Privacy Policy
Status: February 12, 2025
Preamble
With the following privacy policy, we would like to inform you about the types of your personal data (hereinafter also referred to as "data") that we process, for what purposes, and to what extent. This privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and, in particular, on our websites, in mobile applications, and within external online presences such as our social media profiles (hereinafter collectively referred to as the "online offering").
The terms used are not gender-specific.
Controller
Auktionshaus Ulrich Felzmann GmbH & Co. KG
Bussardweg 18
41468 Neuss
Authorized representatives: Dr. Reinhard Fischer, Managing Director
Email address: info@felzmann.de
Phone: +49 (0) 211 – 550 440
Legal notice: felzmann-legal-notice-en.html
Data Protection Officer
Data protection officer: Hans-Jürgen Zieger
Email: datenschutz@felzmann.de
Overview of Processing Activities
The following overview summarizes the types of data processed and the purposes of their processing, and refers to the data subjects concerned.
Types of Data Processed
- Inventory data.
- Payment data.
- Location data.
- Contact data.
- Content data.
- Contract data.
- Usage data.
- Meta, communication, and procedural data.
- Event data (Facebook).
Categories of Data Subjects
- Customers.
- Prospective customers.
- Communication partners.
- Users.
- Sweepstakes and competition participants.
- Business and contractual partners.
- Participants.
Purposes of Processing
- Provision of contractual services and customer service.
- Contact requests and communication.
- Security measures.
- Direct marketing.
- Reach measurement.
- Tracking.
- Office and organizational procedures.
- Managing and responding to inquiries.
- Conducting sweepstakes and competitions.
- Feedback.
- Marketing.
- User-related profiles.
- Provision of our online offering and user-friendliness.
- Information technology infrastructure.
Relevant Legal Bases
Below is an overview of the legal bases under the GDPR on which we process personal data. Please note that, in addition to the provisions of the GDPR, national data protection regulations in your or our country of residence or registered office may apply. Should more specific legal bases be relevant in individual cases, we will inform you of these in this privacy policy.
- Consent (Art. 6 (1) sentence 1 lit. a GDPR) – The data subject has given consent to the processing of their personal data for one or more specific purposes.
- Performance of a contract and pre-contractual inquiries (Art. 6 (1) sentence 1 lit. b GDPR) – Processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract.
- Legal obligation (Art. 6 (1) sentence 1 lit. c GDPR) – Processing is necessary for compliance with a legal obligation to which the controller is subject.
- Legitimate interests (Art. 6 (1) sentence 1 lit. f GDPR) – Processing is necessary for the purposes of the legitimate interests pursued by the controller or a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.
In addition to the data protection provisions of the GDPR, national regulations on data protection apply in Germany. This includes, in particular, the Act to Adapt Data Protection Law to Regulation (EU) 2016/679 (Bundesdatenschutzgesetz – BDSG). The BDSG contains, in particular, special provisions on the right to information, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, and automated individual decision-making, including profiling. It further governs data processing for purposes of the employment relationship (Sec. 26 BDSG), in particular with regard to the establishment, performance, or termination of employment relationships, as well as the consent of employees. In addition, the data protection laws of the individual German federal states may apply.
Security Measures
In accordance with statutory requirements, and taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we take appropriate technical and organizational measures to ensure a level of protection appropriate to the risk.
Such measures include, in particular, safeguarding the confidentiality, integrity, and availability of data by controlling physical and electronic access to the data as well as access to, input, transmission, and availability of, and separation of, such data. We have also established procedures to ensure the exercise of data subjects' rights, the erasure of data, and responses to any compromise of data. Furthermore, we take the protection of personal data into account as early as the development or selection of hardware, software, and procedures, in accordance with the principle of data protection by design and by default.
Shortening of the IP address: If IP addresses are processed by us or by the service providers and technologies we use, and processing of the complete IP address is not required, the IP address is shortened (also referred to as "IP masking"). In this process, the last two digits, or the last part of the IP address after a period, are removed or replaced with placeholders. Shortening the IP address is intended to prevent or substantially impede the identification of a person based on their IP address.
TLS encryption (https): To protect the data you transmit via our online offering, we use TLS encryption. You can recognize such encrypted connections by the prefix https:// in your browser's address bar.
Disclosure of Personal Data
In the course of our processing of personal data, it may occur that data is transmitted to, or disclosed to, other bodies, companies, legally independent organizational units, or persons. Recipients of this data may include, for example, service providers entrusted with IT tasks, or providers of services and content that are integrated into a website. In such cases, we comply with statutory requirements and, in particular, conclude appropriate contracts or agreements with recipients of your data that serve to protect your data.
