{"id":5200,"date":"2020-12-11T12:02:31","date_gmt":"2020-12-11T11:02:31","guid":{"rendered":"https:\/\/1million.humbaur.com\/?page_id=5200"},"modified":"2020-12-11T12:04:54","modified_gmt":"2020-12-11T11:04:54","slug":"data-protection","status":"publish","type":"page","link":"https:\/\/1-111-111.humbaur.com\/en\/data-protection\/","title":{"rendered":"Data protection"},"content":{"rendered":"
We, Humbaur GmbH, are responsible for collecting, processing and storing your data. Refer to our\u00a0imprint<\/a>\u00a0at any time for details about us.<\/p>\n Our top priority is to handle your personal data with care. When processing your data, we adhere to statutory provisions such as the General Data Protection Regulation (GDPR), as well as the associated national provisions.<\/p>\n This privacy statement applies to all of our company\u2019s websites that can be accessed under our domains (https:\/\/www.humbaur.com<\/a>,\u00a0https:\/\/shop.humbaur.com<\/a>,\u00a0https:\/\/partner.humbaur.com<\/a>, https:\/\/ ***.humbaur.com). If our websites lead you to websites of other operators, the respective data protection regulations for those sites will apply. The relevant operators of these websites are responsible for the content of their data protection regulations.<\/p>\n As we would like to provide you with a comprehensive overview of how your personal data is processed, below you will find an overview of all of our services in the context of which we collect and process personal data.<\/p>\n Where specific or additional conditions apply to individual services or we ask you to provide your consent, we will specifically notify you of this before you use the relevant service (subscribe to the newsletter or make a purchase from our online shop, for example).<\/p>\n In addition, we take a variety of security measures to protect your personal data. This means that data is transmitted between your web browser and our servers in an encrypted manner as a matter of principle, for example; in addition, we implement a range of technical and organisational measures to protect your data.<\/p>\n As a matter of principle, you can visit our websites without having to disclose your identity. Should you wish to register for one of our personalised services, use our online shop, register for our newsletter or wish to contact us, we will ask you to provide your name and other personal information. It is your prerogative as to whether you provide this (additional) data. Data that is essential in order for us to be able to provide our services to you is identified as such.<\/p>\n Your personal data is collected and processed for the following purposes on the basis of the following legal bases:<\/p>\n We collect different categories of personal data from you. Personal data means any information relating to an identified or identifiable natural person; a natural person is considered to be identifiable if he or she can be identified, directly or indirectly, in particular by reference to an identifier such as a name. Personal data includes information such as your name, your address, your telephone number and your date of birth (if specified), for example. Statistical information that cannot be linked to you directly or indirectly, such as the popularity of individual web pages of ours or the number of site users, is not considered to be personal data. We refer to data that is collected directly and indirectly. In both cases, data will be collected only to the extent necessary; the data will be processed exclusively for the purposes stated under Clause 2. It is your prerogative whether you would like to send data to us which, although will optimise the way in which you use our services, is not essential for this purpose. The relevant data fields are labelled “optional”.<\/p>\n Data that is collected directly includes:<\/p>\n When using our services, data will also be collected about you indirectly:<\/p>\n Minors:<\/strong><\/p>\n Our website is not intended for minors and we do not knowingly collect personal data from minors (with the exception of applications).<\/p>\n Individuals under the age of 16 may only provide us with personal data if their parent or guardian has given their own consent or has agreed to the minor\u2019s consent. For this purpose, we must be informed of the contact details of the parent or guardian in accordance with Art. 8 (2) of the GDPR in order for us to be assured that the parent or guardian has given their consent or approval. This data, as well as the data about the minor, will then be processed in accordance with this privacy statement.<\/p>\n If we find that a minor under the age of 16 has sent personal data to us without their parent or guardian having given their own consent or having agreed to the minor\u2019s consent, we will immediately delete the data.<\/p>\n Access to your personal data stored by us is limited to our employees and appointed service providers whose tasks require them to handle this personal data.<\/p>\n Insofar as third parties have access to your data, we have obtained consent from you for this purpose or there is a legal basis for this.