Legal
Privacy Policy
This is a translation for your convenience. The German version of this page is the legally binding one.
This privacy policy informs you about the nature, scope and purpose of the processing of personal data (hereinafter referred to simply as “data”) within our online offering and the websites, functions and content connected with it (hereinafter jointly referred to as the “online offering”). With regard to the terms used, such as “processing” or “controller”, we refer you to the definitions in Article 4 of the General Data Protection Regulation (GDPR).
Controller
Olga Kaiser, PKP GmbH (Automir Germany), Schwabentorring 10, 79098 Freiburg, Germany
Email address: data@automir-germany.com
Managing Directors: Olga Kaiser, Dr. Martin Preusse
Data protection contact: data@automir-germany.com
Types of data processed
- Master data (e.g. names, addresses)
- Contact data (e.g. email, telephone numbers)
- Content data (e.g. text entries, photographs, videos)
- Usage data (e.g. websites visited, interest in content, access times)
- Meta and communication data (e.g. device information, IP addresses)
Categories of data subjects
Visitors and users of the online offering (hereinafter we also refer to the data subjects collectively as “users”).
Purpose of processing
- Provision of the online offering, its functions and content
- Responding to contact enquiries and communicating with users
- Security measures
- Reach measurement / marketing
Terms used
“Personal data” means any information relating to an identified or identifiable natural person (hereinafter the “data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. a cookie) or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
“Processing” means any operation or set of operations which is performed on personal data, whether or not by automated means. The term is broad and covers practically any handling of data.
“Pseudonymisation” means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person.
“Profiling” means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.
“Controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
“Processor” means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
Relevant legal bases
In accordance with Article 13 GDPR, we inform you of the legal bases for our data processing. Where the legal basis is not stated in this privacy policy, the following applies: the legal basis for obtaining consent is Article 6 (1) (a) and Article 7 GDPR; the legal basis for processing in order to perform our services, carry out contractual measures and respond to enquiries is Article 6 (1) (b) GDPR; the legal basis for processing in order to fulfil our legal obligations is Article 6 (1) (c) GDPR; and the legal basis for processing in order to safeguard our legitimate interests is Article 6 (1) (f) GDPR. Should the vital interests of the data subject or another natural person require the processing of personal data, Article 6 (1) (d) GDPR serves as the legal basis.
Security measures
In accordance with Article 32 GDPR, and taking into account the state of the art, the costs of implementation and the nature, scope, circumstances and purposes of processing as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we take appropriate technical and organisational measures to ensure a level of security appropriate to the risk.
These measures include in particular safeguarding the confidentiality, integrity and availability of data by controlling physical access to the data as well as access to, input of, disclosure of, assurance of availability of and separation of that data. We have also established procedures that guarantee the exercise of data subject rights, the erasure of data and a response to threats to the data. Furthermore, we take the protection of personal data into account as early as the development or selection of hardware, software and procedures, in line with the principle of data protection by design and by default (Article 25 GDPR).
Cooperation with processors and third parties
Where, in the course of our processing, we disclose data to other persons and companies (processors or third parties), transmit it to them or otherwise grant them access to the data, this only takes place on the basis of a legal permission (for example where a transfer of data to third parties, such as payment service providers, is necessary for the performance of a contract pursuant to Article 6 (1) (b) GDPR), where you have consented, where a legal obligation provides for it, or on the basis of our legitimate interests (for example when engaging agents, web hosts and the like).
Where we commission third parties to process data on the basis of what is known as a data processing agreement, this takes place on the basis of Article 28 GDPR.
Transfers to third countries
Where we process data in a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)), or where this occurs in the course of using third-party services or disclosing or transferring data to third parties, this only takes place in order to fulfil our (pre-)contractual obligations, on the basis of your consent, due to a legal obligation, or on the basis of our legitimate interests. Subject to legal or contractual permissions, we process data in a third country, or have it processed there, only where the specific requirements of Articles 44 et seq. GDPR are met. This means that processing takes place, for example, on the basis of particular guarantees such as an officially recognised adequacy decision of the EU Commission or compliance with officially recognised special contractual obligations (so-called standard contractual clauses).
Rights of data subjects
You have the right to request confirmation as to whether data concerning you is being processed, and to obtain information about that data as well as further information and a copy of the data in accordance with Article 15 GDPR.
In accordance with Article 16 GDPR you have the right to request the completion of data concerning you or the rectification of inaccurate data concerning you.
In accordance with Article 17 GDPR you have the right to request that the data concerned be erased without delay, or alternatively, in accordance with Article 18 GDPR, to request a restriction of the processing of the data.
You have the right to request that the data concerning you which you have provided to us be made available to you in accordance with Article 20 GDPR, and to request its transmission to other controllers.
You also have the right, pursuant to Article 77 GDPR, to lodge a complaint with the competent supervisory authority.
