
Data protection
1) Information on the Collection of Personal Data and Contact Details of the Controller
1.1 We are pleased that you are visiting our website and thank you for your interest. On the following pages, we inform you about the handling of your personal data when using our website. Personal data is all data with which you can be personally identified.
1.2 The controller in charge of data processing on this website, within the meaning of the General Data Protection Regulation (GDPR), is Christopher Gansert, LavaLoft, Am Kirchweg 29, 06188 Landsberg, Germany, Phone.: 0172 5207875, e-mail: teams@lava-loft.com. The controller in charge of the processing of personal data is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data.
2) Data Collection When You Visit Our Website
2.1 When using our website for information only, i.e. if you do not register or otherwise provide us with information, we only collect data that your browser transmits to our server (so-called "server log files"). When you visit our website, we collect the following data that is technically necessary for us to display the website to you:
- Our visited website
- Date and time at the moment of access
- Amount of data sent in bytes
- Source/reference from which you came to the page
- Browser used
- Operating system used
- IP address used (if applicable: in anonymized form)
Data processing is carried out in accordance with Art. 6 (1) point f GDPR on the basis of our legitimate interest in improving the stability and functionality of our website. The data will not be passed on or used in any other way. However, we reserve the right to check the server log files subsequently, if there are any concrete indications of illegal use.
2.2 This website uses SSL or TLS encryption for security reasons and to protect the transmission of personal data and other confidential content (e.g. orders or inquiries to the controller). You can recognize an encrypted connection by the character string https:// and the lock symbol in your browser line.
3) Hosting & Content Delivery Network
For the hosting of our website and the presentation of the page content, we use a provider that provides its services itself or through selected subcontractors exclusively on servers within the European Union.
All data collected on our website is processed on these servers.
We have concluded an order processing contract with the provider, which ensures the protection of the data of our website visitors and prohibits unauthorised disclosure to third parties.
4) Contacting Us
4.1 Calendly
For the provision of an online appointment booking function, we use the services of the following provider: Calendly, LLC, BB&T Tower, 271 17th St NW, Atlanta, GA 30363, USA
For the purpose of making an appointment, your first name, surname and e-mail address (and telephone number, if a telephone appointment is requested) are collected in accordance with Art. 6 (1) point b GDPR and transferred to the provider in accordance with Art. 6 (1) point f GDPR on the basis of our legitimate interest in effective customer management and efficient appointment management and stored there for the purpose of organising the appointments.
After the appointment has been held or after the agreed appointment period has expired, your data will be deleted by the provider.
We have concluded an order processing agreement with the provider, which ensures the protection of our website visitors' data and prohibits unauthorised disclosure to third parties.
For data transfers to the USA, the provider participates in the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission.
4.2 WhatsApp Business
We offer visitors to our website the opportunity to contact us via the WhatsApp news service of WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. For this purpose we use the so-called "Business Version" of WhatsApp.
If you contact us via WhatsApp in connection with a specific business transaction (e.g. an order placed), we will store and use the mobile telephone number you use at WhatsApp and - if provided - your first name and surname in accordance with Art. 6 para. 1 lit. b. GDPR to process and answer your request. On the basis of the same legal basis, we will ask you via WhatsApp to provide further data (order number, customer number, address or e-mail address), if necessary, in order to be able to allocate your enquiry to a specific transaction.
If you use our WhatsApp contact for general enquiries (e.g. about the range of services, availability or our website), we will store and use the mobile phone number you use at WhatsApp and - if provided - your first and last name in accordance with Art. 6 Para. 1 lit. f GDPR on the basis of our justified interest in the efficient and prompt provision of the requested information.
Your data will always be used only to answer your request via WhatsApp. Your data will not be passed on to third parties.
