Data privacy statement
The protection of your personal data is important to us. With this data privacy statement, we aim to explain to you in more detail what personal data we collect when you use our website and the Borondo City Stroll mobile app, and for what purpose the data is used. Where a section applies only to the website or only to the app, we say so expressly.
Contact information and responsible party
Responsible for the processing of your personal data is Borondo City Stroll. If you have any questions or suggestions regarding data protection, please feel free to email us at info@borondoapp.com.
Subject matter of data protection
The subject of data protection is personal data, i.e. all information relating to an identified or identifiable natural person.
Automated data collection
When accessing our website, your device automatically transmits data for technical reasons. The following data is stored separately from other data that you may transmit to us:
- Browser type and version
- Operating system
- Referrer URL
- URL of the loaded website
- The latency of the network connection
- Date and time of the server request
- Your IP address
We save this data for the following purposes:
Ensuring the security of our IT systems, for example, to prevent
specific attacks on our systems and to identify attack patterns.
Ensuring the proper operation of our IT systems, for example if errors
occur that we can only remedy by storing the IP address.
To enable criminal prosecution, security or legal prosecution if there
are specific indications of criminal offenses.
Your IP address is only saved for a period of 90 days. In this case, the
processing takes place on the basis of our predominant legitimate
interests mentioned above.
Registration data
To be able to use all functions of Borondo City Stroll, you must register. For this you have to provide the following mandatory information:
- Email address
- Username
- Password
Alternatively, you can log into Borondo City Stroll using your Google or Apple account. Doing so means we will receive the following information from the Google/Apple corporation:
- Name
- Email address
- An authorisation token
Your registration data is necessary in order for Borondo City Stroll to create a user account for you. This is also used to activate and manage your account and to allow you to use all the features of the Borondo City Stroll application. In this way, you opt-in to a (free) user contract which allows us to store the data (according to Art. 6 Para. 1 lit. b GDPR).
In order to conclude the contract, you have to provide us with this data. However, you are neither contractually nor legally obliged to conclude the contract and thus to provide the data. In addition, you can provide further voluntary information as part of the registration, for example you can save a profile photo. This information is voluntary and not necessary to register you. Please note, however, that this information may be visible to other Borondo City Stroll users according to your settings. We collect this data in order to be able to provide you with the corresponding functions of our website and app, Art. 6 Para. 1 lit. b GDPR.
You may also provide further optional information in your profile, including a phone number, date of birth, gender, nationality or country, a profile photo and a cover photo. This information is voluntary and not necessary to create an account. Please note that some of this information (for example your name, photos and nationality) may be visible to other Borondo City Stroll users according to your settings. We collect this data in order to provide you with the corresponding functions of our application, Art. 6 Para. 1 lit. b GDPR.
When you log in to Borondo City Stroll, we also save your IP address for a short period of time in order to be able to detect and prevent possible attacks and mass misuse of logins to Borondo City Stroll (e.g. so- called brute force attacks) by blocking these IP addresses temporarily if necessary. The processing takes place in order to ensure the security of the processing according to Art. 32 GDPR and based on our legitimate interest in protecting us from misuse of our service (Art. 6 Para. 1 lit.f GDPR). Data is stored for a maximum of 90 days. It is subsequently anonymised.
Community functions
At Borondo City Stroll, you can interact with other users, for example by publishing personal Highlights, commenting, giving other tips or discussing with other users. You can also follow other users if you want to keep up to date with new posts from them.
The use of these functions is of course voluntary. If you use it, we collect the data you have entered in order to make it accessible to other Borondo City Stroll users in accordance with your settings and the function you use.
If you want, we can also inform you by push notification if there is any news about your published posts. You can manage which notifications you receive in your settings.
Your data is processed for these purposes in order to be able to provide you with the functions within the framework of your user contract (Art. 6 Para. 1 lit. b GDPR).
