We appreciate your interest in Thea – Hair Shaping Technology. Please note that Thea is a registered trademark of Asclepion Laser Technologies; the website thea-hairshapingtechnology.com is wholly owned by Asclepion Laser Technologies, and the company is responsible for all matters regarding intellectual property, text content, images, videos, and the collection and use of data during site navigation. Data protection is a top priority for the management of Asclepion Laser Technologies, the owner of the Thea brand. You may use the thea-hairshapingtechnology.com website without providing personal data; however, if a user wishes to access specific company services via our website, the processing of personal data may be required. If the processing of personal data is necessary and there is no legal basis for such processing, we generally obtain the consent of the data subject.
The processing of personal data—such as the name, address, e-mail address, or telephone number of a data subject—is always carried out in accordance with the General Data Protection Regulation (GDPR) and the national data protection regulations applicable to Asclepion Laser Technologies. With this privacy policy, our company wishes to inform the public about the nature, scope, and purposes of the personal data we collect, use, and process. Furthermore, this privacy policy informs data subjects of the rights to which they are entitled.
As the data controller, Asclepion Laser Technologies has implemented numerous technical and organizational measures to ensure the most comprehensive protection possible for personal data processed via this website. However, data transmissions over the Internet can, in principle, have security gaps; therefore, absolute protection cannot be guaranteed.
For this reason, any interested party is free to transmit their personal data to us via alternative means, for example by telephone.
Asclepion Laser Technologies’ data protection declaration is based on the terms used by the European legislator for the adoption of the General Data Protection Regulation (GDPR). Our data protection declaration is intended to be readable and understandable for the general public, as well as for our customers and business partners. To ensure this, we would first like to explain the terminology used.
In this data protection statement, we use, among others, the following terms:
PERSONAL DATA
“Personal data” means any information relating to an identified or identifiable natural person (“data subject”). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
INTERESTED
“Data subject” means any identified or identifiable natural person whose personal data are processed by the data controller.
PROCESSING
“Processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
RESTRICTION OF PROCESSING
The restriction of processing consists of marking stored personal data with the aim of limiting their processing in the future.
PROFILING
“Profiling” means any form of automated processing of personal data consisting of the use of such data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements.
PSEUDONYMIZATION
Pseudonymisation is the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person.
DATA CONTROLLER OR DATA PROCESSOR
The controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.
PROCESSOR
The processor is the natural or legal person, public authority, agency, or other body which processes personal data on behalf of the controller.
RECIPIENT
A recipient is a natural or legal person, public authority, agency, or other body to which the personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law are not regarded as recipients; the processing of such data by those public authorities must be in compliance with the applicable data protection rules according to the purposes of the processing.
PART THREE
“Third party” means a natural or legal person, public authority, agency, or body other than the data subject, the controller, the processor, and persons who, under the direct authority of the controller or the processor, are authorized to process personal data.
CONSENT
The data subject’s consent is any freely given, specific, informed, and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.
The data controller within the meaning of the General Data Protection Regulation (GDPR), other data protection laws applicable in the Member States of the European Union, and other provisions related to data protection is:
Asclepion Laser Technologies GmbH
Brüsseler Str. 10
07747 Jena, Germania
Phone number: +49 (0) 3641 7700 100
E-mail: info@asclepion.com
Website: www.asclepion.com
The Data Protection Officer can be contacted at the following details:
Phone: +49 (0) 3641 7700 252
E-mail: datenschutzbeauftragter@asclepion.com
The thea-hairshapingtechnology.com website uses cookies. Cookies are text files that are stored on a computer system via an Internet browser.
Many websites and Internet servers use cookies. Many cookies contain a so-called cookie ID. A cookie ID is a unique identifier for the cookie. It consists of a string of characters that allows websites and Internet servers to be associated with the specific Internet browser in which the cookie was stored.
This allows the visited websites and servers to distinguish the user’s individual browser from other internet browsers containing different cookies. A specific internet browser can be recognized and identified using the unique cookie ID. Through the use of cookies, thea-hairshapingtechnology.com can provide users of this website with more intuitive and user-friendly services—something that would not be possible without the use of cookies.
