details (e.g. email, telephone numbers); content data (e.g. entries in online forms); contract data (e.g. subject matter of the contract, term, customer category) ; usage data (e.g. websites visited, interest in content, access times); meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, consent status).
- Data subjects: customers; prospective customers; users (e.g. website visitors, users of online services); business and contractual partners; communication partners.
- Purposes of processing: Provision of contractual services and customer service; Office and organisational procedures; contact enquiries and communication; conversion tracking (measuring the effectiveness of marketing measures); marketing; provision of our online offering and user-friendliness; direct marketing (e.g. by email or post); audience measurement (e.g. access statistics, identification of returning visitors); Target group segmentation.
- Legal bases: Legitimate interests (Art. 6(1), first sentence, point (f) of the GDPR).
- DIRS21: Software for making and managing bookings directly or via third-party platforms, as well as for booking management and customer support; Service provider: TourOnline AG, Borsigstraße 26, 73249 Wernau, Germany; Legal basis: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR); Website:https://www.dirs21.de/ ; Privacy Policy: https://www.dirs21.de/datenschutz/.
- 3RPMS: Cloud-based software for managing hotels, inns, guesthouses, B&Bs and other accommodation providers, managing bookings and guest services, invoicing and accounting interfaces; Service provider: HaDre GmbH, Bauerngasse 32, 90443 Nuremberg, Germany; Website:https://3rpms-hotelsoftware.de/ ; Privacy Policy: https://3rpms-hotelsoftware.de/datenschutz/.
- VIATO BookingEngine: Provision, processing and management of online bookings; Service provider: Viato GmbH, Burkheimer Str. 3, 79111 Freiburg, Germany; Legal basis: Legitimate interests (Art. 6(1)(f) GDPR); Website: https://www.viato.net/produkte/bookingengine/; Privacy policy:https://www.viato.net/datenschutz/.
- Feratel: Tourism-related services (sales and marketing support, loyalty cards and customer loyalty programmes, communication and direct marketing via various channels (multi-channel), data analysis); Service provider: feratel media technologies AG, Maria-Theresien-Straße 8, 6020 Innsbruck, Austria; Legal basis: Legitimate interests (Art. 6(1), first sentence, point (f) of the GDPR); Website: https://www.feratel.at/; Privacy policy:https://www.feratel.at/datenschutz/.
- Saarland Tourist Board: Saarland Card: If guests do not wish to receive the Saarland Card, they must actively opt out by emailing booking@saar-apartments.com. Legal basis: performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR); Service provider: Saarland Tourist Board GmbH, Trierer Str. 10, 66111 Saarbrücken; Website: https://www.urlaub. saarland/Reisefuehrer/Saarland-Card; Privacy Policy:https: //www.urlaub.saarland/Reisefuehrer/Saarland-Card/Datenschutz-Saarland-Card.
- SALTO KS: electronic locking system with real-time access control based on remote control and authorisation categories; Legal basis: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR); Service provider:SALTO Systems, S.L, C/ Arkot z 9, Polígono Lanbarren 20180 Oiartzun, Gipuzkoa, Spain; Website: https://saltosystems.com/; Privacy Policy: https://saltosystems.com/de/rechtliche-hinweise/datenschutz/privacy-policies/salto-systems/.
Payment methods
Within the framework of contractual and other legal relationships, on the basis of statutory obligations or otherwise on the basis of our legitimate interests, we offer data subjects efficient and secure payment options and, for this purpose, engage banks, credit institutions and other service providers (collectively referred to as ‘payment service providers’). The data processed by the payment service providers includes master data, such as e.g. name and address, bank details such as account numbers or credit card numbers, passwords, TANs and checksums, as well as details relating to the contract, the amount and the recipient. This information is required to carry out the transactions. However, the data entered is processed and stored solely by the payment service providers. This means that we do not receive any account- or credit card-related information, but only information confirming the payment or indicating that the payment has been declined. In some circumstances, the data may be passed on by the payment service providers to credit reference agencies. The purpose of this transfer is to verify identity and creditworthiness. In this regard, we refer you to the terms and conditions and privacy policies of the payment service providers. Payment transactions are governed by the terms and conditions and privacy policies of the respective payment service providers, which are available on their respective websites or within the transaction applications. We also refer you to these for further information and to exercise your rights of withdrawal, access, and other data subject rights.- Types of data processed: Master data (e.g. names, addresses); payment data (e.g. bank details, invoices, payment history); contract data (e.g. subject matter of the contract, term, customer category); usage data (e.g. websites visited, interest in content, access times); meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, consent status).
