Privacy Policy
We are delighted that you are interested in our company. Data protection is of particular importance to the management of Kressin Consulting – Bernhard Kressin. It is generally possible to use the Kressin Consulting – Bernhard Kressin website without providing any personal data. However, if a data subject wishes to use particular services offered by our company through our website, the processing of personal data may be necessary. Where the processing of personal data is necessary and there is no statutory basis for such processing, we generally obtain the data subject’s consent.
Personal data, such as a data subject’s name, address, email address or telephone number, is always processed in accordance with the General Data Protection Regulation and the country-specific data protection provisions applicable to Kressin Consulting – Bernhard Kressin. Through this Privacy Policy, our company wishes to inform the public about the nature, scope and purpose of the personal data we collect, use and process. It also informs data subjects of their rights.
As the controller, Kressin Consulting – Bernhard Kressin has implemented numerous technical and organisational measures to ensure the most comprehensive protection possible for personal data processed through this website. Nevertheless, internet-based data transmission may be subject to security vulnerabilities, meaning that absolute protection cannot be guaranteed. Data subjects are therefore free to provide personal data to us by alternative means, such as by telephone.
1. Definitions
This Privacy Policy is based on the terminology used by the European legislature when adopting the General Data Protection Regulation (GDPR). It is intended to be clear and easy to understand for the public as well as for our customers and business partners. To ensure this, we explain the terminology used below.
This Privacy Policy uses the following terms, among others:
a) Personal data
Personal data means any information relating to an identified or identifiable natural person (“data subject”). An identifiable natural person is one who can be identified, directly or indirectly, particularly by reference to an identifier such as a name, identification number, location data or online identifier, or to one or more factors specific to that person’s physical, physiological, genetic, mental, economic, cultural or social identity.
b) Data subject
A data subject is any identified or identifiable natural person whose personal data is processed by the controller.
c) Processing
Processing means any operation or set of operations performed on personal data, whether or not by automated means. This includes collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making data available, alignment or combination, restriction, erasure or destruction.
d) Restriction of processing
Restriction of processing means marking stored personal data with the aim of limiting its processing in the future.
e) Profiling
Profiling means any form of automated processing of personal data that involves using such data to evaluate certain personal aspects relating to a natural person. In particular, this may include analysing or predicting aspects concerning that person’s work performance, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.
f) Pseudonymisation
Pseudonymisation means processing personal data in such a way that it can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures ensuring that the personal data is not attributed to an identified or identifiable natural person.
g) Controller
The controller is the natural or legal person, public authority, agency or other body that, alone or jointly with others, determines the purposes and means of processing personal data. Where the purposes and means of processing are determined by European Union or Member State law, the controller or the specific criteria for its nomination may be provided for by that law.
h) Processor
A processor is a natural or legal person, public authority, agency or other body that processes personal data on behalf of the controller.
i) Recipient
A recipient is a natural or legal person, public authority, agency or other body to which personal data is disclosed, whether or not that party is a third party. Public authorities that may receive personal data as part of a specific inquiry under European Union or Member State law are not regarded as recipients.
j) Third party
A third party is a natural or legal person, public authority, agency or other body other than the data subject, controller or processor, or persons authorised to process personal data under the direct authority of the controller or processor.
k) Consent
Consent means any freely given, specific, informed and unambiguous indication of the data subject’s wishes, provided through a statement or other clear affirmative action, by which the data subject signifies agreement to the processing of personal data relating to them.
2. Name and address of the controller
The controller within the meaning of the General Data Protection Regulation, other data protection legislation applicable in the Member States of the European Union and other provisions relating to data protection is:
Kressin Consulting – Bernhard Kressin
Stieglitzstrasse 25
04229 Leipzig
Germany
Telephone: +49 341 4805490
Email: info@kressin-consulting.com
Website: www.kressin-consulting.com
3. Cookies
The Kressin Consulting – Bernhard Kressin website uses cookies. Cookies are text files stored on a computer system through an internet browser.
