Privacy Policy
1. Privacy at a Glance
General Information
The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is all data that can personally identify you. Detailed information on the topic of privacy can be found in our privacy policy listed below this text.
Data Collection on This Website
Who is responsible for data collection on this website?
Data processing on this website is carried out by the website operator. Their contact details can be found in the section “Information on the Responsible Party” in this privacy policy.
How do we collect your data?
Your data is collected in part by you providing it to us. This could include data entered into a contact form.
Other data is collected automatically or with your consent when visiting the website by our IT systems. This mainly includes technical data (e.g., internet browser, operating system, or the time of the page visit). Collection of this data occurs automatically as soon as you enter this website.
What do we use your data for?
Some of the data is collected to ensure the website is provided without errors. Other data may be used to analyze your user behavior. If contracts can be concluded or initiated via the website, the transmitted data is also processed for contract offers, orders, or other service inquiries.
What rights do you have regarding your data?
You have the right at any time to obtain free information about the origin, recipients, and purpose of your stored personal data. You also have the right to request the correction or deletion of this data. If you have given consent for data processing, you can revoke this consent at any time for the future. In addition, you have the right, under certain circumstances, to request the restriction of processing of your personal data. Furthermore, you have the right to lodge a complaint with the competent supervisory authority.
For this and other questions regarding privacy, you can contact us at any time.
Analysis Tools and Third-Party Tools
Your surfing behavior may be statistically evaluated when visiting this website. This is mainly done using so-called analysis programs.
Detailed information about these analysis programs can be found in the following privacy policy.
2. Hosting
We host the content of our website with the following provider:
IONOS
The provider is IONOS SE, Elgendorfer Str. 57, 56410 Montabaur (hereinafter IONOS). When you visit our website, IONOS collects various log files, including your IP addresses. Details can be found in IONOS’s privacy policy: https://www.ionos.de/terms-gtc/terms-privacy.
The use of IONOS is based on Art. 6 para. 1 lit. f GDPR. We have a legitimate interest in a reliable presentation of our website. If corresponding consent has been requested, processing is carried out exclusively based on Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG, insofar as the consent covers the storage of cookies or access to information on the user’s device (e.g., device fingerprinting) within the meaning of TDDDG. Consent can be revoked at any time.
Order Processing
We have concluded a contract for order processing (AVV) for the use of the above service. This is a legally required contract that ensures that the service processes the personal data of our website visitors only according to our instructions and in compliance with GDPR.
3. General Information and Mandatory Information
Privacy
The operators of this website take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with legal data protection regulations as well as this privacy policy.
When you use this website, various personal data is collected. Personal data is data that can personally identify you. This privacy policy explains which data we collect and what we use it for. It also explains how and for what purpose this occurs.
We point out that data transmission over the Internet (e.g., when communicating by email) can have security gaps. Complete protection of data against third-party access is not possible.
Information on the Responsible Party
The responsible party for data processing on this website is:
GC Footwear GmbH
Plauener Str. 163-165, House 4/D
D-13053 Berlin
Phone: +49 (0) 30 60986990
Email: info@gcfootwear.com
The responsible party is the natural or legal person who, alone or jointly with others, determines the purposes and means of processing personal data (e.g., names, email addresses, or similar).
Storage Duration
Unless a more specific storage period is mentioned within this privacy policy, your personal data will remain with us until the purpose for data processing no longer applies. If you assert a legitimate request for deletion or revoke consent for data processing, your data will be deleted, provided we have no other legally permissible reasons for storing your personal data (e.g., statutory retention periods for tax or commercial law); in the latter case, deletion will occur once these reasons no longer apply.
General Information on the Legal Basis for Data Processing on This Website
If you have consented to data processing, we process your personal data based on Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR if special categories of data pursuant to Art. 9 para. 1 GDPR are processed. In the case of explicit consent for the transfer of personal data to third countries, data processing is also based on Art. 49 para. 1 lit. a GDPR. If you have consented to the storage of cookies or access to information on your device (e.g., via device fingerprinting), data processing is also based on § 25 para. 1 TDDDG. Consent can be revoked at any time. If your data is required for the performance of a contract or for pre-contractual measures, we process your data based on Art. 6 para. 1 lit. b GDPR. Furthermore, we process your data if it is necessary to fulfill a legal obligation based on Art. 6 para. 1 lit. c GDPR. Data processing can also be based on our legitimate interest pursuant to Art. 6 para. 1 lit. f GDPR. The specific legal basis applicable in each case is explained in the following sections of this privacy policy.
