This is a translated version of our original German privacy policy, which is primarily applicable due to our company’s location in Germany. In the event of any discrepancies or ambiguities the German original shall prevail.
As a general rule you can use this website without providing any personal information. We also do not offer the option to create a user account or anything similar. Therefore providing personal information such as your address, phone number or email address is not required to use the website.
However in some areas of the website you have the option to contact us via forms. The information provided here is voluntary. For more information see the “Forms” section.
Personal data also includes information that can be used to uniquely identify you as a visitor. This may take the form of cookies or the storage of your IP address. Even though this information cannot be directly linked to you by name, we would like to inform you about how we handle this data.
The protection of personal data is a matter of great importance to us. Therefore the processing of personal data is carried out in accordance with applicable European and national laws.
You may, of course, revoke your consent at any time with future effect. To do so please contact the data controller as specified in Section 1.
This statement provides an overview of the types of data collected, how this data is used and shared, the security measures we take to protect your data and how you can obtain information about the data you have provided to us.
1. Legal Basis for the Processing of Personal Data
To the extent that we obtain the data subject’s consent for the processing of personal data, Article 6(1)(a) of the EU General Data Protection Regulation (GDPR) serves as the legal basis.When processing personal data necessary for the performance of a contract to which the data subject is a party, Article 6(1)(b) of the GDPR serves as the legal basis. This also applies to processing operations necessary for the implementation of pre-contractual measures.
To the extent that the processing of personal data is necessary to comply with a legal obligation to which we are subject, Article 6(1), sentence 1, letter c) of the GDPR serves as the legal basis.
If the processing is necessary to protect a legitimate interest of our company or a third party and the interests, fundamental rights and fundamental freedoms of the data subject do not override the former interest, Article 6(1)(f) of the GDPR serves as the legal basis for the processing.
2. Minors
Minors should not provide us with any personal data without the consent of a parent or legal guardian.
3. Storage of IP addresses, Retention Period and Data Deletion
When you access our websites, your IP address is transmitted and stored by us for security purposes (for exceptions, see Section 4: Forms). This may occur in so-called technical server log data or in visitor counter applications (see the section “Web Analytics Software”). The IP data in the stored log files is not analyzed for marketing purposes, nor are these server log files made available to third parties. Storage is carried out solely for traceability purposes to ensure the technical security of our systems.
The personal data of the data subject will be deleted or blocked as soon as the purpose for which it was stored no longer applies. Data may also be stored if this is provided for by European or national legislation in EU regulations, laws or other provisions to which we are subject. Data will also be blocked or deleted when a retention period prescribed by the aforementioned standards expires unless further storage of the data is necessary for the conclusion or performance of a contract.
4. Forms
The use of forms on this website is voluntary. Alternatively you can contact us at any time via email, phone or mail. The data collected through the contact forms is used exclusively to process your inquiry. In addition to the data you enter we also store the full IP address used to submit the form indefinitely for security purposes and to ensure traceability.
Technically we use the TLS (Transport Layer Security) security standard for all forms. This procedure, also known as SSL encryption, guarantees the confidential transmission of the data sent from your browser to our server. Third parties therefore have no access to the data during transmission. You can recognize proper encryption in your browser by the lock icon – usually green – in the address bar.
Contact forms or inquiries submitted via the website are additionally forwarded by email to the appropriate internal staff member. As part of the standard email transmission process it is possible that the transmitted information may be routed through third-party mail servers. Technically we also use TLS encryption for this process. Furthermore the scope of data transmitted via email is limited to the absolute minimum necessary.
5. The Data Controller and the Data Protection Officer
The data controller within the meaning of the General Data Protection Regulation (GDPR) and other national data protection laws of the member states, as well as other data protection regulations, is:
planetlan GmbH
Feldstraße 5 - 9
44867 Bochum
Germany
Phone: +49-2327-369-42-0
Website: https://planetlan.de
6. Definitions
This Privacy Policy is based on the terminology used by the European legislator when enacting the EU General Data Protection Regulation (hereinafter referred to as the “DSGVO”). This Privacy Policy is intended to be easy to read and understand. To ensure this, the most important terms are explained:
a) Personal data refers to any information relating to an identified or identifiable natural person (hereinafter referred to as the “betroffene Person”). A natural person is considered identifiable if they can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
b) A data subject is any identified or identifiable natural person whose personal data is processed by the controller.
c) Processing means any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, distribution or any other form of disclosure; the alignment or combination; the restriction, erasure or destruction.
d) Profiling means any form of automated processing of personal data consisting of the use of such personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that natural person’s work performance, economic situation, health, personal preferences, interests, reliability, behavior, location or movements.
e) Pseudonymization means the processing of personal data in such a way that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures that ensure the personal data is not attributed to an identified or identifiable natural person.
