This privacy policy explains the nature, scope and purpose of the processing of personal data (hereinafter referred to as ‘data’) within our online service and the associated websites, functions and content, as well as external online presences, such as our social media profiles. (hereinafter collectively referred to as the ‘online service’). With regard to the terms used, such as ‘personal data’ or its ‘processing’, we refer to the definitions in Article 4 of the General Data Protection Regulation (GDPR).
Data controller:
COLLECTION BC Luxembourg S.A.
18, rue Robert Stümper
L – 2557 Luxembourg
German Commercial Register No.: B 188117
Managing Director: Dr Andre Helf
Contact for data protection enquiries:
Email address: datenschutz@ubc-collection.com
Types of data processed:
- Master data (e.g. names, addresses)
- Contact details (e.g. email, telephone numbers)
- Content data (e.g. text entries)
- Contract data (e.g. subject matter of the contract, term)
- Payment data (e.g. bank details, payment history)
- Usage data (e.g. websites visited, interest in content, access times)
- Meta/communication data (e.g. device information, IP addresses)
Processing of special categories of data (Article 9(1) of the GDPR):
- No special categories of data are processed.
Categories of data subjects affected by the processing:
- Customers, prospective customers, business partners
- Visitors and users of the online service
Hereinafter, we also refer to the data subjects collectively as ‘users’.
Purpose of processing:
- To provide the online service, its content and functions
- Provision of contractual services, customer support and customer care
- Responding to enquiries and communicating with users
- Marketing and advertising
- Security measures
Date: 14 August 2019
1. Applicable legal bases
In accordance with Article 13 of the GDPR, we hereby inform you of the legal bases for our data processing activities. Where the legal basis is not specified in this privacy policy, the following applies: The legal basis for obtaining consent is Article 6(1)(a) and Article 7 of the GDPR; the legal basis for processing to fulfil our services, carry out contractual obligations and respond to enquiries is Article 6(1)(b) of the GDPR; the legal basis for processing to fulfil our legal obligations is Article 6(1)(c) of the GDPR, and the legal basis for processing to safeguard our legitimate interests is Article 6(1)(f) of the GDPR. In the event that the vital interests of the data subject or another natural person necessitate the processing of personal data, Article 6(1)(d) of the GDPR serves as the legal basis.
2. Changes and updates to the privacy policy
We ask you to review the content of our privacy policy regularly. We will amend the Privacy Policy as soon as changes to the data processing activities we carry out make this necessary. We will inform you as soon as the changes require action on your part (e.g. consent) or any other individual notification.
3. Security measures
3.1. In accordance with Article 32 of the GDPR, and taking into account the state of the art, the costs of implementation and the nature, scope, circumstances and purposes of the processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, to ensure a level of security appropriate to the risk; These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical access to the data, as well as access to, input of, disclosure of, and the safeguarding of the availability of data, and ensuring data segregation. Furthermore, we have established procedures to ensure that data subjects’ rights are upheld, that data is erased and that we respond to any data breaches. Furthermore, we take the protection of personal data into account right from the development or selection of hardware, software and procedures, in accordance with the principle of data protection by design and by default (Article 25 of the GDPR).
3.2. The security measures include, in particular, the encrypted transmission of data between your browser and our server.
4. Cooperation with data processors and third parties
4.1. Where, in the course of our data processing, we disclose data to other individuals and organisations (data processors or third parties), transfer it to them or otherwise grant them access to the data, this is done only on the basis of a legal authorisation (e.g. where the transfer of data to third parties, such as payment service providers, is necessary for the performance of a contract in accordance with Article 6(1)(b) of the GDPR), you have given your consent, a legal obligation requires it, or on the basis of our legitimate interests (e.g. when engaging agents, web hosts, etc.).
4.2. Where we engage third parties to process data on the basis of a so-called ‘data processing agreement’, this is done in accordance with Article 28 of the GDPR.