Push notifications and device identifiers
This section applies to the Borondo City Stroll mobile app. When you use the app, we collect technical identifiers that leave your device, including:
- A Firebase Cloud Messaging (FCM) push token
- Firebase installation / instance identifiers
- Other device or installation identifiers generated by Google Play services, Google Sign-In, Google Play Billing and Mapbox in order to provide their services
We use this data to deliver push notifications, keep you signed in, verify in-app purchases and operate maps. This data is collected because it is required for these functions (Art. 6 Para. 1 lit. b GDPR). It is shared with Google (Firebase, Google Sign-In, Google Play) and Mapbox as described in this statement. If you delete your account, we delete or invalidate the push token stored on our servers. Backup copies may be retained for up to 30 days as described in the section “Deletion of your data”.
Live Tracking
If you use Live Tracking, a feature of Borondo City Stroll, your location data will be sent to our API at regular intervals during the route recording. Your location data will be deleted after 28 days.
Your data is processed for the aforementioned purposes in order to be able to provide you with the functions as part of your user contract (Art. 6 Para. 1 lit. b GDPR).
Maps (Mapbox)
The Borondo City Stroll app uses Mapbox maps, a service provided by Mapbox, Inc., to display maps, places and routes. To provide map tiles, search and navigation-related functions, your device transmits to Mapbox:
- Precise location, if you have granted location permission
- Approximate location (including location derived from your IP address) if precise location is not available
- Technical device or installation identifiers and telemetry needed to operate the map SDK
This processing is necessary to provide the core map functions of the app (Art. 6 Para. 1 lit. b GDPR) and, where you have granted permission, based on that permission. Mapbox processes this data under its own privacy policy: https://www.mapbox.com/legal/privacy. Personal data may be transferred to the USA. Where applicable, transfers are based on the EU-U.S. Data Privacy Framework (Art. 45 GDPR) and/or standard contractual clauses (Art. 46 GDPR).
In-app purchases
If you purchase paid content in the Borondo City Stroll app (for example access to a city or a subscription), payments on Android are processed by Google Play (Google Ireland Limited / Google LLC) and payments on iOS are processed by Apple (Apple Distribution International Ltd. / Apple Inc.). You can find their privacy policies at https://policies.google.com/privacy and https://www.apple.com/legal/privacy/.
We do not collect or store your full payment card details. Google or Apple process the payment under their own responsibility. We receive confirmation that the purchase was completed, together with a purchase or transaction token and information needed to unlock the content in your account (for example the product purchased and your user ID). We process this information along with your name in order to complete the transaction you have made. The legal basis for processing is Art. 6 (1) (b) GDPR.
In order to conclude the purchase, you must complete the payment with Google or Apple. You are neither contractually nor legally obliged to make a purchase.
Requests Support
Direct inquiries via our contact details
If you send us inquiries by e-mail or by other means (e.g. by post), your details will be processed to process the enquiry. This includes:
- Your name
The time and date of your request and the other information you provide us with in your request Depending on how you contact us or the contact details you have provided, we may also process:
- Your email address
- Your address
Purpose and legal basis of processing
The legal basis for the processing is our legitimate interest (Art. 6 Para. 1 lit. f GDPR) in rapid communication in order to conduct the exchange you are seeking and to be able to process your request properly. In the case of inquiries in connection with an existing or future contractual relationship with us, processing is carried out to initiate and implement the respective contractual relationship, Art. 6 (1) (b) GDPR. In addition, we have a legitimate interest in the efficient management of our customer relationships, Article 6 (1) (f) GDPR.
Storage data
We store inquiries about contracts or of potential legal relevance during the general limitation period, i.e. three years from the end of the year in which we received your requests. We store all other inquiries for a period of 24 months. Your requests will then be deleted unless we are legally obliged to keep them for a longer period of time.
The storage takes place on the basis of our legitimate interest, the proper documentation of our business operations and the protection of our legal positions (Art. 6 Para. 1 lit. f GDPR). In the case of inquiries about contracts, the storage takes place to initiate and implement the respective contractual relationship (Art. 6 Para. 1 lit. b GDPR) and, if necessary, to fulfil legal obligations (Art. 6 Para.1 lit. c GDPR).
Security vulnerability reward program
If you have discovered a vulnerability on our website and in our services and report it to us, we will process your contact details as well as other information you have provided in order to receive and process your report and, if necessary, to ask you any questions. If your report is included in our bounty reward program and you qualify for a reward, we also need additional information from you in order to pay you the corresponding reward.
