DATA PROTECTION


We treat your personal data confidentially and in accordance with the statutory data protection regulations and this data protection declaration.

The use of our website is generally possible without providing personal data. Insofar as personal data (for example name, address or e-mail addresses) is collected on our pages, this is always done, as far as possible, on a voluntary basis. This data will not be passed on to third parties without your express consent.


We point out that data transmission over the Internet (eg communication by e-mail) security gaps. A complete protection of data against access by third parties is not possible. (Source:e-Recht24)


BROWSER PLUGIN


You may refuse the use of cookies by selecting the appropriate settings on your browser, however please note that if you do this you may not be able to use the full functionality of this website. You can also prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) to Google and the processing of this data by Google by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=de.

This data protection declaration informs you about the nature, scope and purpose of the processing of personal data (hereinafter referred to as "data") within our online offer and the websites, functions and content associated with it, as well as external online presences, such as our social media profiles. (hereinafter collectively referred to as "online offer"). With regard to the terms used, such as "processing" or "controller", we refer to the definitions in Article 4 of the General Data Protection Regulation (GDPR).


TYPES OF DATA PROCESSED

- Inventory data (e.g. names, addresses).

- Contact data (e.g. e-mail, telephone numbers).

- Content data (e.g. text entries, photographs, videos).

- Usage data (e.g. websites visited, interest in content, access times).

- Meta/communication data (e.g., device information).


PURPOSE OF PROCESSING.

- Provision of the online offer, its functions and content.

- Responding to contact requests and communicating with users.

- Security measures.

- Reach measurement/marketing.


TERMS USED

"Personal data" means any information relating to an identified or identifiable natural person (hereinafter "data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. cookie) or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

"Processing" means any operation or set of operations which is performed upon personal data, whether or not by automatic means. The term is broad and encompasses virtually any handling of data.


"Controller" means the natural or legal person, public authority, agency or other body which alone or jointly with others determines the purposes and means of the processing of personal data.


RELEVANT LEGAL BASES

In accordance with Article 13 of the GDPR, we inform you of the legal basis for our data processing activities. If the legal basis is not mentioned in the Privacy Policy, the following applies: The legal basis for obtaining consent is Art. 6(1)(a) and Art. 7 DSGVO, the legal basis for processing to fulfill our services and carry out contractual measures and respond to inquiries is Art. 6(1)(b) DSGVO, the legal basis for processing to fulfill our legal obligations is Art. 6(1)(c) DSGVO, and the legal basis for processing to protect our legitimate interests is Art. 6(1)(f) DSGVO. In the event that vital interests of the data subject or another natural person require processing of personal data, Art. 6 (1) lit. d DSGVO serves as the legal basis.


Translated with www.DeepL.com/Translator (free version)DATA PROTECTION


We treat your personal data confidentially and in accordance with the statutory data protection regulations and this data protection declaration.

The use of our website is generally possible without providing personal data. Insofar as personal data (for example name, address or e-mail addresses) is collected on our pages, this is always done, as far as possible, on a voluntary basis. This data will not be passed on to third parties without your express consent.


We point out that data transmission over the Internet (eg communication by e-mail) security gaps. A complete protection of data against access by third parties is not possible. (Source:e-Recht24)


BROWSER PLUGIN


You may refuse the use of cookies by selecting the appropriate settings on your browser, however please note that if you do this you may not be able to use the full functionality of this website. You can also prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) to Google and the processing of this data by Google by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=de.

This data protection declaration informs you about the nature, scope and purpose of the processing of personal data (hereinafter referred to as "data") within our online offer and the websites, functions and content associated with it, as well as external online presences, such as our social media profiles. (hereinafter collectively referred to as "online offer"). With regard to the terms used, such as "processing" or "controller", we refer to the definitions in Article 4 of the General Data Protection Regulation (GDPR).


TYPES OF DATA PROCESSED

- Inventory data (e.g. names, addresses).

- Contact data (e.g. e-mail, telephone numbers).

- Content data (e.g. text entries, photographs, videos).

- Usage data (e.g. websites visited, interest in content, access times).

- Meta/communication data (e.g., device information).


PURPOSE OF PROCESSING.

- Provision of the online offer, its functions and content.

- Responding to contact requests and communicating with users.

- Security measures.

- Reach measurement/marketing.


TERMS USED

"Personal data" means any information relating to an identified or identifiable natural person (hereinafter "data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. cookie) or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

"Processing" means any operation or set of operations which is performed upon personal data, whether or not by automatic means. The term is broad and encompasses virtually any handling of data.


"Controller" means the natural or legal person, public authority, agency or other body which alone or jointly with others determines the purposes and means of the processing of personal data.


