Data Protection Statement
Thank you for your interest in our website. With our privacy policy we inform you in detail about the handling of your data.
You have the following rights with respect to your personal data:
- Right of access (Art. 15 GDPR): You have the right to access the personal data concerning you. You may contact us at any time to request access to this information. If your request for access is not made in writing, please understand that we may ask you to provide proof of your identity to verify that you are the person you claim to be.
- Right to Rectification or Erasure (Art. 16 and Art. 17 GDPR): You have the right to have your personal data rectified or erased, to the extent permitted by law. As a general rule, we will only erase personal data once there is no longer a need for further storage. A need may exist, in particular, if the personal data is still required to fulfill contractual obligations, or to assess, grant, or defend against warranty and, where applicable, guarantee claims. In the case of statutory retention obligations, erasure may only be considered after the respective retention period has expired.
- Right to restriction of processing (Art. 18 GDPR): You have the right to restrict the processing of your personal data to the extent permitted by law.
- Right to be informed (Art. 19 GDPR): If you have exercised your right to rectification, erasure, or restriction of processing against the controller, the controller is obligated to notify all recipients to whom your personal data has been disclosed of such rectification, erasure, or restriction of processing, unless this proves impossible or involves disproportionate effort. You have the right to be informed by the controller about these recipients.
- Right to data portability (Art. 20 GDPR): You have the right to receive the personal data concerning you that you have provided to the controller in a structured, commonly used, and machine-readable format. You also have the right to transmit this personal data to another controller without hindrance from the controller to whom the personal data was provided, to the extent that you are legally entitled to do so.
- Objection to the processing of your personal data (Art. 21 GDPR):
a) If you have given consent to the processing of your personal data, you may withdraw it at any time. However, the processing of your personal data prior to your withdrawal remains valid.
b) To the extent that we process personal data as described in this Privacy Policy to safeguard our legitimate interests that prevail following a balancing of interests, you may object to such processing with effect for the future. If your personal data is processed for advertising and data analysis purposes, you may exercise this right at any time. If the processing is carried out for other purposes, you have a right to object only if there are grounds arising from your particular situation. After you exercise your right to object, we will no longer process your personal data for the specified purposes, unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or if the processing serves to assert, exercise, or defend legal claims.
c) You may notify us of your objection using the contact information provided in § 1. - Right to lodge a complaint with a supervisory authority: You also have the right to lodge a complaint with a data protection supervisory authority regarding our processing of your personal data. Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or the place of the alleged infringement, if you consider that our processing of your personal data violates the GDPR. The supervisory authority to which the complaint is submitted shall inform the complainant of the status and outcome of the complaint, including the possibility of a judicial remedy under Article 78 of the GDPR.
§ 3 Scope of Data Collection and Storage for Purely Informational Use
When you use our website for informational purposes only—that is, when you do not send us any information—we do not collect any personal data, with the exception of the data that your browser transmits to us in order to enable you to visit our website. When you view our website, we collect the following data, which is technically necessary for us to display our website to you and to ensure its stability and security: IP address, date and time of the request, time zone difference from Greenwich Mean Time (GMT), content of the request (specific page), access status/HTTP status code, amount of data transferred in each case, the website from which the request originates, browser, operating system and its interface, and the language and version of the browser software. This data is stored in log files to ensure the website functions properly. Additionally, the data helps us optimize the website and ensure the security of our IT systems. We analyze this data exclusively to improve our services and cannot use it to identify you personally. In this context, the data is not analyzed for marketing purposes. The legal basis is Article 6(1)(f) of the GDPR. The data is deleted as soon as it is no longer necessary to achieve the purpose for which it was collected. In the case of data collected for the provision of our website, this is the case once the respective session has ended. In the case of data stored in log files, this is the case after one month at the latest. Storage beyond this period is possible. In this case, the users’ IP addresses are deleted or anonymized so that the client making the request can no longer be identified.
To make your visit to our website more engaging, enable the use of certain features, and display relevant products, we use cookies on various pages in addition to the data mentioned above. This serves to protect our legitimate interests—which, following a balancing of interests, take precedence—in presenting our offerings in an optimized manner. Cookies are small text files that are automatically stored on your device. Some of the cookies we use are deleted at the end of the browser session, i.e., after you close your browser (so-called session cookies). Other cookies remain on your device and allow us to recognize your browser the next time you visit (persistent cookies). When you visit our website, you will be informed about the use of cookies for analytical purposes and asked to give your consent to the processing of the personal data used in this context. In this context, reference is also made to this Privacy Policy. The legal basis for data processing using cookies for analytical purposes is Article 6(1)(a) of the GDPR, provided the user has given their consent. Otherwise, the legal basis for the use of technically necessary cookies is Article 6(1)(f) of the GDPR. You can find the storage duration in the overview in your web browser’s cookie settings. You can configure your browser to notify you when cookies are set and decide individually whether to accept them, or to exclude the acceptance of cookies in specific cases or generally. Each browser differs in how it manages cookie settings. This is described in the help menu of each browser, which explains how you can change your cookie settings. If you do not accept cookies, the functionality of our website may be limited.
