STEMMER IMAGING respects your privacy and handles all private data confidentially and with the greatest care on the basis of the relevant legal privacy regulations. Any personal data that you submit while accessing the pages of this website, i.e. your IP address, postal address or e-mail address, are used solely to help us provide you with a quality service. The processing and usage of personal data is made in accordance with the German Federal Data Protection Act in its current version and the EU Regulation 2016/679 (General Data Protection Regulation, hereinafter referred to as GDPR.) .
1. GENERAL INFORMATION
> Who is responsible for the processing of personal data?
According to the GDPR, other data protection regulations applicable within the EU and other regulations with data protection requirement, the data controller is:
STEMMER IMAGING AG
Phone: +49 89 80902-0
Represented by its CEO Arne Dehn
As data controller for the processing of personal data, STEMMER IMAGING has implemented the necessary technical and organisational measures in accordance with the current state of technology in order to ensure a high levels of protection of the personal data collected for our service provision.
> Whom can I contact in case of further questions?
Should you have any questions regarding data privacy protection, the data collected about you or the use of our website, please contact us at email@example.com.
> Which is the responsible supervisory authority?
Landesamt für Datenschutzaufsicht
Promenade 27 (Schloss)
Phone: +49 (0) 981 53 1300
> What are my rights?
Every data subject has:
- the right of free access to the personal data collected by us (Art. 15 GDPR),
- the right to rectification (Art.16 GDPR),
- the right to erasure ("right to be forgotten") (Art.17 GDPR),
- the right to restriction of processing (Art. 18 GDPR),
- the right to data portability (Art. 20 GDPR),
- the right to object (Art. 21 GDPR),
- the right to lodge a complaint with a supervisory authority (Art. 77 GDPR).
We may periodically revise this privacy statement. The use of your data is subject to the current version which can be accessed at www.stemmer-imaging.de/privacy. In the event of major changes, we will notify you via our services or in any other way, so that you have the opportunity to review the changes and, if necessary, exercise your right to object.
> Commissioned data processing
We have commissioned the following organisations, companies and individuals to process data:
- ClickMeeting Sp. z o.o., ul. Arkońska 6, bud. A4, 80-387 Gdańsk, Poland
- EQS Group AG, Karlstr. 47, 80333 München, Germany
- Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
- Invitario GmbH, Lerchenfelder Straße 74/1/6, 1080 Wien, Österreich
- salesforce UK Limited, village 9, floor 26 Salesforce Tower, 110 Bishopsgate, London, UK, EC2N 4AY
- TEAM23 GmbH, Beim Glaspalast 1, 86153 Augsburg, Germany
- WebhostOne GmbH, Mumpferfährstr. 68, 79713 Bad Säckingen, Germany
> SSL encryption
We use state-of-the-art encryption technology (e.g. SSL) via HTTPS to protect the security of your data during transmission.
> Use of script libraries (Google Fonts)
Some of our websites use "Google Fonts" from Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) in order to display the content correctly across all browsers.
The legal basis for the integration of Google Webfonts and the associated data transfer to Google is your consent (Art. 6 para. 1 lit. a GDPR).
2. COLLECTION OF DATA AND INFORMATION
This privacy statement applies exclusively to
- the websites of STEMMER IMAGING,
- the newsletter of STEMMER IMAGING and
- whenever reference is made to this data privacy statement from one of our offers (e.g. websites, subdomains, mobile applications, web services or integrations in third-party websites), regardless of the way in which it is accessed or used.
STEMMER IMAGING cannot influence or control other providers’ data protection compliance when linking to their websites.
2.1 Data on your profile and web usage which is personally identifiable (personal data)
Personal data is information that relates to an identified or identifiable living natural person. This includes information such as your name, phone number or address, but may also include your IP address.
> Why is my personal data collected
Some pages of our website require personal information such as address, phone number or e-mail address. The indication of your personal data is subject to your free decision. STEMMER IMAGING uses the data entrusted to us to send you the items or information requested by you by post or e-mail (voluntary consent within the meaning of Art. 6 (1) lit. a GDPR), as well as for the purpose of initiating and processing business relationships and customer care (processing for the fulfilment of a contract within the meaning of Art. 6 (2) GDPR).
> How is personal data collected by STEMMER IMAGING?
Personal data is collected via web forms on our website, such as when registering and setting up a user account, subscribing to our newsletter or registering for an event, as well as when implementing contracts or using other services.
> How long will my personal data be stored?