Data disclosure within the organization: We may transmit personal data to other bodies within our organization, or grant them access to such data. Where such disclosure is made for administrative purposes, it is based on our legitimate business and economic interests, or is made where necessary for the performance of our contractual obligations, or where the consent of the data subject or a statutory permission exists.
Erasure of Data
The data we process will be erased in accordance with statutory requirements as soon as consent permitting its processing is revoked, or other permissions no longer apply (e.g. when the purpose of processing this data has ceased to apply, or the data is not required for that purpose). If the data is not erased because it is required for other legally permissible purposes, its processing is restricted to those purposes. That is, the data is blocked and not processed for other purposes. This applies, for example, to data that must be retained for commercial or tax law reasons, or whose storage is necessary for the assertion, exercise, or defense of legal claims, or to protect the rights of another natural or legal person.
Our privacy notices may also contain further information on the retention and erasure of data that takes precedence for the respective processing activities.
Use of Cookies
Cookies are small text files, or other storage markers, that store information on end devices and read information from end devices. For example, to store the login status in a user account, the contents of a shopping cart in an e-shop, the content accessed, or the functions used in an online offering. Cookies may also be used for various purposes, e.g. for the functionality, security, and convenience of online offerings, as well as for the creation of analyses of visitor traffic.
Notes on consent: We use cookies in accordance with statutory provisions. We therefore obtain prior consent from users, except where this is not legally required. Consent is not required, in particular, if the storage and reading of information, including cookies, is strictly necessary to provide users with a telemedia service they have explicitly requested (i.e. our online offering). Strictly necessary cookies generally include cookies with functions relating to the display and operation of the online offering, load balancing, security, storage of user preferences and choices, or similar purposes related to the provision of the main and ancillary functions of the online offering requested by users. Revocable consent is clearly communicated to users and includes information on the respective use of cookies.
Notes on data protection legal bases: The legal basis on which we process users' personal data using cookies depends on whether we ask users for consent. If users consent, the legal basis for processing your data is the consent given. Otherwise, data processed using cookies is processed on the basis of our legitimate interests (e.g. in the efficient operation of our online offering and improvement of its usability), or, if this occurs as part of fulfilling our contractual obligations, where the use of cookies is necessary to fulfil our contractual obligations. We explain the purposes for which cookies are processed by us in the course of this privacy policy, or as part of our consent and processing procedures.
Storage period: With regard to storage period, the following types of cookies are distinguished:
- Temporary cookies (also: session cookies): Temporary cookies are deleted at the latest once a user has left an online offering and closed their end device (e.g. browser or mobile app).
- Permanent cookies: Permanent cookies remain stored even after the end device has been closed. For example, this allows the login status to be saved, or preferred content to be displayed directly when the user visits a website again. Likewise, data collected via cookies may be used for reach measurement. Unless we provide users with explicit information on the type and storage period of cookies (e.g. as part of obtaining consent), users should assume that cookies are permanent and that the storage period may be up to two years.
General notes on revocation and objection (opt-out): Users can revoke any consent given at any time, and may also object to processing in accordance with statutory provisions under Article 21 GDPR. Users can also declare their objection via their browser settings, e.g. by disabling the use of cookies (which may also limit the functionality of our online services). An objection to the use of cookies for online marketing purposes can also be declared via the websites optout.aboutads.info and youronlinechoices.com.
Further information on processing operations, procedures, and services:
- Complianz: Cookie consent management; service provider: hosted locally on our server, no data is passed on to third parties; website: complianz.io; privacy policy: complianz.io/legal; further information: an individual user ID, language, and the types of consent given and the time they were given are stored server-side and in a cookie on the user's device.
Business Services
We process the data of our contractual and business partners, e.g. customers and prospective customers (collectively referred to as "contractual partners"), in the context of contractual and comparable legal relationships, as well as related measures and communication with contractual partners (or prior to entering into a contract), e.g. to respond to inquiries.
