English
info@pneutotal.ch
Swiss Tyre Group

Privacy Policy

Status: March 27, 2020

Controller
Swiss Tyre Group GmbH
Gewerbe Mooshof 1
CH-6022 Grosswangen

Authorized Representatives: Ralph Wiederkehr
Email address: info@swisstyregroup.ch

Overview of Processing Operations
The following overview summarizes the types of data processed and the purposes of their processing, and refers to the data subjects concerned.

Types of Data Processed

  • Inventory data (e.g., names, addresses).

  • Content data (e.g., text inputs, photographs, videos).

  • Contact data (e.g., email addresses, telephone numbers).

  • Meta/communication data (e.g., device information, IP addresses).

  • Usage data (e.g., visited websites, interest in content, access times).

  • Location data (data indicating the geographic position of an end user's device).

  • Contractual data (e.g., subject matter of contract, term, customer category).

  • Payment data (e.g., bank details, invoices, payment history).

Categories of Data Subjects

  • Business and contractual partners.

  • Interested parties / Prospective customers.

  • Communication partners.

  • Customers.

  • Users (e.g., website visitors, users of online services).

Purposes of Processing

  • Provision of our online offering and user-friendliness.

  • Visit action evaluation.

  • Office and organizational procedures.

  • Cross-device tracking (cross-device processing of user data for marketing purposes).

  • Direct marketing (e.g., by email or mail).

  • Interest-based and behavioral marketing.

  • Contact requests and communication.

  • Conversion measurement (measuring the effectiveness of marketing measures).

  • Profiling (creation of user profiles).

  • Remarketing.

  • Reach measurement (e.g., access statistics, recognition of returning visitors).

  • Security measures.

  • Tracking (e.g., interest/behavioral profiling, use of cookies).

  • Contractual performance and service.

  • Management and responding to inquiries.

  • Target group formation (determination of target groups relevant for marketing purposes or other output of content).

Relevant Legal Bases
Below we communicate the legal bases of the General Data Protection Regulation (GDPR) on the basis of which we process personal data. Please note that in addition to the regulations of the GDPR, national data protection provisions in your or our country of residence and domicile may apply. If, furthermore, more specific legal bases are decisive in individual cases, we will inform you of these in the Privacy Policy.

  • Consent (Art. 6 para. 1 sentence 1 lit. a GDPR) - The data subject has given consent to the processing of his or her personal data for one or more specific purposes.

  • Performance of a contract and prior inquiries (Art. 6 para. 1 sentence 1 lit. b GDPR) - Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.

  • Legal obligation (Art. 6 para. 1 sentence 1 lit. c GDPR) - Processing is necessary for compliance with a legal obligation to which the controller is subject.

  • Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR) - Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.

  • National data protection regulations in Switzerland: In addition to the data protection regulations of the General Data Protection Regulation, national data protection regulations apply in Switzerland. This includes in particular the Federal Act on Data Protection (FADP/DSG). The FADP applies in particular when no EU/EEA citizens are affected and, for example, only data of Swiss citizens is processed.

Security Measures
In accordance with legal requirements, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, we take appropriate technical and organizational measures to ensure a level of security appropriate to the risk. The measures include, in particular, safeguarding the confidentiality, integrity, and availability of data by controlling physical and electronic access to the data, as well as access, entry, disclosure, securing availability, and separation of data. Furthermore, we have established procedures to ensure the exercise of data subject rights, the erasure of data, and response to data threats. Furthermore, we take the protection of personal data into account as early as the development or selection of hardware, software, and procedures, in accordance with the principle of data protection by design and by default.

  • IP Address Truncation: If possible for us or if storing the IP address is not necessary, we truncate or have your IP address truncated. In the case of IP address truncation (also known as "IP masking"), the last octet (i.e., the last two numbers of an IP address) is deleted (in this context, the IP address is an identifier individually assigned to an internet connection by the online access provider). The truncation of the IP address is intended to prevent or significantly hinder the identification of a person by their IP address.

  • SSL Encryption (https): To protect your data transmitted via our online offer, we use SSL encryption. You can recognize such encrypted connections by the prefix https:// in the address line of your browser.

Transmission and Disclosure of Personal Data
In the context of our processing of personal data, it may happen that the data is transmitted to other places, companies, legally independent organizational units, or persons, or disclosed to them. Recipients of this data may include, for example, payment institutions in the context of payment transactions, service providers commissioned with IT tasks, or providers of services and content that are integrated into a website. In such cases, we comply with legal requirements and, in particular, conclude corresponding contracts or agreements serving to protect your data with the recipients of your data.