Please note that we may forward reports regarding vulnerabilities on service providers or third parties to them.
The legal basis for the processing of your personal data is Article 6 (1) (f) GDPR. We have a legitimate interest in receiving and processing your report to ensure the security and functionality of our website and services.
We store reports of potentially legal relevance during the general limitation period, i.e. three years from the end of the year in which we received your report. We store all other reports for a period of 24 months. Your report will then be deleted unless we are legally obliged to keep it for a longer period of time.
The storage takes place on the basis of our legitimate interest, the proper documentation of our business operations and the safeguarding of our legal positions (Art. 6 Para. 1 lit. f GDPR) and, if necessary, to fulfil legal obligations (Art. 6 Para.1 lit. c GDPR).
Newsletter
If you register with us, we will inform you about news about our services on the Borondo City Stroll platform about once a month.
In this case, the collection and processing of your personal data takes place due to our legitimate interest in promoting similar services to your user account with Borondo City Stroll (Art. 6 Para. 1 lit. f GDPR, § 7 Para. 3 UWG).
You can object to this at any time - even when registering - by deactivating the corresponding checkbox or by clicking on the link to unsubscribe in the respective emails.
For this purpose, we also use customer.io, a service provided by Peaberry Software Inc., 9450 SW Gemini Dr, Suite 43920, Beaverton, Oregon 97008-7105, USA (“ customer.io”). We use customer.io as a processor. Customer.io enables us to only send you news by email or push notification – depending on your selected preferences – that is relevant, of interest, and of use to you. So that we can tailor these notifications to your interests and provide you with the perfect personalized Borondo City Stroll experience – for example, to send you curated inspiration and ideas specific to you – we use data based on your use of Borondo City Stroll, your interactions with us, and the information saved in your user account. This includes:
Data that you actively provide us with, e.g.:
- User and display name
- Email address
- Notification settings (push notification, email)
Data that we obtain from your interaction within Borondo City Stroll, e.g.:
- Device information
- Information about your completed tours (finish time)
- Usage information (start time for a session)
- Community information (how many followers you have, and how many people you are following)
Customer.io also enables us to identify which of our communications are effective and which are not, e.g. whether our communication prompts you to save one of our suggested tours or explore it. We can then use this information to improve our notifications to you.
The usage takes place on the basis of our legitimate interest in being able to send you only news that is also relevant and of interest to you, in order to improve your user experience with our product, and so that you can use Borondo City Stroll more effectively to plan tours and explorations, Art. 6 Para. 1 lit. f GDPR.
Cookies and similar technologies
This section applies only to our website, not to the Borondo mobile app. We store so-called "cookies" and use cookie-like technologies to be able to offer certain functions of our website and to optimize the use of our pages. "Cookies" are small files that are stored on your end device with the help of your internet browser. Similar technologies can be, for example, pixels, scripts, local storage or other comparable technologies for storing information (hereinafter collectively referred to as “cookies”).
Necessary cookies
We set cookies, which are absolutely necessary for the operation and functionality of the website and the associated services, in accordance with Section 25 Paragraph 2 No. 2 of the Telecommunications and Digital Services Data Protection Act ("TDDDG") without your consent. This category includes cookies that ensure that the website is technically accessible and usable. In addition, these cookies ensure essential and basic functionalities of our website and the associated services. Specifically, we use cookies that are absolutely necessary for the following functions:
Cookies, which are required to save certain technical data during your visit to our website and the use of the associated services.
Cookies that determine whether you have logged in or are still logged in. In addition, we use cookies that save your chosen language and your preferred units (miles or meters).
Cookies that ensure that the cookie settings you have made are saved correctly.
Depending on the respective function of these cookies, these cookies are only stored for the duration of your visit (session cookies) or for a longer period of time, e.g. until you actively log out. Cookies for storing your chosen settings and the cookie settings you have made remain stored until the end of the browser session.
If personal data from these cookies are processed, the processing is carried out to ensure the following: That our website and the functions provided can be used by you. This is also our legitimate interest, Art. 6 Para. 1 lit. f GDPR
That your cookie selection, in particular your consent or non-disclosure to the use of cookies, is stored correctly, Art. 6 Para. 1 lit. c GDPR, § 25 TDDDG.
