Privacy Policy
Last updated: 4 August 2024
Table of Contents
- Data Controller
- Overview of data processing
- Relevant Legal Bases
- Security measures
- Transfer of personal data
- International data transfers
- General information on data storage and erasure
- Business services
- Provision of the online service and web hosting
- Use of cookies
- Blogs and publication media
- Contact and enquiry management
- Web analytics, monitoring and optimisation
- Plug-ins, embedded functions and content
Data controller
S. Benz
, Sillerstrasse 1
, 8700 Küsnacht
Authorised representatives: Sascha Benz
Email address: info@blumen-lieferung.ch
Legal notice: /impressum
Overview of data processing
The following overview summarises the types of data processed and the purposes of such processing, and refers to the data subjects.
Types of data processed
- Master data.
- Payment data.
- Location data.
- Contact data.
- Content data.
- Contract data.
- Usage data.
- Meta, communication and procedural data.
- Log data.
Categories of data subjects
- Service recipients and clients.
- Prospective clients.
- Communication partners.
- Users.
- Business and contractual partners.
Purposes of processing
- Provision of contractual services and fulfilment of contractual obligations.
- Communication.
- Security measures.
- Audience measurement.
- Office and organisational procedures.
- Organisational and administrative procedures.
- Feedback.
- Profiles containing user-related information.
- Provision of our online services and user-friendliness.
- IT infrastructure.
- Business processes and operational procedures.
Relevant legal bases
Relevant legal bases under the Swiss Data Protection Act: If you are located in Switzerland, we process your data on the basis of the Federal Act on Data Protection (the ‘Swiss DPA’ for short). Unlike, for example, the GDPR, the Swiss Data Protection Act does not, in principle, require a legal basis for the processing of personal data to be specified, and stipulates that the processing of personal data must be carried out in good faith, lawfully and proportionately (Art. 6(1) and (2) of the Swiss Data Protection Act). Furthermore, we collect personal data only for a specific purpose that is recognisable to the data subject and process it only in a manner compatible with that purpose (Art. 6(3) of the Swiss Data Protection Act).
Security measures
We implement technical and organisational measures in accordance with legal requirements, taking into account the state of the art, the costs of implementation and the nature, scope, circumstances and purposes of the processing, as well as the varying likelihood and severity of threats to the rights and freedoms of natural persons, to ensure a level of protection appropriate to the risk.
These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data, as well as access to, input of, disclosure of, and availability of the data, and ensuring their separation. Furthermore, we have established procedures to ensure that data subjects’ rights are upheld, that data is deleted and that appropriate action is taken in the event of a data breach. Furthermore, we take the protection of personal data into account right from the development and selection of hardware, software and procedures, in accordance with the principle of data protection by design and through privacy-friendly default settings.
Transfer of personal data
In the course of our processing of personal data, it may happen that such data is transferred to or disclosed to other bodies, companies, legally independent organisational units or individuals. Recipients of this data may include, for example, service providers commissioned to carry out IT tasks or providers of services and content integrated into a website. In such cases, we comply with the statutory requirements and, in particular, enter into appropriate contracts or agreements with the recipients of your data to ensure the protection of your data.
International data transfers
Disclosure of personal data abroad: In accordance with the Swiss Data Protection Act (DSG), we only disclose personal data abroad if adequate protection for the data subjects is guaranteed (Art. 16 of the Swiss DSG). Where the Federal Council has not determined that adequate protection exists (list: https://www.bj.admin.ch/bj/de/home/staat/datenschutz/internationales/anerkennung-staaten.html), we implement alternative security measures. These may include international treaties, specific safeguards, data protection clauses in contracts, standard data protection clauses approved by the Federal Data Protection and Information Commissioner (FDPIC), or internal company data protection policies recognised in advance by the FDPIC or a competent data protection authority in another country.
Under Article 16 of the Swiss Data Protection Act (DSG), exceptions to the transfer of data abroad may be permitted if certain conditions are met, including the consent of the data subject, the performance of a contract, the public interest, the protection of life or physical integrity, data that has been made public, or data from a register provided for by law. Such transfers are always carried out in accordance with the legal requirements.
General information on data storage and deletion
We delete the personal data we process in accordance with statutory provisions as soon as the underlying consents are withdrawn or there are no longer any legal grounds for processing. This applies to cases where the original purpose of processing no longer applies or the data is no longer required. Exceptions to this rule apply where legal obligations or specific interests require the data to be retained or archived for a longer period.
