Privacy Policy
1. Information about the collection of personal data
(1) In the following we inform about the collection of personal data when using our website www.sotrusty.com (hereinafter “website”). Personal data are all data that can be related to you personally, e.g. B. Name, address, email addresses, user behavior.
(2) Responsible according to Art. 4 para. 7 EU General Data Protection Regulation (GDPR) is LionMint GmbH with address c / o WeWork, Taunusanlage 8 in 60329 Frankfurt am Main, Germany.
(3) When you contact us by e-mail or via a contact form, the data you provide will be saved by us to answer your questions. We delete the data arising in this context after the storage is no longer necessary, or restrict the processing if there are statutory retention requirements.
(4) If we use contracted service providers for individual functions of our offer or would like to use your data for advertising purposes, we will inform you in detail below about the respective processes. We also state the specified criteria for the storage period.
2. Rights of data subjects
(1) The user and other data subjects have the following rights in relation to their personal data:
Right to information about the personal data concerned (Art. 15 GDPR)
Right to rectification (Art. 16 GDPR)
Right to erasure (Art. 17 GDPR)
Right to restriction of processing (Art. 18 GDPR)
Right to object to processing if data processing is based on Art. 6 Para. 1 lit. e or lit. f GDPR takes place (Art. 21 GDPR); see also the following reference to the right to object according to Art. 21 GDPR
Right to data portability (Art. 20 GDPR)
Right to revoke consent at any time without affecting the lawfulness of the processing carried out based on the consent until the revocation if the data processing was based on consent in accordance with Art. 6 Para. 1 lit. a or Article 9 (2) lit. a GDPR is based
(2) You also have the right to complain to a data protection supervisory authority about the processing of your personal data by us (Art. 77 GDPR).
3. Collection of personal data when visiting our website
(1) When using the website for information purposes only, we only collect the personal data that your browser transmits to our server. If you would like to view our website, we collect the following data, which is technically necessary for us to display our website to you and to ensure stability and security (legal basis is Art. 6 Para. 1 S. 1 lit. f) GDPR) :
IP address
Date and time of the request
Time zone difference to Greenwich Mean Time (GMT)
Content of the request (specific page)
Access status / HTTP status code
amount of data transferred in each case
Website from which the request comes
Browser
Operating system and its surface
Language and version of the browser software.
(2) In addition to the aforementioned data, so-called cookies are stored on your computer when you use our website. Cookies are small text files that are stored on your hard drive, assigned to the browser you are using, and through which certain information flows to the location that sets the cookie (here by us). Cookies cannot run programs or transmit viruses to your computer. They serve to make the Internet offer more user-friendly and effective overall.
(3) Use of cookies:
a) This website uses the following types of cookies, the scope and functionality of which are explained below:
Transient cookies (see b) and
Persistent cookies (see c)
Cookies related to third party services as described below
b) Transient cookies are automatically deleted when you close the browser. These include session cookies in particular. These store a so-called session ID, with which various requests from your browser can be assigned to the joint session. This enables your computer to be recognized when you return to our website. The session cookies are deleted when you log out or close the browser.
c) Persistent cookies are automatically deleted after a specified period, which may differ depending on the cookie. You can delete the cookies in the security settings of your browser at any time.
d) You can configure your browser settings according to your wishes and e.g. B. refuse to accept third-party cookies or all cookies. Information on the management and deletion of cookies as well as corresponding instructions for the common browsers are also available at www.meine-cookies.org. However, we would like to point out that you may then not be able to use all functions of this website.
e) This stored information is stored separately from any other data that we may provide. In particular, the data of the cookies are not linked to your other data, if they are transmitted.
4. Other functions and offers on our website (especially registration)
(1) In addition to the purely informational use of our website, we offer various services that you can use if you are interested (e.g. give us feedback). To do this, you generally have to provide further personal data that we use to provide the respective service and to which the aforementioned data processing principles apply.