Data Protection Officer
We have appointed a data protection officer:
Mathias Eylers
Plauener Str. 163-165, House 4/D
D-13053 Berlin
Phone: +49 (0) 30 60986990
Email: datenschutz@gcfootwear.com
Recipients of Personal Data
As part of our business activities, we work with various external parties. In some cases, this requires the transfer of personal data to these external parties. We only share personal data with external parties if it is necessary for the fulfillment of a contract, if we are legally obliged to do so (e.g., transferring data to tax authorities), if we have a legitimate interest in sharing data pursuant to Art. 6 para. 1 lit. f GDPR, or if another legal basis permits the transfer of data. When using processors, we only transfer customer personal data based on a valid contract for order processing. In the case of joint processing, a contract on joint processing is concluded.
Revocation of Your Consent to Data Processing
Many data processing operations are only possible with your explicit consent. You can revoke consent at any time. The legality of the data processing carried out prior to the revocation remains unaffected.
Right to Object in Specific Cases and to Direct Marketing (Art. 21 GDPR)
IF DATA PROCESSING IS BASED ON ART. 6 PARA. 1 LIT. E OR F GDPR, YOU HAVE THE RIGHT AT ANY TIME TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE APPLICABLE LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR PERSONAL DATA UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING WHICH OVERRIDE YOUR INTERESTS, RIGHTS, AND FREEDOMS, OR THE PROCESSING SERVES THE ESTABLISHMENT, EXERCISE, OR DEFENSE OF LEGAL CLAIMS (OBJECTION PURSUANT TO ART. 21 PARA. 1 GDPR).
IF YOUR PERSONAL DATA IS PROCESSED FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF YOUR PERSONAL DATA FOR SUCH MARKETING PURPOSES; THIS ALSO APPLIES TO PROFILING TO THE EXTENT THAT IT IS LINKED TO SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL NO LONGER BE USED FOR DIRECT MARKETING PURPOSES (OBJECTION PURSUANT TO ART. 21 PARA. 2 GDPR).
Right to Lodge a Complaint with the Competent Supervisory Authority
In the event of violations of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the member state of their habitual residence, place of work, or the place of the alleged violation. The right to lodge a complaint exists without prejudice to other administrative or judicial remedies.
Right to Data Portability
You have the right to receive data that we process automatically based on your consent or in fulfillment of a contract in a commonly used, machine-readable format. If you request direct transfer of the data to another controller, this will only be carried out to the extent technically feasible.
Right of Access, Correction, and Deletion
You have the right, within the applicable legal provisions, to obtain free information about your stored personal data, its origin, recipients, and the purpose of data processing, and, if applicable, the right to correct or delete this data. You can contact us at any time for this or for other questions regarding personal data.
Right to Restrict Processing
You have the right to request the restriction of the processing of your personal data. You can contact us at any time for this purpose. The right to restrict processing exists in the following cases:
- If you contest the accuracy of your personal data stored with us, we usually need time to verify this. During the verification period, you have the right to request the restriction of the processing of your personal data.
- If the processing of your personal data was/is unlawful, you may request the restriction of processing instead of deletion.
- If we no longer need your personal data, but you require it to assert, exercise, or defend legal claims, you have the right to request the restriction of processing instead of deletion.
- If you have lodged an objection under Art. 21 para. 1 GDPR, a weighing of your interests and ours must be carried out. As long as it has not yet been determined whose interests prevail, you have the right to request the restriction of the processing of your personal data.
If you have restricted the processing of your personal data, such data may – aside from storage – only be processed with your consent, for the assertion, exercise, or defense of legal claims, to protect the rights of another natural or legal person, or for reasons of important public interest of the European Union or a member state.