We store your personal data exclusively for the purpose for which you have disclosed it. The duration of the storage is based on the legal requirements. By submitting your data you consent to the collection, the processing and the use of your data by STEMMER IMAGING as described above. You can revoke your agreement for collecting, processing and using your personal data at any time by sending a letter to firstname.lastname@example.org or to the postal address given in the imprint without stating reasons. In this case your data will be deleted or blocked from further use, provided that higher legal regulations do not stand in the way of its deletion.
> Who gets my data? Is data transferred to a third country or to an international organisation?
STEMMER IMAGING will not pass on personal data to third parties unless explicitly indicated beforehand and agreed by you by means of a separate declaration. In exceptional circumstances we may be obliged to pass on personal data by the requirements of the GDPR for the data processing of certain contracts. Personal data is transmitted to analysis and marketing service providers as well as technical service providers who are active in the operation and maintenance of our website. Personal data will comply with the requirements of Art. 28 para. 3 GDPR within the scope of contracts for order processing within the meaning of Art. 28 GDPR.
> Can I have my personal data deleted?
You have the right of free access to your personal data collected by us as well as the right to rectification and erasure. In case of requests for data access, rectification, blocking or erasure, please contact: email@example.com.
> What data is collected for the registration to create a user account (WebLogin)?
You can register for a user account on our website to have access to information such as product prices. Since we offer this service only for our customers we need the following data for registration: your name, valid e-mail address, password, and information on your company.
Any registered person is free to modify personal data or have it deleted at any time, provided that data deletion does not conflict with any legal retention obligations. You can revoke your consent at any time by sending an e-mail to firstname.lastname@example.org.
The data entered during registration is processed on the basis of the user's consent (Art. 6 para. 1 lit. a GDPR). If the purpose of registration is to fulfil a contract to which the data subject is a party or to carry out pre-contractual measures, Art. 6 para. 1 lit. b GDPR is an additional legal basis for processing the data.
> Who receives mailings from STEMMER IMAGING?
STEMMER IMAGING uses Pardot to send out regular mailings with information on important news, products, services and events. This service is provided by Salesforce UK Ltd., village 9, 1 floor 26 Salesforce Tower 110 Bishopsgate, London, UK, EC2N 4AY.
Pardot is a service which organises and analyses the distribution of marketing mailings. Data provided by you to receive mailings (e.g. your e-mail address) will be stored on Pardot servers in the USA. Pardot is certified according to the "EU-US Privacy Shield". The "Privacy-Shield" is an agreement between the European Union (EU) and the USA, which is intended to ensure compliance with European data protection standards in the USA.
We use Pardot to analyse our campaigns. Technical information is also collected (e.g. time of retrieval, IP address, browser type, and operating system). Data processing is based on your consent (Art. 6 para.1 lit. a GDPR). You can revoke this consent at any time by unsubscribing. For this purpose, we provide a link in every e-mail. The legality of any data processing already carried out remains unaffected by the revocation.
We use the double opt-in procedure to send mailings when subscribing via our website. This means, we will not send you mailings unless you have expressly authorised us (by clicking the link included in an e-mail) to activate the service. When subscribing for mailings, we store the IP address assigned by the Internet service provider, as well as date and time of registration and confirmation. The changes to your data stored are also logged. The collection of this data is necessary in order to be able to trace the (possible) misuse of the e-mail address of a data subject at a later point in time and therefore serves the legal protection of the data controller. In order to adapt our mailings to individual reader preferences, we use customary technologies such as cookies or specially prepared graphic files (tracking pixels).
On the basis of your given consent (Art. 6 para. 1 lit. a GDPR), we will regularly send you information by e-mail to your registered address.
Mailing subscriptions can be cancelled by the person concerned at any time by clicking the unsubscribe link at the end of each mailing or by sending an e-mail to email@example.com without any costs other than the transmission costs according to the basic rates. The data will only be processed as long as the corresponding consent is available. The data will then be deleted.
2.2 General data on usage which is personally identifiable (automatically collected usage data)
> How does STEMMER IMAGING collect usage data?
If you access our website, i.e. if you do not register or otherwise submit information, information of a general nature is automatically collected. This information (server log files) includes, for example, the type of web browser, the operating system used, the domain name of your Internet service provider, your IP address and the like. In particular, they are processed for the following purposes:
- Ensuring a trouble-free connection to the website,
- Ensuring the smooth use of our website,
- Evaluation of system safety and stability as well as
- for other administrative purposes.
We do not use your data to draw conclusions about your person or to create a profile. Information of this kind is evaluated statistically by us if necessary, however, in order to optimise our Internet performance and the technology behind it. Data stored in log files will be deleted after 30 days at the latest. Data collection for the provision of the website and data storage in log files is mandatory for the operation of the website. Consequently, there is no possibility of objection on the part of the website user.
