Privacy

Privacy policy

Status: January 12, 2023

Table of contents

Responsible

Martin Balas
Eisenbahnstraße 92/93
16225 Eberswalde

E-mail address:

martin.balas@recet.de

Imprint: https://recet.de/impressum

Processing overview

The following overview summarizes the types of data processed and the purposes of their processing and refers to the data subjects.

Types of data processed

Inventory data.

Contact details.

Content data.

Contract data.

Usage data.

Meta/communication data.

Categories of persons concerned

Interested parties.

Users.

Business and Contractual Partners.

Processing purposes

Provision of contractual services and customer service.

Contact requests and communication.

Office and organizational procedures.

Managing and responding to inquiries.

Feedback.

Marketing.

Provision of our online offer and user-friendliness.

Information Technology Infrastructure.

Relevant legal bases

Below you will find an overview of the legal basis of the GDPR on the basis of which we process personal data. Please note that in addition to the provisions of the GDPR, national data protection regulations may apply in your or our country of residence or domicile. If, in addition, more specific legal bases are relevant in individual cases, we will inform you of these in the data protection declaration.

Contract performance and pre-contractual requests (Art. 6 (1) p. 1 lit. b) DSGVO) – Processing is necessary for the performance of a contract to which the data subject is a party or for the performance of pre-contractual measures taken at the data subject’s request.

Legal obligation (Art. 6 (1) p. 1 lit. c) DSGVO) – Processing is necessary for compliance with a legal obligation to which the controller is subject.

Legitimate interests (Art. 6 (1) p. 1 lit. f) DSGVO) – Processing is necessary to protect the legitimate interests of the controller or a third party, unless such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require the protection of personal data.

In addition to the data protection regulations of the GDPR, national regulations on data protection apply in Germany. This includes, in particular, the Act on Protection against Misuse of Personal Data in Data Processing (Federal Data Protection Act – BDSG). In particular, the BDSG contains special provisions on the right to information, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes and transmission, as well as automated decision-making in individual cases, including profiling. Furthermore, it regulates data processing for purposes of the employment relationship (Section 26 BDSG), in particular with regard to the establishment, implementation or termination of employment relationships as well as the consent of employees. Furthermore, state data protection laws of the individual federal states may apply.

Security measures

We take appropriate technical and organizational measures to ensure a level of protection appropriate to the risk in accordance with the legal requirements, taking into account the state of the art, the implementation costs and the nature, scope, circumstances and purposes of the processing, as well as the different probabilities of occurrence and the extent of the threat to the rights and freedoms of natural persons.

The measures include, in particular, ensuring the confidentiality, integrity and availability of data by controlling physical and electronic access to the data as well as access to, input of, disclosure of, ensuring the availability of and segregation of the data. Furthermore, we have established procedures to ensure the exercise of data subject rights, the deletion of data, and responses to data compromise. Furthermore, we already take the protection of personal data into account during the development or selection of hardware, software and processes in accordance with the principle of data protection, through technology design and through data protection-friendly default settings.

TLS encryption (https): To protect your data transmitted via our online offer, we use TLS encryption. You can recognize such encrypted connections by the prefix https:// in the address bar of your browser.

Business services

We process data of our contractual and business partners, e.g. customers and interested parties (collectively referred to as “contractual partners”) in the context of contractual and comparable legal relationships as well as related measures and in the context of communication with contractual partners (or pre-contractual), e.g. to answer inquiries.

We process this data to fulfill our contractual obligations. This includes, in particular, the obligations to provide the agreed services, any update obligations and remedies in the event of warranty and other service disruptions. In addition, we process the data to safeguard our rights and for the purposes of the administrative tasks associated with these duties and the company organization. In addition, we process the data on the basis of our legitimate interests in proper and business management as well as security measures to protect our contractual partners and our business operations from misuse, endangerment of their data, secrets, information and rights (e.g. for the involvement of telecommunications, transport and other auxiliary services as well as subcontractors, banks, tax and legal advisors, payment service providers or tax authorities). Within the scope of applicable law, we only disclose the data of contractual partners to third parties to the extent that this is necessary for the aforementioned purposes or to fulfill legal obligations. The contractual partners will be informed about further forms of processing, e.g. for marketing purposes, within the scope of this data protection declaration.

We inform the contractual partners which data are required for the aforementioned purposes before or in the course of data collection, e.g. in online forms, by means of special marking (e.g. colors) or symbols (e.g. asterisks or similar), or in person.