Cookies for analysis purposes
Additionally, we use cookies to analyse and evaluate your usage behaviour in accordance with Section 25 (1) TDDDG. This is only done on the basis of your consent (Article 6 (1) (a) GDPR).
These cookies are used to measure online traffic and analyse behaviour. They collect information about how you interact with our website, which pages you have visited, and which features of our website you have used. Your usage behaviour can be traced using a user ID. This enables us to better understand the use of our website and optimize it accordingly.
If personal data from these cookies is processed, this processing is also based on your consent.
If we use cookies on the basis of your consent (or the associated processing of your personal data is based on your consent), you can revoke your consent at any time via the "Privacy Settings" link. Alternatively, you can change your settings at any time. You can find the link in the footer of the website. The revocation of the consent does not affect the lawfulness of the processing carried out on the basis of your consent until the revocation.
These cookies remain stored on your end device for up to two years, unless you withdraw your consent before this period has expired.
Services relating to the cookies we use for analysis purposes
In this section, we explain the services that we use in the context of the cookies we use for analysis purposes in more detail:
Google Analytics
This section applies only to our website, not to the Borondo mobile app. With your permission, we use Google Analytics, a web analysis service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google").
Google Analytics collects pseudonymous data from you about the use of our website - including your abbreviated IP address- and uses cookies. Please note that Google transmits the information generated by the cookies about your use of the website (including your shortened IP address) to servers in the USA and shares this data within the group of companies and with other third parties. Here, too, personal data may be transferred to the USA and third countries for which there is no adequacy decision by the EU Commission. For data transfer to the USA, there is an adequacy decision by the EU Commission in accordance with Article 45 (1) GDPR for the EU-U.S. Data Privacy Framework, which serves as the basis for data transfer to certified companies and organizations in the USA. Apart from that, Google will use the standard contractual clauses approved by the EU Commission in accordance with Article 46 (2) (c) GDPR. Google will use this information to evaluate your use of the website for us, to create reports on the use of our website and to perform further analyses and evaluations related to the use of our website and internet use. Google can also link this data to other data about you, such as your search history, your personal account, the usage data of other devices and other data that Google has stored about you. Google may also transfer this information to third parties if required to do so by law (e.g. state authorities) or if third parties process this data on Google's behalf.
Your data will be stored by Google Analytics for a period of 14 months. After this period, the data will be deleted, and only aggregated statistics will be kept. For more information about how Google uses your data, see Google's privacy policy.
The use of Google Analytics is based on your consent (Art. 6 Para. 1 lit. a GDPR).
You can withdraw your consent at any time by clicking "Privacy Settings" at the bottom of the page. The revocation of your consent does not affect the legality of the processing carried out on the basis of your consent up to the time of revocation.
Google Firebase
We use Google Firebase, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google"). We use Google as a processor (cf. Art. 4 No. 8, 28 GDPR). Google Firebase provides services we need to operate the Borondo City Stroll app. Specifically, we use:
Firebase Authentication
We use Firebase Authentication to enable sign-in with Google and Apple. Google processes authentication tokens and related account data on our behalf so that we can create and manage your user account. The legal basis is Art. 6 Para. 1 lit. b GDPR (performance of the user contract).
Firebase Cloud Messaging
We use Firebase Cloud Messaging to send push notifications (for example about your account, routes or community activity). For this purpose, your device generates a push notification token (FCM token) and other technical installation identifiers. We send the push token to our servers when you sign in or sign out, and associate it with your user account so that we can address your device. These identifiers are required for app functionality and account management; they cannot be switched off while you use the app with an account. The legal basis is Art. 6 Para. 1 lit. b GDPR.
Google may process these technical identifiers on servers in the USA. For data transfer to the USA, there is an adequacy decision by the EU Commission in accordance with Article 45 (1) GDPR for the EU-U.S. Data Privacy Framework, which serves as the basis for data transfer to certified companies and organizations in the USA. Apart from that, Google uses the standard contractual clauses approved by the EU Commission in accordance with Article 46 (2) (c) GDPR. Further information: https://firebase.google.com/support/privacy.
