Below, obst-consulting would like to inform you comprehensively and in detail about how we shall protect your privacy, and how personal data is processed within the framework of our websites and/or our online platforms. Personal data will be deleted as soon as possible and will never be used for advertising purposes, or be passed on, without your consent.
If the information provided below is insufficient or incomprehensible, please do not hesitate to contact us.
The data protection declaration of the obst-consulting is based on the terms used by the European legislator for the adoption of the General Data Protection Regulation (GDPR). Our data protection declaration should be legible and understandable for the general public, as well as our customers and business partners. To ensure this, we would like to first explain the terminology used.
1. “Personal data” means any information relating to an identified or identifiable natural person (hereinafter referred to as "data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by assignment to an identifier such as a name, an identification number, location data, an online identifier or to one or more special characteristics which express the physical, physiological, genetic, psychological, economic, cultural or social identity of that natural person.
2."Processing" means any operation carried out with or without the aid of automated procedures or any such series of operations relating to personal data, such as the collection, conception, organisation, arrangement, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or any other form of provision, reconciliation or linking, restriction, erasure or destruction.
3. "Restriction of processing" means the marking of stored personal data with the aim of restricting or blocking their future processing.
4. "Profiling" means any automated processing of personal data consisting in the use of such personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects relating to the work performance, economic situation, health, personal preferences, interests, reliability, behaviour, location or relocation of that natural person.
5. "Pseudonymisation" means the processing of personal data in such a way that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that this additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person.
6. "Controller" means the natural or legal person, authority, institution or other body which, alone or in association with others, decides on the purposes and means of processing personal data; where the purposes and means of such processing are laid down by Union law or by the law of the Member States, the controller or the specific criteria for his appointment may be laid down by Union law or by the law of the Member States.
7. "Processor" means a natural or legal person, authority, institution or other body processing personal data on behalf of the data controller.
8. "Recipient" means any natural or legal person, authority, institution or other body to which personal data is disclosed, whether or not it is a third party. However, authorities which may receive personal data under Union law or the law of the Member States under a particular investigation mandate shall not be considered recipients; the processing of such data by the said authorities is carried out in accordance with the applicable data protection rules and in accordance with the purposes of the processing.
9. "Third party" means any natural or legal person, authority, institution or other body, other than the data subject, the controller, the data processor and the persons authorised to process the personal data under the direct responsibility of the controller or the data processor.
10. "Consent" of the data subject means any voluntary declaration of intent, in an informed and unequivocal manner, in the form of a declaration or other clear affirmative act, in which the data subject indicates his or her consent to the processing of personal data concerning him or her.
1. Scope of the processing of personal data
In principle, we collect and use personal data of our users only insofar as this is necessary for rendering and providing our services and for providing our web and online platforms (including mobile apps).
As a general rule, any collection and/or use of personal data for other purposes take place only
(i) with the user's prior consent,
(ii) if the processing is for the purpose of performing a contract, or
(iii) for the protection of legitimate interests, except where such interests are outweighed by the data subject's interests or basic rights or basic freedoms that necessitate the protection of personal data.
Moreover, an exception applies in cases where, for practical reasons, it is not possible to obtain prior consent, or in cases where processing of the data is permitted by statutory provisions.
2. Legal bases
Insofar as personal data is processed on the basis of the data subject's consent, Article 6 (1), letter a GDPR forms the legal basis for the processing.
In cases where personal data is processed for the performance of a contract to which the data subject is a party, Article 6 (1), letter b GDPR forms the legal basis; this also applies to processing necessary for the implementation of precontractual measures.
If personal data is processed in order to comply with a legal obligation to which we are subject, Article 6 (1), letter c GDPR forms the legal basis. If processing of personal data is necessary in order to protect vital interests of the data subject or any other natural person, Article 6 (1), letter d GDPR forms the legal basis.
If processing takes place in order to protect a legitimate interest of our company or a third party, and this interest is outweighed by the data subject's interests or basic rights or basic freedoms, Article 6 (1), letter f GDPR forms the legal basis of the processing.
3. Obtaining consent / Right to revoke
Generally, consent under Article 6 (1), letter a GDPR is obtained electronically. Consent is given by ticking a box in the corresponding field for the purpose of documenting the granting of consent. The content of the declaration of consent is recorded electronically.
Right to revoke: Please note that consent once given may be wholly or partly revoked at any time with effect for the future. The lawfulness of the processing that, on the basis of the consent given, has taken place until such revocation will remain unaffected hereby. If you wish to revoke your consent, please contact us.
4. Possible recipients of personal data
In order to provide our web and/or online platforms, we shall sometimes use third-party service providers, who will, when rendering their services, operate on our behalf and in accordance with our directives (commissioned processor). These service providers may receive personal data or come into contact with personal data when rendering their services and will constitute third parties or recipients within the meaning of the GDPR.
