Privacy Notice
The security and protection of your data is of particular concern to us.
General Information
The following information provides a simple overview of what happens to your personal data when you visit our website. Personal data is all data with which you can be personally identified. Detailed information on the subject of data protection can be found in our privacy policy listed below this text.
Data collection on our website
Who is responsible for data collection on this website?
Data processing on this website is carried out by the website operator. Their contact details can be found in the legal notice of this website.
How do we collect your data?
Your data is collected on the one hand by you providing it to us. This may, for example, be data that you enter in a contact form. Other data is automatically collected by our IT systems when you visit the website. This is primarily technical data (e.g. internet browser, operating system or time of the page request). This data is collected automatically as soon as you enter our website.
What do we use your data for?
Some of the data is collected to ensure error-free provision of the website. Other data may be used to analyse your user behaviour.
What rights do you have regarding your data?
You have the right at any time to receive free information about the origin, recipient and purpose of your stored personal data. You also have the right to request the correction, blocking or deletion of this data. For this purpose, as well as for further questions on the subject of data protection, you can contact us at any time at the address given in the legal notice. Furthermore, you have the right to lodge a complaint with the competent supervisory authority. For this purpose, as well as for further questions on the subject of data protection, you can contact us at any time at the address given in the legal notice.
Analysis tool and third-party tools
When visiting this website, your surfing behaviour may be statistically analysed. This is done primarily using so-called analysis programmes. Detailed information on these analysis programmes can be found in the following privacy policy.
General Information and Mandatory Disclosures
Data Protection
The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with statutory data protection regulations and this privacy policy.
When you use this website, various personal data is collected. Personal data is data with which you can be personally identified. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this is done.
We would like to point out that data transmission over the internet (e.g. when communicating by email) may have security vulnerabilities. Complete protection of data from access by third parties is not possible.
Notice regarding the responsible party
The responsible party for data processing on this website is:
The Grand Green Familux Resort
Tambacher Straße 2
98559 Oberhof
External data protection officer:
Sven Lenz
Datenschutzkanzlei Lenz GmbH & Co. KG
Bahnhofstraße 50
87435 Kempten Germany
For any questions regarding data protection or other data privacy matters, please feel free to send an email to the data protection team: datenschutz@familux.com
Revocation of your consent to data procressing
Many data processing operations are only possible with your express consent. You can revoke consent you have already given at any time. The legality of the data processing carried out until the revocation remains unaffected by the revocation.
Right to object to data collection in special cases and to direct marketing (art. 21 gdpr)
If data processing is carried out on the basis of Art. 6 para. 1 lit. e or f GDPR, you have the right at any time to object, on grounds relating to your particular situation, to the processing of your personal data; this also applies to profiling based on these provisions. The respective legal basis on which processing is based can be found in this privacy policy. If you object, we will no longer process your affected personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the assertion, exercise or defence of legal claims (objection pursuant to Art. 21 para. 1 GDPR).
If your personal data is processed for the purpose of direct marketing, you have the right to object at any time to the processing of personal data concerning you for the purpose of such marketing; this also applies to profiling insofar as it is associated with such direct marketing. If you object, your personal data will subsequently no longer be used for the purpose of direct marketing (objection pursuant to Art. 21 para. 2 GDPR).
Right to lodge a complaint with the competent supervisory authority
In the event of violations of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the member state of their habitual residence, their place of work or the place of the alleged violation. The right to lodge a complaint exists without prejudice to other administrative or judicial remedies. A list of data protection officers and their contact details can be found at the following link:
Responsible for Germany: www.bfdi.bund.de
Responsible for Austria: www.dsb.gv.at
Right to data portability
You have the right to have data that we process automatically on the basis of your consent or in fulfilment of a contract handed over to you or to a third party in a common, machine-readable format. If you request the direct transfer of the data to another controller, this will only be done insofar as it is technically feasible.
SSL and TLS encryption
This site uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content, such as orders or enquiries that you send to us as the site operator. You can recognise an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in your browser line. If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.
Information, blocking, deletion
Within the scope of the applicable legal provisions, you have the right at any time to free information about your stored personal data, its origin and recipients and the purpose of the data processing and, if applicable, a right to correction, blocking or deletion of this data. For this purpose, as well as for further questions on the subject of personal data, you can contact us at any time at the address given in the legal notice.
