Privacy Statement of Internethandel Reinart e.K.
Privacy statement according to the new ordinance of 25.05.2018
Unless otherwise stated below, the provision of your personal information is neither required by law nor by contract nor required to conclude a contract. You are not required to provide the data. A non-provisioning has no consequences. This applies only insofar as no other information is given in the subsequent processing operations.
"Personal Data" means any information relating to an identified or identifiable natural person.
Server log files
You can visit our websites without giving any personal information. Every time you access our website, usage data is transmitted through your Internet browser and stored in log data (server log files). These stored data include, for example, the name of the page accessed, the date and time of the retrieval, the amount of data transferred and the requesting provider.These data are used solely to ensure trouble-free operation of our website and to improve our offer. An assignment of this data to a specific person is not possible.
Collection and processing using the contact form
When using the contact form, we collect your personal data (name, e-mail address, message text) only in the scope provided by you. The data processing serves the purpose of establishing contact. By submitting your message, you consent to the processing of the transmitted data. Processing is based on Art. 6 (1) lit. a DSGVO with your consent.
You may revoke your consent at any time by notifying us without affecting the legality of the processing on the basis of the consent to revocation. We only use your e-mail address to process your request. Your data will then be deleted, unless you have consented to the further processing and use.
customer account
When opening a customer account, we collect your personal data in the scope indicated there. The purpose of data processing is to improve your shopping experience and simplify order processing. Processing is based on Art. 6 (1) lit. a DSGVO with your consent. You may revoke your consent at any time by notifying us without affecting the legality of the processing on the basis of the consent to revocation. Your customer account will be deleted afterwards.
Data collection when writing a comment
When commenting on an article or article, we collect your personal data (name, e-mail address, commentary text) only in the scope provided by you. The purpose of the processing is to allow comments and comments. By submitting the comment you consent to the processing of the transmitted data. Processing is based on Art. 6 (1) lit. a DSGVO with your consent.You may revoke your consent at any time by notifying us without affecting the lawfulness of the processing based on the consent to revocation. Your personal data will be deleted afterwards.
When your comment is published, only the name you specify will be published.
n addition, when the comment is submitted, your IP address will be stored for the purpose of preventing misuse of the comment function and ensuring the security of our information technology systems. By submitting the comment you consent to the processing of the transmitted data. Processing is based on Art. 6 (1) lit. a DSGVO with your consent. You may revoke your consent at any time by notifying us without affecting the lawfulness of the processing based on the consent to revocation. Your IP address will be deleted afterwards.
Collection, processing, use and processing of personal data for orders
When ordering, we collect and use your personal data only to the extent necessary to fulfill and process your order and to process your requests. The provision of the data is required for the conclusion of the contract. Non-provisioning means that no contract can be concluded. Processing is based on Art. 6 (1) lit. b DSGVO and is required to fulfill a contract with you.A transfer of your data to third parties without your express consent is not. Excluded from this are only our service partners, which we need to process the contractual relationship or service providers of which we serve in the context of a processing order. In addition to the recipients named in the respective clauses of this privacy policy, these include, for example, recipients of the following categories: shipping service providers, payment service providers, merchandise management service providers, order processing service providers, web hosting providers, IT service providers and dropshipping retailers. In all cases, we strictly adhere to the legal requirements. The amount of data transmission is limited to a minimum.
Use of the e-mail address for sending newsletters
Regardless of the contract, we use your e-mail address solely for our own advertising purposes to send you newsletters, if you have expressly consented to this. Processing is based on Art. 6 (1) lit. a DSGVO with your consent. You may revoke your consent at any time without affecting the legality of the processing carried out on the basis of your consent until your revocation. You can unsubscribe from the newsletter at any time using the corresponding link in the newsletter or by notifying us. Your e-mail address will then be removed from the mailing list.
Use of the e-mail address for sending direct mail
We use your e-mail address, which we obtained in connection with the sale of a good or service, for the electronic transmission of advertising for own goods or services, which are similar to those, which you already acquired with us, as far as this Use did not contradict. The provision of the e-mail address is required for the conclusion of the contract. Non-provisioning means that no contract can be concluded. Processing is based on Art. 6 (1) lit. f DSGVO from the legitimate interest in direct mail. You may object to this use of your e-mail address at any time by notifying us. The contact details for the exercise of the contradiction can be found in the imprint. You can also use the dedicated link in the promotional e-mail.There are no other costs than the transmission costs according to the basic tariffs.
