Data protection

Privacy policy

1. Data protection – short version

General information

The indications provided here offer a simple overview of how the user’s personal data will be processed when he or she visits our website. Personal data consist of all the data by which it is possible to identify the user. For more information regarding data protection, please read the privacy policy regarding the processing of personal data given here below.

Data collection in the website

Who is the Data Controller within the website?

Personal data processing is supervised by the administrator of this website, whose contact data is provided in the section “Information regarding the Data Controller” of this privacy policy.

How do we collect the user’s personal data?

We collect the data provided by the user him/herself. In this case, these data would be those entered by the user in a contact form, for example.

Other data are collected by our computer systems automatically or when the user, when visiting the website, has given his/her consent to do so. These data consist mainly in technical data (including browser, operating system and time of website visit). The collection of these data is done automatically as soon as the user opens the website.

How do we use user data?

Part of the data are collected to ensure that the website works properly. Other data can be used to analyse how the user uses the website.

Which rights does the user have regarding his/her personal data?

The user has the right to obtain, at any time and for free to obtain information regarding the origin, recipients and purpose of the personal data that have been saved. The user also has the right to ask that such data be corrected or deleted. Should the user have given his/her consent, he/she has the right to revoke the consent at any time, with future effects. In given circumstances, the user also has the right to request  the limitation of the processing of his/her personal data.

The user may also lodge a complaint with the competent Supervisory Authority.

To do this, and for any further information regarding the protection of personal data, please contact our company at any time.

Analysis instruments and third-party tools

Upon visiting our website, the navigation preferences of a user may be subjected to statistical analysis mainly carried out using specific ‘analysis programs’.

For detailed information regarding these programs, please consult the privacy policy given below.

2. Hosting and Content Delivery Networks (CDN)

External host

The web host of this website is an external supplier. The personal data collected via the website are stored on the host’s server. In this case, these data consist of IP addresses, requests for contact, metadata and communication data, contractual data, contact information, names, accesses to the website and other data that can be generated through a website.

We use a web host in order to perform a contract with our potential or acquired clients (art. 6 § 1 lett. b) of the GDPR) and for the purposes of our legitimate interests in providing a safe, fast and efficient online presence run by a qualified supplier (art. 6 § 1 lett. f) of the GDPR).

The web host processes the user’s personal data only to the extent required to accomplish its obligations as a supplier, following the instructions we provide regarding the data in question.

Our company utilises the following web host:
COM.POSiTUM Multimediaagentur, Fulda

 

3. General information and mandatory information

Data protection

The administrators of this website truly care about protecting the user’s personal data. We process the user’s personal data with the utmost confidentiality, pursuant to the regulations in force regarding data protection and of this privacy policy.

When a user visits a website, the website collects the user’s personal data. These consist of data with which it is possible to identify the user. This privacy policy explains which data are collected and the purpose of their use, as well as how and why they are processed.

Please be advised, in this context, that the transmission of data over the Internet (via e-mail, for example) is not always safe; for this reason, it is impossible to guarantee total protection against access to the data by unauthorised third parties.

Information regarding the Data Controller

The Data Controller on this website is:

Friedrich Krumme GmbH

Kleine Industriestraße 13

36251 Bad Hersfeld

Phone: (+49) 06621-959990

E-mail: info@krumme-gmbh.de

The data controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data (including names, e-mail addresses, etc.).

Storage period

Unless otherwise specified in this policy, the user’s personal data shall be stored with the company until the purpose of processing comes to an end. Should the user legitimately request the erasure of the data or withdraw consent for processing, the user’s personal data will be eliminated, unless there are other legal grounds for prolonging their storage (e.g.: storage terms for fiscal or commercial purposes); in this case erasure will occur once such legal reasons cease.

Withdrawal of consent to process data

Many data processing procedures are allowed only after the user expresses consent; such consent can be withdrawn at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

Right to object to the collection of personal data in special circumstances and to direct marketing (art. 21 of the GDPR)

WHERE PERSONAL DATA ARE PROCESSED PURSUANT TO ART. 6 §1 LETT. E) OR F) OF THE GDPR, THE USER SHALL HAVE THE RIGHT TO OBJECT AT ANY TIME TO PROCESSING OF PERSONAL DATA ON GROUNDS RELATING TO HIS OR HER PARTICULAR SITUATION, INCLUDING PROFILING BASED ON THESE PROVISIONS. THE LEGAL BASIS FOR PROCESSING WILL BE SPECIFICED IN THIS INFORMATION NOTICE EACH TIME. SHOULD THE USER OBJECT, OUR COMPANY WILL STOP PROCESSING HIS OR HER DATA UNLESS THERE ARE LEGITIMATE GROUNDS AND PROVEN REASONS FOR CONTINUING PROCESSING THAT OVERRIDE HIS OR HER INTERESTS, RIGHTS AND FREEDOM, OR FOR THE ESTABLISHMENT, EXERCISE OR DEFENCE OF LEGAL CLAIMS (RIGHT TO OBJECT, ART. 21 § 1 OF THE GDPR).