Many websites and servers use cookies. Numerous cookies contain a unique cookie ID. This consists of a string of characters that allows websites and servers to associate the cookie with the specific browser in which it is stored. It enables visited websites and servers to distinguish the data subject’s browser from other browsers containing different cookies. A particular browser can therefore be recognised and identified by its unique cookie ID.
By using cookies, Kressin Consulting – Bernhard Kressin can provide website users with more user-friendly services that would not be possible without them.
Cookies allow us to optimise the information and services on our website for the benefit of its users. They also enable us to recognise returning users and make the website easier to use. For example, users of a website that employs cookies may not need to enter their login details on every visit because the website and the cookie stored on their computer handle this process. Another example is a shopping-basket cookie used by an online shop to remember which items a customer has placed in their virtual basket.
Data subjects may prevent our website from setting cookies at any time by adjusting the settings of their internet browser and may thereby permanently object to the use of cookies. Cookies that have already been set can also be deleted at any time through an internet browser or other software. This is possible in all commonly used browsers. If cookies are disabled, some functions of our website may not be fully available.
4. Collection of general data and information
Whenever a data subject or automated system accesses the Kressin Consulting – Bernhard Kressin website, the website collects a range of general data and information. This information is stored in the server log files and may include:
- the browser types and versions used;
- the operating system used by the accessing system;
- the website from which the accessing system reached our website, known as the referrer;
- the pages accessed within our website;
- the date and time of access;
- the internet protocol address, or IP address;
- the internet service provider of the accessing system; and
- other similar data and information used to protect our information technology systems in the event of an attack.
Kressin Consulting – Bernhard Kressin does not use this general data and information to draw conclusions about the data subject. Instead, the information is required to:
- deliver the content of our website correctly;
- optimise our website content and its advertising;
- ensure the continuing functionality of our information technology systems and website technology; and
- provide law-enforcement authorities with the information required for prosecution in the event of a cyberattack.
Kressin Consulting – Bernhard Kressin therefore analyses this anonymously collected data for statistical purposes and to improve data protection and security within the company, ultimately ensuring the highest possible level of protection for the personal data we process. Anonymous server log-file data is stored separately from any personal data provided by a data subject.
5. Contact through the website
In accordance with statutory requirements, the Kressin Consulting – Bernhard Kressin website provides information that allows users to contact our company quickly by electronic means and communicate with us directly. This includes a general email address.
If a data subject contacts the controller by email or through a contact form, the personal data they provide is stored automatically. Personal data supplied voluntarily in this way is stored for the purpose of processing the enquiry or contacting the data subject. This personal data is not disclosed to third parties.
6. Routine erasure and restriction of personal data
The controller processes and stores a data subject’s personal data only for as long as necessary to fulfil the purpose for which it is stored, or for the period required by the European or another competent legislature under laws or regulations to which the controller is subject.
If the purpose for storing the data no longer applies, or if a retention period prescribed by the European or another competent legislature expires, the personal data is routinely restricted or erased in accordance with statutory requirements.
7. Rights of the data subject
a) Right to confirmation
Every data subject has the right to obtain confirmation from the controller as to whether personal data relating to them is being processed. A data subject wishing to exercise this right may contact a member of the controller’s staff at any time.
b) Right of access
Every data subject has the right to obtain, free of charge and at any time, information from the controller about the personal data stored concerning them, together with a copy of that information. The data subject is also entitled to receive the following information:
- the purposes of the processing;
- the categories of personal data concerned;
- the recipients or categories of recipients to whom the personal data has been or will be disclosed, particularly recipients in third countries or international organisations;
- where possible, the intended period for which the personal data will be stored or, where this is not possible, the criteria used to determine that period;
- the existence of a right to request rectification or erasure of personal data, restriction of processing by the controller or to object to such processing;
- the right to lodge a complaint with a supervisory authority;
- where the personal data was not collected from the data subject, any available information concerning its source; and
- the existence of automated decision-making, including profiling, as referred to in Article 22(1) and (4) GDPR and, at least in such cases, meaningful information about the logic involved and the significance and intended consequences of such processing for the data subject.
