Privacy Notice
When you use our offerings, Direkt + Online GmbH processes your personal data. With this privacy notice, we inform you how and why we process your data and how we ensure that it remains confidential and protected.
We take data protection seriously: as a rule, we only process personal data if this is necessary for providing a service or offering, or if the data is voluntarily provided by users. We also protect personal data with technical and organisational safeguards against accidental or intentional manipulation, loss, destruction or access by unauthorised persons. We review and modernise these safeguards regularly.
Privacy at a glance
What data do we collect?
- Master data (e.g. names, addresses)
- Contact data (e.g. email, phone numbers)
- Content data (e.g. entries in online forms)
- Payment data (e.g. bank details, invoices, payment history)
- Contract data (e.g. subject matter of the contract, term)
- Usage data (e.g. websites visited, interest in content, access times)
- Meta/communication data (e.g. device information, IP addresses, ID)
How do we collect the data?
The data generated when you access our digital offerings is collected automatically. Otherwise, we collect data based on your entries or communications, or through the use of cookies or similar technologies.
What do we use the data for?
Providing our content
- Cookies and similar technologies
- Technical provision and security
- Strictly necessary technology
Product optimisation
- Usage analysis
Communication
- Contact and communication
Advertising for our own products
- Company presence on social media
Do we share the data?
If you have consented, or if we are otherwise legally authorised to do so, we share your personal data with service providers (e.g. hosting, marketing, sales partners, payment service providers) for the purposes named above. In such cases, we observe the statutory requirements and, in particular, conclude corresponding contracts or agreements with the recipients of your data that serve to protect it.
We transfer personal data to other companies within our corporate group, or grant them access to this data, for administrative purposes. This transfer of data is based on our legitimate business and commercial interests, or takes place where it is necessary to fulfil our contractual obligations, or where the data subject has given consent or there is a statutory permission.
Do we transfer data to third countries?
Using our digital offerings may require the transfer of certain personal data to third countries, i.e. countries in which the GDPR is not applicable law. However, we only permit the processing of your data in a third country if the specific requirements of Art. 44 et seq. GDPR are met, thereby ensuring an adequate level of data protection in that country. This means that either an adequacy decision by the European Commission must exist for the third country, or appropriate safeguards pursuant to Art. 46 GDPR, or one of the conditions of Art. 49 GDPR must be met. Unless stated otherwise below, we use the respective applicable standard contractual clauses as appropriate safeguards for the transfer of personal data to processors in third countries.
How do we secure the data?
To protect your privacy and ensure a level of protection appropriate to the risk, we take technical and organisational measures in accordance with statutory requirements, taking into account the state of the art, the cost of implementation, and the nature, scope, context and purposes of processing as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons; these measures are reviewed and adjusted regularly. The measures safeguard the confidentiality, integrity, availability and resilience of your data. This includes, among other things, the use of recognised encryption methods (SSL or TLS) and pseudonymisation.
We would like to point out, however, that due to the structure of the internet, it is possible that data protection rules and the security measures described above may not be observed by other persons or institutions outside our area of responsibility. In particular, data disclosed unencrypted – for example, when sent by email – may be read by third parties. We have no technical influence over this.
When do we delete the data?
We delete or anonymise your personal data as soon as it is no longer required for the purposes for which it was collected or used.
In some cases, however, we may need to continue storing your data until the expiry of retention obligations and periods imposed by law or by regulatory authorities, which may arise from the German Commercial Code (Handelsgesetzbuch), the Fiscal Code (Abgabenordnung) and the Money Laundering Act (Geldwäschegesetz) (typically 6 to 10 years). We may also retain your data until the expiry of the statutory limitation periods (i.e. typically 3 years, but in individual cases up to 30 years), insofar as this is necessary for the assertion, exercise or defence of legal claims. The corresponding data is deleted thereafter.
What rights do you have?
- Access
- Erasure
- Rectification
- Objection
You can contact our data protection officer with your request by post or by email at swmh-datenschutz@atarax.de.
This privacy notice is updated from time to time. You will find the date of the last update at the beginning of this notice.
Privacy settings
An overview of all the tools and cookies we use, and an option to withdraw consent, is available if you click on Privacy Settings at the bottom of the website you are visiting.
Below you will find our privacy notice in detailed form.
Privacy notice for job applications
If you have applied to work with us, you will find the required privacy notice here.
How we provide you with our content
Cookies and similar technologies
We use cookies and similar technologies to provide the best experience when using our digital offerings. We use them to ensure functionality, IT security and fraud prevention.
An overview of the technologies used and options for withdrawal or objection can be found under Privacy Settings in the footer of the website you are visiting.
If cookies, device identifiers or other personal data are stored on or retrieved from your device for processing, this takes place on one of the legal bases set out in Art. 6 GDPR.