Right of withdrawal
You have the right to withdraw consent you have given, with effect for the future, in accordance with Article 7 (3) GDPR.
Right to object
You may object at any time to the future processing of data concerning you in accordance with Article 21 GDPR. An objection may be lodged in particular against processing for the purposes of direct marketing.
Cookies and the right to object to direct marketing
“Cookies” are small files stored on users' computers. Various pieces of information can be stored within cookies. A cookie primarily serves to store information about a user (or about the device on which the cookie is stored) during or after their visit within an online offering. Cookies that are deleted after a user leaves an online offering and closes their browser are referred to as temporary cookies, “session cookies” or “transient cookies”. Cookies that remain stored even after the browser has been closed are described as “permanent” or “persistent”. Cookies offered by providers other than the controller operating the online offering are referred to as “third-party cookies”.
This online offering does not use any tracking or marketing cookies. Technically necessary information, such as the language version you have chosen, may be stored locally in your browser.
If users do not wish cookies to be stored on their computer, they are asked to deactivate the corresponding option in their browser's system settings. Stored cookies can be deleted in the browser's system settings. Excluding cookies may result in functional limitations of this online offering.
Erasure of data
The data we process is erased, or its processing restricted, in accordance with Articles 17 and 18 GDPR. Unless expressly stated otherwise in this privacy policy, the data stored by us is erased as soon as it is no longer required for its intended purpose and no statutory retention obligations prevent erasure. Where data is not erased because it is required for other, legally permissible purposes, its processing is restricted. This means that the data is blocked and not processed for other purposes. This applies, for example, to data that must be retained for commercial or tax law reasons.
Under statutory requirements in Germany, data is retained in particular for 10 years pursuant to Section 147 (1) AO and Section 257 (1) nos. 1 and 4, (4) HGB (books, records, management reports, accounting vouchers, commercial books, documents relevant for taxation, etc.) and for 6 years pursuant to Section 257 (1) nos. 2 and 3, (4) HGB (commercial letters).
Business-related processing
In addition, we process contract data (e.g. subject matter of the contract, term, customer category) and payment data (e.g. bank details, payment history) from our customers, prospective customers and business partners for the purpose of providing contractual services, service and customer care, marketing, advertising and market research.
Administration, financial accounting, office organisation, contact management
We process data in the course of administrative tasks as well as the organisation of our operations, financial accounting and compliance with legal obligations such as archiving. In doing so we process the same data that we process in the course of providing our contractual services. The bases for processing are Article 6 (1) (c) GDPR and Article 6 (1) (f) GDPR. Customers, prospective customers, business partners and website visitors are affected by this processing. The purpose of, and our interest in, the processing lies in administration, financial accounting, office organisation and the archiving of data – that is, tasks which serve to maintain our business activities, perform our duties and provide our services.
In this context we disclose or transmit data to the tax authorities, to advisers such as tax consultants or auditors, and to other fee offices and payment service providers.
Furthermore, on the basis of our business interests, we store information on suppliers, organisers and other business partners, for example for the purpose of contacting them at a later date. This predominantly company-related data is generally stored permanently.
Contacting us
When you contact us (e.g. by email or by telephone), the user's details are processed in order to handle and deal with the contact enquiry pursuant to Article 6 (1) (b) GDPR. Users' details may be stored in a customer relationship management system (“CRM system”) or comparable enquiry management system.
We delete enquiries once they are no longer required. We review this necessity every two years; statutory archiving obligations also apply.
Hosting and email dispatch
The hosting services we use serve to provide the following services: infrastructure and platform services, computing capacity, storage space and database services, email dispatch, security services and technical maintenance services, which we use for the purpose of operating this online offering.
In doing so, we or our hosting provider process master data, contact data, content data, contract data, usage data, and meta and communication data of customers, prospective customers and visitors to this online offering on the basis of our legitimate interests in the efficient and secure provision of this online offering pursuant to Article 6 (1) (f) GDPR in conjunction with Article 28 GDPR (conclusion of a data processing agreement).
Collection of access data and log files
On the basis of our legitimate interests within the meaning of Article 6 (1) (f) GDPR, we or our hosting provider collect data on every access to the server on which this service is located (so-called server log files). Access data includes the name of the website accessed, the file, the date and time of access, the volume of data transferred, notification of successful retrieval, browser type and version, the user's operating system, the referrer URL (the previously visited page), the IP address and the requesting provider.
Log file information is stored for security reasons (for example to investigate misuse or fraud) for a maximum of 7 days and then deleted. Data whose further retention is necessary for evidentiary purposes is exempt from erasure until the incident in question has been finally clarified.
Integration of third-party services
This online offering does not integrate any third-party map, analytics or social media services. Fonts, graphics and scripts are delivered from our own server.