Forwarding the e-mail address to shipping companies for information about the shipping status
We will pass on your e-mail address as part of the contract to the transport company, if you have explicitly agreed to this in the ordering process. The purpose of the disclosure is to inform you by e-mail about the delivery status. Processing is based on Art. 6 (1) lit. a DSGVO with your consent. You may revoke your consent at any time by notifying us or the transport company without affecting the legality of the processing carried out on the basis of the consent until the revocation.
Use of PayPal
All PayPal transactions are subject to the PayPal Privacy Policy. These can be found at https://www.paypal.com/webapps/mpp/ua/privacy-prev?locale.x=en_US.
Cookies
Our website uses cookies. Cookies are small text files that are stored in the Internet browser or the Internet browser on the computer system of a user. When a user visits a website, a cookie may be stored on the user's operating system. This cookie contains a characteristic string that allows the browser to be uniquely identified when the website is reopened. We use cookies for the purpose of making our offer more user-friendly, effective and secure. Furthermore, cookies enable our systems to recognize your browser even after a page change and offer you services. Some features of our website can not be offered without the use of cookies. For these, it is necessary that the browser is recognized even after a page break.
In addition, we use cookies on our website for the purpose of enabling an analysis of the surfing behavior of our site visitors.
Furthermore, we use cookies for the purpose of subsequently addressing site visitors on other websites with targeted, interest-based advertising.
Processing is based on 15 (3) TMG and Art. 6 (1) lit. f DSGVO from the legitimate interest in the above-mentioned purposes.
The data collected by you in this way will be pseudonymised by technical means. An assignment of the data to your person is therefore no longer possible. The data will not be stored together with any other personal information about you.
You have the right, for reasons arising from your particular situation, to object at any time to the processing of personal data concerning you, based on Art. 6 (1) of the GDPR.
Cookies are stored on your computer. Therefore, you have full control over the use of cookies. By selecting appropriate technical settings in your internet browser, you can prevent the storage of cookies and transmission of the data contained therein. Already saved cookies can be deleted at any time. We point out, however, that you may not be able to use all the features of this website in full.
Under the links below you can find out how to manage (among other things disable) cookies on the most important browsers:
- Chrome Browser: https://support.google.com/accounts/answer/61416?hl=en
- Internet Explorer: https://windows.microsoft.com/en-us/windows-vista/block-or-allow-cookies
- Mozilla Firefox: https://support.mozilla.org/en/kb/cookies-allow-and-dispose
- Safari: https://support.apple.com/en-us/guide/safari/manage-cookies-and-website-data-sfri11471/mac
Use of Google Analytics
We use the Google Analytics web analytics service provided by Google Inc. (1600 Amphitheater Parkway, Mountain View, CA 94043, USA, "Google"). Data processing is for the purpose of analyzing this website and its visitors. For this purpose, Google will use the information obtained on behalf of the operator of this website to evaluate your use of the website, to compile reports on website activity and to provide other services related to website activity and internet usage to the website operator. The IP address provided by Google Analytics as part of Google Analytics will not be merged with other Google data.
Google Analytics uses cookies that allow you to analyze the use of the website. The information generated by the cookies about your use of this website is usually transmitted to a Google server in the USA and stored there. IP anonymisation is activated on this website. As a result, your IP address will be shortened beforehand by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be sent to a Google server in the US and shortened there. Your data may be transmitted to the United States. There is an adequacy decision by the European Commission for data transfers to the US. Processing is based on Art. 6 (1) lit. f DSGVO from the legitimate interest in the needs-based and targeted design of the website. You have the right, for reasons arising from your particular situation, to object at any time to the processing of personal data concerning you, based on Art. 6 (1) of the GDPR.
You can prevent the storage of cookies by selecting appropriate technical settings of your browser software; however, please note that if you do this, you may not be able to use all the features of this website to the fullest extent possible. You may further prevent the collection by Google of the data generated by the cookie and related to your use of the website (including your IP address) as well as the processing of this data by Google by using the browser plug-in available under the following link. in download and install https://tools.google.com/dlpage/gaoptout?hl=en. o prevent Google Analytics tracking across devices, you can set an opt-out cookie. Opt-out cookies prevent future collection of your data when you visit this website. You must opt-out on all systems and devices used to make it work. If you click here, the opt-out cookie will be set: Disable Google Analytics .
