Privacy Policy.
1. Data Protection at a Glance
General Information
The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any information that can be used to identify you personally. Detailed information on data protection can be found in the full Privacy Policy below.
Data Collection on This Website
Who is responsible for data collection on this website?
Data processing on this website is carried out by the website operator. The operator’s contact details can be found in the section titled “Information on the Data Controller” in this Privacy Policy.
How do we collect your data?
Some data is collected when you provide it to us directly, for example by entering information into a contact form.
Other data is collected automatically, or with your consent, when you visit this website through our IT systems. This mainly includes technical data such as your internet browser, operating system, or the time the page was accessed. This data is collected automatically as soon as you enter the website.
What do we use your data for?
Some of the data is collected to ensure the website functions properly and is provided without errors. Other data may be used to analyze user behavior. Where contracts can be concluded or initiated through the website, the transmitted data may also be processed for offers, orders, or other business inquiries.
What rights do you have regarding your data?
You have the right at any time to obtain free information about the origin, recipient, and purpose of your stored personal data. You also have the right to request that this data be corrected or deleted. If you have given consent to data processing, you may withdraw that consent at any time with effect for the future. In certain circumstances, you also have the right to request restriction of the processing of your personal data. In addition, you have the right to lodge a complaint with the competent supervisory authority.
You may contact us at any time if you have questions about this or any other data protection issue.
Analytics and Third-Party Tools
When you visit this website, your browsing behavior may be analyzed statistically. This is done primarily using analytics tools.
Detailed information about these analytics tools can be found in this Privacy Policy below.
2. Hosting
We host the content of our website with the following provider:
Mittwald
The provider is Mittwald CM Service GmbH & Co. KG, Königsberger Straße 4–6, 32339 Espelkamp, Germany (hereinafter referred to as “Mittwald”).
For more information, please refer to Mittwald’s Privacy Policy:
https://www.mittwald.de/datenschutz
Mittwald is used on the basis of Art. 6(1)(f) GDPR. We have a legitimate interest in ensuring that our website is presented as reliably as possible. Where consent has been requested, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG, insofar as such consent includes the storage of cookies or access to information on the user’s device (e.g. device fingerprinting) within the meaning of the TDDDG. Consent may be withdrawn at any time.
Data Processing Agreement
We have entered into a Data Processing Agreement (DPA) with the above-mentioned provider. This is a contract required under data protection law to ensure that the provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.
3. General Information and Mandatory Disclosures
Data Protection
The operators of this website take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the applicable data protection laws and this Privacy Policy.
When you use this website, various items of personal data are collected. Personal data is any data that can be used to identify you personally. This Privacy Policy explains what data we collect, what we use it for, and how and why this happens.
Please note that data transmission over the Internet, for example when communicating by email, may be subject to security vulnerabilities. Complete protection of data against access by third parties is not possible.
Information on the Data Controller
The controller responsible for data processing on this website is:
HERZWERK WATCHMAKING
Martin Honermann
Rathausstraße 41
85235 Egenburg
Germany
Phone: 0049 172 5933275
Email: contact@herzwerk-watchmaking.com
The data controller is the natural or legal person who alone or jointly with others determines the purposes and means of processing personal data (e.g. names, email addresses, etc.).
Storage Period
Unless a more specific retention period is stated in this Privacy Policy, your personal data will remain with us until the purpose for processing no longer applies. If you make a legitimate request for deletion or withdraw your consent to data processing, your data will be deleted unless we are entitled or required to retain it for other legally permissible reasons (e.g. tax or commercial retention obligations). In such cases, the data will be deleted once those reasons no longer apply.
Legal Bases for Data Processing on This Website
Where you have given consent to data processing, we process your personal data on the basis of Art. 6(1)(a) GDPR or, where special categories of personal data are involved, Art. 9(2)(a) GDPR. Where you have expressly consented to the transfer of personal data to third countries, processing is also based on Art. 49(1)(a) GDPR. Where you have consented to the storage of cookies or access to information on your device (e.g. through device fingerprinting), processing is additionally based on Section 25(1) TDDDG. Consent may be withdrawn at any time.
