Privacy Policy
Preamble
With the following privacy policy, we would like to inform you about the types of your personal data (hereinafter also referred to as 'data') we process, for what purposes and to what extent. The privacy policy applies to all processing of personal data conducted by us, both within the provision of our services and particularly on our websites, in mobile applications, and within external online presences, such as our social media profiles (hereinafter collectively referred to as 'online offer').
Table of Contents
- Preamble
- Responsible person
- Overview of Processing Activities
- Relevant Legal Bases
- Security Measures
- Deletion of Data
- Rights of Data Subjects
- Changes and Updates to the Privacy Policy
- Definitions of Terms
Responsible person
Andre Kempf
Großschneidersweg 2a
76149 Karlsruhe
Phone: 0172-4180328
Email: mail@andre-kempf.com
Overview of Processing Activities
The following overview summarizes the types of data processed and the purposes of their processing, and refers to the data subjects.
Types of Data Processed
- Contact data, content data, usage data, metadata, communication data, procedural data.
Categories of Data Subjects
- Communication partners
Purposes of Processing
- Contact requests and communication, management and response to inquiries, feedback, provision of our online offer and user-friendliness.
Relevant Legal Bases
Relevant Legal Bases under the GDPR:
The following is an overview of the legal bases of the GDPR on which we
process personal data. Please note that, in addition to the provisions of
the GDPR, national data protection regulations may apply in your or our
country of residence or domicile. If specific legal bases are relevant in
individual cases, we will inform you of these in the privacy policy.
-
Legitimate Interests (Art. 6 para. 1 sentence 1 lit. f GDPR):
The processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.
National Data Protection Regulations in Germany:
In addition to the data protection regulations of the GDPR, national
regulations on data protection apply in Germany. This includes, in
particular, the Federal Data Protection Act (BDSG). The BDSG contains
specific regulations on the right of access, the right to deletion, the
right to object, the processing of special categories of personal data,
the processing for other purposes, and the transmission and automated
decision-making in individual cases, including profiling. Furthermore, the
data protection laws of the individual federal states may apply.
Security Measures
We take appropriate technical and organizational measures in accordance with the legal requirements, taking into account the state of the art, the implementation costs, and the nature, scope, context, and purposes of processing, as well as the varying likelihood and severity of the risks to the rights and freedoms of natural persons, to ensure a level of security appropriate to the risk.
The measures include, in particular, securing the confidentiality, integrity, and availability of data by controlling physical and electronic access to the data as well as the related access, input, transfer, securing availability, and separation. Furthermore, we have established procedures that ensure the exercise of data subject rights, the deletion of data, and responses to data risks. Furthermore, we take the protection of personal data into account during the development or selection of hardware, software, and procedures in accordance with the principle of data protection by design and by default.
TLS/SSL encryption (https): To protect the data of users that are transmitted via our online services, we use TLS/SSL encryption. Secure Sockets Layer (SSL) is the standard technology for securing internet connections by encrypting data transmitted between a website or app and a browser (or between two servers). Transport Layer Security (TLS) is an updated and more secure version of SSL. Hyper Text Transfer Protocol Secure (HTTPS) is displayed in the URL when a website is secured by an SSL/TLS certificate.
Deletion of Data
The data processed by us will be deleted in accordance with the legal requirements as soon as their permitted consents are revoked or other permissions cease to apply (e.g., if the purpose for processing this data no longer applies or is not necessary for the purpose). If the data is not deleted because it is required for other and legally permissible purposes, its processing will be restricted to these purposes. This means that the data will be blocked and not processed for other purposes. This applies, for example, to data that must be stored for commercial or tax reasons or whose storage is necessary for the assertion, exercise, or defense of legal claims or for the protection of the rights of another natural or legal person. Our data protection notices may also contain further details on the retention and deletion of data, which take precedence for the respective processing operations.
Rights of Data Subjects
Rights of data subjects under the GDPR: As a data subject, you have various rights under the GDPR, which are particularly set out in Articles 15 to 21 GDPR:
Right to Object:- You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you which is based on Article 6(1)(e) or (f) GDPR; this also applies to profiling based on these provisions. If personal data concerning you is processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for such marketing; this also applies to profiling to the extent that it is related to such direct marketing.
- You have the right to withdraw your consents at any time.
- You have the right to request confirmation as to whether data concerning you is being processed and to access information about this data as well as to further information and a copy of the data in accordance with the legal requirements.
- You have the right, in accordance with the legal requirements, to request the completion of data concerning you or the rectification of inaccurate data concerning you.
- You have the right, in accordance with the legal requirements, to request that data concerning you be deleted immediately, or alternatively, in accordance with the legal requirements, to request a restriction of the processing of the data.
- You have the right to receive the data concerning you that you have provided to us in a structured, commonly used, and machine-readable format in accordance with the legal requirements, or to request that it be transmitted to another controller.
- You also have the right, in accordance with the legal requirements, to lodge a complaint with a supervisory authority, in particular in the member state of your habitual residence, place of work, or place of the alleged infringement, if you consider that the processing of personal data relating to you infringes the GDPR.
Changes and Updates to the Privacy Policy
We kindly ask you to regularly inform yourself about the content of our privacy policy. We adapt the privacy policy as soon as the changes in the data processing we perform make this necessary. We will inform you as soon as the changes require your cooperation (e.g., consent) or another individual notification.
If we provide addresses and contact information of companies and organizations in this privacy policy, please note that the addresses may change over time and we ask you to check the information before contacting us.
Definitions of Terms
In this section, you will find an overview of the terminology used in this privacy policy. Many of the terms are taken from the law and are primarily defined in Art. 4 GDPR. The legal definitions are binding. The following explanations, on the other hand, are primarily intended to aid understanding. The terms are sorted alphabetically.
Personal Data: 'Personal data' means any information relating to an identified or identifiable natural person (hereinafter 'data subject'); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g., cookie) or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Controller: 'Controller' means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
Processing: 'Processing' means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.