We process this data in order to fulfil our contractual obligations. This includes, in particular, the obligations to provide the agreed services, any update obligations, and remedies for warranty and other performance disruptions. We further process the data to safeguard our rights and for administrative tasks associated with these obligations, as well as for company organization. We also process the data on the basis of our legitimate interest in proper and economically sound business management, as well as in security measures to protect our contractual partners and our business operations against misuse, and against threats to their data, secrets, information, and rights (e.g. involving telecommunications, transport, and other ancillary services, as well as subcontractors, banks, tax and legal advisors, payment service providers, or tax authorities). We only disclose the data of contractual partners to third parties, within the scope of applicable law, to the extent required for the aforementioned purposes or to fulfil legal obligations. Contractual partners will be informed of any further forms of processing, e.g. for marketing purposes, within the context of this privacy policy.
We inform contractual partners which data is required for the aforementioned purposes prior to, or in the course of, data collection, e.g. in online forms, through special markings (e.g. colors) or symbols (e.g. asterisks or similar), or in person.
We erase the data after expiry of statutory warranty and comparable obligations, i.e. generally after 4 years, unless the data is stored in a customer account, e.g. for as long as it must be retained for statutory archiving reasons. The statutory retention period is ten years for tax- relevant documents as well as for commercial books, inventories, opening balance sheets, annual financial statements, the work instructions required to understand these documents, and other organizational records and accounting vouchers, and six years for received commercial and business letters and copies of dispatched commercial and business letters. The period begins at the end of the calendar year in which the last entry was made in the book, the inventory, the opening balance sheet, the annual financial statement, or the management report was prepared, the commercial or business letter was received or dispatched, the accounting voucher was created, the record was made, or the other document was created.
To the extent we use third-party providers or platforms to provide our services, the terms and conditions and privacy notices of the respective third-party providers or platforms apply in the relationship between users and the providers.
Further information on processing operations, procedures, and services:
- Shop and e-commerce: We process our customers' data to enable them to select, purchase, or order the selected products, goods, and related services, as well as to pay for and receive delivery or fulfilment of these. Where necessary for order fulfilment, we engage service providers, in particular postal, freight forwarding, and shipping companies, to carry out delivery or fulfilment for our customers. We use the services of banks and payment service providers to process payment transactions. The required information is marked as such in the ordering or comparable purchasing process and includes the information required for delivery, provision, and billing, as well as contact information to enable any follow-up communication; legal bases: performance of a contract and pre-contractual inquiries (Art. 6 (1) sentence 1 lit. b GDPR).
Provision of the Online Offering and Web Hosting
We process user data in order to provide our online services to users. For this purpose, we process the user's IP address, which is necessary to transmit the content and functions of our online services to the user's browser or end device.
Further information on processing operations, procedures, and services:
- Collection of access data and log files: Access to our online offering is logged in the form of so-called "server log files." Server log files may include the address and name of the web pages and files accessed, the date and time of access, the amount of data transferred, notification of successful access, browser type and version, the user's operating system, referrer URL (the previously visited page), and, generally, the IP address and the requesting provider. Server log files can be used, on the one hand, for security purposes, e.g. to prevent server overload (in particular in the case of malicious attacks, so-called DDoS attacks), and, on the other hand, to ensure server load and stability; legal bases: legitimate interests (Art. 6 (1) sentence 1 lit. f GDPR); erasure of data: log file information is stored for a maximum of 30 days and then deleted or anonymized. Data whose continued storage is required for evidentiary purposes is exempt from erasure until the relevant incident is finally resolved.
- Email sending and hosting: The web hosting services we use also include the sending, receiving, and storage of emails. For these purposes, the addresses of recipients and senders, as well as further information relating to email transmission (e.g. the providers involved) and the content of the respective emails, are processed. This data may also be processed for the purposes of spam detection. Please note that emails are generally sent unencrypted over the internet. As a rule, emails are encrypted during transport, but (unless so-called end-to-end encryption is used) not on the servers from which they are sent and received. We therefore cannot accept responsibility for the transmission path of emails between the sender and receipt on our server; legal bases: legitimate interests (Art. 6 (1) sentence 1 lit. f GDPR).
Blogs and Publication Media
We use blogs or comparable means of online communication and publication (hereinafter "publication medium"). Readers' data is processed for the purposes of the publication medium only to the extent necessary for its presentation and for communication between authors and readers, or for security reasons. In all other respects, we refer to the information on the processing of visitors to our publication medium provided elsewhere in this privacy policy.
