Data protection
1. General information and principles of data processing
We are pleased that you are visiting our website. The protection of your privacy and the protection of your personal data, so-called personal data, when using our website is important to us.
According to Art. 4 No. 1 GDPR, personal data is all information that relates to an identified or identifiable natural person. This includes, for example, information such as your first and last name, your address, your telephone number, your email address, but also your IP address.
Data that cannot be linked to you personally, such as through anonymization, is not personal data. Processing (e.g. collection, storage, reading, querying, use, transmission, deletion or destruction) in accordance with Art. 4 No. 2 GDPR always requires a legal basis or your consent. Processed personal data must be deleted as soon as the purpose of the processing has been achieved and there are no longer any legally required retention periods.
Here you will find information about how we handle your personal data when you visit our website. In order to provide the functions and services of our website, it is necessary for us to collect personal data about you.
We also explain to you the type and scope of the respective data processing, the purpose and the corresponding legal basis and the respective storage period.
This privacy statement applies only to this website. It does not apply to other websites to which we merely refer via a hyperlink. We cannot accept any responsibility for the confidential handling of your personal data on these third-party websites, as we have no influence on whether these companies comply with data protection regulations. Please find out about how these companies handle your personal data directly on these websites.
2. Responsible body
Responsible for the processing of personal data on this website is (see imprint):
3. Provision and use of the website/server log files
a) Type and scope of data processing
If you use this website without otherwise transmitting data to us (e.g. by registering or using the contact form), we collect technically necessary data via server log files, which are automatically transmitted to our server, including:
- IP address
- Date and time of the request
- Name and URL of the retrieved file
- Website from which access is made (referrer URL)
- Access status/HTTP status code
- Browser type
- Language and version of the browser software
- operating system
b) Purpose and legal basis
This processing is technically necessary in order to be able to display our website to you. We also use the data to ensure the security and stability of our website.
The legal basis for this processing is Art. 6 (1) (f) GDPR. The processing of the data mentioned is necessary for the provision of a website and thus serves to safeguard a legitimate interest of our company.
c) Storage period
As soon as the personal data mentioned is no longer required to display the website, it will be deleted. The collection of data to provide the website and the storage of data in log files is essential for the operation of the website. Consequently, the user has no option to object to this aspect. Further storage may take place in individual cases if this is required by law.
4. Use of cookies
a) Type, scope and purpose of data processing
We use cookies. Cookies are small files that we send to the browser of your device and store there when you visit our website.
Some functions of our website cannot be offered without the use of technically necessary cookies. Other cookies, on the other hand, enable us to carry out various analyses. For example, some cookies can recognize the browser you use when you visit our website again and send us various information. We use cookies to make our website easier and to improve it. Among other things, cookies enable us to make our internet offering more user-friendly and effective for you by, for example, tracking your use of our website and determining your preferred settings (e.g. country and language settings). If third parties process information using cookies, they collect the information directly via your browser. However, cookies do not cause any damage to your device. They cannot run programs and do not contain viruses. Various types of cookies are used on our website, the type and function of which are explained below.
Temporary cookies/session cookies
Our website uses so-called temporary cookies or session cookies , which are automatically deleted as soon as you close your browser. This type of cookie makes it possible to record your session ID. This allows different requests from your browser to be assigned to a common session and it is possible to recognize your device on subsequent website visits.
Persistent cookies
So-called permanent cookies are used on our website. Permanent cookies are cookies that are stored in your browser for a longer period of time and can transmit information. The respective storage period differs depending on the cookie. You can delete permanent cookies yourself via your browser settings.
Third-party cookies
We use analytical cookies to monitor anonymized user behavior on our website.
We also use advertising cookies. These cookies can be used to track user behavior for advertising and targeted marketing purposes.
Social media cookies enable you to connect to your social networks and share content from our website within your networks.
Configuring browser settings
Most web browsers are preset to accept cookies automatically. However, you can configure your browser to only accept certain cookies or no cookies at all. However, we would like to point out that in this case you may no longer be able to use all the functions of our website.