We delete the data after the expiry of legal warranty and comparable obligations, i.e., basically after 4 years, unless the data is stored in a customer account, e.g., as long as it must be kept for legal archiving reasons. The statutory retention period for documents relevant under tax law and for commercial books, inventories, opening balances, annual financial statements, the work instructions required to understand these documents and other organizational documents and accounting records is ten years and for received commercial and business letters and reproductions of sent commercial and business letters six years. The period begins at the end of the calendar year in which the last entry was made in the book, the inventory, the opening balance sheet, the annual financial statements or the management report was prepared, the commercial or business letter was received or sent, or the accounting voucher was created, furthermore the recording was made or the other documents were created.

Insofar as we use third-party providers or platforms to provide our services, the terms and conditions and data protection notices of the respective third-party providers or platforms shall apply in the relationship between the users and the providers.

Types of data processed: inventory data (e.g. names, addresses); contact data (e.g. e-mail, telephone numbers); contract data (e.g. subject matter of contract, term, customer category).

Affected persons: Interested parties; business and contractual partners.

Purposes of processing: provision of contractual services and customer service; contact requests and communication; office and organizational procedures; management and response to requests.

Legal basis: contract performance and pre-contractual inquiries (Art. 6 para. 1 p. 1 lit. b) GDPR); Legal obligation (Art. 6 para. 1 p. 1 lit. c) DSGVO); Legitimate Interests (Art. 6 para. 1 p. 1 lit. f) DSGVO).

Further guidance on processing operations, procedures and services:

Agency services: We process our customers’ data in the context of our contractual services, which may include, for example, conceptual and strategic consulting, campaign planning, implementation of campaigns and processes, handling and training services; legal basis: contract performance and pre-contractual inquiries (Art. 6 para. 1 p. 1 lit. b) DSGVO).

Provision of the online offer and web hosting

We process users’ data in order to provide them with our online services. For this purpose, we process the user’s IP address, which is necessary to transmit the content and functions of our online services to the user’s browser or terminal device.

Types of data processed: Usage data (e.g. web pages visited, interest in content, access times); meta/communication data (e.g. device information, IP addresses).

Data subjects: Users (e.g., website visitors, users of online services).

Purposes of processing: provision of our online offer and user-friendliness; information technology infrastructure (operation and provision of information systems and technical equipment (computers, servers, etc.).).

Legal basis: Legitimate interests (Art. 6 para. 1 p. 1 lit. f) DSGVO).

Further guidance on processing operations, procedures and services:

Provision of online offer on rented storage space: For the provision of our online offer, we use storage space, computing capacity and software that we rent or otherwise obtain from a corresponding server provider (also called “web hoster”); Legal basis: Legitimate interests (Art. 6 para. 1 p. 1 lit. f) DSGVO).

STRATO: services in the field of provision of information technology infrastructure and related services (e.g., storage space and/or computing capacity); Service Provider: STRATO AG, Pascalstraße 10,10587 Berlin, Germany; Legal basis: Legitimate interests (Art. 6 para. 1 p. 1 lit. f) DSGVO); Website: https://www.strato.de; Privacy policy: https: //www.strato.de/datenschutz; Order processing contract: Provided by the service provider.

Presence in social networks (social media)

We maintain online presences within social networks and process user data in this context in order to communicate with users active there or to offer information about us.

We would like to point out that in the process, user data may be processed outside the area of the European Union. This may give rise to risks for users because, for example, it could make it more difficult to enforce users’ rights.

Furthermore, user data within social networks is usually processed for market research and advertising purposes. For example, usage profiles can be created based on the usage behavior and resulting interests of the users. The usage profiles can in turn be used, for example, to display advertisements within and outside the networks that presumably correspond to the users’ interests. For these purposes, cookies are usually stored on the users’ computers, in which the usage behavior and interests of the users are stored. Furthermore, data may also be stored in the usage profiles regardless of the devices used by the users (especially if the users are members of the respective platforms and are logged in to them).

For a detailed presentation of the respective forms of processing and the options to object (opt-out), we refer to the privacy statements and information provided by the operators of the respective networks.

Also in the case of requests for information and the assertion of data subject rights, we point out that these can be asserted most effectively with the providers. Only the providers have access to the users’ data in each case and can take appropriate measures and provide information directly. If you still need help, then you can contact us.