Thanks to cookies, the information and offers on our website can be optimized to suit the user’s needs. As previously mentioned, cookies allow us to recognize users of our site. The purpose of this recognition is to make navigating the site easier. For instance, a user does not need to enter login details every time they visit the site, as these are stored by the site itself and the cookie is saved on the user’s computer. Another example is the shopping cart cookie used in online stores; the store uses a cookie to remember the items a customer has placed in their virtual shopping cart.
The data subject may, at any time, prevent the setting of cookies through our website by means of a corresponding setting in the Internet browser used, thereby permanently denying the setting of cookies. Furthermore, cookies that have already been set may be deleted at any time via the Internet browser or other software programs. This is possible with all common Internet browsers. If the data subject deactivates the setting of cookies in the Internet browser used, not all functions of our website may be fully usable.
The thea-hairshapingtechnology.com website collects a series of general data and information when a data subject or an automated system accesses the site. This general data and information is stored in server log files. The following may be collected: (1) the browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which the accessing system reaches our website (so-called referrers), (4) the web pages visited, (5) the date and time of access to the website, (6) an Internet Protocol address (IP address), (7) the Internet service provider of the accessing system, and (8) any other similar data and information that may be used in the event of attacks on our information technology systems.
When using this data and general information, Asclepion Laser Technologies draws no conclusions regarding the data subject.
Rather, this information is necessary to (1) correctly deliver our website content, (2) optimize our website content and related advertising, (3) ensure the long-term viability of our IT systems and website technology, and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyberattack.
Therefore, thea-hairshapingtechnology.com uses data and information collected in anonymous form for statistical purposes, with the aim of enhancing our company’s data protection and security and ensuring an optimal level of protection for the personal data we process. Anonymous server log file data is stored separately from any personal data provided by the data subject.
The data subject may register on the data controller’s website by providing their personal data. The personal data transmitted to the data controller are determined by the registration form used. The personal data entered by the data subject are collected and stored exclusively for the data controller’s internal use and purposes. The data controller may arrange for the transfer of data to one or more data processors (such as a courier) who also use the personal data for an internal purpose attributable to the data controller.
When registering on the data controller’s website, the IP address assigned by the Internet Service Provider (ISP) and used by the data subject, along with the date and time of registration, are stored. This data is stored based on the conviction that it is the only way to prevent the misuse of our services and, if necessary, to enable the investigation of any crimes committed. In this regard, the storage of this data is necessary for the security of the data controller. This data is not disclosed to third parties, except where required by law or for the purpose of criminal prosecution.
Registration by the data subject, involving the voluntary provision of personal data, is intended to enable the data controller to offer the data subject content or services that, by their nature, are available only to registered users. Registered users are free to modify the personal data provided during registration at any time or to request their complete deletion from the data controller’s records.
The data controller shall, upon request, provide each data subject with information regarding the personal data concerning them that is being stored. Furthermore, the data controller shall rectify or erase personal data at the request or upon the instruction of the data subject, unless there are statutory retention obligations.
In this regard, the data subject may contact the Data Protection Officer specifically designated in this privacy policy, as well as any employees of the Data Controller.
On the thea-hairshapingtechnology.com website, users have the option to subscribe to the company newsletter. The subscription form used for this purpose determines which personal data are transmitted and when the newsletter subscription is requested from the data controller.
thea-hairshapingtechnology.com regularly informs its customers and business partners about company offers via a newsletter. The newsletter can be received by the data subject only if (1) they possess a valid e-mail address and (2) they subscribe to the newsletter service.
This confirmation email serves to verify that the holder of the email address—as the data subject—is authorized to receive the newsletter.
When registering for the newsletter, we also store the IP address of the computer system assigned by the Internet Service Provider (ISP) and used by the data subject at the time of registration, as well as the date and time of registration. Collecting this data is necessary to identify any potential future misuse of the data subject’s email address and thus serves to provide legal protection for the data controller.