WHERE PERSONAL DATA ARE PROCESSED FOR DIRECT MARKETING PURPOSES, THE USER SHALL HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF HIS OR HER PERSONAL DATA FOR THIS PURPOSE, WHICH INCLUDES PROFILING TO THE EXTENT THAT IT IS RELATED TO SUCH DIRECT MARKETING. SHOULD THE USER OBJECT, OUR COMPANY WILL STOP PROCESSING HIS OR HER DATA FOR THIS PURPOSE (OBJECTIONS, AS PER ART. 21 § 2 OF THE GDPR).

Right to lodge a complaint with the Supervisory Authority of competence

In the event of infringement of the GDPR, the user has the right to lodge a complaint with a supervisory authority, especially in the Member State of his or her habitual residence, place of work or place of the alleged infringement. The right to lodge a complaint exists without prejudice to any other administrative or judicial remedy.

Right to data portability

The user has the right to receive the personal data we have processed based on his or her given consent or for contract performance purposes in a commonly used and machine-readable format. Should the user request it, the direct transmission  of the data to another controller shall be carried out only if technically feasible.

SSL or TLS cryptography

For security reasons and in order to protect the transmission of confidential content, including orders and queries sent by the user to our company in its capacity as website administrator, this website uses SSL or TLS cryptography. Encrypted connection is indicated by the lock icon shown in the top bar when the browser goes from “http://” to ”https://”.

Once the SSL or TLS cryptography function is activated, the data we send cannot be read by third parties.

Information, erasure or rectification

Pursuant to the provisions of the laws in this regard, the user has the right at any time to receive free information regarding his or her own personal data stored, on the origins and on the recipients of such data, and may also request the rectification or erasure of such data. For any further information regarding the protection of personal data, please contact our company at any time.

Right to restriction of processing

In specific circumstances, the user has the right to ask for the restriction of processing of his or her personal data. To this end, the user may contact our company at any time. The right to restriction of processing is feasible in the following cases:

- should the user contest the accuracy of the personal data we have in storage; in this case, their verification takes time. For the entire duration of the verification, the user has the right to request the restriction of processing of his or her personal data;

- should the processing of the personal data have been or is being carried out unlawfully, in place of their erasure the user may request restriction of the processing of such data;

- when the company no longer needs the personal data of the user but the user still requires to use them for the establishment, exercise or defence of legal claims, the user has the right to request, in place of their erasure, the restriction of processing of such personal data;

- when the user has objected pursuant to Art. 21 §1 of the GDPR, the ponderation of whether the user’s interests override our company’s must be made. Pending this, the user has the right to ask for the restriction of processing of his or her personal data.

- when the user has restricted processing of his or her personal data, such personal data shall, with the exception of storage, only be processed with the user’s consent or for the establishment, exercise or defence of legal claims, for the protection of the rights of another natural or legal person or for reasons of public interest of the European Union or of a Member State.

Objection to the sending of advertising notifications via e-mail

Please be advised that we object to the use of company addresses, published in compliance with the obligation of legal notice, for the purpose of sending our company unsolicited advertising and information material. Should we receive unsolicited information, for example via spamming, the website’s administrators expressly reserve the right to take legal action.

 

4. Data collection within the website

Cookies

Our website uses cookies, i.e. small text files  that do not damage the user’s device. Cookies are stored on the user’s device only for the duration of a navigation session (session cookies) or permanently (permanent cookies). Session cookies are deleted automatically once the session ends, while permanent cookies remain stored in the user’s device until they are removed by the user or erased automatically by the browser.

When the user starts navigating the website, another type of cookie that could be stored on his/her computer are third-party cookies that allow the user or our company to use services supplied by third parties (e.g.:  cookies for handling payment services).

Cookies have many functions. Many of them are technically necessary for allowing the use of specific functions that would otherwise be unavailable (including the shopping basket or video viewing functions). Other cookies are used to collect information regarding the user’s navigation behaviour or to display advertisements.

The cookies necessary for the electronic communication procedure (necessary cookies) or for the supply of specific functions requested by the user (functional cookies – for using the shopping basket, for example) or for improving navigation of the website (cookies collecting info about visits to the website by the public), are saved pursuant to Art. 6 §1 lett. f) of the GDPR, unless a different legal basis is specified. It is the website administrator’s legitimate interest to save cookies so as to provide better and technically impeccable services. Should the consent for the storage of cookies be requested, such storage will be performed only based on the user’s consent (art. 6 §1 lett. a) of the GDPR); consent may be withdrawn at any time.

