Privacy policy

1. data protection at a glance

General information

The following information provides a simple overview of what happens to your personal data.

happens when you visit this website. Personal data is all data with which you

can be personally identified. For detailed information on the subject of data protection

Please refer to our privacy policy listed below this text.

Data collection on this website

Who is responsible for data collection on this website?

Data processing on this website is carried out by the website operator. Its contact details

can be found in the section “Information on the controller” in this privacy policy.

How do we collect your data?

On the one hand, your data is collected when you provide it to us. This can be, for example

data that you enter in a contact form.

Other data is collected automatically or with your consent by our IT systems when you visit the website. This is primarily technical data (e.g. internet browser, operating system or time of day).

of the page view). This data is collected automatically as soon as you enter this website.

What do we use your data for?

Some of the data is collected to ensure that the website is provided without errors. Other

Data may be used to analyse your user behaviour. If contracts are concluded via the website

The data transmitted will also be used for contract offers,

orders or other order enquiries are processed.

What rights do you have regarding your data?

You have the right at any time to request information free of charge about the origin, recipient and purpose of your

personal data stored by us. You also have the right to request the rectification or

to request the deletion of this data. If you have given your consent to data processing,

you can revoke this consent at any time for the future. You also have the right to

to request the restriction of the processing of your personal data in certain circumstances.

Furthermore, you have the right to lodge a complaint with the competent supervisory authority.

You can contact us at any time if you have further questions on the subject of data protection.

2. hosting

We host the content of our website with the following provider:

External hosting

This website is hosted externally. The personal data that is collected on this website,

are stored on the servers of the hoster(s). These may be IP addresses in particular,

Contact enquiries, meta and communication data, contract data, contact data, names, website accesses

and other data generated via a website.

External hosting is used for the purpose of contract fulfilment vis-à-vis our potential and existing customers.

existing customers (Art. 6 para. 1 lit. b GDPR) and in the interest of a secure, fast and efficient data processing.

Provision of our online offer by a professional provider (Art. 6 para. 1 lit. f GDPR).

If a corresponding consent has been requested, the processing is carried out exclusively on the basis of

on the basis of Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG, insofar as the consent permits the storage of data.

of cookies or access to information in the user’s end device (e.g. device fingerprinting) in the

within the meaning of the TDDDG. Consent can be revoked at any time.

Our hoster(s) will only process your data to the extent that this is necessary for the fulfilment of its

performance obligations and follow our instructions with regard to this data.

We use the following hoster(s):

1blu AG

Riedemannweg 60

D-13627 Berlin

 

Order processing

We have concluded an order processing contract (AVV) for the use of the above-mentioned service

concluded. This is a contract prescribed by data protection law, which

guarantees that it will only process the personal data of our website visitors in accordance with our

instructions and in compliance with the GDPR.

3 General notes and mandatory information

Data protection

The operators of these pages take the protection of your personal data very seriously. We treat your

personal data confidentially and in accordance with the statutory data protection regulations and

this privacy policy.

When you use this website, various personal data is collected.

Personal data is data that can be used to identify you personally. The present

Privacy Policy explains what data we collect and what we use it for. It also explains how

and for what purpose.

We would like to point out that data transmission over the Internet (e.g. when communicating by e-mail)

may have security gaps. Complete protection of data against access by third parties is not possible.

possible.

Note on the responsible body

The controller responsible for data processing on this website is

Thomas Ellmer

Köppleinstrasse 36

98724 Lauscha

Phone: 036702 352026

E-mail: th.ellmer@outlook.de

The controller is the natural or legal person who, alone or jointly with others, has the power to

the purposes and means of processing personal data (e.g. names, email addresses, etc.)

decides.

Storage duration

Unless a more specific storage period has been specified in this privacy policy, the data will remain

We will retain your personal data until the purpose for processing the data no longer applies. If you have a

request justified deletion or revoke consent to data processing,

your data will be deleted unless we have other legally permissible reasons for storing your data.

personal data (e.g. retention periods under tax or commercial law); in the case of

In the latter case, the deletion takes place after these reasons cease to apply.

General information on the legal basis for data processing on this website

Website

If you have consented to data processing, we process your personal data in the following ways

On the basis of Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR, insofar as special categories of data

processed in accordance with Art. 9 para. 1 GDPR. In the event of express consent to the transfer

personal data to third countries, data processing is also carried out on the basis of Art.

