DATA PRIVACY STATEMENT BIRKENSTOCK ONLINE SHOP
Thank you for your interest in our online shop (www.birkenstock.com) (hereinafter “online shop” or “website”).
The purpose of this data privacy statement is to give you a clear overview of how we process your personal data.
- Who is responsible for processing my data and who is the data protection officer?
- What is the subject of data protection?
- Which categories of data are processed and what is their origin?
- For which purpose and on which legal basis is my data processed?
- With whom is my data shared?
- Is my data transferred to third countries?
- How long is my data stored for?
- What data protection rights can I assert as the data subject?
- The data protection supervisory authority responsible for us
- How is my data protected?
- Are there automated case-by-case decisions or profiling measures?
- Changes to this data privacy statement
1. WHO IS RESPONSIBLE FOR PROCESSING MY DATA AND WHO IS THE DATA PROTECTION OFFICER?
The data processing controller within the meaning of Article 4 no. 7 of the General Data Protec-tion Regulation (GDPR) is:
Birkenstock digital GmbH,
Burg Ockenfels,
53545 Linz am Rhein
Germany
https://birkenstock-privacy.bytemine.net/enquiry/
You can contact our Data Protection Officer at:
Birkenstock digital GmbH,
Data Protection Officer
Burg Ockenfels,
53545 Linz am Rhein
Germany
dpo@birkenstock.com
For general questions on data protection or data subject requests you can contact us via our online form at
https://birkenstock-privacy.bytemine.net/enquiry/
Birkenstock digital GmbH,
Burg Ockenfels,
53545 Linz am Rhein
Germany
https://birkenstock-privacy.bytemine.net/enquiry/
You can contact our Data Protection Officer at:
Birkenstock digital GmbH,
Data Protection Officer
Burg Ockenfels,
53545 Linz am Rhein
Germany
dpo@birkenstock.com
For general questions on data protection or data subject requests you can contact us via our online form at
https://birkenstock-privacy.bytemine.net/enquiry/
2. WHAT IS THE SUBJECT OF DATA PROTECTION?
Data protection legislation governs the use of personal data. Personal data is information relating to an identified or identifiable natural person (hereinafter “data”).
3. WHICH CATEGORIES OF DATA ARE PROCESSED AND WHAT IS THEIR ORIGIN?
In particular the following categories of data are processed within the framework of your use of our online shop:
Data you provide us with: You provide us with data within the framework of your order, contacting us (e.g. via the contact form or email) or within the framework of opening a customer account. Which data exactly you provide us with is shown in the respective input forms. This may, for example, include the following data: your name, your email address, your telephone number, any other contact data including your address or your payment details.
The entry form you use will indicate whether or not you are obligated to provide us with such data. You can find more information in this context in clause 4 of this data privacy statement.
If you visit our website, we may store access data in so-called “server logfiles”.
Data we collect on from third parties: If you place an order via our online shop, we may, under certain circumstances, also collect data about you from third parties, for example from credit agencies or payment service providers.
Cookies: In order to make your visit to our website enjoyable and enable the use of certain functions, we use so-called “cookies” or similar technologies on our website, for example for advertising and analyzing purposes. You can find more information in this context in clause 4 below and in our cookie settings. There, you can change your cookie preferences at any time.
Special categories of personal data: We do not collect and process special categories of personal data. 1
Data you provide us with: You provide us with data within the framework of your order, contacting us (e.g. via the contact form or email) or within the framework of opening a customer account. Which data exactly you provide us with is shown in the respective input forms. This may, for example, include the following data: your name, your email address, your telephone number, any other contact data including your address or your payment details.
The entry form you use will indicate whether or not you are obligated to provide us with such data. You can find more information in this context in clause 4 of this data privacy statement.
If you visit our website, we may store access data in so-called “server logfiles”.
Data we collect on from third parties: If you place an order via our online shop, we may, under certain circumstances, also collect data about you from third parties, for example from credit agencies or payment service providers.
Cookies: In order to make your visit to our website enjoyable and enable the use of certain functions, we use so-called “cookies” or similar technologies on our website, for example for advertising and analyzing purposes. You can find more information in this context in clause 4 below and in our cookie settings. There, you can change your cookie preferences at any time.
Special categories of personal data: We do not collect and process special categories of personal data. 1
4. FOR WHICH PURPOSE AND ON WHICH LEGAL BASIS IS MY DATA PROCESSED?
We process your data for the purposes set forth below. You are generally under no legal or other obligation to provide us with your data for these purposes. However, without your data we may, under circumstances, not be able to offer you the use of our website and our products.