- Data subjects: customers; prospective customers.
- Purposes of processing: Provision of contractual services and customer service.
- Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1), first sentence, point (b) of the GDPR).
- PayPal: payment services (technical integration of online payment methods) (e.g. PayPal, PayPal Plus, Braintree); Service provider: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg; Legal basis:Fulfilment of a contract and pre-contractual enquiries (Article 6(1), first sentence, point (b) of the GDPR) ; Website: https://www.paypal.com/ de; Privacy Policy: https://www.paypal.com/de/webapps/mpp/ua/privacy-full.
- Stripe: Payment services (technical integration of online payment methods); Service provider: Stripe, Inc., 510 Townsend Street, San Francisco, CA 94103, USA; Legal basis: performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR); Website: https://stripe.com; Privacy Policy: https://stripe.com/de/privacy.
Provision of the online service and web hosting
We process users’ data in order to provide them with our online services. For this purpose, we process the user’s IP address, which is necessary to transmit the content and functions of our online services to the user’s browser or device.- Types of data processed: usage data (e.g. webpages visited, interest in content, access times); meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, consent status).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing: Provision of our online offering and user-friendliness; IT infrastructure (operation and provision of information systems and technical equipment (computers, servers, etc.)); security measures.
- Legal bases: Legitimate interests (Art. 6(1), first sentence, point (f) of the GDPR).
- Provision of online services on rented server space: To provide our online services, we use server space, computing capacity and software which we rent or otherwise obtain from a relevant server provider (also known as a ‘web host’); Legal bases: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).
- Collection of access data and log files: Access to our online offering is logged in the form of so-called ‘server log files’. Server log files may include the address and name of the web pages and files accessed, the date and time of access, the volume of data transferred, a notification of successful access, the browser type and version, the user’s operating system, the referrer URL (the previously visited page) and, as a rule, IP addresses and the requesting provider. The server log files may be used, on the one hand, for security purposes, e.g., to prevent the servers from becoming overloaded (particularly in the event of malicious attacks, known as DDoS attacks) and, secondly, to ensure the servers’ capacity utilisation and stability; Legal basis: Legitimate interests (Art. 6(1), first sentence, point (f) GDPR); Deletion of data: Log file information is stored for a maximum of 30 days and is subsequently deleted or anonymised. Data which must be retained for evidential purposes is exempt from deletion until the respective incident has been fully resolved.
Contact and enquiry management
When you contact us (e.g. by post, contact form, email, telephone or via social media), as well as in the context of existing user and business relationships, the details of the enquirers are processed to the extent necessary to respond to the contact enquiries and any requested actions.- Types of data processed: Contact details (e.g. email, telephone numbers); content data (e.g. entries in online forms); usage data (e.g. web pages visited, interest in content, access times); meta, communication and process data (e.g. IP addresses, timestamps, identification numbers, consent status).
- Data subjects: Communication partners.
- Purposes of processing: Contact enquiries and communication; managing and responding to enquiries; feedback (e.g. collecting feedback via online forms); provision of our online services and user-friendliness.
- Legal bases: Legitimate interests (Art. 6(1), first sentence, point (f) of the GDPR); performance of a contract and pre-contractual enquiries (Art. 6(1), first sentence, point (b) of the GDPR).
- Contact form: When users contact us via our contact form, by email or through other communication channels, we process the data provided to us in this context in order to deal with the matter raised; Legal bases: Performance of a contract and pre-contractual enquiries (Article 6(1), first sentence, point (b) of the GDPR), legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).