RELEVANT LEGAL BASES

In accordance with Article 13 of the GDPR, we inform you of the legal basis for our data processing activities. If the legal basis is not mentioned in the Privacy Policy, the following applies: The legal basis for obtaining consent is Art. 6(1)(a) and Art. 7 DSGVO, the legal basis for processing to fulfill our services and carry out contractual measures and respond to inquiries is Art. 6(1)(b) DSGVO, the legal basis for processing to fulfill our legal obligations is Art. 6(1)(c) DSGVO, and the legal basis for processing to protect our legitimate interests is Art. 6(1)(f) DSGVO. In the event that vital interests of the data subject or another natural person require processing of personal data, Art. 6 (1) lit. d DSGVO serves as the legal basis.


SECURITY MEASURES

We ask you to regularly check the content of our privacy policy. We adapt the data protection declaration as soon as the changes in the data processing carried out by us make this necessary. We will inform you as soon as the changes require an act of cooperation on your part (e.g. consent) or other individual notification.


COOPERATION WITH CONTRACT PROCESSORS AND THIRD PARTIES

If, in the course of our processing, we disclose data to other persons and companies (order processors or third parties), transmit it to them or otherwise grant them access to the data, this will only be done on the basis of a legal permission (e.g. if a transmission of the data to third parties, such as to payment service providers, is necessary for the performance of the contract pursuant to Art. 6 (1) lit. b DSGVO), you have consented, a legal obligation provides for this or on the basis of our legitimate interests (e.g. when using agents, web hosts, etc.).

If we commission third parties to process data on the basis of a so-called "order processing agreement", this is done on the basis of Art. 28 DSGVO.


TRANSFERS TO THIRD COUNTRIES

If we process data in a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)) or if this is done in the context of using third-party services or disclosing, or transferring data to third parties, this is only done if it is done to fulfill our (pre)contractual obligations, on the basis of your consent, due to a legal obligation or on the basis of our legitimate interests. Subject to legal or contractual permissions, we process or allow the processing of data in a third country only if the special requirements of Art. 44 et seq. DSGVO are met. I.e. the processing is carried out, for example, on the basis of special guarantees, such as the officially recognized determination of a level of data protection corresponding to that of the EU (e.g. for the USA by the "Privacy Shield") or compliance with officially recognized special contractual obligations (so-called "standard contractual clauses").


RIGHTS OF DATA SUBJECTS

You have the right to request confirmation as to whether data in question is being processed and to information about this data, as well as further information and a copy of the data in accordance with Art. 15 DSGVO.

You have according to. Art. 16 DSGVO the right to request the completion of the data concerning you or the correction of incorrect data concerning you.


You have the right, in accordance with Art. 17 DSGVO, to request that data concerning you be deleted without delay, or alternatively, in accordance with Art. 18 DSGVO, to request restriction of the processing of the data. You have the right to request that the data concerning you that you have provided to us be received in accordance with Art. 20 of the GDPR (smile@arabellaandmichi.de) and to request that it be transferred to other data controllers. You also have the right to lodge a complaint with the competent supervisory authority in accordance with Art. 77 DSGVO.


RIGHT OF REVOCATION

You have the right to revoke given consents pursuant to Art. 7 (3) DSGVO with effect for the future.


RIGHT OF OBJECTION

You may object to the future processing of data relating to you in accordance with Art. 21 DSGVO at any time. The objection may be made in particular against processing for direct marketing purposes.


COOKIES AND RIGHT OF OBJECTION TO DIRECT ADVERTISING

Cookies" are small files that are stored on users' computers. Different information can be stored within the cookies. A cookie is primarily used to store information about a user (or the device on which the cookie is stored) during or after his visit within an online offer. Temporary cookies, or "session cookies" or "transient cookies", are cookies that are deleted after a user leaves an online offer and closes his browser. In such a cookie, for example, the contents of a shopping cart in an online store or a login jam can be stored. Cookies that remain stored even after the browser is closed are referred to as "permanent" or "persistent". For example, the login status can be stored if users visit them after several days. Likewise, the interests of users can be stored in such a cookie, which is used for range measurement or marketing purposes. Third-party cookies" are cookies that are offered by providers other than the responsible party that operates the online offer (otherwise, if they are only its cookies, they are referred to as "first-party cookies").

We may use temporary and permanent cookies and provide information about this in our privacy policy.

If users do not want cookies to be stored on their computer, they are asked to deactivate the corresponding option in the system settings of their browser. Stored cookies can be deleted in the system settings of the browser. The exclusion of cookies can lead to functional restrictions of this online offer.


A general objection to the use of cookies used for online marketing purposes can be declared for a large number of the services, especially in the case of tracking, via the U.S. site http://www.aboutads.info/choices/ or the EU site http://www.youronlinechoices.com/. Furthermore, the storage of cookies can be achieved by disabling them in the browser settings. Please note that you may then not be able to use all functions of this online offer.