Right to restriction of processing
You have the right to request the restriction of the processing of your personal data. For this purpose, you can contact us at any time at the address given in the legal notice. The right to restriction of processing exists in the following cases:
If you dispute the accuracy of your personal data stored with us, we generally need time to verify this. For the duration of the review, you have the right to request the restriction of the processing of your personal data. If the processing of your personal data was or is being carried out unlawfully, you can request the restriction of data processing instead of deletion. If we no longer need your personal data, but you need it to exercise, defend or assert legal claims, you have the right to request the restriction of the processing of your personal data instead of deletion. If you have lodged an objection pursuant to Art. 21 para. 1 GDPR, a balancing of your interests and ours must be carried out. As long as it has not yet been determined whose interests prevail, you have the right to request the restriction of the processing of your personal data.
If you have restricted the processing of your personal data, this data – apart from its storage – may only be processed with your consent or for the assertion, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the European Union or a member state.
Objection to advertising emails
The use of contact data published within the scope of the imprint obligation for the purpose of sending advertising and information materials that have not been expressly requested is hereby objected to. The operators of the pages expressly reserve the right to take legal action in the event of the unsolicited sending of advertising information, such as spam emails.
Protection of minors
Persons who have not yet reached the age of 16 may not transmit personal data to us without the consent of their parents or guardians. Personal information may only be provided to us by persons who have not yet reached the age of 16 if the express consent of the parents or guardians is present, or if the persons have reached the age of 16 or are older. This data is processed in accordance with this privacy policy.
Data Collection on our Website
Cookies
Our internet pages use so-called "cookies". Cookies are small text files and do not cause any damage to your device. They are stored either temporarily for the duration of a session (session cookies) or permanently (permanent cookies) on your device. Session cookies are automatically deleted at the end of your visit. Permanent cookies remain stored on your device until you delete them yourself or an automatic solution is carried out by your web browser.
In some cases, cookies from third-party companies may also be stored on your device when you enter our site (third-party cookies). These enable us or you to use certain services of the third-party company (e.g. cookies for processing payment services).
Cookies have various functions. Many cookies are technically necessary, as certain website functions would not work without them (e.g. the shopping cart function or the display of videos). Other cookies are used to evaluate user behaviour or to display advertising.
Cookies that are required to carry out the electronic communication process (necessary cookies) or to provide certain functions desired by you (functional cookies, e.g. for the shopping cart function) or to optimise the website (e.g. cookies for measuring the web audience) are stored on the basis of Art. 6 para. 1 lit. f GDPR, unless another legal basis is specified. The website operator has a legitimate interest in storing cookies for the technically error-free and optimised provision of its services. If consent to the storage of cookies has been requested, the storage of the relevant cookies takes place exclusively on the basis of this consent (Art. 6 para. 1 lit. a GDPR); consent can be revoked at any time.
You can set your browser so that you are informed about the setting of cookies and only allow cookies in individual cases, exclude the acceptance of cookies for certain cases or in general, and activate the automatic deletion of cookies when closing the browser. If cookies are deactivated, the functionality of this website may be restricted.
Insofar as cookies are used by third-party companies or for analysis purposes, we will inform you of this separately within the scope of this privacy policy and, if necessary, request your consent.
Cookies in Detail
Google Analytics
This is a web analytics service. It allows the user to measure advertising ROI as well as track Flash, video, and social networking sites and applications. CONSENT: Used to determine whether the visitor has accepted the marketing category in the cookie banner. This cookie is necessary for the website's GDPR compliance. gat: Used by Google Analytics to throttle the request rate. ga: Registers a unique ID that is used to generate statistical data on how the visitor uses the website. gid: Registers a unique ID that is used to generate statistical data on how the visitor uses the website. r/collect: This cookie is used to send data to Google Analytics about the visitor's device and behaviour. It tracks the visitor across devices and marketing channels. _utma: Enables us to see how many visitors come to our website and how often. utmb: Records when a page is closed and is used in conjunction with utmc to measure how long visitors view individual pages of ours. utmc: Records when a page is closed and is used in conjunction with utmb to measure how long visitors view our pages. utmv – utmx – utmz: Tracks how visitors find our website – whether, for example, they come via a search engine or via links from other websites, or whether they have entered the web address directly. Also shows the order of pages that visitors access. utmt: Used to throttle the request rate.