Social Plugins
If you want, you can use social plugins to share the content of our website on social networks. We have provided a two-click solution: If you want to share content via such a plugin, you must first click on an icon of the corresponding social network. This click then unlocks the plug-in of the respective social network for the future.
Only then will various data be transmitted to the respective social network. This can include:
- Date and time of the visit to the website
- Browser used Operating system used
- URL of the website you previously visited (“referrer”) URL of the website you are on
- Your IP address
Processing your personal data as mentioned above for the purpose of integrating social plugins is done solely based on your consent in accordance with Art. 6 Para. 1 lit. a GDPR.
You can withdraw your consent by adjusting settings here or by clicking “Privacy Settings” at the bottom of the page. Withdrawing your consent does not affect the lawfulness of the processing carried out on the basis of your consent up until the moment you withdrew it.
If you are logged into the respective social network while visiting our site, the provider may recognize that you visited our site and assign the visit to your account. If you use the plugin functions (e.g. clicking the "Like" button, submitting a comment), this information will also be transmitted from your browser directly to the respective social network and saved there if necessary. The purpose and scope of the data collection and the further processing and use of the data by the networks can be found in the data protection information of the respective social network.
Location determination
If you use the Borondo City Stroll app and grant location permission, we collect your precise location (GPS) while you browse maps, view nearby cities and places, follow a route, or use navigation or Live Tracking. On Android, while a tour is active, location may also be processed through a foreground location service so that route guidance can continue if the screen is off or the app is in the background. You can deny or revoke location permission in your device settings; some map and route features will then be limited or unavailable.
If you do not grant precise location permission, we may still use your IP address to determine your approximate location so that we can show you maps and routes in your vicinity. This processing is carried out in accordance with Art. 6 Para. 1 lit. f GDPR, based on our legitimate interest in providing a product that is relevant to you. Precise location is processed on the basis of Art. 6 Para. 1 lit. b GDPR (to provide map and route functions you request) and, where required, your permission under applicable law.
Location data used only to display the map in the current session is not kept after the session ends, except where another section of this statement applies. If you use Live Tracking, your location data is sent to our API at regular intervals during the route recording and is deleted after 28 days, as described in the section “Live Tracking”. Location coordinates sent to Mapbox to load map tiles are processed by Mapbox as described in the section “Maps (Mapbox)”.
Integrated third-party content
We have also included third-party content on our website. This content is loaded from the servers of the respective providers, so that your end device transmits certain technically necessary data to the third- party provider. In particular, it is not excluded that these providers can take note of the IP address assigned to you. As far as personal data is processed, this is done on the basis of the data protection declarations of the respective third-party providers. The inclusion of your data is processed to allow us to display corresponding content and to offer necessary functions, as well as allowing us to operate our website more efficiently as long as this doesn't infringe on your own legitimate interests (Art. 6 para. 1 lit. f GDPR). We include the following third-party content:
Webhoster
We operate our website on the servers of our web host Amazon Web Services EMEA SARL, 38 avenue John F. Kennedy, L-1855, Luxembourg, which processes personal data on our behalf. We also store app content (including profile photos, cover photos and place images) using Amazon Web Services. Some storage may take place in the United States (for example Amazon S3). Where personal data is transferred to the USA, we rely on the EU-U.S. Data Privacy Framework (Art. 45 GDPR) and/or standard contractual clauses (Art. 46 GDPR).
Our social media presence
Our social media presence General information
We operate pages or profiles on different social media platforms. In this context, the processing of personal data described below takes place.
If you interact with us via our social media pages or our posts, we will collect and process the data you have provided, including your username and your profile photo (if applicable). The relevant processing takes place regularly on the basis of our legitimate interest in making the corresponding functions available on our social media pages (Art. 6 Para. 1 lit. f GDPR) and, if necessary, on the basis of your consent to the operator of the respective network (Art . 6 (1) (a) GDPR) or your contractual relationship with the operator (Art. 6 (1) (b) GDPR). Please also note that this content will be published on our relevant social media pages according to your account settings and may be accessible by anyone worldwide.
Further data processing by us can be carried out in order to be able to receive and process inquiries or messages via our social media pages (Art. 6 Para. 1 lit. b GDPR).