The user can use the browser settings in order to be informed each time about cookie storage, to enable only certain cookies, to accept cookies only in specific cases or to exclude them a priori, and to enable the automatic elimination of cookies whenever the browser closes. Should the cookies be disabled, however, website functions may prove to be limited.

When third company or analytic cookies are used, the user will receive information pursuant to the provisions of this privacy policy together with the request for user consent, where required.

Server log files

The website provider automatically collects and stores information in files called server log files that the user’s browser automatically transmits to the website. The information transmitted is the following:

- browser type and version, operating system, referrer’s URL;

- hostname of the accessing computer;

- time of requests to server;

- IP address.

These data are not combined with data from other sources.

Data collection occurs according to the provisions of Art. 6 §1 lett. f) of the GDPR. It is the website administrator’s legitimate interest to provide better and technically impeccable web pages. To this end, the analysis of the server log file is necessary.

Contact form

Should the user contact us using the specific contact form, the relating data, including the contact data provided, will be stored so as to meet the request and engage in any subsequent communication regarding the request. Such data are transmitted only with the consent of the user.

Data processing is carried out in accordance with Art. 6 §1 lett. b) of the GDPR, to the extent that the user’s request is related to the performance of a contract or necessary for preparation for entering into a contract. In all other cases, the legal basis of processing is our legitimate interest in providing the efficient execution of the requests arriving to our company (Art. 6 §1 lett. f) of the GDPR) or the consent given by the user (Art. 6 §1 lett. a) of the GDPR) following the request.

The data entered by the user in the contact form will be stored by the company until it receives the user’s request for erasure, until consent for processing is withdrawn or when the purpose for which they were stored no longer subsists (e.g.: when the request is fulfilled), without prejudice to the provisions of any pertinent laws and especially to any storage terms or periods contemplated therein.

Requests by e-mail, phone or telefax

Should the user contact us by e-mail, phone or fax, the request will be stored and processed by the company with the relating personal data (name, request) for the purpose of its execution. Such data are transmitted only with the user’s consent.

Data processing is performed based on Art. 6 §1 lett. b) of the GDPR, to the extent that the user’s request is related to the performance of a contract or necessary for preparation for entering into a contract. In all other cases, the legal basis of processing is our legitimate interest in providing the efficient execution of the requests arriving to our company (Art. 6 §1 lett. f) of the GDPR) or the consent given by the user (Art. 6 §1 lett. a) of the GDPR) following the request.

The data entered by the user in the contact form will be stored by the company until it receives the user’s request for erasure, until consent for processing is withdrawn or when the purpose for which they were stored no longer subsists (e.g.: when the request is fulfilled), without prejudice to the provisions of any pertinent laws and especially to any storage terms or periods contemplated therein.

5. Newsletter

Data for the newsletter

Should the user intend to subscribe to the newsletter proposed in the website, in addition to the e-mail address he/she will be requested to provide information that allows to check the user’s actual ownership of the e-mail address and for obtaining the consent to us sending the newsletter.  In this context, no other data are collected or only on a voluntary basis, if any. We use these data only for the purpose of delivering the information requested, and such data are not transmitted to third parties.

Processing of the data entered in the newsletter subscription form occurs solely with the prior consent given by the user (Art. 6 §1 lett, a) of the GDPR). The user has the right to withdraw at any time the consent he/she has given for the storage of data, of the e-mail address and for their use in sending the newsletter, also via the dedicated ‘unsubscribe’ link provided in the newsletter itself. The withdrawal does not affect the lawfulness of the processing performed up to that time.

The data provided by the user for the purpose of receiving the newsletter are filed with the company or by the newsletter service operator; following unsubscription from the newsletter or once the purpose for storage has ceased, the data shall be deleted from the mailing list. We reserve the right to eliminate or block the mailing list addresses, at our discretion and based on our legitimate interests as per Art. 6 §1 lett. f) of the GDPR.

Once removed from the mailing list, the user’s e-mail address filed with the company or with the newsletter service operator will be placed in a black list so as to avoid future sending. The black list data are used only for the purpose described and are not associated with any other data in our possession. This is in our own interest as well as that of the user in compliance with the provisions of the law regarding the sending of newsletters (legitimate interest as per Art. 6 §1 lett. f) of the GDPR). The period of time of storage in the black list is undefined. The user has the right to object to such data storage should his or her interests override our legitimate interest in storing them.

Source: e-recht24.de