Privacy Policy

Privacy Policy

With this data protection declaration we would like to inform you about the type, scope and purpose of processing personal data (hereinafter also referred to as "data"). Personal data are all data that have a personal reference to you, e.g. name, address, e-mail address or your user behavior. This data protection declaration applies to all data processing operations carried out by us both within the scope of our core activity and for the online media we maintain.

Who is responsible for data processing in our company

Responsible for data processing:

Bildhuus GmbH
Sönke Ludwig, Meikel Steiding
Steinrader Weg 31
23558 Lübeck
Deutschland
+49 451 30505803
privacy@bildhuus.com
https://bildhuus.com/impressum

Processing of your data within the scope of the core activity of our company

If you are our customer or business partner or are interested in our services, the type, scope and purpose of processing your data is based on the contractual or pre-contractual relationship existing between us. In this sense, the data processed by us includes all those data which are or were provided by you for the purpose of using the contractual or pre-contractual services and which are required to process your inquiry or the contract concluded between us. Unless otherwise stated in the further notes of this data protection declaration, the processing of your data as well as their transfer to third parties is limited to those data which are necessary and expedient for answering your inquiries and/or for the fulfilment of the contract concluded between you and us, for the protection of our rights as well as for the fulfilment of legal obligations. We will inform you of which data is required for this purpose before or during the data collection process. If we use third party providers to provide our services, the data protection information of the respective third party provider applies.

Data concerned:

  • Inventory data (e.g. names, addresses)
  • Payment data (e.g. bank details, invoices)
  • Contact details (e.g. e-mail address, telephone number, postal address)
  • Contract data (e.g. object of contract, contract period)

Persons concerned: Interested parties, business and contractual partners

Processing purpose: processing of contractual services, communication as well as answering contact inquiries, office and organizational procedures

Legal basis: Fulfilment of contract and pre-contractual inquiries, Art. 6 Para. 1 lit. b GDPR, legal obligation, Art. 6 Para. 1 lit. c GDPR, legitimate interest, Art. 6 Para. 1 lit. f GDPR

Your rights according to the GDPR

According to the GDPR, you are entitled to the rights listed below, which you can assert at any time with the person responsible named in section 1 of this data protection declaration:

  • Right to information: You have the right to demand information from us as to whether and which of your data we are processing.
  • Right of rectification: You have the right to request the rectification of incorrect data or the completion of incomplete data.
  • Right to cancellation: You have the right to ask for the cancellation of your data.
  • Right to limitation: In certain cases, you have the right to request that we process your data only to a limited extent.
  • Right to data transferability: You have the right to demand that we transfer your data to you or another responsible party in a structured, common and machine-readable format.
  • Right of complaint:: You have the right to complain to a supervisory authority. The competent authority is the supervisory authority of your usual place of residence, your place of work or our company headquarters.

Right of withdrawal

You have the right to revoke your consent to data processing at any time.

Right of objection

You have the right to object at any time to the processing of your data, which we base on our legitimate interest according to Art. 6 Par. 1 letter f GDPR. If you exercise your right of objection, we would ask you to explain the reasons. We will then no longer process your personal data unless we can prove to you that compelling reasons for data processing worthy of protection outweigh your interests and rights.

Irrespective of the above, you have the right at any time to object to the processing of your personal data for advertising and data analysis purposes.

Please send your objection to the contact address of the person responsible stated above.

When do we delete your data?

We delete your data when we no longer need it or when you tell us to do so. This means that - unless otherwise stated in the individual data protection notices in this privacy policy - we delete your data,

  • if the purpose of the data processing has ceased to exist and thus the respective legal basis mentioned in the individual data protection notices no longer exists, e.g.
    • after termination of the contractual or membership relations existing between us (Art. 6 para. 1 lit. a GDPR) or
    • after loss of our legitimate interest in the further processing or storage of your data (Art. 6 para. 1 lit. f GDPR),
  • if you make use of your right of revocation and no other legal basis for the processing within the meaning of Art. 6 para. 1 lit. b-f GDPR intervenes,
  • if you make use of your right of objection and there are no compelling reasons worthy of protection against the deletion.