You can also delete cookies that have already been saved in your browser using your browser settings. It is also possible to set your browser so that it notifies you before cookies are saved. Since different browsers can work differently, we ask you to use the respective help menu of your browser for the corresponding configuration options.
Disabling the use of cookies may require a permanent cookie to be stored on your computer. If you subsequently delete this cookie, you will have to disable it again.
b) Legal basis
Due to the purposes described, the legal basis for the processing of personal data using cookies is Art. 6 Para. 1 lit. f) GDPR. If you have given us your consent to use cookies on the basis of a notice provided by us on the website (“cookie banner”), the legal basis is additionally Art. 6 Para. 1 lit. a) GDPR.
c) Storage period
As soon as the data transmitted to us via cookies is no longer required for the purposes described above, this information is deleted. Further storage may take place in individual cases if this is required by law.
5. Data collection for the implementation of pre-contractual measures and for the performance of the contract
a) Type and scope of data processing
We collect personal data about you in the pre-contractual area and when concluding the contract. This includes, for example, your first and last name, address, email address, telephone number or bank details.
b) Purpose and legal basis of data processing
We collect and process this data exclusively for the purpose of executing the contract or fulfilling pre-contractual obligations.
The legal basis for this is Art. 6 Para. 1 lit. b) GDPR. If you have also given your consent, the additional legal basis is Art. 6 Para. 1 lit. a) GDPR.
c) Storage period
The data will be deleted as soon as it is no longer required for the purpose for which it was processed.
In addition, there may be statutory retention obligations, for example retention obligations under commercial or tax law in accordance with the German Commercial Code (HGB) or the German Fiscal Code (AO). If such retention obligations exist, we will block or delete your data at the end of these retention obligations.
6. Order form
There is an order form on our website that can be used for electronic pre-orders.
a) Type and scope of data processing
Our data collection is limited to the following data:
- First and Last Name
- Telephone number
- e-mail address
- Account details
- Name of the product
b) Purpose and legal basis
The purpose of data processing is to enable us to process your order properly.
The legal basis for this is Art. 6 (1) (b) GDPR. The processing of the data serves to fulfill a contract or is necessary for the implementation of a pre-contractual measure that was carried out at the request of the data subject.
c ) Storage period
The data will be deleted as soon as it is no longer required to achieve the purpose of processing.
In addition, there may be statutory retention obligations, for example retention obligations under commercial or tax law in accordance with the German Commercial Code (HGB) or the German Fiscal Code (AO). If such retention obligations exist, we will block or delete your data at the end of these retention obligations.
7. Registration option
a) Type and scope of data processing
You can register on our website. When you register, we collect and store the data you enter in the input mask (e.g. last name, first name, email address). This data will not be passed on to third parties.
b) Purpose and legal basis of data processing
Your registration is required for the use of certain content and services on our website or for the fulfillment of a contract or to carry out pre-contractual measures. After registration, you are free to change the personal data provided during registration at any time or to have it completely deleted from the data records of the data controller.
In the case of consent, the legal basis for processing is Art. 6 para. 1 lit. a)
GDPR. If your registration serves to prepare for the conclusion of a contract, Art. 6 (1) lit. b) GDPR is an additional legal basis.
c) Storage period
The data collected during registration will be stored by us for as long as you are registered on our website and will then be deleted. Statutory retention periods remain unaffected.
8. Data transmission
We will only share your personal information with third parties if:
a) You have given your express consent in accordance with Art. 6 (1) (a) GDPR.
b) this is legally permissible and is necessary according to Art. 6 (1) (b) GDPR to fulfil a contractual relationship with you or to carry out pre-contractual measures.
c) there is a legal obligation to pass on the data pursuant to Art. 6 (1) (c) GDPR.
We are legally obliged to transmit data to state authorities, e.g. tax authorities, social insurance providers, health insurance companies, supervisory authorities and law enforcement authorities.
d) the transfer pursuant to Art. 6 (1) (f) GDPR is necessary to safeguard legitimate corporate interests, as well as to assert, exercise or defend legal claims and there is no reason to assume that you have an overriding legitimate interest in not disclosing your data.
e) in accordance with Art. 28 GDPR, we use external service providers (so-called data processors) for processing, who are obliged to handle your data carefully.