In particular, data that must be retained for commercial or tax law reasons, or where storage is necessary for the purposes of legal proceedings or to protect the rights of other natural or legal persons, must be archived accordingly.
Our privacy policy contains additional information on the retention and erasure of data, which applies specifically to certain processing operations.
Where there are several specifications regarding the retention period or deletion deadlines for a particular piece of data, the longest period shall always apply.
If a period does not expressly commence on a specific date and is at least one year in duration, it shall automatically commence at the end of the calendar year in which the event triggering the period occurred. In the case of ongoing contractual relationships within the framework of which data is stored, the event triggering the period is the date on which the termination or other cessation of the legal relationship takes effect.
We process data that is no longer retained for the purpose originally intended, but is retained due to legal requirements or other reasons, exclusively for the purposes that justify its retention.
Further information on processing procedures, processes and services:
- Retention and deletion of data: The following general time limits apply to the retention and archiving of data under Swiss law:
- 10 years – Retention period for books and records, annual accounts, inventories, management reports, opening balance sheets, accounting documents and invoices, as well as all necessary work instructions and other organisational documents (Art. 958f of the Swiss Code of Obligations (CO)).
- 10 years – Data necessary to address potential claims for damages or similar contractual claims and rights, as well as for processing related enquiries, based on past business experience and standard industry practices, shall be stored for the statutory limitation period of ten years, unless a shorter period of five years applies, which is relevant in certain cases (Art. 127, 130 CO). After five years, claims for rent, lease payments and interest on capital, as well as other periodic payments arising from the supply of food, for board and lodging and for pub debts, and from craft work, the retail sale of goods, medical services, professional services provided by lawyers, legal agents, solicitors and notaries, and arising from the employment relationship of employees (Art. 128 OR).
Business Services
We process data relating to our contractual and business partners, e.g. customers and prospective customers (collectively referred to as ‘contractual partners’), within the framework of contractual and similar legal relationships, as well as associated measures and for the purposes of communication with contractual partners (or on a pre-contractual basis), for example to respond to enquiries.
We use this data to fulfil our contractual obligations. These include, in particular, the obligations to provide the agreed services, any obligations to update information, and to remedy warranty claims and other service disruptions. Furthermore, we use the data to safeguard our rights and for the purposes of administrative tasks associated with these obligations, as well as for the organisation of our business. We also process the data on the basis of our legitimate interests in both the proper and sound management of our business and in security measures to protect our contractual partners and our business operations from misuse or any risk to their data, confidential information, information and rights (e.g. the involvement of telecommunications, transport and other ancillary service providers, as well as subcontractors, banks, tax and legal advisers, payment service providers or tax authorities). Within the framework of applicable law, we only disclose contractual partners’ data to third parties to the extent that this is necessary for the aforementioned purposes or to fulfil legal obligations. Contractual partners are informed about other forms of processing, such as for marketing purposes, within the framework of this privacy policy.
We inform contractual partners of which data is required for the aforementioned purposes either before or during the data collection process, e.g. in online forms, by means of specific markings (e.g. colours) or symbols (e.g. asterisks or similar), or in person.
We delete the data once statutory warranty and similar obligations have expired, i.e. generally after four years, unless the data is stored in a customer account, e.g. for as long as it must be retained for statutory archiving purposes (typically ten years for tax purposes). We delete data disclosed to us by the contractual partner in the course of a contract in accordance with the relevant specifications and, as a general rule, upon completion of the contract.
- Types of data processed: Master data (e.g. full name, residential address, contact details, customer number, etc.); payment data (e.g. bank details, invoices, payment history); contact details (e.g. postal and email addresses or telephone numbers); contract details (e.g. subject matter of the contract, term, customer category).
- Data subjects: Service recipients and clients; prospective clients; business and contractual partners.
- Purposes of processing: Provision of contractual services and fulfilment of contractual obligations; communication; office and organisational procedures; organisational and administrative procedures; business processes and business management procedures.
- Retention and erasure: Erasure in accordance with the information provided in the section ‘General information on data storage and erasure’.
- Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1), first sentence, point (b) of the GDPR); legal obligation (Art. 6(1), first sentence, point (c) of the GDPR). Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).
