We are very pleased about your interest in our business. Data protection is of particular importance to the management of Arvid Selle. The websites of Arvid Selle can generally be used without providing personal data. If a data subject wishes to use particular services through our website, however, processing of personal data may become necessary. Where processing is necessary and there is no statutory basis for it, we generally obtain the data subject’s consent.
Personal data such as a data subject’s name, address, email address or telephone number is always processed in accordance with the General Data Protection Regulation and the country-specific data-protection provisions applicable to Arvid Selle. This privacy policy informs the public about the nature, scope and purpose of the personal data that we collect, use and process, and informs data subjects about their rights.
As controller, Arvid Selle has implemented numerous technical and organisational measures designed to ensure the most complete protection possible for personal data processed through this website. Internet-based data transmissions can nevertheless have security gaps, meaning absolute protection cannot be guaranteed. Every data subject is therefore free to transmit personal data to us by alternative means, for example by telephone.
1. Definitions
This privacy policy uses the terminology employed by the European legislature when adopting the General Data Protection Regulation (GDPR). To make this policy easy to read and understand for the public, customers and business partners, the principal terms are explained below.
a) Personal data
Personal data means any information relating to an identified or identifiable natural person (“data subject”). A person is identifiable when they can be identified directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, online identifier or one or more factors specific to their physical, physiological, genetic, mental, economic, cultural or social identity.
b) Data subject
A data subject is any identified or identifiable natural person whose personal data is processed by the controller.
c) Processing
Processing means any operation or set of operations performed on personal data, whether or not by automated means, including collection, recording, organisation, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure, dissemination, alignment, combination, restriction, erasure or destruction.
d) Restriction of processing
Restriction of processing means marking stored personal data with the aim of limiting its processing in the future.
e) Profiling
Profiling means automated processing of personal data used to evaluate personal aspects relating to a natural person, in particular work performance, economic situation, health, preferences, interests, reliability, behaviour, location or movements.
f) Pseudonymisation
Pseudonymisation means processing personal data so it can no longer be attributed to a specific data subject without additional information, provided that the additional information is kept separately and protected by technical and organisational measures.
g) Controller
The controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of processing personal data.
h) Processor
A processor is a natural or legal person, public authority, agency or other body that processes personal data on behalf of the controller.
i) Recipient
A recipient is a natural or legal person, public authority, agency or another body to which personal data is disclosed, whether or not it is a third party. Public authorities receiving data within a particular inquiry under Union or Member State law are not regarded as recipients.
j) Third party
A third party is a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons authorised to process personal data under the direct authority of the controller or processor.
k) Consent
Consent is any freely given, specific, informed and unambiguous indication of the data subject’s wishes by a statement or clear affirmative action signifying agreement to the processing of their personal data.
2. Name and address of the controller
The controller within the meaning of the GDPR and other applicable data-protection law is:
Arvid Selle
Landsberger Allee 180D
10369 Berlin
Germany
Telephone: 01738529590
Email: management@anovra.de
Website: www.anovra.de
3. Cookies
The websites of Arvid Selle use cookies. Cookies are text files placed and stored on a computer system through an internet browser. Many cookies contain a unique cookie ID that allows websites and servers to distinguish the browser in which the cookie was stored from other browsers.
Cookies can enable more user-friendly services and make the website easier to use. A data subject can prevent cookies at any time through the settings of the browser used and can permanently object to cookies. Cookies already stored can also be deleted through a browser or other software. If cookies are disabled, some functions of the website may not be fully available.
4. Collection of general data and information
Each time a data subject or automated system accesses the website, the website may collect general data and information stored in server log files. This may include browser type and version, operating system, referrer, accessed subpages, date and time of access, IP address, internet service provider and comparable information used to defend against attacks on our information-technology systems.
Arvid Selle does not use this general information to draw conclusions about the data subject. The information is needed to deliver the website correctly, maintain the website and its technology, and provide law-enforcement authorities with necessary information in the event of a cyberattack. Anonymous server-log data is stored separately from personal data supplied by a data subject.
5. Contact through the website
The website contains information enabling rapid electronic contact and direct communication, including an email address. If a data subject contacts the controller by email or through a contact form, the personal data transmitted is stored automatically. Data supplied voluntarily is processed to handle the inquiry or contact the data subject and is not passed to third parties.
6. Routine erasure and blocking of personal data
The controller processes and stores personal data only for the period necessary to achieve the purpose of storage or as required by European or national law. If the purpose ceases to apply or an applicable retention period expires, personal data is routinely blocked or erased in accordance with the law.
7. Rights of the data subject
a) Right to confirmation
Every data subject has the right to obtain confirmation from the controller as to whether personal data concerning them is being processed.
b) Right of access
Every data subject has the right to obtain free information about their stored personal data and a copy of that information. This includes the purposes of processing, categories of data, recipients, envisaged retention period or criteria, rights to rectification, erasure, restriction and objection, the right to complain to a supervisory authority, the source of data not collected from the person, and meaningful information about automated decision-making including profiling. Where data is transferred to a third country, the data subject may request information on the appropriate safeguards.
c) Right to rectification
Every data subject has the right to obtain without undue delay the rectification of inaccurate personal data and to have incomplete data completed.