Please note that WhatsApp Business gains access to the address book of the mobile device we use for this purpose and automatically transfers telephone numbers stored in the address book to a server of the parent company Meta Platforms Inc. in the USA. To operate our WhatsApp Business account, we use a mobile device whose address book stores only the WhatsApp contact data of those users who have also contacted us via WhatsApp.
This ensures that each person whose WhatsApp contact data is stored in our address book has already consented to the transmission of his WhatsApp telephone number from the address books of his chat contacts in accordance with Art. 6 Para. 1 lit. a GDPR when using the app on his device for the first time by accepting the WhatsApp terms of use. The transmission of data of such users who do not use WhatsApp and/or have not contacted us via WhatsApp is therefore excluded.
For the purpose and scope of data collection and the further processing and use of data by WhatsApp, as well as your rights and setting options for protecting your privacy, please refer to WhatsApp's data protection information: https://www.whatsapp.com/legal/?eea=1#privacy-policy
In the course of the above-mentioned processing, data may be transferred to servers of Meta Platforms Inc. in the USA.
For data transfers to the USA, the provider participates in the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission.
4.3 When you contact us (e.g. via contact form or e-mail), personal data is collected. Which data is collected in the case of a contact form can be seen from the respective contact form. This data is stored and used exclusively for the purpose of responding to your request or for establishing contact and for the associated technical administration.
The legal basis for processing data is our legitimate interest in responding to your request in accordance with Art. 6 (1) point f GDPR. If your contact is aimed at concluding a contract, the additional legal basis for the processing is Art. 6 (1) point b GDPR. Your data will be deleted after final processing of your enquiry; this is the case if it can be inferred from the circumstances that the facts in question have been finally clarified, provided there are no legal storage obligations to the contrary.
5) Use of Client Data for Direct Advertising
5.1 Subscribe to our e-mail newsletter
If you register for our e-mail newsletter, we will regularly send you information about our offers. The only mandatory data for sending the newsletter is your e-mail address. The provision of further data is voluntary and will be used to address you personally. We use the so-called double opt-in procedure for sending the newsletter. This means that we will only send you an e-mail newsletter once you have expressly confirmed that you consent to receiving newsletters. We will then send you a confirmation e-mail asking you to confirm that you wish to receive the newsletter in future by clicking on an appropriate link.
By activating the confirmation link, you give us your consent for the use of your personal data pursuant to Art. 6 (1) point a GPPR. When you register for the newsletter, we store your IP address entered by your Internet service provider (ISP) as well as the date and time of registration for the purpose of tracing any possible misuse of your e-mail address at a later date. The data collected by us when you register for the newsletter is used exclusively for the promotional purposes by way of the newsletter. You can unsubscribe from the newsletter at any time via the link provided for this purpose in the newsletter or by sending a corresponding message to the responsible person named at the beginning. After unsubscribing, your e-mail address will be deleted from our newsletter distribution list immediately, unless you have expressly consented to further use of your data, or we reserve the right to a more extensive use your data which is permitted by law and about which we inform you in this declaration.
5.2 HubSpot
Our e-mail newsletters are sent via this provider: HubSpot Ireland Ltd, 2nd Floor 30 North Wall Quay, Dublin 1, Ireland
On the basis of our legitimate interest in effective and user-friendly newsletter marketing, we pass on the data you provided when registering for the newsletter to this provider in accordance with Art. 6 (1) point f GDPR so that they can send the newsletter on our behalf.
Subject to your express consent pursuant to Art. 6 (1) point a GDPR, the provider also carries out a statistical analysis of the success of newsletter campaigns by means of web beacons or tracking pixels in the emails sent, which can measure opening rates and specific interactions with the newsletter content. In the process, end device information (e.g. time of page view, IP address, browser type and operating system) is also collected and analysed, but not combined with other data records.
You can revoke your consent to newsletter tracking at any time with effect for the future.
We have concluded an order processing agreement with the provider, which safeguards the data of our website visitors and prohibits a transfer to third parties.
