Privacy Policy

DATA PRIVACY DECLARATION

(Last updated September 2018)

Section 1 Information on the collection of personal data

(1) In the following document, we will inform you how personal data are collected when you use our website www.winkelmann-idee.de (hereinafter referred to as the “website”). Personal data includes all data that can be used to personally identify you, such as your name, address, e-mail addresses, and user behavior.

(2) The controller in accordance with Art. 4 para. 7 of the EU General Data Protection Regulation (GDPR) is

Hans E. Winkelmann GmbH
Maybachstraße 5
63322 Rödermark

Telephone 06074 9206 0
Fax 06074 9206 300
E-mail info@winkelmann-idee.de

The controller has appointed the following Data Protection Officer for its company:

Data Protection Officer
Maybachstraße 5
63322 Rödermark

Telephone 06074 9206 0
E-mail datenschutz@winkelmann-idee.de

(3) When you contact us via e-mail or using a contact form, we store the data you provide (your e-mail address, and your name and telephone number in some cases) for the purpose of answering your questions. We delete the data collected during this process once storage is no longer required, or we restrict the processing of such data if statutory retention periods apply.

(4) If we use commissioned service providers to offer individual functions of our website, or if we want to use your data for commercial purposes, we inform you about these processes below in more detail. We also indicate the criteria established for storage durations.

Sec. 2 Rights of data subjects

(1) You have the following rights towards us with respect to your personal data:

  • Right to information on the personal data in question (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to deletion (Art. 17 GDPR)
  • Right to restrict data processing (Art. 18 GDPR)
  • Right to object to processing, if data processing is carried out on the basis of Art. 6 para. 1 lit. e or lit. f GDPR (Art. 21 GDPR), see also the following reference to your right to object in accordance with Art. 21 GDPR
  • Right to data portability (Art. 20 GDPR)
  • Right to revoke consent granted at any time, without this affecting the legality of processing carried out based on the consent until revocation, if the data processing is based on consent in accordance with Art. 6 para. 1 lit. a or Article 9 para. 2 lit. a GDPR.

(2) In addition, you have the right to lodge complaints with a data protection supervisory authority regarding the processing of your personal data (Art. 77 GDPR). See also Section 11

The Hesse Commissioner for Data Protection and Freedom of InformationPO Box 3163
65201 Wiesbaden

Telephone  +49 611 1408 -0
Fax +49 611 1408 – 900
https://datenschutz.hessen.de/über-uns/kontakt

Section 3 Collection of personal data when you visit our website

(1) If you simply use our website for informational purposes, for instance if you do not register and do not transmit information to us in any other manner, we only collect the personal data your browser transmits to our server. If you want to view our website, we collect the following data. These data are required for technical purposes to display the website to you and ensure the stability and security of the website (the legal basis is Art. 6 para. 1 lit. f GDPR):

  • IP address
  • Date and time of the inquiry
  • Time zone difference to Greenwich Mean Time (GMT)
  • Content of the request (specific page)
  • Access status/HTTP status code
  • Quantity of data transmitted
  • Website from which the request comes
  • Browser
  • Operating system and interface
  • Language and version of browser software

(2) In addition to the above data, cookies are saved on your computer when you use our website. Cookies are small text tiles saved on your hard drive by the browser you use. They are used to deliver information to the entity setting the cookie (in this case, us). Cookies cannot execute programs or transmit viruses to your computer. They are used to make the website overall more user-friendly and effective.

(3) Use of cookies:

a) This website uses the following types of cookies, the scope and function of which are explained in the following:

  • Transient cookies (see b) and
  • Persistent cookies (see c) and
  • Cookies associated with third party services, as described in the following:

(b) Transient cookies are deleted automatically when you close your browser. These specifically include session cookies. These cookies store a so-called session ID that can be used to attribute different requests by your browser to the overall session. This allows us to recognize your computer once again when you return to our website. Session cookies are deleted when you log out or close your browser.

c) Persistent cookies are automatically deleted after a specified time period, which can differ depending on the cookie. You can delete the cookies at any time using your browser’s security settings.

(d) You can configure your browser settings as desired, for instance to deny acceptance of third party cookies or all cookies. Information on managing and deleting cookies and instructions for doing so for common browsers are also available at www.meine-cookies.org. Please note that you may not be able to use all functions of this website if you delete cookies.

(e) This stored information is saved separate from any other data you provide to us. In particular, cookie data are not linked to your other data, if such data are transmitted.

Section 4 Additional functions and services of our website

(1) In addition to simply using our website for informational purposes, we offer a variety of services you can use if desired. To do so, you must typically provide further personal data, which we will use to perform the specific service and for which the aforementioned data processing principles apply.

(2) In some cases, we use external service providers to process your data. We select and commission such providers carefully. They are bound to carry out our instructions, and undergo regular controlling.

(3) In addition, we can transmit your personal data to third parties if we offer the option of taking part in a sweepstakes or competition, concluding a contract, or similar services alongside a partner. Further information is available when you provide your personal data, or below in the description of the services.