5. Transfers to third countries
Where we process data in a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)), or where this occurs in the context of using third-party services or disclosure, or transfer of data to third parties, this shall only take place if it is necessary to fulfil our (pre-)contractual obligations, on the basis of your consent, due to a legal obligation, or on the basis of our legitimate interests. Subject to statutory or contractual authorisations, we shall only process data in a third country, or have it processed there, where the specific conditions set out in Articles 44 et seq. of the GDPR are met. This means that processing takes place, for example, on the basis of specific safeguards, such as the officially recognised determination that a level of data protection equivalent to that of the EU is in place (e.g. for the USA through the ‘Privacy Shield’) or compliance with officially recognised specific contractual obligations (so-called ‘standard contractual clauses’).
6. Rights of data subjects
6.1. You have the right to request confirmation as to whether data concerning you is being processed, and to obtain access to this data, as well as further information and a copy of the data, in accordance with Article 15 of the GDPR.
6.2. In accordance with Article 16 of the GDPR, you have the right to request that data relating to you be completed or that any inaccurate data relating to you be rectified.
6.3. You have the right, in accordance with Article 17 of the GDPR, to request that the data concerning you be erased without delay, or, alternatively, in accordance with Article 18 of the GDPR, to request a restriction on the processing of the data.
6.4. You have the right to request that the data concerning you which you have provided to us be made available to you in accordance with Article 20 of the GDPR and to request that it be transferred to other data controllers.
6.5. You also have the right, in accordance with Article 77 of the GDPR, to lodge a complaint with the competent supervisory authority.
7. Right to withdraw consent
You have the right to withdraw any consent you have given, with future effect, in accordance with Article 7(3) of the GDPR.
8. Right to object
You may object at any time to the future processing of your personal data in accordance with Article 21 of the GDPR. In particular, you may object to processing for the purposes of direct marketing.
9. Cookies and the right to object to direct marketing
We use temporary and permanent cookies, i.e. small files that are stored on users’ devices (for an explanation of the term and function, see the final section of this privacy policy). In some cases, cookies serve security purposes or are necessary for the operation of our online service (e.g. for displaying the website) or to save the user’s choice when confirming the cookie banner. In addition, we or our technology partners use cookies for audience measurement and marketing purposes, as explained further in this privacy policy.
A general objection to the use of cookies for online marketing purposes can be lodged with a number of services, particularly in the case of tracking, via the US website https://www.aboutads.info/ or the EU website www.youronlinechoices.com. Furthermore, the storage of cookies can be prevented by disabling them in your browser settings. Please note that, in such cases, you may not be able to use all the features of this website.
10. Deletion of data
10.1. The data we process will be deleted or its processing restricted in accordance with Articles 17 and 18 of the GDPR. Unless expressly stated in this privacy policy, the data stored by us will be erased as soon as it is no longer required for the purpose for which it was collected and there are no legal retention obligations preventing its erasure. Where data is not erased because it is required for other, legally permissible purposes, its processing will be restricted. This means that the data will be blocked and not processed for any other purposes. This applies, for example, to data that must be retained for commercial or tax law reasons.
10.2. Germany: In accordance with statutory requirements, data is retained in particular for 6 years pursuant to Section 257(1) of the German Commercial Code (HGB) (commercial ledgers, inventories, opening balance sheets, annual financial statements, commercial correspondence, accounting documents, etc.) and for 10 years in accordance with Section 147(1) of the German Fiscal Code (AO) (ledgers, records, management reports, accounting vouchers, commercial and business correspondence, documents relevant to taxation, etc.).
10.3. Austria: In accordance with statutory requirements, documents are retained for 7 years in particular, pursuant to Section 132(1) of the Austrian Federal Tax Code (BAO) (accounting records, supporting documents/invoices, accounts, business documents, statements of income and expenditure, etc.), for 22 years in relation to immovable property, and for 10 years in the case of documents relating to services provided electronically, telecommunications, radio and television services provided to non-business customers in EU Member States and for which the Mini One-Stop Shop (MOSS) is utilised.