49 para. 1 lit. a GDPR. If you consent to the storage of cookies or access to information in

your end device (e.g. via device fingerprinting), the data processing also takes place

on the basis of § 25 para. 1 TDDDG. Consent can be revoked at any time. If your data for

fulfilment of the contract or for the implementation of pre-contractual measures, we process your personal data.

data on the basis of Art. 6 para. 1 lit. b GDPR. Furthermore, we process your data insofar as this

are required to fulfil a legal obligation on the basis of Art. 6 para. 1 lit. c GDPR.

Data processing may also be based on our legitimate interest in accordance with Art. 6 para. 1 lit. f

DSGVO are carried out. The relevant legal bases in each individual case are described in the following

The data subject is informed in the first paragraphs of this privacy policy.

Recipients of personal data

As part of our business activities, we work together with various external organisations. In doing so

In some cases, it is also necessary to transfer personal data to these external bodies.

We only pass on personal data to external bodies if this is necessary in the context of a

fulfilment of the contract if we are legally obliged to do so (e.g. transfer of data to third parties).

to tax authorities), if we have a legitimate interest pursuant to Art. 6 para. 1 lit. f GDPR in the disclosure

or if another legal basis permits the transfer of data. When using

We only disclose our customers’ personal data to processors on the basis of a valid data processing agreement.

contract on order processing. In the case of joint processing, a contract for

joint processing closed.

Revocation of your consent to data processing

Many data processing operations are only possible with your express consent. You can

revoke consent already granted at any time. The legality of the processing carried out until the revocation

Data processing remains unaffected by the cancellation.

Right to object to the collection of data in special cases and against

Direct marketing (Art. 21 GDPR)

IF THE DATA PROCESSING IS BASED ON ART. 6 ABS. 1 LIT. E OR F GDPR

YOU HAVE THE RIGHT TO WITHDRAW FROM THE CONTRACT AT ANY TIME FOR REASONS ARISING FROM YOUR PARTICULAR

SITUATION, AGAINST THE PROCESSING OF YOUR PERSONAL DATA

THIS ALSO APPLIES TO AN OBJECTION BASED ON THESE PROVISIONS.

PROFILING. THE RESPECTIVE LEGAL BASIS ON WHICH PROCESSING IS BASED,

PLEASE REFER TO THIS PRIVACY POLICY. IF YOU LODGE AN OBJECTION,

WE WILL NO LONGER PROCESS YOUR PERSONAL DATA CONCERNED, IT WILL BE

UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING.

THAT OUTWEIGH THEIR INTERESTS, RIGHTS AND FREEDOMS OR THAT

PROCESSING SERVES THE ESTABLISHMENT, EXERCISE OR DEFENCE OF LEGAL

LEGAL CLAIMS (OBJECTION PURSUANT TO ART. 21 PARA. 1 GDPR).

YOUR PERSONAL DATA IS PROCESSED FOR THE PURPOSE OF DIRECT MARKETING,

YOU HAVE THE RIGHT TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA AT ANY TIME.

PERSONAL DATA CONCERNED FOR THE PURPOSE OF SUCH ADVERTISING

THIS ALSO APPLIES TO PROFILING TO THE EXTENT THAT IT IS RELATED TO SUCH DIRECT MARKETING.

CONNECTION. IF YOU OBJECT, YOUR PERSONAL DATA WILL BE

SUBSEQUENTLY NO LONGER USED FOR THE PURPOSE OF DIRECT ADVERTISING (CONTRADICTION

IN ACCORDANCE WITH ART. 21 ABS. 2 GDPR).

Right to lodge a complaint with the competent supervisory authority

In the event of violations of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority.

supervisory authority, in particular in the Member State of their habitual residence, their place of work

or the location of the alleged infringement. The right of appeal exists without prejudice to other

administrative or judicial remedies.

Right to data portability

You have the right to access data that we process on the basis of your consent or in fulfilment of a contract.

automatically, to itself or to a third party in a commonly used, machine-readable format.

to have the data handed over. If you request the direct transfer of the data to another controller

this will only be done to the extent that it is technically feasible.

Information, correction and deletion

Within the framework of the applicable legal provisions, you have the right at any time to free-of-charge

information about your stored personal data, its origin and recipients and the

The purpose of the data processing and, if applicable, a right to rectification or erasure of this data. For this and

You can contact us at any time if you have further questions on the subject of personal data.

Right to restriction of processing

You have the right to request the restriction of the processing of your personal data.

You can contact us at any time to exercise this right. The right to restriction of processing exists in

the following cases:

If you dispute the accuracy of your personal data stored by us, we require

usually has time to check this. For the duration of the review, you have the right to

to demand the restriction of the processing of your personal data.