Newsletters and electronic notifications
We send out newsletters, emails and other electronic notifications (hereinafter ‘newsletters’) only with the consent of the recipients or where permitted by law. Where the content of a newsletter is specifically described as part of the subscription process, this content forms the basis for the user’s consent. Furthermore, our newsletters contain information about our services and our organisation. To subscribe to our newsletters, it is generally sufficient to provide your email address. However, we may ask you to provide a name, so that we can address you personally in the newsletter, or further details, provided these are necessary for the purposes of the newsletter. Double opt-in procedure: Subscription to our newsletter generally takes place via a so-called double opt-in procedure. This means that, after subscribing, you will receive an email asking you to confirm your subscription. This confirmation is necessary to ensure that nobody can subscribe using someone else’s email address. Newsletter subscriptions are logged so that we can provide evidence of the subscription process in accordance with legal requirements. This includes recording the time of subscription and confirmation and the IP address. Any changes to your data stored with the email service provider are also logged. Deletion and restriction of processing: We may store the email addresses of those who have unsubscribed email addresses for up to three years on the basis of our legitimate interests before deleting them, in order to be able to provide evidence of consent that was previously given. The processing of this data is restricted to the purpose of potentially defending against claims. An individual request for erasure may be made at any time, provided that the prior existence of consent is confirmed at the same time. In the event of obligations to permanently comply with objections, we reserve the right to store the email address solely for this purpose in a block list (so-called ‘blocklist ”). The registration process is logged on the basis of our legitimate interests for the purpose of verifying that it was carried out correctly. Where we engage a service provider to send emails, this is done on the basis of our legitimate interests in an efficient and secure mailing system. Content: Information about us, our services, promotions and offers.- Types of data processed: Master data (e.g. names, addresses); contact details (e.g. email, telephone numbers); meta, communication and process data (e.g. IP addresses, time stamps, identification numbers, consent status); usage data (e.g. websites visited, interest in content, access times).
- Data subjects: Communication partners; users (e.g. website visitors, users of online services).
- Purposes of processing: Direct marketing (e.g. by email or post); audience measurement (e.g. access statistics, identification of returning visitors); conversion measurement (measuring the effectiveness of marketing measures); profiles containing user-related information (creation of user profiles).
- Legal bases: Consent (Art. 6(1), first sentence, point (a) of the GDPR); Legitimate interests (Art. 6(1), first sentence, point (f) of the GDPR) .
- Right to object (opt-out): You may unsubscribe from our newsletter at any time, i.e. withdraw your consent, or object to receiving it in future. You will find a link to unsubscribe from the newsletter at the end of each newsletter, or you may use one of the contact options listed above – preferably by email – for this purpose.
- Measuring open and click-through rates: The newsletters contain a so-called ‘web beacon’, i.e. a pixel-sized file that is retrieved from our server – or, if we use a mailing service provider, from their server – when the newsletter is opened. As part of this retrieval, technical information – such as details about your browser and system – as well as your IP address and the time of retrieval are initially collected. This information is used to improve our newsletter technically, based on the technical data or the target groups and their reading behaviour, determined by their location (which can be identified using the IP address) or the times of access. This analysis also includes determining whether the newsletters are opened, when they are opened and which links are clicked. This information is linked to individual newsletter recipients and stored in their profiles until it is deleted. The analyses help us to identify our users’ reading habits and tailor our content to them, or to send different content according to our users’ interests. The measurement of open rates and click-through rates, as well as the storage of the measurement results in users’ profiles and their further processing are carried out on the basis of the users’ consent. Unfortunately, it is not possible to withdraw consent for performance measurement separately; in this case, the entire newsletter subscription must be cancelled or objected to. In this case, the stored profile information will be deleted; Legal basis: Consent (Art. 6(1), first sentence, point (a) of the GDPR ).
- Google Analytics: Measuring the success of email campaigns and creating user profiles with a retention period of up to two years; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal basis: Consent (Art. 6(1), first sentence, (a) of the GDPR); Website:https://marketingplatform.google.com/intl/de/about/analytics/; Privacy policy: https://policies.google.com/privacy; Data Processing Agreement: https://business.safety.google/adsprocessorterms; Standard contractual clauses (ensuring an adequate level of data protection when processing in third countries): https://business. safety.google/adsprocessorterms; Right to object (opt-out): Opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=de, settings for the display of adverts: https://adssettings.google.com/authenticated; Further information: https://privacy.google.com/businesses/adsservices (Types of processing and data processed).
- MailPoet: email marketing service; service provider: Aut O’Mattic A8C Ireland Ltd., Grand Canal Dock, 25 Herbert Pl, Dublin, D02 AY86, Ireland; Legal basis: Legitimate interests (Art. 6(1), first sentence, point (f) of the GDPR); Website:https://www.mailpoet.com/; Privacy Policy: https://automattic.com/privacy/.