11. Provision of contractual services
11.1. We process master data (e.g., names, addresses and contact details of users), contractual data (e.g. services used, names of contact persons, payment details) for the purpose of fulfilling our contractual obligations and providing services in accordance with Article 6(1)(b) of the GDPR. The fields marked as mandatory in online forms are required for the conclusion of the contract.
11.2. When you make a booking, reservation or contact enquiry, or use our online services, we store the IP address and the time of the respective user action. This data is stored on the basis of our legitimate interests, as well as the users’ interests in protection against misuse and other unauthorised use. This data is not, as a matter of principle, disclosed to third parties, unless it is necessary for the pursuit of our claims or there is a legal obligation to do so in accordance with Article 6(1)(c) of the GDPR.
11.3. We process usage data (e.g. the web pages visited on our website, interest in our products) and content data (e.g. entries in the contact form or user profile) for advertising purposes within a user profile, in order, for example, to display product recommendations based on the services the user has previously used.
11.4. Data is deleted once statutory warranty obligations and comparable obligations have expired; the necessity of retaining the data is reviewed every three years; in the case of statutory archiving obligations, deletion takes place upon their expiry (end of the retention period under commercial law (6 years) and tax law (10 years)); details in the customer account remain until the account is deleted.
12. Contact
12.1. When you contact us (via the contact form or by email), your details are processed for the purpose of handling your enquiry and its resolution in accordance with Article 6(1)(b) of the GDPR.
12.2. Users’ details may be stored in our Customer Relationship Management system (“CRM system”) or a similar enquiry management system.
12.3. We use the CRM system “Dynamic 365”, provided by Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA, on the basis of our legitimate interests (efficient and rapid processing of user enquiries). To this end, we have entered into a contract with Microsoft Corporation containing so-called standard contractual clauses, in which Microsoft Corporation undertakes to process user data solely in accordance with our instructions and to comply with EU data protection standards. Microsoft Corporation is also certified under the Privacy Shield Agreement, thereby providing an additional guarantee of compliance with European data protection law (https://www.privacyshield.gov/participant?id=a2zt0000000KzNaAAK&status=Active).
12.4. We delete enquiries once they are no longer required. We review the necessity of retaining them every two years; enquiries from customers who have a customer account are stored permanently, and we refer to the information relating to the customer account regarding deletion. In the case of statutory archiving obligations, deletion takes place once the commercial law (6 years) and tax law (10 years) retention periods have expired.
13. Collection of access data and log files
13.1. On the basis of our legitimate interests within the meaning of Article 6(1)(f) of the GDPR, we collect data on every access to the server on which this service is hosted (so-called server log files). Access data includes the name of the webpage accessed, the file, the date and time of access, the volume of data transferred, confirmation of successful access, browser type and version, the user’s operating system, the referrer URL (the page visited previously), IP address and the requesting provider.
13.2. Log file information is stored for a maximum of seven days for security reasons (e.g. to investigate cases of misuse or fraud) and is subsequently deleted. Data which must be retained for further evidence purposes is exempt from deletion until the relevant incident has been fully resolved.
14. Online Presence on Social Media
14.1. We maintain a presence on social media networks and platforms in order to communicate with customers, prospective customers and users active on these platforms and to inform them about our services. When accessing the respective networks and platforms, the terms and conditions and data processing policies of their respective operators apply.
14.2. Unless otherwise stated in our Privacy Policy, we process users’ data where they communicate with us within social networks and platforms, e.g. by posting comments on our social media accounts or sending us messages.
15. Cookies & Audience Measurement
15.1. Cookies are pieces of information transmitted by our web server or third-party web servers to users’ web browsers, where they are stored for later retrieval. Cookies may be small files or other forms of information storage.
15.2. We use ‘session cookies’, which are stored only for the duration of your current visit to our website (e.g. to save your login status or the shopping basket function, thereby enabling you to use our online service at all). A session cookie contains a randomly generated unique identification number, known as a session ID. A cookie also contains information about its origin and the storage period. These cookies cannot store any other data. Session cookies are deleted once you have finished using our online service and, for example, log out or close your browser.