  • Data Transmission within the Organization: We may transmit personal data to other entities within our organization or grant them access to this data. If this transfer takes place for administrative purposes, the transfer of data is based on our legitimate business interests or takes place if necessary to fulfill our contract-related obligations, or if consent of the data subjects or legal permission exists.

Data Processing in Third Countries
If we process data in a third country (i.e., outside the European Union (EU), the European Economic Area (EEA)) or if processing takes place in the context of using third-party services or disclosure/transmission of data to other persons, entities, or companies, this will only be done in accordance with legal requirements. Subject to explicit consent or contractually or legally required transmission, we process or have data processed only in third countries with a recognized level of data protection, which includes US processors certified under the "Privacy Shield", or on the basis of special guarantees, such as contractual obligations through so-called standard contractual clauses of the EU Commission, existence of certifications, or binding corporate rules (Art. 44 to 49 GDPR, information page of the EU Commission: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection_en).

Use of Cookies Cookies are text files containing data from visited websites or domains and are stored by a browser on the user's computer. A cookie serves primarily to store information about a user during or after their visit within an online offering. The stored information may include, for example, language settings on a website, login status, a shopping cart, or the place where a video was watched. The term "cookies" also includes other technologies that fulfill the same functions as cookies (e.g., when user information is stored using pseudonymous online identifiers, also referred to as "user IDs").

The following cookie types and functions are distinguished:

  • Temporary cookies (also: session cookies): Temporary cookies are deleted at the latest after a user has left an online offer and closed their browser.

  • Permanent cookies: Permanent cookies remain stored even after the browser is closed. For example, login status can be stored or preferred content can be displayed directly when the user revisits a website. Likewise, user interests used for reach measurement or marketing purposes can be stored in such a cookie.

  • First-party cookies: First-party cookies are set by us.

  • Third-party cookies: Third-party cookies are mainly used by advertisers (so-called third parties) to process user information.

  • Necessary (also: essential) cookies: Cookies may be essential for the operation of a website (e.g., to store logins or other user inputs or for security reasons).

  • Statistics, marketing, and personalization cookies: Furthermore, cookies are generally used for reach measurement and when user interests or behavior (e.g., viewing specific content, using functions, etc.) are stored on individual websites in a user profile. Such profiles serve to display content to users that corresponds to their potential interests. This process is also referred to as "tracking" (following potential user interests). Insofar as we use cookies or tracking technologies, we will inform you separately in our privacy policy or when obtaining consent.

  • Notes on legal bases: The legal basis on which we process your personal data using cookies depends on whether we ask for your consent. If this applies and you consent to the use of cookies, the legal basis for processing your data is your declared consent. Otherwise, data processed using cookies will be processed on the basis of our legitimate interests (e.g., in the commercial operation and improvement of our online offer) or if the use of cookies is necessary to fulfill our contractual obligations.

  • General information on revocation and objection (Opt-Out): Depending on whether processing is based on consent or legal permission, you have the option at any time to revoke consent given or to object to the processing of your data by cookie technologies (collectively referred to as "opt-out"). You can initially declare your objection using your browser settings, e.g., by disabling the use of cookies (which may also restrict the functionality of our online offer). An objection to the use of cookies for online marketing purposes can also be declared via a variety of services, especially in the case of tracking, via the websites https://optout.aboutads.info and https://www.youronlinechoices.com/. In addition, you can receive further objection notices within the information on used service providers and cookies.

  • Types of data processed: Usage data (e.g., visited websites, interest in content, access times), meta/communication data (e.g., device information, IP addresses).

  • Data subjects: Users (e.g., website visitors, users of online services).

  • Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a GDPR), Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR).

