Data Policy

This Privacy Policy informs you about the nature, scope, and purpose of the processing of personal data (hereinafter referred to as “data”) within the context of providing our services, as well as within our online offering and the associated websites, functions, and content, including external online presences such as our social media profiles (hereinafter collectively referred to as the “Online Offering”). With regard to the terminology used, such as “processing” or “controller,” we refer to the definitions in Article 4 of the General Data Protection Regulation (GDPR).

Controller

Lena Sennekamp
Hertener Straße 208
45659 Recklinghausen
Germany

Phone: +49 171 4409479
Email: [email protected]

Controller: Lena Sennekamp

Types of Data Processed

  • Inventory data (e.g., personal master data, names, or addresses)

  • Contact data (e.g., email address, phone numbers)

  • Content data (e.g., text entries, photographs, videos)

  • Usage data (e.g., visited websites, interest in content, access times)

  • Meta/communication data (e.g., device information, IP addresses)

Categories of Data Subjects

Visitors and users of the Online Offering (hereinafter collectively referred to as “users”).

Purpose of Processing

  • Provision of the Online Offering, its functions, and content

  • Responding to contact requests and communicating with users

  • Security measures

  • Reach measurement / marketing

Definitions

“Personal data” means any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, particularly by reference to an identifier such as a name, identification number, location data, online identifier (e.g., cookie), or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.

“Processing” means any operation or set of operations performed on personal data, whether or not by automated means. The term is broad and covers virtually any handling of data.

“Pseudonymization” means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and subject to technical and organizational measures ensuring that the personal data are not attributed to an identified or identifiable natural person.

“Profiling” means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, particularly to analyze or predict aspects concerning work performance, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements.

“Controller” means the natural or legal person, public authority, agency, or other body which alone or jointly with others determines the purposes and means of processing personal data.

“Processor” means a natural or legal person, public authority, agency, or other body which processes personal data on behalf of the controller.

Applicable Legal Bases

In accordance with Article 13 GDPR, we inform you of the legal bases of our data processing activities. For users within the scope of the GDPR, i.e., the EU and EEA, the following applies unless the legal basis is specifically stated in this Privacy Policy:

  • The legal basis for obtaining consent is Article 6(1)(a) and Article 7 GDPR.

  • The legal basis for processing for the performance of our services and implementation of contractual measures as well as responding to inquiries is Article 6(1)(b) GDPR.

  • The legal basis for processing to fulfill legal obligations is Article 6(1)(c) GDPR.

  • If processing is necessary to protect vital interests of the data subject or another natural person, Article 6(1)(d) GDPR serves as the legal basis.

  • The legal basis for processing necessary for the performance of a task carried out in the public interest or in the exercise of official authority is Article 6(1)(e) GDPR.

  • The legal basis for processing to safeguard our legitimate interests is Article 6(1)(f) GDPR.

  • The processing of data for purposes other than those for which they were collected is governed by Article 6(4) GDPR.

  • The processing of special categories of data (according to Article 9(1) GDPR) is governed by Article 9(2) GDPR.

Security Measures

We implement appropriate technical and organizational measures in accordance with legal requirements, taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of processing, as well as the varying likelihood and severity of risks to the rights and freedoms of natural persons, in order to ensure a level of security appropriate to the risk.

These measures include, in particular, safeguarding the confidentiality, integrity, and availability of data by controlling physical access to the data, as well as access to, input, disclosure, safeguarding availability, and separation of data. Furthermore, we have established procedures ensuring the exercise of data subject rights, deletion of data, and responses to data breaches. We also take data protection into account during the development and selection of hardware, software, and procedures, in accordance with the principle of data protection by design and by default.

Cooperation with Processors and Third Parties

If, within the scope of our processing, we disclose data to other persons or companies (processors, jointly responsible parties, or third parties), transfer data to them, or otherwise grant them access to the data, this is done only on the basis of legal permission (e.g., if transfer of data to third parties, such as payment service providers, is necessary for contract fulfillment), users have consented, a legal obligation requires this, or on the basis of our legitimate interests (e.g., when using agents, web hosts, etc.).

