Privacy Policy kitchenplanner.net
1. Name and contact details of the person responsible (data controller) for processing and of the company Data Protection Officer
The data controller:
KüchenAtlas Portal Betriebs GmbH
Fürstenrieder Str. 5
80687 München
Tel.: +49 (0) 89 - 961 600 38-0
Fax: +49 (0) 89 / 961 600 38-9
For data protection questions, please contact the above address or send an email to datenschutz@kuechenatlas.com
2. Collection and storage of personal data as well as the type and purpose of their use
-
When visiting the website
When you visit our website, the browser used on your device automatically sends information to the server of our website. This information is temporarily stored in a "log file". The following information is recorded without your intervention and stored until it is automatically deleted:
- Name of the file requested
- Date and time of the access
- The amount of data transferred
- Indication whether query was successful
- Description of the type of browser used
- Operating system used
- Previously visited page
- Provider
- Your IP address
The data listed will be processed by us for the following purposes:
- ensuring a smooth connection to the website;
- ensuring comfortable use of our website;
- evaluation of system security and stability as well as
- for other administrative purposes.
The legal basis for data processing is Art. 6 para. 1 sentence 1 (f) GDPR. Our legitimate interest arises from the purposes listed above for data collection. Under no circumstances do we use the data collected for the purpose of drawing conclusions about you personally.
We also use cookies, analysis and marketing services when you visit our website. You will find more detailed explanations under Sections 4 - 6 of this data protection declaration.
-
When using our kitchen planner or watch lists
On our website we offer you the possibility to plan a kitchen or to create watch lists. By entering an email address you can save the current kitchen plan or watch list and call it up again in the future via the access mail sent to you.
The data will be processed in accordance with Art. 6 para. 1 (b) GDPR on the basis of your specific request.
-
When using a service on a partner's website
For the preparation of concrete offers we offer partners, e.g. kitchen dealers, the possibility to integrate one of our services (e.g. kitchen planner) on their website, in the context of which you have the possibility to make a qualified inquiry by stating the name, their contact data (telephone number or email address), postal code and city. In some cases, further information may be added voluntarily. The data you enter in the service will be stored by us and passed on to the operator of the website in which the service is integrated for processing the request.
The data processing for the purpose of storage and/or the establishment of contact by the respective partner takes place according to Art. 6 Abs.1 (b) GDPR on basis of your concrete inquiry.
-
When using our contact forms
If you have any questions, we offer you the opportunity to contact us via a contact form provided on the website. Your name, your contact details (telephone number or e-mail address) and a message are required in order to be able to answer them. Further information can be provided voluntarily.
The data processing for the purpose of storage and/or the establishment of contact by the respective partner takes place according to Art. 6 para.1 (b) GDPR on basis of your concrete inquiry.
-
When using our forms for qualified enquiries
For the preparation of concrete offers, we offer you various kitchen planners and selection tools on the website, within the scope of which you have the possibility of a qualified inquiry by entering your surname, your contact data (telephone number or email address), postcode and city. In some cases, further information may be added voluntarily.
The data processing for the purpose of storage and/or the establishment of contact by the respective partner takes place according to Art. 6 para.1 (b) GDPR on basis of your concrete inquiry.
-
When using our rating portal
When entering a rating in our rating portal, an email address is required for verification or any queries.
Data processing is thus carried out on the basis of our legitimate interest pursuant to Art. 6 para. 1 (f) GDPR.
-
When creating a user account
On our website, we offer users the option to register by the entering personal data. The data is entered into an input screen, transmitted to us, and stored. This data is not transferred to third parties.
The following data are collected during the registration process:
- User name
- Email address
- Nickname
- Public pseudonym
User registration is required for the following functions and services on our website:
- Creation of a user account (customer)
- Creation of a user account (kitchen dealer)
- Posting of job vacancies
- Saving kitchen plans
- Publish reviews
- Save watch lists
The legal basis for the processing of data is Art. 6 para. 1 (a) GDPR if the user has given his consent. If registration serves the fulfilment of a contract to which the user is a party or the implementation of pre-contractual measures, the additional legal basis for the processing of the data is Art. 6 para. 1 (b) GDPR.
3. Sharing of data
Your personal data will not be transmitted to third parties for reasons other than those listed below.