We use such service providers in the following areas:
- IT
- logistics
- telecommunications
When transferring data to external bodies in third countries, i.e. outside the EU or EEA, we ensure that these bodies treat your personal data with the same care as within the EU or EEA. We only transfer personal data to third countries where the EU Commission has confirmed an adequate level of protection or if we ensure the careful handling of the personal data through contractual agreements or other suitable guarantees.
9. Application opportunity
a) Type and scope of data processing
You can apply on our website or by email. When you apply, we collect and store the data that you enter in the input mask or that you send us by email.
b) Purpose and legal basis
- We process your data only for the purpose of processing your application.
There will be no transfer to third parties. The legal basis for the processing is Art. 88 Para. 1 GDPR in conjunction with Section 26 BDSG and additionally Art. 6 Para. 1 lit. b) GDPR.
If you give us your consent to be included in our applicant pool, the legal basis is Art. 6 (1) (a) GDPR.
c) Storage period
If we are unable to offer you a position, we will store your data for a maximum of six months after the end of the application process, taking into account Section 61b Paragraph 1 ArbGG in conjunction with Section 15 AGG. The deadline begins upon receipt of the rejection letter.
If you have given us your consent to be included in our applicant pool, we will store your data for a maximum of two years.
d) Data transfer
Your data will only be made available to those departments that are involved in the decision (responsible HR or specialist departments, management, works council).
In addition, we are obliged to transmit your data to public bodies and institutions (e.g. public prosecutors, police, supervisory authorities, tax authorities, social insurance providers, etc.).
Other data recipients may be those entities for which you have given us your consent to transmit data.
10. Comment function
a) Type and scope of data processing
You can comment on posts on our website. When you comment on a post, we collect and store the data you enter in the input mask. In addition to the comments you leave, information on the time the comment was entered and possibly the user name (pseudonym) you chose are also stored and published. In addition, the IP address assigned to the person concerned by the Internet service provider (ISP) is stored. The data is not passed on to third parties.
b) Purpose and legal basis
The data you transmit (e.g. IP address) is stored for security reasons and in the event that the person concerned violates the rights of third parties or posts illegal content through a comment.
The personal data collected will not be passed on to third parties unless such disclosure is required by law or serves the legal defense of the person responsible for processing.
The legal basis for the processing of personal data transmitted when using the comment function is Art. 6 Paragraph 1 Letter a) of GDPR, if and to the extent that you have given your consent. You can revoke this consent at any time. The legality of the data processing operations that have already taken place remains unaffected by the revocation.
The further legal basis is Art. 6 Para. 1 lit. f) GDPR.
We have a legitimate interest in processing if the rights of third parties are violated or illegal content is posted. This is for security reasons in case someone writes illegal content in comments and posts (insults, prohibited political propaganda, etc.).
c) Storage period
The comments and the associated data (e.g. IP address) are stored and remain on our website until the commented content has been completely deleted or the comments have to be deleted for legal reasons.
11. Contact form
a) Type and scope of data processing
On our website we offer you the opportunity to contact us using a form provided. When you send your request via the contact form, reference will be made to this privacy policy to obtain your consent.
If you use the contact form, the following personal data will be processed:
- Salutation
- First name
- Last name
- Title
- Company
- Industry
- Function
- Street
- Street number
- Postal code
- Location
- Country
- E-mail address
- Telephone number
- Reference
- Content of the message
b) Purpose and legal basis
The purpose of providing your email address is to send you an answer to your inquiry by email. When you use the contact form, your personal data will not be passed on to third parties.
The legal basis for the processing is consent in accordance with Art. 6 (1) (a) GDPR based on the declaration of consent you have voluntarily provided below and which can be revoked at any time for the future:
c) Storage period
The data you enter in the contact form will remain with us until you request deletion, revoke your consent to storage or the purpose for data storage no longer applies (e.g. after your request has been processed).
