Privacidad

Date: May 2018

Data Protection Notice

I. Name and Address of Controller

The controller within the meaning of the General Data Protection Regulation (GDPR), other national data protection legislation of the Member States and other data protection provisions is

Utimaco TS GmbH

Germanusstrasse 4

52080 Aachen

Germany

Tel.: +49 241 1696-200

Fax: +49 241 1696-199

E-mail: li-contact@utimaco.com

Website: https://lims.utimaco.com

II. Contact details of Data Protection Officer

The controller’s data protection officer can be contacted via

Utimaco TS GmbH
- Datenschutzbeauftragter -
Germanusstraße 4
52080 Aachen
Germany
Telefon: 0049 241 16960
E-Mail: dataprotection-NOSPAM-utimaco.com

III. General Information on Data Processing

1. What are personal data?

Personal data within the meaning of the GDPR include all information relating to the personal or material circumstances of an identified or identifiable natural person (see Art. 4(1) GDPR). Such information will regularly include not only a person’s name and (e-mail) address, for example, but also the IP address and any other information that could permit identification of that person.

2. Scope of Processing of Personal Data

We process the personal data of our users only insofar as this is required to maintain a functional website and present our content and services. We regularly process personal data of our users only with their consent. An exception may be made in cases in which it is not possible to obtain such consent for concrete reasons and the processing of the data is legally allowed.

3. Legal Basis for Processing Personal Data

Art. 6(1)(a) of the General Data Protection Regulation (GDPR) provides the legal basis for any request we may make for consent to process the personal data of data subjects.

Art. 6(1)(b) GDPR provides the legal basis for processing personal data for the performance of any contract to which a data subject is party. This will also apply to processing required prior to entering into such a contract.

Art. 6(1)(c) GDPR provides the legal basis for processing required to comply with any legal obligations to which our Company is subject.

Art. 6(1)(d) GDPR provides the legal basis for processing personal data in order to protect the vital interests of a data subject or other natural person.

Art. 6(1)(f) GDPR provides the legal basis for processing personal data in order to safeguard the legitimate interests of our Company or any third party and the interests, fundamental rights or freedoms of a data subject do not override the interests of the former.

4. Erasure and Duration of Storage of Data

The personal data of data subjects will be erased or blocked as soon as the purpose for which they were initially stored no longer applies. Personal data may be stored for longer periods if provision for such storage has been made by European or national legislatures in Union regulations, laws or other regulatory requirements to which the controller is subject. Personal data will also be blocked or erased if a corresponding period of retention prescribed by such regulations, laws or legal requirements expires unless such data are required for the entry into or performance of a contract.

IV. Availability of the Website and Creation of Log Files

1. Description and Scope of Data Processing

Our system automatically records data and information from the computer system of every visitor to our Internet site.

This involves recording the following data:

(1) Date and time of access

(2) Browser type, version and language

(3) City/region/country

(4) IP address of the user

(5) System used by the user

These data are stored in the log files of our system. We store IP addresses only in pseudonymized form. This is done by using a standard procedure that involves replacing the final three digits of the IP addresses stored in the log files by three digits selected at random. This makes it impossible to identify data subjects.

2. Legal Basis for Processing of Data

Art. 6(1)(f) GDPR provides the legal basis for the temporary storage of data and log files.

3. Purpose of Processing Data

Temporary storage of IP addresses by the system is required to deliver the website to the computer of the user. As a result, the IP addresses of users must be stored for the duration of the respective session.

The purpose of storage in log files is to ensure the functionality of the website and support technical administration of the network infrastructure. In addition, such data enable us to enhance our website and maintain the security of our information technology systems. We also use these data to prepare and evaluate internal statistics. This involves no evaluation of data for marketing purposes.

We have a legitimate interest in processing data for such purposes pursuant to Art. 6(1)(f) GDPR.

4. Duration of Storage

Data are erased as soon as they are no longer needed to achieve the purposes for which they were initially collected. In the case of data collected to permit delivery of our website, this occurs when the respective session is ended.