Marketing communications via email, post, fax or telephone
We process personal data for the purposes of marketing communications, which may be sent via various channels, such as email, telephone, post or fax, in accordance with statutory requirements. Recipients have the right to withdraw any consent given at any time or to object to marketing communications at any time. Following withdrawal of consent or an objection, we store the data necessary to prove the previous legitimacy of contacting the recipient or sending communications for up to three years after the end of the year in which the withdrawal or objection was made, on the basis of our legitimate interests. The processing of this data is limited to the purpose the possible defence against claims. On the basis of the legitimate interest in permanently honouring users’ revocation or objection, we also store the data necessary to prevent further contact (e.g. depending on the communication channel, the email address, telephone number or name).- Types of data processed: Master data (e.g. names, addresses); contact details (e.g. email, telephone numbers).
- Data subjects: Communication partners.
- Purposes of processing: Direct marketing (e.g. by email or post).
- Legal bases: Consent (Art. 6(1), first sentence, point (a) of the GDPR); Legitimate interests (Art. 6(1), first sentence, point (f) of the GDPR).
Prize draws and competitions
We process the personal data of participants in prize draws and competitions only in compliance with the relevant data protection regulations, insofar as such processing is contractually necessary for the provision, organisation and administration of the prize draw, the participants have consented to the processing, or the processing serves our legitimate interests (e.g. in ensuring the security of the prize draw or protecting our interests against misuse through the possible collection of IP addresses when prize draw entries are submitted). If participants’ entries are published as part of the prize draws (e.g. as part of a vote or the presentation of competition entries or winners, or in reporting on the competition), we would like to point out that participants’ names may also be published in this context. Participants may object to this at any time. If the competition takes place on an online platform or social network (e.g. Facebook or Instagram, hereinafter referred to as an ‘online platform’), the terms of use and privacy policies of the respective platforms shall also apply. In such cases, we would like to point out that we are responsible for the information provided by participants in connection with the prize draw and that any enquiries regarding the prize draw should be directed to us. Participants’ data will be deleted as soon as the prize draw or competition has ended and the data is no longer required, to inform the winners or because enquiries regarding the prize draw are to be expected. In principle, participants’ data will be deleted no later than 6 months after the end of the prize draw. Data relating to winners may be retained for longer, for example, to answer enquiries about the prizes or to fulfil the prize obligations; in this case, the retention period depends on the nature of the prize and may, for example, be up to three years for goods or services, so that warranty claims can be dealt with. Furthermore, participants’ data may be stored for longer, for example in the form of reports on the competition in online and offline media. If data has also been collected for other purposes in connection with the prize draw, its processing and the retention period are governed by the privacy notice relating to that use (e.g. in the case of subscribing to a newsletter as part of a prize draw).- Types of data processed: Master data (e.g. names, addresses); content data (e.g. entries in online forms); meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, consent status).
- Data subjects: Prize draw and competition participants.
- Purposes of processing: Organisation of prize draws and competitions.
- Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1), first sentence, point (b) of the GDPR).
Web analytics, monitoring and optimisation
Web analytics (also referred to as ‘reach measurement’) serves to analyse visitor traffic to our online offering and may include behaviour, interests or demographic information about visitors, such as age or gender, in pseudonymised form. With the help of reach analysis, we can, for example, identify at what times our online service, or its functions or content, are used most frequently or encourage repeat visits. We can also identify which areas require optimisation. In addition to web analytics, we may also use testing procedures, for example, to test and optimise different versions of our online service or its components. Unless otherwise stated below, for these purposes, profiles, i.e. data aggregated into a usage session, and information may be stored in a browser or on a device and retrieved from it. The data collected includes, in particular, the webpages visited and the elements used there, as well as technical details such as the browser and computer system used, and information on usage times. Provided that users have consented to the collection of their location data either to us or to the providers of the services we use , location data may also be processed. Users’ IP addresses are also stored. However, we use an IP masking procedure (i.e. pseudonymisation by truncating the IP address) to protect users. Generally speaking, no personally identifiable data relating to users (such as email addresses or names) is stored in the context of web analytics, A/B testing and optimisation are not stored as users’ personally identifiable data (such as email addresses or names), but as pseudonyms. This means that neither we nor the providers of the software used know the actual identity of the users, but only the information stored in their profiles for the purposes of the respective processes.- Types of data processed: Usage data (e.g. webpages visited, interest in content, access times); Meta, communication and process data (e.g. IP addresses, time stamps, identification numbers, consent status).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing: Audience measurement (e.g. access statistics, identification of returning visitors); profiles containing user-related information (creation of user profiles) ; provision of our online services and user-friendliness.
