FOOLOGRAPHY PRIVACY POLICY
Table of contents
- Data Controller
- Relevant Legal Basis
- Data Securitys
- Collection, Processing and Use of Personal Data
- Collection, Processing and Use of Non-Personal Data
- Collection, Processing and Use of Data When Contacting Us and Subscribing to the Newsletter
- Use of Social-Plugins
- Online Presence in Social Media
- Your Rights Towards Foolography
- Contact the Data Protection Officer of Foolography
- Modification of the Privacy Policy conditions
The protection of personal data is an important concern to us. We value your privacy and we collect, process and use personal data in accordance with the laws and regulations of the Federal Republic of Germany as well as superordinate European legal requirements.
By agreeing to the following privacy policy you hereby consent to the collection, processing and use of personal data by Foolography GmbH, Greifswalder Str. 9, 10405 Berlin, Germany in compliance with the applicable legal requirements and the following provisions. Detailed information on the use of personal data can be found under the point “Collection, Processing and Use of Personal data” in this privacy policy.
1. Data Controller
Data controller for the collection, processing and use of personal data within the meaning of the Federal Data Protection Act is
Foolography GmbHGreifswalder Str. 9
10405 Berlin
Germany
E-Mail: info@foolography.com
For some of the below mentioned data processings, our respective cooperation partners share responsibility from the data protection point of view, in addition to Foolography GmbH. Therefore, you can exercise certain rights against the respective cooperation partners. Related relevant information can be obtained in the respective part of this privacy policy.
2. Relevant Legal Basis
In accordance with Art. 13 GDPR, we inform you about the legal basis of our data processing. Unless the legal basis in the data protection declaration is mentioned, the following applies: The legal basis for obtaining consent is Article 6 (1) lit. a and Art. 7 GDPR, the legal basis for the processing for the performance of our services and the execution of contractual measures as well as the response to inquiries is Art. 6 (1) lit. b GDPR, the legal basis for processing in order to fulfil our legal obligations is Art. 6 (1) lit. c GDPR, and the legal basis for processing in order to safeguard our legitimate interests is Article 6 (1) lit. f GDPR. In the event that vital interests of the affected person or another natural person require the processing of personal data, Art. 6 para. 1 lit. d GDPR serves as legal basis.
3. Data Security
To ensure that your data is secure during transfer, we use state-of-the-art encryption methods on our website in accordance with Art. 32 GDPR.
However, we would like to point out that data transmissions via internet (e.g. e-mail communication) cannot be entirely secure and may have security vulnerabilities. A complete protection of personal details against unauthorised access by third parties is not possible.
4. Collection, Processing and Use of Personal Data
Collection, Processing and Use of Personal Data by Foolography
The use of our website is usually possible without providing personal data. Personal data are always provided on a voluntary basis if possible.
Personal data means any information concerning the personal or material circumstances of an identified or identifiable natural person. In essence, this includes any personal information that you communicate to us during registration or when placing an order.
To facilitate the delivery and use of the our products, we collect, process and use the
In principle, we collect, process and use the specified data only for the purpose of execution and settlement of the contract.
Personal data shall only be stored on servers within the EU. We currently use ALL-INKL.COM – Neue Medien Münnich (the server is located in Germany).
Collaboration with Processors and Third Parties
If, in the context of our processing, we disclose data to other persons and companies (contract processors or third parties), transmit them to them or otherwise grant access to the data, this will only be done on the basis of a legal permission (eg if a transmission of the data to third parties, as required by payment service providers, delivery services, pursuant to Art. 6 (1) (b) GDPR to fulfill the contract), if you have consented to a legal obligation or based on our legitimate interests (eg the use of agents, webhosters, etc.).
If we commission third parties to process data on the basis of a so-called “data-processing-agreement”, this is done on the basis of Art. 28 GDPR.
We use external payment service providers, through whose platforms the users and we can make payment transactions (eg, with a link to the privacy policy, Paypal (https://www.paypal.com/de/webapps/mpp/ua/privacy-full?locale.x=en_DE), Stripe for acceptance of credit card payments (https://stripe.com/privacy)).
As part of the fulfillment of contracts, we use payment service providers on the basis of Art. 6 (1) (b) GDPR. Moreover, we use external payment service providers on the basis of our legitimate interests. Art. 6 (1) (f) GDPR to offer you as a user effective and secure payment options.