If the processing of your personal data has occurred/is occurring unlawfully, you can

request the restriction of data processing instead of erasure.

If we no longer need your personal data, but you need it to exercise your rights, we will delete it,

defence or assertion of legal claims, you have the right, instead of the

request the restriction of the processing of your personal data.

If you have lodged an objection in accordance with Art. 21 (1) GDPR, a balance must be struck between

your interests and our interests. As long as it is not yet clear whose interests

you have the right to obtain the restriction of the processing of your personal data.

to demand.

If you have restricted the processing of your personal data, this data – from

Apart from their storage – only with your consent or for the assertion, exercise or defence of legal claims.

defence of legal claims or for the protection of the rights of another natural or legal person

legal person or for reasons of important public interest of the European Union, or

of a Member State.

SSL or TLS encryption

This site uses cookies for security reasons and to protect the transmission of confidential content, such as

For example, orders or enquiries that you send to us as the site operator use SSL or TLS encryption. You can recognise an encrypted connection by the fact that the address line of the browser is marked by

“http://” changes to “https://” and on the lock symbol in your browser line.

If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.

can be read by third parties.

4. data collection on this website

Cookies

Our Internet pages use so-called “cookies”. Cookies are small data packets and are aimed at

do no damage to your end device. They are either temporarily blocked for the duration of a session

(session cookies) or permanently (permanent cookies) on your end device. Session cookies

are automatically deleted at the end of your visit. Permanent cookies remain on your end device

stored until you delete them yourself or they are automatically deleted by your web browser.

Cookies may originate from us (first-party cookies) or from third-party companies (so-called third-party cookies). Third-party cookies enable the integration of certain services from

Third-party companies within websites (e.g. cookies for processing payment services).

Cookies have various functions. Many cookies are technically necessary because certain

website functions would not work without them (e.g. the shopping basket function or the display of

of videos). Other cookies can be used to analyse user behaviour or for advertising purposes.

can be used.

Cookies that are required to carry out the electronic communication process, to provide

certain functions that you have requested (e.g. for the shopping basket function) or to optimise the

website (e.g. cookies for measuring the web audience) are required (necessary cookies), are stored on

stored on the basis of Art. 6 para. 1 lit. f GDPR, unless another legal basis is specified.

The website operator has a legitimate interest in the storage of necessary cookies for the purpose of

technically error-free and optimised provision of its services. If consent to the

storage of cookies and comparable recognition technologies, the storage of cookies and comparable recognition

Processing exclusively on the basis of this consent (Art. 6 para. 1 lit. a GDPR and Section 25 para. 1

TDDDG); consent can be revoked at any time.

You can set your browser so that you are informed about the setting of cookies and

Allow cookies only in individual cases, exclude the acceptance of cookies for certain cases or in general

and activate the automatic deletion of cookies when the browser is closed. With the

Deactivating cookies may limit the functionality of this website.

You can find out which cookies and services are used on this website in this

privacy policy.

Contact form

If you send us enquiries via the contact form, your details from the contact form will be

Enquiry form including the contact details you provide there for the purpose of processing the request

and stored by us in the event of follow-up questions. We will not disclose this data without your

Consent further.

This data is processed on the basis of Art. 6 para. 1 lit. b GDPR, provided that your enquiry is related to

is related to the fulfilment of a contract or for the implementation of pre-contractual measures

is necessary. In all other cases, the processing is based on our legitimate interest in the

effective processing of the enquiries addressed to us (Art. 6 Para. 1 lit. f GDPR) or on your consent.

Consent (Art. 6 para. 1 lit. a GDPR) if this has been requested; consent can be revoked at any time.

revocable.

The data you enter in the contact form will remain with us until you ask us to delete it.

revoke your consent to the storage or the purpose for the data storage no longer applies

(e.g. after your enquiry has been processed). Mandatory legal provisions –

in particular retention periods – remain unaffected.

5. plugins and tools

YouTube with extended data protection

This website embeds videos from the YouTube website. The operator of the website is Google Ireland Limited

(“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.

When you visit one of these websites on which YouTube is integrated, a connection is established to the

servers of YouTube. This tells the YouTube server which of our pages you have visited.

have visited. If you are logged into your YouTube account, you enable YouTube to recognise your

assign your surfing behaviour directly to your personal profile. You can prevent this by logging out of

log out of your YouTube account.

