Privacy Policy
1. Data controller
Orleansstr. 24 | 81669 München | Germany
Amtsgericht München | HRB 295733 | VAT Number DE450302995
Represented by the managing directo: Franziska Ruppert | +49 89 5116 1504 | ruppert@cert4trust.de
2. Company Data Protection Officer
If you have any questions about our website, please do not hesitate to contact our Data Protection Officer.
E-Mail: m.mikulovic@data-security.one
Carl-Jordan-Straße 14
83059 Kolbermoor
Managing director: Dominik Mikulovic
https://data-security.one
3. Sources and data relating to the processing of personal data
- Personal details (name, address).
- Contact details (email, telephone numbers).
- Content data (text entries, photographs, videos).
- Usage data (webpages visited, interest in content, access times).
- Meta/communication data (device information, IP addresses).
Data is also stored in server log files, which are collected and automatically stored by the provider and are, for the most part, transmitted to us by your browser. These are:
- Referrer URL
- Hostname of the accessing computer
- Date and time of the server request
- Name of the requested file
- Page from which the relevant file was requested
- Web browser and operating system used
- (Full) IP address of the requesting computer
Amount of data transferred
4. Hosting
5. Purpose of processing and legal basis
Where necessary, we process your data beyond the actual fulfilment of the contract in order to safeguard our legitimate interests or those of third parties. We collect the data listed above to ensure that the website connects smoothly and to enable users to use it conveniently. The log file is used to assess system security and stability, as well as for administrative purposes. We also store your data for technical security reasons, in particular to defend against attempts to attack our web server.
- Provision of the online service, its functions and content,
- Responding to enquiries and communicating with users,
- Reviewing and optimising processes for needs analysis and direct customer engagement;
- Advertising or market and opinion research, e.g. through the use of cookies, provided you have not objected to the use of your data;
- Asserting legal claims and defending against legal disputes;
- Ensuring IT security and IT operations;
- Measures for business management and the further development of services and products.
Social media companies use your usage behaviour to create so-called user profiles, which are used to display advertisements. Cookies are usually stored on your computer for this purpose.
The lawfulness of the processing of personal data for specific purposes (e.g. disclosure of data to third parties, analysis of data for marketing purposes) is based on your consent, provided you have given it to us in accordance with Article 6(1)(a) of the GDPR. Consent that has been given may be withdrawn at any time.
Please note that withdrawal of consent only takes effect for the future. Any processing carried out prior to the withdrawal is not affected by this.
Where you have given your consent to social media companies for specific data processing, such processing is carried out on the legal basis of Article 6(1)(a) of the GDPR.
We are also subject to legal requirements. Where data is processed in this context, this is done exclusively on the basis of statutory provisions.
6. Relevant legal basis
- Consent, Article 6(1)(a) and Article 7 of the GDPR;
- to provide our services and carry out contractual measures, as well as to respond to enquiries, Article 6(1)(b) of the GDPR;
- to comply with legal obligations, Article 6(1)(c) of the GDPR;
- where the vital interests of the data subject or of another natural person require the processing of personal data, Article 6(1)(d) of the GDPR;
- for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller, Article 6(1)(e) of the GDPR;
- to safeguard legitimate interests, Article 6(1)(f) of the GDPR.
- The processing of data for purposes other than those for which it was collected is governed by the provisions of Article 6(4) of the GDPR.
- The processing of special categories of data (in accordance with Article 9(1) of the GDPR) is governed by the provisions of Article 9(2) of the GDPR.
7. Disclosure of data
Within the company, your data is only disclosed to those departments that require it to fulfil our contractual and legal obligations. Data may also be disclosed to data processors (Art. 28 GDPR) engaged by us for the purposes stated. These are companies in the categories of IT services, telecommunications, advisory and consultancy services, and sales and marketing.
When disclosing data to recipients outside the company, please note that we will only disclose your data if permitted or required by law, if we have your consent, or if we are authorised to provide such information. In this context, recipients of personal data may include, for example, public authorities and institutions (e.g. the Crown Prosecution Service, the police, supervisory authorities) where there is a legal or regulatory obligation to do so.
8. Data transferal to third countries
9. Cookies
Our website only sets cookies for the YouTube video – which are stored by the browser on your device and contain certain settings relating to the use of the website (e.g. for the current session) – once consent has been given via the Consent Manager. Where individual cookies implemented by us also process personal data, such processing is carried out in accordance with Article 6(1)(b) of the GDPR, either for the performance of a contract, or in accordance with Article 6(1)(f) of the GDPR to safeguard our legitimate interests in ensuring the best possible functionality of the website and a user-friendly and effective experience for visitors. Cookies serve to make our website more user-friendly, effective and secure. Cookies are small text files that are stored on your computer and saved by your browser. Most of the cookies we use are so-called session cookies, which are automatically deleted when you close your browser. Other cookies remain stored on your device until you delete them or their storage period expires. These cookies enable us to recognise your browser the next time you visit.
In some cases, cookies are used to simplify website processes by storing settings (e.g. retaining previously selected options).
You can configure your browser so that you are notified when cookies are set and can choose to allow cookies only on a case-by-case basis, block cookies in specific cases or generally, and enable the automatic deletion of cookies when you close your browser. If you disable cookies, the functionality of this website may be restricted.
