Privacy Policy
Person in charge
ARONA GmbH
Bitzwiesen 2
74915 Waibstadt
Germany
Types of data processed:
- Record data (e.g., names, addresses).
- Contact details (e.g., email, phone numbers).
- Content data (e.g., text inputs, photographs, videos).
Usage data (e.g., websites visited, interest in content, access times).
- Meta/communication data (e.g., device information, IP addresses).
Purpose of processing
- Provision of the online offering, its functions and content.
- Responding to contact requests and communicating with users.
- Safety measures.
Reach measurement/Marketing
Terminology used
„Personal data“ means any information relating to an identified or identifiable natural person („data subject“); a natural person is identifiable who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
„Processing“ means any operation or set of operations which is performed upon personal data, whether or not by automatic means. The term is broad and covers virtually any handling of data.
„Pseudonymisation“ means the processing of personal data in such a way that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person;
„Profiling“ means any automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements;
The „controller“ is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
„Processor“ a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller;
Authorised Legal Basis
In accordance with Article 13 GDPR, we hereby inform you of the legal bases for our data processing. If the legal basis is not mentioned in the privacy policy, the following applies: The legal basis for obtaining consent is Article 6(1)(a) and Article 7 GDPR, the legal basis for processing for the performance of our services and the execution of contractual measures, as well as for responding to enquiries, is Article 6(1)(b) GDPR, the legal basis for processing for the fulfilment of our legal obligations is Article 6(1)(c) GDPR, and the legal basis for processing for the safeguarding of our legitimate interests is Article 6(1)(f) GDPR. In cases where vital interests of the data subject or another natural person require the processing of personal data, Article 6(1)(d) GDPR serves as the legal basis.
Safety measures
In accordance with Article 32 of the GDPR, taking into account the state of the art, the costs of implementation and the nature, scope, circumstances and purposes of the processing as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk; such measures shall include, in particular, ensuring the confidentiality, integrity and availability of data by controlling physical access to the data, as well as access, input, disclosure, safeguarding availability and separation relating to it. Furthermore, we have established procedures to ensure the exercise of data subject rights, data deletion and response to data breaches. We also take account of the protection of personal data right from the development or selection of hardware, software and procedures, in accordance with the principle of data protection by design and by default (Article 25 GDPR).
Co-operation with contract processors and third parties
If we disclose, transmit or otherwise grant access to data to other persons and companies (processors or third parties) within the scope of our processing, this will only be done on the basis of a legal permit (e.g. if the transfer of data to third parties, such as payment service providers, is necessary for the performance of the contract in accordance with Art. 6 para. 1 lit. b GDPR), you have given your consent, a legal obligation provides for this, or on the basis of our legitimate interests (e.g. when using vicars, web hosts, etc.).
Where we engage third parties to process data on the basis of a so-called „data processing agreement“, this is done in accordance with Article 28 of the GDPR.
Remittances to third countries
Where we process data in a third country (i.e., outside the European Union (EU) or the European Economic Area (EEA)), or this occurs in the context of using third-party services or disclosing or transferring data to third parties, this will only happen if it is for the performance of our (pre)contractual obligations, based on your consent, due to a legal obligation, or based on our legitimate interests. Subject to legal or contractual permissions, we will only process or allow data to be processed in a third country if the specific conditions of Art. 44 ff. GDPR are met. This means that the processing will occur, for example, based on specific guarantees, such as the officially recognised determination of a level of data protection equivalent to that of the EU (e.g., for the USA through the „Privacy Shield“) or compliance with officially recognised special contractual obligations (so-called „standard contractual clauses“).
Rights of data subjects
You have the right to request confirmation as to whether personal data concerning you are being processed, and to access that data, as well as further information and a copy of the data in accordance with Article 15 GDPR.
In accordance with Article 16 GDPR, you have the right to request the completion of your personal data or the correction of inaccurate personal data concerning you.
In accordance with Article 17 GDPR, you have the right to request the immediate erasure of your personal data, or alternatively, in accordance with Article 18 GDPR, to request a restriction on the processing of your data.
You have the right to request the personal data you have provided to us, in accordance with Article 20 of the GDPR, and to request its transmission to other controllers.
Furthermore, pursuant to Art. 77 GDPR, you have the right to lodge a complaint with the competent supervisory authority.