Contractual processing purposes on the legal basis of Art. 6 para. 1 sent. 1 lit b) GDPR
Creation of a customer account: To open a customer account, you must first register with us. We will process certain personal data in the course of this registration, for example your name and your email address. The data we collect is indicated in the respective input form. We collect this data in order to be able to create a customer account for you.
Collection and use of data for the contract performance: We collect and process the data you disclose to us in the course your order process. The data that is collected is indicated in the respective input forms. We use the data you provide us with for the performance of our contractual obligations vis-à-vis you as well as to process all of your inquiries, in particular for the processing of your order, the processing of your payment as well as any contract-related communication with you, such as the answering of any questions or complaints. Thus, your data is necessary for the contract performance, in particular to process your order. It is marked in the input forms which data is necessary and which data is optional.
Data processing due to consent on the legal basis of Art. 6 para. 1 sent. 1 lit a) GDPR
Use of your data for advertising and analyzing purposes: We use your data on the basis of your consent in order to use it and contact you for advertis-ing purposes (newsletters, surveys about customer satisfaction, notifications on availability) via email. If you grant your consent in this context, we personalize the content of the newsletters according to your preferences. We also use your data on the legal basis of your consent in order to show you, either on our website or the website of an advertising partner, advertise-ments based on your interests we determine on the basis of the cookies and similar technolo-gies which we use. In addition, we use cookies and similar technologies on the basis of your consent which enable us to offer you certain comfort functions as well as to analyze the use of the website so that we can evaluate and improve its performance. You can find more infor-mation on the use of cookies and similar technologies in our cookie settings.
You may withdraw your consent for the use of your data for advertising and analyzing purposes at any time with effect for the future. In case of advertising emails, you can simply click on the “unsubscribe” link in the respective email or contact us via privacy@birkenstock.com or via the address specified in clause 1 of this data privacy statement. You can withdraw your consent for the use of cookies and similar technologies in our cookie settings.
Data processing to perform legal obligations on the legal basis of Art. 6 para. 1 sent. 1 lit. c) GDPR
Data security: Within the framework of the operation of our online shop we have to fulfill legal obligations. This includes the obligation to guarantee the safety of your data while using the online shop. For this purpose, we may process your data within the framework of measures for ensuring data security.
Retention obligations: Moreover, we have to retain certain data (e.g. commercial letters and receipts) for a period set forth by law. We may only delete such data upon expiry of the statutory retention period, even if a request for deletion was made.
Product Safety: According to the EU General Product Safety Regulation ("GPSR"), we are obliged to maintain a register of complaints in which we document complaints and information received about accidents affecting the safety of our products. In it, we also document product recalls and any corrective actions. In this register of complaints, we only store your data that is necessary for the investigation and only for as long as it is necessary for the purpose of the investigation (maximum five years according to the GPSR).
In the event of a product safety recall or safety warning, we must also be able to contact you and notify you of this. For this purpose, we use the data you have provided to us in your customer account or in a contact form for product safety.
The legal basis for the processing is Art. (6) (1) (c) GDPR in conjunction with Art. 9 (11) and (12) and Art. 35 paras. (1) and (2) GPSR.
Data processing due to legitimate interests on the legal basis of Art. 6 para. 1 sent. 1 lit f) GDPR
In the following paragraph you can find information on the data processing, including transfer, which we perform on the legal basis of legitimate interests in the respective purpose of the processing which we describe in more detail below. In this case, processing only takes place if necessary to pursue our legitimate interests or those of a third party and if your interests, fundamental rights and freedoms do not override these interests. If you require more information regarding the balancing of interests in such cases, please contact us at the address given in clause 1 of this data privacy statement.
Storing of access data in server log files: When you visit our online shop, we store access data in so-called server log files, e.g. the name of the requested file, date and time of the ac-cess, the data volume transmitted and the requesting provider. If personal data is processed in this context, this processing is based on our overriding legitimate interests in ensuring a smooth operation of the website and improving our offer.