In the case of data stored in log files, this will regularly take place within seven days. Storage for a longer period is possible. In such cases, data are pseudonymized so that they no longer permit identification of a specific user. Backups are kept in encrypted form for 14 days.

5. Possibility of Objection and Elimination

It is absolutely necessary to collect and store data in log files to permit delivery of the website. As a result, users may not object to such storage.

V. Use of Cookies

1. Description and Scope of Data Processing

Our website uses cookies. Cookies are text files that are stored in the Internet browser or by the Internet browser on the user's computer system. When a user visits a website, a cookie can be placed on the user’s device. Cookies contain a unique string of random letters that clearly identify the users’ browser when they revisit the website.

We place cookies to make our website user-friendlier. A few elements of our website make it necessary to be able to recognize visiting browsers after page changes.

We use the following cookies:

(1) _ga
This cookie is set to identify visitors but does not contain any personal information and is created on the basis of a random routine. In order for Google Analytics to be able to determine whether two visits were made by the same user, a unique identifier must be sent with each visit that can be used to permit recognition of the individual user. The analytics.js library does this by using a ‘Client ID’, which is a unique, randomly generated string of numbers that is stored on the user’s computer by the user’s web browser so that subsequent visits to a website by the same user can be associated with that user. Analytics.js uses a single standard first-party cookie called _ga to store Client IDs.

(2) ga-disable-UA-97568300-1
This cookie is used to determine whether the user has disabled Google Analytics.

(3) cookie-accept
We use this cookie to prevent our cookie window from being displayed again each time you visit a new page on our website. This cookie does not contain any personal information and is merely intended not to constantly irritate you with a cookie "warning".

(4) _gat
This cookie is set to limit the amount of traffic sent between your browser and Google Analytics' servers. We use Google Analytics to analyze the traffic on our website and improve your experience. Google Analytics helps us determine which pages are the most popular and how our visitors navigate the site so that we can optimize navigation and the like. The cookie is deleted after ten minutes.

(5) typo3_fe_user
This cookie is used in the "My Utimaco" area to facilitate login to the portal. This allows you to navigate to another page and return to the portal later without losing information or having to log in again. The cookie contains an identification key that refers to our system running in the background, in which your login data is stored. The cookie itself does not contain any personal information.

The following data are stored and transmitted in the cookies:

(1) Language settings

(2) Log-in information

Our website also uses cookies that support analysis of the surfing habits of users.

This makes it possible to obtain the following data:

(1) Search terms entered

(2) Use of website functionality: Data on users who initiate a download

Technical means are used to pseudonymize the data of users collected in this manner. That makes it impossible to use the data to identify visiting users. Such data are not stored together with user’s other personal data.

Visitors to our website are notified of the use of cookies for analytical purposes by a banner and asked to give their consent to having their personal data processed for such purposes. A reference to this privacy statement also appears at the same time. In addition, users are notified that the browser settings make it possible to prevent the storage of cookies.

2. Legal Basis for Processing of Data

Art. 6(1)(f) GDPR provides the legal basis for the use of cookies in connection with the processing of personal data.

Art. 6(1)(a) GDPR provides the legal basis for the use of cookies for analytical purposes in connection with the processing of personal data if the consent of the user has been obtained.

3. Purpose of Processing Data

The purpose of using of cookies is to simplify the use of websites for users. Some of the functions of our website cannot be used without the use of cookies. In the case of these functions, it is necessary to be able to recognize the browser again when changing to a new page. This permits temporary storage of technical data or information required for proper operation of certain features on the computer.

We need cookies for the following applications:

(1) to obtain language settings

(2) Login in the download area

The user data collected by these cookies are not used to create user profiles.

Analytics cookies are used to improve the quality of our website and its content. They tell us how our website is being used so we can continually make improvements. More precise descriptions of the function and purpose of cookies can be found in section V.1 above.

These purposes also give rise to our legitimate interest in processing personal data pursuant to Art. 6(1)(f) GDPR.