§ 6 Collection, Processing, Use, and Disclosure of Personal Data
In addition to simply browsing our website, we offer various services that you can use if you are interested. To do so, you will generally need to provide additional personal data, which we use to provide the respective service and to which the aforementioned data processing principles apply
- Contact us by email or through our contact form
When you contact us via email or through the contact form on our website, we will store the email address you provide and—if you voluntarily provide them—your last name, first name, message, and any files you submit via the form in order to respond to your questions and messages. In the case of contact via email, this also constitutes the necessary legitimate interest in processing the data provided. The other personal data processed during the submission process and voluntarily provided in the contact form serves to prevent misuse of the form(s) and to ensure the security of our IT systems. The legal basis for processing data transmitted via email or through the contact form is Article 6(1)(f) of the GDPR. If the purpose of contacting us via email or the contact form is to enter into a contract, the additional legal basis for processing is Article 6(1)(b) of the GDPR. The mandatory information required to respond to your questions and messages is marked separately; all other information is voluntary. The data will be deleted as soon as it is no longer necessary to achieve the purpose for which it was collected, or we will restrict processing if statutory retention obligations apply. For personal data entered in the contact form and data sent via email, this is the case once the relevant conversation with the user has ended. The conversation is considered concluded when it can be inferred from the circumstances that the matter in question has been definitively resolved. The personal data additionally collected during the submission process will be deleted no later than 7 days after submission. - Data processing by external service providers
In some cases, we use external service providers to process your data. These providers have been carefully selected and commissioned by us, are bound by our instructions, and are regularly monitored. As part of the processing carried out on our behalf, a third-party provider provides us with website hosting and display services. This service provider is headquartered in a country within the European Union or the European Economic Area. All data collected in connection with the use of this website or through the forms provided, as described in this Privacy Policy, is processed on its servers. The legal basis for this is Article 6(1)(b) of the GDPR. Processing on other servers takes place only within the scope described in this Privacy Policy. - Using the online application forms on our website
When you use the online application forms on our website, we do not yet process the data and information you enter into the forms. Only once you submit this information via the contact form on our website or by email do we process your data in accordance with Section 5(1) of this Privacy Policy. The legal basis for processing the data transmitted via email or through the contact form is Article 6(1)(f) of the GDPR. If the purpose of contacting us via email or the contact form is to enter into a contract, the additional legal basis for processing is Article 6(1)(b) of the GDPR. The mandatory fields required to respond to your questions and messages are marked separately; all other information is optional. We will delete the data or restrict its processing, subject to any applicable legal retention requirements, as soon as it is no longer necessary for the purpose for which it was collected. For personal data entered in the contact form and data sent via email, this is the case once the relevant conversation with the user has ended. The conversation is considered concluded when it can be inferred from the circumstances that the matter in question has been definitively resolved. The personal data additionally collected during the submission process will be deleted no later than 7 days after submission. - Customer Portal
a) We provide our customers with access to our customer portal on our website. For this personal area, we will provide you with a username (email address or contract number) and a password to log in. If you are logging in for the first time or have forgotten your password, please click on “Reset Password”. A link will then be sent to the email address you provided and on file with us, along with further instructions on how to reset your password.
b) In the customer portal, you can view, print, and download your invoices, contract documents, and proof of insurance. It is not possible to change the stored data.
c) We process the data you provided during registration to activate the customer account stored in the customer portal and to fulfill the contract with you, as all communication regarding the contract between you and us—including the transmission of documents, invoices, and important notices (such as price adjustment letters, etc.)—takes place exclusively via our customer portal (online member area), by making the documents available there (Art. 6(1)(b) GDPR). If no customer account has been created for you, we cannot activate a customer account for you in the customer portal.
d) Every login and every attempt to log in to the customer account is logged (IP address, time of access to the customer account, transmitted cookies, the requested website URL, and the URL of the website from which the file was requested, the stored cookies, the status of the access (file transferred, file not found, etc.), date and time of access, amount of data transferred during the connection, type and version of the browser used, language used, destination of an automatic browser redirection). Logging serves to identify and resolve technical malfunctions and, where there are concrete technical indications, also for the purposes of detecting and preventing misuse (Art. 6(1)(f) GDPR). - e) Your customer account will be deleted 90 days after the termination of your contractual relationship with us. The data accessible through the customer account will be processed and deleted in accordance with your contract with us. Logs of customer account access will be deleted 7 days after they are created.
f) Please log out after each use of the customer account to prevent, for example, unwanted data changes by subsequent users of your browser
We maintain up-to-date technical measures to ensure data security, particularly to protect your personal data from risks associated with data transmission and from unauthorized access by third parties. These measures are regularly updated to reflect the latest technological advancements. Your personal data is transmitted over the internet using SSL encryption, particularly during the ordering process. We secure our website and other systems through technical and organizational measures against loss, destruction, unauthorized access, alteration, or disclosure of your data by unauthorized persons. If you have a customer account, access to your account is only possible after entering your email address [as per Section 4: Email Address or Contract Number; see the note further up on this page] and your personal password. You should therefore always treat your login information as confidential, not share it with others, and close the browser window once you have finished communicating with us. This is especially important if you share a computer with other people.