Skip to Content

Privacy Policy

Preamble

With the following privacy policy, we would like to inform you about which types of your personal data (hereinafter also referred to as “data”) we process for which purposes and to what extent. The privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and particularly on our websites, in mobile applications, as well as within external online presences, such as our social media profiles (hereinafter collectively referred to as “online offering”).

The terms used are not gender-specific.

As of: 15 January 2025

Table of Contents

  • Preamble
  • Controller
  • Overview of Processing
  • Relevant Legal Bases
  • Security Measures
  • Transmission of Personal Data
  • International Data Transfers
  • General Information on Data Storage and Deletion
  • Rights of the Affected Persons
  • Provision of the Online Offering and Web Hosting
  • Contact and Inquiry Management

Controller

Björn Oliver Wiegel

Nordstraße 13A

38106 Braunschweig, Germany

Email Address: bjoern.wiegel@sailmotive.de

Overview of Processing

The following overview summarises the types of processed data and the purposes of their processing and refers to the affected persons.

Types of processed data

  • Inventory data.
  • Contact data.
  • Content data.
  • Usage data.
  • Meta, communication and procedural data.
  • Log data.

Categories of data subjects

  • Communication partners.
  • Users.

Purposes of processing

  • Communication.
  • Security measures.
  • Organisational and administrative procedures.
  • Feedback.
  • Provision of our online services and user-friendliness.
  • Information technology infrastructure.

Relevant Legal Bases

Relevant legal bases under the GDPR: In the following, you will receive an overview of the legal bases of the GDPR, on which we process personal data. Please note that in addition to the provisions of the GDPR, national data protection regulations may apply in your or our country of residence or establishment. If, in individual cases, more specific legal bases are relevant, we will inform you of these in the privacy policy.

  • Contract fulfilment and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR) – The processing is necessary for the fulfilment of a contract, of which the data subject is a party, or for the implementation of pre-contractual measures that are carried out at the request of the data subject.
  • Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR) – the processing is necessary for the purposes of the legitimate interests of the controller or a third party, provided that the interests, fundamental rights and freedoms of the data subject, who requires the protection of personal data, do not override.

National data protection regulations in Germany: In addition to the data protection regulations of the GDPR, national regulations on data protection apply in Germany. This includes in particular the law on the protection against the misuse of personal data in data processing (Federal Data Protection Act – BDSG). The BDSG contains in particular special provisions on the right to information, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, and the transfer as well as automated decision-making in individual cases including profiling. Furthermore, state data protection laws of the individual federal states may apply.

Note on the applicability of the GDPR and Swiss DPA: These data protection notices serve both to provide information under the Swiss DPA and under the General Data Protection Regulation (GDPR). For this reason, we ask you to note that due to the broader spatial application and comprehensibility, the terms of the GDPR are used. In particular, instead of the terms used in the Swiss DPA "processing" of "personal data", "overriding interest" and "particularly sensitive personal data", the terms used in the GDPR "processing" of "personal data" as well as "legitimate interest" and "special categories of data" are used. However, the legal meaning of the terms will continue to be determined in accordance with the Swiss DPA within the framework of the applicability of the Swiss DPA.

Security Measures

We take appropriate technical and organisational measures in accordance with the legal requirements, taking into account the state of the art, the implementation costs, and the nature, scope, circumstances, and purposes of the processing, as well as the different probabilities of occurrence and the extent of the threat to the rights and freedoms of natural persons, in order to ensure a level of protection appropriate to the risk.

The measures include, in particular, ensuring the confidentiality, integrity, and availability of data by controlling physical and electronic access to the data as well as the access, input, transfer, availability assurance, and separation of the data concerned. Furthermore, we have established procedures that ensure the exercise of data subject rights, the deletion of data, and responses to data threats. Additionally, we consider the protection of personal data already during the development or selection of hardware, software, and procedures in accordance with the principle of data protection, through technical design and through data protection-friendly default settings.

Transmission of Personal Data

In the context of our processing of personal data, it may occur that this data is transmitted or disclosed to other locations, companies, legally independent organisational units, or persons. Recipients of this data may include, for example, service providers commissioned with IT tasks or providers of services and content that are integrated into a website. In such cases, we comply with the legal requirements and, in particular, conclude corresponding contracts or agreements that serve to protect your data with the recipients of your data.