Personal data collected upon subscription to the newsletter will be used exclusively for sending the newsletter itself. Furthermore, subscribers may be notified via email if necessary for the operation of the newsletter service or the subscription itself—for example, in the event of changes to the newsletter offering or technical updates. Personal data collected through the newsletter service will not be shared with third parties. Subscribers may cancel their subscription at any time.
Consent to the processing of personal data, provided by the data subject for the purpose of receiving the newsletter, may be withdrawn at any time. To this end, each newsletter contains a specific link for withdrawing consent. It is also possible to unsubscribe from the newsletter at any time directly via the data controller’s website or by notifying the data controller through other means.
The Asclepion Laser Technologies newsletter contains so-called tracking pixels. A tracking pixel is a small graphic image embedded in emails sent in HTML format, enabling the recording and analysis of log files. This allows for a statistical analysis of the success or failure of online marketing campaigns. Thanks to the embedded tracking pixel, Asclepion Laser Technologies can determine whether and when an email was opened by a user and which links within the email were clicked.
Personal data collected via tracking pixels contained in the newsletters are stored and analyzed by the data controller in order to optimize newsletter delivery and further tailor the content of future newsletters to the data subject’s interests. Such personal data will not be disclosed to third parties.
Data subjects have the right to withdraw the consent previously given via the double opt-in procedure at any time. Following such withdrawal, the personal data will be deleted by the data controller. Asclepion Laser Technologies automatically treats unsubscribing from the newsletter as a withdrawal of consent.
The thea-hairshapingtechnology.com website contains information that enables rapid electronic contact with our company, as well as direct communication with us, including a general email address.
If a data subject contacts the data controller via email or a contact form, the personal data transmitted by the data subject are automatically stored. Such personal data, voluntarily transmitted by the data subject to the data controller, are retained for the purpose of processing the request or contacting the data subject.
No transfer of such personal data to third parties is envisaged.
The data controller processes and stores the data subject’s personal data only for the period necessary to achieve the purpose for which they were collected, or to the extent permitted by the European legislator or other legislators in laws or regulations to which the data controller is subject.
Where the purpose of retention is no longer applicable, or where the retention period prescribed by European legislators or other competent authorities expires, personal data are generally blocked or deleted in accordance with legal requirements.
RIGHT OF CONFIRMATION
Each data subject has the right, granted by the European legislator, to obtain from the controller confirmation as to whether or not personal data concerning them are being processed. If a data subject wishes to exercise this right of confirmation, they may contact our Data Protection Officer or another employee of the controller at any time.
RIGHT OF ACCESS
Each data subject has the right, recognized by the European legislator, to obtain from the data controller, at any time, free information regarding the personal data concerning them and a copy of such information.
Furthermore, European directives and regulations guarantee the data subject access to the following information:
> the purposes of the processing;
> the categories of personal data concerned;
> the recipients or categories of recipients to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organisations;
> where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period;
> the right to request from the controller rectification or erasure of personal data or restriction of processing concerning the data subject, or to object to such processing;
> the existence of the right to lodge a complaint with a supervisory authority;
> where personal data are not collected from the data subject, any available information as to their source;
> the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4) of the GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.
RIGHT TO RECTIFICATION
Each data subject has the right, recognized by the European legislator, to obtain from the controller, without undue delay, the rectification of inaccurate personal data concerning them.
Taking into account the purposes of the processing, the data subject has the right to have incomplete personal data completed, including by means of providing a supplementary statement.
Should a data subject wish to exercise the right to rectification, they may contact our Data Protection Officer or another employee of the data controller at any time.
RIGHT OF CANCELLATION
Each data subject has the right, recognized by the European legislator, to obtain from the controller the erasure of personal data concerning them without undue delay, and the controller has the obligation to erase personal data without undue delay where one of the following grounds applies, provided that the processing is not necessary:
> The personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed.
> The data subject withdraws the consent on which the processing is based pursuant to Article 6(1)(a) or Article 9(2)(a) of the GDPR, and where there is no other legal ground for the processing.