(2) In particular, there is the possibility for users to register on our website in order to use their own account at www.sotrusty.com and the functions of the app. To register as a user, the following mandatory information must be provided: company name, telephone number, street, house number, business telephone number, post code, city, location; In addition, a business email address must be specified and a secure password for the login defined. In addition, further information about the operation can be made as part of the account creation and a logo can also be stored. The personal data collected as part of the registration as a user are stored on the legal basis of Art. 6 Para. 1 lit. b) GDPR for processing the contractual relationship (mandatory information) and in accordance with Art. 6 Para. 1 lit. a) GDPR based on the consent of the person concerned (optional information) collected and stored. The data will be deleted at the latest by the end of the year in which the registration was canceled by the user, unless there are statutory retention requirements that require longer storage.
(3) The registered user should be aware that we offer a direct ordering option for the visitor via digital menus in the context of the presentation of the individual functions. This form of order processing is processed by us, so that personal data of the user (first name, last name, address, email address and / or telephone number) is passed on to the respective user. If possible, no sensitive information should be exchanged via this contact option.
(4) We sometimes use external service providers to process your data. These have been carefully selected and commissioned by us, are bound by our instructions and are regularly checked.
(5) If our service providers or partners are based in a country outside the European Economic Area (EEA), we will inform you about the consequences of this in the description of the offer.
(6) We do not use automated decision making or profiling.
5. Newsletter
(1) With your consent, you can subscribe to our newsletter, which we use to inform you about our current interesting offers. The advertised goods and services are named in the declaration of consent.
(2) We send the newsletter via the third-party provider SendGrid. You can find more information on SendGrid in Section 8. “Third-party services”.
(3) We use the so-called double opt-in procedure to register for our newsletter. This means that after you register, we will send you an email to the email address you provided, asking you to confirm that you want the newsletter to be sent.
(4) The only mandatory information for sending the newsletter is your email address. The provision of further, separately marked data is voluntary and is used to be able to address you personally. After your confirmation, we will save your email address for the purpose of sending the newsletter. The legal basis is Art. 6 para. 1 sentence 1 lit. a) GDPR.
(5) You can revoke your consent to the sending of the newsletter at any time and unsubscribe from the newsletter. You can declare your revocation by clicking on the link provided in every newsletter e-mail, by e-mail to lukas@sotrusty.com or by sending a message to the contact details given in the imprint.
6. Objection or revocation against the processing of your data
A. Right to object due to the special situation
You have the right, for reasons that arise from your particular situation, at any time against the processing of your personal data, which is based on Art. 6 Para. 1 lit. e (public security) or f (data processing based on a balance of interests) GDPR, to object; this also applies to profiling based on these provisions. We no longer process the personal data unless we can demonstrate compelling reasons for the processing worthy of protection that outweigh your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims.
B. Right to object to direct mail
If we process your personal data for direct marketing purposes, you have the right to object at any time to the processing of your personal data for the purpose of such advertising; this also applies to profiling insofar as it is connected to such direct advertising. If you object to processing for direct marketing purposes, the personal data will no longer be processed for these purposes.
C. Exercising the right to object
The right to object can be exercised informally, e.g. B. also by email. Our contact details can be found in the imprint.
7. Subcontractors and recipients of personal data
(1) We use subcontractors in the processing of personal data and conclude a contract with these processors in accordance with the requirements of Art. 28 GDPR.
We use the Sendgrid mail service to send notifications such as our newsletter. More information on Sendgrid can be found in Section 8. “Third-party services”.
(2) Your personal data will not be transferred to companies other than those already mentioned.
8. Third party services
(1) Use of Wix (www.wix.com)
We use the Wix (Wix.com Ltd.) service for the web design and hosting of our website. Wix.com is a certified participant in the EU-US Privacy Shield Framework. Wix.com is committed to handling all personal data received from member states of the European Union (EU) in accordance with the Privacy Shield Framework in accordance with its applicable principles. Wix.com’s privacy policy is available at https://de.wix.com/about/privacy.
The legal basis for this data processing is Art. 6 Para. 1 lit. f) GDPR, since we have a legitimate interest in ensuring the functioning of our website.
(2) Use of Sendgrid
On our website we have integrated Sendgrid, Sendgrid, Inc., 41 Corsham St Hoxton, London, N1 6DR, United Kingdom (UK) as a service for sending mail. Sendgrid is a commercial email service provider. We use mail delivery when we have to send you notifications as users for the available services.