Commercial and Business Services
We process data of our contractual and business partners, e.g., customers and interested parties (collectively referred to as "contractual partners") within the scope of contractual and comparable legal relationships as well as associated measures and within the scope of communication with contractual partners (or pre-contractually), e.g., to answer inquiries. We process this data to fulfill our contractual obligations, secure our rights, and for administrative tasks associated with these details as well as business organization. Within the framework of applicable law, we only disclose the data of contractual partners to third parties to the extent that this is necessary for the aforementioned purposes or to fulfill legal obligations, or with the consent of contractual partners (e.g., to participating telecommunications, transport, and other auxiliary services as well as subcontractors, banks, tax and legal advisors, payment service providers, or tax authorities). Contractual partners will be informed about further processing forms, e.g., for marketing purposes, within this privacy policy. We inform contractual partners which data is required for the aforementioned purposes before or during data collection, e.g., in online forms, by special marking (e.g., colors) or symbols (e.g., asterisks), or in person. We delete the data after the expiry of statutory warranty and comparable obligations, i.e., fundamentally after 4 years, unless the data is stored in a customer account, e.g., for as long as it must be retained for legal archiving reasons (e.g., for tax purposes, as a rule 10 years). Data disclosed to us by the contractual partner within the framework of an order will be deleted according to the specifications of the order, fundamentally after the end of the order. Insofar as we use third-party providers or platforms to provide our services, the terms and conditions and privacy notices of the respective third-party providers or platforms apply in the relationship between users and providers.

  • Customer Account: Contractual partners can create an account within our online offering (e.g., customer or user account, "customer account" for short). If registration of a customer account is required, contractual partners will be informed of this as well as of the details required for registration. Customer accounts are not public and cannot be indexed by search engines. In the context of registration and subsequent logins and use of the customer account, we store customer IP addresses along with access times to prove registration and prevent potential misuse of the customer account. If customers have terminated their customer account, data concerning the customer account will be deleted, subject to retention being required for legal reasons. It is the responsibility of customers to back up their data upon termination of the customer account.

  • Shop and E-Commerce: We process our customers' data to enable them to select, purchase, or order chosen products, goods, and associated services, as well as their payment and delivery or execution. The required details are marked as such in the context of the ordering or comparable acquisition process and include details required for delivery, provision, and billing, as well as contact information to hold any necessary consultations.

  • Types of data processed: Inventory data (e.g., names, addresses), payment data (e.g., bank details, invoices, payment history), contact data (e.g., email, telephone numbers), contractual data (e.g., subject matter of contract, term, customer category), usage data (e.g., visited websites, interest in content, access times), meta/communication data (e.g., device information, IP addresses).

  • Data subjects: Interested parties, business and contractual partners, customers.

  • Purposes of processing: Contractual performance and service, contact requests and communication, office and organizational procedures, management and responding to inquiries, security measures.

  • Legal bases: Performance of a contract and prior inquiries (Art. 6 para. 1 sentence 1 lit. b GDPR), Legal obligation (Art. 6 para. 1 sentence 1 lit. c GDPR), Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR).

Provision of the Online Offering and Web Hosting In order to provide our online offer safely and efficiently, we use the services of one or more web hosting providers, from whose servers (or servers managed by them) the online offer can be accessed. For these purposes, we may use infrastructure and platform services, computing capacity, storage space, database services, security services, and technical maintenance services. Data processed within the scope of providing hosting services may include all information concerning users of our online offer incurred during use and communication. This regularly includes the IP address, which is necessary to deliver online content to browsers, and all entries made within our online offer or websites.

  • Email Sending and Hosting: Web hosting services used by us also include sending, receiving, and storing emails. For these purposes, recipient and sender addresses as well as further information regarding email dispatch (e.g., participating providers) and the content of respective emails are processed. The aforementioned data may also be processed for SPAM detection purposes. Please note that emails on the Internet are generally not sent encrypted. As a rule, emails are encrypted in transit, but (unless end-to-end encryption is used) not on the servers from which they are sent and received. We can therefore assume no responsibility for the transmission path of emails between the sender and receipt on our server.

  • Collection of Access Data and Log Files: We ourselves (or our web hosting provider) collect data on every access to the server (so-called server log files). Server log files may include the address and name of retrieved web pages and files, date and time of retrieval, data volume transferred, notification of successful retrieval, browser type and version, user operating system, referrer URL (previously visited page), and usually IP addresses and requesting provider. Server log files can be used for security purposes, e.g., to prevent server overload (especially in cases of abusive attacks, so-called DDoS attacks) and to ensure server utilization and stability.

  • Types of data processed: Content data (e.g., text inputs, photographs, videos), usage data (e.g., visited websites, interest in content, access times), meta/communication data (e.g., device information, IP addresses).

  • Data subjects: Users (e.g., website visitors, users of online services).

  • Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR).