Uploaded content can be stored for an unlimited period of time. If you would like us to remove content you have uploaded to our social media site, please send us an email with your request to the contact details given under point 1.
In addition, the respective operators collect and process personal data from you under their own data protection responsibility when you visit our social media pages and/or interact with them or our contributions. This applies in particular if you are registered or logged in to the relevant social media
network. Even if you are not logged into a social media network, the operators collect certain personal data when you visit the site, such as unique identifiers that are linked to your browser or your device. Please note that this data may be merged across different platforms and services if they are operated by the same operator. Further information can be found in the data protection notices of the respective operators, to which we refer below.
Specifically, we operate the following social media presences:
Facebook Fanpage
For users outside of the USA and Canada, Facebook is operated by Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. For users in the USA and Canada, Meta Platforms Inc., 1601 Willow Road Menlo Park, CA 9402, USA, operates Facebook.
Even if you are not registered with Facebook and visit our Facebook fan page, Meta Platforms can collect pseudonymous usage data from you. You can find more information in the Meta Platforms data policy at https://de-de.facebook.com/about/privacy/ and at https://www.facebook.com/legal/terms/information\_about\_page\_insights\_data. In the data policy you will also find information about the setting options for your Facebook account.
Meta Platforms may share your data within the Meta group of companies and with other third parties. This can lead to a transfer of personal data to the USA and other third countries for which there is no adequacy decision by the EU Commission. For data transfer to the USA, there is an adequacy decision by the EU Commission in accordance with Article 45 (1) GDPR for the EU-U.S. Data Privacy Framework, which serves as the basis for data transfer to certified companies and organizations in the USA. Otherwise, Facebook Ireland will use the standard contractual clauses approved by the EU Commission in accordance with Article 46(2)(c) GDPR. You can also refer to the Meta Platforms Data Policy for more information.
In addition, together with Meta Platforms Ireland Limited, we are responsible for the processing of so- called insights data when you visit our Facebook fan page. With the help of this insight data, Meta Platforms Ireland Limited analyses the behaviour on our Facebook fan page and makes this data available to us in an anonymous form. To this end, we have entered into a joint data controllership agreement with Meta Platforms Ireland Limited, which you can view here. Among other things, Meta Platforms Ireland Limited undertakes the primary responsibility under the GDPR for the processing of Insights data and to fulfil all obligations according to all GDPR regulations regarding the processing of Insights data. The processing serves our legitimate economic interests in the optimization and needs-based design of our Facebook fan page, Art. 6 Para. 1 lit f. GDPR. Additionally, we also draw your attention to the following:
If you visit or like our Facebook page as a registered Facebook user, Meta Platforms Ireland Limited collects personal data from you. If you are not registered with Facebook and visit the Facebook page, Meta Platforms can collect pseudonymous usage data from you.
In detail, the following information is collected by Meta Platforms:
- Going to a page, post or video from a page
- Subscribing or unsubscribing to/from a page
- Liking or unlinking a page or post
- Recommending a page in a post or comment
- Commenting, sharing, or reacting to a page post (including how you react)
- Hiding a page post or reporting it as spam
- Clicking a link that leads to the page from another page on Facebook or from a website outside of Facebook Hovering over a page's name or profile picture to see a preview of the page's contents
- Clicking the website, phone number, "Get Directions" button, or any other button on a page
- Information about whether you are logged in from a computer or mobile device while visiting or interacting with a site or its content.
You can find more information in Meta’s privacy policy. This includes further information on how Meta Platforms uses your data when you like our Facebook page. Meta’s privacy policy: https://www.facebook.com/legal/terms/information_about_page_insights_data.
Provision of your data
You are neither legally nor contractually obliged to provide your personal data; furthermore, the provision of your personal data - unless expressly mentioned in the aforementioned clauses - is not necessary for the conclusion of a contract.
However, the provision of your personal data is necessary to a certain extent so that we can provide you with the functions on our website. In particular, the provision of your data is necessary so in order to: Effectively make use of the community functions
Process any requests/messages you submit to us
If it is necessary to provide your data, we will point this out to you when you enter it by marking it as a mandatory field. Providing further data is voluntary. In the case of required data, failure to provide this data means that we cannot provide you with the relevant functions of our website and cannot receive and process your inquiries or reports.