Matomo
On this website, data is collected and stored for statistical and optimisation purposes using the web tracking tool Matomo. Matomo uses cookies, which are text files stored on your computer that enable us to analyse the use of the website. For this purpose, the usage information generated by the cookie (including your anonymised IP address) is transmitted to our server and stored. This function can be deactivated in the browser. The information generated by the cookie is used for statistical purposes and to improve the website and server. Your IP address is anonymised and cannot be traced back to you. Data is not passed on to third parties. MATOMO_SESSID: Used by the Piwik Analytics Platform to track page requests of the visitor during the session. tool-piwik-php: Used by the Piwik Analytics Platform to track page requests of the visitor during the session. pkses: Used by the Piwik Analytics Platform to track page requests of the visitor during the session. pkid: Collects statistics on user visits to the website, such as the number of visits, average time spent on the website and which pages were read.
Google Adwords
This service is used to track the effectiveness of personalised advertising content. CONSENTT: Used to determine whether the visitor has accepted the marketing category in the cookie banner. This cookie is necessary for the website's GDPR compliance. NID: Registers a unique ID that identifies the device of a returning user. The ID is used for targeted advertising.
Maps (Google)
This service is used to display map material on the website. NID: Registers a unique ID that identifies the device of a returning user. The ID is used for targeted advertising.
Server Log files
The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are: browser type and browser version, operating system used, referrer URL, hostname of the accessing computer, time of the server request, IP address. This data is not merged with other data sources. The collection of this data is based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimisation of its website – for this purpose, the server log files must be recorded.
Contact form
If you send us enquiries via the contact form, your details from the enquiry form, including the contact data you provided there, will be stored by us for the purpose of processing the enquiry and in the event of follow-up questions. We do not pass on this data without your consent.
The processing of this data is based on Art. 6 para. 1 lit. b GDPR, provided your enquiry is related to the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective processing of enquiries directed to us (Art. 6 para. 1 lit. f GDPR) or on your consent (Art. 6 para. 1 lit. a GDPR) if this has been requested.
The data you entered in the contact form will remain with us until you request us to delete it, revoke your consent to storage, or the purpose for data storage no longer applies (e.g. after completed processing of your enquiry). Mandatory statutory provisions – in particular retention periods – remain unaffected.
Enquiry by email, telephone or fax
If you contact us by email, telephone or fax, your enquiry including all resulting personal data (name, enquiry) will be stored and processed by us for the purpose of processing your request. We do not pass on this data without your consent.
The processing of this data is based on Art. 6 para. 1 lit. b GDPR, provided your enquiry is related to the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective processing of enquiries directed to us (Art. 6 para. 1 lit. f GDPR) or on your consent (Art. 6 para. 1 lit. a GDPR) if this has been requested.
The data you sent to us via contact enquiries will remain with us until you request us to delete it, revoke your consent to storage, or the purpose for data storage no longer applies (e.g. after completed processing of your request). Mandatory statutory provisions – in particular statutory retention periods – remain unaffected.
Regular guest club (guest club)
This website uses KunLeiSys Guest Club Software (regular guest area). The provider is GASTROpoint GmbH, Pommernstraße 17, 83395 Freilassing, Germany. KunLeiSys Guest Club Software is a service used to organise and manage the guest club, offers, loyalty points, occasion emails and newsletter dispatch.
You can register for the guest club on our website. The data entered for this purpose is used by us only for the purpose of using the respective offer or service. The mandatory information requested during registration must be provided in full. Otherwise, we will reject the registration. The processing of the data entered during registration is based on your consent (Art. 6 para. 1 lit. a GDPR). You can revoke any consent you have given at any time free of charge. You can do this via the unsubscribe link in the email or via the cancellation in the guest club.
The data you have stored with us for the purpose of the guest club will be stored by us until you unsubscribe and, after unsubscription and deletion of the guest club account, will be deleted from both our servers and the servers of GASTROpoint GmbH.
For important changes, such as changes in the scope of the offer or technically necessary changes, we use the email address provided or stored during registration or in your profile to inform you in this way. Statutory retention periods remain unaffected. We have concluded a data processing agreement with GASTROpoint GmbH and fully implement the strict requirements of the data protection authorities when using KunLeiSys Guest Club Software.