Right of withdrawal
You have the right to withdraw any consent given, in accordance with Article 7(3) of the GDPR, with effect for the future.
Right to object
You can object to the future processing of your personal data at any time in accordance with Art. 21 GDPR. The objection can be made in particular against processing for the purposes of direct marketing.
Cookies and the right to object to direct marketing
„Cookies“ are small files that are stored on users„ computers. Different information can be stored within cookies. A cookie primarily serves to store information about a user (or the device on which the cookie is stored) during or after their visit to an online service. Temporary cookies, or “session cookies„ or “transient cookies,„ are cookies that are deleted after a user leaves an online service and closes their browser. For example, the contents of a shopping cart in an online shop or a login status can be stored in such a cookie. “Permanent„ or “persistent„ cookies are cookies that remain stored even after the browser is closed. This way, for example, the login status can be saved if users visit again after several days. Similarly, user interests can be stored in such a cookie, which are used for reach measurement or marketing purposes. “Third-party cookies„ are cookies offered by providers other than the controller operating the online service (otherwise, if they are only its cookies, they are referred to as “first-party cookies").
We can use temporary and permanent cookies, and we explain this in our Privacy Policy.
If users do not wish for cookies to be stored on their computer, they are asked to disable the relevant option in their browser's system settings. Stored cookies can be deleted in the browser's system settings. The exclusion of cookies may lead to functional limitations of this online service.
A general objection to the use of cookies for online marketing purposes can be raised with a variety of services, especially in the case of tracking, via the US website. http://www.aboutads.info/choices/ or the EU page http://www.youronlinechoices.com/ explained. Furthermore, cookies can be prevented from being stored by disabling them in the browser settings. Please note that if you do this, you may not be able to use all functions of this online service.
Data deletion
The data processed by us will be deleted or its processing restricted in accordance with Articles 17 and 18 of the GDPR. Unless expressly stated otherwise in this privacy policy, the data stored by us will be deleted as soon as it is no longer required for its intended purpose and no legal retention obligations prevent deletion. If the data is not deleted because it is required for other legally permissible purposes, its processing will be restricted. This means that the data will be blocked and not processed for other purposes. This applies, for example, to data that must be retained for commercial or tax law reasons.
According to legal requirements in Germany, retention is carried out in particular for 10 years in accordance with §§ 147 Para. 1 AO, 257 Para. 1 No. 1 and 4, Para. 4 HGB (books, records, annual financial statements, booking vouchers, commercial books, documents relevant for taxation, etc.) and for 6 years in accordance with § 257 Para. 1 No. 2 and 3, Para. 4 HGB (commercial letters).
According to legal requirements in Austria, retention periods are as follows: specifically for 7 years according to § 132 (1) BAO (accounting documents, receipts/invoices, accounts, documents, business papers, income and expenditure statements, etc.), for 22 years in connection with real estate, and for 10 years for documents relating to electronically supplied services, telecommunications, radio and television services provided to non-business customers in EU Member States, for which the Mini-One-Stop-Shop (MOSS) is used.
Hosting
The hosting services we use are for providing the following services: infrastructure and platform services, computing capacity, storage and database services, security services, and technical maintenance services, which we use for the purpose of operating this online offering.
In this regard, we, or rather our hosting provider, process inventory data, contact data, content data, contract data, usage data, meta and communication data of customers, interested parties and visitors to this online offer on the basis of our legitimate interest in an efficient and secure provision of this online offer in accordance with Art. 6 para. 1 lit. f GDPR in conjunction with Art. 28 GDPR (conclusion of a data processing agreement).
Collection of access data and log files
We, or rather our hosting provider, collect data on every access to the server on which this service is located (so-called server log files) on the basis of our legitimate interests within the meaning of Art. 6 para. 1 lit. f. GDPR. The access data includes the name of the retrieved website, file, date and time of retrieval, amount of data transferred, notification of successful retrieval, browser type and version, the user's operating system, referrer URL (the previously visited page), IP address, and the requesting provider.
Log file information is stored for a maximum of 7 days for security reasons (e.g. for investigating misuse or fraud) and deleted thereafter. Data that requires further retention for evidence purposes is exempt from deletion until the respective incident has been finally clarified.
Created with privacy-generator.de by Dr. Thomas Schwenke (Attorney-at-Law)