In other cases, non-provision may mean that we do not provide the relevant functions or not to the usual extent, or that we are only able to process your inquiries and reports to a limited extent.
Disclosure of your data
Your data will only be passed on beyond what is described in this data protection declaration to the following extent:
If it is necessary to clarify the illegal use of our website and services or for legal prosecution, personal data will be forwarded to external consultants (e.g. lawyers), the law enforcement authorities and, if necessary, to injured third parties. However, this only happens if there are concrete indications of illegal or abusive behaviour. A transfer can also take place if this serves to assert, exercise or defend claims. We are also legally obliged to provide information to certain public bodies upon request. These are criminal prosecution authorities, authorities that prosecute administrative offenses subject to fines and the financial authorities.
In addition, your personal data may also be passed on if we are exposed to other claims by third parties, which may include information about your data.
This data is passed on the basis of our legitimate interest in combating abuse, prosecuting criminal offenses and asserting, exercising or defending claims according to article 6 (1) (f) GDPR or on the basis of a legal obligation under article 6 Paragraph 1 lit. c GDPR.
For the provision of the services, we rely on contractually linked third-party companies and external service providers, so-called processors (cf. Art. 4 No. 8, 28 GDPR). In such cases, personal data is passed on to these processors in order to enable them to carry out further processing. These processors process personal data on our behalf and are strictly bound by instructions. In addition to the processing parties already mentioned in this data protection declaration, we also use the following categories of processors:
- IT service providers
- Cloud service providers
- Software service providers
As part of administrative processes and the organization of our operations, financial accounting and compliance with legal obligations (such as archiving), we disclose or transmit your data to financial administrations and consultants. These include tax consultants or auditors as well as other fee offices and payment service providers.
This data is transmitted on the basis of our legitimate interest in maintaining our business activities, performing our tasks, asserting, exercising or defending claims (according to Art. 6 (1) lit. f du RGPD) or on the basis of a legal obligation (according to Art. 6 Paragraph 1 lit. c du RGPD).
As part of the further development of our business, the structure of our company may change as a result of a change in legal form, establishment, acquisition or sale of subsidiaries, parts of companies or components. In such transactions, user information is shared with the part of the transferring company. Whenever personal data is passed on to third parties to the extent described above, we ensure that this is done in accordance with this data protection declaration and the relevant data protection laws. The transfer of personal data is justified by the fact that we have a legitimate interest in adapting our company’s form to fit economic and legal circumstances in accordance with Art. 6 Para. 1 lit. f GDPR. Transfer of data to third-party countries
We also process data in countries outside the European Economic Area ("EEA"), in so-called third-party countries, or transfer data to recipients in these third-party countries.
Insofar as your personal data is transferred beyond the cases described in this data protection declaration to recipients outside the European Economic Area, we transfer your data to third-party countries for which there is an adequacy decision by the EU Commission in accordance with Article 45 (1) GDPR.
If such an adequacy decision does not exist, we use the standard contractual clauses approved by the EU Commission in accordance with Article 46 (2) (c) GDPR when structuring the contractual relationships with recipients in third-party countries. You can request a corresponding copy of these standard contractual clauses as well as information on the additional measures that we have taken to ensure an appropriate level of data protection using the contact details given under point 1.
Automated decision making and visitor profiling
We do not use automation to make specific decisions in regard to profiling.
Deletion of your data
Unless otherwise stated, we will delete or anonymize your personal data as soon as it is no longer required for the purposes for which we collected or used it in accordance with the preceding paragraphs. As a rule, we store your personal data for the duration of the usage or contractual relationship via the website plus a period of 30 days in which we keep backup copies after the deletion. We will also keep your data if we are obliged to do so for legal reasons or if the data is needed for criminal prosecution or to secure, assert or enforce legal claims.
If you delete your user account, your profile will be completely and permanently deleted. However, we will keep backup copies of your data for a period of 30 days before they are finally deleted, provided that this data is no longer required for legal reasons or for criminal prosecution or to secure, assert or enforce legal claims.