4. Duration of Storage, Possibility of Objection and Elimination

Cookies are stored on the device of the user and sent to our website. The user therefore is in complete control of the use of cookies. By changing the settings of the Internet browser, the transmission of cookies can be deactivated or restricted. Cookies that have already been placed can be disabled at any time. This process can also be automated. If the user chooses to disable cookies, he may not be able to use all of the features of our website.

 

VI. Downloadcenter

1. Description and Scope of Data Processing

In our download area on our website https://lims.utimaco.com/de/utimaco-lims/ "Downloadcenter" you can download various documents or receive a download link. These functions are only available to registered members of the download center. Personal data is required for registration. The user will be informed of this before submitting any data. In addition, cookies are used when initiating downloads (see above under V. 1.).

If a user enters his or her data in the input mask, the following data will be recorded:

(1) First and last name (required)

(2) Address (optional)

(3) E-mail address (required)

(4) Phone number (optional)

(5) Company name (required)

After sending the data the user will receive an e-mail with the information regarding the revocation.

2. Legal Basis for Processing of Data

Legal basis for the processing of the data is the consent of the user in accordance with
Art. 6(1)(a) GDPR.

3. Purpose of Processing Data

By collecting the data, we can make the closed area of the download center and its functions available to the user. In addition, by collecting the data we can identify which download content users are interested in and better adapt it to demand.

4. Duration of Storage

Data are erased as soon as they are no longer needed to achieve the purposes for which they were initially collected.

Other personal data that are also collected during the delivery process will regularly be erased within seven days.

5. Possibility of Objection and Elimination

The user has the possibility to revoke his consent to the processing of personal data at any time. The revocation can be declared to us by an e-mail to li-contact-NOSPAM-utimaco.com.

All personal data will be erased in this case.

VII. Newsletter

1. Description and Scope of Data Processing

Visitors to our website can subscribe to a free newsletter. This involves the transfer of the following data from the input mask to us when they register to receive the newsletter:

(1) First and last name (optional)

(2) E-mail address (required)

(3) Company name (optional)

(4) Country (optional)

The following data will also be recorded:

(1) IP address (anonymized)

(2) Time zone/date and time of registration

(3) Date of last profile-update

(4) Location

(5) Groups and segments

Data are forwarded to the service provider MailChimp in connection with data processing for the distribution of newsletters. Data will not otherwise be made available to third parties. More detailed information on MailChimp may be found in section VI. 5. The data will be used exclusively for the purposes of distributing our newsletter.

Users will be asked to provide their consent and will be referred to this privacy statement during the registration process.

2. Legal Basis for Processing of Data

Consent of the user pursuant to Art. 6(1)(a) GDPR provides the legal basis for processing data after a user registers to receive a newsletter.

3. Purpose of Processing Data

The e-mail addresses of users will be recorded for the purposes of delivery of the newsletter.

Other personal data recorded in connection with the registration process serve to prevent abusive use of the services or the e-mail address used.

4. Duration of Storage

The data from the input mask will be deleted as soon as they are no longer necessary to achieve the purpose of their collection. The user's e-mail address will therefore be stored until the user cancels the subscription. The deletion takes place automatically by the system. If required, manual deletion can also be carried out. To do this, the user can contact us at the following e-mail address: li-contact-NOSPAM-utimaco.com.

Other personal data recorded in connection with the subscription process will regularly be erased within seven days.

5. Newsletter through MailChimp

We use the MailChimp component to distribute our newsletter. Mailchimp is a service provided by The Rocket Science Group, LLC, 512 Means Street, Suite 404, Atlanta, GA 30318, USA.

The data stored during newsletter registration (e-mail address, if applicable name, IP address, country/region, timezone/date and the time of your registration) are transmitted to a server of The Rocket Science Group in the USA and stored there in compliance with the "EU-U.S. Privacy Shield". The Rocket Science Group, LLC -, which operates MailChimp, is certified according to the requirements of Privacy Shield (https://www.privacyshield.gov/participant?id=a2zt0000000TO6hAAG[AS1] ). According to the EU Commission, a company on the "Privacy Shield List" can in principle be assumed to offer an adequate level of data protection. The e-mail address is recorded only for the purposes of sending users an e-mail that they can use to confirm that they want to be included in the e-mail list (“double opt-in”). If the e-mail address is confirmed, it will be permanently stored by the list provider until its owner withdraws his or her consent or it is deleted manually by us.