Mandatory legal provisions – in particular retention periods according to the German Commercial Code (HGB) or the German Tax Code (AO) – remain unaffected by this.
12. Contact options by email
You can contact us via email on our website.
a) Type and scope of data processing
You can contact us by email. Our data collection is limited to the email address of the email account you used to contact us and to any personal data you provide when contacting us.
b) Purpose and legal basis
The purpose of data processing is to be able to answer your request appropriately. The legal basis for this is Art. 6 Paragraph 1 Letter f) GDPR. There is a legitimate interest in processing the above-mentioned personal data in order to be able to process your request appropriately.
c) Storage period
The duration for which the above data is stored depends on the reason for your contact. Your personal data is regularly deleted if the purpose of the communication no longer applies and storage is no longer necessary. This may, for example, result from processing your request.
13. Newsletter
a) Type and scope of data processing
On our website you have the opportunity to subscribe to a free regular e-mail newsletter. In order to send you the newsletter regularly, we need your e-mail address.
We use the so-called double opt-in procedure to send newsletters.
This means that we will only send you an email newsletter if you have expressly confirmed to us that you agree to receive the newsletter. We will then send you a confirmation email asking you to confirm that you wish to receive newsletters from us in the future by clicking on a link.
This is to ensure that only you, as the owner of the specified email address, can subscribe to the newsletter. Your confirmation must be made promptly after receiving the confirmation email, otherwise your newsletter registration will be automatically deleted from our database.
If you subscribe to the newsletter, we collect and store the data you enter in the input mask (e.g. last name, first name, e-mail address).
When you register for the newsletter, we also save your IP address entered by your Internet Service Provider (ISP) as well as the date and time of registration in order to be able to trace any possible misuse of your email address at a later date. In the confirmation email sent for control purposes (double opt in the
E-mail) we also save the date and time of clicking on the confirmation link and the IP address entered by the Internet Service Provider (ISP).
b) Purpose and legal basis
The data we collect when you register for the newsletter will be used exclusively for the purposes of advertising via the newsletter.
The processing of your email address for sending the newsletter is based on Art. 6 (1) (a) GDPR and Section 7 (2) No. 3 UWG on the declaration of consent you voluntarily provide below and which can be revoked at any time in the future.
In addition, the processing is based on Art. 6 (1) (f) GDPR due to our legitimate interest in documenting proof of the required consent.
c) Storage period
Your email address will be stored as long as you are subscribed to the newsletter. After unsubscribing from the newsletter, your email address will be deleted unless you have expressly consented to further use of your data.
14. Tracking and analysis tools
Amazon Pay
We offer the option of processing the payment transaction via the payment service provider Amazon Payments Europe SCA 5, Rue Plaetis - 2338 Luxembourg.
The legal basis for this is our legitimate interest in efficient and secure payment processing in accordance with Art. 6 Para. 1 lit. f GDPR. In this context, we pass on the following data to Amazon Pay insofar as it is necessary for the performance of the contract (Art. 6 Para. 1 lit b. GDPR): name, address, bank details, possibly credit card number, invoice amount, currency and transaction number. Your data will be passed on exclusively for the purpose of payment processing with the payment service provider Amazon Payments and only to the extent that it is necessary for this purpose.
Amazon carries out a credit check for various services such as payment by direct debit in order to ensure your willingness and ability to pay. This corresponds to the legitimate interest of Amazon Pay (according to Art. 6 Para. 1 lit. f GDPR) and serves the purpose of executing the contract (according to Art. 6 Para. 1 lit. b GDPR). For this purpose, your data (name, address and date of birth, bank account details) are passed on to credit agencies. We have no influence on this process and only receive the result of whether the payment was made or rejected or whether a review is pending.