SSL or TLS Encryption
For security reasons and to protect the transmission of confidential content, such as orders or inquiries you send to us as the site operator, this website uses SSL or TLS encryption. An encrypted connection can be recognized by the change of the browser address bar from “http://” to “https://” and the padlock symbol in your browser’s address bar.
When SSL or TLS encryption is active, the data you transmit to us cannot be read by third parties.
Encrypted Payment Transactions on This Website
If, after concluding a paid contract, you are required to provide us with your payment data (e.g., bank account number for direct debit), this data is necessary for payment processing.
Payment transactions using common payment methods (Visa/MasterCard, direct debit) are conducted exclusively via an encrypted SSL or TLS connection. An encrypted connection can be recognized by the change of the browser address bar from “http://” to “https://” and the padlock symbol in your browser’s address bar.
With encrypted communication, your payment data transmitted to us cannot be read by third parties.
4. Data Collection on This Website
Cookies
Our website uses so-called “cookies.” Cookies are small data packages and do not harm your device. They are either stored temporarily for the duration of a session (session cookies) or permanently (persistent cookies) on your device. Session cookies are automatically deleted at the end of your visit. Persistent cookies remain on your device until you delete them yourself or until automatic deletion occurs via your web browser.
Cookies can come from us (first-party cookies) or from third-party companies (so-called third-party cookies). Third-party cookies enable the integration of certain services from third-party companies within web pages (e.g., cookies for payment processing services).
Cookies have different functions. Many cookies are technically necessary because certain website functions would not work without them (e.g., shopping cart functionality or video display). Other cookies can be used to analyze user behavior or for advertising purposes.
Cookies that are necessary for the electronic communication process, for providing specific functions desired by you (e.g., shopping cart function), or for optimizing the website (e.g., cookies for measuring web traffic) are stored based on Art. 6 para. 1 lit. f GDPR, unless another legal basis is specified. The website operator has a legitimate interest in storing necessary cookies to provide its services technically error-free and optimized. If consent has been requested for the storage of cookies and comparable recognition technologies, processing is carried out exclusively based on this consent (Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG); consent can be revoked at any time.
You can configure your browser so that you are informed about the setting of cookies and allow cookies only on a case-by-case basis, block the acceptance of cookies for certain cases or generally, and enable the automatic deletion of cookies when closing the browser. Disabling cookies may limit the functionality of this website.
Which cookies and services are used on this website can be found in this privacy policy.
Consent with Borlabs Cookie
Our website uses the consent technology from Borlabs Cookie to obtain your consent for storing certain cookies in your browser or for the use of certain technologies and to document this in a privacy-compliant manner. The provider of this technology is Borlabs GmbH, Rübenkamp 32, 22305 Hamburg (hereinafter “Borlabs”).
When you visit our website, a Borlabs cookie is stored in your browser in which the consents you have given or the revocation of these consents are stored. This data is not passed on to the provider of Borlabs Cookie.
The collected data is stored until you request deletion from us, delete the Borlabs cookie yourself, or the purpose for storing the data ceases to exist. Mandatory statutory retention periods remain unaffected. Details on data processing by Borlabs Cookie can be found at https://de.borlabs.io/kb/welche-daten-speichert-borlabs-cookie/.
The use of Borlabs Cookie consent technology is carried out to obtain the legally required consents for the use of cookies. The legal basis for this is Art. 6 para. 1 lit. c GDPR.
Contact Form
If you send inquiries to us via the contact form, your details from the inquiry form, including the contact information you provide there, will be stored by us for the purpose of processing the inquiry and in case of follow-up questions. We do not pass on this data without your consent.
Processing of this data is based on Art. 6 para. 1 lit. b GDPR, provided your inquiry is related to the fulfillment of a contract or necessary for pre-contractual measures. In all other cases, processing is based on our legitimate interest in the effective handling of inquiries addressed to us (Art. 6 para. 1 lit. f GDPR) or on your consent (Art. 6 para. 1 lit. a GDPR) if obtained; consent can be revoked at any time.
