privacy policy

1) Introduction and contact details of the responsible person

1.1 Introduction

We are pleased that you are visiting our website and thank you for your interest. Below, we inform you about how we handle your personal data when you use our website. Personal data refers to all data that can be used to identify you personally.

1.2 Person responsible

The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:

Smartfoot Shoes GmbH
Dockenhudener Straße 27
22587 Hamburg, Germany
Email: info@smartfoot.de

The controller is the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data.

2) Data collection when visiting our website

2.1 Server log files

When you visit our website purely for informational purposes—that is, if you do not register or otherwise provide us with information—server log files are automatically recorded. This data is technically necessary to display the website correctly and to ensure the stability and security of our system.

Since our website is operated via the Shopify platform, this access data is collected by Shopify itself. The log files contain, among other things, the following information:

- Visited page of our website

- Date and time of access

- Amount of data sent in bytes

- Referrer URL (source/reference from which you accessed the page)

- Browser type and operating system used

- IP address (in pseudonymized form)

This data is processed in accordance with Art. 6 (1) (f) GDPR based on our legitimate interest in ensuring a technically error-free presentation and optimizing our website. The data will not be shared or used for any other purpose. However, we reserve the right to subsequently review the server log files if there is concrete evidence of illegal use.

Shopify stores this data for a maximum of 7 days and then automatically deletes it unless there are legal retention obligations or a security-related incident requires longer storage.

2.2 SSL or TLS encryption

For security reasons and to protect the transmission of confidential content, such as orders or inquiries, our website uses SSL or TLS encryption. You can recognize an encrypted connection by the "https://" character string and the lock symbol in your browser bar.

3) Cookies

To make visiting our website more attractive and enable the use of certain functions, we use cookies. These are small text files that are stored on your device. Some of these cookies are automatically deleted after the end of the browser session (so-called "session cookies"), while others remain on your device for a certain period of time and allow us to recognize your settings on your next visit (so-called "persistent cookies").

When you first visit our website, you have the option of individually deciding which categories of cookies you wish to accept via our cookie banner. We use the Consentmo GDPR Compliance app to manage consent, which allows for transparent selection and documentation of your cookie preferences. You can revoke or adjust your consent at any time via the cookie settings on our website.

If personal data is processed through individual cookies, the processing is carried out - depending on the type and purpose of the respective cookie - on the basis of Art. 6 (1) (a) GDPR (consent), Art. 6 (1) (b) GDPR (performance of contract) or Art. 6 (1) (f) GDPR (legitimate interest in a technically error-free and optimized provision of our services).

We may also use third-party cookies, e.g., to analyze user behavior or display personalized advertising. Further information on the cookies used, their purpose, and storage period can be found in our [Cookie Policy / Overview https://smartfoot.de/pages/gdpr-compliance ].

You can configure your browser to inform you about the use of cookies, to allow cookies only in specific cases, to exclude cookies for specific cases or in general, and to activate the automatic deletion of cookies when closing the browser. Please note that deactivating cookies may limit the functionality of our website.

4) Contact

When you contact us (e.g. via contact form or email), personal data will be processed exclusively for the purpose of processing and answering your request and only to the extent necessary for this purpose.

The legal basis for processing this data is our legitimate interest in responding to your request in accordance with Art. 6 (1) (f) GDPR. If your contact is related to a contract, the additional legal basis for processing is Art. 6 (1) (b) GDPR. Your data will be deleted if the circumstances indicate that the matter in question has been conclusively resolved and provided there are no statutory retention periods to the contrary.


5) Use of customer data for direct marketing

5.1 Registration for our email newsletter

If you subscribe to our email newsletter, we will regularly send you information about our offers. The only mandatory information required to receive the newsletter is your email address. Providing additional information is voluntary and will be used to address you personally. We use the so-called double opt-in procedure to send the newsletter, which ensures that you only receive the newsletter after you have expressly confirmed your consent to receive the newsletter by clicking on a verification link sent to the specified email address.

By activating the confirmation link, you consent to the use of your personal data in accordance with Art. 6 (1) (a) GDPR. We store your IP address entered by your Internet service provider (ISP), as well as the date and time of registration, in order to be able to trace any possible misuse of your email address at a later date. The data we collect when you register for the newsletter is used strictly for the intended purpose.

You can unsubscribe from the newsletter at any time using the link provided in the newsletter or by sending a corresponding message to the person responsible mentioned above. After unsubscribing, your email address will be immediately deleted from our newsletter distribution list unless you have expressly consented to further use of your data or we reserve the right to use the data in any other way that is permitted by law and about which we will inform you in this statement.