The data subject also has the right to be informed whether personal data has been transferred to a third country or international organisation. Where this is the case, the data subject is entitled to information about the appropriate safeguards relating to the transfer.
A data subject wishing to exercise this right may contact a member of the controller’s staff at any time.
c) Right to rectification
Every data subject has the right to obtain without undue delay the rectification of inaccurate personal data concerning them. Taking account of the purposes of the processing, the data subject also has the right to have incomplete personal data completed, including by providing a supplementary statement.
A data subject wishing to exercise this right may contact a member of the controller’s staff at any time.
d) Right to erasure (“right to be forgotten”)
Every data subject has the right to obtain from the controller the erasure of personal data concerning them without undue delay where one of the following grounds applies and the processing is not necessary:
- the personal data is no longer necessary for the purposes for which it was collected or otherwise processed;
- the data subject withdraws the consent on which the processing is based under Article 6(1)(a) or Article 9(2)(a) GDPR, and there is no other legal basis for the processing;
- the data subject objects to the processing under Article 21(1) GDPR and there are no overriding legitimate grounds for the processing, or the data subject objects under Article 21(2) GDPR;
- the personal data has been processed unlawfully;
- the personal data must be erased to comply with a legal obligation under European Union or Member State law to which the controller is subject; or
- the personal data was collected in connection with information society services offered under Article 8(1) GDPR.
Where one of these grounds applies and a data subject wishes to request the erasure of personal data stored by Kressin Consulting – Bernhard Kressin, they may contact a member of the controller’s staff at any time. Kressin Consulting – Bernhard Kressin will ensure that the request is fulfilled without undue delay.
Where Kressin Consulting – Bernhard Kressin has made personal data public and is required under Article 17(1) GDPR to erase it, the company will, taking account of available technology and implementation costs, take reasonable steps, including technical measures, to inform other controllers processing the published personal data that the data subject has requested the erasure of any links to, or copies or reproductions of, that personal data, insofar as the processing is not required. Kressin Consulting – Bernhard Kressin will take the necessary action in each individual case.
e) Right to restriction of processing
Every data subject has the right to obtain restriction of processing from the controller where one of the following conditions applies:
- the data subject disputes the accuracy of the personal data, for a period allowing the controller to verify its accuracy;
- the processing is unlawful, but the data subject opposes erasure and requests restriction of its use instead;
- the controller no longer requires the personal data for processing purposes, but the data subject requires it to establish, exercise or defend legal claims; or
- the data subject has objected to processing under Article 21(1) GDPR and it has not yet been determined whether the controller’s legitimate grounds override those of the data subject.
Where one of these conditions applies and a data subject wishes to request the restriction of personal data stored by Kressin Consulting – Bernhard Kressin, they may contact a member of the controller’s staff at any time. Kressin Consulting – Bernhard Kressin will arrange for the processing to be restricted.
f) Right to data portability
Every data subject has the right to receive personal data concerning them that they have provided to a controller in a structured, commonly used and machine-readable format. They also have the right to transmit that data to another controller without obstruction from the controller to which it was originally provided, where the processing is based on consent under Article 6(1)(a) or Article 9(2)(a) GDPR, or on a contract under Article 6(1)(b) GDPR, and the processing is carried out by automated means. This does not apply where processing is necessary to perform a task carried out in the public interest or in the exercise of official authority vested in the controller.
When exercising the right to data portability under Article 20(1) GDPR, the data subject also has the right to have personal data transmitted directly from one controller to another where technically feasible, provided that this does not adversely affect the rights and freedoms of others.
A data subject wishing to exercise the right to data portability may contact a member of staff at Kressin Consulting – Bernhard Kressin at any time.
g) Right to object
Every data subject has the right to object at any time, on grounds relating to their particular situation, to the processing of personal data concerning them based on Article 6(1)(e) or (f) GDPR. This also applies to profiling based on those provisions.
