Objective and Responsibility
This Data Privacy Statement is to inform you about the nature, scope and purpose of the processing of personal data related to our online service and the related websites, features and contents (hereinafter collectively referred to as “online service” or “website”).
The online service is provided by REMBE® Kersting GmbH (Zur Heide 39, 59929 Brilon, Germany) – hereinafter referred to as “provider”, “we” or “us” – who is also legally responsible under the data protection law.
Our online service is hosted by Cloudflare, Inc (101 Townsend St, San Francisco, CA 94107, USA).
You can reach out to our Data Protection Officer under: Sven Meyzis – IT.DS Beratung (Telefon: 0049 40-21091514 / E-Mail: [email protected])
The term “user” encompasses all customers, interested people, employees and visitors of our online service.
We collect and process personal data based on the following legal grounds:
Consent in accordance with Article 6 paragraph 1 (a) General Data Protection Regulation (GDPR). Consent meaning any freely given, specific, informed and unambiguous indication of agreement, which could be in the form of a statement or any other unambiguous confirmatory act, given by the data’s subject consenting to the processing of personal data relating to him or her.
Necessity for the performance of a contract or in order to take steps prior to entering into a contract according to Article 6 paragraph 1 (b) GDPR, meaning the data is required in order for us to fulfil our contractual obligations towards you or to prepare the conclusion of a contract with you.
Processing to fulfil a legal obligation in accordance with Article 6 paragraph 1 (c) GDPR, meaning that e.g. the processing of data is required by law or other provisions.
Processing in order to protect legitimate interests in accordance with Article 6 paragraph 1 (f) GDPR, meaning that the processing is necessary to protect legitimate interests pursued by us or by a third party, unless such interests are overridden by your interests or fundamental rights and freedoms which require the protection of personal data.
Data Subject Rights
You have the following rights with regards to the processing of your data through us:
The right to lodge a complaint with a supervisory authority in accordance with Article 13 paragraph 2 (d) GDPR and Article 14 paragraph 2 (e) GDPR.
Right of access in accordance with Article 15 GDPR
Right to rectification in accordance with Article 16 GDPR
Right to erasure („right to be forgotten“) in accordance with Article 17 GDPR
Right to restriction of processing in accordance with Article 18 GDPR
Right to data portability in accordance with Article 20 GDPR
Right to objection in accordance with Article 21 GDPR
Notice: Users may object to the processing of their personal data in accordance with legal allowances at any time with effect for the future. The objection may in particular be made against processing for the purposes of direct marketing.
Without prejudice to any other administrative or judicial remedy, you shall have the right to complain to a supervisory authority, in particular in the Member State of your place of residence, employment or the place of the alleged infringement, if you believe that the processing of your personal data violates the GDPR.
Data Erasure and Duration of storage
The personal data of the data subject will be erased or blocked as soon as the purpose of the storage is inapplicable. Storage of data beyond that may occur if such storage is required by the European or national legislator in EU regulations, laws or other regulations to which the controller is subject. Blocking or erasure of data also takes place when a retention period mandated by the standards mentioned expires, unless the continued storage of data is required for the conclusion of a contract or the fulfilment of contractual obligations.
Security of Processing
We have implemented appropriate and state-of-the-art technical and organisational security measures (TOMs). Thus, the data that is processed by us is protected against accidental or intentional manipulation, loss, destruction and unauthorized access.
These security measures include in particular the encrypted transfer of data between your browser and our server.
Transfer of Data to Third Parties, Subcontractors and Third Party Providers
A transfer of personal data to third parties only occurs within the framework of legal requirements. We only disclose personal data of users to third parties, if this is required e.g. for billing purposes or other purposes, if the disclosure is necessary to ensure the fulfilment of contractual obligations towards the users.
If we engage subcontractors for our online service, we have made appropriate contractual arrangements as well as adequate technical and organizational measures with these companies.
