Privacy Policy
1. Information about the collection of personal data and contact details of the controller
1.1 We are pleased that you are visiting our website and thank you for your interest. Below, we inform you about the handling of your personal data when using our website. Personal data refers to any data that can be used to personally identify you.
1.2 The controller for data processing on this website in the sense of the General Data Protection Regulation (GDPR) is icertificate GmbH, Werner-von-Siemens-Str. 15, Industriepark Kottenforst, 53340 Meckenheim, Tel.:
+49 (2225) 997 920, Email: support@sslplus.de.
The controller is the natural or legal person who alone or jointly with others determines the purposes and means of processing personal data.
1.3 The controller has appointed a data protection officer for this website, who can be contacted as follows:
Torsten Fenselau-Menzel, c/o netzreform GmbH, Werner-von-Siemens-Str. 15, 53340 Meckenheim,
menzel@netzreform.de
1.4 This website uses SSL or TLS encryption for security reasons and to protect the transmission of personal data and other confidential content (e.g., orders or inquiries to the controller). You can recognize an encrypted connection by the "https://" string and the lock symbol in your browser's address bar.
2. Data collection when visiting our website
When you use our website purely for informational purposes, i.e., when you do not register or otherwise provide us with information, we only collect data that your browser transmits to our server (so-called "server log files").
When you access our website, we collect the following data that is technically necessary for us to display the website to you:
The processing is carried out in accordance with Art. 6 (1) lit. f GDPR based on our legitimate interest in improving the stability and functionality of our website. No further transmission or use of the data will take place. However, we reserve the right to check the server log files retroactively if there are concrete indications of illegal use.
3. Cookies
In order to make the visit to our website attractive and to enable the use of certain functions, we use cookies on various pages. These are small text files that are stored on your device. Some of the cookies we use are deleted after the end of the browser session, i.e., after you close your browser (so-called session cookies). Other cookies remain on your device and allow us or our partner companies (third-party cookies) to recognize your browser during your next visit (persistent cookies). When cookies are set, they collect and process certain user information such as browser and location data as well as IP address values in individual scope.
Persistent cookies are automatically deleted after a predefined period, which may vary depending on the cookie. Cookies sometimes serve the purpose of simplifying the ordering process by storing settings (e.g., remembering the contents of a virtual shopping cart for a later visit to the website). If personal data is processed by individual cookies implemented by us, the processing is carried out in accordance with Art. 6 (1) lit. b GDPR either for the performance of the contract or in accordance with Art. 6 (1) lit. f GDPR to safeguard our legitimate interests in the optimal functionality of the website as well as a customer-friendly and effective design of the site visit.
We may work with advertising partners who help us make our online offerings more interesting for you. In this case, cookies from partner companies are also stored on your hard drive (third-party cookies). If we work with such advertising partners, you will be individually and separately informed about the use of such cookies and the scope of the information collected in the following paragraphs. Please note that you can set your browser to notify you about the setting of cookies and to allow you to decide individually whether to accept them or to exclude the acceptance of cookies for specific cases or in general. Each browser differs in the way it manages cookie settings. This is described in the help menu of each browser, which explains how you can change your cookie settings. You can find them for the respective browsers under the following links:
Please note that if you do not accept cookies, the functionality of our website may be limited.
4. Contacting us
If you contact us (e.g., via contact form or email), personal data will be collected. The data collected in the case of a contact form can be seen in the respective contact form. This data is stored and used exclusively for the purpose of answering your inquiry or for contacting you and the associated technical administration. The legal basis for the processing of the data is our legitimate interest in answering your inquiry in accordance with Art. 6 (1) lit. f GDPR. If your contact aims at the conclusion of a contract, an additional legal basis for the processing is Art. 6 (1) lit. b GDPR. Your data will be deleted after the final processing of your request, which is the case when the circumstances indicate that the matter has been resolved, unless legal retention obligations are in conflict.