The data you enter in the contact form will remain with us until you request deletion, revoke your consent to storage, or the purpose for storing the data ceases (e.g., after the inquiry has been fully processed). Mandatory statutory provisions – in particular retention periods – remain unaffected.
Inquiries via Email, Telephone, or Fax
If you contact us by email, telephone, or fax, your inquiry, including all personal data arising from it (name, inquiry), will be stored and processed for the purpose of handling your request. We do not pass on this data without your consent.
Processing of this data is based on Art. 6 para. 1 lit. b GDPR if your inquiry relates to the fulfillment of a contract or necessary for pre-contractual measures. In all other cases, processing is based on our legitimate interest in the effective handling of inquiries addressed to us (Art. 6 para. 1 lit. f GDPR) or on your consent (Art. 6 para. 1 lit. a GDPR) if obtained; consent can be revoked at any time.
The data sent to us via contact requests will remain with us until you request deletion, revoke your consent to storage, or the purpose for storing the data ceases (e.g., after your request has been fully processed). Mandatory statutory provisions – in particular legal retention periods – remain unaffected.
5. Analysis Tools and Advertising
Google Tag Manager
We use Google Tag Manager. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Google Tag Manager is a tool that allows us to integrate tracking or analytics tools and other technologies on our website. Google Tag Manager itself does not create user profiles, does not store cookies, and does not carry out independent analyses. It is only used for managing and deploying the tools integrated through it. However, Google Tag Manager may record your IP address, which may also be transmitted to Google’s parent company in the United States.
The use of Google Tag Manager is based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in the quick and uncomplicated integration and management of various tools on its website. If consent is obtained, processing is carried out solely on the basis of Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG, insofar as the consent covers the storage of cookies or access to information on the user’s device (e.g., via device fingerprinting). Consent can be revoked at any time.
The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the USA that aims to ensure compliance with European data protection standards for data processing in the USA. Any company certified under the DPF commits to adhering to these data protection standards. Further information can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780.
Google Analytics
This website uses features of the web analytics service Google Analytics. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
Google Analytics allows the website operator to analyze the behavior of website visitors. The website operator receives various usage data, such as page views, duration of stay, operating systems used, and the user’s origin. These data are assigned to the respective user device. No assignment to a user ID takes place.
Furthermore, we can use Google Analytics to record, among other things, your mouse and scroll movements and clicks. Google Analytics also uses various modeling approaches to supplement the collected data sets and applies machine learning technologies in data analysis.
Google Analytics uses technologies that enable user recognition for the purpose of analyzing user behavior (e.g., cookies or device fingerprinting). The information collected by Google about the use of this website is generally transmitted to a Google server in the USA and stored there.
Use of this service is based on your consent according to Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG. Consent can be revoked at any time.
Data transfer to the USA is based on the standard contractual clauses of the European Commission. Details can be found here: https://business.safety.google/adscontrollerterms/sccs/.
The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the USA that ensures compliance with European data protection standards for data processing in the USA. Any company certified under the DPF commits to adhering to these data protection standards. Further information can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780.
IP Anonymization
Google Analytics IP anonymization is enabled. As a result, your IP address is truncated by Google within member states of the European Union or other contracting states of the Agreement on the European Economic Area before transmission to the USA. Only in exceptional cases is the full IP address transmitted to a Google server in the USA and truncated there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, compile reports on website activities, and provide further services related to website and internet usage to the website operator. The IP address transmitted from your browser within Google Analytics is not merged with other Google data.
Browser Plugin
You can prevent the collection and processing of your data by Google by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=de.
More information on how Google Analytics handles user data can be found in Google’s privacy policy: https://support.google.com/analytics/answer/6004245?hl=de.
Data Processing Agreement
We have concluded a data processing agreement with Google and fully implement the strict requirements of the German data protection authorities when using Google Analytics.
6. Newsletter
Newsletter Data
If you wish to subscribe to the newsletter offered on the website, we require an email address from you and information that allows us to verify that you are the owner of the email address provided and consent to receiving the newsletter. No further data is collected, or only on a voluntary basis. For processing the newsletter, we use newsletter service providers, which are described below.