f) “Controller” means the natural or legal person, public authority, agency or other body that alone or jointly with others determines the purposes and means of the processing of personal data. Where the purposes and means of such processing are determined by Union law or the law of the Member States, the controller or the specific criteria for its designation may be provided for by Union law or the law of the Member States.
g) A processor is a natural or legal person, public authority, agency or other body that processes personal data on behalf of the controller.
h) A recipient is a natural or legal person, public authority, agency or other body to whom personal data are disclosed, regardless of whether that body is a third party or not. However public authorities that may receive personal data in the course of a specific investigative mandate under Union law or the law of the Member States are not considered recipients.
i) A “third party” means a natural or legal person, public authority, agency or other body other than the data subject, the controller, the processor and the persons authorized to process the personal data under the direct authority of the controller or the processor.
j) Consent means any freely given, specific, informed and unambiguous indication of the data subject’s wishes, expressed by a statement or by a clear affirmative action, by which the data subject signifies agreement to the processing of personal data relating to him or her.
7. Provision of the Website and Creation of Log Files
(1) When you use the website for informational purposes only, that is, if you do not register or otherwise provide us with information, we automatically collect the following data and information from the computer system of the accessing device each time the website is accessed:
a) The user’s
IP address b) Information about the browser type and version
used c) The user’s
operating system d) The user’s
Internet service provider e) Date and time of access
f) Websites from which the user’s system accessed
the website g) Websites accessed
by the user’s system via our website h) Content of the visits (specific pages)
i) Amount
of data transferred in each case j) Language and version of the browser software
The data is also stored in our system’s log files. This data is not stored together with any other personal data of the user.
(2) The legal basis for the temporary storage of log files is Article 6(1)(f) of the GDPR.
(3) The temporary storage of the IP address by the system is necessary to
a) enable the website to be delivered to the user’s computer. For this purpose the user’s IP address must remain stored for the duration of the session.
b) optimize
the content of our website as well as the advertising displayed on it; c) ensure
the functionality of our information technology systems and the technology of our website; d) provide
law enforcement authorities with the information necessary for criminal prosecution in the event of a cyberattack. Data is stored in log files to ensure the website functions properly. In addition we use this data to optimize the website and ensure the security of our IT systems. The data is not analyzed for marketing purposes in this context.
These purposes also constitute our legitimate interest in data processing pursuant to Art. 6(1)(f) of the GDPR.
(4) The data will be deleted as soon as it is no longer necessary to achieve the purpose for which it was collected, in this case at the end of the usage session
In the case of data stored in log files this occurs no later than seven days after collection. Storage beyond this period is possible. In this case the IP addresses are deleted or anonymized so that the accessing client can no longer be identified.
(5) The collection of data for the purpose of providing the website and the storage of data in log files are strictly necessary for the operation of the website; therefore there is no option to object.
The content and validity of the document remain unaffected by this.
8. Use of Cookies
This website does not use tracking or marketing cookies. Under certain circumstances technically necessary cookies may be set; however these serve exclusively technical purposes and are not used for individual user tracking.
Cookies are small text files that, as soon as you visit a website, are sent from a web server to your browser and stored locally on your device (PC, laptop, tablet, smartphone, etc.), where they are saved on your computer and provide the user (that is, us) with certain information. Cookies are used to make the website more user-friendly and secure, in particular to collect usage-related information such as the frequency of use, the number of users visiting the pages and user behavior patterns. Cookies do not cause any damage to your computer and do not contain viruses. This cookie contains a unique string of characters (known as a cookie ID) that allows the browser to be uniquely identified when you revisit the website.
Cookies remain stored even after the browser session ends and can be retrieved when you visit the site again.
However cookies are stored on your computer and transmitted from it to our site. Therefore you have full control over the use of cookies. If you do not wish to have data collected via cookies you can configure your browser via the “Settings” menu so that you are notified when cookies are set, can generally prevent cookies from being set or can delete individual cookies. Please note that disabling cookies may limit the functionality of this website. Session cookies are automatically deleted when you leave the website anyway.
9. Disclosure of Personal Data to Third Parties
(1) Use of Web Analytics Software
For data protection reasons we do not use Google Analytics or other external third-party providers. Instead we rely on the freely available open-source analytics software “PIWIK/Matomo,” which is operated on one of our systems in Germany. To comply with the principle of data minimization we anonymize the IP addresses stored in this process by removing the last digit (for example 10.20.30.40 would become 10.20.30.xx). This truncated stored form of the IP address is also removed from the database after a maximum of 60 days. We respect your browser’s “DO NOT TRACK” setting which allows you to easily opt out of this tracking. All analytics data is used solely for internal website analysis and to improve our offerings; the data is not used for advertising purposes or made available to third parties.
