Data Policy

Information about how we handle your personal data

Privacy Policy

1. Data Protection at a Glance

General Information

The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any data by which you can be personally identified. For detailed information on data protection, please refer to our privacy policy listed below this text.

Data Collection on This Website

Who is responsible for data collection on this website?

Data processing on this website is carried out by the website operator. You can find their contact details in the “Note on the Responsible Entity” section of this privacy policy.

How do we collect your data?

Your data is collected in part by you providing it to us, such as data entered into a contact form.

Other data is collected automatically or after your consent when visiting the website by our IT systems. This mainly includes technical data (e.g., browser, operating system, or time of page view). This data is collected automatically when you access this website.

What do we use your data for?

Part of the data is collected to ensure the proper functioning of the website. Other data may be used to analyze your user behavior. If contracts can be concluded or initiated via the website, the transmitted data is also processed for contract offers, orders, or other requests.

What rights do you have regarding your data?

You have the right at any time to receive free information about the origin, recipient, and purpose of your stored personal data. You also have the right to request the correction or deletion of this data. If you have given consent to data processing, you can revoke this consent at any time for the future. You also have the right, under certain circumstances, to request the restriction of processing of your personal data. Furthermore, you have the right to lodge a complaint with the competent supervisory authority.

You can contact us at any time about this or any other questions regarding data protection.

2. Hosting

We host the content of our website with the following provider:

Amazon Web Services (AWS)

Provider: Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, 1855 Luxembourg (hereinafter “AWS”).

When you visit our website, your personal data is processed on AWS servers. This may also involve the transfer of personal data to AWS’s parent company in the United States. The data transfer is based on EU Standard Contractual Clauses. Details can be found here:https://aws.amazon.com/de/blogs/security/aws-gdpr-data-processing-addendum/.

For more information, see AWS’s privacy policy:https://aws.amazon.com/de/privacy/?nc1=f_pr.

The use of AWS is based on Art. 6(1)(f) GDPR. We have a legitimate interest in a reliable presentation of our website. If consent has been obtained, processing is based solely on Art. 6(1)(a) GDPR and § 25(1) TDDDG, where the consent includes the storage of cookies or access to information on the user’s device (e.g., device fingerprinting) under the TDDDG. Consent can be revoked at any time.

The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the EU and the US that ensures compliance with European data protection standards for data processing in the US. Certified companies agree to adhere to these standards. For more information, visit:https://www.dataprivacyframework.gov/participant/5776.

Data Processing Agreement

We have signed a data processing agreement (DPA) with AWS. This legally required contract ensures AWS processes personal data of our website visitors only according to our instructions and in compliance with the GDPR.

3. General Information and Mandatory Disclosures

Data Protection

The operators of this website take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with legal data protection regulations and this privacy policy.

When you use this website, various pieces of personal data are collected. Personal data is any data that can identify you personally. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this is done.

Please note that data transmission over the Internet (e.g., when communicating by email) can have security gaps. A complete protection of data against access by third parties is not possible.

Note on the Responsible Entity

The responsible entity for data processing on this website is:

Gerhard Brühl
Ochsenstraße 56
76327 Pfinztal

Phone: +49 1520 8848161
Email: alibaba@alibaba-internet.com

The responsible entity is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data (e.g., names, email addresses, etc.).

Storage Duration

Unless a more specific retention period has been stated in this privacy policy, your personal data will remain with us until the purpose for data processing no longer applies. If you make a legitimate deletion request or revoke your consent to data processing, your data will be deleted unless we have other legally permissible reasons for storing your personal data (e.g., tax or commercial law retention periods); in the latter case, the data will be deleted after these reasons cease to apply.

Legal Basis for Data Processing

If you have consented to data processing, we process your personal data based on Art. 6(1)(a) GDPR or Art. 9(2)(a) GDPR if special categories of data are processed according to Art. 9(1) GDPR. In case of explicit consent to the transfer of personal data to third countries, data processing is also based on Art. 49(1)(a) GDPR. If you consent to the storage of cookies or access to information on your end device, data processing is also based on § 25(1) TDDDG. The consent can be revoked at any time. If your data is required for the performance of a contract or for pre-contractual measures, we process it on the basis of Art. 6(1)(b) GDPR. If we are legally obliged to process data, this is done based on Art. 6(1)(c) GDPR. Data processing can also be based on our legitimate interest according to Art. 6(1)(f) GDPR.