15.3. Users are informed about the use of cookies in the context of pseudonymous audience measurement in this Privacy Policy.
15.4. If users do not wish cookies to be stored on their computer, they are asked to disable the relevant option in their browser’s settings. Stored cookies can be deleted via the browser’s settings. Disabling cookies may result in functional limitations on this website.
15.5. You can object to the use of cookies for audience measurement and advertising purposes via the Network Advertising Initiative’s opt-out page (http://optout.networkadvertising.org/) and, in addition, via the US website (http://www.aboutads.info/) or the European website (http://www.youronlinechoices.com/uk/your-ad-choices/).
16. Google Analytics
16.1. On the basis of our legitimate interests (i.e. our interest in the analysis, optimisation and commercial operation of our online service within the meaning of Article 6(1)(f) of the GDPR), we use Google Analytics, a web analytics service provided by Google LLC (‘Google’). Google uses cookies. The information generated by the cookie regarding users’ use of the online service is usually transmitted to a Google server in the USA and stored there.
16.2. Google is certified under the Privacy Shield Framework and thereby provides a guarantee of compliance with European data protection law (https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active).
16.3. Google will use this information on our behalf to analyse how users use our online service, to compile reports on activity within this online service, and to provide us with further services relating to the use of this online service and internet usage. In doing so, pseudonymous user profiles may be created from the processed data.
16.4. We use Google Analytics to ensure that adverts displayed within Google’s advertising services and those of its partners are shown only to users who have demonstrated an interest in our online service or who exhibit certain characteristics (e.g. interests in specific topics or products, determined on the basis of the webpages visited), which we transmit to Google (so-called ‘remarketing’ or ‘Google Analytics audiences’). We also use Remarketing Audiences to ensure that our adverts match users’ potential interests and do not come across as intrusive.
16.5. We only use Google Analytics with IP anonymisation enabled. This means that users’ IP addresses are truncated by Google within Member States of the European Union or in other signatory states to the Agreement on the European Economic Area. Only in exceptional cases is the full IP address transmitted to a Google server in the USA and truncated there.
16.6. The IP address transmitted by the user’s browser is not combined with other data held by Google. Users can prevent the storage of cookies by adjusting the settings in their browser software accordingly; users may also prevent Google from collecting the data generated by the cookie and relating to their use of the online service, as well as the processing of this data by Google, by downloading and installing the browser plug-in available via the following link: tools.google.com/dlpage/gaoptout.
16.7. Further information on Google’s use of data, as well as options for settings and opting out, can be found on Google’s websites: www.google.com/intl/de/policies/privacy/partners (“How Google uses data when you use our partners’ websites or apps”), policies.google.com/technologies/ads (“Data use for advertising purposes”), https://adssettings.google.com/authenticated (“Manage the information Google uses to show you adverts”).
17. Google Re/Marketing Services
17.1. We use the marketing and remarketing services (hereinafter “Google Marketing Services”) on the basis of our legitimate interests (i.e. our interest in the analysis, optimising and ensuring the economic operation of our online offering within the meaning of Article 6(1)(f) of the GDPR) the marketing and remarketing services (hereinafter ‘Google Marketing Services’) provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, (‘Google’).
17.2. Google is certified under the Privacy Shield Framework and thereby provides a guarantee of compliance with European data protection law (https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active).