d) Right to erasure (“right to be forgotten”)
A data subject may request erasure without undue delay where the data is no longer necessary, consent is withdrawn and no other legal basis applies, the data subject objects and there are no overriding legitimate grounds, processing was unlawful, erasure is legally required, or data was collected in relation to information-society services. Exceptions apply in particular for freedom of expression, legal obligations, public interest, archiving or research, and legal claims.
e) Right to restriction of processing
A data subject may request restriction where accuracy is contested, processing is unlawful but erasure is opposed, the controller no longer needs the data but it is required for legal claims, or an objection is pending verification.
f) Right to data portability
Where processing is based on consent or contract and carried out by automated means, a data subject has the right to receive personal data they provided in a structured, commonly used and machine-readable format and to transmit it to another controller, where technically feasible and without adversely affecting the rights of others.
g) Right to object
A data subject has the right, on grounds relating to their particular situation, to object at any time to processing based on Article 6(1)(e) or (f) GDPR, including related profiling. The controller will stop processing unless compelling legitimate grounds override the person’s interests, rights and freedoms or processing is needed for legal claims. A person may object at any time to processing for direct marketing, including related profiling.
h) Automated individual decision-making, including profiling
A data subject has the right not to be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects them, except where necessary for a contract, authorised by law with safeguards, or based on explicit consent. Where permitted, the controller implements suitable safeguards, including human intervention and the opportunity to express a point of view and contest the decision.
i) Right to withdraw consent
A data subject has the right to withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
8. Google Analytics (with anonymisation)
The controller has integrated Google Analytics with an anonymisation function on this website. Google Analytics is a web-analysis service used to collect and evaluate information about website visits. The operator is Google Ireland Limited, Gordon House, Barrow Street, Dublin, D04 E5W5, Ireland.
The controller uses the “_gat._anonymizeIp” extension. This causes Google to shorten and anonymise a data subject’s IP address where access originates in the European Union or another state party to the European Economic Area Agreement.
The purpose is to analyse visitor flows and prepare reports about website activity. Google Analytics places a cookie on the data subject’s device and may process access time, place of access, visit frequency and the IP address. Data may be transferred to and stored in the United States and may be disclosed by Google to third parties.
The data subject can prevent cookies through browser settings and delete existing cookies. Collection and processing by Google Analytics can also be prevented by installing the browser add-on available at tools.google.com/dlpage/gaoptout. Further information is available in Google’s privacy policy and Google Analytics terms.
9. Instagram
The controller has integrated components of Instagram, an audiovisual platform for sharing photos and videos. The service is operated by Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.
When a page containing an Instagram component is accessed, the browser downloads that component and Instagram learns which subpage was visited. If the person is logged in to Instagram, Instagram can associate the visit and any interaction with the person’s account. To prevent this association, the person can log out of Instagram before visiting the website. Further information is available at Instagram Help and in Instagram’s privacy policy.
10. LinkedIn
The controller has integrated components of LinkedIn, a professional social network. LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA operates the service; LinkedIn Ireland, Wilton Plaza, Wilton Place, Dublin 2, Ireland is responsible for privacy matters outside the United States.
When a page containing a LinkedIn component is accessed, the browser downloads the component and LinkedIn learns which subpage was visited. If the person is logged in to LinkedIn, LinkedIn can associate the visit and interactions with the person’s account. The person can prevent this by logging out before visiting the website. Information on privacy and cookies is available in LinkedIn’s privacy policy and cookie policy.
11. PayPal as a payment method
The controller has integrated PayPal components. PayPal is an online payment service operated in Europe by PayPal (Europe) S.à.r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg.
If a data subject selects PayPal during an online-shop order, data required to process the payment is transmitted automatically to PayPal. This generally includes first name, surname, address, email address, IP address, telephone number and order-related data. The transmission serves payment processing and fraud prevention. PayPal may transfer data to credit agencies for identity and credit checks and to affiliated companies, service providers or subcontractors where required to perform contractual obligations.
Consent relating to personal data may be withdrawn from PayPal at any time, but withdrawal does not affect data that must be processed for contractual payment handling. PayPal’s applicable privacy information is available at paypal.com.
12. Legal basis for processing
Article 6(1)(a) GDPR is the legal basis where consent is obtained for a specific purpose. Article 6(1)(b) applies where processing is necessary to perform a contract or take pre-contractual steps, for example inquiries about products or services. Article 6(1)(c) applies where processing is required to comply with a legal obligation, such as tax duties. In rare cases, Article 6(1)(d) applies to protect the vital interests of the data subject or another person. Processing not covered by these bases may rely on Article 6(1)(f) where necessary for a legitimate interest of the controller or a third party and the interests, fundamental rights and freedoms of the data subject do not override that interest.
13. Legitimate interests pursued by the controller or a third party
Where processing is based on Article 6(1)(f) GDPR, our legitimate interest is conducting our business for the benefit of our employees and stakeholders.
14. Period for which personal data is stored
The criterion for the storage period is the applicable statutory retention period. After that period expires, the data is routinely erased unless it remains necessary to perform or initiate a contract.
15. Statutory or contractual provision of personal data
Providing personal data may be required by law, for example under tax rules, or by contract, for example information about a contracting party. A contract may require a data subject to provide personal data that we must process. Failure to provide required data may mean that the contract cannot be concluded. Before providing personal data, a data subject may contact us to clarify whether provision is required by law or contract, whether it is necessary for entering into a contract, and the possible consequences of not providing it.
16. Automated decision-making
As a responsible business, we do not use automated decision-making or profiling.