(2) Disclosure of Data to Third
Parties Unless expressly stated otherwise, we do not disclose or make personal
data, IP addresses or visit logs available to third parties. However in the course of technical data transmission and storage it is necessary for the transmitted data – or parts thereof – to be stored on devices or servers belonging to external service providers such as our web host. Further details can be found in Section 9.4, “External Service Providers.” (3) Links to External Websites
This website contains links to external sites.
We are solely responsible for our own content. We have no influence over the content of external links and are therefore not responsible for it; in particular we do not endorse their content. If you are redirected to an external site the privacy policy provided there applies. If you notice any illegal activities or content on that site please feel free to bring it to our attention. In this case we will review the content and take appropriate action (notice-and-takedown procedure).
(4) External Service Providers
Servers are required to operate a website. These are typically operated by external service providers, known as hosting providers or data centers. When selecting service providers we ensure that they are not legally granted any right to use the stored data. Technically however access by for example data center employees cannot be completely ruled out. For this reason we have contracts with these service providers that prohibit the viewing and use of customer-specific data on our servers.
In addition it is possible that components from third parties are used in certain parts of the site. Under certain circumstances these may be loaded from servers located outside of Germany, for example social plugins. In such cases the respective provider also has access to the IP address you are using. Furthermore it is possible that individual providers may use cookies without us being able to specifically notify you of this. Under no circumstances, however, do we actively transmit personal data to these third-party providers.
BunnyNet
To speed up website delivery, we use a so-called CDN (Content Delivery Network) provided by:
BunnyWay, informacijske storitve d.o.o.
Dunajska cesta 165
1000 Ljubljana
Slovenia
Your browser retrieves some necessary resources and images via the CDN provider’s so-called mirror servers. This allows the CDN provider to log your IP address and the time of your website visit. However apart from your IP address and the page you visited no personal data is transmitted to or via the provider. BunnyWay’s privacy policy: https://bunny.net/privacy/
Wildbit, LLC
To send system and form emails we use the “Postmark” product from the US-based service provider Wildbit LLC, 225 Chestnut St., Philadelphia, PA, 19106 USA. Wildbit is certified under the US-EU “Privacy Shield” framework and is therefore committed to complying with EU data protection regulations. Furthermore we have entered into a “Data Processing Agreement.” This is a contract in which Wildbit LLC commits to protecting our users’ data, processing it on our behalf in accordance with its privacy policy and in particular not disclosing it to third parties.
If you do not want the data you provide to leave the EU please contact us directly by email or mail and refrain from filling out contact forms.
Various Server Hosts
The content of this site as well as the underlying databases is stored on a so-called web server. We place a high priority on using servers located in Germany. The servers we use are housed in one or more data centers operated by an external provider. We do not use so-called “managed contracts” here but rely exclusively on self-managed “root servers.” In this case the external hosting provider is responsible only for operating the hardware and surrounding infrastructure; the software side is operated and maintained directly by us. We use various systems from the following providers:
- domainfactory GmbH, Oskar-Messter-Str. 33, 85737 Ismaning
- Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen
11. Rights of the Data Subject
If your personal data is processed, you are a data subject within the meaning of the GDPR and you have the following rights vis-à-vis the controller:2. Right to rectification
, 3. Right to restriction of processing,
4. Right to erasure
, 5. Right to be informed
, 6. Right to data portability.
7. Right to object to processing
8. Right to withdraw consent
under data protection law 9. Right not to be subject to automated decision-making
10. Right to lodge a complaint with a supervisory authority
1. Right of access
a) the purposes for which the personal data is processed;
b) the categories of personal data being processed;
c) the recipients or categories of recipients to whom the personal data concerning you have been or will be disclosed;
d) the planned duration of storage of the personal data concerning you or, if specific details cannot be provided, the criteria used to determine the storage period;
e) the existence of a right to rectification or erasure of the personal data concerning you, a right to restriction of processing by the controller or a right to object to such processing;
f) the existence of a right to lodge a complaint with a supervisory authority;
g) any available information regarding the origin of the data if the personal data are not collected from the data subject;
h) the existence of automated decision-making, including profiling, pursuant to Article 22(1) and (4) of the GDPR, and – at least in such cases – meaningful information regarding the logic involved, as well as the scope and intended effects of such processing on the data subject.
(2) You have the right to request information as to whether the personal data concerning you will be transferred to a third country or to an international organization. In this context you may request to be informed of the appropriate safeguards pursuant to Article 46 of the GDPR in connection with the transfer.
2. Right to Rectification
3. Right to Restriction of Processing
a) if you contest the accuracy of the personal data concerning you for a period that allows the controller to verify the accuracy of the personal data;
b) the processing is unlawful and you oppose the erasure of the personal data and instead request the restriction of its use;
c) the controller no longer needs the personal data for the purposes of the processing but you need it to assert, exercise or defend legal claims; or
d) if you have objected to the processing pursuant to Article 21(1) of the GDPR and it has not yet been determined whether the controller’s legitimate grounds override your grounds.
