Privacy Policy

1. Introduction

The protection of your personal data is our top priority. This Privacy Policy explains the nature, scope and purpose of the processing of personal data (hereinafter referred to as ‘data’) in connection with our online services. This includes the associated website, its features and content, as well as external online presences, such as social media profiles (hereinafter collectively referred to as the ‘online service’). Your personal data will be treated confidentially, and we strictly comply with statutory data protection regulations and the provisions of this Privacy Policy.

General Information

This Privacy Policy provides you with a comprehensive overview of what happens to your personal data when you visit this website. Personal data refers to any information that can be used to identify you personally. Please refer to this full Privacy Policy for detailed information on data protection. 

Data Controller

Data processing on this website is carried out by the website operator. The contact details of the data controller can be found in the ‘Data Controller’ section of this privacy policy.

 Collection of your data

Personal data is collected, on the one hand, when you actively provide it, for example by filling in a contact form. Other data is collected automatically or, with your consent, by the data controller’s IT systems when you visit the website. This primarily consists of technical data (e.g. internet browser, operating system or time of page view). This data is collected automatically as soon as you access the website.

Use of Your Data

Some of the data is collected to ensure the website functions correctly. Other data may be used to analyse your user behaviour to optimise the service and tailor it to your needs.

Data Transfer to External Parties

During the data controller’s business activities, it may be necessary to transfer personal data to external parties. Such transfers take place exclusively under specific conditions: where the transfer is necessary to fulfil a contract; where there is a legal obligation, for example to tax authorities; where there is a legitimate interest in accordance with Article 6(1)(f) of the GDPR; or where another legal basis permits the transfer of data. Where external service providers are used for data processing, the transfer of personal data takes place exclusively based on a valid data processing agreement in accordance with Article 28 of the Data Protection Act (DSG). Where data is processed jointly with other bodies, a joint processing agreement will be concluded in accordance with Article 26 of the GDPR.

Withdrawal of consent to data processing

Certain data processing operations may only take place with your explicit consent. This consent may be withdrawn at any time. The lawfulness of the data processing carried out up to the time of withdrawal remains unaffected by the withdrawal.

Right to object to specific data processing operations and marketing activities (Article 21 of the GDPR)

If the processing of your personal data is based on Article 6(1)(e) or (f) of the GDPR, you have the right to object to such processing at any time, provided you have grounds relating to your situation. This also applies to profiling based on these provisions. The specific legal basis for the data processing can be found in this privacy policy. If you object, the data controller will no longer process your personal data, unless it can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing is necessary for the establishment, exercise or defence of legal claims (objection under Article 21(1) of the GDPR).

Rights under the General Data Protection Regulation

You have the right to lodge a complaint with a competent supervisory authority in the event of infringements of the GDPR. This right may be exercised in the Member State in which you have your habitual residence, your place of work or the place where the alleged infringement occurred. This is without prejudice to other administrative or judicial remedies.

Personal data processed automatically based on consent or for the performance of a contract may be requested in a structured, commonly used and machine-readable format. Upon request, this data may also be transferred directly to another data controller, provided this is technically feasible.

Every data subject has the right to obtain, free of charge, information about their stored personal data, its origin, recipients and the purpose of the data processing. Furthermore, there is a right to have this data rectified or erased, provided that statutory provisions permit this. Should you have any further questions or concerns regarding personal data, you may contact the data controller at any time.

You have the right to request the restriction of the processing of your personal data if the accuracy of the data is disputed and a verification is pending. In the event of unlawful processing, the restriction of the data may also be requested instead of erasure.

Furthermore, restriction may be requested if the data are no longer required but are necessary for the establishment, exercise or defence of legal claims. In the event of an objection to processing pursuant to Article 21(1) of the GDPR, the right to restriction also applies until it has been determined whose interests prevail.

Where the processing of personal data is restricted, such data may, apart from storage, only be processed with the data subject’s consent or for the purpose of establishing, exercising or defending legal claims, for the protection of the rights of other natural or legal persons, or for reasons of an important public interest of the EU or a Member State.