Analysis Tools and Advertising
Google Analytics
This website uses functions of the web analytics service Google Analytics. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
Google Analytics enables the website operator to analyse the behaviour of website visitors. In doing so, the website operator receives various usage data, such as page views, length of visit, operating systems used and the origin of the user. This data may be summarised by Google in a profile that is assigned to the respective user or their device.
Google Analytics uses technologies that enable the recognition of the user for the purpose of analysing user behaviour (e.g. cookies or device fingerprinting). The information collected by Google about the use of this website is generally transferred to a Google server in the USA and stored there.
The use of this analysis tool is based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in analysing user behaviour in order to optimise both its web offering and its advertising. If corresponding consent has been requested (e.g. consent to the storage of cookies), processing takes place exclusively on the basis of Art. 6 para. 1 lit. a GDPR; consent can be revoked at any time.
IP Anonymisation
We have activated the IP anonymisation function on this website. This means that your IP address is shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area before being transmitted to the USA. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, to compile reports on website activity and to provide other services related to website use and internet use to the website operator. The IP address transmitted by your browser in the context of Google Analytics is not merged with other Google data.
Browser Plugin
You can prevent the collection and processing of your data by Google by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=de. More information on the handling of user data in Google Analytics can be found in Google's privacy policy: https://support.google.com/analytics/answer/6004245?hl=de.
Demographic features in google analytics
This website uses the "demographic features" function of Google Analytics in order to be able to display suitable advertisements to website visitors within the Google advertising network. This allows reports to be created that contain statements about the age, gender and interests of page visitors. This data comes from interest-based advertising from Google as well as from visitor data from third-party providers. This data cannot be assigned to any specific person. You can deactivate this function at any time via the ad settings in your Google account or generally prohibit the collection of your data by Google Analytics as shown in the section "Objection to data collection".
Storage period
Data stored at Google at user and event level that is linked to cookies, user identifiers (e.g. User ID) or advertising IDs (e.g. DoubleClick cookies, Android advertising ID) is anonymised or deleted after 14 months. Details on this can be found at the following link: https://support.google.com/analytics/answer/7667196?hl=de
Matomo
This website uses the open source web analytics service Matomo. Matomo uses technologies that enable cross-site recognition of the user for the purpose of analysing user behaviour (e.g. cookies or device fingerprinting). The information collected by Matomo about the use of this website is stored on our server. The IP address is anonymised before storage.
The use of this analysis tool is based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in the anonymised analysis of user behaviour in order to optimise both its web offering and its advertising. If corresponding consent has been requested (e.g. consent to the storage of cookies), processing takes place exclusively on the basis of Art. 6 para. 1 lit. a GDPR; consent can be revoked at any time. The information collected by Matomo about the use of this website is not passed on to third parties.
Google Ads
The website operator uses Google Ads. Google Ads is an online advertising programme of Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
Google Ads enables us to display advertisements in the Google search engine or on third-party websites when the user enters certain search terms in Google (keyword targeting). Furthermore, targeted advertisements can be displayed based on the user data available at Google (e.g. location data and interests) (audience targeting). We as the website operator can evaluate this data quantitatively by, for example, analysing which search terms led to the display of our advertisements and how many advertisements led to corresponding clicks.
The use of Google Ads is based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in marketing its services and products as effectively as possible.
Google tag manager
For reasons of transparency, please note that we use Google Tag Manager. Google Tag Manager itself does not collect any personal data. It facilitates the integration and management of our tags. Tags are small code elements that serve to measure traffic and visitor behaviour, identify the impact of online advertising, or test and optimise our websites. Further information on Google Tag Manager can be found at: https://www.google.com/intl/de/tagmanager/use-policy.html
Google conversion tracking
This website uses Google Conversion Tracking. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
With the help of Google Conversion Tracking, Google and we can recognise whether the user has carried out certain actions. For example, we can evaluate which buttons on our website were clicked how often and which products were particularly frequently viewed or purchased. This information serves to create conversion statistics. We learn the total number of users who clicked on our advertisements and what actions they carried out. We do not receive any information that allows us to personally identify the user. Google itself uses cookies or comparable recognition technologies for identification purposes.