Amongst the data processed by the payment service providers are inventory data, eg the name and the address, bank data, such as account numbers or credit card numbers, passwords, checksums and contract, summary and recipient-related information. The information is required to complete the transactions. However, the data entered will only be processed and stored by the payment service providers, meaning we do not receive any account or credit card information, but only information with confirmation or negative disclosure of the payment. The data may be transmitted by the payment service providers to credit reporting agencies. This transmission aims at the identity and credit check. For this we refer to the terms and privacy policy of payment service providers.
For the payment transactions, the terms and conditions and the privacy notices of the respective payment service providers, which are available within the respective websites or transaction applications apply. We also refer to these for further information and assertion of rights of withdrawal, information and other data subjects.
Transfers to Third Countries
If we process data in a third country (ie outside the European Union (EU) or the European Economic Area (EEA)) or in the context of the use of third party services or disclosure or transmission of data to third parties, this will only be done if it is to fulfill our (pre) contractual obligations, on the basis of your consent, on the basis of a legal obligation or on the basis of our legitimate interests. Subject to legal or contractual permissions, we process or have the data processed in a third country only in the presence of the special conditions of Art. 44 et seq. GDPR. i.e. the processing is e.g. on the basis of specific guarantees, such as the officially recognized level of data protection or compliance with officially recognized special contractual obligations (so-called “standard contractual clauses”).
5. Collection, Processing and Use of Non-Personal Data
Non-personally identifiable information in this sense is information collected or processed for solely statistical purposes (e.g. about the usage behaviour on our website), which cannot be traced back to a natural person.
Technically Required Data: Sever-Logfiles
Information is automatically recorded when you access our website. This information (Server-Log files) includes
This only means such information, which does not allow any conclusions about your person. This information is technically necessary to correctly provide the website contents that you want, as well as to clarify any incidents or security incidents (such as attempts to attack), and is mandatory when using the Internet. We may statistically evaluate anonymous information of this type, to optimise our Internet presence and the technology behind it.
Those files only get stored for the time of your use of our website. Log files whose further storage is required for evidential purposes are excluded from the deletion until final clarification of the respective incident and can be forwarded to investigating authorities in individual cases.
The legal basis for the processing of your data for technical purposes is the preservation of our legitimate interest in the usability and protection of our website, Art. 6 (1) p. 1 lit. f GDPR.
Cookies
To make the visit to our website attractive and to enable the use of certain functions, we use so-called cookies like many other websites. Cookies are small text files that are transferred from a website server to your hard drive. This automatically gives us certain data, such as IP address, browser used, operating system via your computer and your connection to the Internet. Cookies cannot be used to launch programs or to transfer viruses to a computer. With the help of cookies, we can make navigation easier for you, improve website performance and make surfing safer. Under no circumstances will the data processed by us be passed on to third parties or a link with your personal data will be established without your consent.
Most of the cookies we use are so-called “session cookies”. They will be automatically deleted after the end of the Internet offer. Otherwise, a storage takes place in compliance with applicable data protection regulations – until you contradict the further use of cookies.
You can configure your browser so that you will be informed about the setting of cookies and individually decide on their acceptance or may exclude the acceptance of cookies for specific cases or in general. Please use the help features of your internet browser to find out how to change these settings.
A general objection to the use of cookies used for online marketing purposes can be found in a variety of services, especially in the case of tracking, via the US website http://www.aboutads.info/choices/ or the EU site http://www.youronlinechoices.com/ be explained.
Please note that if you choose not to accept cookies, the functionality of our site may be reduced.
The legal basis for the processing of your data for technical purposes is the preservation of our legitimate interest in the usability and protection of our website, Art. 6 (1) p. 1 lit. f GDPR.
Use of Google Analytics
Based on our legitimate interests (i.e., interest in the analysis, optimization, and economic operation of our online offer within the meaning of Art. 6 (1) lit. GDPR), we use Google Analytics, a web analytics service provided by Google LLC (“Google”). Google uses cookies. The information generated by the cookie about the use of the online offer by the users are usually transmitted to a Google server in the USA and stored there.
Google will use this information on our behalf to evaluate the use of our online offer by users, to compile reports on the activities within this online offer and to provide us with further services related to the use of this online offer and the internet usage. In this case, pseudonymous usage profiles of the users can be created from the processed data.
We only use Google Analytics with activated IP anonymization. This means that the IP address of the users will be shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be sent to a Google server in the US and shortened there.
The IP address submitted by the user’s browser will not be merged with other data provided by Google. Users can prevent the storage of cookies by setting their browser software accordingly; Users may also prevent the collection by Google of the data generated by the cookie and related to its use of the online offer and the processing of such data by Google by downloading and installing the browser plug-in available at the following link: http://tools.google.com/dlpage/gaoptout?hl=DE.
