Privacy Police

1. Introduction and Contact Details of the Controller

1.1 We are pleased that you are visiting our website and thank you for your interest. Below, we inform you about how we handle your personal data when you use our website. Personal data includes all data that can personally identify you.

1.2 The controller for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is Renee Müller-Naendrup, TrintCo, Berchardweg 8, 80995 Munich, Germany, Tel .: +49 (0) 89 / 55 29 30 70, Email: mueller-naendrup@trintco.de. The data controller is the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data.

1.3 For security reasons and to protect the transmission of personal data and other confidential content (e.g., orders or inquiries to the controller), this website uses SSL or TLS encryption. You can recognize an encrypted connection by the string “https://” and the lock symbol in your browser bar.

2. Data Collection When Visiting Our Website

When you visit our website for informational purposes only, i.e., if you do not register or otherwise provide us with information, we only collect the data that your browser sends to our server (so-called “server log files”). When you visit our website, we collect the following data, which is technically necessary for us to display the website:

  • Our visited website
  • Date and time of access
  • Amount of data sent in bytes
  • Source/referral from which you came to the page
  • Used browser
  • Used operating system
  • IP address used (if applicable: in anonymized form)

 

The processing is carried out in accordance with Art. 6 Para. 1 lit. f GDPR based on our legitimate interest in improving the stability and functionality of our website. There is no further disclosure or other use of the data. However, we reserve the right to check the server log files retrospectively if there are concrete indications of unlawful use.

3. Cookies

To make visiting our website attractive and to enable the use of certain functions, we use cookies, which are small text files that are stored on your device. Some of the cookies we use are automatically deleted after you close your browser (so-called “session cookies”), while others remain on your device and enable us to store your preferences (so-called “persistent cookies”). You can find out the storage duration from the overview of cookie settings in your web browser.

If individual cookies used by us also process personal data, the processing is carried out in accordance with Art. 6 Para. 1 lit. b GDPR either to fulfill the contract, in accordance with Art. 6 Para. 1 lit. a GDPR in the case of consent given, or in accordance with Art. 6 Para. 1 lit. f GDPR to safeguard our legitimate interests in the best possible functionality of the website and a customer-friendly and effective design of the site visit.

You can configure your browser so that you are informed about the setting of cookies and can decide on their acceptance individually or exclude the acceptance of cookies for specific cases or in general.

Please note that if you do not accept cookies, the functionality of our website may be limited.

4. Contact

When contacting us (e.g., via contact form or email), personal data is collected. The data collected when using a contact form can be seen from the respective contact form. This data is stored and used solely for the purpose of responding to your request or for contacting you and the associated technical administration. The legal basis for processing this data is our legitimate interest in responding to your request pursuant to Art. 6 Para. 1 lit. f GDPR. If your contact is aimed at concluding a contract, the additional legal basis for processing is Art. 6 Para. 1 lit. b GDPR. Your data will be deleted after final processing of your request. This is the case if it can be inferred from the circumstances that the matter concerned has been finally clarified and provided that there are no statutory retention obligations.

5. Web Analytics Services

Google Analytics 4

This website uses Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland (“Google”), which enables an analysis of your use of our website.

By default, when visiting the website, Google Analytics 4 sets cookies that are small pieces of text stored on your device and collect certain information. This information includes your IP address, which is however truncated by Google to exclude direct identifiability.

The information is transmitted to Google’s servers and processed there. Transfers to Google LLC in the United States are also possible.

Google uses the information collected on our behalf to evaluate your use of the website, compile reports on website activity for us, and provide other services related to website usage and internet usage. The IP address transmitted by your browser within the scope of Google Analytics is not merged with other data from Google. The data collected during the use of Google Analytics 4 is stored for a period of two months and then deleted.

All processing described above, particularly the setting of cookies on the device used, only occurs if you have given us your explicit consent in accordance with Art. 6 Para. 1 lit. a GDPR. Without your consent, the use of Google Analytics 4 is not activated during your visit to the site. You can revoke your consent at any time with effect for the future. To exercise your right of withdrawal, please deactivate this service using the “Cookie Consent Tool” provided on the website.

We have entered into a data processing agreement with Google to ensure the protection of our website visitors’ data and to prohibit unauthorized disclosure to third parties. For the transfer of data to the USA, Google relies on standard contractual clauses of the European Commission, which are intended to ensure compliance with the European level of data protection. Further legal information on Google Analytics 4, including a copy of the mentioned standard contractual clauses, can be found at https://policies.google.com/privacy?hl=en&gl=en and https://policies.google.com/technologies/partner-sites.

Demographic Features Google Analytics 4 uses the special feature “demographic features” and can thus create statistics that provide information about the age, gender, and interests of website visitors. This is done through the analysis of advertising and information from third-party providers. This allows target groups for marketing activities to be identified. However, the collected data cannot be attributed to any specific individual and is deleted after storage for a period of two months.

Google Signals As an extension to Google Analytics 4, Google Signals may be used on this website to create cross-device reports. If you have enabled personalized ads and linked your devices to your Google account, Google, subject to your consent to the use of Google Analytics pursuant to Art. 6 Para. 1 lit. a GDPR, can analyze your usage behavior across devices and create database models, including cross-device conversions. We do not receive any personal data from Google, only statistics. If you wish to stop cross-device analysis, you can disable the “Personalized Advertising” feature in your Google account settings. Follow the instructions on this page: https://support.google.com/ads/answer/2662922?hl=en. For more information on Google Signals, visit the following link: https://support.google.com/analytics/answer/7532985?hl=en.

