PRIVACY PROTECTION

Rapunzel Naturkost GmbH

 

General


With the following information we would like to give you an overview of the processing of your personal data by us and your data protection rights when you visit our company website bionella.info/en. We will inform you separately about data processing when you visit our online shop, if you visit the Rapunzelwelt.de website, you will find further information on this in the data protection information there.

It is generally possible to use bionella.info without entering personal data. However, if you wish to make use of special services via our website or other options, it may be necessary to process personal data. If the processing of personal data is necessary and there is no legal basis for such processing, we generally obtain your consent.

As the responsible party, we always try to ensure the most complete possible protection of the personal data processed via this website using the latest technical and organizational measures, just as we attach great importance to security and data protection friendliness in our other processing activities. Nevertheless, Internet-based data transmissions can generally have security gaps, so that absolute protection against unauthorized access by third parties cannot be guaranteed. For this reason, you are free to contact us by telephone or post and to transmit personal data to us in this way.
 

Responsible


RAPUNZEL NATURKOST GmbH
Rapunzelstr. 1
D-87764 Legau
Phone: +49 (0) 8330 - 529 1402
Fax: +49 (0) 8330 - 529 1139
Web: rapunzel.de
E-mail: info@rapunzel.de
Further information can be found in our imprint.
 

Data protection officer


If you have any questions about data processing or data protection at bionella, you can contact our data protection officer at DAISECO GmbH at any time.
You can contact him by post at the above address (please note 'For the attention of the data protection officer' on the envelope), by e-mail datenschutzbeauftragter@rapunzel.de or confidentially via our data protection portal.
 

Transmission of data to third parties


We do not transfer your personal data to third parties for purposes other than those listed below when you visit our website. We only pass on your personal data to third parties if:
1. you have given us your express consent to do so in accordance with Art. 6 para. 1 lit. a GDPR,
2. the disclosure is permissible to protect our legitimate interests in accordance with Art. 6 para. 1 lit. f GDPR and there is no reason to assume that you have an overriding interest worthy of protection in not disclosing your data,
3. in the event that there is a legal obligation for the disclosure pursuant to Art. 6 para. 1 lit. c GDPR, and
4. this is legally permissible and necessary for the processing of contractual relationships with you in accordance with Art. 6 para. 1 lit. b GDPR.

As part of the processing operations described in this privacy policy, personal data may be transferred to the USA. The USA does not have an adequate level of data protection (ECJ: Schrems II ruling). In particular, US investigative authorities can oblige US companies to hand over or disclose personal data without the data subjects being able to take effective legal action against this. This means that there is a fundamental possibility that your personal data may be processed by US investigative authorities. We have no influence on these processing activities. In order to protect your data, we have concluded data processing agreements based on the European Commission's standard contractual clauses. If the standard contractual clauses are not sufficient to establish an adequate level of security, your consent may serve as the legal basis for the transfer to third countries in accordance with Art. 49 para. 1 lit. a) GDPR. This may not apply in the case of data transfer to third countries for which the European Commission has issued an adequacy decision pursuant to Art. 45 GDPR.
 

SSL/TLS encryption


This site uses SSL or TLS encryption to ensure the security of data processing and to protect the transmission of confidential content, such as orders, login data or contact requests that you send to us as the operator. You can recognize an encrypted connection by the “https://” instead of “http://” in the address line of the browser and by the lock symbol in your browser line. We use this technology to protect your transmitted data.
 

Data collection when visiting the website


If you only use our website for information purposes, i.e. if you do not register or otherwise transmit information to us, we only collect the data that your browser transmits to our server (in so-called “server log files”). Our website collects a range of general data and information each time you or an automated system accesses a page. This general data and information is stored in the server log files. The following can be recorded
1. the browser types and versions used
2. the operating system used by the accessing system
3. the website from which an accessing system accesses our website (so-called referrer)
4. the sub-websites which are accessed via an accessing system on our website
5. the date and time of access to the website
6. an internet protocol address (anonymized IP address) and,
7. the Internet service provider of the accessing system.