We also keep your data for the following reasons:
If we are obliged to do so for legal reasons, Article 6 (1) (c) GDPR. Insofar as we are legally obliged to store it, we store your data for the period prescribed by law. Legal requirements for storage can result in particular from the retention periods of the German Commercial Code (HGB) or the Tax Code (AO). The retention period according to these regulations is usually between 6 and 10 years from the end of the year in which the corresponding process was completed.
If the data is required for a longer period of time for criminal prosecution or for the assertion, exercise or defence of legal claims. This is also our legitimate interest in accordance with Art. 6 Para. 1 lit. f GDPR.
Storage then takes place until the relevant process has been completed plus the statutory limitation period.
If data must be stored for legal reasons, processing will be restricted. The data is then no longer available for further use.
Your rights as a data subject
With regard to the processing of your personal data, you have the rights described below. To assert your rights, you can submit an application by post or email to the address given in Section 1 above.
Right to information
You have the right to receive information from us at any time on request about the personal data processed by us in the scope and under the conditions of Art. 15 GDPR and § 34 BDSG. To do this, you can submit an application by post or email to the above address.
Right to correct incorrect data
You have the right to request that we immediately correct your personal data if it is incorrect. For this, please contact the contact addresses given above.
Right to cancellation
You have the right, under the conditions described in Art. 17 GDPR and § 35 BDSG, to request that we delete your personal data. These requirements provide in particular a right to erasure if the personal data is no longer necessary for the purposes for which they were collected or otherwise processed, as well as in cases of unlawful processing, the existence of an objection or the obligation to erase them under EU law or the law of the Member State to which we are subject. For the period of data storage, see also the section “Deletion of your data” in this data protection declaration.
Right to restriction of processing
You have the right to demand that we restrict processing in accordance with Art. 18 GDPR.
Right to data portability
You have the right to receive the personal data concerning you that you have provided to us in a structured, common, machine-readable format in accordance with Art. 20 GDPR. In order to assert your above right, please contact the above address.
Right to object
You have the right to object to the processing of your personal data at any time for reasons that arise from your particular situation on the basis of Art. 6 Para. 1 (GDPR). Your right to objection exists for reasons arising out of your particular situation, unless we can establish compelling legitimate grounds for processing that outweigh your interests, rights and freedoms or if the processing is necessary for the assertion and exercise of or defence against legal claims (Art. 21 (1) GDPR). If we process your personal data for direct marketing purposes, including profiling, you have the right to object to this processing. After your objection, we will stop processing.
Unless otherwise stated in this data protection declaration, please use the contact addresses given in Section 1 above to assert your abovementioned right.
Right to complain
You have the right to contact a supervisory authority of your choice in the event of complaints.
Data processing when exercising your rights
Finally, we would like to point out that we process the personal data transmitted by you when you exercise your rights in accordance with Article 7 (3) sentence 1 GDPR and Articles 15 to 22 GDPR for the purpose of implementing these rights and to provide evidence of this and, if necessary, to defend legal positions. The processing of your data to fulfil your rights as a data subject is based on the legal basis of Art. 6 (1) (c) GDPR in conjunction with Art. 15 to 22 GDPR and Section 34 (2) BDSG. Insofar as we process the personal data for the purposes of legal defence, this is also our legitimate interest, Art. 6 Para. 1 lit. f GDPR.
For the sake of completeness, we would like to point out that any personal data in connection with requests to exercise your rights to fulfil the legal documentation obligations in accordance with GDPR (and
in particular to prove the timely response to your request) is stored for the duration of the regular limitation period of three years, beginning with the end of the year in which your application was finally processed by us.
The legal basis for storage is Art. 6 (1) (f) GDPR. It is in our legitimate interest to provide and document the aforementioned evidence.
This personal data will be blocked and will not be processed for other purposes, unless the processing is necessary for the establishment, exercise or defence of legal claims. This is also in our legitimate interest, according to art. 6 Para. 1 lit. f GDPR.
You are neither contractually nor legally obliged to provide your personal data, but we can refuse to fulfil your request to exercise your rights as a data subject in accordance with Art. 12 Para 2 when you do not provide the required data.