As an alternative to the browser add-on or within browsers on mobile devices, please click this link to prevent the future detection by Google Analytics within this website:
[gadwp_useroptout html_tag=”a”]Google Analytics Opt-out[/gadwp_useroptout].
An opt-out cookie is stored on your device. If you delete your cookies, you must click this link again.
For more information about Google’s data usage, hiring and disparaging options, please read Google’s Privacy Policy (https://policies.google.com/technologies/ads) and Google’s Ads Ads Settings (https://adssettings.google.com/authenticated).
The personal data of users will be deleted or anonymized after 14 months.
6. Collection, Processing and Use of Data When Contacting Us and Subscribing to our Newsletter
Use of Data When Contacting Us
If you contact us by e-mail or telephone, we will process the information provided by you for the purpose of processing the request and for possible follow-up questions.
The legal basis for the processing of your data may be in particular: the execution or initiation of a contract with you, Art. 6 para. 1 lit. b GDPR, or our legitimate interest in answering and following up your request, Art. 6 para. 1 lit. f GDPR.
Comments and Posts
If users leave comments or other contributions, their IP addresses may be stored for 7 days based on our legitimate interests within the meaning of Art. 6 (1) lit. f. DSGVO. This is for our own safety, if someone leaves illegal content in comments and contributions (insults, prohibited political propaganda, etc.). In this case, we ourselves can be prosecuted for the comment or post and are therefore interested in the identity of the author.
Furthermore, we reserve the right, in accordance with our legitimate interests according to Art. 6 (1) lit. f. DSGVO to process the information of users for the purpose of spam detection.
On the same legal basis, we reserve the right, in the case of surveys, to store users’ IP addresses for the survey’s duration and to use Cookies to avoid multiple reconciliations.
The data provided in the comments and contributions are stored by us permanently until the users object.
Use of Data for Email-Newsletter-Sign-Up
With the following instructions, we will inform you about the content of our newsletter as well as the registration, shipping and statistical evaluation procedures as well as your right of objection. By subscribing to our newsletter, you agree to the receipt and the procedures described.
Content of the Newsletter
We send newsletters, e-mails and other electronic notifications with advertising information (hereinafter “newsletter”) only with the consent of the recipient or a legal permission. Insofar as the contents of a newsletter are concretely described, they are authoritative for the consent of the users. Incidentally, our newsletters contain information about Foolography, its products, offers or other news in the field of photography/videography.
Double Opt-In and Logging
The registration for our newsletter takes place in a so-called double opt-in procedure. That means after registration you will receive an e-mail asking you to confirm your registration. This confirmation is necessary so that nobody can register with unauthorised e-mail addresses.
The registration for the newsletter will be logged in order to prove the registration process according to the legal requirements. This includes the storage of the login and the confirmation time, as well as the IP address. Likewise, changes to your data stored with MailChimp will be logged.
Use of the Service Provider “MailChimp”
The newsletter is distributed via “MailChimp”, a newsletter shipping platform of Rocket Science Group, LLC, 675 Ponce De Leon Ave # 5000, Atlanta, GA 30308, USA.
The e-mail addresses of our Newsletter recipients, as well as their other information described in these notes, are stored on the servers of MailChimp in the USA. MailChimp uses this information to send and evaluate the newsletters on our behalf. Furthermore, MailChimp may, according to its own information, use this data to optimize or improve its own services, e.g. for the technical optimization of the shipping and the presentation of the newsletter or for economic purposes, to determine from which countries the recipients come. However, MailChimp does not use the data of our newsletter recipients to write them down or to pass them on to third parties.
We rely on the reliability, IT and data security of MailChimp. MailChimp is committed to complying with EU data protection requirements. Furthermore, we have concluded a data processing agreement with MailChimp (https://mailchimp.com/legal/forms/data-processing-agreement/). This is a contract in which MailChimp pledges to protect the data of our users, to process it in accordance with its privacy policy on our behalf and, in particular, not to disclose it to third parties. You can read the privacy policy of MailChimp here (https://mailchimp.com/legal/privacy/).
Credentials
To sign up for the newsletter, it is sufficient to enter your e-mail address.
Optionally, we ask you to provide your first and last name. This information is only for the personalization of the newsletter. In addition, we also kindly ask you to indicate your industry or your interest in our products. We only use this information to adapt the content of the newsletter to the interests of our readers.