5.3 Microsoft Dynamics 365
Our e-mail newsletters are sent via this provider: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA
On the basis of our legitimate interest in effective and user-friendly newsletter marketing, we pass on the data you provided when registering for the newsletter to this provider in accordance with Art. 6 (1) point f GDPR so that they can send the newsletter on our behalf.
Subject to your express consent pursuant to Art. 6 (1) point a GDPR, the provider also carries out a statistical analysis of the success of newsletter campaigns by means of web beacons or tracking pixels in the emails sent, which can measure opening rates and specific interactions with the newsletter content. In the process, end device information (e.g. time of page view, IP address, browser type and operating system) is also collected and analysed, but not combined with other data records.
You can revoke your consent to newsletter tracking at any time with effect for the future.
We have concluded an order processing agreement with the provider, which safeguards the data of our website visitors and prohibits a transfer to third parties.
For data transfers to the USA, the provider participates in the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission.
5.4 Newsletter dispatch via MailChimp
Our email newsletters are sent via the technical service provider The Rocket Science Group, LLC d/b/a MailChimp, 675 Ponce de Leon Ave NE, Suite 5000, Atlanta, GA 30308, USA (https://www.mailchimp.com/), to whom we pass on the data you provided when registering for the newsletter. This transmission takes place in accordance with Art. 6 (1) point f GDPR and serves our legitimate interest in using a newsletter system that is promotionally effective, secure, and user-friendly. Please note that your data is usually transferred to a MailChimp server in the USA and stored there.
MailChimp uses this information to send and statistically evaluate the newsletters on our behalf. For the evaluation, the emails sent contain so-called web beacons or tracking pixels, which are single-pixel image files stored on our website. This enables us to determine whether a newsletter message has been opened and which links, if any, have been clicked on. With the help of the web beacons, Mailchimp automatically creates general, non-personal statistics about the response behavior to newsletter campaigns. However, based on our legitimate interest in the statistical evaluation of the newsletter campaigns for the optimization of the advertising communication and the better alignment with recipient interests, the web beacons also collect and use data of the respective newsletter recipient (email address, time of retrieval, IP address, browser type and operating system) in accordance with Art. 6 (1) point f GDPR. This data allows an individual conclusion to be drawn about the newsletter recipient and is processed by Mailchimp to automatically create statistics showing whether a particular recipient has opened a newsletter message. If you wish to deactivate the data analysis for statistical evaluation purposes, you must unsubscribe from the newsletter.
MailChimp may also use this data itself in accordance with Art. 6 (1) point f GDPR based on its own legitimate interest in the needs-based design and optimization of the service as well as for market research purposes, for example to determine which countries the recipients come from. However, MailChimp does not use the data of our newsletter recipients to contact these recipients itself or to pass this data on to third parties.
To protect your data in the USA, we have concluded a data processing agreement ("Data Processing Agreement") with MailChimp based on the standard contractual clauses of the European Commission to enable the transfer of your personal data to MailChimp. If you are interested, this data processing agreement can be viewed at the following internet address: https://mailchimp.com/legal/data-processing-addendum/.
You can view MailChimp's privacy policy here: https://mailchimp.com/legal/privacy/
5.5 Salesforce
Our e-mail newsletters are sent via this provider: Salesforce.com Germany GmbH, Erika-Mann-Str. 31, 80636 Munich, Germany
On the basis of our legitimate interest in effective and user-friendly newsletter marketing, we pass on the data you provided when registering for the newsletter to this provider in accordance with Art. 6 (1) point f GDPR so that they can send the newsletter on our behalf.
Subject to your express consent pursuant to Art. 6 (1) point a GDPR, the provider also carries out a statistical analysis of the success of newsletter campaigns by means of web beacons or tracking pixels in the emails sent, which can measure opening rates and specific interactions with the newsletter content. In the process, end device information (e.g. time of page view, IP address, browser type and operating system) is also collected and analysed, but not combined with other data records.