> The data subject objects to the processing pursuant to Article 21(1) of the GDPR and there are no overriding legitimate grounds for the processing, or the data subject objects to the processing pursuant to Article 21(2) of the GDPR.
> The personal data have been processed unlawfully.
> Personal data must be erased to comply with a legal obligation under Union or Member State law to which the controller is subject.
> The personal data have been collected in relation to the offer of information society services referred to in Article 8, paragraph 1, of the GDPR.
Should any of the aforementioned circumstances arise and a data subject wish to request the erasure of personal data held by Asclepion Laser Technologies, they may contact our Data Protection Officer or another employee of the data controller at any time.
The Data Protection Officer of Asclepion Laser Technologies or another employee will promptly fulfill the request for deletion.
Where the controller has made personal data public and is obliged pursuant to Article 17(1) to erase the personal data, the controller, taking account of available technology and the cost of implementation, shall take reasonable steps, including technical measures, to inform other controllers which are processing the personal data that the data subject has requested the erasure by such controllers of any links to, or copy or replication of, those personal data, insofar as processing is not necessary. The Data Protection Officer of Asclepion Laser Technologies or another employee will take the necessary measures on a case-by-case basis.
Right to restriction of processing
Each data subject has the right, recognized by the European legislator, to obtain from the controller the restriction of processing when one of the following conditions applies:
> The accuracy of the personal data is contested by the data subject, for a period enabling the controller to verify the accuracy.
> The processing is unlawful and the data subject opposes the erasure of the personal data, requesting instead the restriction of their use.
> The controller no longer needs the personal data for the purposes of the processing, but the data are required by the data subject for the establishment, exercise, or defense of legal claims.
> The data subject has objected to the processing pursuant to Article 21(1) of the GDPR, pending verification as to whether the legitimate grounds of the controller override those of the data subject.
Right to data portability
> Each data subject has the right, recognized by the European legislator, to receive the personal data concerning them—which they have provided to a data controller—in a structured, commonly used, and machine-readable format. They also have the right to transmit such data to another data controller without hindrance from the controller to whom the personal data were provided, provided that the processing is based on consent pursuant to Article 6(1)(a) or Article 9(2)(a) of the GDPR, or on a contract pursuant to Article 6(1)(b) of the GDPR, and that the processing is carried out by automated means, provided that the processing is not necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the data controller.
Furthermore, in exercising their right to data portability pursuant to Article 20(1) of the GDPR, the data subject has the right to have personal data transmitted directly from one controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.
To exercise the right to data portability, the data subject may at any time contact the Data Protection Officer designated by Asclepion Laser Technologies or another employee.
RIGHT TO OBJECT
Each data subject has the right, recognized by the European legislator, to object at any time, on grounds relating to their particular situation, to the processing of personal data concerning them based on Article 6(1)(e) or (f) of the GDPR. This also applies to profiling based on those provisions.
In the event of an objection, Asclepion Laser Technologies will no longer process the personal data, unless it can demonstrate compelling legitimate grounds for the processing that override the interests, rights, and freedoms of the data subject, or for the establishment, exercise, or defense of legal claims.
Where Asclepion Laser Technologies processes personal data for direct marketing purposes, the data subject has the right to object at any time to the processing of personal data concerning them for such purposes. This also applies to profiling to the extent that it is related to such direct marketing. If the data subject objects to processing by Asclepion Laser Technologies for direct marketing purposes, Asclepion Laser Technologies will no longer process the personal data for such purposes.
Furthermore, the data subject has the right, on grounds relating to their particular situation, to object to the processing of personal data concerning them by Asclepion Laser Technologies for scientific or historical research purposes or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the processing is necessary for the performance of a task carried out for reasons of public interest.
To exercise the right to object, the data subject may contact Asclepion Laser Technologies’ Data Protection Officer or another employee directly. Furthermore, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, the data subject is free to exercise their right to object by automated means using technical specifications.