In order to provide the telemedia service you expressly requested, we also take into account the provisions of Sec. 25 of the German Telecommunications-Digital-Services-Data-Protection Act (TDDDG), in particular the necessity requirement under Sec. 25(2) No. 2 TDDDG.
Cookie types and functions
Cookies are text files containing data from websites or domains visited, which are stored on users’ devices by a browser. A cookie primarily serves to store information about a user during or after their visit within an online offering. The stored information may include, for example, language settings on a website, login status, a shopping cart or video interactions. The term “cookies” also covers other technologies that perform the same functions as cookies (e.g. when user data is stored using pseudonymous online identifiers, also referred to as “user IDs”).
There are the following types of cookies and functions:
- Temporary cookies (also: session cookies): temporary cookies are deleted at the latest once a user has left an online offering and closed their browser.
- Permanent cookies: permanent cookies remain stored even after the browser is closed. For example, login status can be saved or preferred content displayed directly when the user visits a website again. Likewise, information about users’ interests, used for reach measurement or marketing purposes, can be stored in such a cookie.
- First-party cookies: first-party cookies are set and used by us ourselves to process user information.
- Third-party cookies: third-party cookies are mainly used by advertisers (so-called third parties) or other partners to process user information.
- Strictly necessary (also: essential) cookies: these cookies ensure functions without which these digital offerings could not be used as intended. They may be strictly necessary for operating a website, for example to store logins or other user entries, or for security reasons.
- Analysis and statistics cookies: these cookies allow us to analyse the use of our digital offerings, in particular to measure reach – i.e. clicks, visit and visitor numbers. The aim is to statistically determine the number of visits and visitors and their browsing behaviour (duration, origin), thereby obtaining values comparable across the market. The information collected is evaluated in aggregate form in order to derive improvements and optimisations to our products.
- Marketing and personalisation cookies: cookies are also used to store a user’s interests or behaviour (e.g. viewing certain content, using features, etc.) in a user profile. Such profiles are used, for example, to show users content that is likely to correspond to their interests. This process is also referred to as “tracking”, i.e. tracking users’ likely interests. Insofar as we use cookies or “tracking” technologies, we inform you of this separately in our privacy notice or when obtaining consent.
Technical provision and security
When our offering is used, strictly necessary technologies are automatically deployed by us and the following information is processed:
- Information about the accessing device and the software used
- Date and time of access
- Websites from which the user reaches our website, or which the user accesses via our website
- IP address
The collection of these logs and their temporary storage and processing are necessary to ensure system security and integrity (in particular to ward off and defend against attacks or attempted damage), and take place on the basis of our corresponding legitimate interest (Sec. 25(2) No. 2 TDDDG, Art. 6(1)(f) GDPR).
The retention period for this log data is generally seven days; for the reliable detection of AI bots, it is 30 days. After this point, these specific server log records are anonymised on the basis of our legitimate interest in a statistical evaluation to assess AI bots and their effects on our content (Art. 6(1)(f) GDPR).
The legal basis for the aforementioned data processing is our legitimate interest pursuant to Art. 6(1) sentence 1(f) GDPR.
Strictly necessary technology
The following tools and cookies are strictly necessary technologies, i.e. essential, in order to provide our services as requested by the user.
The legal basis for the data processing described below is our legitimate interest pursuant to Art. 6(1) sentence 1(f) GDPR.
Consent management
In order to obtain and store your consent under data protection law, we use the consent management platform of Sourcepoint (Sourcepoint Technologies, Inc., 228 Park Avenue South, #87903, New York, NY 10003-1502, United States). This sets strictly necessary cookies in order to query consent status and thereby deliver the corresponding content.
The data is stored for a maximum of 13 months.
How we optimise our products
Usage analysis
We want to continuously develop and improve our products. To do this, we need usage analysis. This is used to evaluate the visitor traffic of our digital offerings and may include behaviour, interests or demographic information about visitors, such as age or gender, as pseudonymous values. With its help, we can, for example, see when our digital offerings are used most frequently or which features are frequently reused. This allows us to identify which areas need optimisation.
In addition to usage analysis, we also use testing procedures, for example to test different versions of our digital offerings or their components and, where applicable, to increase a particular user action or response.
For these purposes, profiles – i.e. data combined for a usage process – are created, and information is stored in and read from a browser or device. The information collected includes, in particular, websites visited and the elements used there, as well as technical information such as the browser used, the computer system used, and information on usage times.
Users’ IP addresses are also stored. For this we use an IP masking procedure (i.e. pseudonymisation by shortening the IP address) for your protection. As a general rule, no plain-text user data (such as email addresses or names) is stored as part of web analysis, A/B testing and optimisation, but rather pseudonyms, so that neither we nor the providers of the software used, who act as processors on our behalf, know the actual identity of the users.