For more information about Terms of Use and Privacy, please visit https://www.google.com/analytics/terms/en.html or https://www.google.com/intl/en/policies/
Using the Remarketing or "Like Audiences" feature of Google Inc.
We use the Remarketing or "Like Audiences" feature of Google Inc. on our website (1600 Amphitheater Parkway, Mountain View, CA 94043, USA; "Google"). This feature is for the purpose of analyzing visitor behavior and visitor interests.
Google uses cookies to carry out the analysis of the website usage, which forms the basis for the creation of interest-based advertisements. The cookies are used to record site visits and anonymous data on the use of the website. There is no storage of personal data of visitors to the website. If you visit another website on the Google Display Network, you'll see ads that are likely to include previously viewed product and information areas.
If necessary, your data will also be transmitted to the USA. There is an adequacy decision by the European Commission for data transfers to the US.
Processing is based on Art. 6 (1) lit. f DSGVO of legitimate interest in targeting visitors to the Website through advertising by showing personalized, interest-based advertising ads to visitors to the Provider's website when visiting other websites on the Google Display Network.
You have the right, for reasons arising from your particular situation, to object at any time to the processing of personal data concerning you, based on Art. 6 (1) of the GDPR.
You can permanently deactivate the use of cookies by Google by following the link below and downloading and installing the plug-in provided there:https://support.google.com/ads/answer/7395996?hl=en
Alternatively, you may opt out of third-party cookies by visiting the Network Advertising Initiative deactivation page athttps://www.networkadvertising.org/choices/ and implementing the opt-out information listed there.
For more information about Google Remarketing and its privacy policy, please visit: https://www.google.com/privacy/ads/
Using Google Adwords Conversion Tracking
We use the online advertising program "Google AdWords" on our website and, in this context, conversion tracking (visit evaluation). Google Conversion Tracking is an analytics service provided by Google Inc. (1600 Amphitheater Parkway, Mountain View, CA 94043, USA; "Google"). When you click on an ad served by Google, a conversion tracking cookie will be placed on your machine. These cookies have a limited validity, contain no personal data and are therefore not for personal identification. If you visit certain pages on our website and the cookie has not expired, Google and we may recognize that you have clicked on the ad and have been redirected to this page. Each Google AdWords customer receives a different cookie. Thus, there is no way that cookies can be tracked through the websites of advertisers.
The information obtained with the help of the conversion cookie is used to create conversion statistics. This tells us the total number of users who clicked on one of our ads and were redirected to a conversion tracking tag page. However, we do not receive any information that personally identifies users. Processing is based on Art. 6 (1) lit. f DSGVO from the legitimate interest in targeted advertising and the analysis of the impact and efficiency of this advertising.
You have the right, for reasons arising from your particular situation, to object at any time to the processing of personal data concerning you, based on Art. 6 (1) of the GDPR.
You can prevent the storage of cookies by selecting appropriate technical settings of your browser software. We point out, however, that in this case you may not be able to use all the functions of this website in full. You will not be included in the conversion tracking statistics.
You can also opt out of personalized advertising in Google Ads Ads Settings. For instructions, see https://support.google.com/ads/answer/2662922?hl=en. In addition, you may disable the use of third-party cookies by visiting the Network Advertising Initiative deactivation page at https://www.networkadvertising.org/choices/ and implementing the opt-out information listed there.
For more information and Google's privacy policy, please visit : https://www.google.de/policies/privacy/
Use of social plug-ins with Shariff
We use social networking plugins on our website. To keep control over your data, we use the privacy-protected "Shariff" buttons.
Without your express consent, no links will be made to the servers of the social networks and consequently no data will be transmitted.
"Shariff" is a development of the specialists of the computer magazine c't. It allows for more privacy on the network and replaces the usual "share" buttons on social networks. More information about the Shariff project can be found here https://www.heise.de/ct/artikel/Shariff-Social-Media-Buttons-mit-Datenschutz-2467514.html.