Automated individual decision-making, including profiling
> Every data subject has the right, recognized by the European legislator, not to be subject to a decision based solely on automated processing—including profiling—which produces legal effects concerning them or similarly significantly affects them, provided that such decision (1) is not necessary for entering into, or the performance of, a contract between the data subject and the data controller, or (2) is not authorized by Union or Member State law to which the data controller is subject and which also lays down suitable measures to safeguard the data subject’s rights, freedoms, and legitimate interests, or (3) is not based on the data subject’s explicit consent.
If the decision (1) is necessary for entering into, or the performance of, a contract between the data subject and the controller, or (2) is based on the data subject’s explicit consent, Asclepion Laser Technologies shall implement suitable measures to safeguard the data subject’s rights, freedoms, and legitimate interests, at least the right to obtain human intervention on the part of the controller, to express their point of view, and to contest the decision.
Should the data subject wish to exercise rights relating to automated decision-making, they may at any time directly contact the Data Protection Officer of Asclepion Laser Technologies or another employee of the data controller.
Right to withdraw consent to data processing
Each data subject has the right, recognized by the European legislator, to withdraw their consent to the processing of personal data at any time.
If the data subject wishes to exercise the right to withdraw consent, they may at any time directly contact our Data Protection Officer at Asclepion Laser Technologies or another employee of the data controller.
The data controller collects and processes candidates’ personal data for the purpose of managing the selection process. Processing may also be carried out electronically. This occurs, in particular, when a candidate submits application documents via email or through an online form on the data controller’s website.
Should the data controller enter into an employment contract with a candidate, the data provided will be retained for the purpose of managing the employment relationship, in compliance with legal obligations. If the data controller does not enter into an employment contract with the candidate, the application documentation will be automatically deleted two months after the notification of rejection, unless there are other legitimate interests of the data controller that preclude such deletion.
Another legitimate interest in this regard is, for example, the burden of proof in proceedings under equal treatment legislation (General Equal Treatment Act).
On this website, the data controller has integrated components from Facebook. Facebook is a social network. A social network is a social meeting place on the Internet—an online community that typically allows users to communicate with one another and interact within a virtual space. A social network can serve as a platform for exchanging opinions and experiences or enable the online community to share personal or professional information. Facebook, for instance, allows users to create private profiles, upload photos, and interact via friend requests.
Facebook’s operating company is Facebook, Inc., 1 Hacker Way, Menlo Park, CA 94025, United States. If a person resides outside the United States or Canada, the data controller is Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.
Each time a user accesses one of the individual pages of this website—which is managed by the data controller and incorporates a Facebook component (Facebook plug-in)—the web browser on the data subject’s computer system is automatically prompted to download and display the corresponding Facebook component. A list of all Facebook plug-ins is available at https://developers.facebook.com/docs/plugins/. During this technical process, Facebook is informed of the specific sub-page of our website that the data subject has visited.
If the data subject is simultaneously logged into Facebook, Facebook detects—each time the data subject accesses our website and for the entire duration of their visit—which specific sub-page of our site has been visited. This information is collected via the Facebook component and associated with the data subject’s respective Facebook account. If the data subject clicks on one of the Facebook buttons integrated into our website—such as the “Like” button—or submits a comment, Facebook associates this information with the data subject’s personal Facebook user account and stores the personal data.
Facebook always receives information about the user’s visit to our website via the Facebook component if the user is simultaneously logged into Facebook while visiting our site. This occurs regardless of whether or not the user clicks on the Facebook component. If the user does not wish for this information to be transmitted to Facebook, they can prevent it by logging out of their Facebook account before accessing our website.
The privacy policy published by Facebook, available at https://facebook.com/about/privacy/, provides information regarding Facebook’s collection, processing, and use of personal data. It also outlines the settings options offered by Facebook to protect the user’s privacy. Various configuration options are available to prevent the transmission of data to Facebook; users can utilize these options to block such data transmission.