For more information about data protection at Amazon Pay, please visit:
https://pay.amazon.com/de/help/201751600
Consent Manager
We have integrated the consent management tool “consentmanager” (www.consentmanager.net) from consentmanager AB, Håltgelvågen 1b, 72348 Västerås, Sweden, mail@consentmanager.net, on our website in order to request consent for data processing or the use of cookies or similar functions. With the help of “consentmanager” you have the option of giving or rejecting your consent for certain functionalities of our website, e.g. for the purpose of integrating external elements, integrating streaming content, statistical analysis, reach measurement and personalized advertising. With the help of “consentmanager” you can give or reject your consent for all functions or give your consent for individual purposes or individual functions. The settings you have made can also be changed by you retrospectively. The purpose of integrating “consentmanager” is to leave the decision on the aforementioned things to the users of our website and to offer the opportunity to change settings already made as part of further use of our website. When using “consentmanager”, personal data and information about the end devices used (IP address, language, browser, etc.) are processed and sent to consentmanager AB. Information about the settings you have made is also stored on your end device.
The legal basis for the processing is Art. 6 Para. 1 Clause 1 Letter c) GDPR in conjunction with Art. 7 Para. 1 GDPR, insofar as the processing serves to fulfill the legally standardized proof obligations for the granting of consent. Otherwise, Art. 6 Para. 1 Clause 1 Letter f) GDPR is the relevant legal basis. Our legitimate interests in the processing lie in the storage of user settings and preferences with regard to the use of cookies and the evaluation of consent rates. Consent will be requested again no later than twenty-four months after the user settings have been made. The user settings made will then be saved again for this period, unless you yourself delete the information about your user settings in the end device capacities provided for this purpose.
You can object to the processing if the processing is based on Art. 6 Paragraph 1 Clause 1 Letter f) of GDPR. You have the right to object for reasons arising from your particular situation. To object, please send an email to mail@consentmanager.net.
Facebook
If you visit our Facebook fan page, Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2 D02 X525, Ireland , collects, stores and processes your personal data in accordance with Facebook's privacy policy. You can find the privacy policy here:
https://de-de.facebook.com/policy.php
As part of the “Facebook Insights” function, Facebook can provide us with the following data categories in anonymized/statistical form for the purpose of measuring performance and optimizing our Facebook presence:
- Predefined interactions on our fan page
- Time stamp
- User's country/city
- HTTP language code
- Age/Gender group
- Previously visited website (so-called referral URL)
- User's device
- Facebook user ID (if logged in)
With regard to the processing of Insights data, there is a joint responsibility between Facebook and us, within the framework of which Facebook has assumed primary responsibility. This concerns the processing of Insights data and the implementation of the rights of those affected. Please therefore contact Facebook directly regarding all obligations under the GDPR with regard to the processing of Insights data. We will forward any inquiries we receive in this regard to Facebook. Further details on this are set out in the Joint Controller Addendum, which you can find here: www.facebook.com/legal/terms/page_controller_addendum
You can find more information about Facebook Insights here:
www.facebook.com/legal/terms/information_about_page_insights_data
Google reCAPTCHA
In order to ensure sufficient data security when submitting forms, in certain cases we use the reCAPTCHA service, a service provided by Google LLC, 1600 Amphitheater Parkway, Mountainview, California 94043, USA.
This allows us to distinguish whether the input was made by a human or by automated computer programs (bots). By using reCAPTCHA, the user's IP address and possibly other data required by Google for the reCAPTCHA service are transmitted to Google. The data protection provisions of Google LLC apply to this.
The legal basis for the use of reCAPTCHA is Art. 6 (1) (f) GDPR. Checking form entries to see whether they were created by a human represents a legitimate interest of the website operator.
Google’s European contact details:
Google Analytics
Gordon House, 4 Barrow Street
Dublin D04 E5W5
Ireland
Phone: +353 1 543 1004
For more information about Google LLC's privacy policy, please visit http://www.google.de/intl/de/privacy or https://www.google.com/intl/de/policies/privacy/
If you visit our Instagram channel, personal data will be stored and processed by Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2 D02 X525, Ireland, as the provider of Instagram, in accordance with Instagram's privacy policy. You can find the privacy policy here:
https://help.instagram.com/519522125107875
We use the statistics service Instagram Insights to design our pages to meet your needs and to continuously optimize them. This service records your activity on our site and makes it available to us in anonymized statistics. This gives us insights into the interactions of our fan page visitors, the number of visits to our site, the reach of posts, information about the activity of our subscribers, information about the countries and locations from which our visitors come, and statistics about the gender ratio of our visitors. We are unable to draw conclusions about individual users or access individual user profiles.