If you click on the buttons a pop-up window appears, in which you can log in with your data to the respective provider. Only after this active login by you a direct connection to the social networks is established.
By logging in, you give your consent to the transfer of your data to the respective social media provider. Among other things, both your IP address and the information on which of our pages you have visited are transmitted. If you are connected to one or more of your social network accounts at the same time, the collected information will also be associated with your corresponding profiles. You can only prevent this assignment by logging out of your social media accounts before visiting our website and before activating the buttons. The following social networks are integrated by means of the "Shariff" function.
For more information on the scope and purpose of the collection and use of data, as well as your related rights and ways to protect your privacy, see the linked privacy policy of the provider.
Google Inc. Google+ (1600 Amphitheater Parkway, Mountain View, California, 94043 USA)https://www.google.com/intl/de/+/policy/+1button.html
Facebook der Facebook Inc. (1601 S. California Ave, Palo Alto, CA 94304, USA) https://www.facebook.com/policy.php
Twitter der Twitter Inc. (795 Folsom St., Suite 600, San Francisco, CA 94107, USA) https://twitter.com/privacy
Information about job processing
1. Subject and duration of processing
1.1. The subject matter of the agreement is the rights and obligations of the parties in the context of the provision of services in accordance with the contract, terms of performance and terms and conditions, insofar as the processing of personal data by the contractor as processor for the client in accordance with Art. 28 DSGVO. This includes all activities that the contractor performs to fulfill the contract and that represent a processing of orders. This also applies if the order does not explicitly refer to this order processing agreement.
1.2. The duration of the processing corresponds to the term agreed in the order.
2. Nature and purpose of the processing
2.1. The type of processing includes all types of processing as defined by the GDPR to fulfill the contract.
2.2. Purposes of processing are all purposes required to provide the contracted services in terms of cloud services, hosting, Software as a Service (SaaS) and IT support.
3. Type of personal data and categories of data subjects
3.1. The type of processed data is determined by the client by the product selection, the configuration, the use of the services and the transmission of data.
3.2. The categories of data subjects determine the client by the product selection, the configuration, the use of the services and the transmission of data.
4. Responsibility and processing on documented instructions
4.1. Within the scope of this contract, the client is solely responsible for compliance with the statutory provisions of data protection laws, in particular for the lawfulness of the data transfer to the contractor and for the lawfulness of the data processing (? Responsible person? Within the meaning of Art. 4 No. 7 GDPR) , This also applies to the purposes and means of processing set out in this Agreement.
4.2. The instructions are initially determined by the main contract and can then be changed by the client in writing or in an electronic format (text form) by individual instructions (individual instruction). Verbal instructions are to be confirmed immediately in writing or in text form.Instructions that are not provided for in the contract are treated as a request for a change in performance. In the event of proposed changes, the contractor will inform the client of the effects that will have on the agreed services, in particular the possibility of providing services, deadlines and remuneration. If the implementation of the instruction is not reasonable for the contractor, the contractor is entitled to terminate the processing. Unacceptability exists in particular if the services are provided in an infrastructure that is used by several clients / clients of the contractor (shared services), and a change in processing is not possible or unreasonable for individual clients.
4.3. The contractually agreed data processing takes place exclusively in a member state of the European Union or in another Contracting State of the Agreement on the European Economic Area, unless otherwise agreed, eg on the product description of the commissioned service.
4.4. If an integral part of the contract is the registration of domains with registration offices located in a third country (outside the European Union and the European Economic Area), it is also agreed that the contractor will transfer personal data to these registries in compliance with the mandatory regulations.
4.5. The parties further agree that the contractor is entitled to transfer personal data - in compliance with the mandatory provisions for the provision of services in a third country. This is particularly the case if the subject of the contract is the service of a third party providing this service wholly or partly in a third country.
5. Rights of the client, obligations of the contractor
5.1. The contractor may process data of affected persons only within the framework of the order and the documented instructions of the client, unless there is an exceptional case within the meaning of Article 28 (3) (a) GDPR (obligation under the law of the European Union or of a Member State) , The contractor informs the client immediately if he considers that a directive violates applicable laws. The contractor may suspend the implementation of the instruction until it has been confirmed or modified by the client.