17.3. Google’s marketing services enable us to display adverts on and for our website in a more targeted manner, so as to present users only with adverts that are likely to match their interests. If, for example, a user is shown adverts for products they have shown an interest in on other websites, this is referred to as ‘remarketing’. For these purposes, when our website or other websites on which Google Marketing Services are active are accessed, a Google code is executed directly by Google and so-called (re)marketing tags (invisible graphics or code, also known as ‘web beacons’) are embedded in the website. With the help of these, an individual cookie – i.e. a small file – is stored on the user’s device (comparable technologies may also be used instead of cookies). The cookies may be set by various domains, including google.com, doubleclick.net, invitemedia.com, admeld.com, googlesyndication.com or googleadservices.com. This file records which web pages the user has visited, what content they are interested in and which offers they have clicked on, as well as technical information about the browser and operating system, referring web pages, time of visit and further details regarding the use of the online service. The user’s IP address is also collected; however, we would like to point out, in the context of Google Analytics, that within Member States of the European Union or in other signatory states to the Agreement on the European Economic Area, the IP address is truncated and is only transferred in full to a Google server in the USA – where it is then truncated – in exceptional cases. The IP address is not merged with the user’s data held within other Google services. The information mentioned above may also be combined by Google with information from other sources. If the user subsequently visits other websites, they may be shown adverts tailored to their interests.
17.4. Users’ data is processed pseudonymously within the framework of Google Marketing Services. This means that Google does not, for example, store or process users’ names or email addresses, but instead processes the relevant data on a cookie-by-cookie basis within pseudonymous user profiles. In other words, from Google’s perspective, the adverts are not managed and displayed for a specifically identified individual, but for the cookie holder, regardless of who that cookie holder is. This does not apply if a user has expressly permitted Google to process the data without this pseudonymisation. The information collected by Google marketing services about users is transmitted to Google and stored on Google’s servers in the USA.
17.5. The Google marketing services we use include, amongst others, the online advertising programme ‘Google AdWords’. In the case of Google AdWords, each AdWords customer receives a different ‘conversion cookie’. Cookies cannot therefore be tracked across the websites of AdWords customers. The information collected via the cookie is used to generate conversion statistics for AdWords customers who have opted for conversion tracking. AdWords customers are informed of the total number of users who clicked on their advert and were redirected to a page tagged with a conversion tracking tag. However, they do not receive any information that can be used to personally identify users.
17.6. Further information on Google’s use of data for marketing purposes can be found on the overview page: policies.google.com/technologies/ads; Google’s privacy policy is available at policies.google.com/privacy.
17.7. If you wish to object to interest-based advertising via Google Marketing Services, you can use the settings and opt-out options provided by Google: https://adssettings.google.com/authenticated
17.8. We may also use the ‘Google Optimizer’ service. Google Optimizer enables us, as part of so-called ‘A/B testing’, to analyse the impact of various changes to a website (e.g. alterations to input fields, design, etc.). Cookies are stored on users’ devices for these testing purposes. Only pseudonymous user data is processed in this process.
17.9. Furthermore, we may use ‘Google Tag Manager’ to integrate and manage Google’s analytics and marketing services on our website.
18. Facebook Social Plugins
18.1. We use, on the basis of our legitimate interests (i.e. our interest in the analysis, optimisation and commercial operation of our online offering within the meaning of Article 6(1)(f) of the GDPR) social plugins (“plugins”) from the social network facebook.com, which is operated by Facebook Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (“Facebook”). The plugins may display interactive elements or content (e.g. videos, graphics or text posts) and can be recognised by one of the Facebook logos (a white ‘f’ on a blue tile, the terms ‘Like’, “Gefällt mir” or a “thumbs-up” symbol) or are labelled with the addition “Facebook Social Plugin”. The list and appearance of the Facebook Social Plugins can be viewed here: developers.facebook.com/docs/plugins/.
18.2. Facebook is certified under the Privacy Shield Agreement and thereby guarantees compliance with European data protection law (https://www.privacyshield.gov/participant?id=a2zt0000000GnywAAC&status=Active).
18.3. When a user accesses a feature of this website that contains such a plugin, their device establishes a direct connection to Facebook’s servers. The content of the plug-in is transmitted directly from Facebook to the user’s device and integrated into the online service. In the process, user profiles may be created from the data processed. We therefore have no influence over the scope of the data that Facebook collects via this plug-in and are therefore informing users in accordance with the information available to us.