UserIDs As an extension to Google Analytics 4, the “UserIDs” feature may be used on this website. If you have consented to the use of Google Analytics 4 in accordance with Art. 6 Para. 1 lit. a GDPR, set up an account on this website, and log in with this account on different devices, your activities, including conversions, can be analyzed across devices.

6. Site Functionalities

6.1 Google Web Fonts

This site uses web fonts from the following provider for a uniform display of fonts: Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland.

When a page is accessed, your browser loads the required web fonts into its browser cache to display texts and fonts correctly and establishes a direct connection to the provider’s servers. Certain browser information, including your IP address, is transmitted to the provider.

Data may also be transferred to: Google LLC, USA.

The processing of personal data in connection with establishing a connection with the font provider is only carried out if you have given us your express consent pursuant to Art. 6 Para. 1 lit. a GDPR. You can revoke your consent at any time with effect for the future by deactivating this service via the “Cookie Consent Tool” provided on the website. If your browser does not support web fonts, a standard font will be used from your computer.

The provider relies on standard contractual clauses of the European Commission for the transfer of data to the USA, which are intended to ensure compliance with the European level of data protection.

6.2 hCaptcha

This website uses the CAPTCHA service from the following provider: Intuition Machines, Inc., 350 Alabama St, San Francisco, CA 94110, USA.

The service verifies whether input is made by a natural person or is done abusively by machine and automated processing and blocks spam, DDoS attacks, and similar automated malicious access. To ensure that an action is taken by a human rather than an automated bot, Cloudflare Turnstile collects the IP address of the device used, detection data of the browser and operating system type used, as well as the date and duration of the visit, and transmits this data for evaluation to the provider’s servers.

The legal basis is our legitimate interest in determining individual responsibility on the internet and preventing abuse and spam in accordance with Art. 6 Para. 1 lit. f GDPR.

We have concluded a data processing agreement with the provider to ensure the protection of our website visitors’ data and to prohibit unauthorized disclosure to third parties.

The provider relies on standard contractual clauses of the European Commission for the transfer of data to the USA, which are intended to ensure compliance with the European level of data protection.

7. Rights of the Data Subject

7.1 The applicable data protection law grants you, as the data subject, the following rights regarding the processing of your personal data by the controller (information and intervention rights), with reference to the legal basis for exercising the respective rights:

Right to information pursuant to Art. 15 GDPR; Right to rectification pursuant to Art. 16 GDPR; Right to erasure pursuant to Art. 17 GDPR; Right to restriction of processing pursuant to Art. 18 GDPR; Right to notification pursuant to Art. 19 GDPR; Right to data portability pursuant to Art. 20 GDPR; Right to withdraw consent granted pursuant to Art. 7 Para. 3 GDPR; Right to lodge a complaint pursuant to Art. 77 GDPR.

7.2 RIGHT TO OBJECT

IF WE PROCESS YOUR PERSONAL DATA BASED ON OUR OVERRIDING LEGITIMATE INTERESTS WITHIN THE FRAMEWORK OF A BALANCING OF INTERESTS, YOU HAVE THE RIGHT TO OBJECT TO THIS PROCESSING AT ANY TIME, FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION, WITH EFFECT FOR THE FUTURE.

IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL CEASE PROCESSING THE CONCERNED DATA. HOWEVER, FURTHER PROCESSING MAY CONTINUE IF WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING THAT OVERRIDE YOUR INTERESTS, FUNDAMENTAL RIGHTS, AND FREEDOMS, OR IF THE PROCESSING IS FOR THE ESTABLISHMENT, EXERCISE, OR DEFENSE OF LEGAL CLAIMS.

IF WE PROCESS YOUR PERSONAL DATA FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA CONCERNING SUCH MARKETING AT ANY TIME. YOU CAN EXERCISE THIS RIGHT TO OBJECT AS DESCRIBED ABOVE.

IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL CEASE PROCESSING THE CONCERNED DATA FOR DIRECT MARKETING PURPOSES.

8.DURATION OF STORAGE OF PERSONAL DATA

The duration of storage of personal data is based on the respective legal basis, the purpose of processing, and, if applicable, additionally on the respective statutory retention period (e.g., commercial and tax retention periods).

For the processing of personal data based on explicit consent pursuant to Art. 6 Para. 1 lit. a GDPR, the data concerned will be stored until you revoke your consent.

If there are statutory retention periods for data processed within the scope of contractual or similar legal obligations based on Art. 6 Para. 1 lit. b GDPR, this data will be routinely deleted after the retention periods expire, provided it is no longer necessary for the performance of the contract or the initiation of contracts and/or there is no longer a legitimate interest on our part in continuing storage.

For the processing of personal data based on Art. 6 Para. 1 lit. f GDPR, this data will be stored until you exercise your right to object under Art. 21 Para. 1 GDPR, unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the processing is necessary for the establishment, exercise, or defense of legal claims.

For the processing of personal data for direct marketing purposes based on Art. 6 Para. 1 lit. f GDPR, this data will be stored until you exercise your right to object under Art. 21 Para. 2 GDPR.

Unless otherwise indicated by the other information in this declaration regarding specific processing situations, stored personal data will be deleted when they are no longer necessary for the purposes for which they were collected or otherwise processed.