We will only disclose your personal data to third parties if:
- you have given your express consent pursuant to Art. 6 para. 1 sentence 1 (a) GDPR,
- the disclosure pursuant to Art. 6 para. 1 sentence 1 (f) GDPR is necessary to assert, exercise or defend legal claims and there is no reason to assume that you have an overriding interest worthy of protection in not disclosing your data,
- in the event that a legal obligation exists for the transfer pursuant to Art. 6 para. 1 sentence 1 (c) GDPR, and
- this is legally permissible and is necessary for the processing of contractual relationships with you in accordance with Art. 6 para. 1 sentence 1 (b) GDPR.
We use so-called cookies in some areas of our website. Such file elements enable the identification of your computer as a technical unit while you visit in order to facilitate your use of our services - even during repeat visits.
However, your Internet browser generally gives you the option to edit your settings so that you are informed of the occurrence of cookies so that you can accept or reject them, as well as the option delete existing cookies.
Please refer to your Internet browser's help function to learn how to change these settings. Please note that some features of our website may not work if you have disabled the use of cookies.
Cookies do not allow a server to read private data from your computer or data stored by another server. Cookies do not harm your computer and do not contain viruses.
We base the use of cookies on art. 6 par. 1 (f) GDPR: they are processed to improve the functioning of our website. It is therefore necessary to protect our legitimate interests.
5. Use of hCaptcha
We use the hCaptcha security service (hereinafter "hCaptcha") on our website. This service is provided by Intuition Machines, Inc., a Delaware US Corporation ("IMI"). hCaptcha is used to check whether user actions on our online service (such as submitting a login or contact form) meet our security requirements. To do this, hCaptcha analyzes the behavior of the website or mobile app visitor based on various characteristics. This analysis starts automatically as soon as the website or mobile app visitor enters a part of the website or app with hCaptcha enabled. For the analysis, hCaptcha evaluates various information (e.g. IP address, how long the visitor has been on the website or app, or mouse movements made by the user). The data collected during the analysis will be forwarded to IMI. hCaptcha analysis in the "invisible mode" may take place completely in the background. Website or app visitors are not advised that such an analysis is taking place if the user is not shown a challenge.
Data processing is based on Art. 6(1)(b) of the GDPR: the processing of personal data is necessary for the performance of a contract to which the website visitor is party (for example, the website terms) or in order to take steps at the request of the website visitor prior to entering into a contract. Our online service (including our website, mobile apps, and any other apps or other forms of access offered by us) needs to ensure that it is interacting with a human, not a bot, and that activities performed by the user are not related to fraud or abuse.
In addition, processing may also be based on Art. 6(1)(f) of the GDPR:
our online service has a legitimate interest in protecting the service from abusive automated crawling, spam,
and other forms of abuse that can harm our service or other users of our service.
IMI acts as a "data processor" acting on behalf of its customers as defined under the GDPR, and a "service provider" for the purposes of the California Consumer Privacy Act (CCPA).
For more information about hCaptcha’s privacy policy and terms of use, please visit the following links:
https://www.hcaptcha.com/privacy and https://www.hcaptcha.com/terms
6. Use of marketing cookies
We use Loopa Automate marketing and remarketing services ('Marketing Services' for short) from Signifi Media Pty Ltd, Suite 168, 580 Hay Street, Perth, 6000, Australia.
Marketing Services use cookies from the third parties listed below, which are stored on your computer and allow us to better target ads for and on our website, to show users only ads that may of interest to them. For example, if a user sees ads for products he has been interested in on other websites, this is referred to as 're-marketing.' For these purposes, when our and other websites on which Marketing Services are active are accessed, a code is immediately executed and so-called (re)marketing tags are integrated into the website.
Further data protection regulations of the Marketing Service Loopa and Signifi Media can be found under the following links:
- Signifi Media (https://www.signifimedia.com.au/privacy-policy/)
- Loopa Automate (https://www.loopaautomate.com/privacy-policy/)
Loopa Automate uses the following third-party providers to whom the respective usage data may be transmitted:
- Facebook (https://www.facebook.com/privacy/policy/)
- Google (https://policies.google.com/privacy)
- Xandr (https://www.xandr.com/privacy/)
- Taboola (https://www.taboola.com/policies/privacy-policy)
We base the use of the above-mentioned feature on Art. 6 para. (1) (a) GDPR.