Mailchimp
This website uses the services of Mailchimp to send newsletters. The provider is Rocket Science Group LLC, 675 Ponce De Leon Ave NE, Suite 5000, Atlanta, GA 30308, USA.
Mailchimp is a service that allows, among other things, the organization and analysis of newsletter distribution. If you provide data for the purpose of subscribing to the newsletter (e.g., email address), this data is stored on Mailchimp’s servers in the USA.
With the help of Mailchimp, we can analyze our newsletter campaigns. When you open an email sent via Mailchimp, a file contained in the email (so-called web beacon) connects to Mailchimp’s servers in the USA. This allows us to determine whether a newsletter message has been opened and which links, if any, were clicked. Technical information is also collected (e.g., time of access, IP address, browser type, and operating system). This information cannot be attributed to the respective newsletter recipient and is used solely for the statistical analysis of newsletter campaigns. The results of these analyses can be used to better tailor future newsletters to the interests of recipients.
If you do not want analysis by Mailchimp, you must unsubscribe from the newsletter. A corresponding link is provided in every newsletter message.
Data processing is based on your consent (Art. 6 para. 1 lit. a GDPR). You can revoke this consent at any time by unsubscribing from the newsletter. The legality of the data processing carried out prior to revocation remains unaffected.
The data you provide to us for the purpose of subscribing to the newsletter will be stored by us until you unsubscribe from the newsletter or the newsletter service provider, and deleted from the mailing list after unsubscribing. Data stored for other purposes remains unaffected.
Data transfer to the USA is based on the standard contractual clauses of the European Commission. Details can be found here: https://mailchimp.com/eu-us-data-transfer-statement/ and https://mailchimp.com/legal/data-processing-addendum/#Annex_C_-_Standard_Contractual_Clauses.
After unsubscribing from the mailing list, your email address may be stored by us or the newsletter service provider in a blacklist if this is necessary to prevent future mailings. Data in the blacklist is used solely for this purpose and is not combined with other data. This serves both your interest and our interest in complying with legal requirements for sending newsletters (legitimate interest according to Art. 6 para. 1 lit. f GDPR). The storage in the blacklist is not time-limited. You can object to the storage if your interests outweigh our legitimate interest.
Further information can be found in Mailchimp’s privacy policy: https://mailchimp.com/legal/terms/.
The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the USA that ensures compliance with European data protection standards for data processing in the USA. Any company certified under the DPF commits to adhering to these data protection standards. Further information can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/participant/7693.
Data Processing Agreement
We have concluded a data processing agreement (DPA) for the use of the above-mentioned service. This is a legally required agreement that ensures the service processes the personal data of our website visitors only according to our instructions and in compliance with the GDPR.
7. Plugins and Tools
YouTube with Enhanced Privacy Mode
This website embeds videos from YouTube. The operator of the site is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
When you visit a website that embeds YouTube videos, a connection is established with YouTube’s servers. The YouTube server is informed which of our pages you have visited. If you are logged into your YouTube account, you allow YouTube to directly associate your browsing behavior with your personal profile. You can prevent this by logging out of your YouTube account.
We use YouTube in enhanced privacy mode. Videos played in enhanced privacy mode are, according to YouTube, not used for personalizing surfing on YouTube. Ads shown in enhanced privacy mode are also not personalized. No cookies are set in enhanced privacy mode. However, so-called Local Storage elements may be stored in the user’s browser, which may contain personal data and be used for recognition. Details on enhanced privacy mode can be found here: https://support.google.com/youtube/answer/171780.
Additional data processing may be triggered after activating a YouTube video, over which we have no control.
Use of YouTube is in the interest of presenting our online offerings attractively. This constitutes a legitimate interest under Art. 6 para. 1 lit. f GDPR. If consent is requested, processing occurs exclusively on the basis of Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG, as far as the consent includes the storage of cookies or access to information on the user’s device (e.g., device fingerprinting). Consent can be revoked at any time.
Further information on privacy at YouTube can be found in their privacy policy: https://policies.google.com/privacy?hl=de.