The controller has integrated the Google Analytics component (with the anonymization function) into this website. Google Analytics is a web analytics service. Web analytics involves the collection and analysis of data regarding the behavior of website visitors. A web analytics service collects data such as the website from which a user arrived (the so-called referrer), the subpages visited, and the frequency and duration of views for each subpage. Web analytics is primarily used to optimize a website and to conduct cost-benefit analyses of online advertising.
The operator of the Google Analytics component is Google Inc., 1600 Amphitheatre Pkwy, Mountain View, CA 94043-1351, United States. For web analysis using Google Analytics, the data controller employs the “_gat._anonymizeIp” application. Through this application, the IP address of the data subject’s internet connection is truncated and anonymized by Google when accessing our websites from a European Union Member State or another contracting state to the Agreement on the European Economic Area.
The purpose of the Google Analytics component is to analyze traffic on our website. Google uses the data and information collected to, among other things, evaluate the use of our website and provide online reports showing activity on our website, as well as to provide us with other services related to the use of our website.
Google Analytics places a cookie on the data subject’s computer system. The definition of a cookie is provided above. Through the placement of this cookie, Google is able to analyze the use of our website. Each time an individual page of this website—which is operated by the data controller and incorporates a Google Analytics component—is accessed, the internet browser on the data subject’s computer system automatically transmits data to Google via the Google Analytics component for the purposes of online advertising and commission calculation. During this technical process, Google obtains personal information, such as the data subject’s IP address; Google uses this information to, among other things, understand the origin of visitors and clicks and, subsequently, to calculate commissions.
The cookie is used to store personal information, such as the time of access, the location from which access was made, and the frequency of the data subject’s visits to our website. Each time our website is visited, this personal data—including the IP address of the internet connection used by the data subject—is transmitted to Google in the United States of America. This personal data is stored by Google in the United States of America. Google may transmit the personal data collected through this technical process to third parties.
As previously indicated, the data subject may at any time prevent the setting of cookies through our website by adjusting the settings of the browser used, thereby permanently denying the setting of cookies. Such a browser setting would also prevent Google Analytics from setting a cookie on the data subject’s information technology system. Furthermore, cookies already set by Google Analytics may be deleted at any time via the browser or other software programs.
Furthermore, the data subject has the option to object to the collection of data generated by Google Analytics regarding the use of this website, as well as to the processing of such data by Google, and to prevent it.
To this end, the data subject must download and install a browser add-on via the link https://tools.google.com/dlpage/gaoptout. This add-on informs Google Analytics, via JavaScript, that data and information regarding visits to web pages must not be transmitted to Google Analytics. Google considers the installation of the browser add-on to be an objection to the processing of data.
Should the data subject’s computer system subsequently be wiped, formatted, or reinstalled, the data subject must reinstall the browser add-on to disable Google Analytics. If the add-on has been uninstalled or disabled by the data subject or by anyone acting on their behalf, it can be reinstalled or reactivated.
Further information and applicable Google data protection provisions can be found at the following addresses: https://www.google.com/intl/en/policies/privacy/ and http://www.google.com/analytics/terms/us.html . Google Analytics is further explained at the following link: https://www.google.com/analytics/ .
The data controller has integrated Google AdWords into this website. Google AdWords is an online advertising service that allows advertisers to place ads within Google search engine results and the Google advertising network. Google AdWords enables advertisers to pre-define specific keywords so that an ad appears in Google search results only when a user employs the search engine to find results relevant to those keywords. Within the Google advertising network, ads are distributed across relevant web pages via an automated algorithm, taking into account the previously defined keywords.
The company that manages Google AdWords is Google Inc., 1600 Amphitheatre Pkwy, Mountain View, CA 94043-1351, United States.
The purpose of Google AdWords is to promote our website by placing relevant advertisements on third-party websites and in Google search engine results, as well as by displaying third-party advertisements on our website.