For further information on MailChimp and data protection can be found at http://mailchimp.com/legal/privacy/.

6. Possibility of Objection and Elimination

Subscribers can cancel their subscriptions to the newsletter at any time by withdrawing their consent. Detailed information on the procedure to be used is provided in the confirmation e-mail and each individual newsletter. Each newsletter contains a dedicated link for this purpose. Users can also cancel their subscriptions by sending an e-mail at
li-contact-NOSPAM-utimaco.com. This will permit withdrawal of consent to store the personal data collected during the registration process.

VIII. Newsletter Tracking

1. Description and Scope of Data Processing

Our newsletters contain ‘tracking pixels’ (web bugs) that tell us whether an e-mail has been opened and, if so, when and track links to external websites contained in the e-mail if they are clicked by the recipient.

2. Legal Basis for Processing of Data

Legal basis for the processing of data within the scope of newsletter tracking is the consent of the user pursuant to Art. 6(1)(a) GDPR.

3. Purpose of Processing Data

We store newsletter tracking data to achieve optimal alignment of the content of our newsletter with the wishes and interests of our subscribers. Accordingly, the data we collect are used to send personalized newsletters to the respective recipients.

4. Duration of Storage

Data are erased as soon as they are no longer needed to achieve the purposes for which they were initially collected. The e-mail addresses of users are therefore kept as long as the subscriptions to the newsletter remain active.

Other personal data recorded in connection with the subscription process will regularly be erased within seven days.

5. Possibility of Objection and Elimination

Users can object to newsletter tracking at any time by simply canceling their subscription to the newsletter. Tracking will be automatically suspended upon cancellation.

IX. Deployment of Website Analysis Services

1. Description, Scope and Purpose of Data Processing

(1) WiredMinds GmbH

We use the tracking technology of WiredMinds GmbH (www.wiredminds.de) to analyze visitor activity for marketing purposes and optimization of our website. This involves collecting, processing and storing data to prepare use profiles that are identified by pseudonyms. Whenever possible and appropriate, these use profiles are completely anonymized. Cookies may be used for such purposes (see above).

The data, which may also include personal data, are transferred to or collected directly by WiredMinds. WiredMinds may use information left on websites by visitors to create anonymized use profiles. The data collected will not be used to determine the personal identity of a website visitor and will not be compiled with personal data relating to the person identified by the pseudonym except in the case of a separate agreement with the data subject. If IP addresses are collected, they are anonymized immediately after collection by removing the last octet.

Opt-Out Link: https://wm.wiredminds.de/track/cookie_mgr.php?mode=dont_track_ask&websitesel=09253eca370e15b7&lang=en[AS2]

(2) Google Analytics

We use Google Analytics, a website analysis service of Google Inc. (“Google”), 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, on our website. Google Analytics uses cookies that are placed on the computers of users and permit analysis of the use of websites. The information generated by such cookies (including your IP address) is sent to and stored on a Google server in US. When visiting our website, the user is informed of the use of cookies by an information banner and asked for his or her consent. A collection of data by the cookies only takes place when the user has given his consent by clicking a checkbox.

The following data is processed by Google Analytics:

(1) Date and time of access

(2) Duration of visit per visitor and page

(3) Type of visit and history (in the sense of distinction between new and returning visitors)

(4) Names and URLs of files and pages accessed

(5) Website from which access is initiated (originating end)

(6) Websites accessed by the systems of users through our website

(7) The search term (query input)

(8) Entry and exit pages

(9) Pageview frequency

(10) Click paths

(11) Browser type, version and language

(12) Operating system, screen resolution

(13) City/region/country

(14) Internet service provider of users

(15) Internet connection speed

(16) IP addresses of users

Google uses this information for the purposes of evaluating the use of websites, compiling reports on website activity for website operators and providing other services relating to website activity and Internet usage. Google may also transfer this information to third parties if required to do so by law or such third parties process the information on Google’s behalf. Google will under no circumstances combine the IP addresses of users with other data in the possession of Google. You may prevent the use of cookies by selecting the appropriate settings on your browser. However, you should be aware that this may make it impossible for you use the full functionality of this website. By using this website, you consent to the processing of data collected on you by Google in the manner and for the purposes described above.