2. Data Controller

The data controller for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:

Ute Sidenstein

Address: Färberweg 10A

D – 55128 Mainz

Website: www.sidenstein.com

Email: info(at)sidenstein.com

Phone: 06131/480 9 420

3. Data processors

We work with various data processors who process data on our behalf. These service providers are contractually obliged to treat the data confidentially and to use it exclusively within the scope of the respective service. Furthermore, there are cases in which responsibility for data processing is shared with other bodies. In such cases, responsibilities are clearly defined and documented to ensure compliance with data protection requirements.

4. Definitions

To ensure the transparency of this privacy policy and to make it understandable to everyone, this policy primarily uses terms that are also defined in the General Data Protection Regulation (GDPR). The full legal definitions can be found in Article 4 of the GDPR. The most important terms in the context of this privacy policy are explained below:

Personal data: This includes all information relating to an identified or identifiable natural person (hereinafter referred to as the ‘data subject’). A person is considered to be identifiable if they can be identified, directly or indirectly, in particular by association with an identifier such as a name, an identification number, location data, an online identifier (e.g. a cookie) or one or more specific characteristics that reflect that person’s physical, physiological, genetic, mental, economic, cultural or social identity.

Processing: This term covers any operation or set of operations performed on personal data, whether by automated means. This may include the collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction of data.

Data controller: This is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.

Data processor: A natural or legal person, public authority, agency or other body which processes personal data on behalf of the data controller.

Consent: Any freely given, specific, informed and unambiguous indication of the data subject’s wishes, by a statement or by a clear affirmative action, by which the data subject signifies their agreement to the processing of personal data relating to them.

Website: The website refers to the entire online offering provided by the data controller via a specific URL. This includes all content, information, functions and services published by the data controller and made available to users via this URL. The website serves as a digital platform for providing information and services, and for interaction between the data controller and users.

End device: An end device is an electronic device capable of accessing the internet and loading web pages. These include, amongst others, computers, laptops, tablets and smartphones.

These definitions help you to better understand the privacy policy and grasp the meaning of the terms used.

5. Hosting

This website is hosted on the servers of an external service provider to ensure that you c Data processing by the hosting provider is carried out in accordance with Article 6(1)(f) of the GDPR, as the data controller has a legitimate interest in providing a stable and secure website. Should it be necessary to obtain the user’s consent (for example, for the use of certain cookies or tracking technologies), data processing is based on the user’s consent in accordance with Article 6(1)(a) of the GDPR and Section 25(1) of the TTDSG. You may withdraw your consent at any time with future effect.

The hosting provider is:

IONOS SE

Elgendorfer Str. 57, 56410 Montabaur, Germany

Details regarding data processing and data protection can be found in the hosting provider’s privacy policy. This can be found here: https://www.ionos.de/terms-gtc/datenschutzerklaerung/

6. Legal basis for data processing

The processing of your personal data is carried out in accordance with the General Data Protection Regulation (GDPR) and other relevant legal provisions. Different legal bases apply depending on the purpose of the data processing.

Where you have consented to the processing of your personal data, this is carried out based on your consent in accordance with Article 6(1)(a) of the GDPR. This applies to the processing of special categories of personal data in accordance with Article 9(2)(a) of the GDPR, as well as to the transfer of personal data to third countries in accordance with Article 49(1)(a) of the GDPR. You may withdraw your consent at any time.

The processing of your data may be necessary for the performance of a contract or for the implementation of pre-contractual measures and, in this case, is carried out based on Article 6(1)(b) of the GDPR. Furthermore, processing may be necessary to comply with legal obligations, in which case it is carried out in accordance with Article 6(1)(c) of the GDPR.

In certain cases, processing is carried out to safeguard the legitimate interests of the controller or a third party, provided that your interests or fundamental rights and freedoms do not take precedence. This processing is based on Article 6(1)(f) of the GDPR.