Country and language preferences: When visiting our online shop for the first time or when you delete the cookie concerning country preferences, you will be asked to select a country for your order and, if applicable, a language for the respective country so that we can display the prices in our online shop with the correct currency. With the help of your IP address, we can also suggest suitable countries which our service provider determines as the probable delivery region on the basis of your IP address within the framework of a pop-up window The data processing is based on our overriding legitimate interest in providing a user-friendly website. You can change the country and the language at any time by clicking on the globe symbol on the right side of the footer of the website and then selecting the respective country and language.
Product recommendations: If you order goods from our online shop, we can use your data in order to provide you with product information on similar products. This is based on our legitimate interest in being able to provide you with suitable product recommendations. You can object to our use of your data for advertising purposes at any time with effect for the future. For this purpose, you can simply click on the “unsubscribe” link in the respective advertising email or contact us via privacy@birkenstock.com or via the address specified in clause 1 of this data privacy statement.
Credit check and fraud prevention: We use your data in order to reduce the risks of non-payment and fraud within the framework of online orders and the operation of our online shop, in particular if you choose payment by invoice. This is based on our legitimate interest in protecting ourselves, our customers and other users from misuse of data, in particular with regard to fraudulent orders. For this purpose, we in particular process device and access data as well as purchasing and payment data. In this context, we cooperate with credit check and fraud prevention service providers which provide us with creditworthiness data and information to assess the risk which the service provider determined with regard to you. The processing of your data for the aforementioned purposes is necessary for the performance of the contract. Without such data we may not be able to process your order. You may object to our use of your data for these purposes at any time with effect for the future by stating the reasons resulting from your special situation. For this purpose you can contact us at privacy@birkenstock.com or via the address provided in clause 1 of this data privacy statement.
Contractual processing purposes on the legal basis of Art. 6 para. 1 sent. 1 lit b) GDPR
Creation of a customer account: To open a customer account, you must first register with us. We will process certain personal data in the course of this registration, for example your name and your email address. The data we collect is indicated in the respective input form. We collect this data in order to be able to create a customer account for you.
Collection and use of data for the contract performance: We collect and process the data you disclose to us in the course your order process. The data that is collected is indicated in the respective input forms. We use the data you provide us with for the performance of our contractual obligations vis-à-vis you as well as to process all of your inquiries, in particular for the processing of your order, the processing of your payment as well as any contract-related communication with you, such as the answering of any questions or complaints. Thus, your data is necessary for the contract performance, in particular to process your order. It is marked in the input forms which data is necessary and which data is optional.
Data processing due to consent on the legal basis of Art. 6 para. 1 sent. 1 lit a) GDPR
Use of your data for advertising and analyzing purposes: We use your data on the basis of your consent in order to use it and contact you for advertis-ing purposes (newsletters, surveys about customer satisfaction, notifications on availability) via email. If you grant your consent in this context, we personalize the content of the newsletters according to your preferences. We also use your data on the legal basis of your consent in order to show you, either on our website or the website of an advertising partner, advertise-ments based on your interests we determine on the basis of the cookies and similar technolo-gies which we use. In addition, we use cookies and similar technologies on the basis of your consent which enable us to offer you certain comfort functions as well as to analyze the use of the website so that we can evaluate and improve its performance. You can find more infor-mation on the use of cookies and similar technologies in our cookie settings.
You may withdraw your consent for the use of your data for advertising and analyzing purposes at any time with effect for the future. In case of advertising emails, you can simply click on the “unsubscribe” link in the respective email or contact us via privacy@birkenstock.com or via the address specified in clause 1 of this data privacy statement. You can withdraw your consent for the use of cookies and similar technologies in our cookie settings.
Data processing to perform legal obligations on the legal basis of Art. 6 para. 1 sent. 1 lit. c) GDPR
Data security: Within the framework of the operation of our online shop we have to fulfill legal obligations. This includes the obligation to guarantee the safety of your data while using the online shop. For this purpose, we may process your data within the framework of measures for ensuring data security.
Retention obligations: Moreover, we have to retain certain data (e.g. commercial letters and receipts) for a period set forth by law. We may only delete such data upon expiry of the statutory retention period, even if a request for deletion was made.
Product Safety: According to the EU General Product Safety Regulation ("GPSR"), we are obliged to maintain a register of complaints in which we document complaints and information received about accidents affecting the safety of our products. In it, we also document product recalls and any corrective actions. In this register of complaints, we only store your data that is necessary for the investigation and only for as long as it is necessary for the purpose of the investigation (maximum five years according to the GPSR).
In the event of a product safety recall or safety warning, we must also be able to contact you and notify you of this. For this purpose, we use the data you have provided to us in your customer account or in a contact form for product safety.
The legal basis for the processing is Art. (6) (1) (c) GDPR in conjunction with Art. 9 (11) and (12) and Art. 35 paras. (1) and (2) GPSR.
Data processing due to legitimate interests on the legal basis of Art. 6 para. 1 sent. 1 lit f) GDPR
In the following paragraph you can find information on the data processing, including transfer, which we perform on the legal basis of legitimate interests in the respective purpose of the processing which we describe in more detail below. In this case, processing only takes place if necessary to pursue our legitimate interests or those of a third party and if your interests, fundamental rights and freedoms do not override these interests. If you require more information regarding the balancing of interests in such cases, please contact us at the address given in clause 1 of this data privacy statement.
Storing of access data in server log files: When you visit our online shop, we store access data in so-called server log files, e.g. the name of the requested file, date and time of the ac-cess, the data volume transmitted and the requesting provider. If personal data is processed in this context, this processing is based on our overriding legitimate interests in ensuring a smooth operation of the website and improving our offer.
Country and language preferences: When visiting our online shop for the first time or when you delete the cookie concerning country preferences, you will be asked to select a country for your order and, if applicable, a language for the respective country so that we can display the prices in our online shop with the correct currency. With the help of your IP address, we can also suggest suitable countries which our service provider determines as the probable delivery region on the basis of your IP address within the framework of a pop-up window The data processing is based on our overriding legitimate interest in providing a user-friendly website. You can change the country and the language at any time by clicking on the globe symbol on the right side of the footer of the website and then selecting the respective country and language.
Product recommendations: If you order goods from our online shop, we can use your data in order to provide you with product information on similar products. This is based on our legitimate interest in being able to provide you with suitable product recommendations. You can object to our use of your data for advertising purposes at any time with effect for the future. For this purpose, you can simply click on the “unsubscribe” link in the respective advertising email or contact us via privacy@birkenstock.com or via the address specified in clause 1 of this data privacy statement.
Credit check and fraud prevention: We use your data in order to reduce the risks of non-payment and fraud within the framework of online orders and the operation of our online shop, in particular if you choose payment by invoice. This is based on our legitimate interest in protecting ourselves, our customers and other users from misuse of data, in particular with regard to fraudulent orders. For this purpose, we in particular process device and access data as well as purchasing and payment data. In this context, we cooperate with credit check and fraud prevention service providers which provide us with creditworthiness data and information to assess the risk which the service provider determined with regard to you. The processing of your data for the aforementioned purposes is necessary for the performance of the contract. Without such data we may not be able to process your order. You may object to our use of your data for these purposes at any time with effect for the future by stating the reasons resulting from your special situation. For this purpose you can contact us at privacy@birkenstock.com or via the address provided in clause 1 of this data privacy statement.
5. WITH WHOM IS MY DATA SHARED?
Even if we share your data with service providers, we will ensure that your data is processed, protected and transmitted in accordance with the applicable statutory provisions.
We share your data with the following bodies for the purposes stipulated in each case:
Shipping
Within the framework of processing your order and for the purpose of delivering your package, we forward your data to delivery and transport companies commissioned with the delivery which have their seat in Germany, provided that this is necessary for the shipment of your ordered goods.
The forwarding of data is necessary for the processing of your order and thus for the performance of our contractual obligations and therefore takes place on the basis of Art. 6 para. 1 sent. 1 lit. b) GDPR.
Credit check
Should you choose payment via invoice, it is our legitimate interest that we are able to assess the related financial risks before the conclusion of the contract. If you choose the payment method “Payment via invoice”, we thus forward your data (name, address and possibly your date of birth) to a financial service provider for the purpose of a credit check to assess the risk of non-payment on the basis of mathematical and statistical procedures by using your address data and to verify your address (check of deliverability). The legal basis for this transfer is Art. 6 para. 1 sent. 1 lit. f) GDPR. The transfer is based on our legitimate interest in your ability to pay for a purchase of our products in case of a payment by invoice.
Fraud prevention
When orders are placed, we carry out a fraud screening and transfer your order details to our service providers for this purpose. Should, on the basis of this screening, an order be assessed as bearing a risk, your order may be cancelled.
If you choose payment via invoice or payment via PayPal, we transfer your order data (name, address, gender, date of birth, value of the shopping cart, time of the order, IP address, means of payment) to a service provider having its seat in Germany for purposes of fraud prevention.
If you choose to make the payment by credit card, we transfer your data to a service provider having its seat in the USA. During the fraud screening carried out by this service provider, probability values are used on the basis of which orders are detected which contain a fraud risk for us. If you wish to be provided with more information on how our service provider processes personal data, you can contact us at any time via the contact details specified in clause 1 of this data privacy statement. If you do not consent to a data transfer to this service provider, please choose a different payment method.
The legal basis for these transfers is our legitimate interest in preventing fraud at your or at our expense, Art. 6 para. 1 sent. 1 lit f) GDPR.
Payment service provider
Depending on the chosen payment method, our payment service providers may collect information about you so that they can allocate the data of your order to your payment and so that they can make the payment on your behalf. During this process, we cannot see your payment-related information, such as your credit card data.
The forwarding of data is necessary for the processing of your order and thus for the performance of our contractual obligations and therefore takes place on the basis of Art. 6 para. 1 sent. 1 lit. b) GDPR.
Claims management
If there are any outstanding claims from your orders, we will contact you via email with another payment request. Should you not comply with this request despite the existence of a legitimate claim, we can hand over the assertion of the claim to a collection service provider to whom we will forward your order and contact data for this purpose.
The legal basis for the transfer of your data is the necessity for the performance of the contract, Art. 6 para. 1 sent. 1 lit. b) GDPR.
Newsletters, personal product recommendations and surveys
We use a service provider for the technical processes of sending the newsletters and the personal product recommendations and personalized messages based on the user’s conduct via email.
We also use a service provider for carrying out the surveys about customer satisfaction in order to receive customer feedback, e.g. regarding awareness of our brand and our products.
In this context, our partners only process your data pursuant to our instructions and on our behalf. We have ensured by way of a contract that our partners comply with any and all data protection regulations. The scope of the data that is transmitted is limited to the absolute minimum that is required. The transfer of data is based on Art. 28 para. 1 GDPR.
We furthermore transfer data to third parties within the framework of the use of tracking functions on our website for advertising purposes. You can find more information in this regard as well as on the different options of the settings in our cookie settings.
We share your data with the following bodies for the purposes stipulated in each case:
Shipping
Within the framework of processing your order and for the purpose of delivering your package, we forward your data to delivery and transport companies commissioned with the delivery which have their seat in Germany, provided that this is necessary for the shipment of your ordered goods.
The forwarding of data is necessary for the processing of your order and thus for the performance of our contractual obligations and therefore takes place on the basis of Art. 6 para. 1 sent. 1 lit. b) GDPR.
Credit check
Should you choose payment via invoice, it is our legitimate interest that we are able to assess the related financial risks before the conclusion of the contract. If you choose the payment method “Payment via invoice”, we thus forward your data (name, address and possibly your date of birth) to a financial service provider for the purpose of a credit check to assess the risk of non-payment on the basis of mathematical and statistical procedures by using your address data and to verify your address (check of deliverability). The legal basis for this transfer is Art. 6 para. 1 sent. 1 lit. f) GDPR. The transfer is based on our legitimate interest in your ability to pay for a purchase of our products in case of a payment by invoice.
Fraud prevention
When orders are placed, we carry out a fraud screening and transfer your order details to our service providers for this purpose. Should, on the basis of this screening, an order be assessed as bearing a risk, your order may be cancelled.
If you choose payment via invoice or payment via PayPal, we transfer your order data (name, address, gender, date of birth, value of the shopping cart, time of the order, IP address, means of payment) to a service provider having its seat in Germany for purposes of fraud prevention.
If you choose to make the payment by credit card, we transfer your data to a service provider having its seat in the USA. During the fraud screening carried out by this service provider, probability values are used on the basis of which orders are detected which contain a fraud risk for us. If you wish to be provided with more information on how our service provider processes personal data, you can contact us at any time via the contact details specified in clause 1 of this data privacy statement. If you do not consent to a data transfer to this service provider, please choose a different payment method.
The legal basis for these transfers is our legitimate interest in preventing fraud at your or at our expense, Art. 6 para. 1 sent. 1 lit f) GDPR.
Payment service provider
Depending on the chosen payment method, our payment service providers may collect information about you so that they can allocate the data of your order to your payment and so that they can make the payment on your behalf. During this process, we cannot see your payment-related information, such as your credit card data.