If we disclose, transfer, or otherwise grant access to data to companies within our corporate group, this is done particularly for administrative purposes as a legitimate interest and otherwise on a basis compliant with legal requirements.

Transfers to Third Countries

If we process data in a third country (i.e., outside the European Union (EU), the European Economic Area (EEA), or the Swiss Confederation), or if this occurs in the context of using third-party services or disclosure or transfer of data to other persons or companies, this is done only if it is necessary for fulfilling our (pre-)contractual obligations, based on your consent, due to a legal obligation, or on the basis of our legitimate interests. Subject to legal or contractual permissions, we process or have data processed in a third country only if the legal requirements are met. This means processing is carried out, for example, on the basis of specific guarantees, such as officially recognized determination of an EU-equivalent level of data protection or compliance with officially recognized contractual obligations.

Rights of Data Subjects

You have the right to request confirmation as to whether relevant data are being processed and to obtain information about such data, as well as further information and a copy of the data in accordance with legal requirements.

You have the right, in accordance with legal requirements, to request completion of data concerning you or correction of inaccurate data concerning you.

You have the right, in accordance with legal requirements, to request the immediate deletion of relevant data or, alternatively, restriction of the processing of the data.

You have the right to request that the data concerning you that you have provided to us be received in accordance with legal requirements and to request their transfer to other controllers.

You also have the right to lodge a complaint with the competent supervisory authority in accordance with legal requirements.

Right of Withdrawal

You have the right to withdraw granted consent with effect for the future.

Right to Object

You may object at any time to the future processing of data concerning you in accordance with legal requirements. The objection may particularly be made against processing for direct marketing purposes.

Cookies and Right to Object to Direct Advertising

“Cookies” are small files stored on users’ computers. Different information can be stored within cookies. A cookie primarily serves to store information about a user (or the device on which the cookie is stored) during or after their visit to an Online Offering. Temporary cookies, also known as “session cookies” or “transient cookies,” are deleted after a user leaves an Online Offering and closes their browser. Such a cookie may store the contents of a shopping cart in an online shop or login status. “Permanent” or “persistent” cookies remain stored even after the browser is closed. For example, the login status can be stored if users revisit after several days. Likewise, user interests can be stored in such cookies for reach measurement or marketing purposes. “Third-party cookies” are cookies offered by providers other than the controller operating the Online Offering (otherwise they are referred to as “first-party cookies”).

We may use temporary and permanent cookies and provide information about this within our Privacy Policy.

If users do not want cookies stored on their computer, they are asked to deactivate the corresponding option in their browser settings. Stored cookies can be deleted in the browser settings. Excluding cookies may result in functional restrictions of this Online Offering.

A general objection to the use of cookies for online marketing purposes can be declared for many services, especially in the case of tracking, via the US website http://www.aboutads.info/choices/ or the EU website http://www.youronlinechoices.com/. Furthermore, cookies can be disabled in browser settings. Please note that in this case not all functions of this Online Offering may be usable.

Deletion of Data

The data processed by us are deleted or restricted in their processing in accordance with legal requirements. Unless expressly stated otherwise within this Privacy Policy, data stored by us are deleted as soon as they are no longer required for their intended purpose and no legal retention obligations prevent deletion.

If the data are not deleted because they are required for other legally permissible purposes, their processing is restricted. This means the data are blocked and not processed for other purposes. This applies, for example, to data that must be retained for commercial or tax law reasons.

Changes and Updates to the Privacy Policy

We ask you to regularly inform yourself about the content of our Privacy Policy. We adapt the Privacy Policy as soon as changes to the data processing activities we carry out make this necessary. We will inform you as soon as changes require an act of cooperation on your part (e.g., consent) or other individual notification.

Business-Related Processing

Additionally, we process:

  • Contract data (e.g., subject matter of the contract, duration, customer category)

  • Payment data (e.g., bank details, payment history)

from our customers, prospective customers, and business partners for the purpose of providing contractual services, customer support, marketing, advertising, and market research.

[Translation continues similarly for all remaining sections.]

  • Hinweis: Dieses Projekt wurde mit der Marketingsoftware FunnelCockpit realisiert. Für den Inhalt ist der Seitenbetreiber verantwortlich.