When using this general data and information, we do not draw any conclusions about your person. Rather, this information is required in order to

1. deliver the content of our website correctly
2. optimize the content of our website and the advertising for it,
3. ensure the long-term functionality of our IT systems and the technology of our website, and
4. to provide law enforcement authorities with the information necessary for prosecution in the event of a cyber attack.

This collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our company in order to ultimately ensure an optimal level of protection for the personal data processed by us. The anonymous data of the server log files are stored separately from all personal data provided by a data subject.

The legal basis for data processing is Art. 6 para. 1 sentence 1 lit. f GDPR. Our legitimate interest follows from the data collection purposes listed above.


a) Google Tag Manager

We use the Google Tag Manager service on this website. The operating company of Google Tag Manager is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Ireland Limited is part of the Google group of companies headquartered at 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
This tool allows “website tags” (i.e. keywords that are integrated into HTML elements) to be implemented and managed via an interface. By using Google Tag Manager, we can automatically track which button, link or personalized image you have actively clicked on and can then record which content on our website is of particular interest to you. The tool also triggers other tags, which in turn may collect data. Google Tag Manager does not access this data. If you have made a deactivation at domain or cookie level, this remains in place for all tracking tags that are implemented with Google Tag Manager. These processing operations are only carried out with your express consent in accordance with Art. 6 para. 1 lit. a GDPR. Google's privacy policy: https://www.google.com/intl/de/policies/privacy/.

b) YouTube (videos)

We have integrated YouTube components on this website. The operating company of YouTube is YouTube, LLC, 901 Cherry Ave, San Bruno, CA 94066, USA. YouTube, LLC is a subsidiary of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. YouTube is an Internet video portal that enables video publishers to post video clips free of charge and other users to view, rate and comment on them free of charge. YouTube allows the publication of all types of videos, which is why complete film and television programs as well as music videos, trailers or videos made by users themselves can be accessed via the Internet portal. Each time you access one of the individual pages of this website, which is operated by us and on which a YouTube component (YouTube video) has been integrated, the Internet browser on your IT system is automatically prompted by the respective YouTube component to download a representation of the corresponding YouTube component from YouTube.

Further information about YouTube can be found at https://www.youtube.com/yt/about/de/. As part of this technical process, YouTube and Google receive information about which specific sub-page of our website you visit.

If you are logged in to YouTube at the same time, YouTube recognizes which specific subpage of our website you are visiting when you access a subpage that contains a YouTube video. This information is collected by YouTube and Google and assigned to your YouTube account.

YouTube and Google always receive information via the YouTube component that you have visited our website if you are logged in to YouTube at the same time as accessing our website; this occurs regardless of whether you click on a YouTube video or not. If you do not want this information to be transmitted to YouTube and Google, you can prevent it from being transmitted by logging out of your YouTube account before accessing our website. These processing operations are only carried out with your express consent in accordance with Art. 6 para. 1 lit. a GDPR. Data protection information from YouTube:
https://www.google.de/intl/de/policies/privacy/.

c) Search for organic stores with OpenStreetMap

We can help you to find our sales partners in the organic trade who offer our products throughout Germany and other countries. We offer you a Rapunzel store finder via >Organic store search, where you can search by location or zip code. We have also integrated map sections from the online map tool “OpenStreetMap”. This is a so-called open source mapping that we can access via an API (interface). This function is offered by the OpenStreetMap Foundation, St John's Innovation Center, Cowley Road, Cambridge, CB4 0WS, United Kingdom. By using this service, you can, for example, be shown our location or that of our partner stores, making it easier for you to find where to buy our products in your area. When you access the subpages in which OpenStreetMap is integrated, information about your use of our website (such as your IP address, data about your browser, device type, operating system) is transmitted to OpenStreetMap and stored there.
We use the leading open source JavaScript library from leafletjs.com for the simple plugin implementation to display the mobile-friendly interactive maps.
OpenStreetMap uses the Content Delivery Network (CDN) of Fastly, Inc, PO Box 78266, San Francisco, CA 94107, USA (fastly) to accelerate the service. A CDN is a service with the help of which the contents of our online offer, in particular large media files such as graphics or scripts, are delivered faster with the help of regionally distributed servers connected via the Internet. Your data is processed exclusively for the aforementioned purposes and to maintain the security and functionality of the CDN. Fastly transmits personal data from the log files (e.g. IP addresses) to the USA for all data processing, as certain servers for processing the log files are only located in the USA. Fastly has therefore undertaken to comply with the standards and regulations of European data protection law. Fastly's privacy policy: https://www.fastly.com/de/privacy/.