The use of Google Conversion Tracking is based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in analysing user behaviour in order to optimise both its web offering and its advertising. If corresponding consent has been requested (e.g. consent to the storage of cookies), processing takes place exclusively on the basis of Art. 6 para. 1 lit. a GDPR; consent can be revoked at any time. More information on Google Conversion Tracking can be found in Google's privacy policy: https://policies.google.com/privacy?hl=de.
Facebook pixel
Within our online offering, so-called "Facebook pixels" of the social network Facebook, which is operated by Facebook Inc., 1 Hacker Way, Menlo Park, CA 94025, USA, or, if you are resident in the EU, Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland ("Facebook"), are used. With the help of the Facebook pixel, it is possible for Facebook to determine the visitors to our offering as a target group for the display of advertisements, so-called "Facebook Ads". Accordingly, we use the Facebook pixel to display the Facebook Ads placed by us only to those Facebook users who have also shown an interest in our internet offering. That is, with the help of the Facebook pixel, we want to ensure that our Facebook Ads correspond to the potential interest of users and are not annoying. With the help of the Facebook pixel, we can furthermore track the effectiveness of the Facebook advertisements for statistical and market research purposes by seeing whether users were redirected to our website after clicking on a Facebook advertisement.
The Facebook pixel is integrated directly by Facebook when our websites are accessed and can save a so-called cookie, i.e. a small file, on your device. If you subsequently log in to Facebook or visit Facebook while logged in, the visit to our offering will be noted in your profile. The data collected about you is anonymous to us, so it does not allow us to draw any conclusions about the identity of the users. However, the data is stored and processed by Facebook, so that a connection to the respective user profile is possible. The processing of data by Facebook takes place within the framework of Facebook's data use policy. Accordingly, you can find further information on the functioning of the remarketing pixel and generally on the display of Facebook Ads in Facebook's data use policy: https://www.facebook.com/policy.php.
You can object to the collection by the Facebook pixel and the use of your data for the display of Facebook Ads. To do so, you can visit the page set up by Facebook and follow the instructions there on the settings for usage-based advertising: https://www.facebook.com/settings?tab=ads or declare your objection via the US website http://www.aboutads/choices/ or the EU website http://www.youronlinechoices.com/. The settings are platform-independent, meaning they are applied for all devices, such as desktop computers or mobile devices.
Facebook retargeting
We advertise for this website on the Facebook platform via Facebook (Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA). For this purpose, a cookie is set by Facebook when our website is visited, which enables interest-based advertising by means of a pseudonymous cookie ID and based on the pages you have visited. As a Facebook member, you can deactivate the retargeting cookie via this link. Alternatively, you can set your browser so that you are informed about the setting of cookies and can decide individually about their acceptance, or can exclude the acceptance of cookies for certain cases or in general. If cookies are not accepted, the functionality of our website may be restricted.
Use of the retargeting technology of the trade desk
This website uses the retargeting technology of The Trade Desk, Inc. ("The Trade Desk"). This function is used to present interest-based advertisements to visitors of the website within the framework of The Trade Desk advertising network. The visitor's browser stores so-called "cookies", text files that are stored on your computer and that make it possible to recognise the visitor when they access websites that belong to The Trade Desk advertising network. On these pages, the visitor can then be presented with advertisements that relate to content that the visitor has previously accessed on websites that use the retargeting technology of The Trade Desk. According to its own statements, The Trade Desk collects pseudonymised data in this process.
Should you nevertheless not wish to use this retargeting function, you can deactivate it. Please note that deactivation must be carried out separately for each browser or for each device using one of the following methods: via the AdChoices icon in the advertising banner, via youronlinechoices, directly at The Trade Desk here, on mobile apps and aboutads. Further information on the retargeting technology of The Trade Desk, the privacy policy of The Trade Desk and the opt-out options can be found at thetradedesk.
Newsletter
Newsletter data
In the context of sending the newsletter, your personal data that you have provided to us will be stored and processed insofar as this is necessary for sending the newsletter. By consenting to this newsletter, you agree that you will receive advertising in the form of banners or text advertisements from our company, but also from other companies (partner companies, cooperation partners) as part of the newsletter.