For certain processing activities, national regulations may also apply, such as Section 25 of the TTDSG (German Teleservices Data Protection Act) regarding the storage of cookies or access to information on your device. The applicable legal bases are explained in detail in the relevant sections of this privacy policy.

Where your data is required to fulfil a contract or to take pre-contractual measures, the processing of your data is based on Article 6(1)(b) of the GDPR. Where data processing is necessary to comply with a legal obligation, it is based on Article 6(1)(c) of the GDPR. Furthermore, data processing may be carried out based on legitimate interests in accordance with Article 6(1)(f) of the GDPR. The specific legal bases in each individual case are explained in the following sections of this privacy policy.

7. Data transfers to third countries with inadequate data protection standards and US companies not certified under the DPF

If this website uses tools provided by companies based in third countries with inadequate data protection standards, or if US tools are used whose providers are not certified under the EU-US Data Privacy Framework (DPF), your personal data may be transferred to and processed in those countries. Please note that in third countries deemed unsafe from a data protection perspective, a level of data protection equivalent to that of the EU cannot be guaranteed. As a third country deemed unsafe, the US generally does not guarantee a level of data protection comparable to that of the EU. A data transfer to the USA is therefore only permitted if the recipient either holds certification under the ‘EU-US Data Privacy Framework’ (DPF) or has appropriate additional safeguards in place. Detailed information on possible transfers to third countries, including the data recipients, can be found in this privacy policy.

8. Retention period

Unless a more specific retention period is stated in this privacy policy, personal data will be retained by the data controller until the purpose for which the data is processed no longer applies. If a legitimate request for erasure is made or consent to data processing is withdrawn, the data in question will be erased, provided there are no other legally permissible grounds for retaining the personal data (e.g. retention periods under tax or commercial law). In such cases, erasure will take place once these grounds no longer apply.

The data controller retains personal data only for as long as is necessary to fulfil the respective purposes for which the data was collected. These include the fulfilment of contractual obligations, compliance with statutory retention periods, and the protection of the data controller’s legitimate interests, such as IT security and protection against misuse. Where the processing of personal data is based on consent, the data will be stored until such consent is withdrawn by the data subject. Such withdrawal is possible at any time with future effect. Thereafter, the data will be deleted without delay, unless there are statutory retention obligations or other overriding legal grounds that necessitate further storage.

In summary, personal data is deleted once the purpose for which it was collected has been fulfilled or the legal basis for its storage no longer applies, unless there are continuing legal obligations or legitimate interests that justify its continued storage.

9. Security measures and data minimisation

Comprehensive technical and organisational measures are taken to effectively protect your personal data against accidental or unlawful destruction, loss, alteration or unauthorised disclosure or access. Care is taken to ensure that only the data strictly necessary for the respective purpose is collected and processed. This data minimisation strategy helps to significantly reduce the risk of misuse and unauthorised access. The security measures are continuously updated in line with the state of the art to ensure that your data is always protected to a high standard.

10. Storage of user information in log files

Each time the website is accessed, general information transmitted by your browser to the server is automatically recorded. This information is stored in so-called log files and usually includes:

  1. a) The IP address of the requesting computer
  2. b) The date and time of access
  3. c) Name and URL of the file accessed
  4. d) Website from which the access originated (referrer URL)
  5. e) Browser used and user agent string
  6. f) Operating system
  7. g) Name of your internet service provider
  8. h) HTTP status code

This data is stored for security reasons, to ensure the website connects smoothly, to facilitate convenient use of the website, to assess system security and stability, and for other administrative purposes.

The legal basis for data processing is Article 6(1)(f) of the GDPR. The legitimate interest arises from the stated purposes of data collection. Under no circumstances will the data collected be used for the purpose of identifying you personally. The stored data will be anonymised or deleted, provided there are no statutory retention obligations.

11. Cookies

This website uses cookies. These are small files that your browser creates automatically, and which are stored on your device (laptop, tablet, smartphone, etc.) when you visit the site. Cookies do not cause any damage to your device and do not contain any viruses, Trojans or other malware.