By default, the integration is deactivated for data protection reasons and is only enabled for the map view after your consent has been requested. After that, the processing takes place exclusively on the basis of Art. 6 para. 1 lit. a GDPR. You can find detailed information about OpenStreetMap at:
https://wiki.osmfoundation.org/wiki/Privacy_Policy.

d) Shop search via geolocalization of your location

Instead of searching by city or zip code, you can also click on the search “NEAR”. In this case, you will be asked via your browser whether you want to allow or block a location query for rapunzel.de. In this case, you will be asked for your voluntary consent in accordance with Art. 6 para. I a GDPR in order to allow your browser to use location-based surfing and to be able to provide information relevant to your location. This specific authorization to query and exchange data cannot be done via our consent tool (the “cookie banner”) but is done directly, e.g. via Firefox or other browsers. The authorizations granted can also be easily revoked via your browser settings.

To determine your location, your browser uses Google Location Services with your permission. The following data is transmitted to the Google service via an encrypted connection: the IP address of your computer, information about nearby radio access points and a random identification number. Further information from Google on the use of location information can be found here: https://policies.google.com/technologies/location-data?hl=de.

We only use the geographical position of your device to show you, at your request, organic stores in your vicinity where our products are available. We do not process the location data in any other way.


 

Contents and contact options


Here we inform you about Rapunzel as a company as well as about our products and novelties. In addition to Rapunzel Naturkost's organic products, you will find information about cooking with Rapunzel Naturkost, our fair trade program HAND IN HAND and our Rapunzel Bio-Cent campaign. We provide links to other projects such as “jedes-essen-zaehlt.de” and other websites of our corporate family.
We offer our business customers a login for our specialist store and for downloading from our media database. We give you various options for dialog with our contacts and also offer various ways of contacting us.

a) Contacting us via contact forms

For questions of any kind, we offer you the opportunity to contact us using one of the forms provided on the website. On the one hand, this is our general contact request form for general questions and one for product complaints.
It is first necessary to provide a valid e-mail address and a name so that we know who sent the request and can respond to it. Which other data is collected can be seen from the respective contact form.

If you have a complaint about a product and use the form, we will ask you for further data so that we can assign the complaint to a specific order and possibly a specific product batch, in particular your address. This enables us to clearly assign orders to the complaint processing and to be able to send you replacement products without having to ask for your data again. If you do not wish this, you can also contact us by telephone or via the general contact form. If you make a callback request, it is necessary to provide a telephone number so that our contact persons can also contact you.

The information you provide in the form fields will be stored and used exclusively for the purpose of responding to your request or for contacting you and the associated technical administration. The legal basis for processing the data is our legitimate interest in responding to your request in accordance with Art. 6 para. 1 lit. f GDPR. If your contact is aimed at the conclusion or complaint of a contract, the additional legal basis for the processing is Art. 6 para. 1 lit. b GDPR.
We have secured our forms with a simple verification question that does not require data processing or disclosure to third parties. You can attach files, such as photos, to the forms. The submitted information is transmitted to us securely.
Your data will be deleted after final processing of your request; this is the case if it can be inferred from the circumstances that the matter in question has been conclusively clarified and provided that there are no statutory retention obligations to the contrary. Alternatively, you can also contact us directly informally and ask us to delete your data.

b) Contact via e-mail

If you contact us via one of the e-mail addresses provided by us, the personal data you provide will be processed exclusively for the purpose of processing your respective request, for correspondence with you, as well as for any initiation and justification of a contract, for inquiries for products and complaints etc. with you in accordance with Art. 6 Para. 1 S. 1 lit. b) GDPR. The personal data collected will be automatically deleted after your inquiry has been dealt with; this is the case if it can be inferred from the circumstances that the matter in question has been conclusively clarified and provided that there are no statutory retention obligations to the contrary.

c) Download via our media database

We provide you with a wide range of information for download on our website. For example, you can use our database to search specifically for media and information for product images, recipe cards, brochures/flyers and displays and also download them collectively in the selected resolution. We explain how the media database works in a PDF.

