Back

Privacy Policy

Preamble

With the following privacy policy, we would like to inform you about the types of your personal data (hereinafter also referred to as 'data') we process, for what purposes and to what extent. The privacy policy applies to all processing of personal data conducted by us, both within the provision of our services and particularly on our websites, in mobile applications, and within external online presences, such as our social media profiles (hereinafter collectively referred to as 'online offer').

Table of Contents

Responsible person

Andre Kempf

Großschneidersweg 2a

76149 Karlsruhe


Phone: 0172-4180328

Email: mail@andre-kempf.com

Overview of Processing Activities

The following overview summarizes the types of data processed and the purposes of their processing, and refers to the data subjects.

Types of Data Processed

Categories of Data Subjects

Purposes of Processing

Relevant Legal Bases

Relevant Legal Bases under the GDPR:
The following is an overview of the legal bases of the GDPR on which we process personal data. Please note that, in addition to the provisions of the GDPR, national data protection regulations may apply in your or our country of residence or domicile. If specific legal bases are relevant in individual cases, we will inform you of these in the privacy policy.

National Data Protection Regulations in Germany:
In addition to the data protection regulations of the GDPR, national regulations on data protection apply in Germany. This includes, in particular, the Federal Data Protection Act (BDSG). The BDSG contains specific regulations on the right of access, the right to deletion, the right to object, the processing of special categories of personal data, the processing for other purposes, and the transmission and automated decision-making in individual cases, including profiling. Furthermore, the data protection laws of the individual federal states may apply.

Security Measures

We take appropriate technical and organizational measures in accordance with the legal requirements, taking into account the state of the art, the implementation costs, and the nature, scope, context, and purposes of processing, as well as the varying likelihood and severity of the risks to the rights and freedoms of natural persons, to ensure a level of security appropriate to the risk.

The measures include, in particular, securing the confidentiality, integrity, and availability of data by controlling physical and electronic access to the data as well as the related access, input, transfer, securing availability, and separation. Furthermore, we have established procedures that ensure the exercise of data subject rights, the deletion of data, and responses to data risks. Furthermore, we take the protection of personal data into account during the development or selection of hardware, software, and procedures in accordance with the principle of data protection by design and by default.

TLS/SSL encryption (https): To protect the data of users that are transmitted via our online services, we use TLS/SSL encryption. Secure Sockets Layer (SSL) is the standard technology for securing internet connections by encrypting data transmitted between a website or app and a browser (or between two servers). Transport Layer Security (TLS) is an updated and more secure version of SSL. Hyper Text Transfer Protocol Secure (HTTPS) is displayed in the URL when a website is secured by an SSL/TLS certificate.

Deletion of Data

The data processed by us will be deleted in accordance with the legal requirements as soon as their permitted consents are revoked or other permissions cease to apply (e.g., if the purpose for processing this data no longer applies or is not necessary for the purpose). If the data is not deleted because it is required for other and legally permissible purposes, its processing will be restricted to these purposes. This means that the data will be blocked and not processed for other purposes. This applies, for example, to data that must be stored for commercial or tax reasons or whose storage is necessary for the assertion, exercise, or defense of legal claims or for the protection of the rights of another natural or legal person. Our data protection notices may also contain further details on the retention and deletion of data, which take precedence for the respective processing operations.

Rights of Data Subjects

Rights of data subjects under the GDPR: As a data subject, you have various rights under the GDPR, which are particularly set out in Articles 15 to 21 GDPR:

Right to Object: Right to Withdraw Consent: Right of Access: Right to Rectification: Right to Erasure and Restriction of Processing: Right to Data Portability: Right to Lodge a Complaint with a Supervisory Authority:

Changes and Updates to the Privacy Policy

We kindly ask you to regularly inform yourself about the content of our privacy policy. We adapt the privacy policy as soon as the changes in the data processing we perform make this necessary. We will inform you as soon as the changes require your cooperation (e.g., consent) or another individual notification.

If we provide addresses and contact information of companies and organizations in this privacy policy, please note that the addresses may change over time and we ask you to check the information before contacting us.

Definitions of Terms

In this section, you will find an overview of the terminology used in this privacy policy. Many of the terms are taken from the law and are primarily defined in Art. 4 GDPR. The legal definitions are binding. The following explanations, on the other hand, are primarily intended to aid understanding. The terms are sorted alphabetically.

Personal Data: 'Personal data' means any information relating to an identified or identifiable natural person (hereinafter 'data subject'); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g., cookie) or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

Controller: 'Controller' means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.

Processing: 'Processing' means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.