Recipients of Personal Data

We work with various external parties in the course of our business operations. Personal data is shared with external parties only when necessary for contract fulfillment, when legally required (e.g., sharing with tax authorities), when based on a legitimate interest (Art. 6(1)(f) GDPR), or if another legal basis permits it. In the case of data processors, we share personal data only based on a valid processing agreement.

Withdrawal of Your Consent

Many data processing operations are only possible with your explicit consent. You can revoke your previously given consent at any time. The legality of the data processing carried out before the revocation remains unaffected.

Right to Object to Data Collection in Special Cases and to Direct Marketing (Art. 21 GDPR)

If data processing is based on Art. 6(1)(e) or (f) GDPR, you have the right to object to the processing of your personal data at any time for reasons arising from your particular situation. This also applies to profiling based on these provisions.

If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms or if the processing serves to assert, exercise, or defend legal claims (Art. 21(1) GDPR).

If your personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of your personal data for such marketing. This also applies to profiling to the extent that it is related to such direct marketing. If you object, your personal data will no longer be used for direct marketing purposes (Art. 21(2) GDPR).

Right to Lodge a Complaint with the Supervisory Authority

In the event of violations of the GDPR, affected persons have the right to lodge a complaint with a supervisory authority, especially in the member state of their habitual residence, workplace, or the place of the alleged violation. This right exists without prejudice to any other administrative or judicial remedies.

Right to Data Portability

You have the right to receive data that we process based on your consent or in fulfillment of a contract in a commonly used, machine-readable format and to have this data transmitted to a third party where technically feasible.

Access, Rectification, and Deletion

Within the framework of applicable laws, you have the right to access your stored personal data, its origin and recipients, and the purpose of data processing free of charge. You also have the right to rectification or deletion of this data.

Right to Restriction of Processing

You have the right to request restriction of the processing of your personal data. You may contact us at any time for this. The right to restrict processing exists in the following cases:

If processing has been restricted, such data may only be processed – apart from storage – with your consent or for the establishment, exercise, or defense of legal claims or to protect the rights of another natural or legal person or for important public interest reasons of the EU or a Member State.

SSL or TLS Encryption

This site uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content, such as orders or inquiries that you send to us as the site operator. You can recognize an encrypted connection by the browser’s address line changing from “http://” to “https://” and by the lock symbol in your browser bar.

When SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.

Objection to Advertising Emails

We hereby object to the use of contact data published as part of the imprint obligation for sending unsolicited advertising and information materials. The operators of this site expressly reserve the right to take legal action in the event of unsolicited advertising, such as spam emails.

4. Data Collection on This Website

Cookies

Our websites use so-called “cookies.” Cookies are small data packets that do not cause any damage to your device. They are either stored temporarily for the duration of a session (session cookies) or permanently (persistent cookies). Session cookies are automatically deleted after your visit. Persistent cookies remain stored until you delete them or your web browser deletes them automatically.

Cookies can be set by us (first-party cookies) or by third parties (third-party cookies). Third-party cookies allow certain services from third-party companies to be integrated within websites (e.g., cookies for processing payment services).

Cookies have various functions. Many cookies are technically necessary, as certain website functions would not work without them (e.g., the shopping cart or video display). Other cookies are used to evaluate user behavior or for advertising purposes.

Cookies necessary for the electronic communication process, for providing specific functions requested by you (e.g., shopping cart), or for optimizing the website (e.g., audience measurement cookies) are stored based on Art. 6(1)(f) GDPR, unless another legal basis is specified. The website operator has a legitimate interest in the storage of necessary cookies for the technically error-free and optimized provision of services. If consent has been requested, processing is carried out exclusively based on this consent (Art. 6(1)(a) GDPR and § 25(1) TDDDG); consent can be revoked at any time.

You can configure your browser to inform you about the setting of cookies, allow cookies only in individual cases, exclude the acceptance of cookies for specific cases or in general, and activate the automatic deletion of cookies when closing the browser. Disabling cookies may limit the functionality of this website.

Details on the cookies and services used on this website can be found in this privacy policy.

Source: eRecht24