The shipping service provider is based on our legitimate interests. Art. 6 para. 1 lit. f) GDPR and an order processing contract in accordance with 28 para. 3 sentence 1 GDPR.
Sendgrid can use the recipient’s data in pseudonymous form, ie without assignment to a user, to improve its own services, e.g. to optimize the presentation of the newsletter, to improve the technical delivery and or for statistical purposes. However, the shipping service provider does not use the data of our newsletter recipients to pass the data on to third parties or to write to them themselves.
You can view the data protection regulations of the shipping service provider here: https://sendgrid.com/policies/privacy/services-privacy-policy/.
(4) Use of Google Analytics
We use Google Analytics to analyze website usage. The data obtained from this is used to optimize our website and advertising measures.
Google Analytics is a web analytics service operated and provided by Google Inc. (1600 Amphitheater Parkway, Mountain View, CA 94043, United States). Google processes the website usage data on our behalf and is contractually obliged to take measures to ensure the confidentiality of the processed data.
The following data is recorded during your visit to the website:
-
Pages called
-
Orders including sales and ordered products
-
The achievement of “website goals” (e.g. contact requests and newsletter subscriptions)
-
Your behavior on the pages (e.g. clicks, scrolling behavior and length of stay)
-
Your approximate location (country and city)
-
Your IP address (in abbreviated form so that no clear assignment is possible)
-
Technical information such as browser, internet provider, end device and screen resolution
-
Source of origin of your visit (ie via which website or via which advertising material you came to us)
This data is transferred to a Google server in the USA. Google observes the data protection provisions of the “EU-US Privacy Shield” agreement.
Google Analytics stores cookies in your web browser for a period of two years since your last visit. These cookies contain a randomly generated user ID with which you can be recognized on future website visits.
The recorded data is saved together with the randomly generated user ID, which enables the evaluation of pseudonymous user profiles. This user-related data is automatically deleted after 14 months. Other data remain stored indefinitely in aggregate form.
Further information on data processing by Google can be found in Google’s data protection guidelines at https://www.google.de/intl/de/policies/privacy/.
9. Protection of personal data
(1) We take technical and organizational measures in accordance with the requirements of Art. 32 GDPR to protect the user’s personal data.
(2) Personal data of the user is encrypted using HTTPS when transmitted to the website.
10. Legal basis
In accordance with Art. 13 GDPR, we will inform you of the legal basis for our data processing.
Insofar as we obtain the data subject’s consent for the processing of personal data, Art. 6 para. 1 lit. a) GDPR as the legal basis.
When processing personal data, which is necessary for the performance of a contract to which the data subject is a party, Art. 6 para. 1 lit. b) GDPR as the legal basis. This also applies to processing operations that are necessary to carry out pre-contractual measures.
Insofar as processing of personal data is necessary to fulfill a legal obligation to which we are subject, Art. 6 para. 1 lit. c) GDPR as the legal basis.
The legal basis for the temporary storage of data and log files is Art. 6 Para. 1 lit. f) GDPR.
The legal basis for the processing of personal data using technically necessary cookies is Art. 6 Para. 1 lit. f) GDPR. The legal basis for the processing of personal data using cookies for analysis purposes is Art. 6 Para. 1 lit. f) GDPR.
If processing is necessary to safeguard a legitimate interest of us or a third party and if the interests, fundamental rights and freedoms of the data subject do not outweigh the first-mentioned interest, Art. 6 para. 1 lit. f) GDPR as the legal basis for processing.
11. Data protection supervisory authority and right of appeal
The data protection supervisory authority responsible for us, to which (among others) a complaint about a violation of data protection law can also be submitted is:
The Hessian representative for data protection and freedom of information
Gustav Stresemann Ring 1
Telephone: 0611-14080
Fax: 0611-1408611
Email: poststelle@datenschutz.hessen.de
12. Update of this data protection declaration
From time to time, it is necessary to adjust the content of this data protection declaration. We therefore reserve the right to change them at any time. We will send the changed version of the data protection notice to registered users by email before it comes into force and publish it in the same place as this data protection notice.
As of May 2020