1. Responsible for data processing
In accordance with the provisions of the General Data Protection Regulation (GDPR), the controller responsible for data processing is:
Phone: +49 (0) 6242-7048
2. General information about data processing
We process data in connection with the operation of our business and our website.
This also includes disclosure by means of transmission to third parties and, if applicable, to “third-countries” outside of the European Union (“EU”) and the European Economic Area (“EEA”). We have provided appropriate notices below in cases where we transfer data outside of the EU or EEA.
3. Data processing
Specific data concerned, processing purposes, legal bases, recipients and, if applicable, transfers to third countries are listed below:
a) Log files when visiting our website
We log your visit to our website. The following data is processed in this context: Name of the website accessed, http status/error code, date and time of access, the amount of data transferred, the browser type and version, the operating system you are using, the referrer URL (the previously visited website), your IP address and the host name of the requesting computer and/or provider.
IP addresses are only saved in anonymized form. The administrators of the data center have access to the real, unmodified IP addresses for seven days in order to be able to pass them on to authorities, for criminal prosecution for example. The log file is deleted after fourteen days unless it is required for clarification or verification of specific violations of the law of which we have become aware within the retention period.
This data is transferred on the basis of our legitimate interest in ensuring the security of our website in accordance with Art. 6(1)(f) GDPR.
In order to operate our website, we use the services of web hosting providers which process the data described above, all of which is needed to operate our website (log file when you visit our website), on our behalf.
According to Art. 6(1)(f) GDPR, the legal basis for this data processing is our overriding legitimate interest in operating our website.
c) Contacting us
If you contact us, we will process the following data you have provided to us in order to process and resolve your inquiry: Name, contact details – if you have provided them – and your inquiry.
The legal basis for this data processing is our obligation to satisfy a contract and/or to satisfy pre-contractual obligations according to Art. 6(1)(b) GDPR and/or our overriding legitimate interest in processing your inquiry according to Art. 6(1)(f) GDPR.
d) Contract performance
In the event that you order goods from our winery by telephone or e-mail, we will process your order data within the scope of performing the contract between you and us.
The legal basis for this data processing is Art. 6(1)(b) GDPR when fulfilling our contractual obligations and, in specific cases, Art. 6(1)(c) GDPR when fulfilling our legal obligations.
We transmit your address data to the company hired to carry out the delivery. Where necessary to execute the contract, we also provide your e-mail address or telephone number to coordinate a delivery date (notification of dispatch) to the company hired to carry out the delivery.
We transmit your transaction data (name, date of order, payment method, date of dispatch and/or receipt, amount and payment recipient, bank details or credit card details) to the payment service provider responsible for processing the payment.
e) AWStats and Report Magic
We use the statistics programs AWStats and Report Magic for purposes of performing a statistical analysis of the number of visitors to our website.
This statistical analysis is performed using log files that have already been made anonymous; personal identification is not possible. No cookies are used.
The following data is processed from the log files: website accessed, date and time of server inquiry, the amount of data transferred, the number of visits, your country of origin, the length of stay on the website, the browser type and version, the operating system used by you, the referrer URL (the website visited previously) and your anonymized IP address.
Both programs work exclusively via our own web server; no data is transferred to third parties.
This data is processed in accordance with Art. 6(1)(f) GDPR on the basis of our overriding interest in the optimization of our website.
f) Third-party content
We use third-party dynamic content (“content”) to optimize the display and offerings on our website. When visiting our website, a request is automatically submitted via an interface to the server of the respective content provider, as part of which certain log data (e.g. the user’s IP address) is transmitted. The dynamic content is then transmitted to our website and displayed there.
We use third-party content in connection with the following functionalities:
We use external fonts provided by Adobe Fonts in order to make our website more attractive. They are uploaded from servers operated by Adobe Systems Inc., San Jose, California, USA (“Adobe”) when you visit our website. Adobe does not save any cookies to your browser. However, as we understand it, the IP address of a user’s device is sent to Adobe and stored there.
Processing in this context is performed on the basis of our overriding legitimate interest in the optimum marketing of our website in accordance with Art. 6(1)(f) GDPR.
Adobe is certified under: https://www.privacyshield.gov/participant?id=a2zt0000000TNo9AAG&status=Active
Further information on data protection can be found at: http://www.adobe.com/privacy.html
4. Social media profiles
We maintain the following social media profiles to present our company and to interact and communicate with customers and potential customers:
Processing in this context is performed on the basis of our overriding legitimate interest in the optimum marketing of our website as well as customer loyalty and customer acquisition in accordance with Art. 6(1)(f) GDPR.
5. Data retention period
We only retain personal data for as long as is necessary for the purposes for which it is processed or until you withdraw your consent. The retention period for certain data can be up to 10 years irrespective of the processing purposes in the event that we must comply with statutory retention obligations.
6. Your rights as a data subject
Upon request, you may receive information about all personal data that we have stored about you at any time and free of charge.
b) Rectification, erasure, restriction of processing (blocking), objection
Should you no longer agree to the retention of your personal data or should such data have since become incorrect, we will arrange for the erasure or blocking of your data or make the necessary corrections (insofar as this is possible under applicable law) upon instruction from you. The same applies if you would like us to restrict the processing of your data in future. You have the right to object in particular in cases where your data is necessary for the performance of a task carried out in the public interest, or in pursuit of our legitimate interests or in cases based on profiling. You likewise have a right to object in the case of data processing for purposes of direct marketing.
c) Data portability
You have a right of data portability in cases where data is processed on the basis of a contract, pre-contractual negotiations or consent or by means of an automated process. Upon request, we will provide you with your data in a structured, commonly used and machine-readable format so that you can, if you wish, transmit your data to another controller.
d) Right to withdraw consent with prospective effect
You can withdraw your consent at any time with prospective effect. Withdrawal of your consent does not affect the lawfulness of processing conducted before you have withdrawn consent.
e) Right to lodge a complaint
You also have the option of lodging a complaint related to your rights as a data subject with a supervisory authority: (https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html).
The rights described above do not apply to data for which we are not able to identify the data subject, e.g. if anonymized for analytical purposes. It may be possible to exercise your rights of access, erasure, blocking, rectification or portability with regard to this data if you provide us with additional information that enables us to make the required identification.
6. Exercising your rights as a data subject
If you have any questions regarding the processing of your personal data, or if you would like to request access, rectification, blocking, if you would like to object or have your data erased, or if you wish to transfer your data to another company, please contact firstname.lastname@example.org.