If you click on the button for the Rapunzel media database, you will be redirected to our media solution in the cloud provided by this service provider and leave our Rapunzel.de page. We use the services of Verdacloud Solutions - Gnann Verwaltung GmbH for the management of images, videos and digital data via our media database in the cloud and Dagnamedia from Six Offene Systeme GmbH for the Rapunzel Media Center.

We make the aforementioned media available via our service providers with a legitimate interest in providing comprehensive information to our customers as an aid and for the possible initiation and justification of a contract. When you request the media, in addition to the data processed on the server side, such as log files and IP addresses, the data that you have selected for the download and where it is to be downloaded to is also processed. The processing is carried out in accordance with Art. 6 para. 1 sentence 1 lit. b) and f) GDPR. If necessary, we have concluded contracts with our service providers for commissioned processing in accordance with Art. 28 GDPR.

d) Login for business customers

If you have registered with us as a business customer, you can log in to our specialist store via the login. You can obtain access via our sales department - speak to your contact at our company or write to us. We inform our business partners separately about the individual data processing in our specialist store. The legal basis for processing the data of our business customers as contractual partners is Art. 6 para. 1 lit. b and f GDPR.

e) Contacting us for application purposes

We also provide information about vacancies and apprenticeships with us on our own website. If you apply, we process personal data about you for the purpose of your application for an employment relationship, insofar as this is necessary for the decision on the establishment of an employment relationship with us.
The legal basis for this is Section 26 para. 1 in conjunction with para. 8 sentence 2 BDSG as well as for contract fulfillment or pre-contractual measures (Art. 6 para. 1 sentence 1 lit. b GDPR). Furthermore, we may process personal data about you if this is necessary to defend against legal claims asserted against us in the application process. The legal basis for this is Art. 6 para. 1, lit. f GDPR; the legitimate interest is, for example, a burden of proof in proceedings under the General Equal Treatment Act (AGG). If there is an employment relationship between you and us, we may process the personal data already received from you for the purposes of the employment relationship in accordance with Section 26 (1) BDSG if this is necessary for the performance or termination of the employment relationship or for the exercise or fulfillment of existing legal rights and obligations.

We process data in connection with your application. In particular, this includes general personal data such as your name, address and contact details, information on your professional qualifications and school education or information on further professional training or other information that you provide to us in connection with your application. We do not use any external applicant management systems in which we store the application data. Your applicant data will not be transferred to a third country. We store your personal data for as long as is necessary to make a decision about your application. If an employment relationship is not established between you and us, we may also continue to store data if this is necessary to defend against possible legal claims. In this case, the application documents will be deleted two months after notification of the rejection decision, unless longer storage is required due to legal disputes.

Please apply exclusively via e-mail: jobs@rapunzel.de - in this way you can ensure in your own interest that your details end up in our HR department and do not have to be forwarded unnecessarily within the company.


 

Our activities in social networks


a) Links to media appearances

No plugins or other interfaces of social media are integrated on our website, nor are any analytics of the services. We only link to our presence on the services of Instagram, Facebook, Pinterest, YouTube and LinkedIn, which are marked with an icon. After clicking on the links, you will be redirected to the page of the respective provider, i.e. only then will user information be transmitted to the respective provider. For information on the handling of your personal data when using these websites, please refer to the respective privacy policies of the providers.

b) Presence on social networks

We use the aforementioned social networks to inform users about our products and information offerings, to discuss with interested parties and to bring our entrepreneurial, ecological, economic, social and political actions closer to our interested parties and to publicize recipes and news.

You can contact us directly via the respective platform at your own request and instigation. The aforementioned social media channels supplement our website and offer an additional, supplementary information and communication option.
As soon as you call up the respective social media profile of bionella in the corresponding network, the terms and conditions and data protection notices of the respective operators apply. We only process visitor data on the social media sites ourselves if you contact and communicate with us via comments or direct messages, for example.