Das Unternehmen verfügt über eine Zertifizierung nach dem „EU-US Data Privacy Framework“ (DPF). Der DPF ist ein Übereinkommen zwischen der Europäischen Union und den USA, der die Einhaltung europäischer Datenschutzstandards bei Datenverarbeitungen in den USA gewährleisten soll. Jedes nach dem DPF zertifizierte Unternehmen verpflichtet sich, diese Datenschutzstandards einzuhalten. Weitere Informationen hierzu erhalten Sie vom Anbieter unter folgendem Link: https://www.dataprivacyframework.gov/participant/5780.
Vimeo
Diese Website nutzt Plugins des Videoportals Vimeo. Anbieter ist die Vimeo Inc., 555 West 18th Street, New York, New York 10011, USA.
Wenn Sie eine unserer mit einem Vimeo-Video ausgestatteten Seiten besuchen, wird eine Verbindung zu den Servern von Vimeo hergestellt. Dabei wird dem Vimeo-Server mitgeteilt, welche unserer Seiten Sie besucht haben. Zudem erlangt Vimeo Ihre IP-Adresse. Dies gilt auch dann, wenn Sie nicht bei Vimeo eingeloggt sind oder keinen Account bei Vimeo besitzen. Die von Vimeo erfassten Informationen werden an den Vimeo-Server in den USA übermittelt.
Wenn Sie in Ihrem Vimeo-Account eingeloggt sind, ermöglichen Sie Vimeo, Ihr Surfverhalten direkt Ihrem persönlichen Profil zuzuordnen. Dies können Sie verhindern, indem Sie sich aus Ihrem Vimeo-Account ausloggen.
Zur Wiedererkennung der Websitebesucher verwendet Vimeo Cookies bzw. vergleichbare Wiedererkennungstechnologien (z. B. Device-Fingerprinting).
Die Nutzung von Vimeo erfolgt im Interesse einer ansprechenden Darstellung unserer Online-Angebote. Dies stellt ein berechtigtes Interesse im Sinne des Art. 6 Abs. 1 lit. f DSGVO dar. Sofern eine entsprechende Einwilligung abgefragt wurde, erfolgt die Verarbeitung ausschließlich auf Grundlage von Art. 6 Abs. 1 lit. a DSGVO und § 25 Abs. 1 TDDDG, soweit die Einwilligung die Speicherung von Cookies oder den Zugriff auf Informationen im Endgerät des Nutzers (z. B. Device-Fingerprinting) im Sinne des TDDDG umfasst. Die Einwilligung ist jederzeit widerrufbar.
Die Datenübertragung in die USA wird auf die Standardvertragsklauseln der EU-Kommission sowie nach Aussage von Vimeo auf „berechtigte Geschäftsinteressen“ gestützt. Details finden Sie hier: https://vimeo.com/privacy.
Weitere Informationen zum Umgang mit Nutzerdaten finden Sie in der Datenschutzerklärung von Vimeo unter: https://vimeo.com/privacy.
Das Unternehmen verfügt über eine Zertifizierung nach dem „EU-US Data Privacy Framework“ (DPF). Der DPF ist ein Übereinkommen zwischen der Europäischen Union und den USA, der die Einhaltung europäischer Datenschutzstandards bei Datenverarbeitungen in den USA gewährleisten soll. Jedes nach dem DPF zertifizierte Unternehmen verpflichtet sich, diese Datenschutzstandards einzuhalten. Weitere Informationen hierzu erhalten Sie vom Anbieter unter folgendem Link: https://www.dataprivacyframework.gov/participant/5711.
ManageWP
Wir verwalten diese Website mit Hilfe des Tools ManageWP. Anbieter ist die GoDaddy.com WP Europe, Trg republike 5, 11000 Belgrad, Serbien (nachfolgend ManageWP).
Mit ManageWP können wir u. a. die Sicherheit und die Performance unserer Website überwachen und automatische Backups anfertigen. ManageWP hat somit Zugriff auf sämtliche Inhalte der Website inklusive unserer Datenbanken. ManageWP wird auf den Servern des Anbieters gehostet.