Matomo
We use the web analytics platform Matomo to analyse visitor data. This serves our product optimisation on the basis of our legitimate interest, Art. 6(1) sentence 1(f) GDPR. For this purpose, the following usage information is transmitted to our server and stored for analysis purposes:
- User IP address (with anonymisation of 2 bytes)
- Date and time of access
- URL of the page accessed (page URL)
- URL of the page accessed before the current page (referrer URL)
- Screen resolution used
- Time in the local user’s time zone
- User’s location: country, region, city, approximate latitude and longitude (geolocation)
- User agent of the browser used (user agent header): using the user agent, we use our Universal Device Detection Library to identify the browser, operating system, device used (desktop, tablet, mobile, TV, car, console, etc.), brand and model.
- Random unique visitor ID
- Time of this user’s first visit
- Time of this user’s most recent visit
- Number of visits by this user
- Site search
- Goals
- Events
The retention period is 14 months (applies to data at user and event level).
As part of our web analysis, no cookies are set on your computer. Nor is any data shared with third parties.
If you do not agree to a fully anonymous storage and evaluation of this data from your visit, you can object to this storage and use in the privacy settings (accessible via the website’s footer). In this case, an opt-out cookie is stored in your browser, with the result that Matomo no longer collects any session data whatsoever.
The legal basis for the data processing is your consent pursuant to Art. 6(1)(a) GDPR.
If you order offerings from us
Ordering products
If you order one of our offerings or products, we require your address, contact and communication data, as well as your bank and, where applicable, credit card details, when the contract is concluded.
The processing of this data is necessary for the initiation or performance of the contract (Art. 6(1) sentence 1(b) GDPR).
After the contract has ended, we delete or block your data unless we are legally obliged to retain it. Deletion generally takes place after ten years at the latest.
Payment
In order to offer you various payment functions, we use software from service providers who assist us in processing payments. This software also manages transactions and controls access control, billing, the checkout process, invoicing and payment transactions. It also supports our user, product and pricing management. In doing so, we process your provided personal master data (e.g. name, address details), your communication data (e.g. email), order data, contract billing and payment data, as well as our planning and control data.
The legal basis for this is the performance of the contract (Art. 6(1) sentence 1(b) GDPR) as well as our legitimate interest in proper and functioning payment processing (Art. 6(1) sentence 1(f) GDPR).
If you contact us
Contact
If you get in touch with us, we only collect personal data (e.g. name, email address, phone number) if you provide it to us of your own accord. Providing this information is expressly voluntary. The purpose of processing your data is to handle and respond to your request. This also constitutes our legitimate interest in the data processing pursuant to Art. 6(1) sentence 1(f) GDPR.
In the case of a telephone enquiry, your data is also processed by telephone applications and, in some cases, via a voice dialogue system, in order to assist us in distributing and handling enquiries.
We will delete the data we received in connection with your enquiry as soon as your request has been fully dealt with and no further communication with you is required or desired by you.
Callback form
If you use the callback form on our homepage, we process the data you voluntarily provide — name and phone number, plus optionally company, preferred time window and message — in order to process your request and call you back. The legal basis is our legitimate interest in handling your enquiry pursuant to Art. 6(1) sentence 1(f) GDPR. The recipient of the data is exclusively our own sales team; transmission takes place by email via our own infrastructure, without involving any external form or analytics service. [PLACEHOLDER — the specific retention period for this form data has not yet been finalised and must be confirmed by the data protection officer; until then, the general retention rule described above for enquiries applies as an interim measure.]
If we advertise our products
Direct marketing
We use your contact data beyond the contract-related use for advertising purposes as well. This only happens if you have expressly consented (Art. 6(1)(a) GDPR) or on the basis of our legitimate interest in personal customer contact or direct marketing (Art. 6(1)(f) GDPR), for example for information about the same or similar products of our company (Sec. 7(3) UWG, German Act Against Unfair Competition).
If you no longer want to receive advertising, you can withdraw your consent or object to the advertising at any time, without incurring any costs other than the transmission costs according to the basic rates.
The data we process is deleted as soon as it is no longer required for its intended purpose, you have objected to the advertising, and no statutory retention obligations stand in the way of deletion.
- by email to data-privacy@direktundonline.de
- in writing to Direkt + Online GmbH, Martin-Kollar-Str. 5, 81829 München
- by clicking the unsubscribe link at the end of the email
Company presence on social media
We maintain a presence on “social media”. Insofar as we have control over the processing of your data, we ensure that the applicable data protection regulations are observed. Below you will find the most important data protection information relating to our company’s social media presence.