International Data Transfers

Data processing in third countries: If we process data in a third country (i.e., outside the European Union (EU), the European Economic Area (EEA)) or if the processing takes place in the context of using third-party services or the disclosure or transmission of data to other persons, bodies or companies , this is only done in accordance with the legal requirements. If the level of data protection in the third country has been recognised by means of an adequacy decision (Art. 45 GDPR), this serves as the basis for the data transfer. Furthermore, data transfers only occur if the level of data protection is otherwise secured, in particular through standard contractual clauses (Art. 46 para. 2 lit. c) GDPR), explicit consent or in the case of contractual or legally required transmission (Art. 49 para. 1 GDPR). Furthermore, we will inform you of the basis for the transfer of data to third countries with the individual providers from the third country, whereby the adequacy decisions are primarily considered as the basis. Information on third country transfers and existing adequacy decisions can be obtained from the information provided by the EU Commission: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en?prefLang=de. As part of the so-called “Data Privacy Framework” (DPF), the EU Commission has also recognised the level of data protection for certain companies from the USA as safe under the adequacy decision of 10.07.2023. The list of certified companies as well as further information on the DPF can be found on the website of the U.S. Department of Commerce at https://www.dataprivacyframework.gov/ (in English). We will inform you in the context of the data protection notices which service providers we use are certified under the Data Privacy Framework.

General Information on Data Storage and Deletion

We delete personal data that we process in accordance with the legal provisions as soon as the underlying consents are revoked or there are no further legal grounds for the processing. This applies in cases where the original purpose of processing ceases to exist or the data is no longer needed. Exceptions to this regulation exist when legal obligations or special interests require a longer retention or archiving of the data.

In particular, data that must be retained for commercial or tax reasons or whose storage is necessary for legal enforcement or to protect the rights of other natural or legal persons must be archived accordingly.

Our privacy notices contain additional information on the retention and deletion of data that specifically applies to certain processing processes.

In the case of multiple indications regarding the retention period or deletion deadlines of a date, the longest period shall always apply.

If a period does not explicitly begin on a specific date and is at least one year, it automatically starts at the end of the calendar year in which the event triggering the period occurred. In the case of ongoing contractual relationships in which data is stored, the event triggering the period is the time at which the termination or other conclusion of the legal relationship becomes effective.

Data that is no longer processed for the originally intended purpose, but is retained due to legal requirements or other reasons, is processed exclusively for the reasons that justify its retention.

Further information on processing processes, procedures and services:

  • Storage and deletion of data: The following general periods apply for the storage and archiving according to German law:
    • 10 years – Retention period for books and records, annual financial statements, inventories, management reports, opening balance sheet as well as the necessary work instructions and other organisational documents for their understanding (§ 147 para. 1 no. 1 in conjunction with para. 3 AO, § 14b para. 1 UStG, § 257 para. 1 no. 1 in conjunction with para. 4 HGB).
    • 8 years – Booking documents, such as invoices and expense receipts (§ 147 para. 1 no. 4 and 4a in conjunction with para. 3 sentence 1 AO as well as § 257 para. 1 no. 4 in conjunction with para. 4 HGB).
    • 6 years – Other business documents: received commercial or business letters, copies of sent commercial or business letters, other documents, insofar as they are relevant for taxation, e.g. hourly wage slips, operational accounting sheets, cost calculation documents, price labels, but also payroll documents, insofar as they are not already booking documents and cash register slips (§ 147 para. 1 no. 2, 3, 5 in conjunction with para. 3 AO, § 257 para. 1 no. 2 and 3 in conjunction with para. 4 HGB).
    • 3 years – Data that is necessary to consider potential warranty and compensation claims or similar contractual claims and rights as well as to process related inquiries, based on previous business experiences and common industry practices, will be stored for the duration of the regular statutory limitation period of three years (§§ 195, 199 BGB).