5.2. In the light of the nature of the processing, the contractor shall, as far as possible, assist the client with appropriate technical and organizational measures in order to fulfill the claims of the persons concerned in accordance with Chapter III of the GDPR. The contractor is entitled to demand appropriate compensation from the client for these services.
5.3. The contractor shall assist the contracting authority, having regard to the nature of the processing and the information at its disposal, in complying with the obligations set out in Articles 32 to 36 of the GDPR. The contractor is entitled to demand appropriate compensation from the client for these services.
5.4. The contractor warrants that the employees involved in the processing of the data of the client and other persons acting on behalf of the contractor are prohibited from processing the data outside the directive. Furthermore, the contractor guarantees that the persons authorized to process the personal data have committed themselves to confidentiality or are subject to an appropriate legal secrecy obligation. The same applies to the secrecy of telecommunications according to 88 TKG and - in knowledge of criminal liability - for the preservation of secrets of the professional secret holders according to 203 StGB. The obligation of confidentiality / secrecy persists even after the order has been completed.
5.5. The contractor informs the client without delay if he or she becomes aware of violations of the protection of personal data of the client.The contractor shall take the necessary measures to safeguard the data and to mitigate possible adverse consequences for the persons concerned.
5.6. The contractor guarantees the written appointment of a data protection officer who carries out his activity in accordance with Art. 38 and 39 GDPR. A contact option will be published on the website of the contractor.
5.7. Upon completion of the provision of the processing services, the contractor will, at the choice of the contracting authority, either delete or return the personal data, unless there is an obligation under Union or national law to retain the personal data or under any contractual arrangements something else results. If the client does not exercise this option, the cancellation is deemed agreed. If the client chooses the return, the contractor can demand a reasonable compensation.
5.8. If the data subject asserts claims for damages according to Art. 82 DSGVO, the contractor supports the client in defending the claims within the scope of his possibilities. The contractor may demand an appropriate remuneration for this.
6. Obligations of the client
6.1. The client must inform the contractor immediately and completely if he detects any errors or irregularities regarding data protection regulations during the execution of the order.
6.2. In the event of termination, the client undertakes to delete personal data before the termination of the contract, which he has stored in the services.
6.3. At the request of the contractor, the client appoints a contact person in data protection matters.
7. Measures for the safety of processing according to Art. 32 DSGVO
7.1. The contractor will take appropriate technical and organizational measures in his area of responsibility to ensure that processing takes place in accordance with the requirements of the GDPR and ensures the protection of the rights and freedoms of the data subject. In accordance with Art. 32 GDPR, the contractor takes appropriate technical and organizational measures to ensure the confidentiality, integrity, availability and resilience of the systems and services related to the processing in the long term.
7.2. The current technical and organizational measures are listed in Annex 2.
7.3. The contractor operates a procedure for the regular review of the effectiveness of the technical and organizational measures to ensure the security of processing in accordance with Art. 32 (1) lit. d) GDPR.
7.4. The contractor will adapt the measures taken over time to developments in the state of the art and the risk situation. A change in the technical and organizational measures taken is reserved to the contractor, provided that the level of protection under Art. 32 DSGVO is not exceeded.
8. Verification and verification
8.1. The contractor shall provide the principal with all the information necessary to prove compliance with the obligations laid down in Art. 28 GDPR and shall facilitate and contribute to inspections, including inspections, carried out by the contracting entity or another inspector appointed by the contracting authority. The contractor is entitled to demand a declaration of confidentiality from the client and its appointed auditor. The contractor agrees to the designation of an independent external auditor by the client, provided that the client provides the contractor with a copy of the audit report. Competitors of the client or persons working for competitors of the client may refuse the contractor as examiner.
8.2. As evidence of compliance with the obligations set out in Art. 28 DSGVO, the client is required to obtain this ISO 27001 certification. The current certificate is provided by the contractor on its website.
8.3. The client's inspection right has the objective of verifying compliance with the obligations incumbent on a processor in accordance with the GDPR and this contract. Proof of compliance with these obligations is provided by the certification referred to in the previous paragraph.Insofar as the customer asserts legitimate doubts on the basis of factual indications that these certifications are sufficient or correct, or if special incidents within the meaning of Art. 33 para. 1 DSGVO in connection with the execution of the order processing justify this for the client, he may Perform site controls. These can be carried out during normal business hours without disruption to the operation after registration, taking into account a reasonable lead time.