In such cases, we shall ensure that our service providers offer sufficient guarantees that suitable technical and organisational measures exist, and processing is carried out in a manner that is in keeping with the requirements of this Regulation and safeguards the protection of the data subject's rights (cf. Article 28 GDPR).
Insofar as personal data is transmitted to third parties and/or recipients outside of commissioned processing, we shall ensure that this occurs only in compliance with the requirements of the GDPR (e.g. Article 6 (4) GDPR) and only if a corresponding legal basis exists (e.g. Article 6 (4) GDPR; see also subsection III.2).
5. Processing of data in so-called third countries
In principle, the processing of your personal data will take place within the EU or the European Economic Area ("EEA").
Merely in exceptional cases (e.g. in connection with the calling-in of service providers for rendering web analysis services) may information be transmitted to so-called "third countries". "Third parties" are countries that are outside of the European Union and the Agreement on the European Economic Area. Therefore, it cannot be automatically assumed that the level of data protection in those countries is adequate and corresponds to the standards in the EU.
If the transmitted information also includes personal data, we ensure before such a transfer that an adequate level of data protection is guaranteed in the respective third country or with the respective recipient in the third country, that you have given your consent to this, or that another reason for authorisation (e.g. Art 49 DSGVO) exists.
An appropriate level of data protection can result from a so-called "adequacy decision" of the European Commission or be ensured by using the so-called "EU standard contractual clauses". In the case of recipients in the USA, compliance with the principles of the so-called "EU-US Privacy Shield" can also ensure an appropriate level of data protection. We will be happy to provide you with further information on the appropriate and appropriate guarantees for maintaining an appropriate level of data protection upon request; the contact details can be found at the beginning of this data protection information. Information on the participants of the EU-US Privacy Shield can also be found here www.privacyshield.gov/list.
6. Data deletion and storage period
The data subject's personal data will be deleted or blocked as soon as the purpose for which the data is being processed ceases to exist. After this purpose has ceased to exist, the data will continue to be stored only if such storage is provided for by the European or national legislator in ordinances, laws or other provisions under European Union law to which our company is subject (e.g. for compliance with statutory retention duties and/or if there are legitimate interests in such storage, e.g. in the course of limitation periods for the purpose of a legal defence against any claims). The data will also be blocked or deleted when a storage period prescribed by the aforementioned standards expires, unless further storage of the data is necessary for the conclusion of a contract or for other purposes.
7. Rights of the data subject
A person whose personal data is processed is granted certain rights under the GDPR (so-called rights of the data subject, in particular Articles 12 to 22 GDPR). The data subject's individual rights are explained in greater detail in Section VII. If you wish to make use of one or more of these rights, you may contact us at any time.
Every time our website is accessed, our system collects data and information from the accessing computer's computer system in an automated manner. The following data is collected (hereinafter "Log Data"):
information on the type of browser and the version used
the user's operating system
the user's Internet service provider
the user's IP address (not personal data)
the date and time of access
websites from which the user's system accesses our website
websites accessed by the user's system via our website
the user's movements on our site
With the exception of the IP address, the above-mentioned log data does not allow any personal reference to the user; personal reference can only be established by assigning or linking the log data to an IP address.
1. Purpose and legal basis
The collection and processing of Log Data, in particular the IP address, take place for the purpose of making available to the user the content contained on our website, i.e. for the purpose of communication between the user and our web or online platform. It is necessary to temporarily store the IP address for the duration of the respective communication process. This is needed for addressing the communication between the user and our web and/or online platform and/or for making use of our web and/or online platform. Article 6 (1), letter b GDPR and/or Section 96 TKG [Telecommunications Act] and/or Section 15 (1) TMG [Telemedia Act] will, for the duration of your website visit, form the legal basis for this data processing. Any processing and storage of the IP address in log files beyond the communication process take place for the purpose of ensuring the functionality of our web and online platforms, optimising these platforms and ensuring the security of our IT systems. Article 6 (1), letter f GDPR (protection of legitimate interests) and/or Section 109 TKG form the legal basis for any storage of the IP address for these purposes beyond the communication process.
2. Data deletion and storage period
The data will be deleted as soon as it is no longer needed for attaining the purpose for which it was collected. If the data was collected for the purpose of providing the website, this will be the case when the respective session (the website visit) has ended. Any further storage of Log Data, including the IP address, for the purpose of system security will take place for a short period after the user's access to the website has ended. Further processing and/or storage of Log Data will be possible and permissible insofar as the users' IP addresses are, following the expiration of the aforementioned short storage period, deleted or masked to such an extent that it is no longer possible to allocate the Log Data to an IP address.
