Data Privacy Policy

This Privacy Policy explains the nature, scope and purposes of the processing of personal data (hereinafter ‘data’) in connection with our online services, including the associated websites, functions, content and external online presences, e.g., our social media profile (hereinafter collectively referred to as the ‘online services’).

The terms used in this Privacy Policy, such as ‘processing’ and ‘controller’, have the meanings assigned to them in Article 4 of the General Data Protection Regulation (GDPR).

Controller

Catherine Besendahl
Blankeneser Bahnhofstr. 60
22587 Hamburg, Germany
+49 (0)170 – 90 35 395

Types of data processed

  • Personal data (e.g., names and addresses)
  • Contact data (e.g., e-mail addresses and phone numbers)
  • Content data (e.g., text submissions, photographs and videos)
  • Usage data (e.g., websites visited, content accessed, user interests and access times)
  • Metadata and communication data (e.g., device information and IP addresses)

Categories of data subjects

Visitors to and users of our online services (hereinafter collectively referred to as ‘users’).

Purpose of data processing

  • Providing the online offering, including its features and content
  • Answering contact requests and communicating with users
  • Implementing security measures
  • Measuring audience reach/marketing

Terminology

‘Personal data’ means any information relating to an identified or identifiable natural person (hereinafter ‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g., cookie) or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

‘Processing’ means any operation performed with or without the aid of automated means or any such set of operations that is performed on personal data. The term is interpreted broadly, and it includes virtually every instance where data are processed.

‘Controller’ refers to a natural or legalperson, public authority, agency or other body that decides, alone or in concert with others, on the goals and means of processing personal data.

Relevant legal bases

In accordance with Art. 13 GDPR, we hereby inform you about the legal basis of our data processing. If no legal basis is stated in the Privacy Policy, the following applies: The legal basis for obtaining consent is Art. 6 (1), point (a) and Art. 7 GDPR. The legal basis for processing that is conducted while performing our services and carrying out contractual measures as well as answering inquiries is Art. 6 (1), point (b) GDPR. The legal basis for processing during the fulfilment of our legal obligations is Art. 6 (1), point (c) GDPR. The legal basis for processing in order to protect our legitimate interests is Art. 6 (1), point (f) GDPR. If personal data must be processed to protect the vital interests of the data subject or any other natural person, then Art. 6 (1), point (d) GDPR provides the legal basis for said processing.

Cooperation with processors and third parties

In the scope of our processing, we only disclose or transmit data or otherwise grant access to data to other persons or companies (processors or third parties) if we are authorised to do so by law (e.g., if data must be transmitted to a third party, such as a payment processer, to fulfill the contract as per Art. 6 (1), point (b) GDPR), if you have given your consent, if a legal obligation provides for this or if such transmission is based on a legitimate interest (e.g., when contracting with agents, web hosting providers, etc.).

Whenever we commission third parties to process data, we always conclude a data processing agreement pursuant to Art. 28 GDPR.

Rights of data subjects

You have the right to request confirmation as to whether your data as a data subject is being processed, a disclosure of what data are in our possession, detailed information about these data, and a copy of these data in accordance with Art. 15 GDPR.

In accordance with Art. 16 GDPR, you have the right to provide supplementary information or to rectify any incorrect data that exists about you.

In accordance with Art. 17 GDPR, you have the right to demand that your data as a data subject be erased immediately. Alternatively, in accordance with Art. 18 GDPR, you have the right to restrict the processing of your data.

You have the right to request a copy of data relating to you that you have provided to us in accordance with Art. 20 GDPR, and you may also request that it be transmitted to other data controllers.

Furthermore, in accordance with Art. 77 GDPR, you have the right to file a complaint with the competent supervisory authority.

Right of withdrawal

You have the right to withdraw your granted consent in accordance with Art. 7 (3) GDPR with future effect.

Right to object

Pursuant to Art. 21 GDPR, you may at any time object to future processing of personal data concerning you. In particular, you have the right to object to the processing of your personal data for direct marketing purposes.