If your data is required for the performance of a contract or for pre-contractual measures, we process your data on the basis of Art. 6(1)(b) GDPR. We also process your data where necessary to comply with a legal obligation on the basis of Art. 6(1)(c) GDPR. Processing may also be based on our legitimate interests pursuant to Art. 6(1)(f) GDPR. The relevant legal basis in each individual case is explained in the following sections of this Privacy Policy.
Recipients of Personal Data
In the course of our business activities, we work with various external service providers and partners. In some cases, this requires the transfer of personal data to those external parties.
We only share personal data with external parties where this is necessary to perform a contract, where we are legally required to do so, where we have a legitimate interest in doing so pursuant to Art. 6(1)(f) GDPR, or where another legal basis permits the transfer. Where we use data processors, we only share personal data on the basis of a valid Data Processing Agreement. In the case of joint processing, a joint controller agreement will be concluded.
Withdrawal of Your Consent to Data Processing
Many data processing operations are only possible with your express consent. You may withdraw any consent you have already given at any time. The lawfulness of processing carried out before the withdrawal remains unaffected.
Right to Object to Data Processing in Special Cases and to Direct Marketing (Art. 21 GDPR)
Where data processing is based on Art. 6(1)(e) or (f) GDPR, you have the right, at any time, to object to the processing of your personal data on grounds relating to your particular situation. This also applies to profiling based on those provisions. The applicable legal basis for processing can be found in this Privacy Policy. If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or where the processing serves the establishment, exercise, or defense of legal claims (objection under Art. 21(1) GDPR).
Where your personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of your personal data for such marketing. This also applies to profiling insofar as it is related to direct marketing. If you object, your personal data will no longer be used for direct marketing purposes (objection under Art. 21(2) GDPR).
Right to Lodge a Complaint with a Supervisory Authority
In the event of a breach of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work, or the place of the alleged infringement. This right exists without prejudice to any other administrative or judicial remedies.
Right to Data Portability
You have the right to receive data that we process automatically on the basis of your consent or in performance of a contract, either for yourself or for transfer to a third party, in a commonly used, machine-readable format. Where you request direct transfer to another controller, this will only be done where technically feasible.
Right of Access, Rectification, and Erasure
Within the framework of the applicable legal provisions, you have the right at any time to obtain free information about your stored personal data, its origin, its recipients, and the purpose of processing, and, where applicable, a right to rectification or erasure of that data. You may contact us at any time in this regard or if you have further questions about personal data.
Right to Restriction of Processing
You have the right to request restriction of the processing of your personal data. You may contact us at any time to exercise this right. The right to restriction of processing applies in the following cases:
if you contest the accuracy of your personal data stored by us, we usually need time to verify this. For the duration of that review, you have the right to request restriction of processing;
if the processing of your personal data is or has been unlawful, you may request restriction of processing instead of deletion;
if we no longer need your personal data, but you require it for the establishment, exercise, or defense of legal claims, you may request restriction of processing instead of deletion;
if you have objected pursuant to Art. 21(1) GDPR, a balancing of interests must be carried out. Until it has been determined whose interests prevail, you have the right to request restriction of processing.
Where processing of your personal data has been restricted, such data may, apart from being stored, only be processed with your consent or for the establishment, exercise, or defense of legal claims, for the protection of the rights of another natural or legal person, or for reasons of important public interest of the European Union or a Member State.
SSL / TLS Encryption
For security reasons and to protect the transmission of confidential content, such as orders or inquiries that you send to us, this website uses SSL or TLS encryption.
You can recognize an encrypted connection by the change in the browser address line from “http://” to “https://” and by the lock symbol in your browser.
If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.
Objection to Unsolicited Promotional Emails
We hereby object to the use of contact data published as part of our legal notice obligations for the purpose of sending unsolicited advertising and information materials. The operators of this website expressly reserve the right to take legal action in the event of unsolicited advertising being sent, for example by spam email.