Responsible for the company presence within the meaning of the EU General Data Protection Regulation (GDPR) and other data protection provisions are, in addition to us:
- X (Twitter International Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland); further information on data protection can be found here.
We process the data for statistical purposes, in order to further develop and optimise the content and make our offering more attractive. This data includes the total number of page views, page activities, and data and interactions provided by visitors. This information is compiled and made available by the social networks. We have no influence on its generation and presentation.
In addition, your personal data is processed for market research and advertising purposes. For example, based on your usage behaviour and the resulting interests, usage profiles may be created. This can, among other things, be used to place advertisements within and outside the platforms that are presumed to match your interests. Cookies are generally stored on your computer for this purpose. Independently of this, data that is not collected directly from your devices may also be stored in your usage profiles. Storage and analysis also takes place across devices; this applies in particular, but not exclusively, if you are registered as a member and logged in on the respective platforms.
Beyond this, we do not collect or process any personal data.
Our processing of your personal data is based on our legitimate interests in effective information and communication pursuant to Art.
6(1) sentence 1(f) GDPR.
If you are asked to consent to data processing, i.e. if you declare your
consent by confirming a button or similar (opt-in), the legal basis for the
processing is Art. 6(1) sentence 1(a), Art. 7 GDPR.
If you are a member of a social network and do not want the network
to collect data about you via our presence and link it to your stored member data
with the respective network, you must
- log out of the respective network before visiting our fan page,
- delete the cookies present on the device, and
- close and restart your browser.
After logging in again, however, you will once again be identifiable to the network as a specific user.
Overall, you have the following rights regarding the processing of your personal data:
Right to information; right to rectification; right to erasure; right to restriction of processing; right to object; right to data portability; right to
lodge a complaint about unlawful processing of your personal data with the
competent data protection authority.
As we do not have full access to your personal data, you should
contact the providers of the social media directly to assert your data subject rights,
since they each have access to their users’ personal data and
can take appropriate measures and provide information.
Should you nevertheless need help, we will of course try to support you. Our contact details can be found here.
For a detailed description of the respective processing operations and the options for withdrawal, please refer to the information linked below.
- X opt-out
What else you should know
Controller
Direkt + Online GmbH
Martin-Kollar-Str. 5
81829 München
Data protection officer
atarax Unternehmensgruppe
Luitpold-Maier-Str. 7
91074 Herzogenaurach
Phone: 09132 79800
Email: datenschutz@atarax.de.
You can direct your data protection questions here.
Your rights
- Pursuant to Art. 15 GDPR, you have the right to request information about the personal data we process about you. In this context, pursuant to Art. 15(3)-(4) GDPR, you also have the right to receive a copy of the personal data we process about you.
- Pursuant to Art. 16 GDPR, you can request the immediate rectification of inaccurate personal data stored by us, or the completion of such data.
- Pursuant to Art. 17 GDPR, you can request the erasure of your personal data stored by us.
- Pursuant to Art. 18 GDPR, you can request the restriction of the processing of your personal data.
- Pursuant to Art. 20 GDPR, you can request to receive the personal data you have provided to us in a structured, commonly used and machine-readable format, and you can request that it be transmitted to another controller.
- Pursuant to Art. 7(3) GDPR, you can withdraw any consent you have given us at any time. This means that processing carried out on the basis of consent before the withdrawal remains lawful, and has the effect that we may no longer continue the data processing based on this consent going forward.
Right to object
Where we process your personal data on the basis of legitimate interests pursuant to Art. 6(1) sentence 1(f) GDPR or pursuant to Art. 6(1) sentence 1(e) GDPR, you have the right, pursuant to Art. 21 GDPR, to object to the processing of your personal data. In the event of such an objection, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims.
In the case of direct marketing, you have the right to object at any time to the processing of personal data concerning you for such purposes. If you object to processing for direct marketing purposes, the personal data will no longer be processed for these purposes.
Right to lodge a complaint with the supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority against the processing of your personal data if you believe your rights under the GDPR have been violated. As a rule, you can contact the supervisory authority of your usual place of residence, your workplace, or our company’s registered office.
Data protection notices in the terms and conditions
With this privacy notice, we fulfil the information obligations under the GDPR. Our general terms and conditions also contain data protection notices. These set out in detail, once again, how in particular the personal data required for performing contracts and for identity and creditworthiness checks is processed.
Links to other websites
We link to websites of other providers, or have embedded elements of theirs on our site. This privacy notice does not apply to these — we have no influence over such sites and cannot control whether others comply with applicable data protection regulations.
Changes to this privacy notice
We reserve the right to amend or adjust this privacy notice at any time, in compliance with applicable data protection regulations.
Email data-privacy@direktundonline.de
Phone +49 89 420013 0
Direkt + Online GmbH
Martin-Kollar-Str. 5
81829 München
Imprint