Further information on processing operations, procedures and services:
- Provision of software and platform services: We process the data of our users, registered users and any trial users (hereinafter collectively referred to as ‘users’) in order to provide them with our contractual services and, on the basis of legitimate interests, to ensure the security of our service and to enable its further development. The required information is identified as such when concluding a contract, placing an order or entering into a comparable agreement, and comprises the details necessary for the provision of services and invoicing, as well as contact details to enable us to consult with users where necessary; Legal basis: performance of a contract and pre-contractual enquiries (Article 6(1), first sentence, point (b) of the GDPR).
Provision of the online service and web hosting
We process users’ data in order to provide them with our online services. For this purpose, we process the user’s IP address, which is necessary to transmit the content and functions of our online services to the user’s browser or device.
- Types of data processed: usage data (e.g. page views and time spent on the site, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and functions); Meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, persons involved); log data (e.g. log files relating to logins, data retrieval or access times). Content data (e.g. text or image-based messages and posts, as well as related information such as details of authorship or the time of creation).
- Data subjects: users (e.g. website visitors, users of online services).
- Purposes of processing: Provision of our online services and user-friendliness; IT infrastructure (operation and provision of information systems and technical equipment (computers, servers, etc.)). Security measures.
- Retention and erasure: Erasure in accordance with the details in the section ‘General information on data storage and erasure’.
- Legal basis: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).
Further information on processing operations, procedures and services:
- Provision of online services on leased storage space: To provide our online services, we use storage space, computing capacity and software which we lease or otherwise obtain from a relevant server provider (also known as a ‘web host’); Legal basis: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).
- Collection of access data and log files: Access to our online service is logged in the form of so-called ‘server log files’. Server log files may include the address and name of the web pages and files accessed, the date and time of the request, the volume of data transferred, confirmation of a successful request, browser type and version, the user’s operating system, the referrer URL (the previously visited page) and, as a rule, IP addresses and the requesting provider. The server log files may be used, on the one hand, for security purposes, e.g. to prevent server overload (particularly in the event of malicious attacks, known as DDoS attacks), and, on the other hand, to ensure server capacity utilisation and stability; Legal basis: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR). Deletion of data: Log file information is stored for a maximum of 30 days and is then deleted or anonymised. Data which must be retained for evidential purposes is exempt from deletion until the relevant incident has been fully resolved.
- WordPress.com: Hosting and software for the creation, provision and operation of websites, blogs and other online services; Service provider: Aut O’Mattic A8C Ireland Ltd., Grand Canal Dock, 25 Herbert Pl, Dublin, D02 AY86, Ireland; Legal basis: Legitimate interests (Art. 6(1), first sentence, point (f) of the GDPR); Website: https://wordpress.com; Privacy policy: https://automattic.com/de/privacy/; Data processing agreement: https://wordpress.com/support/data-processing-agreements/. Basis for transfers to third countries: Adequacy decision (Ireland).
Use of cookies
Cookies are small text files or other storage markers that store and retrieve information on end devices. For example, to store the log-in status in a user account, the contents of a shopping basket in an online shop, the content accessed or the functions used on an online service. Cookies may also be used for various purposes, such as to ensure the functionality, security and convenience of online services, as well as to analyse visitor traffic.
Information on consent: We use cookies in accordance with the relevant legal provisions. We therefore obtain prior consent from users, unless this is not required by law. In particular, consent is not required if the storage and retrieval of information – including cookies – are strictly necessary to provide users with a telemedia service (i.e. our online service) that they have expressly requested. The revocable consent is clearly communicated to you and contains information on the respective use of cookies.
Notes on the legal basis under data protection law: The legal basis under data protection law on which we process users’ personal data using cookies depends on whether we ask for their consent. If users accept, the legal basis for the processing of their data is their explicit consent. Otherwise, the data processed via cookies is processed on the basis of our legitimate interests (e.g. the efficient operation of our online service and the improvement of its usability) or, where this takes place in the context of fulfilling our contractual obligations, if the use of cookies is necessary to fulfil our contractual obligations. We explain the purposes for which we use cookies in this privacy policy or as part of our consent and processing procedures.
Retention period: With regard to the retention period, a distinction is made between the following types of cookies:
- Temporary cookies (also known as session cookies): Temporary cookies are deleted at the latest once a user has left an online service and closed their device (e.g. browser or mobile application).