However, if we (certain parts of) your data have to keep your data for other purposes, for example, because tax retention periods (usually 6 years for business correspondence or 10 years for accounting records) or the assertion, exercise or defence of legal claims arising from contractual relationships (up to four years) make this necessary, or if the data is used to protect the rights of another natural person or legal entity, we will not delete (that part of) your data until these periods have expired. Until the expiry of these periods, however, we will limit the processing of this data to these purposes (fulfilment of the storage obligations).

Cookies

Our website uses cookies. Cookies are small text files consisting of a series of numbers and letters that are stored on the terminal device you use. Cookies are primarily used to exchange information between the end device you use and our website. This includes, for example, the language settings on a website, the login status or the location where a video was viewed.

Two types of cookies are used when you visit our website::

  • Temporary cookies (session cookies): hese store a so-called session ID, which can be used to assign various requests from your browser to the shared session. The session cookies are deleted when you log out or close your browser.
  • Permanent cookies: Permanent cookies remain stored even after you close your browser. This enables our website to recognize your computer when you return to our website. Information on language settings or log-in information, for example, is stored in these cookies. In addition, these cookies can be used to document and store your surfing behavior. This data can be used for statistical, marketing and personalization purposes.

In addition to the above classification, cookies can also be differentiated according to their purpose:

  • Necessary cookies: These are cookies that are absolutely necessary for the operation of our website, to store logins or shopping baskets for the duration of your session or cookies that are set for security reasons.
  • Statistical, marketing and personalization cookies: These are cookies that are used for analysis purposes or to measure the reach of our website. Such "tracking" cookies may be used to store information on search terms entered or the frequency of page views. In addition, the surfing behaviour of an individual user (e.g. viewing certain content, using functions, etc.) can also be stored in a user profile. Such profiles are used to display content to users that matches their potential interests. Insofar as we use services via which cookies are stored on your end device for statistical, marketing and personalization purposes, we will inform you separately in the following sections of our data protection declaration or when obtaining your consent.

Data concerned:

  • Usage data (e.g. access times, websites clicked on)
  • Communication data (e.g. information about the device used, IP address).

Data subjects: Users of our online offers

Processing purpose: Playing our Internet pages, ensuring the operation of our Internet pages, improving our Internet offer, communication and branding

Legal basis:
Legitimate interest, Art. 6 para. 1 lit. f GDPR

If we do not obtain your consent to the use of cookies, we base the processing of your data on our legitimate interest in improving the quality and user-friendliness of our website, in particular the content and functions. You have the security settings of your browser to object to the use of cookies set by us within the scope of our legitimate interest. There you have the possibility to specify whether you do not accept cookies from the outset or only accept cookies on request, or whether you specify that cookies are deleted each time you close your browser. If cookies are deactivated for our website, it is possible that not all functions of the website can be used to their full extent.

Web hosting

For the maintenance of our Internet pages we use a provider on whose server our Internet pages are stored and made available for retrieval on the Internet (hosting). The provider may process all data transmitted via the browser used by you that are generated when using our Internet pages. This includes in particular your IP address, which the provider requires in order to be able to deliver our online offer to the browser you are using, as well as all entries made by you via our website. In addition, the provider used by us can

  • the date and time of access to our website
  • Time zone difference to Greenwich Mean Time (GMT)
  • Access status (HTTP status)
  • the amount of data transferred
  • the Internet service provider of the accessing system
  • the type of browser you use and its version
  • the operating system you use
  • the website from which you may have accessed our website
  • the pages or sub-pages that you visit on our website.

raise. The aforementioned data is stored as log files on the servers of our provider. This is necessary to ensure the stability and security of the operation of our website.