Processing takes place on the basis of our justified interest (Art. 6 Para. 1 lit. f GDPR) in improving the stability and functionality of our website.
> What is this data needed for?
STEMMER IMAGING implements current technology in order to compile statistics on the usage of our web service. Web analytics tools collect and store anonymised data and create anonymised usage profiles from the collected data for the target-group-oriented design and optimisation of our web pages.
3. ANALYSIS TOOLS AND ADVERTISING
3.1 Website analysis with Google Analytics
Due to the activation of IP anonymisation on this website, your IP address will be shortened by Google within the Member States of the European Union or other states which are party to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the United States and shortened there. On behalf of STEMMER IMAGING Google will use this information for the purpose of evaluating your use of the website, compiling reports on website activity and providing other services relating to website activity and internet usage at STEMMER IMAGING. Google may also transfer this information to third parties where required to do so by law, or where such third parties process the information on Google's behalf.
The IP address transmitted by your browser as part of Google Analytics will not be connected with any other data held by Google. You may refuse the storage of cookies by selecting the appropriate settings on your browser.
Furthermore, you can prevent data collected by cookies about your use of the website (including your IP address), being transmitted to Google and being processed by Google by simply downloading and installing the browser plug-in available under the following link: https://tools.google.com/dlpage/gaoptout?hl=en.
Opt-out cookies prevent your data from being collected on future visits to this site. To prevent Universal Analytics from collecting across devices, you must opt-out on all systems you use. Click here to change your consent.
For more information regarding conditions of use and privacy: https://marketingplatform.google.com/about/analytics/terms/gb/ and https://policies.google.com/?hl=en.
STEMMER IMAGING uses Google Analytics with the „gat._anonymizeIp();“ code extension in order to ensure anonymised IP addresses (known as IP masking).
The legal basis for the use of Google Analytics is your consent pursuant to Art. 6 para. 1 lit. a GDPR.
3.2 Website analysis with Pardot
a) Description and purpose of data processing
This website uses a Pardot analysis tool from Salesforce UK Ltd. Pardot tracks visitor and prospect activities on our website and landing pages by setting cookies on their browsers. Cookies are set to remember preferences (like form field values) when a visitor returns to our website. Pardot cookies do not store personally identifying information, only a unique identifier.
We use Pardot in order to be able to analyse the use of our website and to improve it regularly. For this purpose, we analyse user and click behaviour on our website in order to better tailor our communication to customer needs.
b) Legal basis for data processing
The legal basis for the use of Pardot is Art. 6 para. 1 sentence 1 lit. f GDPR. For cases in which personal data is transferred to the US, Salesforce has submitted to the EU-US Privacy Shield and thus offers a guarantee of compliance with the European data protection law.
c) Duration of storage
The data is deleted as soon as it is no longer required for our purposes.
d) Possibilities to object You may block the storage of cookies by selecting the appropriate settings on your browser. However, please note that by doing this you may not be able to use the full functionality of this website.
3.3 Google Ads (formerly Google Adwords)
Our website uses Google Conversion Tracking. Operator of the services of Google Ads is Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. If you have reached our website via an advertisement placed by Google, Google Ads places a cookie on your computer. The conversion tracking cookie is set when a user clicks on an ad placed by Google. Every time you visit our website, personal data (your IP address) is transferred to Google in the USA. This personal data is stored by Google. Google may share this personally identifiable information with third parties. Our company does not contain any information from Google that could be used to identify the person concerned.
These cookies lose their validity after 30 days and are not used for personal identification. Google processes your data in the USA and has submitted to the EU-US Privacy Shield https://www.privacyshield.gov/eu-us-framework.
The legal basis for the use of Google AdWords is your consent (Art. 6 para. 1 lit. a GDPR).
3.4 Google Remarketing
Legal basis for the use of Google Remarketing and the associated data transfer to Google is your consent (Art. 6 para. 1 lit. a GDPR).
3.5 Google Tag Manager
This website uses the Google Tag Manager. Google Tag Manager is a solution that allows marketers to manage website tags through a single interface. The Tag Manager tool itself (which implements the tags) is a cookie-less domain and does not collect any personally identifiable information. The tool triggers other tags that may themselves collect data. Google Tag Manager does not access this data. If deactivation has been performed at the domain or cookie level, it will remain in effect for all tracking tags implemented with Google Tag Manager.