- Security measures: IP masking (pseudonymisation of the IP address).
- Legal bases: Consent (Art. 6(1), first sentence, point (a) of the GDPR).
- Google Analytics 4: We use Google Analytics to measure and analyse the use of our online service on the basis of a pseudonymous user identification number. This identification number does not contain any unique data, such as names or email addresses. It serves to associate analytical information with a device in order to identify which content users have accessed during one or more sessions, which search terms they have used, whether they have revisited that content, or how they have interacted with our online service. The time of use and its duration are also stored, as well as the sources from which users that link to our online service and technical details of their devices and browsers. In doing so, pseudonymous user profiles are created using information from the use of various devices, for which cookies may be employed. In Analytics, data on geographical location is provided at a higher level by collecting the following metadata via IP lookup: ‘City’ (and the derived latitude and longitude of the city), ‘Continent’, ‘Country’, ‘Region’, ‘Subcontinent’ (and the ID-based equivalents). To ensure the protection of user data within the EU, Google receives and processes all user data via domains and servers located within the EU. Users’ IP addresses are not logged and, by default, are truncated to the last two digits. The truncation of IP addresses takes place on EU servers for EU users. Furthermore, all sensitive data collected from users in the EU is deleted before it is recorded via EU domains and servers; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal basis: Consent (Art. 6(1), first sentence, point (a) of the GDPR); Website:https://marketingplatform.google.com/intl/de/about/analytics/; Privacy policy: https://policies.google.com/privacy; Data Processing Agreement: https://business.safety.google/adsprocessorterms/ ; Standard contractual clauses (ensuring an adequate level of data protection when processing in third countries): https://business.safety.google/adsprocessorterms; Right to object (opt-out): Opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=de, Settings for the display of adverts: https://adssettings.google.com/authenticated; Further information: https://privacy.google.com/businesses/adsservices(types of processing and the data processed).
- Google Tag Manager: Google Tag Manager is a solution that enables us to manage so-called website tags via a single interface and thus integrate other services into our online offering (please refer to further details in this privacy policy) . The Tag Manager itself (which implements the tags) therefore does not, for example, create user profiles or store cookies. Google only receives the user’s IP address, which is necessary to run Google Tag Manager; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal basis: Consent (Art. 6(1), first sentence, point (a) of the GDPR); Website: https://marketingplatform.google.com;Privacy policy: https://policies.google.com/privacy; Data Processing Agreement:https://business.safety.google/adsprocessorterms; Standard contractual clauses (ensuring an adequate level of data protection when processing in third countries): https://business.safety.google/adsprocessorterms.
Online marketing
We process personal data for the purposes of online marketing, which may include, in particular, the marketing of advertising space or the display of advertising and other content (collectively referred to as ‘content’) based on users’ potential interests, as well as the measurement of its effectiveness. For these purposes, so-called user profiles are created and stored in a file (known as a ‘cookie’) or similar methods are used, by means of which information relevant to the display of the aforementioned content is stored. This information may include, for example, content viewed, websites visited, online networks used, as well as communication partners and technical details such as the browser and computer system used, and information on usage times and functions utilised. Where users have consented to the collection of their location data, this may also be processed. Users’ IP addresses are also stored. However, we use available IP masking methods (i.e. pseudonymisation by truncating the IP address) to protect users. Generally, no users’ plain text data (such as email addresses or names) is stored as part of online marketing procedures; instead, pseudonyms are used. This means that neither we nor the providers of the online marketing services know the actual identity of the users, but only the information stored in their profiles. The information in the profiles is usually stored in cookies or by means of similar methods. These cookies can generally also be read later on other websites that use the same online marketing service, analysed for the purpose of displaying content, and combined with further data and stored on the server of the online marketing service provider. In exceptional cases, personal data may be linked to the profiles. This is the case, for example, when users are members of a social network whose online marketing services we use and the network links the users’ profiles with the aforementioned information. Please note that users may enter into additional agreements with the providers, e.g. by giving consent during registration. In principle, we only have access to aggregated information regarding the success of our adverts. However, as part of so-called conversion tracking, we may check which of our online marketing methods have led to a so-called conversion, i.e. for example, the conclusion of a contract with us. Conversion tracking is used solely to analyse the success of our marketing measures. Unless otherwise stated, please assume that the cookies used are stored for a period of two years.- Types of data processed: usage data (e.g. web pages visited, interest in content, access times); meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, consent status).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing: Audience measurement (e.g. access statistics, identification of returning visitors); tracking (e.g. interest-based/behavioural profiling, use of cookies); marketing; profiles containing user-related information (creation of user profiles); conversion measurement (measuring the effectiveness of marketing measures).