E-mail transmission: In addition to hosting our website, we have also commissioned our provider to send, receive and store our e-mails. For this purpose, our provider processes the e-mail addresses of the recipients and senders as well as other data (meta-communication data such as time, IP address, etc.) arising from e-mail communication and the content of the respective e-mails. We would like to draw your attention to the fact that e-mails are generally sent unencrypted. We therefore accept no responsibility for the transmission path of the e-mails between the sender and receipt on our server.

Data concerned:

  • Content data (e.g. posts, photos, videos)
  • Usage data (e.g. access times, web pages clicked on)
  • Communication data (e.g. information about the used device, IP address)

Persons concerned: Users of our Internet presence

Purpose of processing: Playing our Internet pages, ensuring the operation of our Internet pages Legal basis: Legitimate interest, Art. 6 para. 1 lit. f GDPR

Web host(s) commissioned by us:

Hetzner Online

service provider: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen
Website: https://www.hetzner.de/
Privacy policy: https://www.hetzner.de/rechtliches/datenschutz

Contact

If you contact us via e-mail, social media, telephone, fax, post, our contact form or in any other way and provide us with personal data such as your name, telephone number or e-mail address or provide further information about yourself or your request, we will process this data to answer your request within the framework of the pre-contractual or contractual relationship existing between us.

Data concerned:

  • Stock data (e.g. names, addresses)
  • Contact details (e.g. e-mail address, telephone number, postal address)
  • Content data (texts, photos, videos)
  • Contract data (e.g. object of contract, contract period)

Purpose of processing:communication and answering contact requests, office and organizational procedures

Verarbeitungszweck: Kommunikation sowie Beantwortung von Kontaktanfragen, Büro und Organisationsverfahren

Legal basis: Fulfilment of contract and pre-contractual inquiries, Art. 6 Para. 1 lit. b GDPR, legitimate interest, Art. 6 Para. 1 lit. f GDPR

Registration, login and user account

You have the possibility to register on our online medium to create a user account. For this purpose, it is necessary to enter personal data resulting from the input mask. The data requested there includes in particular your name, your e-mail address, a user name if applicable, and the password. This data will be stored and processed by us in order to set up a user account for you and to enable you to log in (repeatedly). The data can be changed or deleted by you at any time. The data will not be passed on to third parties unless this serves the technical and organizational processing of the existing user contract between us. To protect you and us from abusive registrations, we store the IP address assigned to you at the time of registration, as well as the date and time of registration.

Data concerned:

  • inventory data (e.g. names, addresses)
  • Contact details (e.g. e-mail address, telephone number, postal address)
  • Contract data (e.g. object of contract, contract period)
  • Payment data (e.g. bank details, invoices)
  • Content data (e.g. posts, photos, videos)
  • Usage data (e.g. access times, web pages clicked on)
  • Communication data (e.g. information about the used device, IP address)

Processing purpose: processing of contractual services, communication as well as answering contact requests, security measures.

Legal basis: Fulfilment of contract and pre-contractual inquiries, Art. 6 para. 1 lit. b GDPR, legal obligation, Art. 6 para. 1 lit. c GDPR, legitimate interest, Art. 6 para. 1 lit. f GDPR

Deletion: See the point: "When do we delete your data?". In addition, we would like to point out that we delete the data collected during registration as well as the content data stored in the account, subject to any conflicting legal retention obligations, as soon as you delete your account. We therefore ask you, if you want or need to access the content data stored in your account even after your account has been deleted, to save it otherwise before deleting the account.

Your comments or ratings

You have the opportunity to comment on our contributions, express your opinion or post content on the designated areas of our website. As we may be held liable for any infringing content of your comment (insult, abusive criticism, sedition, forbidden violence, etc.), we store your IP address for a period of 7 days in order to be able to determine your identity.

Legal basis: : Art. 6 para. 1 lit. f GDPR

Data concerned:

  • Stock data (e.g. names, addresses)
  • Content data (e.g. posts, photos, videos)
  • Usage data (e.g. access times, web pages clicked on)
  • Communication data (e.g. information about the used device, IP address)

Purpose of processing: performance of contractual obligations, communication and processing of inquiries, obtaining feedback, security measures.