Further information on processing operations, procedures, and services:
- Comments and posts: If users leave comments or other posts, their IP addresses may be stored on the basis of our legitimate interests. This is done for our security in case someone posts unlawful content in comments and posts (insults, prohibited political propaganda, etc.). In such a case, we ourselves could be held liable for the comment or post, and are therefore interested in the identity of the author. We also reserve the right, on the basis of our legitimate interests, to process users' information for spam detection purposes. On the same legal basis, we reserve the right, in the case of surveys, to store users' IP addresses for the duration of the survey and to use cookies to prevent multiple voting. Personal information, any contact and website information, as well as the content provided in the context of comments and posts, are stored permanently by us until users object; legal bases: legitimate interests (Art. 6 (1) sentence 1 lit. f GDPR).
- Loading of WordPress emojis and smileys: Within our WordPress blog, graphical emojis (or smileys), i.e. small graphic files expressing feelings, are used for the purposes of efficient integration of content elements, sourced from external servers. The providers of the servers collect users' IP addresses. This is necessary in order for the emoji files to be transmitted to users' browsers; service provider: Aut O'Mattic A8C Ireland Ltd., Grand Canal Dock, 25 Herbert Pl, Dublin, D02 AY86, Ireland; legal bases: legitimate interests (Art. 6 (1) sentence 1 lit. f GDPR); website: automattic.com; privacy policy: automattic.com/privacy.
- Akismet anti-spam check: On the basis of our legitimate interests, we use the "Akismet" service. Akismet is used to distinguish comments made by real people from spam comments. To do so, all comment data is sent to a server in the USA, where it is analyzed and stored for comparison purposes for four days. If a comment is classified as spam, the data is stored beyond this period. This data includes the name entered, the email address, the IP address, the comment content, the referrer, information about the browser used and the computer system, and the time of the entry. Users are welcome to use pseudonyms or refrain from entering their name or email address. They can prevent the transmission of data completely by not using our comment system; service provider: Aut O'Mattic A8C Ireland Ltd., Grand Canal Dock, 25 Herbert Pl, Dublin, D02 AY86, Ireland; legal bases: legitimate interests (Art. 6 (1) sentence 1 lit. f GDPR); website: automattic.com; privacy policy: automattic.com/privacy.
- UpdraftPlus: Backup software and backup storage; service provider: Simba Hosting Ltd., 11, Barringer Way, St. Neots, Cambs., PE19 1LW, UK; legal bases: legitimate interests (Art. 6 (1) sentence 1 lit. f GDPR); website: updraftplus.com; privacy policy: updraftplus.com/data-protection-and-privacy-centre.
Contact and Inquiry Management
When contacting us (e.g. by post, contact form, email, telephone, or via social media), as well as in the context of existing user and business relationships, the information of the person making the inquiry is processed to the extent necessary to respond to contact inquiries and any requested measures.
Further information on processing operations, procedures, and services:
- Contact form: When users contact us via our contact form, email, or other means of communication, we process the data communicated to us in this context in order to handle the matter raised; legal bases: performance of a contract and pre-contractual inquiries (Art. 6 (1) sentence 1 lit. b GDPR), legitimate interests (Art. 6 (1) sentence 1 lit. f GDPR).
Newsletter and Electronic Notifications
We send newsletters, emails, and other electronic notifications (hereinafter "newsletter") only with the recipient's consent or a statutory permission. Where the content of a newsletter is specifically described as part of a sign-up process, that description is decisive for users' consent. Otherwise, our newsletters contain information about our services and about us.
To subscribe to our newsletters, it is generally sufficient to provide your email address. However, we may ask you to provide a name for personal address in the newsletter, or other information, if required for the purposes of the newsletter.
Double opt-in procedure: Registration for our newsletter generally takes place using a so-called double opt-in procedure. This means that after registering, you will receive an email asking you to confirm your registration. This confirmation is necessary to ensure that no one registers using someone else's email address. Newsletter registrations are logged in order to be able to prove the registration process in accordance with legal requirements. This includes storing the time of registration and confirmation, as well as the IP address. Changes to your data stored with the mailing service provider are likewise logged.
Erasure and restriction of processing: We may store unsubscribed email addresses for up to three years on the basis of our legitimate interests before deleting them, in order to be able to prove that consent was previously given. Processing of this data is limited to the purpose of possible defense against claims. An individual request for erasure is possible at any time, provided the prior existence of consent is simultaneously confirmed. In the event of obligations to permanently observe objections, we reserve the right to store the email address solely for this purpose in a block list.
Logging of the registration process is carried out on the basis of our legitimate interests for the purpose of proving its proper conduct. To the extent we engage a service provider to send emails, this is done on the basis of our legitimate interests in an efficient and secure sending system.
Content: Information about us, our services, promotions, and offers.