- Security measures: IP masking (pseudonymisation of the IP address).
- Legal bases: Consent (Art. 6(1), first sentence, point (a) of the GDPR); Legitimate interests (Art. 6(1), first sentence, point (f) of the GDPR).
- Right to object (opt-out): We refer you to the privacy policies of the respective providers and the opt-out options specified by them. If no explicit opt-out option has been provided, you may disable cookies in your browser settings. However, this may restrict certain functions of our online service. We therefore also recommend the following opt-out options, which are summarised and provided for the respective regions: a) Europe: https://www.youronlinechoices.eu. b) Canada: https://www.youradchoices.ca/choices. c) USA: https://www.aboutads.info/choices. d) Cross-regional: https://optout.aboutads.info.
- Google Ads and conversion tracking: Online marketing methods for the purpose of placing content and adverts within the service provider’s advertising network (e.g. in search results, in videos, on websites, etc.), so that they are displayed to users who are presumed to have an interest in the adverts. In addition, we measure the conversion rate of the adverts, i.e. whether users have been prompted to interact with the adverts and make use of the advertised offers (so-called ‘conversion’) . However, we only receive anonymous information and no personal information about individual users; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal basis: Consent (Art. 6(1), first sentence, point (a) of the GDPR), Legitimate interests (Art. 6(1), first sentence, point (f) of the GDPR); Website: https://marketingplatform.google.com; Privacy Policy: https://policies.google.com/privacy; Further information: Types of processing and data processed: https://privacy.google.com/businesses/adsservices; Data processing terms between data controllers and standard contractual clauses for data transfers to third countries: https://business.safety. google/adscontrollerterms.
Customer reviews and rating procedures
We take part in review and rating procedures in order to evaluate, optimise and promote our services. If users rate us or provide feedback in any other way via the participating review platforms or procedures, the providers’ general terms and conditions or terms of use and privacy policies also apply. As a rule, submitting a rating also requires registration with the respective providers. To ensure that the reviewers have actually used our services, we transmit the necessary data relating to the customer and the service used to the relevant review platform (including name, email address and order number or item number) with the customer’s consent. This data is used solely to verify the authenticity of the user.- < strong>Types of data processed: Contract data (e.g. subject matter of the contract, term, customer category); usage data (e.g. websites visited, interest in content, access times); meta, communication and process data (e.g. IP addresses, time stamps, identification numbers, consent status); content data (e.g. entries in online forms).
- Data subjects: customers; users (e.g. website visitors, users of online services).
- Purposes of processing: Feedback (e.g. collecting feedback via an online form); marketing.
- Legal bases: Legitimate interests (Art. 6(1), first sentence, point (f) of the GDPR).
- Google Customer Reviews: service for gathering and/or displaying customer satisfaction and customer opinions; service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal basis: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR); Terms and conditions: https://support.google.com/merchants/topic/7259129? hl=de&ref_topic=7257954; Privacy Policy: https://policies.google.com/privacy; Further information: As part of the process of collecting customer reviews, an identification number and the time of the transaction being reviewed are processed; in the case of review requests sent directly to customers, the customer’s email address, details of their country of residence and the review details themselves are also processed; further details on the types of processing and the data processed: https://privacy.google.com/businesses/adsservices; Data processing terms for Google advertising products: Information on the services, data processing terms between data controllers and standard contractual clauses for data transfers to third countries: https://business.safety.google/adscontrollerterms.