5. Data processing when opening a customer account and for contract processing
5.1 According to Art. 6 (1) lit. b GDPR, personal data is also collected and processed when you provide us with this data for the execution of a contract or when opening a customer account. The following data is collected for the creation of a customer account:
- First name
- Last name
- Company
- Address
- Phone number
- Fax number
- VAT ID
5.2 We store and use the data you provide for contract processing. After full processing of the contract or deletion of your customer account, your data will be blocked with regard to tax and commercial law retention periods and deleted after the expiry of these periods, unless you have expressly consented to further use of your data (e.g., customer account) or legal grounds for further data usage have been reserved, of which we will inform you accordingly below. You can delete your customer account at any time by sending a message to the address of the controller mentioned above.
6. Use of your data for direct advertising
6.1 Sending the email newsletter to existing customers If you have provided us with your email address when purchasing goods or services, we reserve the right to send you regular offers for similar goods or services from our range via email. We do not need to obtain separate consent from you for this according to § 7 (3) UWG. The data processing is carried out solely on the basis of our legitimate interest in personalized direct advertising according to Art. 6 (1) lit. f GDPR. If you no longer wish to receive newsletters, you can object to this at any time by sending a message to the address of the controller mentioned above. Of course, you will also find an unsubscribe link in every email.
7. Data processing for order processing
We may pass on your personal data to third parties as part of the contract processing. For example, to the transport company commissioned with the delivery or the payment service provider for payment processing. In all cases, we strictly observe the legal requirements. The scope of the data transmission is limited to a minimum.
8. Data security
We use appropriate technical and organizational measures to secure our website and other systems against loss, destruction, access, modification, or dissemination of your data by unauthorized persons. However, despite regular controls, absolute protection against all risks is not possible.
7. Data Processing for Order Handling
7.1 To process your order, we collaborate with the following service providers, who assist us either wholly or partially in executing the contracts concluded. Certain personal data will be transmitted to these service providers as required, following the details outlined below.
If payment service providers are employed, we explicitly inform you about this below. The legal basis for data sharing is Article 6(1)(b) GDPR.
7.2 To fulfill our contractual obligations to our customers, we collaborate with external shipping partners. We share your name and delivery address solely for the purpose of delivering goods in accordance with Article 6(1)(b) GDPR with a selected shipping partner.
7.3 For payment via credit card through Heidelpay, payment processing is carried out by Heidelberger Payment GmbH, Vangerowstraße 18, 69115 Heidelberg (hereinafter "Heidelpay"). We transfer the data provided during the ordering process exclusively for payment processing purposes in accordance with Article 6(1)(b) GDPR. The data transfer occurs only to the extent necessary for payment processing. Heidelpay forwards your data to HUELLEMANN & STRAUSS ONLINESERVICES S.A., 1, Place du Marché, 6755 Grevenmacher, Luxembourg, as necessary for payment processing in compliance with Article 6(1)(b) GDPR.
When selecting the payment option "Direct Debit via Heidelpay," you will be prompted during the ordering process to provide your personal data (first and last name, address, postal code, city, date of birth, email address, and phone number). To protect our legitimate interest in assessing the payment ability of our customers, we forward this data to Heidelberger Payment GmbH, Vangerowstr. 18, 69115 Heidelberg (hereinafter "Heidelpay") in accordance with Article 6(1)(f) GDPR for a credit check. Based on the personal data provided and other data (e.g., shopping cart, invoice amount, order history, payment experiences), Heidelpay evaluates whether the selected payment method can be granted considering risks of payment or default.