Statistical Survey and Analyzes
The newsletters contain a so-called “web-beacon”, i.e. a pixel-sized file that is retrieved from the MailChimp server when the newsletter is opened. This retrieves technical information, such as browser and system information, as well as your IP address and time of retrieval. This information is used to improve the technical performance of services based on their specifications or audience and their reading habits, based on their locations (which can be determined using the IP address) or access times.
Statistical surveys also include determining if the newsletters are opened, when they are opened and which links are clicked. For technical reasons, this information can be assigned to the individual newsletter recipients. However, it is neither our desire nor that of MailChimp to observe individual users. The evaluations serve us much more to recognize the reading habits of our users and to adapt our content to them or to send different content according to the interests of our users.
Online Call and Data Management
There are cases in which we direct the newsletter recipients to the MailChimp websites. For example, our newsletters contain a link that allows newsletter recipients to retrieve newsletters online (for example, in the case of display problems in the e-mail program). Furthermore, newsletter recipients can store their data, such as correct the e-mail address later. Also, the privacy policy (https://mailchimp.com/legal/privacy/) of MailChimp is only available on their page.
In this context, we point out that on the websites of MailChimp cookies are used and thus personal data processed by MailChimp, their partners and service providers are used (for example, Google Analytics). We have no influence on this data collection. For more information, see the privacy policy (https://mailchimp.com/legal/privacy/) provided by MailChimp. We also inform you of the possibility of objecting to the data collection for promotional purposes on the websites http://www.aboutads.info/choices/ and http://www.youronlinechoices.com/ (for the European area).
Termination / Revocation
You can terminate the receipt of our newsletter at any time, i.e. revoke your consent. At the same time, your consent to sending it via MailChimp and the statistical analyzes will be canceled. A separate revocation of the dispatch via MailChimp or the statistical evaluation is unfortunately not possible.
A link to cancel the newsletter can be found at the end of each newsletter. Alternatively, you can send us a message to info@foolography.com.
Legal Basis of the Data Protection Regulation
In accordance with the provisions of the Data Protection Regulation (GDPR), which will apply from May 25, 2018, we inform you that the consent to the sending of e-mail addresses is on the basis of Art. 6 (1) lit. a, 7 GDPR and § 7 (2) no. 3 and (3) UWG. The use of the mail service provider MailChimp, carrying out the statistical surveys and analyzes as well as logging the registration process, are based on our legitimate interests in accordance with. Art. 6 para. 1 lit. f GDPR. We are interested in using a user-friendly and secure newsletter system that serves both our business’ interests as well as the expectations of our users.
We further point out that you can object to the future processing of your personal data in accordance with the statutory requirements. Art. 21 GDPR at any time. The objection may in particular be made against processing for direct marketing purposes.
7. Use of Social Plugins
Based on our legitimate interests (i.e. interest in the analysis, optimization and economic operation of our online offer within the meaning of Art. 6 (1) f. GDPR) we use social plugins (“plugins”) of the social network facebook.com, which is operated by Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbor, Dublin 2, Ireland (“Facebook”). The plugins can represent interaction elements or content (e.g. videos, graphics or text contributions) and can be recognized by one of the Facebook logos (white “f” on blue tile or lined border, the terms “Like”, “Gefällt mir” or a “thumbs up” sign) or are marked with the addition “Facebook Social Plugin”. The list and appearance of Facebook Social Plugins can be viewed here: https://developers.facebook.com/docs/plugins/.
When a user makes use of a feature of this online offering that includes such a plugin, their device establishes a direct connection to the Facebook servers. The content of the plugin is transmitted by Facebook directly to the device of the user and incorporated by it into the online offer. In the process, user profiles can be created from the processed data. We therefore have no influence on the amount of data that Facebook collects with the help of this plugin and therefore inform you according to our knowledge.
By integrating the plugins, Facebook receives the information that a user has accessed the corresponding page of the online offer. If the user is logged-in to Facebook, Facebook can assign the visit to his Facebook account. If users interact with the plugins, for example, press the Like button or leave a comment, the information is transmitted from your device directly to Facebook and stored there. If a user is not a member of Facebook, there is still the possibility that Facebook will find out and save their IP address. According to Facebook, only an anonymous IP address is stored in Germany.
The purpose and scope of the data collection and the further processing and use of the data by Facebook, as well as the related rights and setting options for protecting the privacy of users, can be found in Facebook’s privacy policy: https://www.facebook.com/about/privacy/.