Rights of the Affected Persons

Rights of the data subjects under the GDPR: You have various rights as data subjects under the GDPR, which particularly arise from Articles 15 to 21 GDPR:

  • Right to object: You have the right to object at any time to the processing of your personal data that relates to you, for reasons arising from your particular situation, which is carried out based on Art. 6 para. 1 lit. e or f GDPR; this also applies to profiling based on these provisions. If your personal data is processed for the purpose of direct marketing, you have the right to object at any time to the processing of your personal data for the purposes of such advertising; this also applies to profiling insofar as it is related to such direct marketing.
  • Right of withdrawal for consents: You have the right to withdraw consents given at any time.
  • Right to information: You have the right to request confirmation as to whether personal data concerning you is being processed and to request information about this data as well as further information and a copy of the data in accordance with legal requirements.
  • Right to rectification: You have the right, in accordance with legal requirements, to request the completion of your personal data or the rectification of inaccurate personal data concerning you.
  • Right to deletion and restriction of processing: You have the right, in accordance with legal requirements, to request that personal data concerning you be deleted immediately, or alternatively, to request a restriction of the processing of the data in accordance with legal requirements.
  • Right to data portability: You have the right to receive data concerning you that you have provided to us, in accordance with legal requirements, in a structured, commonly used and machine-readable format, or to request its transfer to another controller.
  • Complaint to the supervisory authority: You have, without prejudice to any other administrative or judicial remedy, the right to lodge a complaint with a supervisory authority, in particular in the member state of your habitual residence, your place of work or the place of the alleged violation, if you believe that the processing of your personal data violates the provisions of the GDPR.

Provision of the Online Offering and Web Hosting

We process user data to provide our online services to them. For this purpose, we process the user's IP address, which is necessary to transmit the content and functions of our online services to the user's browser or device.

  • Types of processed data: Usage data (e.g. page views and duration of visit, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and functions); meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, involved parties). Log data (e.g. log files regarding logins or the retrieval of data or access times.).
  • Affected persons: Users (e.g. website visitors, users of online services).
  • Purposes of processing: Provision of our online services and user-friendliness; IT infrastructure (operation and provision of information systems and technical devices (computers, servers, etc.)). Security measures.
  • Storage and deletion: Deletion in accordance with the information in the section “General information on data storage and deletion.”
  • Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).

Further information on processing processes, procedures and services:

  • Provision of online services on rented storage space: For the provision of our online services, we use storage space, computing capacity, and software that we rent or obtain from a corresponding server provider (also referred to as “web host”); Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
  • Collection of access data and log files: The access to our online services is logged in the form of so-called “server log files.” The server log files may include the address and name of the retrieved websites and files, date and time of retrieval, transferred data volumes, notification of successful retrieval, browser type and version, the user's operating system, referrer URL (the previously visited page), and usually IP addresses and the requesting provider. The server log files can be used for security purposes, e.g., to prevent server overload (especially in the case of abusive attacks, so-called DDoS attacks), and also to ensure the utilisation of the servers and their stability; Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR). Deletion of data: Log file information is stored for a maximum of 30 days and then deleted or anonymised. Data that needs to be retained for evidential purposes is exempt from deletion until the final clarification of the respective incident.

Contact and Inquiry Management

When contacting us (e.g. by post, contact form, email, phone or via social media) as well as in the context of existing user and business relationships, the details of the inquiring persons are processed as far as necessary to respond to the contact requests and any requested actions.

  • Processed types of data: Inventory data (e.g. the full name, residential address, contact information, customer number, etc.); contact data (e.g. postal and email addresses or telephone numbers); content data (e.g. textual or visual messages and posts as well as the information related to them, such as e.g. details about authorship or time of creation); usage data (e.g. page views and duration of visit, click paths, usage intensity and frequency, types of devices used and operating systems, interactions with content and features). Meta-, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, involved persons).
  • Affected persons: Communication partners.
  • Purposes of processing: Communication; organisational and administrative procedures; feedback (e.g. collecting feedback via online form). Provision of our online services and user-friendliness.
  • Storage and deletion: Deletion in accordance with the information in the section “General information on data storage and deletion.”
  • Legal bases: Legitimate interests (Art. 6 Para. 1 S. 1 lit. f) GDPR). Contract fulfilment and pre-contractual requests (Art. 6 Para. 1 S. 1 lit. b) GDPR).

Further information on processing processes, procedures and services:

  • Contact form: When contacting us via our contact form, by email or other communication methods, we process the personal data transmitted to us for responding to and handling the respective request. This generally includes information such as name, contact details and, if applicable, further information that is communicated to us and necessary for appropriate processing. We use this data solely for the stated purpose of contacting and communicating; Legal bases: Contract fulfilment and pre-contractual requests (Art. 6 Para. 1 S. 1 lit. b) GDPR), Legitimate interests (Art. 6 Para. 1 S. 1 lit. f) GDPR).

Created with free data protection generator.de by Dr. Thomas Schwenke