Privacy Policy for Our Customers
– Information pursuant to Articles 13, 14 and 21 of the General Data Protection Regulation (GDPR) –
Overview
Dear Customers,
the following information provides details on the processing of personal data and on your rights under the General Data Protection Regulation (GDPR) in the context of a business relationship.
Who is responsible for data processing?
The data controller is:
Digital2gether GmbH
Parkallee 20
21521 Wohltorf
Germany
Phone: + 49 33763 2362 17
Email: hello@d2g.ericschlottke.de
If you have any questions regarding data protection, you can contact us at:
Email: hello@d2g.ericschlottke.de
Which sources and data do we use?
We process personal data that we receive from you in the course of our business relationship. In addition, we process personal data that we have lawfully obtained from other companies or public authorities. Relevant personal data includes personal details, order data, data arising from the fulfilment of contractual obligations, financial information, and information relating to the use of our telemedia services.
For what purposes and on what legal basis do we process personal data?
We process personal data in accordance with the provisions of the GDPR and the German Federal Data Protection Act (BDSG).
For the fulfilment of contractual obligations (Article 6(1)(b) GDPR)
Personal data is processed (Article 4(2) GDPR) for the provision and mediation of services, for the performance of contracts, and for the execution of orders. This may include the engagement of third parties for the fulfilment of contractual obligations.
On the basis of a balancing of interests (Article 6(1)(f) GDPR)
Where necessary, we process personal data to safeguard our legitimate interests or those of third parties. Examples include business management, direct marketing, ensuring IT security, preventing and investigating criminal offences, and consulting credit agencies for creditworthiness assessments.
On the basis of consent (Article 6(1)(a) GDPR)
Where you have given consent to the processing of personal data, the processing is lawful for the specific purposes covered by that consent.
On the basis of legal obligations (Article 6(1)(c) GDPR) or in the public interest (Article 6(1)(e) GDPR)
As a company, we are subject to various legal obligations, in particular statutory requirements (e.g. tax laws). The purposes of processing include, among others, the fulfilment of statutory reporting and monitoring obligations, as well as disclosures to public authorities resulting from the nature and content of the contractual relationship.
Who receives the data?
Within our company, access to personal data is granted only to those departments and employees who require it to fulfil contractual or legal obligations.
Processors engaged by us pursuant to Article 28 GDPR may also receive personal data. Data is disclosed only where required by law, where consent has been given, or where there is a legal entitlement to disclosure. Possible recipients include financial institutions, external advisors, IT service providers and public authorities.
Is data transferred to a third country or to an international organisation?
Data is transferred to countries outside the European Economic Area (EEA) only where this is necessary for the performance of a contract, required by law, or where you have given your consent. Any transfer to a third country takes place only if an adequate level of data protection exists or if appropriate safeguards are in place, such as standard contractual clauses.
Is there an obligation to provide personal data?
Within the scope of our business relationship, you are required to provide only those personal data that are necessary for the establishment, performance and termination of a business relationship, or which we are legally required to collect. Without such data, we may generally be unable to conclude a contract, perform an order, or continue an existing contractual relationship and may be required to terminate it.
Is automated decision-making used in individual cases?
As a rule, we do not use fully automated decision-making pursuant to Article 22 GDPR for the establishment or execution of a business relationship. Should such procedures be used in individual cases, we will inform you separately where required by law.
To what extent is profiling (scoring) used?
In individual cases, we use automated procedures to evaluate certain personal aspects (profiling), for example to offer targeted advertising or to assess creditworthiness.
How long is personal data stored?
Personal data is generally processed and stored for the duration of the business relationship, including the initiation and execution of a contract.
In addition, statutory retention and documentation obligations apply, in particular under the German Commercial Code (HGB), the Fiscal Code (AO) and tax law. The retention periods specified in these laws typically range from two to ten years.
Furthermore, data retention periods are based on statutory limitation periods, which pursuant to Sections 195 et seq. of the German Civil Code (BGB) generally amount to three years, but may be longer in certain cases.
What rights do data subjects have?
Under the GDPR, you have the following rights:
Right of access to personal data stored and processed (Article 15 GDPR)
Right to rectification of inaccurate personal data (Article 16 GDPR)
Right to erasure of personal data (Article 17 GDPR)
The right to erasure is limited where processing is necessary:
for compliance with a legal obligation under Union or Member State law;
for the establishment, exercise or defence of legal claims.
Right to restriction of processing where data cannot yet be erased due to statutory obligations (Article 18 GDPR)
Right to object to processing (Article 21 GDPR)
Right to data portability where processing is based on consent or on a contract (Article 20 GDPR)
Any consent given may be withdrawn at any time with effect for the future. Withdrawal may be made in text form by email or post to the address stated above.
You also have the right to lodge a complaint with a supervisory authority (Article 77 GDPR in conjunction with Section 19 BDSG).
Supervisory authority
The competent supervisory authority in Schleswig-Holstein is:
Independent State Centre for Data Protection (ULD)
Holstenstraße 98
24103 Kiel
Germany
Phone: +49 431 988 1200
Fax: +49 431 988 1223
Email: mail@datenschutzzentrum.de
Website: www.datenschutzzentrum.de
Information on your right to object
pursuant to Article 21 GDPR
You have the right to object at any time to the processing of your personal data where such processing is based on Article 6(1)(e) GDPR (processing in the public interest) or Article 6(1)(f) GDPR (processing based on legitimate interests).
In the event of an objection, your personal data will no longer be processed unless there are compelling legitimate grounds for the processing.
The objection may be submitted in text form by email or post to the address stated above.