Newsletter and Broad Communication
We send newsletters, emails, and other electronic notifications (hereinafter "newsletter") only with recipient consent or legal permission. Insofar as contents are specifically outlined during newsletter registration, they are decisive for user consent. Otherwise, our newsletters contain information about our services and us. To subscribe to our newsletters, it is generally sufficient to provide your email address. However, we may ask you to provide a name for personal address in the newsletter, or further details if required for newsletter purposes.

  • Double-Opt-In Procedure: Registration for our newsletter takes place via a double-opt-in procedure. That is, after registration you will receive an email asking you to confirm your registration. This confirmation is necessary so that nobody can register with foreign email addresses. Newsletter registrations are logged in order to prove the registration process according to legal requirements. This includes storing registration and confirmation times as well as the IP address. Changes to your data stored with the shipping service provider are also logged.

  • Deletion and Restriction of Processing: We may store unsubscribed email addresses for up to three years based on our legitimate interests before deleting them, in order to prove previously given consent. Processing of this data is restricted to the purpose of a possible defense against claims. An individual erasure request is possible at any time, provided that former existence of consent is simultaneously confirmed. In case of obligations to permanently observe objections, we reserve the right to store the email address solely for this purpose in a blocklist ("blacklist"). Logging of the registration process is based on our legitimate interests for proving its proper course. Insofar as we commission a service provider to send emails, this is based on our legitimate interests in an efficient and secure sending system.

  • Notes on legal bases: Newsletters are sent on the basis of recipient consent or, if consent is not required, based on our legitimate interests in direct marketing, insofar as permitted by law, e.g., in the case of existing customer advertising. Insofar as we commission a service provider to send emails, this is done based on our legitimate interests. The registration process is recorded based on our legitimate interests to demonstrate that it was carried out in accordance with the law.

  • Content: Information about us, our services, promotions, and offers.

  • Performance Measurement: Newsletters contain a "web beacon", i.e., a pixel-sized file retrieved from our server (or, if we use a shipping service provider, from their server) when opening the newsletter. As part of this retrieval, technical information, such as browser and system info, your IP address, and time of retrieval are initially collected. This info is used for technical improvement of our newsletter based on technical data or target groups and their reading behavior based on access locations (determined via IP address) or access times. This analysis also includes determining whether newsletters are opened, when they are opened, and which links are clicked. For technical reasons, this info can be assigned to individual newsletter recipients. However, it is neither our intention nor that of the service provider to observe individual users. Rather, evaluations serve us to recognize reading habits of our users and adapt our content or send different content according to user interests. Evaluation of the newsletter and performance measurement are carried out, subject to explicit user consent, based on our legitimate interests for using a user-friendly and secure newsletter system serving both our business interests and user expectations. A separate revocation of performance measurement is unfortunately not possible; in this case, the entire newsletter subscription must be canceled or objected to.

  • Types of data processed: Inventory data (e.g., names, addresses), contact data (e.g., email, telephone numbers), meta/communication data (e.g., device information, IP addresses), usage data (e.g., visited websites, interest in content, access times).

  • Data subjects: Communication partners.

  • Purposes of processing: Direct marketing (e.g., via email or mail).

  • Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a GDPR), Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR).

  • Opt-Out Option: You can cancel receipt of our newsletter at any time, i.e., revoke your consent or object to further receipt. A link to cancel the newsletter can be found at the end of each newsletter, or you can use one of the contact options provided above, preferably email.

Online Marketing
We process personal data for online marketing purposes, which may include marketing advertising space or displaying promotional and other content (collectively referred to as "content") based on potential user interests and measuring their effectiveness. For these purposes, user profiles are created and stored in a file (so-called "cookie") or similar procedures are used to store details relevant to displaying the aforementioned content. These details may include, for example, viewed content, visited websites, used online networks, but also communication partners and technical information, such as the browser used, computer system used, and usage time info. If users have consented to collection of location data, this may also be processed. User IP addresses are also stored. However, we use available IP masking procedures (i.e., pseudonymization by truncating the IP address) to protect users. Generally, no clear user data (such as email addresses or names) is stored in online marketing procedures, but pseudonyms. That is, we and online marketing procedure providers do not know actual user identities, but only information stored in their profiles. Profile information is generally stored in cookies or via similar procedures. These cookies can later generally also be read on other websites using the same online marketing procedure, analyzed for content display, supplemented with further data, and stored on the server of the online marketing provider. Exceptionally, clear data can be assigned to profiles. This is the case if users are members of a social network whose online marketing procedure we use and the network connects user profiles with the aforementioned details. Please note that users can make additional agreements with providers, e.g., through consent during registration. We generally only receive access to aggregated information about the success of our advertisements. However, within the scope of conversion measurement, we can check which of our online marketing procedures led to a conversion, i.e., e.g., to a contract concluded with us. Conversion measurement is used solely to analyze the success of our marketing measures. Unless otherwise stated, please assume that used cookies are stored for a period of two years.