Those responsible for the respective platforms carry out data processing for their own purposes in accordance with their own privacy policies, over which we have no influence. Furthermore, we are not aware of the full scope of data processing, its purposes or storage periods. In certain cases, we process your data with the provider of the social network on the basis of joint controllership within the meaning of Art. 26 GDPR.

The processing of your personal data is necessary for the purpose of your use of the social media platform.

We are not the original provider of these pages, but only use them within the scope of the possibilities offered to us by the respective providers. As a precautionary measure, we would therefore like to point out that your data may also be processed outside the European Union or the European Economic Area. Use may therefore be associated with data protection risks for you, as it may be more difficult to safeguard your rights, e.g. to information, deletion, objection, etc., and processing in social networks is often carried out directly for advertising purposes or for the analysis of user behavior by the providers without us being able to influence this. If user profiles are created by the provider, cookies are often used or the user behavior is assigned to your own social network member profile.
The described processing operations of personal data are carried out in accordance with Art. 6 para. 1 lit. f GDPR on the basis of our legitimate interest and the legitimate interest of the respective provider in order to communicate with you in a timely manner or to inform you about our services.

If you have to give your consent to data processing as a user with the respective providers, the legal basis refers to Art. 6 para. 1 lit. a GDPR in conjunction with Art. 7 GDPR. Art. 7 GDPR.

As we do not have access to the providers' databases, we would like to point out that it is best to assert your rights (e.g. to information, correction, deletion, etc.) directly with the respective provider despite possible joint responsibility with the social media portal operators.

Further information on the processing of your data in the social networks and the possibility of exercising your right of objection or revocation (so-called opt-out) is provided below by the respective social network provider we use.

c) Social media services

Facebook
(Co-)responsible for data processing in Europe:
Meta Platforms Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland
Privacy policy (data policy): https://www.facebook.com/about/privacy
Opt-out and advertising settings: https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen

Instagram
(Co-)responsible for data processing in Germany:
Meta Platforms Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland
Privacy policy (data policy): https://instagram.com/legal/privacy/

LinkedIn
(Co-)responsible for data processing in Europe:
LinkedIn Ireland Unlimited Company Wilton Place, Dublin 2, Ireland
Privacy policy: https://www.linkedin.com/legal/privacy-policy

YouTube
(Co-)responsible for data processing in Europe:
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Privacy policy: https://policies.google.com/privacy

Pinterest
(Co-)responsible for data processing in Europe:
Pinterest Europe Ltd Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland.
Privacy policy: https://policy.pinterest.com/de/privacy-policy


 

Web Analysis with Google Analytics 4


On our websites we use Google Analytics 4 (GA4), a web analysis service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). In this context, pseudonymized user profiles are created and cookies (see “Cookies”) are used. The information generated by the cookie about your use of this website may include, but is not limited to:
  • short-term recording of the IP address without permanent storage
  • location data
  • Browser type/version
  • Screen resolution
  • Browser language
  • Browser information
  • Device information
  • Operating system used
  • Referrer URL (previously visited page)
  • Date and time of the visit
  • Click path
  • Interaction data
  • User behavior
  • URL visited
  • Cookie ID
  • Hostname


The pseudonymized data may be transmitted by Google to a server in the USA and stored there. The information is used to evaluate the use of the website, to compile reports on website activity and to provide other services relating to website activity and internet usage for the purposes of market research and the needs-based design of this website. This information may also be transferred to third parties if this is required by law or if third parties process this data on our behalf. These processing operations are only carried out if express consent is given in accordance with Art. 6 para. 1 lit. a) GDPR. Google's default data storage period is 14 months. Otherwise, the personal data is stored for as long as it is required to fulfill the purpose of processing. The data is deleted as soon as it is no longer required to achieve the purpose. The parent company Google LLC is certified as a US company under the EU-US Data Privacy Framework. This constitutes an adequacy decision pursuant to Art. 45 GDPR, meaning that personal data may be transferred without further guarantees or additional measures.