Information relating to the specific device used is stored in the cookie. However, this does not mean that the data controller thereby gains direct knowledge of your identity.

The use of cookies serves, on the one hand, to make your use of the website more convenient. For example, the data controller uses so-called session cookies to recognise that you have already visited individual pages of the website. These are automatically deleted when you leave the site.

In addition, the data controller also uses temporary cookies to optimise user-friendliness; these are stored on your device for a specific, predetermined period. If you visit the site again to use the services, the system automatically recognises that you have been there before and recalls the entries and settings you have made, so that you do not have to re-enter them.

Furthermore, the data controller uses cookies to collect statistical data on the use of the website and to analyse this data with a view to optimising the service provided to you. These cookies enable the data controller to automatically recognise that you have previously visited the site when you return. These cookies are automatically deleted after a predefined period.

The data processed by cookies is necessary for the purposes to safeguard the legitimate interests of the controller and third parties in accordance with Article 6(1)(f) of the GDPR.

Most browsers accept cookies automatically. However, you can configure your browser so that no cookies are stored on your computer or so that a notification always appears before a new cookie is created. Please note, however, that completely disabling cookies may mean that you are unable to use all the website’s features.

12. Cookie Consent Banner

This website uses a cookie consent banner to manage your consent to the use of cookies. The provider of this service is:

Borlabs GmbH

Hamburger Str. 11, 22083 Hamburg, Germany

Further information on data processing can be found at: https://de.borlabs.io/datenschutz/

Functionality and purpose

The cookie consent banner sets a technically necessary cookie to store your cookie preferences. This cookie does not process any personal data. It merely stores the settings you selected when you first visited the website, including:

  1. a) Acceptance or rejection of specific cookies
  2. b) Time of consent
  3. c) Duration for which the settings are stored
  4. d) Legal basis for data processing

 

Data processing via the cookie consent banner is carried out in accordance with Article 6(1)(f) of the GDPR. The data controller’s legitimate interest lies in ensuring lawful consent to the use of cookies. Where consent has been sought, the processing is based on Article 6(1)(a) of the GDPR.

Retention period and deletion

The stored data remains stored until you delete the cookies from your browser yourself or withdraw your consent. You can change your settings at any time in the cookie settings on this website.

13. Enquiries by email or telephone

You may submit enquiries to the data controller by email or telephone. The personal data provided in this context (e.g. name, email address, telephone number and the enquiry itself) will be processed and stored by the data controller solely for the purpose of handling the enquiry and any follow-up questions.

The legal basis for this data processing is Article 6(1)(b) of the GDPR, as the processing is necessary for the performance of a contract or for the implementation of pre-contractual measures. Where the processing is not related to a contract, it is carried out based on Article 6(1)(f) of the GDPR, as the controller has a legitimate interest in processing and responding to enquiries.

14. Prohibition on sending promotional emails

The use of the contact details published in the legal notice to send unsolicited advertising, and information material is hereby prohibited. Any unauthorised use of the contact details for advertising purposes constitutes a violation of the rights of the operator of this website and will not be tolerated. The operator of this website expressly reserves the right to take legal action in the event of any infringements, particular in the case of the unsolicited sending of advertising information such as spam emails.

15. Use of analytics and tracking tools

Analytics and tracking tools are used to ensure that this website is designed to meet users’ needs and is continuously optimised. These measures help to collect statistical data on the use of this website and thus to optimise the service we provide for you. The storage and analysis of data is carried out based on Article 6(1), first sentence, point (f) of the GDPR, as the provider has a legitimate interest in offering an appealing and functional website.

Where relevant consent has been obtained, processing is also carried out based on Article 6(1), first sentence, point (a) of the GDPR and Section 25(1) of the TTDSG, provided that the consent covers the storage of cookies or access to information on the user’s device (e.g. device fingerprinting). This consent may be withdrawn at any time.