8.4. The contractor may request reasonable remuneration for information and assistance. The cost for the contractor through an inspection is generally limited to one day per calendar year.
8.5. If a data protection supervisory authority or another state or church supervisory authority of the client carries out an inspection, the above rules apply accordingly. A signing of a confidentiality obligation is not required if this supervisory authority is subject to a professional or legal secrecy, in which a violation under the Criminal Code is punishable.
9. Subcontractors (other processors)
9.1. The client grants the contractor the general permission to use other processors within the meaning of Art. 28 DSGVO for the fulfillment of the contract.
9.2. The currently used additional processors are listed in Annex 1. The client agrees to their use.
9.3. The contractor shall inform the contracting entity if he intends to change the consultation or replacement of other processors. The client may object to such changes.
9.4. The objection to the proposed change can only be raised against the Contractor for a material data protection right within a reasonable time after receipt of the information about the change. In the event of an objection, the contractor may choose to provide the service without the intended change or, if the performance of the service without the intended change is not reasonable for the contractor, the service affected by the change to the client within a reasonable time after receipt of the objection.
9.5. If the contractor places orders with other processors, it is the contractor's responsibility to transfer his data protection obligations under this contract to the other processor.
9.6. Additional processors within the meaning of this regulation are only those subcontractors who provide services directly related to the provision of the main service. It does not cover ancillary services related to telecommunications, printing / postal / transport services, maintenance and servicing, user services or the disposal of data media and other measures to ensure the confidentiality, availability, integrity and resilience of personal data, networks, services, Data processing systems and other IT systems. However, in order to ensure data protection and data security with respect to the data of the client, the contractor is obliged to take appropriate and legally compliant contractual agreements as well as control measures for such ancillary services.
10. Liability and damages
10.1. In the case of assertion of a claim for damages by a data subject pursuant to Art. 82 DSGVO, the parties undertake to support each other and to contribute to the clarification of the underlying facts.
10.2. The liability regulation agreed between the parties in the main contract for the provision of services also applies to claims arising from this agreement for the processing of orders and in the internal relationship between the parties for claims of third parties under Art. 82 DSGVO, unless expressly agreed otherwise.
11. Contract period, other
11.1. The agreement begins with the conclusion by the customer. It ends with the end of the last contract under the above-mentioned customer number. If a order processing still takes place after termination of this contract, the regulations of these agreements are valid until the actual end of the processing.
11.2. STRATO may change the Agreement at its reasonable discretion with reasonable notice. It applies number 1.4 Terms and Conditions.
11.3. In addition, the terms and conditions of the contractor, available at https://www.strato.de/agb/ . In the event of any contradictions, the provisions of this agreement for order processing shall apply to the provisions of the main contract. Should individual parts of this agreement be ineffective, this does not affect the validity of the remaining agreements.
11.4. The exclusive place of jurisdiction for all disputes arising from and in connection with this contract is Berlin. This is subject to any exclusive legal jurisdiction. This contract is subject to the statutory provisions of the Federal Republic of Germany.
11.5. If the data of the client are endangered by attachment or seizure, by a bankruptcy or settlement procedure or by other events or measures of third parties, the contractor shall inform the client immediately. The contractor will immediately inform all persons responsible in this connection that the sovereignty and the ownership of the data is exclusively the responsibility of the client as "responsible person".within the meaning of the GDPR.
Annex 1 to the Order Processing Agreement - Approved Subcontractors / Additional Processors
Stand 20180321
xxxx Tabellen xxxx
Annex 2 to the contract processing agreement - Technical and organizational security measures according to Art. 32 DSGVO
Version 1.0
1. Confidentiality (Article 32 (1) (b) GDPR)
1.1 Access control
Unauthorized persons should be denied access to rooms containing data processing equipment.
Definition of security areas
- Realization of an effective access protection
- Logging of the access
- Definition of persons with access rights
- Management of personal access authorizations
- Accompaniment of external personnel
- Monitoring the rooms
1.2 Access control
It must be prevented that data processing systems are used by unauthorized persons.