Types of data processed: contact data (e.g. e-mail, telephone numbers); content data (e.g. entries in online forms); usage data (e.g. websites visited, interest in content, access times); meta/communication data (e.g. device information, IP addresses).

Data subjects: Users (e.g., website visitors, users of online services).

Purposes of processing: contact requests and communication; feedback (e.g. collecting feedback via online form); marketing.

Legal basis: Legitimate interests (Art. 6 para. 1 p. 1 lit. f) DSGVO).

Further guidance on processing operations, procedures and services:

Instagram: Social network; Service provider: Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland; Legal basis: Legitimate interests (Art. 6 para. 1 p. 1 lit. f) DSGVO); Website: https://www.instagram.com; Privacy policy: https: //instagram.com/about/legal/privacy.

LinkedIn: Social network; Service Provider: LinkedIn Ireland Unlimited Company, Wilton Plaza Wilton Place, Dublin 2, Ireland; Legal basis: Legitimate interests (Art. 6 para. 1 p. 1 lit. f) DSGVO); Website: https://www.linkedin.com; Privacy Policy: https://www.linkedin.com/legal/privacy-policy; Order processing contract: https://legal.linkedin.com/dpa; Standard contractual clauses (guaranteeing the level of data protection for processing in third countries): https://legal.linkedin.com/dpa; Opt-out: https: //www.linkedin.com/psettings/guest-controls/retargeting-opt-out.

Plugins and embedded functions and content

We incorporate into our online offering functional and content elements that are obtained from the servers of their respective providers (hereinafter referred to as “third-party providers”). This may include, for example, graphics, videos or city maps (hereinafter uniformly referred to as “Content”).

The integration always requires that the third-party providers of this content process the IP address of the user, since without the IP address they could not send the content to their browser. The IP address is thus required for the display of these contents or functions. We endeavor to use only such content whose respective providers use the IP address only for the delivery of the content. Third-party providers may also use so-called pixel tags (invisible graphics, also known as “web beacons”) for statistical or marketing purposes. The “pixel tags” can be used to evaluate information such as visitor traffic on the pages of this website. The pseudonymous information may also be stored in cookies on the user’s device and may contain, among other things, technical information about the browser and operating system, referring websites, time of visit, and other information about the use of our online offering, as well as being linked to such information from other sources.

Types of data processed: Usage data (e.g. websites visited, interest in content, access times); meta/communication data (e.g. device information, IP addresses); inventory data (e.g. names, addresses); contact data (e.g. e-mail, telephone numbers); content data (e.g. entries in online forms).

Data subjects: Users (e.g., website visitors, users of online services).

Purposes of processing: provision of our online offer and user-friendliness.

Legal basis: Legitimate interests (Art. 6 para. 1 p. 1 lit. f) DSGVO).

Further guidance on processing operations, procedures and services:

YouTube videos: Video content; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal basis: Legitimate interests (Art. 6 para. 1 p. 1 lit. f) DSGVO); Website: https: //www.youtube.com; Privacy policy: https: //policies.google.com/privacy; Opt-out: Opt-Out Plugin: https://tools.google.com/dlpage/gaoptout?hl=de; Ad Display Settings: https://adssettings.google.com/authenticated.

Modification and update of the privacy policy

We ask you to regularly inform yourself about the content of our privacy policy. We will adapt the privacy policy as soon as the changes in the data processing carried out by us make this necessary. We will inform you as soon as the changes require an act of cooperation on your part (e.g. consent) or other individual notification.

Where we provide addresses and contact information for companies and organizations in this privacy statement, please note that the addresses may change over time and please check the information before contacting us.

Definitions

This section provides you with an overview of the terms used in this privacy statement. Many of the terms are taken from the law and defined especially in Art. 4 GDPR. The legal definitions are binding. The following explanations, on the other hand, are intended primarily to aid understanding. The terms are sorted alphabetically.

Personal data: “Personal data” means any information relating to an identified or identifiable natural person (hereinafter “data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. cookie) or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

Controller: a “controller” is the natural or legal person, public authority, agency or other body which alone or jointly with others determines the purposes and means of the processing of personal data.

Processing: “Processing” means any operation or set of operations which is performed upon personal data, whether or not by automatic means. The term is wide-ranging and encompasses practically every handling of data, be it collection, evaluation, storage, transmission or deletion.