If an objection is made, Kressin Consulting – Bernhard Kressin will no longer process the personal data unless we can demonstrate compelling legitimate grounds for the processing that override the data subject’s interests, rights and freedoms, or unless the processing is required to establish, exercise or defend legal claims.
Where Kressin Consulting – Bernhard Kressin processes personal data for direct-marketing purposes, the data subject has the right to object at any time to the processing of personal data for such marketing. This also applies to profiling insofar as it is related to direct marketing. If the data subject objects to processing for direct-marketing purposes, Kressin Consulting – Bernhard Kressin will no longer process the personal data for those purposes.
The data subject also has the right to object, on grounds relating to their particular situation, to the processing of personal data concerning them by Kressin Consulting – Bernhard Kressin for scientific or historical research purposes or statistical purposes under Article 89(1) GDPR, unless the processing is necessary to perform a task carried out in the public interest.
To exercise the right to object, the data subject may contact any member of staff at Kressin Consulting – Bernhard Kressin. In connection with the use of information society services, and notwithstanding Directive 2002/58/EC, the data subject may also exercise this right by automated means using technical specifications.
h) Automated individual decision-making, including profiling
Every data subject has the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning them or similarly significantly affects them, unless the decision:
- is necessary for entering into or performing a contract between the data subject and the controller;
- is authorised by European Union or Member State law to which the controller is subject and that law provides suitable measures to safeguard the data subject’s rights, freedoms and legitimate interests; or
- is based on the data subject’s explicit consent.
Where the decision is necessary for entering into or performing a contract, or is based on the data subject’s explicit consent, Kressin Consulting – Bernhard Kressin will implement suitable measures to safeguard the data subject’s rights, freedoms and legitimate interests. These measures will include, at a minimum, the right to obtain human intervention on the part of the controller, express their point of view and challenge the decision.
A data subject wishing to exercise rights relating to automated decisions may contact a member of the controller’s staff at any time.
i) Right to withdraw consent
Every data subject has the right to withdraw their consent to the processing of personal data at any time.
A data subject wishing to exercise this right may contact a member of the controller’s staff at any time.
8. Data protection provisions concerning the use of Google Analytics with anonymisation
The controller has integrated Google Analytics, including its anonymisation function, into this website. Google Analytics is a web analytics service. Web analytics involves collecting and evaluating data concerning the behaviour of website visitors. Among other things, a web analytics service records the website from which a data subject reached another website, known as the referrer; which pages were accessed; how frequently a page was viewed; and how long visitors remained on it. Web analytics is primarily used to optimise a website and evaluate the cost-effectiveness of online advertising.
The operator of Google Analytics is Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043-1351, USA.
The controller uses the “_gat._anonymizeIp” feature for web analysis through Google Analytics. This feature shortens and anonymises the IP address of the data subject’s internet connection where access to our website takes place from a Member State of the European Union or another state party to the Agreement on the European Economic Area.
Google Analytics is used to analyse visitor traffic on our website. Google uses the resulting data and information, among other purposes, to evaluate the use of our website, compile online reports showing website activity and provide other services relating to website use.
Google Analytics places a cookie on the data subject’s information technology system. Cookies are explained above. The cookie allows Google to analyse the use of our website. Each time a page on this website containing Google Analytics is accessed, the relevant Google Analytics component automatically prompts the browser on the data subject’s system to transmit data to Google for online analysis. As part of this technical process, Google may become aware of personal data such as the data subject’s IP address. Google may use this information, among other purposes, to determine the origin of visitors and clicks and subsequently facilitate commission settlements.
The cookie stores personal information such as the time and location of access and the frequency with which the data subject visits our website. Each time our website is visited, this personal data, including the IP address of the data subject’s internet connection, is transmitted to and stored by Google in the United States. Google may disclose personal data collected through this technical process to third parties.