You can revoke your consent at any time. Simply write us an email at info@thegrandgreen.de or a letter to The Grand Green Familux Resort, Tambacher Straße 2, 98559 Oberhof. Details on how to unsubscribe can be found in the confirmation email and in each individual newsletter.
Further information about the company and data protection can be found as a PDF for download.
YES, I WOULD LIKE TO SUBSCRIBE TO THE NEWSLETTER of The Grand Green Familux Resort and the newsletter(s) of the companies associated with familux.com, which will inform me by email and post about current offers and promotions from familux.com. Furthermore, I expressly consent to my personal data being passed on for advertising and information purposes by email and post within familux.com and being stored, processed and used there. I have read the data protection notices and agree to them. I have the right to object to the collection, processing and use of my data by familux.com at any time with effect for the future.
Online Booking
samera
This page uses the booking system samera via an API. The provider is samera GmbH, Maria-Theresien-Straße 21, 6020 Innsbruck. When a page is accessed, your browser loads the required scripts into the browser cache in order to display the booking function correctly.
For this purpose, the browser you are using must connect to the servers of samera GmbH. This means that samera GmbH becomes aware that our website was accessed via your IP address. We would like to point out that we as the provider of the pages have no knowledge of the content of the transmitted data or its use by samera GmbH. The use of samera is in the interest of a booking process that is as simple and fast as possible. This represents a legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR.
Further information on samera can be found at www.samera.at or office@samera.at.
Type and purpose of data processing
The primary purpose of data processing is the handling of hotel bookings and enquiries.
Type of data
From end customers, personal data such as name, date of birth, telephone number, email address and address are processed. In addition, connection data such as cookie identifier, IP address and browser information ("user agent") are stored. From samera back-office users, the name, email address and login information are stored.
Categories of data subjects
From end customers, personal data such as name, date of birth, telephone number, email address and address are processed. In addition, connection data such as cookie identifier, IP address and browser information ("user agent") are stored. From samera back-office users, the name, email address and login information are stored.
Categories of data subjects
The following categories of data subjects are subject to processing: users of the samera back-office system as well as website visitors with active samera integration.
1. Duration of the agreement
This agreement is concluded for an indefinite period and ends automatically with the end of the samera contract. The possibility of extraordinary termination for good cause remains unaffected.
2. Obligations of the processor
(1) The processor undertakes to process data and processing results exclusively within the framework of the written instructions of the controller. Copies or duplicates of the data are not created without the knowledge of the controller. Excluded from this are backup copies, insofar as they are necessary to ensure proper data processing, as well as data that is required with regard to compliance with statutory retention obligations.
(2) If the processor receives an official order to disclose data of the controller, it shall – insofar as legally permissible – inform the controller immediately and refer the authority to the controller. Likewise, processing of the data for the processor's own purposes requires a written instruction.
(3) Maintaining confidentiality and secrecy: The processor declares bindingly that it has obligated all persons entrusted with data processing to maintain confidentiality before commencing their activities, or that these persons are subject to an appropriate statutory obligation of secrecy. In particular, the obligation of secrecy of the persons entrusted with data processing remains in effect even after the termination of their activities and departure from the processor.
(4) The processor declares bindingly that it has taken all necessary technical and organisational measures to ensure the security of processing in accordance with Art. 32 et seq. GDPR. Specifically, these are measures of data security and to ensure a level of protection appropriate to the risk with regard to the confidentiality, integrity, availability and resilience of the systems. Details can be found in the annex (technical and organisational measures).
(5) Duty to cooperate with regard to data subject rights: The processor takes the technical and organisational measures so that the controller can fulfil the data subject rights under Chapter III of the GDPR (information, access, rectification and erasure, data portability, objection, and automated decision-making in individual cases) within the statutory deadlines at any time and provides the controller with all the information necessary for this purpose. The processor may not correct, delete or restrict the processing of the data processed on behalf of the controller on its own authority, but only in accordance with documented instructions from the controller. If a corresponding request is directed to the processor and it can be seen that the applicant mistakenly considers the processor to be the controller of the data application operated by it, the processor must forward the request to the controller without delay and inform the applicant of this.
(6) Insofar as covered by the scope of services, the deletion concept, right to be forgotten, rectification, data portability and access must be implemented (ensured) directly by the processor in accordance with documented instructions from the controller.
