Data Protection Policy
For comprehensive information on how we collect, use, and safeguard your personal data, please see our Privacy Policy.
Privacy Policy
Introduction
With the following privacy policy, we would like to inform you about which types of your personal data (hereinafter also referred to as “data”) we process, for what purposes, and to what extent. This privacy policy applies to all processing of personal data carried out by us, both in the context of the provision of our services and in particular on our websites, in mobile applications, and within external online presences, such as our social media profiles (hereinafter collectively referred to as “online offering”).
The terms used are not gender-specific.
Stand: 20 October
Person responsible
Michaela Koch
Piercing & Tattoo Studio: Letzte Instanz
Frauenlobstraße 86
55118 Mainz
E-Mail-Address:
anfrage@letzteinstanz-mainz.de
Overview of processing
The following overview summarizes the types of data processed and the purposes of their processing and refers to the data subjects.
Types of data processed
- Contact details.
- Content data.
- Usage data.
- Meta/communication data.
Categories of data subjects
Users.
Purposes of processing
- Contact requests and communication.
- Feedback.
- Marketing.
- Provision of our online offering and user-friendliness.
- Information technology infrastructure.
Relevant legal bases
Below you will find an overview of the GDPR legal bases on which we process personal data. Please note that in addition to the GDPR regulations, national data protection regulations may apply in your or our country of residence or domicile. Should more specific legal bases apply in individual cases, we will inform you of these in the privacy policy.
- Legitimate interests (Article 6 (1) (f) GDPR) – Processing is necessary to protect the legitimate interests of the controller or a third party, unless the interests or fundamental rights and freedoms of the data subject which require protection of personal data prevail.
In addition to the data protection regulations of the General Data Protection Regulation, national data protection regulations apply in Germany. This includes, in particular, the law on protection against misuse of personal data during data processing (Federal Data Protection Act – BDSG). The BDSG contains, in particular, special provisions on the right to information, the right to erasure, the right of objection, the processing of special categories of personal data, processing for other purposes, and transmission and automated decision-making in individual cases, including profiling. Furthermore, it regulates data processing for the purposes of the employment relationship (Section 26 BDSG), particularly with regard to the establishment, implementation, or termination of employment relationships, as well as the consent of employees. Furthermore, state data protection laws of the individual federal states may apply.
Security measures
In accordance with the legal requirements, taking into account the state of the art, the implementation costs and the nature, scope, circumstances and purposes of the processing as well as the different probabilities of occurrence and the extent of the threat to the rights and freedoms of natural persons, we take appropriate technical and organizational measures to ensure a level of protection appropriate to the risk.
These measures include, in particular, ensuring the confidentiality, integrity, and availability of data by controlling physical and electronic access to the data, as well as the access, input, and transfer of data, ensuring availability, and segregation of data. Furthermore, we have established procedures that ensure the exercise of data subject rights, the deletion of data, and responses to data threats. Furthermore, we consider the protection of personal data right from the development and selection of hardware, software, and processes in accordance with the principle of data protection, through technology design, and through data protection-friendly default settings.
TLS encryption (https): To protect the data you transmit via our website, we use TLS encryption. You can recognize such encrypted connections by the prefix https:// in your browser’s address bar.
Provision of the online offer and web hosting
We process user data in order to provide them with our online services. For this purpose, we process the user’s IP address, which is necessary to transmit the content and functions of our online services to the user’s browser or device.
- Types of data processed: Usage data (e.g., websites visited, interest in content, access times); meta/communication data (e.g., device information, IP addresses); content data (e.g., entries in online forms).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing: Provision of our online services and user-friendliness; information technology infrastructure (operation and provision of information systems and technical devices (computers, servers, etc.).).
- Legal basis: Legitimate interests (Art. 6 (1) (f) GDPR).
Further information on processing procedures, methods and services:
- Provision of online services on rented storage space: To provide our online services, we use storage space, computing capacity, and software that we rent from a corresponding server provider (also called a “web host”) or obtain from other sources; legal basis: legitimate interests (Art. 6 (1) (f) GDPR).
- Email sending and hosting: The web hosting services we use also include the sending, receiving, and storing of emails. For these purposes, the addresses of the recipients and senders, as well as other information regarding the email sending (e.g., the providers involved), and the content of the respective emails are processed. The aforementioned data may also be processed for the purpose of detecting spam. Please note that emails are generally not sent encrypted over the Internet. Emails are generally encrypted during transport, but (unless a so-called end-to-end encryption method is used) not on the servers from which they are sent and received. We therefore cannot assume any responsibility for the transmission path of emails between the sender and the recipient on our server; legal basis: legitimate interests (Art. 6 (1) (f) GDPR).
- netcup: Services in the field of providing information technology infrastructure and related services (e.g. storage space and/or computing capacity); Service provider: netcup GmbH, Daimlerstrasse 25, D-76185 Karlsruhe, Germany; Legal basis: Legitimate interests (Art. 6 (1) (f) GDPR); Website: https://www.netcup.de/ ; Data protection declaration: https://www.netcup.de/kontakt/datenschutzerklaerung.php ; Data processing agreement: https://www.netcup-wiki.de/wiki/Zusatzvereinbarung_zur_Auftragsverarbeitung .