(2) If the processing of your personal data has been restricted, such data – apart from its storage – may be processed only with your consent or for the purpose of asserting, exercising or defending legal claims or to protect the rights of another natural or legal person or for reasons of an important public interest of the Union or a Member State. If the restriction on processing has been imposed in accordance with the above conditions you will be notified by the controller before the restriction is lifted.
4. Right to Erasure
a) The personal data concerning you are no longer necessary for the purposes for which they were collected or otherwise processed.
b) You withdraw your consent on which the processing was based pursuant to Article 6(1)(a) or Article 9(2)(a) of the GDPR, and there is no other legal basis for the processing.
c) You object to the processing pursuant to Article 21(1) of the GDPR and there are no overriding legitimate grounds for the processing, or you object to the processing pursuant to Article 21(2) of the GDPR.
d) The personal data concerning you has been processed unlawfully.
e) The erasure of your personal data is necessary to comply with a legal obligation under Union law or the law of the Member States to which the controller is subject.
f) Your personal data was collected in connection with information society services offered pursuant to Article 8(1) of the GDPR.
(2) If the controller has made the personal data concerning you public and is obligated to erase it pursuant to Article 17(1) of the GDPR, the controller shall, taking into account available technology and the cost of implementation, take reasonable measures, including technical measures, to inform controllers who process the personal data that you as the data subject have requested the erasure of all links to such personal data or of copies or replicas of such personal data.
(3) The right to erasure does not apply to the extent that the processing is
necessary a) for the exercise of the right to freedom of expression and information;
b) to comply with a legal obligation that requires processing under Union or Member State law to which the controller is subject or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
c) for reasons of public interest in the area of public health pursuant to Art. 9(2)(h) and (i) and Art. 9(3) of the GDPR;
d) for archiving purposes in the public interest, scientific or historical research purposes or for statistical purposes pursuant to Article 89(1) of the GDPR, insofar as the right referred to in section a) is likely to render impossible or seriously impair the achievement of the purposes of such processing; or
e) for the establishment, exercise or defense of legal claims.
5. Right to Information
6. Right to Data Portability
that: a) the processing is based on consent pursuant to Article 6(1)(a) of the GDPR or Article 9(2)(a) of the GDPR, or on a contract pursuant to Article 6(1)(b) of the GDPR, and
b) the processing is carried out by automated means.
(2) In exercising this right you also have the right to have the personal data concerning you transmitted directly from one controller to another controller, provided this is technically feasible. The freedoms and rights of other individuals must not be infringed upon as a result.
(3) The right to data portability does not apply to the processing of personal data necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.
(4) To exercise the right to data portability the data subject may contact the controller at any time.
7. Right to Object
(2) The controller shall no longer process the personal data concerning you unless it can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms or the processing is necessary for the establishment, exercise or defense of legal claims.
(3) If personal data concerning you is processed for the purpose of direct marketing you have the right to object at any time to the processing of personal data concerning you for the purpose of such marketing; this also applies to profiling to the extent that it is related to such direct marketing. If you object to processing for direct marketing purposes the personal data concerning you will no longer be processed for these purposes.
(4) In connection with the use of information society services – notwithstanding Directive 2002/58/EC – you have the option to exercise your right to object using automated procedures that employ technical specifications.
(5) To exercise the right to object the data subject may contact the data controller directly.
8. Right to Withdraw Consent under Data Protection Law
9. Automated Decision-Making in Individual Cases, Including Profiling
: a) is necessary for the conclusion or performance of a contract between you and the controller;
b) is authorized by Union or Member State law to which the controller is subject, and that law provides for appropriate measures to safeguard your rights and freedoms as well as your legitimate interests; or
c) is based on your explicit consent.
(2) However such decisions may not be based on special categories of personal data as defined in Article 9(1) of the GDPR, unless Article 9(2)(a) or (g) of the GDPR applies and appropriate measures have been taken to protect your rights and freedoms as well as your legitimate interests.
(3) With regard to the cases referred to in (1) and (3) the controller shall take appropriate measures to safeguard your rights and freedoms as well as your legitimate interests, including at least the right to request human intervention by the controller, to express your point of view and to contest the decision.
(4) If the data subject wishes to exercise rights relating to automated decisions, he or she may contact the data controller at any time.
10. Right to File a Complaint with a Supervisory Authority
12. Changes to the Privacy Policy
13. Legal Validity
If any parts or individual provisions of this Privacy Policy do not, no longer or do not fully comply with applicable law, the remaining parts of the document shall remain unaffected in terms of their content and validity.