You can object in general to cookies used for online marketing purposes via the US website http://www.aboutads.info/choices/ or the EU website http://www.youronlinechoices.com/.
You can also disable the storage of cookies in your browser settings. Please note that, in this case, you may not be able to use all the features of this website.
10. Friendly Captcha
We use Friendly Captcha to protect our website, and in particular our forms, against malicious automated access and spam. When you access protected areas, a connection is established with Friendly Captcha’s services, including global.frcapi.com. Friendly Captcha is designed to distinguish automated access from human input without the need to solve traditional image puzzles. In the course of using the service, technically necessary data such as connection, device and interaction data may be processed. Further information on data processing, the legal basis and, where applicable, the recipients of the data can be found in our Privacy Policy.
11. Matomo
We use Matomo to analyse and evaluate the usage of our website statistically. Matomo helps us to understand how visitors use our website, for example which pages are accessed and how users navigate through the site. For the purposes of this analysis, cookies are stored on your device and usage information is processed. As Matomo uses cookies in this configuration, it will only be activated once you have given your consent via the cookie settings. Consent that has been given may be withdrawn at any time with future effect. You can find detailed information on data processing, the retention period and your rights in our privacy policy.
12. Social Media Links to LinkedIn
In accordance with Article 26 of the GDPR, we are jointly responsible for data protection with LinkedIn. This is based on LinkedIn’s ‘Joint Controller Addendum’. You can view this via the following link:
https://legal.linkedin.com/pages-joint-controller-addendum
The link to our company’s LinkedIn page enables us to publish feeds and share content of interest to users directly via our presence on that platform. Data processing in connection with the operation of the profile page is therefore carried out on the basis of our legitimate interest in accordance with Article 6(1)(f) of the GDPR. Where LinkedIn obtains visitors’ consent to data processing (e.g. by ticking a checkbox or clicking a button), the legal basis for data processing is Article 6(1)(a) of the GDPR.
LinkedIn stores data until it is no longer required to provide the services and LinkedIn products, or until the visitor’s account is deleted. This is determined on a case-by-case basis and depends on criteria such as the type of data, the reasons for its collection and processing, and the relevant legal or operational retention requirements.
Further information on this and the available settings can be found on the following LinkedIn Support pages:
https://www.linkedin.com/help/linkedin/answer/125463/managecookie-preferences?lang=de
13. Blockchain Infrastructure
Cert4Trust enables the simple and secure verification of digital documents using blockchain technology, which is operated on behalf of Cert4Trust e.V. by its members.
By storing a unique digital fingerprint (hash) on a trusted blockchain, it is possible to verify at any time whether a document is authentic and unaltered – without any personal data being stored or processed in the process.
To provide this technology, Cert4Trust works with individual members of Cert4Trust e.V. as data processors. Processing is carried out in accordance with the requirements of the General Data Protection Regulation (GDPR), in particular Article 28 of the GDPR, within the framework of an existing data processing agreement (DPA).
The operators implement technical and organisational measures to ensure a high level of data protection and to carry out processing exclusively in accordance with Cert4Trust’s instructions.
The Cert4Trust solution helps to strengthen trust in digital evidence and reliably prevent tampering or attempts at fraud. If you have any questions regarding data processing or your rights as a data subject, you can contact our Data Protection Officer at any time.
14. Contact form and E-Mail requests
15. Administration, financial accounting, office organisation
16. Contractual services
17. Retention period for personal data
18. Your rights
In accordance with Article 15 of the GDPR, you have the right to request information about your personal data processed by us.
In accordance with Article 16 of the GDPR, you have the right to request the rectification of inaccurate personal data or the completion of incomplete personal data held by us without undue delay.
In accordance with Article 17 of the GDPR, you have the right to request the erasure of your personal data stored by us, unless processing is necessary for the exercise of the right to freedom of expression and information, for compliance with a legal obligation, for reasons of public interest, or for the establishment, exercise or defence of legal claims.
In accordance with Article 18 of the GDPR, you have the right to request the restriction of the processing of your personal data where you contest the accuracy of the data, where the processing is unlawful but you oppose its erasure, and where we no longer require the data but you need it to assert, exercise or defend legal claims, or where you have objected to the processing pursuant to Article 21 of the GDPR.
You have the right to receive the personal data you have provided to us in a structured, commonly used and machine-readable format, or to request that it be transmitted to another controller, insofar as this is technically feasible.
You may lodge a complaint with a supervisory authority in accordance with Article 77 of the GDPR. As a rule, you may contact the supervisory authority of the federal state in which we are based or, where applicable, that of your usual place of residence or place of work.
You may withdraw any consent you have already given in accordance with Article 7(3) of the GDPR. You also have the right to withdraw your consent to the processing of data at any time, with effect for the future. In the event of withdrawal, we will delete the relevant data without delay, unless further processing can be based on a legal basis that does not require consent. Withdrawal of consent does not affect the lawfulness of processing carried out on the basis of that consent prior to its withdrawal.
You may, on grounds relating to your particular situation, object at any time to the processing of personal data concerning you which is carried out on the basis of Article 6(1)(e) of the GDPR (data processing in the public interest) and Article 6(1)(f) of the General Data Protection Regulation (data processing based on a balancing of interests). This also includes profiling based on this provision within the meaning of Article 4(4) of the GDPR.
If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.