18.4. By embedding the plugins, Facebook receives the information that a user has accessed the relevant page of the online service. If the user is logged into Facebook, Facebook can associate the visit with their Facebook account. When users interact with the plugins – for example, by clicking the ‘Like’ button or posting a comment – the relevant information is transmitted directly from their device to Facebook and stored there. Even if a user is not a member of Facebook, it is still possible that Facebook may obtain and store their IP address. According to Facebook, only an anonymised IP address is stored in Germany.
18.5. Users can find out about the purpose and scope of data collection, as well as the further processing and use of the data by Facebook, and the relevant rights and settings options for protecting users’ privacy, in Facebook’s privacy policy: www.facebook.com/about/privacy/;
18.6. If a user is a Facebook member and does not wish Facebook to collect data about them via this online service and link it to their membership data stored on Facebook, they must log out of Facebook and delete their cookies before using our online service. Further settings and the option to object to the use of data for advertising purposes are available within the Facebook profile settings: www.facebook.com/settings; or via the US website http://www.aboutads.info/ or the EU website www.youronlinechoices.com. These settings apply across all platforms, i.e. they are applied to all devices, such as desktop computers or mobile devices.
19. Integration of third-party services and content
19.1. Within our online offering, we incorporate third-party content and services on the basis of our legitimate interests (i.e. an interest in the analysis, optimisation and commercial operation of our online offering within the meaning of Article 6(1)(f) of the GDPR) to integrate content or services from third-party providers in order to incorporate their content and services, such as videos or fonts (hereinafter collectively referred to as “content”). This always presupposes that the third-party providers of this content will collect users’ IP addresses, as they would be unable to send the content to users’ browsers without the IP address. The IP address is therefore necessary for the display of this content. We endeavour to use only such content whose respective providers use the IP address solely for the purpose of delivering the content. Third-party providers may also use so-called pixel tags (invisible graphics, also known as ‘web beacons’) for statistical or marketing purposes. These ‘pixel tags’ enable information such as visitor traffic on the pages of this website to be analysed. This pseudonymous information may also be stored in cookies on the user’s device and may include, amongst other things, technical information about the browser and operating system, referring websites, time of visit and further details regarding the use of our online service; it may also be linked to such information from other sources.
19.2. The following list provides an overview of third-party providers and their content, together with links to their privacy policies, which contain further information on data processing and – in some cases already mentioned here – options to object (so-called ‘opt-out’):
- External fonts from Google, LLC, www.google.com/fonts (‘Google Fonts’). Google Fonts are integrated via a server request to Google (usually in the USA). Privacy policy: policies.google.com/privacy, opt-out: https://adssettings.google.com/authenticated
- Maps provided by the ‘Google Maps’ service from the third-party provider Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Privacy policy: www.google.com/policies/privacy/, opt-out: www.google.com/settings/ads/.
- Videos from the “YouTube” platform provided by the third-party provider Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Privacy policy: policies.google.com/privacy, opt-out: https://adssettings.google.com/authenticated
- Functions of the ClickCease service are integrated into our online offering. The company’s registered office (18th Haarba’a Street, Tel Aviv, Israel) is located in a so-called safe third country. The third-party provider collects, stores and processes information that your browser transmits automatically. This data primarily includes the browser, the operating system, the referrer URL, the hostname of the accessing computer and the IP address. Privacy policy: https://www.clickcease.com/tos.html
- Functions of the Instagram service are integrated into our online offering. These functions are provided by Instagram Inc., 1601 Willow Road, Menlo Park, CA, 94025, USA. If you are logged into your Instagram account, you can link the content of our pages to your Instagram profile by clicking the Instagram button. This enables Instagram to associate your visit to our pages with your user account. Please note that, as the provider of these pages, we have no knowledge of the content of the data transmitted or how it is used by Instagram. Privacy Policy: instagram.com/about/legal/privacy/;