If you wish to object to interest-based advertising by the aforementioned marketing services, you can use the following opt-out options:
- Loopa Automate https://ads-eu.loopaautomate.com/pixel/optout
- Facebook https://www.facebook.com/policies/cookies/
- Google https://www.google.com/ads/preferences
- Xandr (https://monetize.xandr.com/privacy-center/)
- Taboola (https://accessrequest.taboola.com/access)
7. Use of Google Marketing Services
We use the marketing and remarketing services ("Google Marketing Services" for short) of Google Inc, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
Google Marketing Services use cookies that are stored on your computer and allow us to target ads for and on our site to show users only ads that may be of interest to them. For example, if a user sees ads for products he has been interested in on other websites, this is referred to as "re-marketing". For these purposes, when our and other websites on which Google marketing services are active are called up, a Google code is executed directly by Google and so-called (re)marketing tags are integrated into the website.
The information generated by the cookie about your use of this website is usually transferred to a Google server in the US and stored there. However, if IP anonymisation is activated on this website, your IP address will be truncated by Google within the member states of the European Union or in other countries that are contracting parties to the Agreement in the European Economic Area. The data of users are processed pseudonymously within the framework of Google marketing services. This means that Google does not store and process, for example, the names or email addresses of users, but processes the relevant data cookie-related within pseudonymous user profiles. This means from Google's point of view, the ads are not managed and displayed for a specifically identified person, but for the cookie holder, regardless of who this cookie holder is. This does not apply if a user has expressly permitted Google to process the data without this pseudonymisation. The information collected by Google marketing services about users is transmitted to Google and stored on Google's servers in the USA.
One of the Google marketing services we use is the online advertising program "Google AdWords". In the case of Google AdWords, each AdWords customer receives a different "conversion cookie". Thus, cookies cannot be tracked using the website of Adwords customers. The information obtained using the conversion cookie is used to create conversion statistics for the Adwords advertisers who have opted for conversion tracking. Adwords customers can find out the total number of users who have clicked on their ad and been redirected to the page with a conversion tracking tag. However, advertisers do not obtain any information that can be used to personally identify users.
We may use the Google marketing service "DoubleClick" to integrate third-party advertisements. AdSense uses cookies to enable Google and its partner sites to serve ads based on users' visits to this site or other sites on the Internet.
We can also use the "Google Tag Manager" to integrate and manage Google analysis and marketing services into our website.
For more information about Google's use of data for marketing purposes, please see the overview page: https://www.google.com/policies/technologies/ads, Google's privacy policy is available at https://www.google.com/policies/privacy
If you wish to object to interest-based advertising by Google marketing services, you can use the setting and opt-out options provided by Google: https://www.google.com/ads/preferences.
We base the use of the aforementioned marketing services on Art. 6 Para. 1 (a) GDPR.
8. Use of Matomo (formerly Piwik)
We use Matomo, an open source software for statistical analysis of user access.
Google Analytics uses "cookies", which are text files stored on your computer. These enable the analysis of your website use. The IP address of the users is shortened before it is stored, so that pseudonymous user profiles are created from the processed data.
The information generated by the cookie about your use of this online offer is stored on our server and not passed on to third parties.
In addition, you can prevent Matomo from doing so by clicking on the following link. An opt-out cookie is then set which prevents further collection of your data when you visit this website.
We base the use of the aforementioned analysis tool on Art. 6 Para. 1 (f) GDPR: the processing takes place for the analysis of the usage behaviour and is therefore necessary to protect our legitimate interests.
We base the use of the aforementioned marketing services on Art. 6 Para. 1 (a) GDPR.
9. Use of Cloudflare
We use a Content Delivery Network (CDN), offered by Cloudflare, Inc. 101 Townsend St, San Francisco, CA 94107, USA. Cloudflare is certified under the Privacy Shield Agreement, which provides a guarantee to comply with European privacy legislation (https://www.privacyshield.gov/participant?id=a2zt0000000TORzAAO&status=Active)
A CDN is a service with the help of which contents of our online offer, in particular large media files, such as graphics or scripts, are delivered faster with the help of regionally distributed servers connected via the Internet. User data is processed solely for the aforementioned purposes and to maintain the security and functionality of the CDN.
We base the use of the aforementioned notification function on Art. 6 Para. 1 (f) GDPR: the processing takes place for the demand-oriented design of our website and is therefore necessary to protect our legitimate interests.