If a user is a Facebook member and does not want Facebook to collect data about him via this online offer and link it to his member data stored on Facebook, he must log out of Facebook and delete his cookies before using our online offer. Other settings and inconsistencies regarding the use of data for advertising purposes are possible within the Facebook profile settings: https://www.facebook.com/settings?tab=ads or via the US-American site http://www.aboutads.info/choices/ or the EU page http://www.youronlinechoices.com/. The settings are platform independent, i.e. they are adopted for all devices, such as desktop computers or mobile devices.
Within our online offering, features and content of the Twitter service offered by Twitter Inc., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA, may be incorporated. These include content such as images, videos, or text and buttons that users use to promote their content. User can also subscribe to content creators or subscribe to our posts. If the users are members of the platform Twitter, Twitter can assign the accessed contents and functions mentioned above to the profiles of the users there. Privacy Policy: https://twitter.com/privacy, Opt-Out: https://twitter.com/personalization.
Within our online offering, features and content of the Instagram service offered by Instagram Inc., 1601 Willow Road, Menlo Park, CA, 94025, USA, may be incorporated. These include content such as images, videos, or text and buttons that users use to promote their content. User can also subscribe to content creators or subscribe to our posts. If the users are members of the platform Instagram, Instagram can assign the accessed contents and functions mentioned above to the profiles of the users there. Instagram privacy policy: http://instagram.com/about/legal/privacy/.
Google Maps
We include maps from the Google Maps service provided by Google LLC, 1600 Amphitheater Parkway, Mountain View, CA 94043, USA. The processed data may include, in particular, users’ IP addresses and location data, but these are not collected without their consent (usually as part of the settings of their mobile devices). The data can be processed in the USA. Privacy Policy: https://www.google.com/policies/privacy/, opt-out: https://adssettings.google.com/authenticated.
8. Online Presence in Social Media
We maintain a Foolography online presence within social networks and platforms in order to communicate with customers, prospects and users active there and to inform them about our services. When visiting the respective networks and platforms, the terms and conditions and the data processing guidelines of the respective operators apply.
Unless otherwise stated in our Privacy Policy, we process users’ data as long as they communicate with us within social networks and platforms, e.g. write posts on our online presence or send us messages.
9. Your Rights Towards Foolography
We would like to inform you briefly about the data protection rights that you can exercise against Foolography:
Right to Information
According to Art. 15 GDPR you have the right to receive information about the personal data stored by us at any time. Please send us an e-mail to info@foolography.com.
Right of Rectification
Foolography may only process applicable data about you. If you – for example, by exercising your right to information – find out that something about you is inaccurate or has become inaccurate, we are basically obliged under Art. 16 GDPR to rectify it immediately. In accordance with Art. 20 GDPR, you also have the right to demand the data relating to you that you provided to us. You may also request their transmission to other persons responsible.
Cancellation Right / Right to Restriction of Processing: Blocking Right
The data processed by us are deleted or limited in their processing in accordance with Articles 17 and 18 GDPR. Unless explicitly stated in this privacy policy, the data stored by us are deleted as soon as they are no longer required for their purpose and the deletion does not conflict with any statutory storage requirements. If the data will not be deleted because it is required for other and legitimate purposes, its processing will be restricted i.e. the data is blocked and not processed for other purposes. This applies, for example for data that must be kept for commercial or tax reasons.
According to legal requirements in Germany, the storage takes place for 10 years according to §§ 147 Abs. 1 AO, 257 Abs. 1 Nr. 1 and 4, Abs. 4 HGB (books, records, management reports, accounting documents, trading books, relevant for taxation Documents, etc.) and 6 years in accordance with § 257 (1) no. 2 and 3, para. 4 HGB (commercial letters).
Withdrawal
You have the right to revoke the granted consent with effect for the future according to Art. 7 (3) GDPR.
Objection
You can object to the future processing of your data in accordance with Art. 21 GDPR at any time. The objection may in particular be made against processing for direct marketing purposes.
Right of Appeal to the Supervisory Authority
You have acc. to. Art. 77 GDPR the right to file a complaint with the competent supervisory authority.
10. Contact the Data Protection Officer of Foolography
If you have any questions or concerns about privacy or our privacy policy, please contact us at the following e-mail address: info@foolography.com.
11. Modification of the Privacy Policy conditions
We reserve the right to occasionally make changes to those parts of this data protection declaration that do not require consent, so that it always corresponds to the current statutory requirements or to implement changes to our services in the data protection declaration. The new data protection declaration shall then be applicable upon your new visit. If your prior consent is required for a change to our services or for introducing new services, we shall inform you accordingly at the right time and request for your consent.