You may at any time object to having your data collected and stored. To prevent storage of the data created by the cookie that pertain to your use of the website (including your IP address) and processing of such data by Google, you can download and install the browser plug-in available under the following link.
You can also prevent collection by Google Analytics by clicking the following link. This will place an opt-out cookie on your device that will prevent the collection of your data when you visit this website in the future: https://tools.google.com/dlpage/gaoptout?hl=en.typo3/#_msocom_3

Against the background of the discussion of the use of analysis tools with complete IP addresses, we would like to draw your attention to the fact that IP addresses are processed only in abbreviated form on this website. Setting the “_anonymousIp()” field when using Google Analytics makes it impossible to associate the data collected with a specific data subject.

The terms of service and privacy policy of Google and Google Analytics can be downloaded at https://www.google.com/analytics/terms/ or https://policies.google.com/.typo3/#_msocom_4

(3) Google Analytics is also used to analyze data from AdWords for statistical purposes. Google AdWords

For our online marketing, we use Google's AdWords function. If the user accesses our website via a Google ad, a cookie is stored on the user's computer.

These so-called "conversion cookies" are no longer active after 30 days and are not used to personally identify the user. If the user visits certain pages of our website while the cookie is still active, we and Google know that the user has clicked on ads on Google and has been redirected to our website. Google uses the information obtained through "conversion cookies" to compile statistics for our website. These statistics show us the total number of users who clicked on our ad and the pages of our website that were visited by each user. However, neither we nor other advertisers who use "Google Adwords" receive information that can be used to personally identify users. The installation of "conversion cookies" can be prevented via the browser settings, e.g. by setting the browser so that the automatic placement of cookies is deactivated or by blocking cookies from the "googleadservices.com" domain.

More information is available at https://policies.google.com/technologies/ads?hl=en.

Further information on data protection at Google is available at https://policies.google.com/privacy?hl=entypo3/#_msocom_6

2. Legal basis

Art. 6(1)(f) GDPR provides the legal basis for processing data for such purposes.

3. Duration of Storage

The data will be deleted manually. The deletion will take place within 30 days.

4. Possibility of Objection and Elimination

The user has the possibility to object to the use of website analysis services in an e-mail to
li-contact-NOSPAM-utimaco.com at any time.

X. Contact Form and Contact by E-Mail

1. Description and Scope of Data Processing

A form that can be used to contact us by electronic means is available on our website. The information entered in the input mask by users who choose this option will be sent to and stored by us. This information will include the following data:

(1) First and last name

(2) E-mail address

(3) Company name

(4) User’s question

The following data will also be collected when the message is sent:

(1) IP address

(2) Date and time of transmission of message

(3) URL of Utimaco entry page

At the time the message is sent, the data specified under item IV. 1. is also stored in log files (see above under IV.).

Alternatively, you can contact us via li-contact-NOSPAM-utimaco.com. In this case, the user's personal data transmitted by e-mail will be stored.

If the purpose of the user’s query is to obtain information on our products, the user’s data will be forwarded to the person responsible for such queries. The user will be notified accordingly before giving his or her consent. These data are not made available to any further third parties. The data will be used exclusively for the purposes of processing and responding to the user’s message.

7. Legal Basis for Processing of Data

Art. 6(1)(f) GDPR provides the legal basis for processing the data transmitted in connection with an e-mail. If the contact takes place in connection with the performance of a contract, Art. 6(1)(b) GDPR provides a further legal basis for processing.

8. Purpose of Processing Data

The processing of personal data within the framework of establishing contact serves us solely for processing the contact. This is also our legitimate interest in processing the personal data.

Other personal data from the input mask processed during the transmission process serve to prevent abusive use of the contact form and maintain the security of our information technology systems.