For decision-making regarding the establishment or execution of a contractual relationship, identity or creditworthiness information from the following credit agencies may also be consulted in accordance with Article 6(1)(f) GDPR:
- SCHUFA Holding AG, Kormoranweg 5, 65201 Wiesbaden
- CRIF Bürgel GmbH, Gasstraße 18, 22761 Hamburg
- Arvato Infoscore GmbH, Rheinstraße 99, 76532 Baden-Baden
- Deltavista GmbH, Kaiserstraße 217, 76133 Karlsruhe
- UNIVERSUM Business GmbH, Hugo-Junkers-Straße 3, 60386 Frankfurt am Main
- Bisnode International Group, Robert-Bosch-Straße 11, 64293 Darmstadt
- Regis24 GmbH, Wallstraße 58, 10179 Berlin
- Creditreform AG, Hellersbergstraße 12, 41460 Neuss
The credit report may contain probability values (so-called score values). If score values are included in the credit report, they are based on scientifically recognized mathematical-statistical methods. The calculation of the score values includes, but is not limited to, address data. You can object to this data processing at any time by notifying the data controller or Heidelpay. However, Heidelpay may still process your personal data if it is required for proper payment processing.
7.4 When selecting the payment option "Invoice," you will be asked during the ordering process to explicitly consent to the transmission of the information necessary for billing and claims enforcement to aifinyo finance GmbH (Tiergartenstraße 8, 01219 Dresden, hereinafter "aifinyo") in accordance with Article 6(1)(a) GDPR. This consent includes the possible transfer of claims to the refinancing Aktivbank AG, Stuttgarter Straße 20-22, 75179 Pforzheim.
For decision-making about the establishment or execution of a contractual relationship, identity or creditworthiness information from the following credit agencies may also be included in accordance with Article 6(1)(f) GDPR:
- SCHUFA Holding AG, Kormoranweg 5, 65201 Wiesbaden
- CRIF Bürgel GmbH, Gasstraße 18, 22761 Hamburg
- Arvato Infoscore GmbH, Rheinstraße 99, 76532 Baden-Baden
- Deltavista GmbH, Kaiserstraße 217, 76133 Karlsruhe
- UNIVERSUM Business GmbH, Hugo-Junkers-Straße 3, 60386 Frankfurt am Main
- Bisnode International Group, Robert-Bosch-Straße 11, 64293 Darmstadt
- Regis24 GmbH, Wallstraße 58, 10179 Berlin
- Creditreform AG, Hellersbergstraße 12, 41460 Neuss
The credit report may contain probability values (so-called score values). If score values are included in the credit report, they are based on scientifically recognized mathematical-statistical methods. The calculation of the score values includes, but is not limited to, address data. You can object to this data processing at any time by notifying the data controller or aifinyo. However, aifinyo may still process your personal data if it is required for proper payment processing. Further information can be found at https://www.aifinyo.de/datenschutz/.
... (The translation continues similarly for sections 7.5 to 8) ...
9. Web Analysis Services
This website uses Google Analytics, a web analysis service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google"). Google Analytics uses "cookies," which are text files stored on your computer that enable the analysis of your use of the website. The information generated by the cookie about your use of this website (including the truncated IP address) is generally transmitted to a Google server in the USA and stored there.
This website uses Google Analytics exclusively with the "_anonymizeIp()" extension, which ensures the anonymization of IP addresses by truncation and excludes direct personal references. Through this extension, your IP address is truncated by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area before transmission. Only in exceptional cases is the full IP address transmitted to a Google server in the USA and truncated there. In these exceptional cases, this processing is carried out in accordance with Article 6(1)(f) GDPR, based on our legitimate interest in the statistical analysis of user behavior for optimization and marketing purposes.
On our behalf, Google uses this information to evaluate your use of the website, compile reports on website activity, and provide us with other services related to website and internet use. The IP address transmitted by your browser within the framework of Google Analytics is not merged with other Google data.
You can prevent the storage of cookies by adjusting your browser software settings accordingly; however, please note that in this case, you may not be able to use all the functions of this website to their full extent. Additionally, you can prevent the collection of data generated by the cookie related to your use of the website (including your IP address) by Google and the processing of this data by Google by downloading and installing the browser plugin available at the following link:
http://tools.google.com/dlpage/gaoptout?hl=en
Alternatively to the browser plugin or within browsers on mobile devices, please click on the following link to set an opt-out cookie that will prevent future collection by Google Analytics on this website (this opt-out cookie only works in this browser and for this domain; if you delete your cookies in this browser, you must click this link again):
Disable Google Analytics
Google LLC, based in the USA, is certified under the EU-US Privacy Shield Framework, which ensures compliance with the level of data protection applicable in the EU.