  • Notes on legal bases: If we ask users for consent to use third-party providers, the legal basis for data processing is consent. Otherwise, user data is processed based on our legitimate interests (i.e., interest in efficient, economic, and recipient-friendly services). In this context, we would also like to refer you to the information on cookie usage in this privacy policy.

  • Facebook Pixel: With the help of the Facebook Pixel, Facebook is able to determine visitors to our online offer as a target group for displaying ads ("Facebook Ads"). Accordingly, we use the Facebook Pixel to display Facebook Ads placed by us only to Facebook users and within services of partners cooperating with Facebook (so-called "Audience Network" https://www.facebook.com/audiencenetwork/) who have shown an interest in our online offer or who exhibit certain characteristics (e.g., interest in certain topics or products evident from visited websites) that we transmit to Facebook ("Custom Audiences"). With the help of the Facebook Pixel, we also want to ensure that our Facebook Ads correspond to potential user interest and do not appear annoying. Furthermore, the Facebook Pixel allows us to track the effectiveness of Facebook Ads for statistical and market research purposes by seeing whether users were redirected to our website after clicking on a Facebook ad ("conversion measurement").

  • Types of data processed: Usage data (e.g., visited websites, interest in content, access times), meta/communication data (e.g., device information, IP addresses), location data (data indicating geographic position of an end user's device).

  • Data subjects: Users (e.g., website visitors, users of online services), interested parties.

  • Purposes of processing: Tracking (e.g., interest/behavioral profiling, use of cookies), remarketing, visit action evaluation, interest-based and behavioral marketing, profiling (creation of user profiles), conversion measurement (measuring effectiveness of marketing measures), reach measurement (e.g., access statistics, recognition of returning visitors), target group formation (determination of relevant target groups for marketing purposes or other output of content), cross-device tracking (cross-device processing of user data for marketing purposes).

  • Security measures: IP masking (pseudonymization of IP address).

  • Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a GDPR), Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR).

  • Opt-Out Option: We refer to the privacy notices of respective providers and opt-out options specified for providers. If no explicit opt-out option is specified, you can disable cookies in your browser settings. However, this may restrict functions of our online offer. We therefore additionally recommend the following opt-out options offered collectively for respective regions: a) Europe: https://www.youronlinechoices.eu. b) Canada: https://www.youradchoices.ca/choices. c) USA: https://www.aboutads.info/choices. d) Cross-regional: https://optout.aboutads.info.

Services and Service Providers Used:

Social Media Presences
We maintain online presences within social networks and process user data in this context to communicate with active users there or to offer information about us. We point out that user data may be processed outside the European Union. This may result in risks for users because enforcing user rights could be made more difficult. Regarding US providers certified under Privacy Shield or offering comparable guarantees of a secure data protection level, we point out that they commit to complying with EU data protection standards. Furthermore, user data within social networks is usually processed for market research and advertising purposes. For example, usage profiles can be created based on usage behavior and resulting user interests. Usage profiles can in turn be used to place advertisements inside and outside networks that presumably correspond to user interests. For these purposes, cookies are usually stored on user computers containing usage behavior and interests. Furthermore, data independent of devices used by users can be stored in usage profiles (especially if users are members of respective platforms and logged in). For a detailed presentation of respective processing forms and opt-out options, we refer to privacy policies and information of operators of respective networks. Also in the case of requests for information and assertion of data subject rights, we point out that these can be asserted most effectively with providers. Only providers have access to user data and can directly take measures and provide information. If you still need help, you can contact us.

  • Types of data processed: Inventory data (e.g., names, addresses), contact data (e.g., email, telephone numbers), content data (e.g., text inputs, photographs, videos), usage data (e.g., visited websites, interest in content, access times), meta/communication data (e.g., device information, IP addresses).