- Within our online offering, we use the marketing functions (known as the ‘LinkedIn Insight Tag’) of the LinkedIn network. The provider is LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA. Each time one of our pages containing LinkedIn features is accessed, a connection is established with LinkedIn’s servers. LinkedIn is informed that you have visited our website using your IP address. With the help of the LinkedIn Insight Tag, we can, in particular, analyse the success of our campaigns within LinkedIn or identify target audiences for these campaigns based on users’ interaction with our online offering. If you are registered with LinkedIn, LinkedIn is able to associate your interaction with our online offering with your user account. Similarly, if you click on the LinkedIn ‘Recommend’ button whilst logged into your LinkedIn account, LinkedIn is able to associate your visit to our website with you and your user account. LinkedIn is certified under the Privacy Shield Agreement and thereby guarantees compliance with European data protection law (https://www.privacyshield.gov/participant?id=a2zt0000000L0UZAA0&status=Active). Privacy policy: www.linkedin.com/legal/privacy-policy, opt-out: www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
- Functions of the Twitter service or platform (hereinafter referred to as ‘Twitter’) may be integrated into our online offering. Twitter is a service provided by Twitter Inc., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA. These functions include the display of our posts on Twitter within our online service, a link to our Twitter profile, and the ability to interact with Twitter’s posts and functions, as well as to measure whether users access our online service via the advertisements we place on Twitter (so-called conversion tracking). Twitter is certified under the Privacy Shield Agreement and thereby guarantees compliance with European data protection law (https://www.privacyshield.gov/participant?id=a2zt0000000TORzAAO&status=Active). Privacy policy: twitter.com/de/privacy, opt-out: twitter.com/personalization.
- We use features from the XING network. The provider is XING AG, Dammtorstraße 29–32, 20354 Hamburg, Germany. Every time one of our pages containing XING features is accessed, a connection is established with XING’s servers. To the best of our knowledge, no personal data is stored in the process. In particular, IP addresses are not stored, nor is usage behaviour analysed. Privacy policy: www.xing.com/app/share.
- Web analytics and optimisation using the Hotjar service, provided by the third-party provider Hotjar Ltd, Level 2, St Julians Business Centre, 3, Elia Zammit Street, St Julians STJ 1000, Malta, Europe. Hotjar enables us to track user movements on websites where it is used (so-called ‘heatmaps’). For example, it shows how far users scroll and which buttons they click and how often. Furthermore, technical data such as the selected language, operating system, screen resolution and browser type are collected. In doing so, user profiles may be created, at least temporarily whilst visiting our website. In addition, Hotjar enables us to gather feedback directly from website users. In this way, we gain valuable insights to help us make our websites even faster and more user-friendly. Privacy policy: https://www.hotjar.com/privacy. Opt-out: https://www.hotjar.com/opt-out.
- Our website uses JavaScript code from the review portal eKomi Ltd., based at Markgrafenstr. 11, 10969 Berlin. The so-called eKomi widget enables us to integrate customer reviews into our website. Please note that, as the provider of the website, we have no knowledge of the content of any data that may be transmitted, nor of its use by eKomi (Privacy Policy: www.ekomi.de/de/datenschutz). The transfer of personal data to eKomi (e.g. email address, etc.), which is required for submitting a review, takes place only with the user’s consent. Participation is voluntary.
20. Use of SalesViewer® technology:
On this website, data is collected and stored using SalesViewer® technology from SalesViewer® GmbH on the basis of the website operator’s legitimate interests (Article 6(1)(f) of the GDPR) for marketing, market research and optimisation purposes.
For this purpose, a JavaScript-based code is used to collect company-related data and for the corresponding processing. The data collected using this technology is encrypted using a one-way function that cannot be reversed (known as hashing). The data is pseudonymised immediately and is not used to personally identify visitors to this website.
The data stored via SalesViewer is deleted as soon as it is no longer required for its intended purpose and there are no legal retention obligations preventing its deletion.
You may object to the collection and storage of data at any time with future effect by clicking on this link www.salesviewer.com/opt-out to prevent SalesViewer® from collecting data on this website in future. An opt-out cookie for this website will then be stored on your device. If you delete your cookies in this browser, you will need to click this link again.