More information on how Google Analytics handles user data can be found in Google's privacy policy:
https://support.google.com/analytics/answer/6004245?hl=en
10. Retargeting / Remarketing / Referral Advertising
Our website uses the features of Google AdWords Remarketing, allowing us to advertise this website in Google search results as well as on third-party websites. The provider is Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”). For this purpose, Google places a cookie in the browser of your device, which automatically enables interest-based advertising using a pseudonymous cookie ID based on the pages you have visited. The processing is based on our legitimate interest in the optimal marketing of our website in accordance with Art. 6 (1) lit. f GDPR.
Further data processing only occurs if you have consented to Google linking your internet and app browsing history to your Google account and using information from your Google account to personalize ads you view on the web. If you are logged into Google during your visit to our website, Google uses your data together with Google Analytics data to create and define audience lists for cross-device remarketing. For this purpose, your personal data is temporarily linked with Google Analytics data to form target groups.
You can permanently disable the setting of cookies for ad targeting by downloading and installing the browser plug-in available at the following link:
https://www.google.com/settings/ads/onweb/
Alternatively, you can find out more about cookie settings and make adjustments at the Digital Advertising Alliance website at www.aboutads.info. You can also set your browser to notify you when cookies are set and allow you to accept them individually or block certain cookies altogether. If you do not accept cookies, some functions of our website may be limited.
Google LLC, located in the USA, is certified under the US-EU Privacy Shield framework, ensuring compliance with the data protection level applicable in the EU. For more information on advertising and Google’s data protection, you can visit:
http://www.google.com/policies/technologies/ads/
11. Use of a Live Chat System
11.1 This website collects and stores anonymized data using technologies from LiveChat Software S.A., al. Dębowa 3, 53-134 Wrocław, Poland (www.livechatinc.com) for web analysis and to operate the live chat system for answering live support inquiries. These anonymized data can be used to create usage profiles under a pseudonym. Cookies may be used for this purpose. Cookies are small text files that are stored locally in the browser cache of the visitor. Cookies allow the internet browser to be recognized. If the collected information is related to a person, the processing is done in accordance with Art. 6 (1) lit. f GDPR based on our legitimate interest in effective customer support and statistical analysis of user behavior for optimization purposes.
The data collected through LiveChat technologies will not be used to personally identify the website visitor or be linked with personal data of the pseudonym holder without separate consent. To prevent the storage of LiveChat cookies, you can configure your internet browser to stop storing cookies or delete any existing cookies. However, disabling all cookies may result in some functions of our website not being able to work. You can object to the collection and storage of pseudonymized usage profiles for future purposes at any time by sending an informal email to the address provided in the legal notice.
11.2 This website also collects and stores pseudonymized data using technologies from Zendesk Inc., 1019 Market St, San Francisco, USA (www.zendesk.com) for web analysis and to operate the live chat system for answering live support inquiries. These pseudonymized data can be used to create usage profiles under a pseudonym. Cookies may also be used for this purpose. Cookies are small text files stored locally in the browser cache of the website visitor. These cookies enable recognition of the internet browser. If the collected information is related to a person, processing is done under Art. 6 (1) lit. f GDPR based on our legitimate interest in effective customer support and statistical analysis of user behavior for optimization purposes.
The data collected through Zendesk technologies will not be used to personally identify the website visitor or be combined with personal data about the holder of the pseudonym without separate consent. To prevent the storage of Zendesk cookies, you can configure your browser to stop saving cookies or delete existing cookies. Disabling all cookies may prevent certain functions from working. You can disable the collection and storage of pseudonymized usage profiles at any time by sending an informal email to the address provided in the legal notice.