We use YouTube in extended data protection mode. Videos that are displayed in extended data protection mode

are not used to personalise the surfing experience on YouTube, according to YouTube.

are used. Adverts that are displayed in extended data protection mode are also not

personalised. In extended data protection mode, no cookies are set. Instead

However, so-called local storage elements are stored in the user’s browser, which are similar to cookies.

contain personal data and can be used for recognition. Details on the

extended data protection mode can be found here:

https://support.google.com/youtube/answer/171780.

If necessary, further data processing operations may be carried out after the activation of a YouTube video.

which we have no influence over.

The use of YouTube is in the interest of an appealing presentation of our online offers.

This constitutes a legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR. Insofar as a corresponding

consent has been requested, the processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a

DSGVO and § 25 para. 1 TDDDG, insofar as the consent permits the storage of cookies or access to

information in the user’s end device (e.g. device fingerprinting) within the meaning of the TDDDG. The

Consent can be revoked at any time.

Further information about data protection at YouTube can be found in their privacy policy at:

https://policies.google.com/privacy?hl=de.

The company is certified in accordance with the “EU-US Data Privacy Framework” (DPF). The

DPF is an agreement between the European Union and the USA that ensures compliance with

European data protection standards for data processing in the USA. Each according to

The company certified by the DPF undertakes to comply with these data protection standards. Further

Information on this can be obtained from the provider under the following link:

https://www.dataprivacyframework.gov/participant/5780.

Google Fonts (local hosting)

This site uses so-called Google Fonts, which are provided by Google, for the uniform display of fonts.

are provided. The Google fonts are installed locally. A connection to Google servers takes place

does not take place.

You can find more information about Google Fonts at

https://developers.google.com/fonts/faq and in Google’s privacy policy:

https://policies.google.com/privacy?hl=de.

OpenStreetMap

We use the OpenStreetMap (OSM) map service.

We integrate the map material from OpenStreetMap on the server of the OpenStreetMap Foundation, St

John’s Innovation Centre, Cowley Road, Cambridge, CB4 0WS, United Kingdom. Great Britain is regarded as

safe third country under data protection law. This means that the UK has a level of data protection

that corresponds to the level of data protection in the European Union. When using the

OpenStreetMap maps, a connection is established to the servers of the OpenStreetMap Foundation.

Among other things, your IP address and other information about your behaviour on this website may be transmitted to the

OSMF can be forwarded. OpenStreetMap may store cookies in your browser for this purpose

or uses comparable recognition technologies.

The use of OpenStreetMap is in the interest of an appealing presentation of our online offers and an easy findability of the places indicated by us on the website. This represents a

legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR. Insofar as a corresponding consent

was queried, the processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a GDPR and §

25 para. 1 TDDDG, insofar as the consent permits the storage of cookies or access to information

in the user’s end device (e.g. device fingerprinting) within the meaning of the TDDDG. The consent is

revocable at any time.

Cloudflare Turnstile

We use Cloudflare Turnstile (hereinafter referred to as “Turnstile”) on this website. The provider is Cloudflare

Inc, 101 Townsend St., San Francisco, CA 94107, USA (hereinafter referred to as “Cloudflare”).

Turnstile is used to check whether the data input on this website (e.g. in a

contact form) by a human or by an automated programme. For this purpose

Turnstile analyses the behaviour of the website visitor based on various characteristics.

This analysis starts automatically as soon as the website visitor visits a website with Turnstile

enters. To analyse this, Turnstile evaluates various information (e.g. IP address, dwell time of the

website visitor on the website or mouse movements made by the user). The data collected during the analysis

collected data is forwarded to Cloudflare.

The data is stored and analysed on the basis of Art. 6 para. 1 lit. f GDPR. The

Website operators have a legitimate interest in protecting their websites from misuse.

from automated spying and SPAM. If a corresponding consent is requested

the processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a GDPR and § 25 para. 1

TDDDG, insofar as the consent permits the storage of cookies or access to information in the

device of the user (e.g. device fingerprinting) within the meaning of the TDDDG. The consent is

revocable at any time.

Data processing is based on standard contractual clauses, which you can find here:

https://www.cloudflare.com/cloudflare-customer-scc/.

Further information on Cloudflare Turnstile can be found in the privacy policy at

https://www.cloudflare.com/cloudflare-customer-dpa/.

The company is certified in accordance with the “EU-US Data Privacy Framework” (DPF). The

DPF is an agreement between the European Union and the USA that ensures compliance with

European data protection standards for data processing in the USA. Each according to

The company certified by the DPF undertakes to comply with these data protection standards. Further

Information on this can be obtained from the provider under the following link:

https://www.dataprivacyframework.gov/participant/5666.

Source:

https://www.e-recht24.de