3.6 Campaign Manager (formerly DoubleClick by Google)
Due to the marketing tools used, your browser automatically establishes a direct connection with the Google server. We have no influence on the extent and further use of the data collected by Google through the use of this tool and therefore inform you according to our state of knowledge: Through the integration of Campaign Manager, Google receives the information that you have called the corresponding part of our website or clicked on an advertisement from us. If you are registered with a Google service, Google can assign the visit to your account. Even if you are not registered with Google or have not logged in, it is possible for the provider to find out and store your IP address.
In addition, the Campaign Manager (DoubleClick Floodlight) cookies used enable us to understand whether you are performing any actions on our website after you have viewed or clicked on one of our display/video ads on Google or another platform via Campaign Manager (conversion tracking). Campaign Manager uses this cookie to understand the content that you have interacted with on our websites in order to send you targeted advertisements later.
You can prevent participation in this tracking process in a number of ways:
a) by setting your browser software accordingly, in particular by suppressing third party cookies to prevent you from receiving advertisements from third parties;
b) by disabling conversion tracking cookies by setting your browser to block cookies from the www.googleadservices.com domain, https://adssettings.google.de, whereby this setting is deleted when you delete your cookies;
c) by disabling the interest-based ads of the providers that are part of the "About Ads" self-regulatory campaign via the link http://optout.aboutads.info, whereby this setting is deleted when you delete your cookies;
d) by permanently disabling it in your Firefox, Internet Explorer or Google Chrome browsers via the link http://www.google.com/settings/ads/plugin;
e) by setting the appropriate cookies setting.
In addition, you can prevent Google from collecting the information generated by the cookies about your use of the websites and the processing of this information by Google by downloading and installing the browser plug-in available at https://support.google.com/adsense/answer/142293?hl=de=en under "Display settings", "Campaign Manager deactivation extension".
The legal basis for the use of Campaign Manager and the associated data transfer to Google is your consent (Art. 6 para. 1 lit. a GDPR).
3.7 Google reCAPTCHA
This website uses Google reCAPTCHA. The supplier is Google Inc, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google"). Google reCAPTCHA is primarily intended to distinguish whether an input is made by a human or improperly by an automated programme. The service includes the transmission of the IP address and any other data required by Google for the reCAPTCHA service to Google. This data is processed on the basis of Art. 6 para. 1 lit. f GDPR. The operator of the website has a legitimate interest in protecting their website against improper automated spying and SPAM. The use of Google reCAPTCHA may also involve the transmission of personal data to the servers of Google LLC. in the USA.
3.8 LinkedIn Insight Tag
LinkedIn does not share the personal data with STEMMER IMAGING, it only provides aggregated reports about the website audience and ad performance. LinkedIn also provides retargeting for website visitors, enabling STEMMER IMAGING to show personalized ads off its website by using this data, but without identifying the member. LinkedIn members can control the use of their personal data for advertising purposes through their account settings.
In addition, you can deactivate data collection on LinkedIn using the following link: https://www.linkedin.com/psettings/advertising/actions-that-showed-interest
The legal basis for the use of LinkedIn Insight tags is your consent (Art. 6 para. 1 lit. a DSGVO).
4. SOCIAL PLUGINS/ SHARIFF
So-called "social plugins" are used on parts of our websites (such as Facebook, Twitter, XING, LinkedIn, Pinterest). These plugins can be used to send data, including personal data, to US service providers and may be used by them.
STEMMER IMAGING does not collect any personal data itself using the social plugins or through their use. To prevent data from being transferred to service providers in the US without the user's knowledge, we deploy the so-called Shariff solution. This solution ensures that no personal data is passed on to the providers of the individual social plugins by simply loading our websites. Data can only be transferred to the respective service provider and stored there by clicking on one of the social plugins.
Further information about Shariff can be found on the pages of the provider Heise Medien GmbH & Co. KG:
5. DATA AUTHORISATION FOR YOUTUBE
STEMMER IMAGING has integrated components from the Internet video portal YouTube (YouTube, LLC, 901 Cherry Ave., San Bruno, CA 94066, USA; subsidiary of Google LCC., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) on this website. YouTube’s “Privacy Enhanced Mode“ option is used for this purpose.
Accessing a STEMMER IMAGING website with an integrated YouTube video will initiate a connection to the YouTube servers. According to YouTube, your data will only be transmitted to the YouTube server in the U.S. in "Privacy Enhanced Mode” if you watch the video. By clicking on the video, you consent to the data transmission. If the person concerned is logged in via a YouTube user account at the same time, the website access will be recognised. Data is collected by YouTube and Google and will be assigned to the respective YouTube account of the person concerned. If the person concerned does not wish to transmit this information to YouTube and Google, the data transmission can be prevented by a log out of the YouTube account before accessing the web page.