Zendesk Inc. is certified under the US-EU Privacy Shield, ensuring compliance with the data protection level applicable in the EU.
12. Tools and Miscellaneous
12.1 This site uses so-called Web Fonts provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”) to ensure uniform font display. When you visit a page, your browser loads the necessary Web Fonts into its browser cache to display texts and fonts correctly. To do this, your browser must connect to Google's servers, which will allow Google to learn that our website has been accessed via your IP address. The use of Google Web Fonts is in the interest of a consistent and attractive presentation of our online offerings. This constitutes a legitimate interest under Art. 6 (1) lit. f GDPR. If your browser does not support Web Fonts, a standard font from your computer will be used. Google LLC, located in the USA, is certified under the US-EU Privacy Shield framework, ensuring compliance with the data protection level applicable in the EU. For more information on Google Web Fonts, please visit https://developers.google.com/fonts/faq and Google’s privacy policy: https://www.google.com/policies/privacy/.
12.2 To display our Trusted Shops quality seal and any collected reviews as well as to offer Trusted Shops products to buyers after an order, the Trusted Shops Trustbadge is integrated into this website.
This serves to protect our legitimate interests in optimal marketing by enabling a secure shopping experience in accordance with Art. 6 (1) S. 1 lit. f GDPR. The Trustbadge and the services advertised with it are offered by Trusted Shops GmbH, Subbelrather Str. 15C, 50823 Cologne. The Trustbadge is provided through a Content Delivery Network (CDN) by an external service provider. Trusted Shops GmbH also uses service providers from the USA. An adequate level of data protection is ensured. For more information on Trusted Shops GmbH's data protection, please visit:
https://www.trustedshops.de/impressum/#datenschutz
When the Trustbadge is called, the web server automatically stores a so-called server log file, which also contains your IP address, the date and time of access, the amount of data transmitted, and the requesting provider (access data), and documents the access. Some access data is stored in a security database for the analysis of security incidents. The log files are automatically deleted no later than 90 days after creation.
Further personal data is transferred to Trusted Shops GmbH if you choose to use Trusted Shops products after completing an order or have already registered for their use. The contractual agreement between you and Trusted Shops applies. For this, personal data is automatically collected from the order data. Whether you are already registered for product usage is automatically verified using a neutral parameter, the hashed email address. The email address is converted into a hash value, which Trusted Shops cannot decrypt. After verification, the parameter is automatically deleted.
This is necessary for fulfilling our and Trusted Shops’ legitimate interests in providing buyer protection and transactional review services related to the specific order, as required by Art. 6 (1) S. 1 lit. f GDPR. For more details, including on objections, refer to the Trusted Shops privacy statement linked above and in the Trustbadge.
13. Rights of the Data Subject
13.1 The applicable data protection law grants you comprehensive rights regarding the processing of your personal data (rights of access and intervention), which we outline below:
13.2 If we process your personal data based on a balance of interests, you have the right to object to this processing at any time for reasons arising from your particular situation, with future effect. If you exercise your right to object, we will stop processing the data concerned. However, further processing remains reserved if we can demonstrate compelling legitimate grounds for the processing that outweigh your interests, fundamental rights, and freedoms, or if the processing serves the assertion, exercise, or defense of legal claims. If your personal data is processed by us for direct marketing purposes, you have the right to object at any time to the processing of your personal data for such advertising. You can exercise your right to object as described above. If you exercise your right to object, we will stop processing the data concerned for direct marketing purposes.
14. Retention Period of Personal Data
The duration of the storage of personal data is based on the respective statutory retention period (e.g., commercial and tax retention periods). After the expiration of the period, the corresponding data is routinely deleted, provided it is no longer required for the fulfillment or initiation of the contract and/or there is no legitimate interest on our part in further storage. If you have provided us with your ID card as part of an order, it will be deleted upon the expiration of the validity of the purchased certificate.