Further information on data protection when using GA4 can be found at: https://support.google.com/analytics/answer/12017362?hl=de

IP anonymization
We have activated the IP anonymization function on this website. This means that your IP address will be shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area before being transmitted to the USA. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. Google will use this information on behalf of the operator of this website for the purpose of evaluating your use of the website, compiling reports on website activity and providing other services relating to website activity and internet usage to the website operator. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.

Browser plugin
You may refuse the use of cookies by selecting the appropriate settings on your browser, however please note that if you do this you may not be able to use the full functionality of this website. You can also prevent Google from collecting the data generated by the cookie and relating to your use of the website (including your IP address) and from processing this data by Google by downloading and installing the browser plug-in available under the following link:
Download page for the browser add-on to deactivate Google Analytics: https://tools.google.com/dlpage/gaoptout?hl=de

a) Additional information on Consent Mode, simple implementation

Under the Digital Markets Act, Google is obliged to obtain user consent before processing user data for personalized advertising. Google meets this requirement with the “Consent Mode”. Users are obliged to implement this and thus prove that they have obtained the consent of website visitors. Google offers two implementation modes, the simple and the advanced implementation.
We use the simple implementation method of Google Consent Mode. Only if you give your consent to the use of Google Analytics (see above) will a connection to Google be established, a Google code executed and the processing described above carried out. If you refuse consent, Google will only receive information that consent has not been given. The Google code is not executed and no Google Analytics cookies are set.
 

Cookies


a) General information on cookies

We use cookies for our website. These are data records as information that your browser automatically creates and that are stored on your IT system or end device (laptop, tablet, smartphone, etc.) when you visit our website. Information is stored in the cookie that results in each case in connection with the specific end device used. However, this does not mean that we obtain direct knowledge of your identity. On the one hand, the use of cookies serves to make the use of our website more pleasant for you. For example, we use so-called session cookies to recognize that you have already visited individual pages of our website. These are automatically deleted after you leave our site.

In addition, we also use temporary cookies to optimize user-friendliness, which are stored on your end device for a specified period of time. If you visit our site again to use our services, it is automatically recognized that you have already visited us and which entries and settings you have made so that you do not have to enter them again.

On the other hand, we use cookies to statistically record the use of our website and to evaluate it for the purpose of optimizing our offer for you. These cookies enable us to automatically recognize that you have already visited our website when you visit it again. These cookies are automatically deleted after a defined period of time. The respective storage duration of the cookies can be found in the settings of the consent tool we use.

b) Notes on avoiding cookies in common browsers

You can delete cookies, allow only selected cookies or deactivate cookies completely at any time via the settings of the browser you are using. Further information can be found on the support pages of the respective providers:
Chrome: https://support.google.com/chrome/answer/95647
Safari: https://support.apple.com/de-at/guide/safari/sfri11471/mac
Firefox: https://support.mozilla.org/de/kb/cookies-und-website-daten-in-firefox-loschen
Microsoft Edge: https://support.microsoft.com/de-de/microsoft-edge/cookies-in-microsoft-edge-l%C3%B6schen-63947406-40ac-c3b8-57b9-2a946a29ae09
c) Usercentrics (Consent Management Tool / CMP)
We use the consent management platform “Usercentrics” from Usercentrics GmbH, Sendlinger Str. 7, 80331 Munich, Germany. This service enables us to obtain and manage the consent of website users for data processing. Usercentrics collects data generated by end users who use our website. When an end user gives consent, Usercentrics automatically logs the following data:
  • Browser information.
  • Date and time of access.
  • Device information.
  • The URL of the page visited.
  • Geographic location.
  • Page path of the website.
  • The consent status of the end user, which serves as proof of consent.


The consent status is also stored in the end-user's browser so that the website can automatically read and follow the end-user's consent on all subsequent page requests and future end-user sessions for up to 12 months. The consent data (consent and withdrawal of consent) is stored for three years. The retention period corresponds to the regular limitation period in accordance with Section 195 of the German Civil Code (BGB). The data will then be deleted immediately or forwarded to the person responsible on request in the form of a data export.