3. Opt-out and removal option
The collection of Log Data for the provision of the website, including the storage of Log Data in log files within the aforementioned limits, is absolutely essential for the operation of the website. Therefore, the user has no possibility of opting out. This does not apply to the processing of Log Data for analysis purposes; this is - depending upon the respective web analysis tool used and the type of data analysis (personal / anonymous / pseudonymous) - governed by Section VI.
In order to optimise our websites and adapt to the changing habits and technical requirements of our users, we use tools for so-called web analysis. In the process thereof, we measure, for example, which elements are visited by the users, whether the information searched for is easy to find, etc. This information is only interpretable and meaningful at all if a relatively large group of users is analysed. To this end, the data collected is aggregated, i.e. combined into relatively large units.
This enables us to adapt the design of websites or optimise content in cases where, for example, we discover that a relevant portion of the visitors uses new technologies or fails to find, or has difficulty finding, an existing piece of information.
On our web and online platforms, we carry out the following analyses and use the following web analysis tools:
1. Analysis of Log Data
Use of Log Data for analysis purposes takes place exclusively on an anonymous basis. In particular, Log Data is not linked to user data that could be used to identify the user; nor is Log Data linked to an IP address. Therefore, such analysis of Log Data is not subject to the provisions of the GDPR under data protection law.
It is possible to contact us via the email address given on our website. In this case, the user's personal data transmitted by email will be stored. In no event will the data be passed on to third parties, unless we need to fall back on third parties for handling the enquiry.
1. Purpose and legal basis
The data will be processed exclusively for the purpose of handling the respective enquiry or the respective user request. The other data collected during the transmission process will serve to prevent misuse of the contact form and safeguard the security of our IT systems. Insofar as data processing takes place for the purpose of fulfilling a customer order or a customer enquiry, Article 6 (1), letter b GDPR forms the legal basis for the processing of the data, regardless of whether we are contacted via the contact form or by email. If the user has given its consent, Article 6 (1), letter a GDPR forms the legal basis for the processing. Article 6 (1) f GDPR forms the legal basis for the collection of additional data during the transmission process; the legitimate interest lies here in the prevention of misuse and the safeguarding of system security (cf. subsection VI.1).
2. Data deletion and storage period
In principle, the data will be deleted as soon as it is no longer needed for attaining the purpose for which it was collected. In respect of the personal data sent by email, this will be the case when the respective communication with the user has ended, and/or the user's enquiry has been definitively answered. The communication will be deemed ended, or the enquiry definitively answered, if it is evident from the circumstances that the matter concerned has been definitively cleared up. Instead of being deleted, the data will be stored and blocked insofar as continued storage of the data is necessary for the reasons specified in subsection II.4. The personal data additionally collected during the transmission process will likewise be deleted as soon as it is no longer needed for attaining the purpose for which it was collected.
3. Opt-out and removal option
The user has the option of at any time discontinuing the communication with us and/or withdrawing its enquiry and opting out of corresponding use of its data. In such case, continued communication will not be possible. All personal data stored in the course of contact with the user will, in this case, be deleted, except where storage of the data continues for the reasons specified in subsection III.6.
Under the GDPR, the user is, in particular, entitled to the following rights as the data subject:
1. Right to information (Article 15 GDPR)
You have the right to request information on whether or not we process personal data concerning you. If our company processes personal data concerning you, you are entitled to information on
the purposes for which the data is processed;
the categories of personal data (type of data) processed;
the recipients, or categories of recipients, to whom your data has been disclosed or is yet to be disclosed; this particularly applies, if data has been disclosed, or is to be disclosed, to recipients in third countries outside of the application of the GDPR;
the planned storage period, insofar as possible; if it is not possible to specify the storage period, the criteria for defining the storage period (e.g. statutory retention periods or the like) will in any case be communicated;
your right to correction and deletion of the data concerning you, including the right to have processing restricted and/or the option of opting out (see also the following subsections in this respect);
the existence of a right to complain to a supervisory authority;
the origin of the data in the case of personal data not collected directly from you.
Furthermore, you are entitled to information on whether your personal data is the subject-matter of an automated decision as defined by Article 22 GDPR, and, if so, what decision-making criteria are taken as a basis for such automated decision (logic), and what effects and implications this automated decision could have for you.
If personal data is transmitted to a third country outside of the scope of application of the GDPR, you are entitled to information on whether and, if so, under what guarantees an adequate level of protection, within the meaning of Articles 45 and 46 GDPR, has been safeguarded at the data recipient in the third country.