- Trustindex: review platform; Service provider: Trustindex Informatikai Kft., Kárpát utca 37, 1133 Budapest, Hungary; Legal basis: Legitimate interests (Art. 6(1), first sentence, point (f) of the GDPR); Website: https://www.trustindex.io/; Privacy policy: https://www.trustindex.io/terms-and-conditions-and-privacy-policy/.
Plugins, embedded functions and content
We incorporate functional and content elements into our online service that are sourced from the servers of their respective providers (hereinafter referred to as “third-party providers”). These may include, for example, graphics, videos or city maps (hereinafter collectively referred to as “content”) . This integration always requires the third-party providers of this content to process users’ IP addresses, as they would be unable to send the content to users’ browsers without them. The IP address is therefore necessary for the display of this content or these functions. We endeavour to use only content whose respective providers use the IP address solely for the purpose of delivering the content. Third-party providers may also use so-called pixel tags (invisible graphics, also known as ‘web beacons’) for statistical or marketing purposes. Through these ‘pixel tags ”, information such as visitor traffic on the pages of this website can be analysed. The pseudonymous information may also be stored in cookies on the user’s device and may include, amongst other things, technical information about the browser and operating system, referring websites, the time of visit, and further details regarding the use of our online service; it may also be linked to such information from other sources.- Types of data processed: Usage data (e.g. web pages visited, interest in content, access times); meta, communication and process data (e.g. IP addresses, timestamps, identification numbers, consent status) .
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing: Provision of our online services and user-friendliness; provision of contractual services and customer service.
- Legal bases: Legitimate interests (Art. 6(1), first sentence, point (f) of the GDPR).
- Integration of third-party software, scripts or frameworks (e.g. jQuery): We integrate software into our online offering which we retrieve from other providers’ servers (e.g. function libraries which we use for the purposes of display or user-friendliness& nbsp;our online service). In doing so, the respective providers collect users’ IP addresses and may process them for the purposes of transmitting the software to users’ browsers, as well as for security purposes and to evaluate and optimise their service. – We integrate software into our online service that we retrieve from servers operated by other providers (e.g. function libraries that we use for the display or user-friendliness& nbsp;our online service). In doing so, the respective providers collect users’ IP addresses and may process them for the purposes of transmitting the software to users’ browsers, for security purposes, and for the evaluation and optimisation of their services; Legal bases: Legitimate interests (Art. 6(1), first sentence, point f) of the GDPR).
- Google Fonts (hosted on our own server): Provision of font files to ensure a user-friendly presentation of our online service; Service provider: Google Fonts are hosted on our server; no data is transmitted to Google; Legal basis: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).
- Google Maps APIs and SDKs: Interfaces to Google’s map and location services, which allow, for example, the completion of address entries, location determination, distance calculations or the provision of supplementary information on locations and other places; Service provider: Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland; Legal basis: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR); Website: https://mapsplatform.google.com/; Privacy Policy: https: //policies.google.com/privacy.
- reCAPTCHA: We incorporate the ‘reCAPTCHA’ function to determine whether entries (e.g. in online forms) are made by humans and not by automated machines (so-called ‘bots’). The data processed may include IP addresses, information on operating systems, devices or browsers used, language settings, location, mouse movements, keystrokes, time spent on webpages, previously visited webpages, interactions with reCAPTCHA on other websites, cookies in some circumstances, and the results of manual verification processes (e.g. answering questions or selecting objects in images). Data processing is carried out on the basis of our legitimate interest in protecting our online service from abusive automated crawling and spam; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal basis:Legitimate interests (Art. 6(1), first sentence, point (f) of the GDPR); Website: https://www.google.com/recaptcha/; Privacy policy: https://policies.google.com/privacy; Right to object (opt-out): Opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=de, Settings for the display of advertisements: https://adssettings.google.com/authenticated.
Amendments and updates to the privacy policy
We ask that you review the content of our privacy policy regularly. We will update the privacy policy as soon as changes to our data processing activities make this necessary. We will inform you as soon as the changes require any action on your part (e.g. consent) or any other individual notification. Where we provide addresses and contact details for companies and organisations in this Privacy Policy, please note that these details may change over time; we therefore ask you to check the details before making contact.Rights of data subjects
As a data subject, you are entitled to various rights under the GDPR, which arise in particular from Articles 15 to 21 of the GDPR:- Right to object: You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you carried out on the basis of Article 6(1)(e) or (f) of the GDPR; this also applies to profiling based on these provisions. If personal data concerning you is processed for the purposes of direct marketing, you have the right to object at any time to the processing of your personal data for the purposes of such marketing; this also applies to profiling insofar as it is related to such direct marketing.
- Right to withdraw consent: You have the right to withdraw any consent you have given at any time.
- Right of access: You have the right to request confirmation as to whether the relevant data is being processed, and to obtain information about this data, as well as further details and a copy of the data in accordance with statutory requirements.
- Right to rectification: In accordance with statutory requirements, you have the right to request that data relating to you be completed or that any inaccurate data relating to you be rectified.
- Right to erasure and restriction of processing: In accordance with the statutory provisions, you have the right to request that data relating to you be erased without delay or, alternatively, in accordance with the statutory provisions, to request a restriction on the processing of the data.
- Right to data portability: You have the right, in accordance with the statutory provisions, to receive the data concerning you that you have provided to us in a structured, commonly used and machine-readable format, or to request that it be transmitted to another data controller.
- Complaint to a supervisory authority: Without prejudice to any other administrative or judicial remedy, the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, your place of work or the place of the alleged infringement, if you consider that the processing of personal data relating to you infringes the provisions of the GDPR.
Definitions
This section provides an overview of the terms used in this privacy policy. Many of the terms are taken from the legislation and are defined, in particular, in Article 4 of the GDPR. The legal definitions are binding. The explanations below, however, are primarily intended to aid understanding. The terms are listed in alphabetical order.- Conversion tracking: Conversion tracking (also referred to as ‘visit action analysis’) is a method used to determine the effectiveness of marketing measures. To this end, a cookie is usually stored on users’ devices whilst they are on the websites where the marketing measures are carried out, and is then retrieved again on the target website. For example, this enables us to track whether the adverts we have placed on other websites have been successful.
- Personal data: ‘Personal data’ means any information relating to an identified or identifiable natural person (hereinafter ‘data subject’); a natural person is regarded as identifiable if they can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. a cookie) or one or more specific characteristics that reflect the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
- Profiles containing user-related information: The processing of ‘profiles containing user-related information’, or ‘profiles’ for short, encompasses any form of automated processing of personal data that involves using such personal data to analyse, evaluate or predict certain personal aspects relating to a natural person (depending on the nature of the profiling, this may include various information concerning demographics, behaviour and interests, such as interaction with websites and their content, etc.) or to predict them (e.g. interests in specific content or products, clicking behaviour on a website or location). Cookies and web beacons are frequently used for profiling purposes.
- Audience measurement: Audience measurement (also known as web analytics) serves to analyse visitor traffic to an online service and may include the behaviour or interests of visitors in relation to specific information, such as website content. With the help of web analytics, website owners can, for example, identify at what times visitors access their website and what content they are interested in. This enables them, for example, to better tailor the website’s content to the needs of their visitors. For the purposes of web analytics, pseudonymous cookies and web beacons are frequently used to recognise returning visitors and thus obtain more accurate analyses of the use of an online service.
- Tracking: The term ‘tracking’ refers to the ability to track users’ behaviour across multiple online services. As a rule, behavioural and interest-based information relating to the online services used is stored in cookies or on the servers of the providers of tracking technologies (so-called ‘profiling’). This information can then be used, for example, to display adverts to users that are likely to match their interests.
- Data controller: The term ‘data controller’ refers to the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
- Processing: ‘Processing’ means any operation or set of operations which is carried out on personal data, whether or not by automated means. The term is broad and covers virtually any handling of data, be it collection, analysis, storage, transmission or erasure.
- Target audience creation: The term ‘target audience creation’ (known as ‘Custom Audiences’ in English) refers to the process of defining target audiences for advertising purposes, e.g. displaying adverts. For example, based on a user’s interest in certain products or topics on the internet, it can be inferred that this user is interested in adverts for similar products or the online shop where they viewed the products. The term ‘Lookalike Audiences’ (or similar target groups), on the other hand, is used when content deemed suitable is displayed to users, whose profiles or interests are presumed to correspond to those of the users on whose profiles the audience was based. Cookies and web beacons are generally used for the purpose of creating Custom Audiences and Lookalike Audiences.