If a user reaches our website via a Google ad, Google stores a conversion cookie on the user’s computer system. The definition of a cookie has been explained previously. A conversion cookie expires after 30 days and is not used to identify the user. If the cookie has not expired, it is used to determine whether specific sub-pages of our website—such as an online store’s shopping cart—have been viewed. Through the conversion cookie, both Google and the data controller can determine whether a person who arrived at our website via an AdWords ad has generated a sale—that is, completed or cancelled a purchase.
The data and information collected via the conversion cookie are used by Google to generate statistics on visits to our website. These statistics serve to determine the total number of users who viewed the AdWords ads, to evaluate the success or failure of each ad, and to optimize our AdWords ads for the future. Neither our company nor other Google AdWords advertisers receive information from Google that could identify the data subject.
The conversion cookie stores personal information, such as the web pages visited by the data subject. Each time our web pages are visited, personal data—including the IP address of the internet connection used by the data subject—are transmitted to Google in the United States of America. This personal data is stored by Google in the United States of America. Google may transmit the personal data collected through this technical process to third parties.
The data subject may, at any time, prevent the installation of cookies by our website—as previously indicated—by adjusting the settings of the internet browser used, thereby permanently denying the installation of cookies. Such a setting on the internet browser would also prevent Google from placing a conversion cookie on the data subject’s computer system. Furthermore, a cookie set by Google AdWords can be deleted at any time via the internet browser or other software programs.
The data subject has the option to object to Google’s interest-based advertising. To do so, the data subject must access the link www.google.de/settings/ads from each browser being used and set their desired preferences.
Further information and applicable provisions regarding Google’s data protection can be found at https://www.google.com/intl/en/policies/privacy/ .
The data controller has integrated components from LinkedIn Corporation into this website. LinkedIn is a web-based social network that allows users with existing professional contacts to connect and establish new ones. More than 400 million registered users across over 200 countries use LinkedIn. Consequently, LinkedIn is currently the largest platform for professional contacts and one of the most visited websites in the world.
LinkedIn’s operating company is LinkedIn Corporation, located at 2029 Stierlin Court, Mountain View, CA 94043, United States. For privacy-related matters outside the United States, responsibility lies with LinkedIn Ireland, Privacy Policy Issues, Wilton Plaza, Wilton Place, Dublin 2, Ireland.
Each time a user accesses one of the individual pages of this website—which is managed by the data controller and incorporates a LinkedIn component (LinkedIn plug-in)—the internet browser on the data subject’s computer system is automatically prompted to download a display of the corresponding LinkedIn component. Further information regarding the LinkedIn plug-in is available at https://developer.linkedin.com/plugins. Through this technical process, LinkedIn becomes aware of which specific sub-page of our website the data subject has visited.
If the data subject is simultaneously logged into LinkedIn, LinkedIn detects—each time the data subject accesses our website and for the entire duration of their visit—which specific sub-page of our website has been visited. This information is collected via the LinkedIn component and associated with the data subject’s respective LinkedIn account. If the data subject clicks on one of the LinkedIn buttons integrated into our website, LinkedIn associates this information with the data subject’s personal LinkedIn user profile and stores the personal data.
LinkedIn receives information about the user’s visit to our website via the LinkedIn component, provided the user is logged into LinkedIn at the time of the visit. This occurs regardless of whether or not the user clicks the LinkedIn button. If the user does not wish for this information to be transmitted to LinkedIn, they can prevent this by logging out of their LinkedIn account before visiting our website.
LinkedIn offers the option to opt out of emails, SMS messages, and targeted ads, as well as to manage ad settings, via the page https://www.linkedin.com/psettings/guest-controls. LinkedIn also works with partners such as Eire, Google Analytics, BlueKai, DoubleClick, Nielsen, Comscore, Eloqua, and Lotame. You can opt out of the placement of these cookies via the page https://www.linkedin.com/legal/cookie-policy. LinkedIn’s privacy policy is available at https://www.linkedin.com/legal/privacy-policy. LinkedIn’s cookie policy is available at https://www.linkedin.com/legal/cookie-policy.
On this website, the data controller has integrated YouTube components. YouTube is an online video portal that allows video creators to publish video clips and other users to view, review, and comment on them free of charge. YouTube enables the publication of videos of all kinds—including full-length movies and television programs, music videos, trailers, and user-generated content—via the portal.