- Permanent cookies: Permanent cookies remain stored even after the device has been closed. This allows, for example, the login status to be saved and preferred content to be displayed directly when the user visits a website again. Similarly, user data collected via cookies may be used for audience measurement. Unless we provide users with explicit information regarding the type and storage period of cookies (e.g. when seeking consent), they should assume that these are permanent and that the storage period may be up to two years.
General information on withdrawal of consent and objection (opt-out): Users may withdraw the consent they have given at any time and may also object to the processing of their data in accordance with legal requirements, including via their browser’s privacy settings.
- Types of data processed: Meta data, communication data and procedural data (e.g. IP addresses, timestamps, identification numbers, individuals involved).
- Data subjects: Users (e.g. website visitors, users of online services).
- Legal bases: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR). Consent (Article 6(1), first sentence, point (a) of the GDPR).
Further information on processing operations, procedures and services:
- Processing of cookie data on the basis of consent: We use a consent management solution through which users’ consent is obtained for the use of cookies or for the procedures and providers specified within the consent management solution. This procedure serves to obtain, log, manage and revoke consents, in particular with regard to the use of cookies and similar technologies employed to store, read and process information on users’ end devices. As part of this procedure, users’ consent is obtained for the use of cookies and the associated processing of information, including the specific processing activities and providers mentioned in the consent management procedure. Users also have the option to manage and withdraw their consents. Consent declarations are stored to avoid having to request them again and to be able to provide evidence of consent in accordance with legal requirements. Storage takes place on the server and/or in a cookie (known as an ‘opt-in cookie’) or by means of comparable technologies, in order to be able to associate the consent with a specific user or their device. Unless specific details regarding the providers of consent management services are available, the following general information applies: Consent is stored for up to two years. A pseudonymous user identifier is created, which is stored together with the time of consent, details of the scope of consent (e.g. relevant categories of cookies and/or service providers) and information about the browser, the system and the end device used; Legal basis: Consent (Article 6(1), first sentence, point (a) of the GDPR).
Blogs and publication media
We use blogs or similar means of online communication and publication (hereinafter “publication medium”). Readers’ data is processed for the purposes of the publication medium only to the extent necessary for its presentation and for communication between authors and readers, or for security reasons. For further details, please refer to the information on the processing of visitors to our publication medium set out in this privacy notice.
- Types of data processed: Personal details (e.g. full name, residential address, contact details, customer number, etc.); contact details (e.g. postal and email addresses or telephone numbers); Content data (e.g. textual or visual messages and posts, as well as related information such as details of authorship or the time of creation); Usage data (e.g. page views and time spent on the site, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and functions). Meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, persons involved).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing: Feedback (e.g. collecting feedback via an online form); provision of our online services and user-friendliness; security measures; organisational and administrative procedures.
- Retention and erasure: Erasure in accordance with the information provided in the section ‘General information on data storage and erasure’.
- Legal basis: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).
Further information on processing procedures, processes and services:
- Comments and posts: When users leave comments or other posts, their IP addresses may be stored on the basis of our legitimate interests. This is done for our own security in the event that someone posts unlawful content in comments or posts (insults, prohibited political propaganda, etc.). In such cases, we ourselves may be held liable for the comment or post and are therefore interested in the author’s identity.
Furthermore, we reserve the right, on the basis of our legitimate interests, to process users’ data for the purpose of spam detection.
On the same legal basis, we reserve the right, in the case of surveys, to store users’ IP addresses for the duration of the survey and to use cookies to prevent multiple votes.
The personal information provided in comments and posts, any contact and website details, as well as the content itself, will be stored by us permanently until the user objects; Legal basis: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).
Contact and enquiry management
When you contact us (e.g. by post, contact form, email, telephone or via social media), and in the context of existing user and business relationships, the details of the enquirers are processed to the extent necessary to respond to contact enquiries and any requested actions.
- Types of data processed: Master data (e.g. full name, residential address, contact details, customer number, etc.); contact details (e.g. postal and email addresses or telephone numbers); Content data (e.g. text or image-based messages and posts, as well as related information such as details of authorship or the time of creation); Usage data (e.g. page views and time spent on the site, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and functions). Meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, persons involved).
- Data subjects: Communication partners.
- Purposes of processing: Communication; organisational and administrative procedures; feedback (e.g. collecting feedback via an online form). Provision of our online services and user-friendliness.