Cookies and your right to object to direct marketing

‘Cookies’ are small files that are stored on users‘ computers. Cookies can be used to store various kinds of information. A cookie is primarily used to store information about a user (or the device on which the cookie is stored) during or after the user’s visit to an online offering. ‘Session cookies’ or ‘transient cookies’ represent a type of temporary cookie that is erased after a user leaves the online offering or closes their browser. This type of cookie can be used to store the contents of a shopping cart at an online store or a login status. ‘Permanent’ or ‘persistent’ cookies are those that remain stored even after the browser has been closed. These types of cookies allow the login status to be stored, for example, which is relevant if a user returns the web resource after several days. Likewise, these cookies can be used to store information about the interests of users, and they can be used to measure audience reach or for marketing purposes. A ‘third-party cookie’ is a cookie that is offered by providers other than the entity that manages the online offering (cookies from the latter entity are called ‘first-party cookies’).

We may use both transient and persistent cookies. Further information on the use of cookies is provided in this Privacy Policy.

If you do not want cookies to be stored on your computer, you are given the option to deactivate cookies in your browser settings or to erase existing cookies. Saved cookies can be erased in the system settings of the browser. If you deactivate cookies, you may not be able to use all the features of this online offering.

You can generally opt out of cookies that are used for the purpose of online marketing on a variety of services, including in particular tracking cookies. To opt out of the use of such cookies by American websites, you can visit www.aboutads.info/choices. For EU websites, you can visit www.youronlinechoices.com. Furthermore, you can prevent cookies from being stored by disabling them in the browser settings. Please note that you may not be able to use all the features of this online offering if you so disable cookies.

Erasure of data

Data that are processed by us will be erased or the processing thereof will be restricted in accordance with Art. 17 and 18 GDPR. Unless expressly stated in this Privacy Policy, we erase the data we store as soon as they are no longer needed for the respective purpose and provided that erasure does not conflict with any statutory preservation periods. If the data are not erased because they are needed for other and legally admissible purposes, the processing of such data is restricted, meaning that the data are made unavailable to users and are not processed for other purposes. This applies, for instance, to data that are subject to preservation periods under commercial law or tax law.

Under German statutory retention requirements, documents must generally be retained for six years pursuant to Section 257 (1) of the German Commercial Code (HGB) (this includes commercial books, inventories, opening balance sheets, annual financial statements, commercial correspondence and accounting records), and for ten years pursuant to Section 147 (1) of the German Fiscal Code (AO) (this includes books, records, management reports, accounting records, commercial and business correspondence, and tax-relevant documentation).

Under Austrian statutory retention requirements, documents must generally be retained for 7 years in accordance with Section 132 (1) Austrian Federal Tax Code (BAO) (accounting documents, receipts/invoices, accounts, receipts, business papers, statements of income and expenses, etc.), for 22 years for property-related information, and for 10 years for documents that are related to electronically supplied services and telecommunications, broadcasting and television services that are provided to individuals who are not entrepreneurs in EU member states and for whom the Mini One-Stop-Shop (MOSS) scheme is applied.

Hosting

Hosting services are used to provide infrastructure and platform services, computing capacity, storage and database services, security, and technical maintenance services, which we use to provide this online offering.

We, or rather our hosting provider, process personal data, contact information, content data, contract data, usage data, the metadata and communication data of customers, prospects and visitors to this online offering on the basis of our legitimate interests to efficiently and securely maintain this online offering in accordance with Art. 6 (1), point (f) GDPR in conjunction with Art. 28 GDPR (data processing agreement).

Collection of access data and log files

Based on our legitimate interests within the meaning of Article 6 (1), point (f) GDPR, we, or our hosting provider, collect data about every access to the server on which this website is hosted (so-called server log files). Access data include the name of the webpage accessed, the file requested, the date and time of access, the volume of data transferred, notification of successful retrieval, the browser type and version, the user‘s operating system, the referrer URL (the previously visited page), the IP address and the requesting internet service provider (ISP).

For safety reasons (e.g., to investigate misuse or fraud), logfile information is stored for a period of no more than seven days and erased thereafter. Data that needs to be stored as evidence for a longer period is excluded from erasure until the respective incident has been clarified.

So-called session cookies are used for this website. These are essential for the site's operation and are used continuously. You can decide for yourself whether you wish to continue allowing cookies. Please note that if you decline, not all of the site's functionalities may remain available.