Further information on processing operations, procedures, and services:
- Measurement of open and click-through rates: Newsletters contain a so-called "web beacon," i.e. a pixel-sized file that is retrieved from our server, or, if we use a mailing service provider, from their server, when the newsletter is opened. In the course of this retrieval, technical information such as information about the browser and your system, as well as your IP address and the time of retrieval, is initially collected. This information is used to technically improve our newsletter based on the technical data or on target groups and their reading behavior, based on their location of access (which can be determined using the IP address) or access times. This analysis also includes determining whether newsletters are opened, when they are opened, and which links are clicked. This information is assigned to individual newsletter recipients and stored in their profiles until they are deleted. These evaluations help us to recognize our users' reading habits and adapt our content to them, or to send different content according to the interests of our users. The measurement of open and click-through rates and storage of the measurement results in user profiles; legal bases: consent (Art. 6 (1) sentence 1 lit. a GDPR).
Advertising Communication via Email, Post, Fax, or Telephone
We process personal data for the purposes of advertising communication, which can take place via various channels such as email, telephone, post, or fax, in accordance with statutory requirements.
Recipients have the right to revoke any consent given at any time, or to object to advertising communication at any time.
After a revocation or objection, we store the data required to prove the previous authorization for contact or dispatch for up to three years after the end of the year of revocation or objection, on the basis of our legitimate interests. Processing of this data is limited to the purpose of possible defense against claims. On the basis of our legitimate interest in permanently observing the user's revocation or objection, we also store the data required to prevent renewed contact (e.g., depending on the communication channel, the email address, phone number, or name).
Sweepstakes and Competitions
We process the personal data of participants in sweepstakes and competitions only in compliance with the applicable data protection provisions, to the extent that processing is contractually necessary for the provision, conduct, and handling of the sweepstakes, participants have consented to the processing, or the processing serves our legitimate interests (e.g. in the security of the sweepstakes or in protecting our interests against misuse through possible collection of IP addresses when entries are submitted).
If entries by participants are published as part of the sweepstakes (e.g. as part of a vote or presentation of entries or winners, or reporting on the sweepstakes), we point out that participants' names may also be published in this context. Participants may object to this at any time.
If the sweepstakes takes place within an online platform or social network (e.g. Facebook or Instagram, hereinafter referred to as "online platform"), the terms of use and privacy provisions of the respective platform additionally apply. In such cases, we point out that we are responsible for the information provided by participants in connection with the sweepstakes, and that inquiries regarding the sweepstakes should be addressed to us.
Participants' data is deleted once the sweepstakes or competition has ended and the data is no longer required to inform winners, or because follow-up questions regarding the sweepstakes are to be expected. As a general rule, participants' data is deleted no later than 6 months after the end of the sweepstakes. Winners' data may be retained for longer, e.g. to answer follow-up questions regarding prizes or to fulfil prize obligations; in this case, the retention period depends on the type of prize and may be up to three years for goods or services, e.g. to process warranty claims. Furthermore, participants' data may be stored for longer, e.g. in the form of reporting on the sweepstakes in online and offline media.
To the extent data collected as part of the sweepstakes was also collected for other purposes, its processing and retention period are governed by the privacy notices relating to that use (e.g. in the case of a newsletter sign-up as part of a sweepstakes).
Surveys and Polls
We conduct surveys and polls to gather information for the specific, communicated survey or poll purpose. The surveys and polls we conduct (hereinafter "surveys") are evaluated anonymously. Personal data is processed only to the extent necessary for the provision and technical conduct of the surveys (e.g. processing the IP address in order to display the survey in the user's browser, or to enable a survey to be resumed using a cookie).
Web Analytics, Monitoring, and Optimization
Web analytics (also referred to as "reach measurement") serves to evaluate visitor traffic to our online offering and may include behavior, interests, or demographic information about visitors, such as age or gender, as pseudonymous values. With the help of reach analysis, we can, for example, identify at what times our online offering, or its functions or content, are used most frequently, or invite repeat use. We can likewise determine which areas require optimization.
In addition to web analytics, we may also use testing procedures, e.g. to test and optimize different versions of our online offering or its components.
Unless otherwise stated below, profiles — i.e. data compiled in connection with a usage process — may be created for these purposes, and information may be stored in and read from a browser or an end device. The data collected includes, in particular, the websites visited and the elements used there, as well as technical information such as the browser used, the computer system used, and information on usage times. Where users have consented to the collection of their location data to us or to the providers of the services we use, location data may also be processed.
