Data Protection Statement
We hereby inform you, in accordance with the legal provisions of data protection law (in particular, pursuant to the new version of the German Federal Data Protection Act (BDSG n.F.) and the European General Data Protection Regulation (GDPR)), about the nature, scope, and purpose of the processing of personal data by our company. This Privacy Policy also applies to our websites and social media profiles. For definitions of terms such as "personal data" or "processing," we refer to Article 4 of the GDPR.
Name and Contact Details of the Controller
Our Controller (hereinafter referred to as "Controller") within the meaning of Article 4 No. 7 GDPR is:
Alexandra Andlinger
80339, Munich
Email: alexandra.andlinger@arcor.de
Types of Data, Purposes of Processing, and Categories of Data Subjects
Below, we inform you about the types, scope, and purpose of the collection, processing, and use of personal data.
- Types of Data We Process
- Purposes of Processing pursuant to Article 13(1)(c) GDPR
- Categories of Data Subjects pursuant to Article 13(1)(e) GDPR
The data subjects are collectively referred to as "Users."
Legal Basis for Processing Personal Data
We process personal data based on the following legal bases:
- If we obtain your consent, Article 6(1)(a) GDPR applies.
- If processing is necessary for contract fulfillment or pre-contractual measures, Article 6(1)(b) GDPR applies.
- If processing is required to comply with legal obligations, Article 6(1)(c) GDPR applies.
- If processing is necessary to protect vital interests, Article 6(1)(d) GDPR applies.
- If processing is based on legitimate interests, Article 6(1)(f) GDPR applies.
Disclosure of Personal Data to Third Parties and Processors
We do not disclose personal data to third parties without your consent. If we do so, it will be based on the above-mentioned legal bases, e.g., in the case of payment providers for contract fulfillment, court orders, or legal obligations for law enforcement.
Data Transfer to Third Countries
If data is processed outside the EU or EEA, it must meet GDPR requirements (Articles 44 et seq.). This includes recognized guarantees, such as EU adequacy decisions or standard contractual clauses.
Data Deletion and Storage Duration
Your personal data will be deleted or blocked when consent is withdrawn, or the purpose for storage ceases, unless legal retention obligations require otherwise.
Existence of Automated Decision-Making
We do not use automated decision-making or profiling.
Provision of Our Website and Creation of Log Files
When you visit our website for informational purposes only, we collect only the necessary technical data:
- IP address
- Internet service provider
- Date and time of access
- Browser type, language, and version
- Content accessed
- Time zone
- Access status/HTTP status code
- Data volume transmitted
- Referring website
- Operating system
These data are used to ensure the security and functionality of our website. The legal basis is our legitimate interest under Article 6(1)(f) GDPR.
Rights of the Data Subject
Objection or Withdrawal of Consent
If processing is based on your consent under Article 6(1)(a) GDPR, you have the right to withdraw your consent at any time without affecting the lawfulness of prior processing.
You may also object to data processing for direct marketing at any time.
Contact details for objections:
Alexandra Andlinger
80634, Munich
Email: alexandra.andlinger@arcor.de
Right of Access
You have the right to request confirmation of whether we process your personal data and access details under Article 15 GDPR.
Right to Rectification
You have the right to request correction of inaccurate or incomplete data under Article 16 GDPR.
Right to Erasure
You have the right to request deletion of your data under Article 17 GDPR, unless legal obligations prevent this.
Right to Restriction of Processing
You may request the restriction of data processing under certain conditions as per Article 18 GDPR.
Right to Data Portability
You have the right to receive your data in a structured, commonly used, and machine-readable format under Article 20 GDPR.
Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority.
Data Security
We take appropriate technical and organizational measures to protect personal data from unauthorized access. All data transmission between your browser and our server is encrypted via SSL.