(4) If our service providers or partners are located in a state outside of the European Economic Area (EEA), we will inform you of the consequences of this in the description of the service.

(5) We do not take part in automated decision-making or profiling.

Section 5 Revocation or objection against data processing

A. Right to object based on specific situation

You have the right to object to the processing of your personal information at any time for reasons related to your specific situation, if such processing is carried out under Art. 6 para. 1 lit. e (public interest) or f (data processing based on a balancing of interests) GDPR; this also applies to profiling based on these provisions. We will no longer process your personal information, unless we can show that there are mandatory and protected grounds for processing that outweigh your interests, rights, and freedoms, or if processing serves to assert, exercise, or defend against legal claims.

B. Right to object to direct advertisement

If we process your personal information for the purpose of direct advertising, you have the right to object against processing of your personal data for the purpose of such advertisements; this also applies to profiling, if it is connected to such direct advertising. If you object to processing for the purpose of direct advertising, your personal data will no longer be processed for this purpose.

C. Exercising your right to object

You can exercise your right to object without any formal requirements, for instance by sending a letter to Hans E. Winkelmann GmbH, Maybachstraße 5, 63322 Rödermark, or by sending an e-mail to info@winkelmann-idee.de

Section 6 Third party services

Use of Google Web Fonts

To display our content correctly across browsers and in an appealing manner, we use the Google Web Fonts library (https://www.google.com/webfonts/) from third party provider Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”). Google Web Fonts are transmitted to the cache of your browser to prevent having to load them multiple times. If the browser does not support Google Web Fonts or prevents access, content is displayed in a standard font. When font libraries are accessed, this automatically initiates a connection to the library operator. In doing so, it is theoretically possible – although it is not clear that this occurs and, if so, for what purposes – that the operators of these libraries may collect data. The data privacy policy of library operator Google is available here: https://www.google.com/policies/privacy)

Data is processed on the legal basis of Art. 6 para. 1 lit. f GDPR.

Use of YouTube

We integrate videos from the “YouTube” platform, from the provider Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

Data Privacy Policy: https://www.google.com/policies/privacy/

Opt out: https://adssettings.google.com/authenticated

Data is processed on the legal basis of Art. 6 para. 1 lit. f GDPR.

Section 7 Subcontractors and recipients of personal data

(1) We use subcontractors to process personal data, and conclude contracts with these processors in accordance with the requirements of Art. 28 GDPR. We use the services of the company WebhostOne GmbH as a subcontractor for website hosting.

(2) Your personal data are not transmitted to any companies besides those indicated.

Section 8 Protection of personal data

(1) We take technical and organizational measures to protect users’ personal data in accordance with the requirements of Art. 32 GDPR.

(2) All of our employees involved in processing personal data are obligated to maintain data secrecy.

(3) Personal data of users is HTTPS encrypted during transmission to the website.

(4) To prevent use by machines, we may use CAPTCHAS in accordance with Art. 32 para. 1 lit. b GDPR. These contain pictures or information that cannot be processed by computer scripts.

Section 9 Legal basis

In accordance with Art. 13 GDPR, we inform you of the legal basis for data processing:

– If we obtain consent from a data subject to process personal data, Art. 6 para. 1 lit. a. of the GDPR serves as the legal basis for processing such personal information.

– When processing personal data necessary to fulfill an agreement to which the data subject is a contractual party, Art. 6 para. 1 lit. b GDPR serves as the legal basis for processing. This also applies to processing procedures necessary to take steps prior to entering into a contract.

– If personal information must be processed to fulfill a legal obligation to which we are subject, Art. 6 para. 1 lit. c GDPR serves as the legal basis.

– The legal basis for temporary storage of data and log files is Art. 6 para. 1 lit. f GDPR.

– Art. 6 para. 1 lit. f GDPR forms the legal basis for processing personal data using technically required cookies. Art. 6 para. 1 lit. f GDPR forms the legal basis for processing personal information using cookies for analytic purposes.

– If data processing is required to safeguard a legitimate interest of our company or a third party, and if the interests, basic rights, and basic freedoms of the data subject do not override the above interest, Art. 6 para. 1 lit. f GDPR serves as the legal basis for processing.

Section 10 Data protection supervisory authorities and right to submit complaints

The data protection authority responsible for us to which complaints regarding a violation of data privacy law can be submitted (among other authorities) is:

The Hesse Commissioner for Data Protection and Freedom of Information
PO Box 3163
65021 Wiesbaden

Telephone +49 611 1408 – 0
Fax +49 611 1408 – 900
https://datenschutz.hessen.de/über-uns/kontakt

Section 11 Updates to this Data Privacy Notice

From time to time, we must adapt the content of this Data Privacy Notice. Therefore, we reserve the right to change this notice at any time. We will send the changed version of the Data Privacy Notice to registered users before the changes take effect, and publish it in the same place as this Data Privacy Notice.