Users' IP addresses are also stored. However, we use an IP masking procedure (i.e. pseudonymization by shortening the IP address) to protect users. As a general rule, no directly identifying user data (such as email addresses or names) is stored in connection with web analytics, A/B testing, and optimization, but rather pseudonyms. That is, neither we nor the providers of the software we use know the actual identity of users, only the information stored in their profiles for the purposes of the respective procedures.
Further information on processing operations, procedures, and services:
- Google Analytics: Web analytics, reach measurement, and measurement of user flows; service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; legal bases: consent (Art. 6 (1) sentence 1 lit. a GDPR); website: marketingplatform.google.com; privacy policy: policies.google.com/privacy; data processing agreement: business.safety.google/adsprocessorterms; right to object (opt-out): opt-out plugin: tools.google.com/dlpage/gaoptout, ad settings: adssettings.google.com.
Presence on Social Networks (Social Media)
We maintain online presences within social networks and process user data in this context, in order to communicate with users active there, or to offer information about us.
We point out that user data may in this context be processed outside the European Union. This may entail risks for users, as it may, for example, make it more difficult to enforce users' rights.
Furthermore, user data within social networks is generally processed for market research and advertising purposes. For example, usage profiles may be created based on user behavior and the interests derived from it. These usage profiles may in turn be used, for example, to place advertisements within and outside the networks that are presumed to correspond to users' interests. For these purposes, cookies are generally stored on users' devices, in which usage behavior and users' interests are stored. Furthermore, data may be stored in usage profiles independently of the devices used by users (in particular where users are members of the respective platforms and are logged in to them).
For a detailed description of the respective forms of processing and the options for objection (opt-out), please refer to the privacy policies and information provided by the operators of the respective networks.
In the case of requests for information and the exercise of data subjects' rights, we also point out that these can be exercised most effectively with the providers. Only the providers have access to users' data and can take appropriate action and provide information directly. Should you nevertheless require assistance, you can contact us.
Further information on processing operations, procedures, and services:
- Instagram: Social network; service provider: Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland; legal bases: legitimate interests (Art. 6 (1) sentence 1 lit. f GDPR); website: instagram.com; privacy policy: instagram.com/about/legal/privacy.
- Facebook pages: Profiles within the Facebook social network – We are jointly responsible, together with Meta Platforms Ireland Limited, for the collection (but not the further processing) of data on visitors to our Facebook page (so-called "fan page"). This data includes information about the types of content users view or interact with, or the actions they take, as well as information about the devices users use (e.g. IP addresses, operating system, browser type, language settings, cookie data). As explained in the Facebook data policy, Facebook also collects and uses information in order to provide analytics services, so-called "page insights," for page operators, so that they can gain insight into how people interact with their pages and with the content connected to them. We have entered into a specific agreement with Facebook, which in particular governs the security measures Facebook must comply with, and in which Facebook has agreed to fulfil data subjects' rights (i.e. users can, for example, submit requests for information or erasure directly to Facebook). Users' rights (in particular to information, erasure, objection, and complaint to a competent supervisory authority) are not restricted by the agreements with Facebook; service provider: Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland; legal bases: legitimate interests (Art. 6 (1) sentence 1 lit. f GDPR); website: facebook.com; privacy policy: facebook.com/about/privacy. Joint responsibility is limited to the collection and transfer of data to Meta Platforms Ireland Limited, a company based in the EU. Further processing of the data is the sole responsibility of Meta Platforms Ireland Limited, in particular with regard to the transfer of data to the parent company Meta Platforms, Inc. in the USA.
- LinkedIn: Social network; service provider: LinkedIn Ireland Unlimited Company, Wilton Plaza Wilton Place, Dublin 2, Ireland; legal bases: legitimate interests (Art. 6 (1) sentence 1 lit. f GDPR); website: linkedin.com; privacy policy: linkedin.com/legal/privacy-policy; right to object (opt-out): linkedin.com/psettings/guest-controls/retargeting-opt-out.
- YouTube: Social network and video platform; service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; legal bases: legitimate interests (Art. 6 (1) sentence 1 lit. f GDPR); privacy policy: policies.google.com/privacy; right to object (opt-out): adssettings.google.com.
- Xing: Social network; service provider: New Work SE, Am Strandkai 1, 20457 Hamburg, Germany; legal bases: legitimate interests (Art. 6 (1) sentence 1 lit. f GDPR); website: xing.de; privacy policy: privacy.xing.com/en/privacy-policy.