5.2 Sending the email newsletter to existing customers

If you provided us with your email address when purchasing goods or services, we reserve the right to regularly send you offers for similar goods or services from our range, as those you have already purchased. According to Section 7 (3) of the German Unfair Competition Act (UWG), we do not need to obtain your separate consent for this. Data processing is carried out solely on the basis of our legitimate interest in personalized direct advertising in accordance with Art. 6 (1) (f) GDPR. If you initially objected to the use of your email address for this purpose, we will not send you emails.

You are entitled to object to the use of your email address for the aforementioned advertising purposes at any time, with future effect, by notifying the controller named at the beginning. You will only incur transmission costs according to the basic rates. Upon receipt of your objection, the use of your email address for advertising purposes will be discontinued immediately.


5.3 Product availability notification by email

For temporarily unavailable items, you can sign up to receive email product availability notifications. We will then send you a one-time email notification about the availability of the item you have selected. The only mandatory information required to receive this notification is your email address. Providing additional information is voluntary and may be used to contact you personally. We use the so-called double opt-in process to send emails, which ensures that you will only receive a notification after you have expressly confirmed your consent by clicking on a verification link sent to the specified email address.

By activating the confirmation link, you consent to the use of your personal data in accordance with Art. 6 (1) (a) GDPR. We store your IP address entered by your Internet service provider (ISP), as well as the date and time of registration, in order to be able to trace any possible misuse of your email address at a later date. The data we collect when you register for our email notification service regarding product availability is used strictly for the intended purpose.

You can unsubscribe from availability notifications at any time by sending a corresponding message to the person responsible named above. After unsubscribing, your email address will be immediately deleted from our mailing list unless you have expressly consented to further use of your data or we reserve the right to use your data in any other way that is permitted by law and about which we will inform you in this statement.

6) Data processing for order processing

6.1 Transfer to transport companies and payment service providers

To the extent necessary for the execution of the contract for delivery and payment purposes, the personal data we collect will be passed on to the commissioned transport company and the commissioned credit institution in accordance with Art. 6 (1) (b) GDPR.

If we owe you updates for goods with digital elements or for digital products based on a corresponding contract, we will process the contact information you provided when placing your order (name, address, email address) in order to inform you personally about upcoming updates within the legally stipulated period via a suitable communication channel (e.g., by post or email) within the scope of our statutory information obligations pursuant to Art. 6 (1) (c) GDPR. Your contact information will be used strictly for the purpose of notifying you about updates owed by us and will only be processed by us to the extent necessary for the respective information.

To process your order, we also work with the following service provider(s), who support us in whole or in part in the execution of concluded contracts. Certain personal data will be transmitted to these service providers in accordance with the following information.

6.2 Transfer of personal data to shipping service providers

  • DHL

We use the following provider as our transport service provider: DHL Paket GmbH, Sträßchensweg 10, 53113 Bonn, Germany.

We will pass on your email address and/or telephone number to the provider in accordance with Art. 6 (1) (a) GDPR prior to delivery of the goods for the purpose of coordinating a delivery date or providing delivery notification, provided you have given your express consent to this during the ordering process. Otherwise, we will only pass on the recipient's name and delivery address to the provider for the purpose of delivery in accordance with Art. 6 (1) (b) GDPR. This information will only be passed on to the extent necessary for the delivery of the goods. In this case, prior coordination of the delivery date with the provider or a delivery notification is not possible.

The consent can be revoked at any time with future effect by contacting the person responsible named above or the provider.

  • DHL Freight

We use the following transport service provider: DHL Freight GmbH, Godesberger Allee 102-104, 53175 Bonn, Germany.

We will pass on your email address and/or telephone number to the provider in accordance with Art. 6 (1) (a) GDPR prior to delivery of the goods for the purpose of coordinating a delivery date or providing delivery notification, provided you have given your express consent to this during the ordering process. Otherwise, we will only pass on the recipient's name and delivery address to the provider for the purpose of delivery in accordance with Art. 6 (1) (b) GDPR. This information will only be passed on to the extent necessary for the delivery of the goods. In this case, prior coordination of the delivery date with the provider or a delivery notification is not possible.

The consent can be revoked at any time with future effect by contacting the person responsible named above or the provider.

6.3 Use of payment service providers (payment services)

  • Klarna

This website offers one or more online payment methods from the following provider: Klarna Bank AB, Sveavägen 46, 111 34 Stockholm, Sweden.