4. Data Collection on This Website
Cookies
Our website uses so-called “cookies.” Cookies are small data files and do not harm your device. They are stored either temporarily for the duration of a session (session cookies) or permanently on your device (persistent cookies). Session cookies are deleted automatically at the end of your visit. Persistent cookies remain on your device until you delete them or your browser deletes them automatically.
Cookies may originate from us (first-party cookies) or from third-party providers (third-party cookies). Third-party cookies enable the integration of certain third-party services within websites, for example cookies used to process payment services.
Cookies serve various purposes. Many cookies are technically necessary because certain website functions would not work without them, such as shopping cart functions or video display. Other cookies may be used to analyze user behavior or for advertising purposes.
Cookies required to carry out electronic communication, provide certain functions requested by you, or optimize the website (necessary cookies) are stored on the basis of Art. 6(1)(f) GDPR unless another legal basis is stated. The website operator has a legitimate interest in storing necessary cookies to ensure the technically flawless and optimized provision of its services. Where consent has been requested for the storage of cookies or similar recognition technologies, processing is carried out exclusively on the basis of that consent (Art. 6(1)(a) GDPR and Section 25(1) TDDDG). Consent may be withdrawn at any time.
You can configure your browser to notify you when cookies are set, to allow cookies only in individual cases, to exclude cookies in certain cases or generally, and to activate automatic deletion of cookies when closing the browser. Please note that disabling cookies may limit the functionality of this website.
Details of any additional cookies and services used on this website can be found in this Privacy Policy.
Contact Form
If you send us inquiries using the contact form, the information you enter in the form, including the contact details you provide, will be stored by us for the purpose of processing your inquiry and handling any follow-up questions. We do not share this data without your consent.
This data is processed on the basis of Art. 6(1)(b) GDPR where your inquiry is related to the performance of a contract or is necessary for pre-contractual measures. In all other cases, processing is based on our legitimate interest in handling inquiries efficiently (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR), where such consent has been requested. Consent may be withdrawn at any time.
The data you enter in the contact form will remain with us until you request its deletion, withdraw your consent to storage, or the purpose for retaining the data no longer applies, for example once your inquiry has been fully processed. Mandatory statutory provisions, in particular retention periods, remain unaffected.
Contact by Email or Telephone
If you contact us by email, telephone, or fax, your inquiry, including all resulting personal data (such as your name and the content of your inquiry), will be stored and processed by us for the purpose of handling your request. We do not share this data without your consent.
This data is processed on the basis of Art. 6(1)(b) GDPR where your inquiry is related to the performance of a contract or is necessary for pre-contractual measures. In all other cases, processing is based on our legitimate interest in handling inquiries efficiently (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR), where such consent has been requested. Consent may be withdrawn at any time.
The data you send to us through contact inquiries will remain with us until you request deletion, withdraw your consent to storage, or the purpose for retaining the data no longer applies, for example once your inquiry has been fully processed. Mandatory statutory provisions, in particular legal retention periods, remain unaffected.
5. Social Media
This website integrates functions of the Instagram service. These functions are provided by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.
When the social media element is active, a direct connection is established between your device and Instagram’s servers. Instagram thereby receives information that you have visited this website.
If you are logged into your Instagram account, clicking the Instagram button allows you to link content from this website to your Instagram profile. This enables Instagram to associate your visit to this website with your user account. Please note that, as the provider of this website, we have no knowledge of the content of the transmitted data or how Instagram uses it.
This service is used on the basis of your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG. Consent may be withdrawn at any time.
Where personal data is collected on our website using this tool and forwarded to Facebook or Instagram, we and Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland, are jointly responsible for this data processing pursuant to Art. 26 GDPR. This joint responsibility is limited solely to the collection of the data and its transfer to Facebook or Instagram. Any subsequent processing carried out by Facebook or Instagram is not part of this joint responsibility.