Plugins and Embedded Functions and Content
We integrate functional and content elements into our online offering that are sourced from the servers of their respective providers (hereinafter "third-party providers"). These may include, for example, graphics, videos, or maps (hereinafter uniformly referred to as "content").
Integration always requires that the third-party providers of this content process users' IP addresses, as without the IP address they would not be able to send content to users' browsers. The IP address is therefore necessary to display this content or functions. We endeavor to only use content whose respective providers use the IP address solely to deliver the content. Third-party providers may also use so-called pixel tags (invisible graphics, also referred to as "web beacons") for statistical or marketing purposes. "Pixel tags" can be used to evaluate information such as visitor traffic on the pages of this website. Pseudonymous information may also be stored in cookies on users' devices and may include, among other things, technical information about the browser and operating system, referring websites, visit time, and further information on the use of our online offering, and may also be linked with such information from other sources.
Further information on processing operations, procedures, and services:
- Facebook plugins and content: Facebook Social Plugins and content – This may include, for example, content such as images, videos, or text, and buttons that allow users to share content from this online offering within Facebook. The list and appearance of the Facebook Social Plugins can be viewed at developers.facebook.com/docs/plugins. We are jointly responsible, together with Meta Platforms Ireland Limited, for the collection or receipt (as part of a transfer) of "event data" that Facebook collects via the Facebook Social Plugins implemented in our online offering, for the following purposes: a) display of content and advertising information corresponding to the presumed interests of users; b) delivery of commercial and transaction-related messages (e.g. contacting users via Facebook Messenger); c) improvement of ad delivery and personalization of functions and content. Service provider: Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland; legal bases: consent (Art. 6 (1) sentence 1 lit. a GDPR); website: facebook.com; privacy policy: facebook.com/about/privacy.
- Font Awesome (hosted on our own server): Display of fonts and icons; service provider: the Font Awesome icons are hosted on our own server; no data is transmitted to the Font Awesome provider; legal bases: legitimate interests (Art. 6 (1) sentence 1 lit. f GDPR).
- Google Maps: We integrate the maps of the "Google Maps" service provided by Google. Data processed may include, in particular, IP addresses and location data of users; service provider: Google Cloud EMEA Limited, 70 Sir John Rogerson's Quay, Dublin 2, Ireland; legal bases: legitimate interests (Art. 6 (1) sentence 1 lit. f GDPR); website: mapsplatform.google.com; privacy policy: policies.google.com/privacy.
- Instagram plugins and content: This may include, for example, content such as images, videos, or text, and buttons that allow users to share content from this online offering within Instagram. We are jointly responsible, together with Meta Platforms Ireland Limited, for the collection or receipt (as part of a transfer) of "event data" that Facebook collects via functions of Instagram, for purposes comparable to the Facebook plugins; service provider: Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland; legal bases: legitimate interests (Art. 6 (1) sentence 1 lit. f GDPR); website: instagram.com; privacy policy: instagram.com/about/legal/privacy.
- LinkedIn plugins and content: This may include, for example, content such as images, videos, or text, and buttons that allow users to share content from this online offering within LinkedIn; service provider: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland; legal bases: legitimate interests (Art. 6 (1) sentence 1 lit. f GDPR); website: linkedin.com; privacy policy: linkedin.com/legal/privacy-policy; right to object (opt-out): linkedin.com/psettings/guest-controls/retargeting-opt-out.
- YouTube videos: Video content; service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; legal bases: legitimate interests (Art. 6 (1) sentence 1 lit. f GDPR); website: youtube.com; privacy policy: policies.google.com/privacy; right to object (opt-out): opt-out plugin: tools.google.com/dlpage/gaoptout, ad settings: adssettings.google.com.
- YouTube videos (enhanced privacy mode): YouTube videos are embedded via a special domain (recognizable by the "youtube-nocookie" component) in so-called "enhanced privacy mode," meaning no cookies relating to user activity are collected in order to personalize video playback. However, information about users' interaction with the video (e.g. remembering the last playback position) may still be stored; service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; legal bases: legitimate interests (Art. 6 (1) sentence 1 lit. f GDPR); website: youtube.com; privacy policy: policies.google.com/privacy.
- Yumpu: We use yumpu.com, operated by i-magazine AG (Gewerbestrasse 3, 9444 Diepoldsau, Switzerland), on our website. Yumpu provides a digital platform for publishing magazines, brochures, or catalogues. The privacy policy and cookie policy of Yumpu (i-magazine AG) can be found here: Yumpu privacy policy: yumpu.com/en/info/privacy_policy; Yumpu cookie policy: yumpu.com/en/info/cookie_policy.