If you select a payment method from the provider that requires you to make an advance payment (e.g., credit card payment), the payment details you provided during the ordering process (including your name, address, bank and payment card information, currency, and transaction number), as well as information about the content of your order, will be passed on to the provider in accordance with Art. 6 (1) (b) GDPR. In this case, your data will be passed on exclusively for the purpose of processing the payment with the provider and only to the extent necessary for this purpose.

If you select a payment method that requires the provider to pay in advance (e.g., purchase on account, installment purchase, or direct debit), you will also be asked to provide certain personal information (first and last name, street, house number, postal code, city, date of birth, email address, telephone number, and, if applicable, details of an alternative payment method) during the ordering process.

In order to protect our legitimate interest in determining our customers' solvency, we forward this data to the provider for the purpose of a credit check in accordance with Art. 6 (1) (f) GDPR. Based on the personal data you provide and other data (such as shopping cart, invoice amount, order history, and payment experience), the provider will check whether the payment option you have selected can be granted in light of payment and/or default risks.

In addition to provider-internal criteria pursuant to Art. 6 (1) (f) GDPR, identity and credit information from the following credit agencies may also be taken into account when making a decision on the application:

https://cdn.klarna.com/1.0/shared/content/legal/terms/0/de_de/credit_rating_agencies

The credit report may contain probability values ​​(so-called scores). To the extent that scores are included in the credit report results, they are based on a scientifically recognized mathematical-statistical procedure. Address data, among other things, is used in the calculation of the scores.

You can object to this processing of your data at any time by sending us a message or contacting the provider. However, the provider may still be entitled to process your personal data if this is necessary for contractual payment processing.

  • Mollie

This website offers one or more online payment methods from the following provider: Mollie BV, Keizersgracht 313, 1016 EE Amsterdam, Netherlands.

If you select a payment method from the provider that requires you to make an advance payment (e.g., credit card payment), the payment details you provided during the ordering process (including your name, address, bank and payment card information, currency, and transaction number), as well as information about the content of your order, will be passed on to the provider in accordance with Art. 6 (1) (b) GDPR. In this case, your data will be passed on exclusively for the purpose of processing the payment with the provider and only to the extent necessary for this purpose.

  • Paypal

This website offers one or more online payment methods from the following provider: PayPal (Europe) Sarl et Cie, SCA, 22-24 Boulevard Royal, L-2449 Luxembourg.

If you select a payment method from the provider that requires you to make an advance payment, the payment details you provided during the ordering process (including your name, address, bank and payment card information, currency, and transaction number), as well as information about the content of your order, will be passed on to the provider in accordance with Art. 6 (1) (b) GDPR. In this case, your data will be passed on exclusively for the purpose of processing the payment with the provider and only to the extent necessary for this purpose.

If you select a payment method for which we make advance payments, you will also be asked to provide certain personal information (first and last name, street, house number, postal code, city, date of birth, email address, telephone number, and, if applicable, details of an alternative payment method) during the ordering process.

In such cases, in order to protect our legitimate interest in determining your ability to pay, we will forward this data to the provider for the purpose of a credit check in accordance with Art. 6 (1) (f) GDPR. The provider will check, based on the personal data you provide and other data (such as shopping cart, invoice amount, order history, and payment experience), whether the payment option you have selected can be granted in view of payment and/or default risks.

The credit report may contain probability values ​​(so-called scores). To the extent that scores are included in the credit report results, they are based on a scientifically recognized mathematical-statistical procedure. Address data, among other things, is used in the calculation of the scores.

You can object to this processing of your data at any time by sending us a message or contacting the provider. However, the provider may still be entitled to process your personal data if this is necessary for contractual payment processing.

7) Online marketing

HubSpot

This website uses the software-based marketing service of the following provider to provide and synchronize various customer management services: HubSpot Ireland Ltd., 2nd Floor, 30 North Wall Quay, Dublin 1, Ireland.

The service enables the automated processing of feed activities, the control of advertising in used marketing channels and the analysis of the success of marketing measures as well as central email marketing and contact management.

To fulfill the various functions, cookies are used. These are small text files that are stored locally in the cache of your web browser on your device and enable us to analyze your use of the website. These cookies collect certain information, such as your IP address, location, and the time of the page visit.

All processing described above, in particular the setting of cookies for reading information on the device used, will only be carried out if you have given us your express consent in accordance with Art. 6 (1) (a) GDPR. You can revoke your consent at any time with future effect by deactivating this service in the "Cookie Consent Tool" provided on the website.

