Table of Contents
1 General Information
1.1 Objective and Responsibility
1.2 Legal Bases
1.3 Data Subject Rights
1.4 Data Erasure and Storage Duration
1.5 Security of Processing
1.6 Data Transfers to Third Parties, Subcontractors and Third Party Providers
2 Concrete Data Processing
2.1 Collection of Information on the Use of the Online Service
2.2 Microsoft Application Insights
2.3 Contact Form and Contact via Email
3 Cookie Policy
3.1 General Information
3.2 Possibilities of Objection
4 Changes to the Data Protection Policy
1 General Information
1.1 Objective and Responsibility
- This Data Protection Policy is to inform you about the nature, scope and purpose of the processing of personal data in relation to our online service and the associated websites, features and contents (hereinafter collectively referred to as "online service" or "website").
- The provider of the online service and responsible for the data protection law is Fairmas GmbH (EUREF-Campus 13, 10829 Berlin, Germany) - hereinafter referred to as "provider", "we", “our” or "us".
- Our online service is made available by 1 & 1 Internet SE, Elgendorfer Str. 57, 56410 Montabaur.
- Our Data Protection Officer can be contacted via the email address: datenschutz@fairmas.com (Data Protection Officer: IT.DS Beratung).
- The term "user" or “you” encompasses all customers, interested people, employees and visitors of our online service.
1.2 Legal Bases
We collect and process personal data based on the following legal grounds:
a. Consent in accordance with Article 6 paragraph 1 (a) General Data Protection Regulation (GDPR). Consent meaning any freely given, specific, informed and unambiguous indication of agreement, which could be in the form of a statement or any other unambiguous confirmatory act, given by the data’s subject consenting to the processing of personal data relating to him or her.
b. Necessity for the performance of a contract or in order to take steps prior to entering into a contract according to Article 6 paragraph 1 (b) GDPR, meaning the data is required in order for us to fulfil our contractual obligations towards you or to prepare the conclusion of a contract with you.
c. Processing to fulfil a legal obligation in accordance with Article 6 paragraph 1 (c) GDPR, meaning that e.g. the processing of data is required by law or other provisions.
d. Processing in order to protect legitimate interests in accordance with Article 6 paragraph 1 (f) GDPR, meaning that the processing is necessary to protect legitimate interests pursued by us or by a third party, unless such interests are overridden by your interests or fundamental rights and freedoms which require the protection of personal data.
1.3 Data Subject Rights
You have the following rights with regards to the processing of your data through us:
a. Right of access in accordance with Article 15 GDPR
b. Right to rectification in accordance with Article 16 GDPR
c. Right to erasure („right to be forgotten“) in accordance with Article 17 GDPR
d. Right to restriction of processing in accordance with Article 18 GDPR
e. Right to data portability in accordance with Article 20 GDPR
f. Right to objection in accordance with Article 21 GDPR
Note: Users can object to the processing of their personal data in accordance to the legal requirements at any time with effect for the future. The objection can be lodged in particular against processing for direct marketing purposes.
Without prejudice to any other administrative or judicial remedy, you have the right to complain to a supervisory authority, in particular in the Member State where you are staying, working or suspected of infringing, if you believe that the processing of personal data concerning you is contrary to the GDPR.
1.4 Data Erasure and Storage Duration
The personal data of the data subject will be erased or blocked as soon as the purpose of the storage is deleted. In addition, such storage may take place if provided for by the European or national legislator in EU regulations, laws or other regulations to which the controller is subject. Blocking or erasure of the data also takes place when a storage period prescribed by the standards mentioned expires, unless there is a need for further storage of the data for conclusion of a contract or fulfillment of the contract.
1.5 Security of Processing
- We have implemented appropriate and state-of-the-art technical and organizational security measures (TOMs). Thus, the data processed by us are protected against accidental or intentional manipulation, loss, destruction and unauthorized access.
- The security measures include in particular the encrypted transfer of data between your browser and our server.