You have the right to demand a copy of your personal data. In principle, data copies will be made available by us in electronic form, unless you have specified otherwise. The first copy will be free of charge; an appropriate fee may be requested for further copies. The data requested will be provided only insofar as no rights or freedoms of other persons could be impaired as a result of the sending of a copy of this data.
2. Right to correction (Article 16 GDPR)
You have the right to request that we correct your data insofar as your data is incorrect, inapplicable and/or incomplete; this right to correction includes the right to make your data complete by means of supplementary statements or notifications. Correction and/or supplementation will take place promptly, i.e. without culpable delay.
3. Right to deletion (Article 17 GDPR)
You have the right to demand that we delete your personal data insofar as
your personal data is no longer needed for the purposes for which it was collected and processed;
the data is being processed on the basis of consent given by you, and you have revoked your consent, unless there is some other legal basis for processing the data;
you have opted out of data processing in accordance with Article 21 GDPR, and no overriding legitimate reasons for continued processing exist;
you have opted out of data processing for the purpose of direct advertising in accordance with Article 21 (2) GDPR;
your personal data has been processed unlawfully;
the data concerned is a child's data collected in connection with information society services in accordance with Article 8 (1) GDPR.
No right to delete personal data exists insofar as
the right to freely express an opinion, or the right to information, conflicts with the request for deletion;
the processing of personal data is (i) necessary for compliance with a legal obligation (e.g. statutory retention duties), (ii) for the performance of public tasks, or the protection of public interests, under European Union law and/or the law of its Member States (this includes interests in the field of public health) or (iii) for archiving and/or research purposes;
the personal data is necessary for asserting, exercising or defending legal claims.
Deletion will take place promptly, i.e. without culpable delay. If we have made personal data public (e.g. on the Internet), we shall, insofar as this is technically possible and can be reasonably expected, ensure that third-party data processors are also informed of the deletion request, including the deletion of links, copies and/or replications.
4. Right to restriction of processing (Article 18 GDPR)
You have the right to have the processing of your personal data restricted in the following cases:
If you have disputed the accuracy of your personal data, you may request of us that, whilst the accuracy is being checked, your data not be used for other purposes and be restricted in this respect.
If your data is unlawfully processed, you may request that, instead of your data being deleted in accordance with Article 17 (1), letter d GDPR, use of your data be restricted in accordance with Article 18 GDPR.
If you need your personal data for asserting, exercising or defending legal claims, but your personal data is otherwise no longer needed, you may request that we limit processing to the aforementioned legal defence purposes.
If you have opted out of data processing in accordance with Article 21 (1) GDPR, and it has not yet been established whether our interests in processing outweigh your interests, you may request that, whilst this is being checked, your data not be used for other purposes and be restricted in this respect.
Personal data whose processing has been restricted at your request will, except for storage, be processed only (i) with your consent, (ii) for asserting, exercising or defending legal claims, (iii) for protecting the rights of other natural persons or legal entities or (iv) for reasons of important public interest. If a processing restriction is lifted, you will be informed thereof.
5. Right to data portability (Article 20 GDPR)
Subject to the following provisions, you have the right to request that the data concerning you be surrendered in a commonly used electronic, machine-readable data format. The right to data transfer includes the right to transmit the data to another data controller. On request, we shall therefore - insofar as technically possible - transmit data directly to a data controller designated, or yet to be designated, by you. The right to data transfer applies only to data provided by you and requires that the processing take place on the basis of consent or for the implementation of a contract and be carried out with the aid of automated procedures. The right to data transfer under Article 20 GDPR does not affect the right to data deletion under Article 17 GDPR. The data will be transferred only insofar as no rights or freedoms of other persons could be impaired as a result of the data transfer.
6. Right to opt out (Article 21 GDPR)
If personal data is processed for the performance of tasks that are in the public interest (Article 6 (1), letter e GDPR) or for the protection of legitimate interests (Article 6 (1), letter f GDPR), you may at any time, with effect for the future, opt out of the processing of personal data concerning you. If you exercise your right to opt out, we shall refrain from all further processing of your data for the aforementioned purposes, unless
the reasons for processing are compelling and worthy of protection and outweigh your interests, rights and freedoms, or
processing is necessary for asserting, exercising or defending legal claims.
You may at any time, with effect for the future, opt out of having your data used for the purpose of direct advertising; this also applies to profiling, insofar as it relates to direct advertising. If you exercise your right to opt out, we shall refrain from all further processing of your data for the purpose of direct advertising.
7. Legal protection options / Right to complain to the supervisory authority
If you have any complaints, you may at any time turn to the relevant supervisory authority of the European Union or its Member States.
Controller for the purposes of the General Data Protection Regulation (GDPR), other data protection laws applicable in Member states of the European Union and other provisions related to data protection is: