Website privacy statement

 

And information for data subjects pursuant to Art. 13 and Art. 14 of the General Data Protection Regulation

General information

bayern design GmbH
Managing Director: Nadine Vicentini
Luitpoldstraße 3
90402 Nuremberg
Germany

Data Protection Officer contact information:

IITR Datenschutz GmbH, Dr. Sebastian Kraska, Marienplatz 2, 80331 Munich, Germany; email @ iitr.de

 

General information regarding data processing

Data concerned:

Your personal data are collected only if provided by you voluntarily. No additional personal data will be collected. Your personal data will be processed beyond the scope of statutory regulations only with your express consent.

Purpose of processing: Fulfillment of contract
Categories of recipients: Public entities in the case of overriding legislation
Third-party service providers or other contractors
Other third parties provided the data subject has given consent or transmission is admissible due to compelling interests
Transfers to third countries: Processors located outside the European Union can be used to fulfil contracts
Duration of data storage:  The duration of data storage depends on legal retention obligations and generally is 10 years

 

Website-specific information

Use of a newsletter

When subscribing to our newsletter, you provide us with your e-mail address and with other data at your option. We use this data exclusively to send our newsletter to you. We store the data you provide when subscribing to our newsletter until you unsubscribe. You can unsubscribe at any time using the respective link in our newsletter or by sending a message to us. By unsubscribing you are objecting to our further use of your e-mail address.

 

Usage-related data

When you access our website you transmit data to our web server via your Internet browser (a technical requisite). The following data are recorded during active sessions to facilitate communication between your Internet browser and our web server:

  • date and time of your request
  • name of the file you request
  • page from which you requested the file
  • access status (file transmitted, file not found, etc.)
  • web browser and operating system you used
  • full IP address of the computer you used
  • volume of data transmitted

 

For technical security reasons including, but not limited to, to stave off attacks on our web server, we store these data temporarily. These data do not allow for any inference to individual users. After a short period of time, the data are anonymized by truncation of the IP address at the domain level and thereafter inference to individual users is not possible. The anonymized data also are processed for statistical purposes; they are not matched against any other existing data and are not forwarded to third parties in full or in part.

 

Website analysis by Matomo

We use the Matomo web analysis service to design our website on a needs-oriented basis. To record and analyze use of our website, this service transmits usage-related information regarding our website to our server and stores it for analytical purposes. Before being processed, your IP address is truncated and thus anonymized. If you wish to object to the processing of your information for analysis purposes, you can do so at any time with the click of your mouse. If you choose to do so, an opt-cut cookie that does not contain any usage-related information will be stored in your browser and Matomo will not collect any session-related data.

Please note: When you erase cookies, you also erase the opt-out cookie and you may have to reactivate it in future visits.

XXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXX

Our own dedicated cookies are used to store the settings required to display our website (cookies are datasets transmitted from the web server to your browser and stored there for future use). Our own cookies do not store any personal data. You can prevent the use of cookies altogether by deactivating the cookie storage function in your browser.

 

Information regarding other types of data processing

Specific information regarding the processing of data concerning customers/prospects

Data concerned:  Data provided for contract fulfillment; if applicable, additional data for processing based on your express consent
Purpose of processing: Contract fulfillment including offers, orders, sales, invoicing, and quality management
Categories of recipients: Public entities in the case of overriding legislation
External service providers or other contractors: for data processing, hosting, dispatching, transportation, logistics, etc.; service providers: for printing and dispatching information
Other third parties provided the data subject has given consent or transmission is admissible due to compelling interests: for credit-rating information if purchases are made against receipt of an invoice, for electronic dispatch of information, and for quality management
Transfers to third countries: As part of contract fulfillment, processors outside the European Union including e-mail service providers may be used
Duration of data storage: The duration of data storage depends on legal retention obligations and generally is 10 years

    

 

Specific information regarding the application process

 

Data concerned:  Application-related information
Purpose of processing: Execution of the application process
Categories of recipients: Public entities in the case of overriding legislation
External service providers or other contractors: for data processing, hosting, etc.
Other third parties provided the data subject has given consent or transmission is admissible due to compelling interests
Transfers to third countries: As part of contract fulfillment, processors outside the European Union including e-mail service providers may be used
Duration of data storage: Following communication of the decision to the applicant, application-related data typically are erased within four (4) months unless the applicant has given consent to an extended storage period for admission to the pool of applicants 

 

Specific information regarding the processing of employee data

 

Data concerned:  Data provided for contract fulfillment; if applicable, additional data for processing based on your express consent
Purpose of processing: Contract fulfillment as part of the employment relationship
Categories of recipients: Public entities in the case of overriding legislation: financial authorities, social insurance companies, trade associations, etc.
External service providers or other contractors: for data processing, hosting, payroll accounting, travel-expense reporting, insurance services, etc.Other third parties, provided the data subject has given consent or transmission is admissible due to compelling interests
Transfers to third countries: As part of contract fulfillment, processors outside the European Union including e-mail service providers may be used
Duration of data storage: The duration of data storage depends on legal retention obligations and generally is 10 years

     

Specific information regarding the processing of supplier data

 

Data concerned:  Data provided for contract fulfillment; if applicable, additional data for processing based on your express consent
Purpose of processing: Contract fulfillment including inquiries, sourcing, and quality management
Categories of recipients: Public entities in the case of overriding legislation; external service providers or other contractors: for data processing, hosting, bookkeeping, payment handling, etc.
Other third parties provided the data subject has given consent or transmission is admissible due to compelling interests
Transfers to third countries: As part of contract fulfillment, processors outside the European Union including e-mail service providers may be used
Duration of data storage: The duration of data storage depends on legal retention obligations and generally is 10 years

 

Specific information regarding the use of software for video conferences/webinars

 

Data concerned:  Data provided for the purpose of using the video conference software or webinar software (mainly first name, last name, e-mail address; optional: audio transmission; optional: image transmission; optional: queries regarding use of chat functions); as required for technical purposes: processing of data concerning your system to activate a connection with the conference software provider
Purpose of processing: Holding video conferences and/or webinars
Categories of recipients: Public entities in the case of overriding legislation; external service providers or other contractors: for data processing, hosting, etc.
Other third parties provided the data subject has given consent or transmission is admissible due to compelling interests
Transfers to third countries: Use of processors outside the European Union (in this case, in the U.S.A.); standard contract clauses have been agreed upon with the respective service provider
Duration of data storage: Video conferences are recorded only upon participants’ previously documented consent; technical data are erased if they no longer are required; in all other cases, the duration of data storage depends on legal retention obligations and generally is 10 years

Additional information and contact information

In addition, you can exercise your right to obtain information, have data concerning you rectified or erased, restrict the processing of data concerning you, or your right to object to the processing, and/or your right to data portability, at any time. To do so, you can write to us by e-mail at datenschutz @ bayern-design.de or send a letter to us. Also, you have the right to lodge a complaint with the data protection supervision authority responsible.

The authority responsible for us is the BayLDA Bayerische Landesamt für Datenschutzaufsicht, Promenade 18, 91522 Ansbach, Germany. You also can contact the data protection authority responsible for your place of residence so your complaint can be forwarded to the data protection supervision authority.

Version of this privacy statement dated April 2021