9. Duration of Storage

Data are erased as soon as they are no longer needed to achieve the purposes for which they were initially collected. In the case of personal data from the input mask of the contact request form and the data transmitted with the e-mail, this occurs when the respective conversation with the user is terminated. A conversation is considered to be terminated when circumstances make it possible to assume that the respective issue has been conclusively clarified.

Other personal data that are also collected during the delivery process will regularly be erased within eight days.

10. Possibility of Objection and Elimination

The user has the right to object to the processing of personal data at any time. In such a case, the conversation cannot be continued. The objection can be explained to us by sending an e-mail to li-contact-NOSPAM-utimaco.com.

All personal data stored in connection with contact requests will be erased in this case.

XI. Rights of Data Subjects

If your personal data are processed, that makes you a data subject within the meaning of the GDPR and you have the following rights, which the controller must respect:

1. Rights of Access

You have the right to request that the controller confirm whether personal data that relate to you are processed by us.

If that should be the case, you can request information on the following from the controller:

(1) the purposes for which the personal data are processed;

(2) the categories of personal data processed;

(3) the recipients or categories of recipients to whom your personal data are or have been disclosed;

(4) the contemplated duration of storage of your personal data or, if concrete information cannot be provided, the criteria for determination of the duration of storage;

(5) the existence of a right to rectification or erasure of your personal data, a right to restriction of processing by the controller or a right to object to such processing;

(6) the existence of a right to lodge complaints with a supervisory authority;

(7) all available information on the origin of personal data not obtained from the data subject;

(8) the existence of automated decision-making, including profiling, pursuant to Art. 22(1) and (4) GDPR and – at least in these cases – meaningful information on the logic involved and the scope and intended effects of such processing for the data subject.

You have the right to receive information on whether your personal data are transferred to a third country or an international organization. In this context, you can require that we notify you of appropriate safeguards pursuant to Art. 46 GDPR in connection with any such transfer.

11. Right to Rectification

You have the right to require that the controller rectify and/or complete your personal data if the data that are processed are inaccurate or incomplete. The controller must make such changes without undue delay.

12. Right to Restrict Processing

You have the right to require that the controller restrict processing of your personal data under the following conditions:

(1) if you contest the accuracy of personal data for a period enabling the controller to verify the accuracy of the respective personal data;

(2) if the processing is unlawful and you oppose erasure of the personal data and request restriction of their use instead;

(3) if the controller no longer needs the personal data for the purposes of processing, but you need the personal data to establish, exercise or defend legal claims; and

(4) if you have objected to processing pursuant to Art. 21(1) GDPR pending verification of whether the legitimate grounds of the controller override your grounds.

If the processing of your personal data has been restricted, such personal data may, except as regards storage, be processed only with your consent or for the establishment, exercise or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the Union or of a Member State.

If processing has been restricted as described above, you will be notified by the controller before such restriction is lifted.

13. Right to Erasure

a) Duty to erase

You have the right to require that the controller erase personal data concerning you without undue delay and the controller must then erase such personal data without undue delay if one of the following grounds applies:

(1) The personal data are no longer needed for the purposes for which they were originally collected or otherwise processed;

(2) You have withdrawn the consent to processing given pursuant to of Art. 6(1)(a) or Art. 9(2)(a) GDPR and there is no other legal ground for such processing;

(3) You object to the processing pursuant to Art. 21(1) GDPR and there are no overriding legitimate grounds for such processing or you object to the processing pursuant to Art. 21(2) GDPR;

(4) Your personal data were processed unlawfully;

(5) Your personal data must be erased to comply with a legal obligation under Union or Member State law to which the controller is subject;

(6) Your personal data were collected in connection with an offer of information society services pursuant to Art. 8(1) GDPR;

b) Information Provided to Third Parties

If the controller has disclosed personal data concerning you and is obligated to erase such data pursuant to Art. 17(1) GDPR, the controller, taking account of available technology and the cost of implementation, must take reasonable steps, including technical measures, to inform controllers that are processing the personal data that you, as the data subject, have requested erasure by such controllers of any links to or copy or replication of such personal data.