Amendment and Update of the Privacy Policy
We ask you to regularly inform yourself about the content of our privacy policy. We will adapt the privacy policy as soon as changes to the data processing we carry out make this necessary. We will inform you as soon as the changes require your involvement (e.g. consent) or any other individual notification.
Where we provide addresses and contact information for companies and organizations in this privacy policy, please note that addresses may change over time; we ask that you verify the information before making contact.
Rights of Data Subjects
As a data subject, you are entitled to various rights under the GDPR, arising in particular from Articles 15 to 21 GDPR:
- Right to object: You have the right to object at any time, for reasons arising from your particular situation, to the processing of personal data concerning you which takes place on the basis of Art. 6 (1) lit. e or f GDPR; this also applies to profiling based on these provisions. Where personal data concerning you is processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for such marketing; this also applies to profiling, to the extent it is related to such direct marketing.
- Right to revoke consent: You have the right to revoke any consent given at any time.
- Right of access: You have the right to request confirmation as to whether relevant data is being processed, and to information about this data as well as further information and a copy of the data in accordance with statutory provisions.
- Right to rectification: In accordance with statutory provisions, you have the right to request the completion of data concerning you, or the correction of inaccurate data concerning you.
- Right to erasure and restriction of processing: In accordance with statutory provisions, you have the right to demand that data concerning you be deleted without delay, or, alternatively, in accordance with statutory provisions, to demand a restriction on the processing of the data.
- Right to data portability: You have the right to receive data concerning you that you have provided to us, in accordance with statutory provisions, in a structured, commonly used, and machine-readable format, or to request its transfer to another controller.
- Complaint to a supervisory authority: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the member state of your habitual residence, place of work, or the place of the alleged infringement, if you believe that the processing of personal data concerning you infringes the GDPR.
Competent supervisory authority:
State Commissioner for Data Protection and Freedom of Information of
North Rhine-Westphalia (Landesbeauftragte für Datenschutz und
Informationsfreiheit Nordrhein-Westfalen)
Kavalleriestr. 2–4
40213 Düsseldorf, Germany
Phone: +49 211 38424-0
Fax: +49 211 38424-999
Email: poststelle@ldi.nrw.de
Definitions
This section provides an overview of the terms used in this privacy policy. Many of the terms are taken from the law and are defined in particular in Art. 4 GDPR. The statutory definitions are binding. The following explanations, on the other hand, are primarily intended to assist understanding. The terms are listed in alphabetical order.
- Personal data: "Personal data" means any information relating to an identified or identifiable natural person (hereinafter "data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. a cookie), or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
- User-related profiles: The processing of "user-related profiles," or "profiles" for short, comprises any type of automated processing of personal data consisting of the use of such personal data to analyze, evaluate, or predict certain personal aspects relating to a natural person (depending on the type of profiling, this may include various information relating to demographics, behavior, and interests, such as interaction with websites and their content). Cookies and web beacons are frequently used for profiling purposes.
- Reach measurement: Reach measurement (also referred to as web analytics) is used to evaluate visitor traffic to an online offering and may include the behavior or interests of visitors in certain information, such as website content. With the help of reach analysis, website operators can, for example, identify at what times visitors visit their website and what content interests them. This allows them to better tailor website content to the needs of their visitors. Pseudonymous cookies and web beacons are frequently used for reach analysis purposes, to recognize repeat visitors and thereby obtain more accurate analyses of the use of an online offering.
- Location data: Location data is generated when a mobile device (or another device with the technical prerequisites for determining location) connects to a cell tower, a WiFi network, or similar technical means and functions for determining location. Location data is used to indicate the geographically determinable position on Earth at which the respective device is located.
- Tracking: "Tracking" refers to the ability to track user behavior across multiple online offerings. As a rule, behavioral and interest-related information relating to the online offerings used is stored in cookies or on servers of the providers of the tracking technologies used (so-called profiling). This information may subsequently be used, for example, to display advertisements to users that are likely to correspond to their interests.
- Controller: "Controller" refers to the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
- Processing: "Processing" is any operation or set of operations performed on personal data, whether or not by automated means. The term is broad and covers virtually any handling of data, whether collecting, evaluating, storing, transmitting, or deleting it.
Created with the free Privacy Policy Generator (Datenschutz-Generator.de) by Dr. Thomas Schwenke