Payment service provider | Payment method | Privacy note of the service provider |
Adyen N.V., Simon Carmiggelstraat 6-50, 1011 DJ Amsterdam, Netherlands | Credit card (Visa, MasterCard, American Express, Diners Club) | https://www.adyen.com/policies-and-disclaimer/privacy-policy |
Apple Inc., 1 Infinite Loop Cupertino, California, United States of America | ApplePay | https://support.apple.com/en-us/HT203027 |
Klarna Bank AB (publ), Sveavägen 46, 111 34 Stockholm, Sweden | Pay now (immediate transfer), Pay later (payment via invoice) | https://cdn.klarna.com/1.0/shared/content/legal/terms/0/en_gb/privacy |
PayPal (Europe), S.à.r.l. et Cie, S.C.A, 22-24 Boulevard Royal, 2449 Luxembourg, Luxembourg | PayPal, PayPal Express | https://www.paypal.com/uk/webapps/mpp/ua/privacy-full |
The forwarding of data is necessary for the processing of your order and thus for the performance of our contractual obligations and therefore takes place on the basis of Art. 6 para. 1 sent. 1 lit. b) GDPR.
Claims management
If there are any outstanding claims from your orders, we will contact you via email with another payment request. Should you not comply with this request despite the existence of a legitimate claim, we can hand over the assertion of the claim to a collection service provider to whom we will forward your order and contact data for this purpose.
The legal basis for the transfer of your data is the necessity for the performance of the contract, Art. 6 para. 1 sent. 1 lit. b) GDPR.
Newsletters, personal product recommendations and surveys
We use a service provider for the technical processes of sending the newsletters and the personal product recommendations and personalized messages based on the user’s conduct via email.
We also use a service provider for carrying out the surveys about customer satisfaction in order to receive customer feedback, e.g. regarding awareness of our brand and our products.
In this context, our partners only process your data pursuant to our instructions and on our behalf. We have ensured by way of a contract that our partners comply with any and all data protection regulations. The scope of the data that is transmitted is limited to the absolute minimum that is required. The transfer of data is based on Art. 28 para. 1 GDPR.
We furthermore transfer data to third parties within the framework of the use of tracking functions on our website for advertising purposes. You can find more information in this regard as well as on the different options of the settings in our cookie settings.
6. IS MY DATA TRANSFERRED TO THIRD COUNTRIES?
Some of our service providers and group companies to which we transfer data are located outside of the European Economic Area (EEA). It may be the case that there is no level of protection of your data comparable to the GDPR in these countries. In particular, governmental authorities may be entitled to access your data without you having any effective legal remedies to defend against it. Such a transfer therefore only takes place if the EU Commission confirmed that the third country has an adequate level of data protection (Art. 45 para. 1 GDPR)2 or if you grant your explicit consent for the transfer of your data to recipients outside of the EEA (Art. 49 para. 1 lit. a) GDPR). Otherwise, we will ensure that an appropriate level of data protection is maintained by way of appropriate contractual, technical and/or organizational measures (in particular by agreeing on the EU standard contractual clauses as well as additional measures and recurring reviews). If you require more information as well as a copy of the EU standard contractual clauses, you can contact us via the contact details specified in clause 1 of this data privacy statement.
7. HOW LONG IS MY DATA STORED FOR?
Your data will be stored in accordance with Art. 5 para. 1 lit e) GDPR for as long as we are legally obliged to store it or for as long as we require your data for the purposes specified in clause 4. Subsequently, the processing of your data will be restricted and/or your data will be deleted in order to comply with the principle of data minimization and storage limitation.
If you require more information regarding our erasure dates and retention periods, please contact us at the address given in clause 1 of this data privacy statement.
If you require more information regarding our erasure dates and retention periods, please contact us at the address given in clause 1 of this data privacy statement.
8. WHAT DATA PROTECTION RIGHTS CAN I ASSERT AS THE DATA SUBJECT?
You can assert the data subject rights specified in more detail below. You can contact us in this respect using the contact details stated in clause 1 of this data privacy statement.
Right of access
You can request access to your personal data processed by us pursuant to Art. 15 GDPR. In your request for access you should provide details about your concern in order to facilitate our provision of the necessary data. Please note that your right of access may under certain circumstances be restricted pursuant to the statutory provisions (in particular Sec. 34 of the Federal German Data Protection Act (Bundesdatenschutzgesetz, BDSG)).
Right to rectification
Should your information not or nor longer be correct, you can request a rectification pursuant to Art. 16 GPDR. Should your data be incomplete, you can request a completion.