c) Exceptions

The right to erasure does not apply if processing is necessary

(1) to exercise the right to freedom of expression and information;

(2) to comply with a legal obligation that requires processing under Union or Member State law to which the controller is subject or for the performance of a task carried out in the public interest or to exercise official authority vested in the controller;

(3) for reasons of public interest in the area of the public health pursuant to Art. 9(2)(h) and (i) and Art. 9(3) GDPR;

(4) for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Art. 89(1) GDPR insofar as the right referred to in section a) is likely to render impossible or seriously impair the achievement of the objectives of such processing; or

(5) to establish, exercise or defend legal claims.

14. Right to Rectification

If you have the right to require that a controller rectify, erase or restrict processing, the controller must notify all recipients to whom personal data concerning you were disclosed of such rectification, erasure or restriction of processing unless notification proves impossible or would entail an unreasonable effort.

You have the right to be notified of such recipients by the controller.

15. Right to data portability

You have right to receive the personal data concerning you that you have made available to a controller in a structured, commonly used and machine-readable format. You also have the right to transmit such data to another controller without hindrance from the controller to which the personal data were provided

(1) if processing is based on consent pursuant to Art. 6(1)(a) GDPR or Art. 9(2)(a) GDPR or on a contract pursuant to Art. 6(1)(b) GDPR and

(2) processing is carried out by automated means.

In exercising this right, you also have the right to have personal data concerning you transmitted directly from one controller to another if technically feasible. This may not be allowed to adversely affect the freedoms and rights of others.

The right to data portability does not apply to the processing of personal data required for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.

16. Right to object

You have the right to object at any time to the processing of personal data concerning you for reasons related to your particular situation on the basis of Art. 6(1)(e) or (f) GDPR. This will also apply accordingly as regards profiling based on these provisions.

The controller will then cease to process personal data concerning you unless it is possible to demonstrate compelling legitimate reasons for such processing that outweigh your interests, rights and freedoms or such processing serves to establish, exercise or defend legal claims.

If personal data concerning you are processed for direct marketing purposes, you have the right to object to the processing of your data for such marketing purposes at any time. This will apply accordingly to any profiling related to such direct marketing activities.

If you object to processing for the purposes of direct marketing, personal data concerning you will no longer be processed for such purposes.

In the context of the use of information society services and notwithstanding Directive 2002/58/EC, you may exercise your right to object by automated means using technical specifications.

17. Right to Withdraw Consent under Data Protection Law

You have right to withdraw your consent to having your personal data processed at any time. Withdrawal of consent will not affect the lawfulness of processing based on your consent prior to withdrawal.

18. Automated Individual Decision-Making, Including Profiling

You have the right not to be subject to a decision based solely on automated processing, including profiling, that legally affects you or entails effects that are of similar importance. This will not apply in the case of any decision that is

(1) necessary for the entry into or performance of a contract between you and the controller,

(2) permissible under Union or Member State law to which the controller is subject and which also lays down suitable measures to safeguard the your rights and freedoms and legitimate interests or

(3) based on your explicit consent.

However, these decisions may not be based on special categories of personal data pursuant to Art. 9(1) GDPR unless Art. 9(2)(a) or (g) GDPR applies and suitable measures have been taken to safeguard your rights and freedoms as well as your legitimate interests.

In the cases referred to in (1) and (3) above, the controller must implement suitable measures to safeguard your rights and freedoms as well as your legitimate interests, at least the right to obtain human intervention on the part of the controller, to express your point of view and to contest the decision.

19. Right to Lodge Complaints with a Supervisory Authority

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your residence, place of work or place of the alleged infringement if you are of the opinion that the processing of personal data relating to you infringes the GDPR.

The supervisory authority with which the complaint is lodged will inform the complainant on the progress and the outcome of the complaint including the possibility of a judicial remedy pursuant to Art. 78 GDPR.

This website uses cookies

This website uses cookies to improve user experience. By using our website you consent to all cookies in accordance with our Cookie Policy.
Read more