For more information, please refer to Cloudflare's privacy policy: https://www.cloudflare.com/security-policy.
10. Use of Vimeo
We use the service of the third-party provider Vimeo, LLC, 555 West 18th Street, New York, New York 10011, USA, to display videos.
In order to display this content, it is necessary for third-party providers to become aware of the IP address.
Further information can be found in the third party's Privacy Policy at https://vimeo.com/privacy.
We base the use of the above-mentioned feature on Art. 6 para. 1 f) GDPR: the processing is carried out in order to design our website in line with users' needs and is therefore necessary to safeguard our legitimate interests.
11. Storage duration
The data stored by us will be deleted as soon as you revoke any consent or if the data is no longer required for its intended use and the deletion is not contrary to any legitimate interests or legal storage obligations.
If the data is not erased because it is necessary for other and legally permissible purposes, the processing of the data will be restricted.
This means that the data is blocked and not processed for other purposes. This applies,
for example, to data that must be retained for commercial or tax reasons.
In accordance with legal requirements, the data is stored for 6 years in accordance
with § 257 (1) HGB (German Commercial Code) (e.g. commercial letters, accounting documents, etc.)
and for 10 years in accordance with § 147 (1) AO (Taxation Regulation) (e.g. commercial and business letters, tax-relevant documents).
12. Social logins
To make it easier for you to log in to our KüchenAtlas portal, we offer you the option of logging into KüchenAtlas with your Google or Facebook platform account. If you already have an account with KüchenAtlas, existing data will not be overwritten or updated but supplemented with the information provided below. We will use the information provided below when registering a new user account. When using the social login, the time of access to KüchenAtlas is logged on the respective platform.
-
Facebook Login
You may register and log in on KüchenAtlas with a Facebook login. This is only done with your express consent in accordance with Article 6, para. 1 (a) of the GDPR. Facebook Login is a service provided by Facebook Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. To log in or register, you will be redirected to the Facebook page, where you can log in with your user data. This will link your Facebook profile and our service. Through the link, we automatically receive the following data from Facebook Inc:
- First and last name
- Email address
- Gender
- Your Facebook user ID or account ID.
For more information on Facebook login and privacy settings, please refer to the data protection declaration and the terms of use of Facebook Inc.
-
Google Sign-In
You may register and log in to KüchenAtlas with Google Sign-In. This is only done with your express consent in accordance with Article 6, para. 1 (a) of the GDPR. Google Sign-In is a service provided by Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland. To log in or register, you will be redirected to the Google site where you can log in with your user data. This will link your Google profile or your Google email address and our service. Through the link, we automatically receive the following data from Google Ireland Limited:
- First and last name
- Email address
- Gender
- Your Google user ID (if different from your email address)
- Indication of whether your email address has been verified
- Account ID
For more information on Google Sign-In and privacy settings, please refer to the data protection declaration and the terms of use of Google Ireland Limited.
13. Rights of data subjects
You are entitled to the following rights for data subjects:
-
Right to information
You have the right to request confirmation from us as to whether they are processing personal data relating to you.
-
Correction, deletion, restriction of processing
Furthermore, you have the right to require us to
- rectify personal data concerning you are corrected without delay (right of rectification);
- personal data concerning you is deleted immediately (right of deletion) and
- the processing is restricted (right to restrict processing).
-
The right to data portability
This means that you have the right to receive the personal data concerning you that you have provided to us in a structured, common, and machine-readable format and to transfer this data to another data controller.
-
Right of revocation
You have the right to withdraw your consent at any time. The revocation of consent shall not affect the legality of processing undertaken on the basis of this consent before its withdrawal.
-
Right of objection
If the processing of personal data concerning you is necessary for the performance of a task which is in the public interest (Art. 6 para. 1 (e) GDPR) or for the protection of our legitimate interests (Art. 6 para. 1 (f) GDPR), you have a right of objection.
-
Right of appeal
If you believe that the processing of your personal data concerning you violates the GDPR, you have the right of appeal to a supervisory authority, without prejudice to other rights of appeal.
14. Modification of the Privacy Policy
We reserve the right to adapt this Privacy Policy in the event of any changes to the legal situation, the service and data processing. However, this only applies with regard to declarations on data processing. If user consents are required or components of the data protection declaration contain provisions of the contractual relationship with the users, the changes will only be made with the users' consent.
Users may periodically review this Privacy Policy for any changes.