Paypal
We offer the option of processing the payment transaction via the payment service provider PayPal, PayPal (Europe) S.à.rl et Cie, SCA, 22-24 Boulevard Royal, L-2449 Luxembourg.
When paying via PayPal, credit card via PayPal, direct debit via PayPal or – if offered
- "Purchase on account" via PayPal, we pass your payment details on to PayPal as part of the payment processing. PayPal reserves the right to carry out a credit check for the payment methods credit card via PayPal, direct debit via PayPal or - if offered - "purchase on account" via PayPal. PayPal uses the result of the credit check in relation to the statistical probability of default for the purpose of deciding on the provision of the respective payment method. The credit report may contain probability values (so-called score values). If score values are included in the result of the credit report, these are based on a scientifically recognized mathematical-statistical procedure. Address data, among other things, is included in the calculation of the score values.
For further information on data protection, including information on the credit agencies used, please refer to PayPal's privacy policy: https://www.paypal.com/de/webapps/mpp/ua/privacy-full .
Shopify
We host our website at Shopify International Limited, Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland. We use Shopify on the basis of processing on our behalf.
When you visit our website, Shopify records your IP address as well as information about the device you are using and your browser. Shopify also analyzes user behavior and creates user statistics. When you make a purchase on our website, your name, email address, delivery and billing addresses, payment details and other data related to the purchase (e.g. telephone number, amount of sales made, etc.) are recorded by Shopify. Shopify stores cookies in your browser for the analysis.
All data collected on our website is processed on Shopify's servers. In the event that data is transferred to Shopify Inc. in Canada, the appropriate level of data protection is guaranteed by the European Commission's adequacy decision. Further information on Shopify's data protection can be found on the following website: https://www.shopify.de/legal/datenschutz
Shopify Payments
We use the payment service provider "Shopify Payments". If you choose a payment method offered by the payment service provider Shopify Payments, payment processing will be carried out by the technical service provider Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland, to whom we pass on the information you provided during the ordering process.
Your data is transmitted to Stripe on the basis of Art. 6 (1) (a) GDPR (consent) and Art. 6 (1) (b) GDPR (processing to fulfill a contract). You have the option of revoking your consent to data processing at any time. A revocation does not affect the effectiveness of data processing operations carried out in the past. All data required for payment processing is used exclusively for the execution of payments and is transmitted via the "SSL" procedure. Stripe is PCI DSS certified.
Stripe may transfer, process and store personal data outside the EU. In this case, Stripe has agreed to EU standard contractual clauses for data transfer outside the EU/EEA, which ensure a level of data protection comparable to the GDPR.
For more information about Shopify Payments’ privacy policy, please visit the following website address: https://www.shopify.com/legal/privacy.
You can find more information about Stripe’s privacy policy at: https://stripe.com/de/privacy .
Social plug-ins
We currently use the following social media plug-ins: Facebook, Tik Tok. Using a button, personal data is transmitted to the respective plug-in provider and stored there.
The respective plug-in provider stores the data collected about you as user profiles and uses them for the purposes of advertising, market research and/or needs-based design of its website. Such an evaluation is carried out in particular (also for users who are not logged in) to display needs-based advertising and to inform other users of the social network about your activities on some of our websites. You have the right to object to the creation of these user profiles; to exercise this right you must contact the respective plug-in provider. We use the plug-ins to offer you the opportunity to interact with social networks and other users so that we can improve our offering and make it more interesting for you as a user. The legal basis for the use of the plug-ins is Art. 6 Paragraph 1 Letter f of GDPR.