Right to erasure
Under the conditions specified in Art. 17 GDPR, you can request the deletion of your personal data. Your right to erasure inter alia depends on whether the data concerning you is necessary for the performance of our contractual or statutory obligations.
Right to restriction of processing
Within the framework of the provisions of Art. 18 GDPR you have the right to request a restriction of the processing of your personal data.
Right to lodge a complaint with a data protection supervisory authority
We undertake to cooperate with you to arrive at a fair solution regarding any complaints concerning data protection.
Irrespective of this, you naturally also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU member state of your place of residence, place of work, or place of the alleged infringement, if you consider that the processing of personal data relating to you infringes data protection legislation as applicable.
Right of access
You can request access to your personal data processed by us pursuant to Art. 15 GDPR. In your request for access you should provide details about your concern in order to facilitate our provision of the necessary data. Please note that your right of access may under certain circumstances be restricted pursuant to the statutory provisions (in particular Sec. 34 of the Federal German Data Protection Act (Bundesdatenschutzgesetz, BDSG)).
Right to rectification
Should your information not or nor longer be correct, you can request a rectification pursuant to Art. 16 GPDR. Should your data be incomplete, you can request a completion.
Right to erasure
Under the conditions specified in Art. 17 GDPR, you can request the deletion of your personal data. Your right to erasure inter alia depends on whether the data concerning you is necessary for the performance of our contractual or statutory obligations.
Right to restriction of processing
Within the framework of the provisions of Art. 18 GDPR you have the right to request a restriction of the processing of your personal data.
Right to object
Pursuant to Art. 21 GDPR, you have the right to object to the processing of your personal data at any time for reasons resulting from your special situation. However, we may not be able to comply with such a request, for example if there are statutory regulations on the basis of which we are obliged to process your data. If we process your data for direct marketing purposes, you have the right to object anytime to the processing of your personal data (Art. 21 para. 2 GDPR).
Pursuant to Art. 21 GDPR, you have the right to object to the processing of your personal data at any time for reasons resulting from your special situation. However, we may not be able to comply with such a request, for example if there are statutory regulations on the basis of which we are obliged to process your data. If we process your data for direct marketing purposes, you have the right to object anytime to the processing of your personal data (Art. 21 para. 2 GDPR).
Right to lodge a complaint with a data protection supervisory authority
We undertake to cooperate with you to arrive at a fair solution regarding any complaints concerning data protection.
Irrespective of this, you naturally also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU member state of your place of residence, place of work, or place of the alleged infringement, if you consider that the processing of personal data relating to you infringes data protection legislation as applicable.
9. THE DATA PROTECTION SUPERVISORY AUTHORITY RESPONSIBLE FOR US
Bayerisches Landesamt für Datenschutzaufsicht (Bavarian State Office for Data Protection Supervision), BayLDA
Promenade 18
91522 Ansbach, Germany
Phone: +49 (0) 981 180093-0
Fax: +49 (0) 981 180093-800
Email: poststelle@lda.bayern.de
Promenade 18
91522 Ansbach, Germany
Phone: +49 (0) 981 180093-0
Fax: +49 (0) 981 180093-800
Email: poststelle@lda.bayern.de
10. HOW IS MY DATA PROTECTED?
We have taken adequate technical and organizational security measures (e.g. an SSL encryp-tion of our website) in order to protect your data against destruction, loss, or disclosure to unauthorized persons.
11. ARE THERE AUTOMATED CASE-BY-CASE DECISIONS OR PROFILING MEASURES?
We do not use any automated processing measures within the meaning of Art. 22 GDPR to make a decision, including profiling, that has legal effect vis-à-vis you or may constitute a significant impairment for you.
12. CHANGES TO THIS DATA PRIVACY STATEMENT
We regularly review this data privacy statement and may occasionally amend it to bring it up to date.
Last Update: December 11, 2024
1 Pursuant to Art. 9 para. 1 GDPR, special categories of personal data are data revealing your racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health, or data concerning a natural person’s sex life or sexual orientation as well as data about criminal convictions and offenses or related security measures pursuant to Art. 10 GDPR.
2 An up-to-date list of these countries can be found here: https://ec.europa.eu/info/law/law-topic/data-protection_de.
2 An up-to-date list of these countries can be found here: https://ec.europa.eu/info/law/law-topic/data-protection_de.