Advertising by e-mail, mail or telephone

We process personal data for our advertising communication by e-mail, post or telephone. You can object to the receipt of our advertising measures at any time or revoke your previously given consent to receive our advertising communication at any time. In order to be able to prove in case of doubt that your consent has been given, we can store your data for up to 4 years after your objection/revocation. After your objection/revocation, we will no longer use your data for other purposes. If you want us to delete your data beforehand, we will do so after you have confirmed to us that you have originally given your consent.

Data concerned:

  • Contact data (e.g. e-mail, telephone number, postal address)
  • inventory data (e.g. names, addresses)

Persons concerned: Communication partner

Purpose of processing:Direct advertising (marketing) by e-mail, post or telephone

Legal basis: Consent, Art. 6 para. 1 lit. a GDPR, legitimate interest, Art. 6 para. 1 lit. f GDPR

Our online presence in social networks

We operate online presences within the social networks listed below. If you visit one of these sites, the data listed below will be collected and processed by the respective provider. As a rule, this data is collected for advertising and market research purposes and user profiles are created. In the user profiles, data can be stored independently of the device you use. This is especially the case if you are a member of the respective platform and logged in to it. The usage profiles can be used by the providers to display interest-related advertising to you. You have a right of withdrawal against the creation of user profiles. To exercise this right, you must contact the respective provider.

If you have an account with one of the providers listed below and are logged in when you visit our website, the respective provider may collect data about your usage behavior on our website. In order to prevent your data from being linked in this way, you can log out of the provider's service before visiting our website.

For which purpose and to what extent data is collected by the provider, you can see the respective data protection declarations of the providers, which are stated below.

We would like to point out that depending on the country of residence of the provider mentioned below, the data collected via his platform may be transferred and processed outside the area of the European Union. In this case there is a risk that the level of data protection prescribed by the GDPR may not be observed and that the enforcement of your rights may not be possible or may be made more difficult.

Data concerned:

  • Stock and contact data (e.g. name, address, telephone number, e-mail address)
  • Content data (e.g. posts, photos, videos)
  • Usage data (e.g. access times, web pages clicked on)
  • Communication data (e.g. information about the device used, IP address).

Processing purpose:communication and marketing, tracking and analysis of user behavior

Legal basis: Consent, Art. 6 Abs. 1 lit. a GDPR, legitimate interests Art. 6 Abs. 1 lit. f GDPR

Possible contradictions: For the respective possibilities of objection (opt-out) we refer to the following linked information of the providers. We maintain online presences on the following social networks:

Facebook

Service provider: Facebook Inc., 1 Hacker Way, Menlo Park, CA 94025, USA
Headquarters in the EU: Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Irland
Website: https://www.facebook.com/
Privacy policy: https://www.facebook.com/about/privacy/
Privacy policy for Facebook pages: https://www.facebook.com/legal/terms/information_about_page_insights_data

Instagram

Service provider: Instagram Inc., 1601 Willow Road, Menlo Park CA 94025, USA
Parent company: Facebook Inc., 1 Hacker Way, Menlo Park, CA 94025, USA
Headquarters in the EU: Facebook Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland
Website: https://www.instagram.com/
Privacy policy: http://instagram.com/about/legal/privacy

Twitter

Service provider: Twitter Inc., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA
Website: https://twitter.com/?lang=de
Privacy policy: https://twitter.com/de/privacy

Security measures

We also take technical and organizational security measures in accordance with the state of the art in order to comply with the provisions of the data protection laws and to protect your data against accidental or intentional manipulation, partial or complete loss, destruction or against unauthorized access by third parties.

Up-to-dateness and amendment of this data protection declaration

This data protection declaration is currently valid and has the status of September 2020. Due to changed legal or official requirements, it may become necessary to adapt this data protection declaration.

This data protection declaration was created with the help of the data protection generator of SOS Recht. SOS Recht is an offer of the Mueller.legal Rechtsanwälte Partnerschaft, based in Berlin.