<\/p>\n We also engage service providers to provide services and to process your data (including for hosting, sending newsletters, delivering goods that have been ordered, processing payments, sending letters or emails, as well as for maintaining and analysing databases, safeguarding our web servers and website tracking). Where specific provisions apply in these cases, we have listed these below for each relevant service. The service providers process the data solely on our instructions and are obliged to comply with the applicable data protection provisions. All processors have been carefully selected and only gain access to your data to the extent necessary and for the required period that is necessary to deliver the services and\/or to the extent to which you have consented to data processing and data use.<\/p>\n An exchange of data within the group of undertakings to which we belong takes place exclusively within the EU\/EEA and only for internal management purposes. By “group of undertakings”, we refer to affiliated companies within the meaning of Art. 4 No. 19 of the GDPR.<\/p>\n The servers of some of the service providers that we use are located in the USA and in other countries outside the European Union. Companies in these countries are subject to a data protection law that does not generally protect personal data to the same extent as it is protected in the Member States of the European Union. Where your data is processed in a country that has a level of data protection that is recognised to be lower than the level within the European Union, we will employ contractual arrangements or other recognised instruments to ensure that your personal data is adequately protected. We will explicitly draw your attention to this point once more within the scope of the individual services.<\/p>\n Where personal data is transferred to third countries, this is done on the basis of the EU Commission\u2019s adequacy decision on the EU-U.S. Privacy Shield in accordance with Art. 45 of the GDPR or on the basis of the standard contractual clauses adopted by the EU in 2010 in accordance with Art. 46 (2)(c) of the GDPR in conjunction with the EU Commission’s decision of 05\/02\/2010 (2010\/87\/EU) or in accordance with Art. 49 (1)(a) of the GDPR.<\/p>\n In exceptional cases, we will forward personal data to law enforcement authorities and criminal investigation authorities. This is carried out on the basis of corresponding statutory obligations, arising from the German Code of Criminal Procedure (Strafprozessordnung), the German Fiscal Code (Abgabenordnung), the German Money Laundering Act (Geldw\u00e4schegesetz) or state police laws, for example.<\/p>\n We retain personal data within the framework of statutory provisions or your given consent.<\/p>\n We take the following criteria into account when determining the specific retention period:<\/p>\n We retain personal data until the purposes for which it was collected cease to apply (e.g. when a contractual relationship comes to an end or as a result of the final activity being performed if a continuing obligation is not in place, or in the case of revocation of consent to specific data processing).<\/p>\n Data will only be retained for longer than this if<\/p>\n or any other exception in accordance with Art. 17 (3) of the GDPR applies.<\/p>\n You have a number of statutory rights, which we would like to draw to your attention below. Of course, you can also contact our data protection officer using the contact details below if you have any questions relating to your personal data that we have collected and processed.<\/p>\n You have the right to access information regarding your personal data processed by us at any time.<\/p>\n Where data processing takes place based on your consent or in accordance with Art. 6 (1)(b) of the GDPR on the basis of a contract, you may also request, in accordance with Art. 20 (1) of the GDPR, the provision of the personal data that is stored about you in a structured, commonly used and machine-readable format. At your request, we will also forward the data directly to a recipient as defined by you.<\/p>\n In addition, you may ask us to rectify, restrict (block) or erase your personal data pursuant to Articles 16 to 18 of the GDPR if we have incorrectly processed the data, if there is a reason for restricting further data processing, or if data processing has become unlawful for a variety of reasons, or if the retention of the data is inadmissible for other legal reasons. We would like to point out that statutory retention periods may restrict your right to erasure.<\/p>\n If our data processing is based exclusively on our legitimate interests in accordance with Art. 6 (1)(f) of the GDPR, you may opt out from this data processing in accordance with Art. 21 (1) of the GDPR. We will then stop processing your data, unless we are able to demonstrate legitimate grounds for the processing which override your interests, rights and freedoms, or the processing is used to establish, exercise or defend a legal claim. In addition, you always have the right to object to your data being used for direct marketing purposes in future in accordance with Art. 21 (2) of the GDPR.