Die Verwendung von ManageWP erfolgt auf Grundlage von Art. 6 Abs. 1 lit. f DSGVO. Der Websitebetreiber hat ein berechtigtes Interesse an einem möglichst effektiven und sicheren Betrieb seiner Webseite(n). Sofern eine entsprechende Einwilligung abgefragt wurde, erfolgt die Verarbeitung ausschließlich auf Grundlage von Art. 6 Abs. 1 lit. a DSGVO und § 25 Abs. 1 TDDDG, soweit die Einwilligung die Speicherung von Cookies oder den Zugriff auf Informationen im Endgerät des Nutzers (z. B. Device-Fingerprinting) im Sinne des TDDDG umfasst. Die Einwilligung ist jederzeit widerrufbar.
Das Unternehmen verfügt über eine Zertifizierung nach dem „EU-US Data Privacy Framework“ (DPF). Der DPF ist ein Übereinkommen zwischen der Europäischen Union und den USA, der die Einhaltung europäischer Datenschutzstandards bei Datenverarbeitungen in den USA gewährleisten soll. Jedes nach dem DPF zertifizierte Unternehmen verpflichtet sich, diese Datenschutzstandards einzuhalten. Weitere Informationen hierzu erhalten Sie vom Anbieter unter folgendem Link: https://www.dataprivacyframework.gov/participant/4957.
Auftragsverarbeitung
Wir haben einen Vertrag über Auftragsverarbeitung (AVV) zur Nutzung des oben genannten Dienstes geschlossen. Hierbei handelt es sich um einen datenschutzrechtlich vorgeschriebenen Vertrag, der gewährleistet, dass dieser die personenbezogenen Daten unserer Websitebesucher nur nach unseren Weisungen und unter Einhaltung der DSGVO verarbeitet.
8. eCommerce und Zahlungsanbieter
Verarbeiten von Kunden- und Vertragsdaten
Wir erheben, verarbeiten und nutzen personenbezogene Kunden- und Vertragsdaten zur Begründung, inhaltlichen Ausgestaltung und Änderung unserer Vertragsbeziehungen. Personenbezogene Daten über die Inanspruchnahme dieser Website (Nutzungsdaten) erheben, verarbeiten und nutzen wir nur, soweit dies erforderlich ist, um dem Nutzer die Inanspruchnahme des Dienstes zu ermöglichen oder abzurechnen. Rechtsgrundlage hierfür ist Art. 6 Abs. 1 lit. b DSGVO.
Die erhobenen Kundendaten werden nach Abschluss des Auftrags oder Beendigung der Geschäftsbeziehung und Ablauf der ggf. bestehenden gesetzlichen Aufbewahrungsfristen gelöscht. Gesetzliche Aufbewahrungsfristen bleiben unberührt.
Zahlungsdienste
Wir binden Zahlungsdienste von Drittunternehmen auf unserer Website ein. Wenn Sie einen Kauf bei uns tätigen, werden Ihre Zahlungsdaten (z. B. Name, Zahlungssumme, Kontoverbindung, Kreditkartennummer) vom Zahlungsdienstleister zum Zwecke der Zahlungsabwicklung verarbeitet. Für diese Transaktionen gelten die jeweiligen Vertrags- und Datenschutzbestimmungen der jeweiligen Anbieter. Der Einsatz der Zahlungsdienstleister erfolgt auf Grundlage von Art. 6 Abs. 1 lit. b DSGVO (Vertragsabwicklung) sowie im Interesse eines möglichst reibungslosen, komfortablen und sicheren Zahlungsvorgangs (Art. 6 Abs. 1 lit. f DSGVO). Soweit für bestimmte Handlungen Ihre Einwilligung abgefragt wird, ist Art. 6 Abs. 1 lit. a DSGVO Rechtsgrundlage der Datenverarbeitung; Einwilligungen sind jederzeit für die Zukunft widerrufbar.
Folgende Zahlungsdienste / Zahlungsdienstleister setzen wir im Rahmen dieser Website ein:
PayPal
Anbieter dieses Zahlungsdienstes ist PayPal (Europe) S.à.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg (im Folgenden „PayPal“).