You can revoke your consent to newsletter tracking at any time with effect for the future.
We have concluded an order processing agreement with the provider, which safeguards the data of our website visitors and prohibits a transfer to third parties.
5.6 WhatsApp newsletter
If you subscribe to our WhatsApp newsletter, we will regularly send you information about our offers via WhatsApp. Only your mobile phone number is required for sending the newsletter.
To send the newsletter, please add our mobile phone number to the address book of your mobile phone and send us the message "Start" via WhatsApp. By sending this WhatsApp message, you give us your consent to use your personal data in accordance with Art. 6 (1) point a GDPR for the purpose of sending the newsletter. We will then add you to our newsletter distribution list.
The data we collect when you subscribe to the newsletter will be processed exclusively for the purpose of addressing you in an advertising manner by the newsletter. You can unsubscribe from the newsletter at any time by sending us the message "Stop" via WhatsApp. After unsubscribing, your mobile phone number will be immediately deleted from our newsletter distribution list, unless you have expressly consented to further use of your data or we reserve the right to use data beyond this, which is legally permitted and about which we inform you in this policy.
Please note that WhatsApp obtains access to the address book of the mobile device used by us for sending the newsletter and automatically transfers telephone numbers stored in the address book to a Facebook server in the USA.
For sending our WhatsApp newsletter, we therefore use a mobile end device in whose address book only the WhatsApp contact data of our newsletter recipients are stored. This ensures that each person whose WhatsApp contact data is stored in our address book has already consented to the transfer of their WhatsApp telephone number from the address books of their chat contacts in accordance with Art. 6 (1) point a GDPR when using the app on their device for the first time by accepting the WhatsApp terms of use. A transfer of data of such users who do not use WhatsApp and/or have not contacted us via WhatsApp is excluded in this respect.
For the purpose and scope of the data collection and the further processing and use of the data by WhatsApp, as well as your rights in this regard and setting options for protecting your privacy, please refer to the WhatsApp privacy policy: https://www.whatsapp.com/legal/privacy-policy-eea?lang=en
In the course of the above-mentioned processing, data may be transferred to servers of Meta Platforms Inc. in the USA.
For data transfers to the USA, the provider participates in the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission.
6) Online Marketing
6.1 Google AdSense
This website uses Google AdSense, a web ad service of Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 ESW5, Ireland ("Google"). Google AdSense uses so-called cookies. These are text files are stored on your computer and enable an analysis of your use of the website. In addition, Google AdSense also uses "web beacons" (small invisible graphics) to collect information, which can be used to record, collect and evaluate simple actions such as visitor traffic on the website. The information generated by those cookies and/or web beacons (including your IP address) about your use of this website will normally be transmitted to a server of Google and will be stored there. When using Google AdSense, personal data may also be transmitted to the servers of Google LLC. in the USA.
Google will use the information obtained in this way to analyze your usage of this website with regard to AdSense ads. The IP address transmitted by your browser as part of Google AdSense is not merged with other Google data. The information collected by Google may be transferred to third parties, if this is prescribed by law and/or if third parties process this data by request of Google.
All processing described above, in particular the reading of information on the end device used, is only carried out if you have given us your express consent to do so in accordance with Art. 6 (1) point a GPDR. Without this consent, Google AdSense will not be used during your visit to the site.
You can revoke your consent at any time with effect for the future. To exercise your revocation, please deactivate this service in the "Cookie Consent Tool" provided on the website.
For data transfers to the USA, the provider participates in the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission.
For more information about Google's privacy policy, please visit: https://privacy.google.com/intl/en-GB/take-control.html?categories_activeEl=sign-in and https://business.safety.google/privacy/
6.2 Hubspot
This website uses the software-based marketing service of the following provider for the provision and synchronisation of various customer management services: HubSpot Ireland Ltd., 2nd Floor 30 North Wall Quay, Dublin 1, Ireland
This service enables the automated processing of feed activities, the control of advertising in the marketing channels used and the analysis of the success of marketing measures, as well as central e-mail marketing and contact management.