  • Data subjects: Users (e.g., website visitors, users of online services).

  • Purposes of processing: Contact requests and communication, tracking (e.g., interest/behavioral profiling, use of cookies), remarketing, reach measurement (e.g., access statistics, recognition of returning visitors).

  • Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR).

Services and Service Providers Used:

Plugins and Embedded Content / Functions
We integrate functional and content elements into our online offer obtained from servers of their respective providers (hereinafter "third-party providers"). These may include, for example, graphics, videos, or social media buttons as well as posts (hereinafter uniformly referred to as "content"). Integration always requires third-party providers of this content to process user IP addresses, as they could not send content to browsers without the IP address. The IP address is therefore required to display this content or functions. We strive to use only content whose respective providers use the IP address solely for content delivery. Third-party providers may also use pixel tags (invisible graphics, also called "web beacons") for statistical or marketing purposes. Pixel tags can evaluate information such as visitor traffic on pages of this website. Pseudonymous info can also be stored in cookies on user devices and contain technical info regarding browser and operating system, referring websites, visit time, and other details on usage of our online offer, as well as link with info from other sources.

  • Notes on legal bases: If we ask users for consent to use third-party providers, the legal basis for processing data is consent. Otherwise, user data is processed based on our legitimate interests (interest in efficient, economic, and recipient-friendly services). We also refer to cookie usage information in this privacy policy.

  • Types of data processed: Usage data (e.g., visited websites, interest in content, access times), meta/communication data (e.g., device info, IP addresses), location data, inventory data, contact data, content data.

  • Data subjects: Users (e.g., website visitors, users of online services).

  • Purposes of processing: Provision of online offer and user-friendliness, contractual performance and service, security measures, management and responding to inquiries.

  • Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR), Consent (Art. 6 para. 1 sentence 1 lit. a GDPR), Performance of a contract and prior inquiries (Art. 6 para. 1 sentence 1 lit. b GDPR).

Services and Service Providers Used:

Deletion of Data
Data processed by us will be deleted in accordance with legal requirements as soon as consents permitted for processing are revoked or other permissions cease to apply (e.g., if the purpose of processing this data no longer applies or data is not required for the purpose). If data is not deleted because it is required for other legally permissible purposes, its processing will be restricted to these purposes. That is, data is blocked and not processed for other purposes. This applies, e.g., to data that must be retained for commercial or tax law reasons or whose storage is necessary for assertion, exercise, or defense of legal claims or protection of rights of another natural or legal person. Further notes on deletion of personal data can also be found in individual privacy notices of this privacy policy.

Changes and Updates to the Privacy Policy We ask you to regularly inform yourself about the content of our privacy policy. We adjust the privacy policy as soon as changes in data processing carried out by us make this necessary. We will inform you as soon as changes require cooperation on your part (e.g., consent) or other individual notification. Insofar as we provide addresses and contact information of companies and organizations in this privacy policy, please note that addresses may change over time and check information before contacting.

Rights of Data Subjects As a data subject under the GDPR, you have various rights arising in particular from Art. 15 to 18 and 21 GDPR:

  • Right to Object: You have the right to object, on grounds relating to your particular situation, at any time to processing of personal data concerning you based on Art. 6 para. 1 lit. e or f GDPR; this also applies to profiling based on these provisions. Where personal data concerning you is processed for direct marketing purposes, you have the right to object at any time to processing of personal data concerning you for such marketing; this applies also to profiling to the extent that it is related to such direct marketing.

  • Right to Revoke Consent: You have the right to revoke consent given at any time.

  • Right of Access: You have the right to request confirmation as to whether concerning data is being processed and to access this data as well as further information and copies of data in accordance with legal requirements.

  • Right to Rectification: In accordance with legal requirements, you have the right to request completion of data concerning you or rectification of inaccurate data concerning you.

  • Right to Erasure and Restriction of Processing: In accordance with legal requirements, you have the right to demand that data concerning you be deleted immediately or, alternatively, to request restriction of data processing in accordance with legal requirements.

  • Right to Data Portability: You have the right to receive data concerning you that you provided to us in a structured, commonly used, and machine-readable format or to demand its transmission to another controller in accordance with legal requirements.

  • Lodge a Complaint with a Supervisory Authority: In accordance with legal requirements, you also have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of alleged infringement if you consider that processing of personal data concerning you infringes the GDPR.