Presence in social networks (social media)
We maintain online presences within social networks and, in this context, process user data in order to communicate with the users active there or to offer information about us.
We would like to point out that user data may be processed outside the European Union. This could pose risks for users, for example, because it could make it more difficult to enforce their rights.
Furthermore, user data within social networks is generally processed for market research and advertising purposes. For example, user profiles can be created based on user behavior and the resulting interests of the users. These user profiles can then be used, for example, to place advertisements within and outside the networks that presumably correspond to the interests of the users. For these purposes, cookies are generally stored on users’ computers, in which the user behavior and interests are saved. Furthermore, data can also be stored in the user profiles regardless of the devices used by the users (particularly if the users are members of the respective platforms and are logged in to them).
For a detailed description of the respective processing methods and the options for objection (opt-out), we refer to the data protection declarations and information provided by the operators of the respective networks.
In the case of requests for information and the assertion of data subject rights, we would like to point out that these can be most effectively asserted with the providers. Only the providers have access to user data and can directly take appropriate measures and provide information. Should you still need assistance, please contact us.
- Types of data processed: Contact data (e.g., email, telephone numbers); content data (e.g., entries in online forms); usage data (e.g., websites visited, interest in content, access times); meta/communication data (e.g., device information, IP addresses).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing: contact requests and communication; feedback (e.g. collecting feedback via online form); marketing.
- Legal basis: Legitimate interests (Art. 6 (1) (f) GDPR).
Further information on processing procedures, methods and services:
- Facebook Pages: Profiles within the social network Facebook – We, together with Meta Platforms Ireland Limited, are responsible for collecting (but not further processing) data from visitors to our Facebook page (so-called “fan page”). This data includes information about the types of content users view or interact with, or the actions they take (see “Things you and others do and provide” in the Facebook Data Policy: https://www.facebook.com/policy ), as well as information about the devices used by users (e.g., IP addresses, operating system, browser type, language settings, cookie data; see “Device Information” in the Facebook Data Policy: https://www.facebook.com/policy ). As explained in the Facebook Data Policy under “How do we use this information?”, Facebook also collects and uses information to provide analytics services, so-called “Page Insights,” to page operators so that they can gain insights into how people interact with their pages and the content associated with them. We have entered into a specific agreement with Facebook (“Page Insights Information,” https://www.facebook.com/legal/terms/page_controller_addendum ), which specifically regulates the security measures Facebook must observe and in which Facebook has agreed to fulfill the rights of data subjects (i.e., users can, for example, submit information or deletion requests directly to Facebook). The rights of users (in particular the right to information, deletion, objection, and complaint to the competent supervisory authority) are not restricted by the agreements with Facebook. Further information can be found in the “Information about Page Insights” ( https://www.facebook.com/legal/terms/information_about_page_insights_data ); Service provider: Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland; Legal basis: Legitimate interests (Art. 6 (1) (f) GDPR); Website: https://www.facebook.com ; Privacy Policy: https://www.facebook.com/about/privacy ; Standard contractual clauses (guaranteeing data protection levels when processing in third countries): https://www.facebook.com/legal/EU_data_transfer_addendum ; Further information: Joint Controller Agreement: https://www.facebook.com/legal/terms/information_about_page_insights_data. Joint controllership is limited to the collection and transfer of data to Meta Platforms Ireland Limited, a company based in the EU. Further processing of the data is the sole responsibility of Meta Platforms Ireland Limited, in particular the transfer of data to its parent company, Meta Platforms, Inc., in the USA (based on the standard contractual clauses concluded between Meta Platforms Ireland Limited and Meta Platforms, Inc.).
Changes and updates to the privacy policy
We ask you to inform yourself regularly about the content of our privacy policy. We will adapt the privacy policy as soon as changes to the data processing we carry out make this necessary. We will inform you as soon as the changes require your cooperation (e.g., consent) or other individual notification.
If we provide addresses and contact information of companies and organizations in this privacy policy, please note that the addresses may change over time and ask you to check the information before contacting us.
Definitions of terms
This section provides an overview of the terms used in this privacy policy. Many of the terms are taken from the law and are defined primarily in Art. 4 GDPR. The legal definitions are binding. The following explanations, however, are intended primarily to facilitate understanding. The terms are sorted alphabetically.
- Personal data: “Personal data” means any information relating to an identified or identifiable natural person (hereinafter “data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. a cookie) or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
- Controller: The “controller” is the natural or legal person, public authority, agency or other body which alone or jointly with others decides on the purposes and means of processing personal data.
- Processing: “Processing” is any operation or set of operations performed on personal data or on sets of personal data, whether or not by automated means. The term is broad and encompasses virtually every handling of data, whether it involves collecting, analyzing, storing, transmitting, or erasing.
Created with free Datenschutz-Generator.de by Dr. Thomas Schwenke