Privacy Policy
This Privacy Policy informs you about the nature, scope and purpose of the processing of personal data (hereinafter referred to as "data") within our online offering and the related websites, features and content, as well as external online presences, such as our social media profiles (collectively referred to as the "online offering"). With regard to the terminology used, such as "processing" or "controller", we refer to the definitions in Article 4 of the General Data Protection Regulation (GDPR).
Controller
Andrej Fahn
Breidenbachstr 19
51373 Leverkusen
Types of data processed
- Inventory data (e.g., names, addresses).
- Contact data (e.g., e‑mail addresses, phone numbers).
- Content data (e.g., text entries, photographs, videos).
- Usage data (e.g., visited websites, interest in content, access times).
- Meta/communication data (e.g., device information, IP addresses).
Categories of data subjects
Visitors and users of the online offering (hereinafter we refer to the data subjects collectively as "users").
Purpose of processing
- Provision of the online offering, its functions and content.
- Responding to contact requests and communicating with users.
- Security measures.
- Reach measurement/marketing
Terminology
"Personal data" means any information relating to an identified or identifiable natural person (hereinafter "data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. cookie) or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
"Processing" means any operation or set of operations which is performed on personal data, whether or not by automated means. The term is broad and covers practically any handling of data.
"Pseudonymisation" means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person.
"Profiling" means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s work performance, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.
"Controller" means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
"Processor" means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
Relevant legal bases
In accordance with Article 13 GDPR, we inform you of the legal bases for our data processing. Unless the legal basis is stated in this Privacy Policy, the following applies: the legal basis for obtaining consent is Art. 6(1)(a) and Art. 7 GDPR; the legal basis for processing for the performance of our services and the implementation of contractual measures as well as responding to enquiries is Art. 6(1)(b) GDPR; the legal basis for processing to fulfil our legal obligations is Art. 6(1)(c) GDPR; and the legal basis for processing to safeguard our legitimate interests is Art. 6(1)(f) GDPR. Where the vital interests of the data subject or of another natural person require processing of personal data, Art. 6(1)(d) GDPR serves as the legal basis.
Security measures
In accordance with Art. 32 GDPR, and taking into account the state of the art, implementation costs and the nature, scope, circumstances and purposes of processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk.
These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical access to data, as well as access, input, disclosure, availability and separation of data. Furthermore, we have established procedures to ensure the exercise of data subject rights, deletion of data and responses to data threats. We also take the protection of personal data into account in the development and selection of hardware, software and processes in accordance with the principle of data protection by design and by default settings (Art. 25 GDPR).