To fulfil the various functions, cookies are used, i.e. small text files that are stored locally in the cache of your web browser on your end device and that enable an analysis of your use of the website by us. In doing so, the cookies collect certain information, such as the IP address, the location, the time of the page access.
All of the processing described above, in particular the setting of cookies to read information from the end device used, will only be carried out if you have given us your express consent to this in accordance with Art. 6 (1) point a GDPR. You can revoke your consent at any time with effect for the future by deactivating this service in the „cookie consent tool" provided on the website.
Other legal bases for data processing that apply in the context of specific service functions (such as the requirement for express consent in accordance with Art. 6 (1) point a GDPR when sending newsletters) remain unaffected by this.
We have concluded an order processing agreement with the provider, which ensures the protection of our website visitors' data and prohibits unauthorised disclosure to third parties.
6.3 Microsoft Dynamics 365
This website uses the software-based marketing service of the following provider for the provision and synchronisation of various customer management services: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA
This service enables the automated processing of feed activities, the control of advertising in the marketing channels used and the analysis of the success of marketing measures, as well as central e-mail marketing and contact management.
To fulfil the various functions, cookies are used, i.e. small text files that are stored locally in the cache of your web browser on your end device and that enable an analysis of your use of the website by us. In doing so, the cookies collect certain information, such as the IP address, the location, the time of the page access.
All of the processing described above, in particular the setting of cookies to read information from the end device used, will only be carried out if you have given us your express consent to this in accordance with Art. 6 (1) point a GDPR. You can revoke your consent at any time with effect for the future by deactivating this service in the „cookie consent tool" provided on the website.
Other legal bases for data processing that apply in the context of specific service functions (such as the requirement for express consent in accordance with Art. 6 (1) point a GDPR when sending newsletters) remain unaffected by this.
We have concluded an order processing agreement with the provider, which ensures the protection of our website visitors' data and prohibits unauthorised disclosure to third parties.
For data transfers to the USA, the provider participates in the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission.
7) Site functionalities
7.1 Vimeo
This website uses plugins to display and play videos from the following provider: Vimeo.com, Inc., 330 West 34th Street, 10th Floor, New York, NY 10001, USA
When you call up a page of our website that contains such a plugin, your browser establishes a direct connection to the provider's servers to load the plugin. This involves certain information, including your IP address, being transmitted to the provider.
If the playback of embedded videos is started via the plugin, the provider also uses cookies to collect information about user behavior, to create playback statistics and to prevent abusive behavior.
If you are logged into a user account maintained by the provider during your visit to the site, your data will be directly assigned to your account when you click on a video. If you do not wish to have your data assigned to your account, you must log out before clicking on the play button.
All the above-mentioned processing, in particular the setting of cookies for reading out information on the end device used, only takes place if you have given us your express consent in accordance with Art. 6 (1) point a GDPR. You can revoke your consent at any time with effect for the future by deactivating this service via the "cookie consent tool" provided on the website.
For data transfers to the USA, the provider participates in the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission.
7.2 Google Translate
This site uses the translation service "Google Translate" from Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google") via an API integration. In order for the translation to be displayed automatically according to your choice of national language, the browser you are using will connect to Google's servers. Google uses so-called "cookies", which are text files stored on your computer that enable an analysis of your use of the website. The information generated by the cookie about your use of this website (including the shortened IP address) is usually transferred to a Google server and stored there; this may also involve transmission to the servers of Google LLC in the USA.
If personal data is processed, this is done in accordance with Art. 6 (1) (f) GDPR on the basis of our legitimate interest in barrier-free and universal accessibility of our website.
To the extent legally required, we have obtained your consent in accordance with Art. 6 (1) (a) GDPR for the processing of your data as described above. You can revoke your consent at any time with effect for the future. To exercise your revocation, deactivate this service in the "Cookie Consent Tool" provided on the website.