- Retention and deletion: Deletion in accordance with the information provided in the section ‘General information on data storage and deletion’.
- Legal bases: Legitimate interests (Art. 6(1), first sentence, point (f) of the GDPR). Performance of a contract and pre-contractual enquiries (Art. 6(1), first sentence, point (b) of the GDPR).
Further information on processing operations, procedures and services:
- Contact form: When you contact us via our contact form, by email or through other communication channels, we process the personal data provided to us in order to respond to and deal with your enquiry. This generally includes details such as your name, contact details and, where applicable, any further information provided to us that is necessary for the appropriate handling of your enquiry. We use this data exclusively for the stated purpose of establishing contact and communication; Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1), first sentence, point (b) of the GDPR), legitimate interests (Art. 6(1), first sentence, point (f) of the GDPR).
Web analytics, monitoring and optimisation
Web analytics (also referred to as ‘reach measurement’) serves to analyse visitor traffic to our online offering and may include pseudonymised data on visitors’ behaviour, interests or demographic information, such as age or gender. With the help of reach analysis, we can, for example, identify at what times our online service or its functions and content are used most frequently, or encourage repeat visits. It also enables us to identify which areas require optimisation.
In addition to web analytics, we may also use testing procedures to, for example, test and optimise different versions of our online service or its components.
Unless otherwise stated below, profiles – that is, data aggregated to a specific usage session – may be created for these purposes, and information may be stored in a browser or on a device and subsequently retrieved. The data collected includes, in particular, websites visited and the elements used there, as well as technical information such as the browser used, the computer system used and details of usage times. Where users have consented to the collection of their location data by us or by the providers of the services we use, the processing of location data is also possible.
In addition, users’ IP addresses are stored. However, we use an IP masking procedure (i.e. pseudonymisation by truncating the IP address) to protect users. Generally, no personally identifiable data (such as email addresses or names) is stored in the context of web analytics, A/B testing and optimisation; instead, pseudonyms are used. This means that neither we nor the providers of the software used know the actual identity of the users, but only the information stored in their profiles for the purposes of the respective processes.
Notes on legal bases: Where we ask users for their consent to the use of third-party providers, the legal basis for data processing is consent. Otherwise, user data is processed on the basis of our legitimate interests (i.e. our interest in providing efficient, cost-effective and user-friendly services). In this context, we would also like to draw your attention to the information on the use of cookies in this privacy policy.
- Types of data processed: Usage data (e.g. page views and time spent on the site, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and functions). Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, individuals involved).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing: Audience measurement (e.g. access statistics, identification of returning visitors); profiles containing user-related information (creation of user profiles). Provision of our online services and user-friendliness.
- Retention and deletion: Deletion in accordance with the information provided in the section ‘General information on data storage and deletion’. Storage of cookies for up to 2 years (Unless otherwise stated, cookies and similar storage methods may be stored on users’ devices for a period of two years).
- Security measures: IP masking (pseudonymisation of the IP address).
- Legal basis: Consent (Art. 6(1), first sentence, point (a) of the GDPR). Legitimate interests (Art. 6(1), first sentence, point (f) of the GDPR).
Further information on processing operations, procedures and services:
- Google Analytics: We use Google Analytics to measure and analyse the use of our online service on the basis of a pseudonymous user identification number. This identification number does not contain any unique data, such as names or email addresses. It serves to associate analytical information with a device in order to identify which content users have accessed during one or more sessions, which search terms they have used, whether they have revisited the content, or how they have interacted with our online service. The time of use and its duration are also stored, as well as the sources from which users have accessed our online service and technical details of their devices and browsers.