As described above, the data subject may prevent our website from setting cookies at any time by adjusting the settings of their internet browser and may thereby permanently object to the use of cookies. Such a setting would also prevent Google from placing a cookie on the data subject’s system. A cookie already placed by Google Analytics may also be deleted at any time through the browser or other software.
The data subject may also object to and prevent the collection of data generated by Google Analytics relating to their use of this website, as well as the processing of that data by Google. To do so, the data subject must download and install the browser add-on available at tools.google.com/dlpage/gaoptout. Through JavaScript, this add-on instructs Google Analytics not to transmit data and information concerning website visits. Google regards installation of the add-on as an objection. If the data subject’s system is subsequently deleted, formatted or reinstalled, the add-on must be installed again to disable Google Analytics. If the add-on is uninstalled or disabled by the data subject or another person within their sphere of control, it may be reinstalled or reactivated.
Further information and Google’s applicable privacy provisions are available at www.google.de/intl/de/policies/privacy/ and www.google.com/analytics/terms/de.html. Further details about Google Analytics are available at www.google.com/intl/de_de/analytics/.
9. Legal basis for processing
Article 6(1)(a) GDPR serves as the legal basis for processing operations for which our company obtains consent for a specific purpose.
Where the processing of personal data is necessary to perform a contract to which the data subject is a party—for example, where processing is required to deliver goods or provide another service—the processing is based on Article 6(1)(b) GDPR. The same applies to processing necessary to take steps before entering into a contract, such as enquiries concerning our products or services.
Where our company is subject to a legal obligation requiring the processing of personal data, such as compliance with tax obligations, the processing is based on Article 6(1)(c) GDPR.
In rare cases, processing may be necessary to protect the vital interests of the data subject or another natural person. This could apply, for example, if a visitor were injured at our premises and their name, age, health insurance information or other vital information needed to be disclosed to a doctor, hospital or another third party. In such cases, processing would be based on Article 6(1)(d) GDPR.
Processing operations may also be based on Article 6(1)(f) GDPR. This legal basis applies to processing not covered by any of the grounds above where processing is necessary for the legitimate interests pursued by our company or a third party, provided that the data subject’s interests or fundamental rights and freedoms do not override those interests. Such processing is permitted in particular because the European legislature specifically acknowledged that a legitimate interest may exist where the data subject is a client of the controller, as stated in the second sentence of Recital 47 GDPR.
10. Legitimate interests pursued by the controller or a third party
Where the processing of personal data is based on Article 6(1)(f) GDPR, our legitimate interest is the conduct of our business activities for the benefit of the well-being of all our employees and stakeholders.
11. Period for which personal data is stored
The applicable statutory retention period determines how long personal data is stored. Once that period has expired, the relevant data is routinely erased, provided that it is no longer required to perform or enter into a contract.
12. Statutory or contractual requirements to provide personal data; necessity for entering into a contract; obligation to provide personal data; and possible consequences of failing to provide it
The provision of personal data may be required partly by law, for example under tax regulations, or may arise from contractual provisions, such as information concerning a contractual partner.
In some cases, a data subject must provide us with personal data so that a contract can be concluded, after which we must process that data. For example, a data subject is required to provide personal data where our company enters into a contract with them. Failure to provide the personal data would mean that the contract could not be concluded.
Before providing personal data, the data subject should contact a member of our staff. Based on the circumstances of the individual case, our staff member will explain whether providing the personal data is required by law or contract, whether it is necessary to enter into the contract, whether there is an obligation to provide it and what the consequences of failing to do so would be.
13. Automated decision-making
As a responsible company, we do not use automated decision-making or profiling.
This Privacy Policy was created using the privacy-policy generator provided by DGD Deutsche Gesellschaft für Datenschutz GmbH, which operates as an external data protection officer in Middle Franconia, in cooperation with the data protection lawyers at WILDE BEUGER SOLMECKE.