For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European data protection level based on an adequacy decision of the European Commission.
Further information on Google's data protection regulations can be found here: https://business.safety.google/privacy/
8) Rights of the Data Subject
8.1 The applicable data protection law grants you the following comprehensive rights of data subjects (rights of information and intervention) vis-à-vis the data controller with regard to the processing of your personal data:
- Right of access by the data subject pursuant to Art. 15 GDPR;
- Right to rectification pursuant to Art. 16 GDPR;
- Right to erasure (“right to be forgotten”) pursuant to Art. 17 GDPR;
- Right to restriction of processing pursuant to Art. 18 GDPR;
- Right to be informed pursuant to Art. 19 GDPR;
- Right to data portability pursuant to Art. 20 GDPR;
- Right to withdraw a given consent pursuant to Art. 7 (3) GDPR;
- Right to lodge a complaint pursuant to Art. 77 GDPR.
8.2 RIGHT TO OBJECT
IF, WITHIN THE FRAMEWORK OF A CONSIDERATION OF INTERESTS, WE PROCESS YOUR PERSONAL DATA ON THE BASIS OF OUR PREDOMINANT LEGITIMATE INTEREST, YOU HAVE THE RIGHT AT ANY TIME TO OBJECT TO THIS PROCESSING WITH EFFECT FOR THE FUTURE ON THE GROUNDS THAT ARISE FROM YOUR PARTICULAR SITUATION.
IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL STOP PROCESSING THE DATA CONCERNED. HOWEVER, WE RESERVE THE RIGHT TO FURTHER PROCESSING IF WE CAN PROVE COMPELLING REASONS WORTHY OF PROTECTION FOR PROCESSING WHICH OUTWEIGH YOUR INTERESTS, FUNDAMENTAL RIGHTS AND FREEDOMS, OR IF THE PROCESSING SERVES TO ASSERT, EXERCISE OR DEFEND LEGAL CLAIMS.
IF WE PROCESS YOUR PERSONAL DATA FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF YOUR PERSONAL DATA WHICH ARE USED FOR DIRECT MARKETING PURPOSES. YOU MAY EXERCISE THE OBJECTION AS DESCRIBED ABOVE.
IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL STOP PROCESSING THE DATA CONCERNED FOR DIRECT ADVERTISING PURPOSES.
9) Duration of Storage of Personal Data
The duration of the storage of personal data is based on the respective legal basis, the purpose of processing and - if relevant – on the respective legal retention period (e.g. commercial and tax retention periods).
If personal data is processed on the basis of an express consent pursuant to Art. 6 (1) point a GDPR, this data is stored until the data subject revokes his consent.
If there are legal storage periods for data that is processed within the framework of legal or similar obligations on the basis of Art. 6 (1) point b GDPR, this data will be routinely deleted after expiry of the storage periods if it is no longer necessary for the fulfillment of the contract or the initiation of the contract and/or if we no longer have a justified interest in further storage.
When processing personal data on the basis of Art. 6 (1) point f GDPR, this data is stored until the data subject exercises his right of objection in accordance with Art. 21 (1) GDPR, unless we can provide compelling grounds for processing worthy of protection which outweigh the interests, rights and freedoms of the data subject, or the processing serves to assert, exercise or defend legal claims.
If personal data is processed for the purpose of direct marketing on the basis of Art. 6 (1) point f GDPR, this data is stored until the data subject exercises his right of objection pursuant to Art. 21 (2) GDPR.
Unless otherwise stated in the information contained in this declaration on specific processing situations, stored personal data will be deleted if it is no longer necessary for the purposes for which it was collected or otherwise processed.
Copyright notice: This privacy policy has been created by the specialist lawyers of IT-Recht Kanzlei and is protected by copyright (https://www.it-recht-kanzlei.de)