In doing so, pseudonymous user profiles are created using information from the use of various devices, for which cookies may be used. Google Analytics does not log or store individual IP addresses for EU users. However, Analytics provides approximate geographical location data by deriving the following metadata from IP addresses: city (and the derived latitude and longitude of the city), continent, country, region, subcontinent (and ID-based equivalents). For EU data traffic, IP address data is used exclusively for this derivation of geolocation data before being deleted immediately. It is not logged, is not accessible and is not used for any other purposes. When Google Analytics collects measurement data, all IP queries are carried out on EU-based servers before the traffic is forwarded to Analytics servers for processing; service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal basis: Consent (Art. 6(1)(a) GDPR); Website: https://marketingplatform.google.com/intl/de/about/analytics/; Security measures: IP masking (pseudonymisation of the IP address); Privacy policy: https://policies.google.com/privacy; Data processing agreement: https://business.safety.google/adsprocessorterms/; Basis for transfers to third countries: Adequacy decision (Ireland); Right to object (opt-out): Opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=de, Settings for the display of adverts: https://myadcenter.google.com/personalizationoff. Further information: https://business.safety.google/adsservices/ (types of processing and the data processed). - Google Tag Manager: We use Google Tag Manager, a software tool from Google that enables us to manage so-called website tags centrally via a user interface. Tags are small pieces of code on our website that are used to track and analyse visitor activity. This technology helps us to improve our website and the content offered on it. Google Tag Manager itself does not create user profiles, does not store cookies containing user profiles, and does not carry out any independent analyses. Its function is limited to simplifying and streamlining the integration and management of the tools and services we use on our website. Nevertheless, when Google Tag Manager is used, users’ IP addresses are transmitted to Google; this is necessary for technical reasons in order to implement the services we use. Cookies may also be set in the process. However, this data processing only takes place when services are integrated via Tag Manager. For more detailed information on these services and their data processing, please refer to the relevant sections of this privacy policy; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal basis: Consent (Art. 6(1)(a) GDPR); Website: https://marketingplatform.google.com; Privacy policy: https://policies.google.com/privacy; Data processing agreement:
https://business.safety.google/adsprocessorterms. Basis for transfers to third countries: Adequacy decision (Ireland).
Plug-ins, embedded functions and content
We incorporate functional and content elements into our online offering which are sourced from the servers of their respective providers (hereinafter referred to as ‘third-party providers’). These may include, for example, graphics, videos or city maps (hereinafter collectively referred to as ‘content’).
This integration always requires the third-party providers of this content to process users’ IP addresses, as they would be unable to send the content to users’ browsers without an IP address. The IP address is therefore necessary for the display of this content or these functions. We endeavour to use only such content where the respective providers use the IP address solely for the purpose of delivering the content. Third-party providers may also use so-called pixel tags (invisible graphics, also known as ‘web beacons’) for statistical or marketing purposes. These ‘pixel tags’ enable information, such as visitor traffic on the pages of this website, to be analysed. This pseudonymous information may also be stored in cookies on the user’s device and may include, amongst other things, technical details regarding the browser and operating system, referring websites, the time of the visit and further details on the use of our online service; it may also be linked to such information from other sources.
Notes on legal bases: Where we ask users for their consent to the use of third-party providers, the legal basis for data processing is that consent. Otherwise, user data is processed on the basis of our legitimate interests (i.e. our interest in providing efficient, cost-effective and user-friendly services). In this context, we would also like to draw your attention to the information on the use of cookies in this privacy policy.
- Types of data processed: Usage data (e.g. page views and time spent on the site, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and functions); Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, individuals involved); Master data (e.g. full name, residential address, contact details, customer number, etc.); Contact details (e.g. postal and email addresses or telephone numbers); content data (e.g. text or image-based messages and posts, as well as related information such as details of authorship or the time of creation); location data (details of the geographical position of a device or a person).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing: Provision of our online services and user-friendliness.
- Retention and deletion: Deletion in accordance with the information provided in the section ‘General information on data storage and deletion’. Storage of cookies for up to 2 years (Unless otherwise stated, cookies and similar storage methods may be stored on users’ devices for a period of two years).
- Legal basis: Consent (Article 6(1), first sentence, point (a) of the GDPR). Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).
Further information on processing operations, procedures and services:
- Google Maps: We embed maps from the “Google Maps” service provided by Google. The data processed may include, in particular, users’ IP addresses and location data; Service provider: Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland; Legal basis: Consent (Article 6(1), first sentence, point (a) of the GDPR); Website: https://mapsplatform.google.com/; Privacy policy: https://policies.google.com/privacy. Basis for transfers to third countries: Adequacy decision (Ireland).
- YouTube videos: Video content; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal basis: Consent (Article 6(1), first sentence, point (a) of the GDPR); Website: https://www.youtube.com; Privacy policy: https://policies.google.com/privacy; Legal basis for transfers to third countries: Adequacy decision (Ireland). Option to object (opt-out): Opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=de, Settings for the display of adverts: https://myadcenter.google.com/personalizationoff.
Created using the free Datenschutz-Generator.de tool by Dr Thomas Schwenke