Browser plugin

You may refuse the use of cookies by selecting the appropriate settings on your browser, however please note that if you do this you may not be able to use the full functionality of this website. You can also prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) to Google, as well as the processing of this data by Google, by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=de 

(source: e-recht24)


DELETION OF DATA

The data processed by us will be deleted or restricted in its processing in accordance with Articles 17 and 18 DSGVO. Unless expressly stated within the scope of this privacy policy, the data stored by us will be deleted as soon as they are no longer required for their intended purpose and the deletion does not conflict with any statutory retention obligations. If the data is not deleted because it is required for other and legally permissible purposes, its processing will be restricted. I.e. the data is blocked and not processed for other purposes. This applies, for example, to data that must be retained for reasons of commercial or tax law.


According to legal requirements in Germany, data is stored in particular for 10 years in accordance with §§ 147 para. 1 AO, 257 para. 1 nos. 1 and 4, para. 4 HGB (books, records, management reports, accounting vouchers, commercial books, documents relevant for taxation, etc.) and 6 years in accordance with § 257 para. 1 nos. 2 and 3, para. 4 HGB (commercial letters).


BUSINESS-RELATED PROCESSING

In addition we process

- Contract data (e.g., subject matter of the contract, term, customer category).

- Payment data (e.g., bank details, payment history)

from our customers, prospective customers and business partners for the purpose of providing contractual services, service and customer care, marketing, advertising and hosting.

The hosting services used by us serve to provide the following services: Infrastructure and platform services, computing capacity, storage space and database services, security services and technical maintenance services, which we use for the purpose of operating this online offer.


In doing so, we, or our hosting provider, process inventory data, contact data, content data, contract data, usage data, meta data and communication data of customers, interested parties and visitors of this online offer on the basis of our legitimate interests in an efficient and secure provision of this online offer pursuant to Art. 6 para. 1 lit. f DSGVO in conjunction with Art. 28 DSGVO. Art. 28 DSGVO (conclusion of order processing contract).


CHANGES AND UPDATES TO THE DATA PROTECTION DECLARATION

We ask you to regularly inform yourself about the content of our privacy policy. We adapt the Privacy Policy as soon as the changes in the data processing carried out by us make it necessary. We will inform you as soon as the changes require an act of cooperation on your part (e.g. consent) or other individual notification.


BUSINESS-RELATED PROCESSING

In addition, we process

- Contract data (e.g., subject matter of the contract, term, customer category).

- Payment data (e.g., bank details, payment history)

of our customers, prospective customers and business partners for the purpose of providing contractual services, service and customer care, marketing, advertising and market research.


COLLECTION OF ACCESS DATA AND LOG FILES

We, or our hosting provider, collects on the basis of our legitimate interests within the meaning of Art. 6 para. 1 lit. f. DSGVO, we collect data about each access to the server on which this service is located (so-called server log files). The access data includes the name of the website accessed, file, date and time of access, amount of data transferred, notification of successful access, browser type and version, the user's operating system, referrer URL (the previously visited page), IP address and the requesting provider.

Log file information is stored for security reasons (e.g. for the clarification of abuse or fraud) for a maximum of 7 days and then deleted. Data whose further storage is required for evidentiary purposes is exempt from deletion until final clarification of the respective incident.


ADMINISTRATION, FINANCIAL ACCOUNTING, OFFICE ORGANIZATION, CONTACT MANAGEMENT

We process data in the context of administrative tasks as well as organization of our business, financial accounting and compliance with legal obligations, such as archiving. In this regard, we process the same data that we process in the context of providing our contractual services. The processing bases are Art. 6 para. 1 lit. c. DSGVO, Art. 6 para. 1 lit. f. DSGVO. Customers, interested parties, business partners and website visitors are affected by the processing. The purpose and our interest in the processing lies in the administration, office organization, archiving of data, i.e. tasks that serve the maintenance of our business activities, performance of our tasks and provision of our services. The deletion of data with regard to contractual services and contractual communication corresponds to the, with these processing activities mentioned.

Furthermore, on the basis of our business interests, we store details of suppliers, event organizers and other business partners, e.g. for the purpose of contacting them at a later date. This data, which is mostly company-related, is generally stored permanently.


CONTACT

When contacting us (e.g. via contact form, email, telephone or via social media), the user's details are processed for the purpose of handling the contact request and its processing pursuant to Art. 6 (1) lit. b) DSGVO. The user's details may be stored in a Cusomer Relationship Management System ("CRM System") or comparable inquiry organization.

We delete the inquiries if they are no longer necessary. We review the necessity every two years; Furthermore, the legal archiving obligations apply.