<\/p>\n If you have consented to our processing of your personal data, you have a right of withdrawal with future effect in accordance with Art. 7 (3) of the GDPR.<\/p>\n You have the right to lodge a complaint with a supervisory authority if you believe that our processing of your personal data violates the European General Data Protection Regulation or other national and international data protection laws.<\/p>\n The contact details of the relevant supervisory authority for us are:<\/p>\n Bayrisches Landesamt f\u00fcr Datenschutz (BayLDA) (Data Protection Authority of Bavaria) In order to exercise your rights, you can send an informal notification to us using the following contact details. Please direct the withdrawal of your consent to the following contact details, indicating which declaration of consent you would like to withdraw:<\/p>\n Controller<\/strong> Data protection officer<\/strong> We use cookies in some areas of our website to identify the preferences of visitors and to enable us to optimise the design of the website accordingly, for example. This makes navigation easier and enhances the user-friendliness of a website. Cookies also help us to identify particularly popular areas of our website. Cookies are small files that are stored on the hard drive of a visitor. They allow information to be held for a certain period of time and enable the visitor\u2019s computer to be identified. We use permanent cookies to improve user guidance and the way in which services are presented to the individual. We also use session cookies, which are automatically deleted when you close your browser. You can set your browser so that it informs you about the placement of cookies. This means that you will be clear about how the cookies are being used. The legal bases are formed by Art. 6 (1)(c) in conjunction with Art. 32 and Art. 6 (1)(f) of the GDPR. We have a legitimate interest in safeguarding our web server to defend it against attacks, for example, and to ensure the functionality of our services.<\/p>\n We only use cookies that are not essential from a technical point of view if you have provided your explicit consent for us to do so, which, of course, you can withdraw at any time.<\/p>\n In this regard, you have agreed to the following declaration in the context of our cookie information on our website:<\/p>\n This website uses tracking cookies or tracking software to, among other things, provide you with the full range of services on our website and thus a better online experience. You can find more information about the cookies and web tracking processes that we use, and the consent you have provided for this purpose, in our privacy statement at [add link]. However, cookies that are not essential from a technical point of view and\/or our tracking software will only be activated once you have given us your consent. [Agreed]<\/p>\n If you fully exclude the use of cookies, you will not be able to use individual features of our website, including the option to opt-out from tracking based on cookies. You may need to allow the opt-out cookies for those services for which you wish to prevent tracking.<\/p>\n Please keep in mind that deleting all cookies also means that opt-out cookies are deleted. You must therefore reset these cookies where applicable. Cookies are also linked to the browser, meaning they need to be set separately for each of the browsers you use on each of the devices you use. The links that are necessary for this purpose can be found below in the description of the respective services.<\/p>\n We use the following cookies, provided you allow them and have not set one or multiple opt-out cookies, for the purposes specified in more detail below:<\/p>\n2. Why we process your data<\/h2>\n
\n
3. The information that we collect from you and process<\/h2>\n
\n
\n
4. Who has access to your data and whom we send your data to<\/h2>\n
a) Access<\/h3>\n
b) Exchanging data within the group of undertakings<\/h3>\n
c) Data transfer to third countries and legal basis<\/h3>\n
d) Data transfer to law enforcement authorities and criminal investigation authorities<\/h3>\n
5. Retention periods<\/h2>\n
\n
6. Your rights<\/h2>\n
a) Right of access and right to data portability<\/h3>\n
b) Right to rectification, restriction and erasure<\/h3>\n
c) Rights to object<\/h3>\n
d) Right of withdrawal<\/h3>\n
e) Right to lodge a complaint with the supervisory authority<\/h3>\n
\nPromenade 27
\n91522 Ansbach
\nGermany
\nPhone: +49 (0) 981 53 1300
\npoststelle@lda.bayern.de<\/p>\nf) Contact details<\/h3>\n
\nHumbaur GmbH
\nMercedesring 1
\n86368 Gersthofen
\nGermany
\nPhone: +49 (0) 821 24929-0
\nEmail: datenschutz@humbaur.com<\/p>\n
\nit.sec GmbH
\nEinsteinstr. 55
\n89077 Ulm
\nGermany
\nDatenschutz@it-sec.de<\/p>\n7. Using our websites \u2014 profiling, cookies and web tracking<\/h2>\n
a) Basic information about cookies and opt-out options<\/h3>\n