(7) The processor supports the controller in complying with the obligations referred to in Art. 32 to 36 GDPR. These include data security measures, notifications of breaches of the protection of personal data to the supervisory authority, notification of the person affected by a breach of the protection of personal data, and data protection impact assessment.
(8) The processor is advised that it must create a record of processing activities pursuant to Art. 30 GDPR for the present commissioned processing.
(9) The processor is obliged, after termination of this agreement, to destroy all documents, processing results and data stocks that have come into its possession and that are related to the contractual relationship, on behalf of the controller. Documentation that serves as proof of proper and orderly data processing must be retained by the processor in accordance with the respective retention periods beyond the end of the contract.
(10) The processor must inform the controller without delay if it is of the opinion that an instruction from the controller violates data protection provisions of the Union or the member states.
3. Technical and organisational measures
The technical and organisational measures (TOMs) are subject to technical progress and further development. The processor is permitted to implement alternative adequate measures, provided that the security level of the defined measures is not undercut. Significant changes must be documented. Details can be found in the annex.
4. Location of data processing
All data processing activities are carried out exclusively within the EU or the EEA.
5. Sub-processors
The processor is authorised to engage the following companies as sub-processors:
- Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany – Type of activity: Server Hosting
- Amazon Web Services, Inc., 410 Terry Avenue North, Seattle WA 98109, United States – Type of activity: Server Hosting: only on systems within the EU
- Freshworks GmbH, Alte Jakobstraße 85/86, Hof 3, Haus 6, 10179 Berlin, Germany – Type of activity: Support System
The outsourcing to sub-processors or the change of the existing sub-processor is permissible, provided that: the processor notifies the controller of this in writing a reasonable time in advance, and the controller does not object in writing to the processor against the planned outsourcing, and the required agreements between the processor and the sub-processor are concluded in accordance with Art. 28 para. 4 GDPR. It must be ensured that the sub-processor enters into the same obligations that apply to the processor under this agreement. If the sub-processor does not comply with its data protection obligations, the processor shall be liable to the controller for compliance with the obligations of the sub-processor.
Payment providers
Processing of data (customer and contract data)
We collect, process and use personal data only insofar as it is necessary for the establishment, substantive definition or modification of the legal relationship (inventory data). This is done on the basis of Art. 6 para. 1 lit. b GDPR, which permits the processing of data for the fulfilment of a contract or pre-contractual measures. We collect, process and use personal data about the use of our internet pages (usage data) only insofar as this is necessary to enable the user to use the service or to invoice for it.
The collected customer data will be deleted after completion of the order or termination of the business relationship. Statutory retention periods remain unaffected.
Data transmission upon conclusion of contract for services and digital content
We only transmit personal data to third parties if this is necessary in the context of contract processing, for example to the credit institution entrusted with payment processing. Further transmission of the data does not take place, or only if you have expressly consented to the transmission. Your data will not be passed on to third parties without your express consent, for example for advertising purposes. The basis for data processing is Art. 6 para. 1 lit. b GDPR, which permits the processing of data for the fulfilment of a contract or pre-contractual measures.
DialogShift GmbH
DialogShift Communication Services on Our Website
Our website uses the communication services of DialogShift GmbH, Torstr. 201, 10115 Berlin. These include a chat application as well as additional communication channels such as email and telephone communication. The applications process and store data for the purpose of operating the communication services and responding to enquiries. Artificial intelligence is used to generate responses; all processing takes place exclusively on servers in the EU. No guest or user profiles are created. For the operation of the chat function, chat texts are stored and a cookie with a unique ID is set – this serves to recognise you as a customer. A cookie is a small text file that is stored locally on your device. This cookie is stored for 90 days from last use. You can disable the storage of cookies in your browser settings. The voluntary disclosure of, for example, name, email address or phone number via chat, telephone or email is optional. This personal data will be deleted after 90 days. The legal basis for setting the cookie is Art. 6(1)(a) GDPR and § 25(1) TTDSG (German Telecommunications-Telemedia Data Protection Act) based on your consent. The legal basis for the use of the communication services is our legitimate interest in efficient customer communication pursuant to Art. 6(1)(f) GDPR. DialogShift provides further information about the collection and use of data as well as your rights and options for protecting your privacy at dialogshift.com/privacy.