The operating company for YouTube is YouTube, LLC, located at 901 Cherry Ave., San Bruno, CA 94066, United States. YouTube, LLC is a subsidiary of Google Inc., located at 1600 Amphitheatre Pkwy, Mountain View, CA 94043-1351, United States.
Each time a user accesses one of the individual pages of this website—which is managed by the data controller and incorporates a YouTube component (YouTube video)—the internet browser on the data subject’s computer system is automatically prompted to download a display of the corresponding YouTube component. Further information about YouTube is available at https://www.youtube.com/yt/about/en/. During this technical process, YouTube and Google are informed of the specific sub-page of our website that the data subject has visited.
If the data subject is logged into YouTube, YouTube recognizes—each time a sub-page containing a YouTube video is accessed—which specific sub-page of our website the data subject has visited. This information is collected by YouTube and Google and associated with the data subject’s respective YouTube account.
YouTube and Google will receive information regarding the user’s visit to our website via the YouTube component, provided the user is logged into YouTube at the time of the visit; this occurs regardless of whether or not the user clicks on a YouTube video. If the user does not wish for this information to be transmitted to YouTube and Google, they can prevent it by logging out of their YouTube account before visiting our website.
YouTube’s data protection policies, available at https://www.google.com/intl/en/policies/privacy/ , provide information on the collection, processing, and use of personal data by YouTube and Google.
Article 6(1)(a) of the GDPR constitutes the legal basis for processing operations for which we obtain consent for a specific processing purpose.
If the processing of personal data is necessary for the performance of a contract to which the data subject is a party—such as in the case of the supply of goods or other services—the processing is based on Article 6(1)(b) of the GDPR. The same applies to processing operations necessary for the implementation of pre-contractual measures, for example, in the case of inquiries regarding our products or services.
Where our company is subject to a legal obligation requiring the processing of personal data—such as for the fulfillment of tax obligations—the processing is based on Article 6(1)(c) of the GDPR.
In rare cases, the processing of personal data may be necessary to protect the vital interests of the data subject or of another natural person. This would occur, for example, if a visitor were injured at our company premises and it became necessary to disclose their name, age, health insurance details, or other vital information to a doctor, hospital, or third party. In such a case, the processing would be based on Article 6(1)(d) of the GDPR.
Finally, processing operations may be based on Article 6(1)(f) of the GDPR. This legal basis is used for processing operations not covered by any of the legal bases mentioned above, where processing is necessary for the purposes of the legitimate interests pursued by our company or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.
Such processing operations are particularly permissible as they are specifically mentioned by the European legislator. The latter considered that a legitimate interest may be presumed where the data subject is a client of the controller (Recital 47, second sentence, GDPR).
Where the processing of personal data is based on Article 6(1)(f) of the GDPR, our legitimate interest is to conduct our business for the well-being of all our employees and shareholders.
The criterion used to determine the personal data retention period is the respective statutory retention period. Once this period has elapsed, the corresponding data are generally deleted, unless they are still required for the performance of the contract or for the conclusion of a contract.
We wish to clarify that the provision of personal data is in part required by law (e.g., tax regulations) or may arise from contractual provisions (e.g., information regarding the contracting party).
In some cases, the conclusion of a contract may require the data subject to provide us with personal data, which we will subsequently need to process. For instance, the data subject is required to provide personal data when our company enters into a contract with them. Failure to provide such personal data would make it impossible to conclude the contract with the data subject.
Before providing their personal data, the data subject must contact our Data Protection Officer. Our Data Protection Officer clarifies to the data subject whether the provision of personal data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the personal data, and the consequences of failing to provide them.
As a responsible company, we do not use automated decision-making processes or profiling.
This Privacy Policy was generated using the Privacy Policy Generator from DGD – Your External DPO, developed in collaboration with German lawyers from the Cologne-based law firm WILDE BEUGER SOLMECKE.