Other legal bases for data processing that are used within the framework of specific service functions (such as the need for express consent pursuant to Art. 6 (1) (a) GDPR when sending newsletters) remain unaffected.

We have concluded a data processing agreement with the provider, which ensures the protection of the data of our website visitors and prohibits unauthorized disclosure to third parties.

8) Web analysis services

8.1 Google (Universal) Analytics

This website uses Google (Universal) Analytics, a web analysis service provided by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"), which enables an analysis of your use of our website.

Google (Universal) Analytics is used on this website exclusively without the use of cookies, which means that the service never places cookies on your device.

Instead, your browser's local storage is used to store a unique ID assigned by Google (Universal) Analytics, which enables an analysis of your website usage. For this purpose, certain user information is processed via the ID. This information also includes your IP address, which Google truncates to prevent it from being directly linked to a person.

The information is transferred to Google servers and processed there. This may also involve transferring it to Google LLC, based in the USA.

Google uses the information collected on our behalf to evaluate your use of the website, compile reports on website activity for us, and provide other services related to website activity and internet usage. The IP address transmitted and abbreviated by your browser as part of Google Analytics will not be merged with other Google data. The data collected as part of the use of Google (Universal) Analytics will be stored for a period of two months and then deleted.

All processing described above, including the storage of information on the device used in the form of the ID, will only take place if you have given us your express consent in accordance with Art. 6 (1) (a) GDPR.

Without your consent, Google (Universal) Analytics will not be used during your visit to the site. You can revoke your consent at any time with future effect.

To exercise your right of withdrawal, you can download and install the browser plug-in available under the following link: https://tools.google.com/dlpage/gaoptout?hl=de

As an alternative to the browser plug-in or within browsers on mobile devices, you can revoke your consent by clicking on the following link to set an opt-out cookie that will prevent Google Analytics from collecting data within this website in the future (this opt-out cookie only works in this browser and only for this domain. If you delete your cookies in this browser, you must click this link again): Deactivate Google Analytics

We have concluded a data processing agreement with Google that ensures the protection of our site visitors' data and prohibits unauthorized disclosure to third parties.

Further legal information on Google (Universal) Analytics can be found at https://policies.google.com/privacy?hl=de&gl=de and at https://policies.google.com/technologies/partner-sites .

Demographic Characteristics Google (Universal) Analytics uses the special "demographic characteristics" feature to create statistics that provide information about the age, gender, and interests of site visitors. This is done by analyzing advertising and information from third parties. This allows target groups to be identified for marketing activities. However, the collected data cannot be assigned to a specific person and is deleted after a storage period of two months.

Google Signals As an extension to Google (Universal) Analytics, Google Signals can be used on this website to create cross-device reports. If you have activated personalized ads and have linked your devices to your Google Account, Google can analyze your usage behavior across devices and create database models, including for cross-device conversions, subject to your consent to the use of Google Analytics in accordance with Art. 6 (1) (a) GDPR. We do not receive any personal data from Google, only statistics. If you would like to stop cross-device analysis, you can deactivate the "Personalized Advertising" function in the settings of your Google Account. To do so, follow the instructions on this page: https://support.google.com/ads/answer/2662922?hl=de . Further information about Google Signals can be found at the following link:https://support.google.com/analytics/answer/7532985?hl=de .

User IDs: As an extension to Google (Universal) Analytics, the "User IDs" feature can be used on this website. If you have consented to the use of Google (Universal) Analytics in accordance with Art. 6 (1) (a) GDPR, have set up an account on this website, and log in with this account on multiple devices, your activities, including conversions, can be analyzed across devices.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision of the European Commission.

8.2 Google Tag Manager

This website uses “Google Tag Manager”, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter: “Google”).

Google Tag Manager provides a technical basis for bundling various web applications, including tracking and analytics services, and calibrating, controlling, and linking them to conditions via a uniform user interface. Google Tag Manager itself does not store or read information on user devices. Nor does the service perform any independent data analyses. However, when you access a page, Google Tag Manager transmits your IP address to Google, where it may store it. It may also transmit the data to Google LLC servers in the USA.

This processing will only be carried out if you have given us your express consent in accordance with Art. 6 (1) (a) GDPR. Without this consent, Google Tag Manager will not be used during your visit to the site. You can revoke your consent at any time with future effect. To exercise your revocation, please deactivate this service using the "Cookie Consent Tool" provided on the website.

We have concluded a data processing agreement with the provider, which ensures the protection of the data of our website visitors and prohibits unauthorized disclosure to third parties.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision of the European Commission.