Die Datenübertragung in die USA wird auf die Standardvertragsklauseln der EU-Kommission gestützt. Details finden Sie hier: https://www.paypal.com/de/webapps/mpp/ua/pocpsa-full.
Details entnehmen Sie der Datenschutzerklärung von PayPal: https://www.paypal.com/de/webapps/mpp/ua/privacy-full.
American Express
Anbieter dieses Zahlungsdienstes ist die American Express Europe S.A., Theodor-Heuss-Allee 112, 60486 Frankfurt am Main, Deutschland (im Folgenden „American Express“).
American Express kann Daten an seine Muttergesellschaft in die USA übermitteln. Die Datenübertragung in die USA wird auf die Binding Corporate Rules gestützt. Details finden Sie hier: https://www.americanexpress.com/en-cz/company/legal/privacy-centre/binding-corporate-rules/.
Further information can be found in the privacy policy of American Express: https://www.americanexpress.com/de-de/firma/legal/datenschutz-center/online-datenschutzerklarung/.
Mastercard
The provider of this payment service is Mastercard Europe SA, Chaussée de Tervuren 198A, B-1410 Waterloo, Belgium (hereinafter “Mastercard”).
Mastercard may transfer data to its parent company in the USA. Data transfer to the USA is based on Mastercard’s Binding Corporate Rules. Details can be found here: https://www.mastercard.de/de-de/datenschutz.html and https://www.mastercard.us/content/dam/mccom/global/documents/mastercard-bcrs.pdf.
VISA
The provider of this payment service is Visa Europe Services Inc., London Branch, 1 Sheldon Square, London W2 6TT, United Kingdom (hereinafter “VISA”).
The United Kingdom is considered a data-protection-safe third country. This means that the UK has a level of data protection equivalent to that of the European Union.
VISA may transfer data to its parent company in the USA. Data transfer to the USA is based on the EU Commission’s standard contractual clauses. Details can be found here: https://www.visa.de/nutzungsbedingungen/visa-globale-datenschutzmitteilung/mitteilung-zu-zustandigkeitsfragen-fur-den-ewr.html.
Further information can be found in VISA’s privacy policy: https://www.visa.de/nutzungsbedingungen/visa-privacy-center.html.
9. Our Own Services
Handling of Applicant Data
We offer you the possibility to apply to us (e.g., by email, by post, or via an online application form). Below we inform you about the scope, purpose, and use of the personal data collected during the application process. We assure you that the collection, processing, and use of your data complies with applicable data protection law and all other statutory provisions and that your data is treated with strict confidentiality.
Scope and Purpose of Data Collection
If you submit an application to us, we process the associated personal data (e.g., contact and communication details, application documents, notes from interviews, etc.) to the extent necessary to make a decision regarding the establishment of an employment relationship. The legal basis for this is § 26 BDSG under German law (initiation of an employment relationship), Art. 6 para. 1 lit. b GDPR (general contract initiation), and—if you have given consent—Art. 6 para. 1 lit. a GDPR. Consent can be revoked at any time. Your personal data will only be shared within our company with individuals involved in processing your application.
If the application is successful, the data you submitted will be stored in our data processing systems for the purpose of managing the employment relationship based on § 26 BDSG and Art. 6 para. 1 lit. b GDPR.
Data Retention Period
If we are unable to make you a job offer, you decline an offer, or you withdraw your application, we reserve the right to retain the data you submitted based on our legitimate interests (Art. 6 para. 1 lit. f GDPR) for up to 6 months after the end of the application process (rejection or withdrawal). Afterwards, the data will be deleted, and physical application documents destroyed. Retention serves, in particular, as evidence in the event of legal disputes. If it becomes apparent that the data will be needed after the 6-month period (e.g., due to an impending or ongoing legal dispute), deletion will only occur once the purpose for further retention no longer exists.
Data may also be retained for a longer period if you have given corresponding consent (Art. 6 para. 1 lit. a GDPR) or if statutory retention obligations prevent deletion.