The functionality of the website is not guaranteed without the described processing. The user has no right to object as long as there is a legal obligation to obtain the user's consent to certain data processing operations (Art. 7 para. 1, 6 para. 1 sentence 1 lit. c GDPR). Usercentrics is the recipient of your personal data and acts as a processor for us. Detailed information on the use of Usercentrics can be found at: https://usercentrics.com/privacy-policy/.

Change your data protection settings
 

Your rights as a data subject


Right to confirmation - You have the right to request confirmation from us as to whether personal data concerning you is being processed.

Right to information in accordance with Art. 15 GDPR - You have the right to receive free information from us at any time about the personal data stored about you and a copy of this data in accordance with the statutory provisions.

Right to rectification in accordance with Art. 16 GDPR - You have the right to request the rectification of inaccurate personal data concerning you. You also have the right to request the completion of incomplete personal data, taking into account the purposes of the processing.

Right to erasure pursuant to Art. 17 GDPR - You have the right to obtain from us the erasure of personal data concerning you without undue delay where one of the grounds provided for by law applies and insofar as the processing or storage is not necessary.

Right to restriction of processing in accordance with Art. 18 GDPR - You have the right to demand that we restrict processing if one of the legal requirements is met.

Right to data portability pursuant to Art. 20 GDPR - You have the right to receive the personal data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format. You also have the right to transmit this data to another controller without hindrance from us to whom the personal data has been provided, provided that the processing is based on consent pursuant to Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR or on a contract pursuant to Art. 6 para. 1 lit. b GDPR and the processing is carried out by automated means, unless the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in us.

Furthermore, when exercising your right to data portability pursuant to Art. 20 para. 1 GDPR, you have the right to obtain that the personal data be transferred directly from one controller to another controller, insofar as this is technically feasible and provided that this does not adversely affect the rights and freedoms of other persons.

Right to object pursuant to Art. 21 GDPR - You have the right to object, on grounds relating to your particular situation, at any time to processing of personal data concerning you which is based on Art. 6 para. 1 lit. e (data processing in the public interest) or f (data processing on the basis of a balancing of interests) GDPR. This also applies to profiling based on these provisions within the meaning of Art. 4 No. 4 GDPR. If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms or if the processing serves the establishment, exercise or defense of legal claims.

In individual cases, we process personal data for direct marketing purposes. You can object to the processing of your personal data for the purpose of such advertising at any time. This also applies to profiling insofar as it is associated with such direct advertising. If you object to processing for direct marketing purposes, we will no longer process the personal data for these purposes.

In addition, you have the right to object, on grounds relating to your particular situation, to the processing of personal data concerning you which is carried out by us for scientific or historical research purposes or for statistical purposes in accordance with Art. 89 para. 1 GDPR, unless such processing is necessary for the performance of a task carried out in the public interest.

You are free to exercise your right to object in connection with the use of information society services, notwithstanding Directive 2002/58/EC, by means of automated procedures using technical specifications.

Right to withdraw consent under data protection law - You have the right to withdraw your consent to the processing of personal data at any time with effect for the future.

Right to lodge a complaint with a supervisory authority - You have the right to lodge a complaint about our processing of personal data with a supervisory authority responsible for data protection. A list of the contact details of the data protection officers in the federal states and the supervisory authorities for the non-public sector and in other countries can be found on the website of the Federal Commissioner for Data Protection and Freedom of Information, BfDI under Addresses and links.


 

Automated decision making & profiling


We do not use profiling in the context of the use of our websites iSv. Art. 22 GDPR.


 

Storage, deletion and blocking


We process and store your personal data only for the period of time required to achieve the purpose of storage or if this is provided for by the legal regulations to which our company is subject. If the storage purpose no longer applies or if a prescribed storage period expires, the personal data will be routinely blocked or deleted in accordance with the statutory provisions.

 

Storage period


The criterion for the duration of the storage of personal data is the respective statutory retention period. Once this period has expired, the corresponding data is routinely deleted, provided it is no longer required to fulfill or initiate a contract.


 

Further data protection issues


You can find further information about our products, our company and data protection on our website. If you have any further questions, comments or other requests regarding your personal data that are not answered here, simply contact us using our contact details or at: datenschutzbeauftragter@rapunzel.de.