- Definition of the protection requirement
- Access protection
- Implementation of secure access procedures, strong authentication
- Implementation of simple authentication via username password
- Logging of access
- Monitoring critical IT systems
- Secure (encrypted) transmission of authentication secrets
- Disabling / Inactivity Blocking and Reset Access Blocking Process
- Prohibited memory function for passwords and / or form input (server / clients)
- Designation of authorized persons
- Management and documentation of personal authentication media and access permissions
- Automatic access lock and manual access lock
1.3 Access Control
Only the data for which access is authorized can be accessed. Data can not be read, copied, altered or removed without authorization during processing, use and after storage.
- Create an authorization concept
- Implementation of access restrictions
- Assigning minimal authorizations
- Administration and documentation of personal access rights
Avoidance of concentration of functions
1.4 Usage control
It must be ensured that data collected for different purposes can be processed separately.
- Data saving in handling personal data
- Separate processing of different data sets
- Regular use inspection and deletion
- Separation of test and development environment
1.5 privacy-friendly presets
- If data is not required to achieve the intended purpose, the technical default settings will be set in such a way that data will only be collected, processed, passed on or published by an action of the person concerned.
2. Integrity (Article 32 (1) (b) GDPR)
2.1 Transfer Control
The purpose of the tracking control is to ensure that personal data can not be read, copied, altered or removed during electronic transmission or during its transport or storage on data carriers, and that it can be verified and ascertained which places a transfer of personal data by means of data transmission is provided.
- Definition of receiving / transferring instances / persons
- Examination of the lawfulness of the transfer abroad
- Logging of transmissions according to logging concept
- Secure data transfer between server and client
- Backup of the transmission in the backend
- Secure transmission to external systems
- Risk minimization through network separation
- Implementation of security gateways at the network transfer points
- Hardening of the backend systems
- Description of the interfaces
- Implementation of machine-machine authentication
- Secure storage of data, including backups
- Secure storage on mobile media
- Introduction of a disk management process
- Process for collection and disposal
- Privacy-friendly extinguishing and destruction procedures
- Management of deletion protocols
2.2 Input control
The purpose of the input control is to ensure that it can be subsequently verified and ascertained whether and by whom personal data has been entered, changed or removed in data processing systems.
- Logging of the entries
- Documentation of the input permissions
3. Availability, resilience, disaster recovery
3.1 Availability and resilience (Article 32 (1) (b) GDPR)
- Fire protection
- Redundancy of the primary technology
- Redundancy of the power supply
- Redundancy of the communication connections
- Monitoring
- Resource planning and deployment
- Defense against systemic abuse
- Data backup concepts and implementation
- Regular check of emergency facilities
3.2 Disaster Recovery - Rapid recovery after incident Incident (Article 32 (1) (c) GDPR)
- Emergency plan
- Data backup concepts and implementation
4. Privacy Organization
- Definition of responsibilities
- Implementation and control of suitable processes
- Reporting and approval process
- Implementation of training measures
- Commitment to confidentiality
- Regulations for the internal distribution of tasks
- Consideration of function separation and assignment
- Introduction of a suitable representative regulation
5. Order control
The purpose of order control is to ensure that personal data processed on behalf of the customer can only be processed in accordance with the instructions of the client.
- Selecting other contractors for suitable warranties
- Conclusion of a contract processing agreement with other contractors
- Conclusion of an order processing agreement with STRATO
6. Procedure for regular review, evaluation and evaluation (Article 32 (1) (d) of the GDPR, Article 25 (1) GDPR)
- Information security management according to ISO 27001
- Process for the evaluation of technical and organizational measures
- Process Security incident management
- Conducting technical reviews
Duration of storage
After completion of the contract, the data are initially stored for the duration of the warranty period, then taking into account statutory, especially tax and commercial retention periods and then deleted after the deadline, unless you have agreed to further processing and use.
Rights of the person concerned
You are entitled to the following rights under Art. 15 to 20 GDPR if the legal prerequisites are met: Right to information, to correction, to cancellation, to limitation of processing, to data portability.
In addition, according to Art. 21 (1) GDPR, you are entitled to a right of objection to the processing based on Art. 6 (1) of the GDPR and to processing for the purpose of direct mail.
Contact us on request. The contact details can be found in our imprint.
Right of appeal to the supervisory authority
According to Art. 77 GDPR you have the right to complain to the supervisory authority if you believe that the processing of your personal data is not legal.
|
|