9) Retargeting/remarketing and conversion tracking

Meta Pixel

Within our online offering, we use the "Meta Pixel" service of the following provider: Meta Platforms Ireland Limited, 4 Grand Canal Quare, Dublin 2, Ireland ("Meta").

When a user clicks on an ad placed by us on Facebook and/or Instagram, a "meta pixel" is used to add a parameter to the URL of our linked page. This URL parameter is then entered into the user's browser after redirection via a cookie set by our linked page itself.

This allows Meta to define visitors to our online offering as a target group for displaying advertisements (so-called "ads"). Accordingly, we use the service to display the Facebook and/or Instagram ads we place only to users who have also shown an interest in our online offering or who exhibit certain characteristics (e.g., interests in certain topics or products determined based on the websites visited) that we transmit to Meta (so-called "custom audiences").

On the other hand, the “Meta Pixel” can be used to track whether users were redirected to our website after clicking on an advertisement and which actions they perform there (so-called “conversion tracking”).

The data collected is anonymous to us, meaning it does not allow us to draw any conclusions about the identity of the users. However, the data is stored and processed by Meta, allowing a connection to the respective user profile and allowing Meta to use the data for its own advertising purposes.

All processing described above, in particular the setting of cookies for reading information on the device used, will only be carried out if you have given us your express consent in accordance with Art. 6 (1) (a) GDPR. You can revoke your consent at any time with future effect by deactivating this service in the "Cookie Consent Tool" provided on the website.

We have concluded a data processing agreement with the provider, which ensures the protection of the data of our website visitors and prohibits unauthorized disclosure to third parties.

The information generated by Meta is generally transferred to a Meta server and stored there; in this context, it may also be transferred to Meta Platforms Inc. servers in the USA.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision of the European Commission.

10) Page functionalities

10.1 YouTube

This website uses plugins to display and play videos from the following provider: YouTube, LLC 901 Cherry Ave. San Bruno, CA 94066 USA.

When you visit a page on our website that contains such a plugin, your browser establishes a direct connection to the provider's servers to load the plugin. Certain information, including your IP address, is transmitted to the provider.

If the playback of embedded videos is started via the plugin, the provider also uses cookies to collect information about user behavior, create playback statistics and prevent abusive behavior.

If you are logged into a user account with the provider during your visit, your data will be directly assigned to your account when you click on a video. If you do not wish to be assigned to your account, you must log out before clicking the play button.

All of the aforementioned processing, in particular the setting of cookies for reading information on the device used, will only take place if you have given us your express consent in accordance with Art. 6 (1) (a) GDPR. You can revoke your consent at any time with future effect by deactivating this service using the "Cookie Consent Tool" provided on the website.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision of the European Commission.


10.2 Google Maps

This website uses an online map service from the following provider: Google Maps (API) from Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland (“Google”).

Google Maps is a web service for displaying interactive maps and geographical information visually. Using this service, you will be shown our location and it will make it easier for you to find us.

As soon as you access the sub-pages in which the Google Maps map is integrated, information about your use of our website (such as your IP address) is transmitted to Google servers and stored there. This may also involve transmission to the servers of Google LLC in the USA. This occurs regardless of whether Google provides a user account through which you are logged in or whether a user account already exists. If you are logged in to Google, your data is assigned directly to your account. If you do not wish to be assigned to your Google profile, you must log out before activating the button. Google stores your data (even for users who are not logged in) as usage profiles and evaluates this.

The collection, storage, and analysis are carried out in accordance with Art. 6 (1) (f) GDPR on the basis of Google's legitimate interest in displaying personalized advertising, market research, and/or tailoring Google websites to meet your needs. You have the right to object to the creation of these user profiles; you must contact Google to exercise this right. If you do not agree to the future transmission of your data to Google when using Google Maps, you also have the option of completely deactivating the Google Maps web service by disabling JavaScript in your browser. Google Maps, and thus the map display on this website, will then no longer be available.

To the extent legally required, we have obtained your consent to process your data as described above in accordance with Art. 6 (1) (a) GDPR. You can revoke your consent at any time with future effect. To exercise your consent, please follow the objection procedure described above.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision of the European Commission.

10.3 Endereco

In order to enable real-time verification of certain entries in the address form of our web shop's ordering process for input errors, we use the services of the following provider: Endereco UG, Balthasar-Neumann-Straße 4b, 97236 Randersacker, Germany.