1.6 Data Transfers to Third Parties, Subcontractors and Third Party Providers
- A transfer of personal data to third parties only takes place within the scope of legal requirements. We only disclose users' data to third parties, when necessary, e.g. for billing purposes or other purposes when the transfer is required to fulfill contractual obligations towards the users.
- If we use subcontractors for our online service, we have made appropriate contractual arrangements as well as adequate technical and organizational measures with these companies.
- If we use content, tools or other means from other companies (hereinafter collectively referred to as "third party providers") whose registered offices are located in a third country, it is assumed that a transfer of data to the home countries of these third party providers occurs. The transfer of personal data to third countries takes place exclusively only, if an adequate level of data protection, the user’s consent or another legal permission is present.
2 Concrete Data Processing
2.1 Collection of Information on the Use of the Online Service
- When using our online service, information may be transferred automatically from the browser of the user to us; this information includes the name of the accessed website, file, date and time of the access, amount of data transferred, notification about successful access, browser type and version, the user's operating system, referrer URL (the previously visited page), IP address and the requesting provider.
- The processing of this information takes place based on legitimate interests in accordance with Article 6 paragraph 1 (f) GDPR (e.g. to optimize the online service) as well as to ensure the security of processing in accordance with Article 5 paragraph 1 (f) GDPR (e.g. for the defense and clarification purposes of cyberattacks).
- The information is automatically deleted 4 weeks after the end of the connection - i. e. use of the online service - provided there are no other retention periods.
- The collection of the data and the storage of the data in log files is absolutely necessary for the provision of the online service. Therefore, the user has no possibility of erasure, objection or correction.
- The information of the employees about the processing of personal data in the context of the use of Fairmas Online products is incumbent on the respective Fairmas customer in his function as employer.
2.2 Microsoft Application Insights
- Our web applications use Azure Application Insights, a service from Microsoft that helps us optimize the performance and usability of our applications. It monitors the application as it runs, and creates charts and tables that tell you, for example, what times of day it is in use or how well the app responds. In the event of crashes, errors, or performance issues, you can help telemetry data to determine the causes of errors. During app execution, Application Insights monitors operation and sends telemetry data to an Application Insights service (a cloud service hosted by Microsoft Azure).
- The majority of standard telemetry (i.e. telemetry sent without writing code) does not contain explicit personal information. However, it may be possible to draw conclusions about individual persons from an event list.
- For more information, see the Microsoft Application Insights privacy policy https://docs.microsoft.com/en-us/azure/application-insights/app-insights-data-retention-privacy
2.3 Contact Form and Contact via Email
- When contacting us (via online form or email), the data provided by the user will be processed exclusively for processing the inquiry and its handling.
- Any other use of the data is only based on the consent of the user.
- User data are stored in our Customer Relationship Management System ("CRM System") or a comparable software / database. The legal storage periods for business letters apply.
3 Cookie Policy
3.1 General Information
- Cookies are information transmitted by our web server or third-party web servers to the users' web browsers where they are stored for later retrieval. Cookies can be in the form of small files or any other types of information storage.
- If users do not want cookies stored on their computer, they will be asked to disable the option in their browser's system settings. Saved cookies can be deleted in the system settings of the browser. The exclusion of cookies can lead to functional restrictions of this online offer.
3.2 Possibilities of Objection
You can object to the use of cookies, which are used for measuring the range of coverage and advertising purposes, via
a. Deactivation page of the Network Advertising Initiative: http://optout.networkadvertising.org/
b. The US-American website: http://www.aboutads.info/choices
c. The European website http://www.youronlinechoices.com/uk/your-ad-choices/
4 Changes to the Data Protection Policy
- We reserve the right to change this data protection policy in relation to data processing, in order to adapt it to changed legal situations, to changes in the online service or to data processing.
- If user consents are required or components of the data protection policy contain provisions of the contractual relationship with the users, the changes will only be made with the users' consent.
- Users are requested to inform themselves regularly about the content of this privacy policy
As of: 29.05.2018