The data is passed on regardless of whether you have an account with the plug-in provider and are logged in there. If you are logged in with the plug-in provider, the data we collect from you will be assigned directly to your account with the plug-in provider. For US providers, the data is transferred to the USA;
Further information on the purpose and scope of data collection and processing by the plug-in provider can be found in the privacy policies of these providers provided below. There you will also find further information on your rights in this regard and setting options for protecting your privacy:
- Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2 D02 X525, Ireland
- TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland
https://www.tiktok.com/legal/privacy-policy?lang=de-DE
TikTok
On our TikTok channel, we provide a brief overview of our services and inform you about current promotions. Users' personal data is processed by TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland ("TikTok"). TikTok's privacy policy can be found at:
https://www.tiktok.com/legal/privacy-policy?lang=de-DE
Using TikTok's analytics functions, we can measure the performance of our channel. For this purpose, TikTok provides us with the following information in statistical form: audiences (e.g. characteristics of target groups for the delivery of advertisements such as age, gender and country), interactions (e.g. likes, duration of video playback), referral information (e.g. where users came to the video from), conclusions about individual users and access to individual user profiles by us are not possible.
For more information about TikTok’s analytics features, visit:
https://ads.tiktok.com/marketing_api/docs?rid=bfu8bedbv2c&id=100509
15. Data security and security measures
We are committed to protecting your privacy and treating your personal data confidentially. To this end, we take extensive technical and organizational security precautions, which are regularly reviewed and adapted to technological advances.
This includes, among other things, the use of recognized encryption methods (SSL or TLS). However, data disclosed unencrypted, for example if this is done via unencrypted email, may be read by third parties. We have no influence on this. It is the responsibility of the respective user to protect the data they have made available against misuse by encrypting or in some other way.
16. Changes to the Privacy Policy
We reserve the right to update this statement at any time as necessary.
17. Your rights
Here you will find your rights with regard to your personal data. Details can be found in Articles 7, 15-22 and 77 of the GDPR. You can contact the responsible body in this regard (Section 2).
Right to revoke your consent to data protection in accordance with Art. 7 Para. 3 Clause 1 GDPR
You can revoke your consent to the processing of your personal data at any time with effect for the future. However, this does not affect the legality of the processing carried out up to the time of revocation.
a) Right to information according to Art. 15 GDPR
You have the right to request confirmation as to whether we process personal data concerning you. If this is the case, you have the right to information about this personal data as well as further information, such as the purposes of processing, the categories of personal data processed, the recipients and the planned storage period or the criteria for determining the duration.
b) Right to rectification and completion according to Art. 16 GDPR
You have the right to request the immediate rectification of inaccurate data. Taking into account the purposes of the processing, you have the right to request the completion of incomplete data.
c) Right to erasure (“right to be forgotten”) according to Art. 17 GDPR
You have the right to erasure if processing is not necessary.
This is the case, for example, if your data is no longer necessary for the original purposes, you have revoked your declaration of consent under data protection law or the data has been processed unlawfully.
d) Right to restriction of processing according to Art. 18 GDPR
You have the right to restrict processing, for example if you believe that the personal data is inaccurate.
e) Right to data portability according to Art. 20 GDPR
You have the right to receive the personal data concerning you in a structured, common and machine-readable format.
f) Right of objection according to Art. 21 GDPR
You have the right to object at any time to the processing of certain personal data concerning you for reasons related to your particular situation.
In the case of direct marketing, you as the data subject have the right to object at any time to the processing of personal data concerning you for the purposes of such advertising; this also applies to profiling insofar as it is related to such direct marketing.
g) Automated decision-making in individual cases, including profiling, in accordance with Art. 22 GDPR
You have the right not to be subjected to a decision based solely on automated processing – including profiling – except in the exceptional circumstances mentioned in Art. 22 GDPR.
Decision-making based solely on automated processing – including profiling – does not take place.
h) Complaint to a data protection supervisory authority pursuant to Art. 77 GDPR
You can also lodge a complaint with a data protection supervisory authority at any time, for example if you believe that the data processing is not in accordance with data protection regulations.