The provider validates the entered address, verifies the spelling, and adds any missing information. If the address is unclear, correct alternative suggestions are displayed. For this purpose, the address data you enter is transmitted to the provider, where it is stored and evaluated.

This processing is carried out in accordance with Art. 6 (1) (f) GDPR on the basis of our legitimate interest in the proper collection of the customer's correct address data in order to conscientiously fulfill our contractual delivery obligations and to prevent contract implementation problems.

The provider processes the data in question separately and does not merge it with other data sets, and deletes it as soon as its status or correctness has been confirmed, but no later than 30 days.

10.4 Google reCAPTCHA

On this website we use the CAPTCHA service of the following provider: Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland.

Data may also be transmitted to: Google LLC, USA. The provider uses "Google Fonts," i.e., fonts downloaded from the Internet by Google, for the visual design of the Captcha window. No further information beyond that mentioned above, which is already transmitted to Google via the ReCaptcha functionality, is processed in this case.

The service checks whether an input was made by a natural person or abusively by machine and automated processing, and blocks spam, DDoS attacks, and similar automated malicious access. To ensure that an action is performed by a human and not an automated bot, the provider collects the IP address of the device used, identification data of the browser and operating system type used, as well as the date and duration of the visit, and transmits this data to the provider's servers for evaluation.

The legal basis is our legitimate interest in determining individual responsibility on the Internet and preventing misuse and spam in accordance with Art. 6 (1) (f) GDPR.

We have concluded a data processing agreement with the provider, which ensures the protection of the data of our website visitors and prohibits unauthorized disclosure to third parties.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision of the European Commission.

11) Rights of the data subject

11.1 The GDPR grants you the following data subject rights (rights of information and intervention) vis-à-vis the controller with regard to the processing of your personal data, whereby reference is made to the legal basis stated for the respective conditions for exercising these rights:

  • Right to information pursuant to Art. 15 GDPR;
  • Right to rectification pursuant to Art. 16 GDPR;
  • Right to erasure pursuant to Art. 17 GDPR;
  • Right to restriction of processing pursuant to Art. 18 GDPR;
  • Right to information pursuant to Art. 19 GDPR;
  • Right to data portability pursuant to Art. 20 GDPR;
  • Right to revoke consent given in accordance with Art. 7 (3) GDPR;
  • Right to lodge a complaint pursuant to Art. 77 GDPR.

11.2 RIGHT OF OBJECTION

IF WE PROCESS YOUR PERSONAL DATA BASED ON OUR OVERRIDING LEGITIMATE INTEREST AS PART OF A BALANCE OF INTERESTS, YOU HAVE THE RIGHT TO OBJECT TO THIS PROCESSING AT ANY TIME WITH FUTURE EFFECT FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION.

If you exercise your right to object, we will stop processing the data in question. However, we reserve the right to continue processing if we can demonstrate compelling legitimate grounds for the processing that override your interests, fundamental rights, and freedoms, or if the processing serves to assert, exercise, or defend legal claims.

If we process your personal data for direct marketing purposes, you have the right to object at any time to the processing of your personal data for such marketing purposes. You can exercise your right of objection as described above.

IF YOU EXERCISE YOUR RIGHT OF OBJECTION, WE WILL STOP PROCESSING THE DATA CONCERNED FOR DIRECT MARKETING PURPOSES.

12) Duration of storage of personal data

The duration of storage of personal data is determined based on the respective legal basis, the purpose of the processing and – where applicable – also on the respective statutory retention period (e.g. retention periods under commercial and tax law).

When processing personal data on the basis of an express consent in accordance with Art. 6 (1) (a) GDPR, the data concerned will be stored until you revoke your consent.

If there are statutory retention periods for data that are processed within the framework of legal transactions or quasi-legal obligations on the basis of Art. 6 (1) (b) GDPR, these data will be routinely deleted after the retention periods have expired, provided that they are no longer required for the fulfilment or initiation of a contract and/or we no longer have a legitimate interest in continuing to store them.

When processing personal data on the basis of Art. 6 (1) (f) GDPR, these data will be stored until you exercise your right of objection in accordance with Art. 21 (1) GDPR, unless we can demonstrate compelling legitimate grounds for the processing which outweigh your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims.

When processing personal data for the purpose of direct marketing on the basis of Art. 6 (1) (f) GDPR, these data will be stored until you exercise your right of objection in accordance with Art. 21 (2) GDPR.

Unless otherwise stated in the other information in this declaration on specific processing situations, stored personal data will be deleted when they are no longer necessary for the purposes for which they were collected or otherwise processed.