If we use content, tools or other means from other companies (hereinafter collectively referred to as “third party providers“) whose registered offices are located in a third country, it is assumed that a transfer of data to the home countries of these third party providers occurs. The transfer of personal data to third countries takes place exclusively only, if an adequate level of data protection, the user’s consent or another legal permission is present.
Concrete Data Processing
Collection of Information on the Use of the Online Service
When using our online-service, information may be transferred automatically from the browser of the user to us; this information includes the name of the accessed website, file, date and time of the access, amount of data transferred, notification about successful access, browser type and version, the user’s operating system, referrer URL (the previously visited page), IP address and the requesting provider.
The processing of this information takes place based on legitimate interests in accordance with Article 6 paragraph 1 (f) GDPR (e.g. to optimize the online service) as well as to ensure the security of processing in accordance with Article 5 paragraph 1 (f) GDPR (e.g. for the defence and clarification purposes of cyberattacks)
This information will be automatically deleted 30 days after the termination of the connection, unless any other retention periods require otherwise.
The collection of the data and the storage of the data in log files is essential for the provision of the online service. Therefore users are not entitled to the options of erasure, objection or correction.
Concrete Data Processing
When contacting us (via online form or e-mail), the data provided by the user will be processed exclusively for processing the inquiry and its handling.
Any other use of the data will only take place based on the given consent from the user.
Links to other websites
While using some of our services (e.g. in section ‘REMBE ALLIANCE’) you will be automatically redirected to other websites.
Our online service uses Google Analytics, a web analysis service of Google Inc. (“Google”).
Furthermore, you have the possibility to prevent future collection of your data when visiting this website by using the following opt-out cookie: Disable Google Analytics
We use Google’s reCAPTCHA service, which protects our site from spam and misuse. The service prevents automated software (so-called bots) from executing abusive activities on our websites, which means that it is checked whether the entries made actually come from a human being. Google collects the following data:
Referrer (address of the page where the captcha is used)
IP address of the user
Google account (if the user is registered with Google, this is recognized and assigned)
The input behavior of the user (eg, input speed into the form fields, order of selection of the input fields by the user) is used to improve pattern recognition on Google.
Browser, browser size and resolution, browser plugins, date, language settings
Mouse and touch events within the page
Our website also contains Facebook’s social network plug-in programs. These programs are solely operated by Facebook Inc., 1601 S. California Avenue, Palo Alto, California 94304, USA.
The plug-ins found on our website can be identified by the Facebook-logo or the icon “Like”. When visiting a website containing this type of plug-in, your browser directly connects to Facebook’s servers, where the plug-in content is transmitted to your browser and integrated into the website displayed. In this manner, the information that you visited our website is transmitted to Facebook. In the event that you are logged-in to your personal Facebook account when visiting our website, Facebook is capable of assigning this website visit to your FB-account. When interacting with the plug-in, e.g. clicking the “Like” button or leaving a comment, this information is transferred directly to Facebook and stored. Should you care to prevent this type of data transfer, please log out of your Facebook account and/or delete the Facebook-cookies on your computer before visiting our website.
The purpose and extent of data collection by Facebook as well as the processing and use of your data there, as well as the respective rights and possible settings to protect your privacy can be researched in the data protection information supplied by Facebook.
Cookies are information transmitted by our web server or third-party web servers to the users’ web browsers where they are stored for later retrieval. Cookies can be in the form of small files or any other types of information storage.
In the case that users do not want that cookies are stored on their computer, they will be asked to disable the corresponding option in their browser’s system settings. Saved cookies may be deleted in the system settings of the browser. The exclusion of cookies can lead to functional impairments of this online service.
Registers a unique ID that is used to generate statistical data on how the visitor uses the website
Registers a unique ID that is used to generate statistical data on how the visitor uses the website.
Used by Google Analytics to throttle request rate
This cookie is part of Cloudflare’s services – including load balancing, providing website content and providing a DNS connection for website operators.
deactivation page of the Network Advertising Initiative: http://optout.networkadvertising.org/
the US-American website: http://www.aboutads.info/choices
the European website http://www.youronlinechoices.com/uk/your-ad-choices/