Our respective obligations have been set out in a joint controller agreement, available at:
https://www.facebook.com/legal/controller_addendum
Under this agreement, we are responsible for providing the relevant privacy information when using the Facebook or Instagram tool and for implementing the tool on our website in a privacy-compliant manner. Facebook is responsible for the security of Facebook and Instagram products. You may exercise your data subject rights in relation to data processed by Facebook or Instagram directly with Facebook. If you assert such rights with us, we are required to forward your request to Facebook.
Transfers of data to the United States are based on the EU Commission’s Standard Contractual Clauses. Further information can be found here:
https://www.facebook.com/legal/EU_data_transfer_addendum
https://privacycenter.instagram.com/policy/
https://de-de.facebook.com/help/566994660333381
For more information, please see Instagram’s Privacy Policy:
https://privacycenter.instagram.com/policy/
The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the United States designed to ensure compliance with European data protection standards for data processing in the US. Every company certified under the DPF undertakes to comply with these standards. More information is available here:
https://www.dataprivacyframework.gov/participant/4452
6. Plugins and Tools
YouTube with Enhanced Privacy Mode
This website embeds videos from YouTube. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
When you visit a page on this website that includes YouTube content, a connection to YouTube’s servers is established. In the process, the YouTube server is informed which of our pages you have visited.
If you are logged into your YouTube account, YouTube may associate your browsing behavior directly with your personal profile. You can prevent this by logging out of your YouTube account.
We use YouTube in enhanced privacy mode. According to YouTube, videos played in enhanced privacy mode are not used to personalize browsing on YouTube. Advertisements shown in enhanced privacy mode are also not personalized. No cookies are set in enhanced privacy mode. However, so-called local storage elements may be stored in the user’s browser. These function similarly to cookies, may contain personal data, and may be used for recognition purposes. More information about enhanced privacy mode is available at:
https://support.google.com/youtube/answer/171780
Please note that activating a YouTube video may trigger additional data processing operations over which we have no control.
The use of YouTube is in the interest of presenting our online services in an appealing manner and therefore constitutes a legitimate interest pursuant to Art. 6(1)(f) GDPR. Where consent has been requested, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG, insofar as such consent includes the storage of cookies or access to information on the user’s device within the meaning of the TDDDG. Consent may be withdrawn at any time.
Further information on data protection at YouTube can be found in Google’s Privacy Policy:
https://policies.google.com/privacy?hl=de
Google is certified under the EU-US Data Privacy Framework (DPF). More information is available here:
https://www.dataprivacyframework.gov/participant/5780
Google Fonts (Local Hosting)
This website uses Google Fonts for the consistent display of fonts. The Google Fonts are installed locally. No connection to Google servers is established in this process.
More information about Google Fonts is available at:
https://developers.google.com/fonts/faq
Google’s Privacy Policy is available at:
https://policies.google.com/privacy?hl=de
Cloudflare Turnstile
We use Cloudflare Turnstile (“Turnstile”) on this website. The provider is Cloudflare Inc., 101 Townsend St., San Francisco, CA 94107, USA.
Turnstile is used to verify whether data entered on this website, for example in a contact form, is entered by a human or by an automated program. To do this, Turnstile analyzes the behavior of website visitors based on various characteristics. This analysis begins automatically as soon as a visitor enters a page on which Turnstile is enabled. For this purpose, Turnstile evaluates various information, such as the IP address, the time spent on the website, or mouse movements made by the user. The data collected during the analysis is forwarded to Cloudflare.
The storage and analysis of this data is based on Art. 6(1)(f) GDPR. The website operator has a legitimate interest in protecting its online services against abusive automated activity and spam. Where consent has been requested, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG, insofar as such consent includes the storage of cookies or access to information on the user’s device within the meaning of the TDDDG. Consent may be withdrawn at any time.
Data processing is based on Standard Contractual Clauses, which are available here:
https://www.cloudflare.com/cloudflare-customer-scc/
Further information about Cloudflare Turnstile can be found here:
https://www.cloudflare.com/cloudflare-customer-dpa/
Cloudflare is certified under the EU-US Data Privacy Framework (DPF). More information is available here:
https://www.dataprivacyframework.gov/participant/5666
Source:
https://www.e-recht24.de
