Privacy Policy
1. Data Protection at a Glance
General Information
The following notes provide a simple overview of what happens to your personal data when you visit this website. Personal data is any data with which you can be personally identified. For detailed information on data protection, please refer to our privacy policy listed below this text.
Data collection on this website
Who is responsible for data collection on this website?
Data processing on this website is carried out by the website operator. You can find their contact details in the „Information on the Controller“ section of this privacy policy.
How do we collect your data?
Your data is collected, firstly, by you providing it to us. This can include, for example, data that you enter into a contact form.
Other data is collected automatically by our IT systems or with your consent when you visit the website. This primarily involves technical data (e.g. internet browser, operating system or time of page access). This data is collected automatically as soon as you access this website.
What do we use your data for?
Some data is collected to ensure the error-free operation of the website. Other data may be used to analyse your user behaviour. If contracts can be concluded or initiated via the website, the transmitted data will also be processed for contract offers, orders or other order requests.
What rights do you have regarding your data?
You have the right at any time to receive free information about the origin, recipients, and purpose of your stored personal data. You also have the right to request the correction or deletion of this data. If you have given your consent to data processing, you can withdraw this consent at any time with future effect. Furthermore, you have the right to request the restriction of the processing of your personal data under certain circumstances. Additionally, you have the right to lodge a complaint with the competent supervisory authority.
You can contact us at any time regarding this and other data protection matters.
Analysis tools and third-party tools
Your browsing behaviour may be statistically analysed when visiting this website. This is primarily done using so-called analysis programmes.
For detailed information on these analysis programmes, please refer to the following privacy policy.
2. Hosting
We host the content of our website with the following provider:
External hosting
This website is hosted externally. The personal data collected on this website is stored on the servers of the hoster(s). This may include, in particular, IP addresses, contact requests, meta and communication data, contract data, contact details, names, website accesses, and other data generated via a website.
External hosting is carried out for the purpose of fulfilling contracts with our potential and existing customers (Art. 6(1)(b) GDPR) and in the interest of providing our online services securely, quickly, and efficiently through a professional provider (Art. 6(1)(f) GDPR). If consent has been requested accordingly, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and § 25(1) TDDDG, insofar as the consent includes the storage of cookies or access to information in the user's end device (e.g. device fingerprinting) within the meaning of the TDDDG. Consent can be withdrawn at any time.
Our host will process your data only to the extent necessary for the performance of its contractual obligations and will follow our instructions regarding this data.
We use the following host(s):
BYTS Tech GmbH
Stadtbadstraße 5
85368 Moosburg
Order processing
We have concluded a contract for order processing (AVV) for the use of the above-mentioned service. This is a contract required by data protection law, which ensures that this service processes the personal data of our website visitors only according to our instructions and in compliance with the GDPR.
3. General Information and Mandatory Disclosures
Data Protection
The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.
By using this website, various personal data will be collected. Personal data is data with which you can be personally identified. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this happens.
We would like to point out that data transmission on the internet (e.g. in email communications) can have security vulnerabilities. It is not possible to protect data completely from third-party access.
Informationen zum Verantwortlichen
The data controller for this website is:
Brasser Accounting Solutions GmbH
At the Alster 6
20099 Hamburg
Telephone: 03681 4289320
E-mail: info@Servicepoint-lohn-gehalt.de
The controller is the natural or legal person that, alone or jointly with others, determines the purposes and means of the processing of personal data (e.g. names, email addresses, etc.).
Storage duration
Unless a more specific retention period is stated within this privacy policy, your personal data will remain with us until the purpose for data processing ceases to apply. If you exercise a legitimate request for deletion or withdraw consent for data processing, your data will be deleted, provided we do not have other legally permissible grounds for retaining your personal data (e.g. tax or commercial retention periods); in the latter case, deletion will occur after these grounds cease to apply.
General information on the legal basis for data processing on this website
If you have consented to data processing, we will process your personal data based on Art. 6 Para. 1 lit. a GDPR or Art. 9 Para. 2 lit. a GDPR if special categories of data pursuant to Art. 9 Para. 1 GDPR are being processed. In the case of express consent to the transfer of personal data to third countries, data processing will also be based on Art. 49 Para. 1 lit. a GDPR. If you have consented to the storage of cookies or access to information on your terminal device (e.g. via device fingerprinting), data processing will additionally be based on Section 25 Para. 1 TDDDG. Consent can be revoked at any time. If your data is required for the performance of a contract or for the implementation of pre-contractual measures, we will process your data based on Art. 6 Para. 1 lit. b GDPR. Furthermore, we will process your data if it is required for the fulfilment of a legal obligation based on Art. 6 Para. 1 lit. c GDPR. Data processing may also take place based on our legitimate interests pursuant to Art. 6 Para. 1 lit. f GDPR. The respective legal bases applicable in individual cases will be explained in the following paragraphs of this privacy policy.
Information regarding the transfer of data to third countries not secure in terms of data protection, as well as the transfer to US companies not DPF-certified
Among other things, we use tools from companies based in third countries that are not considered safe from a data protection perspective, as well as US tools whose providers are not certified under the EU-US Data Privacy Framework (DPF). When these tools are active, your personal data may be transferred to and processed in these countries. We would like to point out that no level of data protection comparable to that of the EU can be guaranteed in third countries that are not considered safe from a data protection perspective.
We would like to point out that the USA, as a safe third country, generally has a comparable level of data protection to the EU. Data transfer to the USA is therefore permissible if the recipient holds a certification under the „EU-US Data Privacy Framework“ (DPF) or has appropriate additional safeguards. Information on transfers to third countries, including data recipients, can be found in this privacy policy.
Recipients of personal data
As part of our business activities, we work with various external bodies. This sometimes also requires the transfer of personal data to these external bodies. We only pass on personal data to external bodies if this is necessary for the performance of a contract, if we are legally obliged to do so (e.g., disclosure of data to tax authorities), if we have a legitimate interest in disclosure pursuant to Art. 6 para. 1 letter f GDPR, or if another legal basis permits the disclosure of data. When using contract processors, we only pass on our customers' personal data on the basis of a valid contract for contract processing. In the event of joint processing, a contract for joint processing is concluded.
Withdrawal of your consent to data processing
Many data processing operations are only possible with your explicit consent. You can withdraw consent already given at any time. The lawfulness of any data processing carried out prior to withdrawal shall remain unaffected by the withdrawal.
Right to object in special cases and to direct marketing (Article 21 GDPR)
Where data processing is based on Article 6(1)(e) or (f) GDPR, you have the right to object to the processing of your personal data at any time for reasons arising from your particular situation; this also applies to profiling based on these provisions. You can find the relevant legal basis on which a processing operation is based in this privacy policy. If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for processing that override your interests, rights and freedoms, or the processing serves the assertion, exercise or defence of legal claims (objection pursuant to Article 21(1) GDPR).
IF YOUR PERSONAL DATA IS PROCESSED FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR SUCH MARKETING, INCLUDING PROFILING WHERE IT IS RELATED TO SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL NO LONGER BE PROCESSED FOR MARKETING PURPOSES (OBJECTION PURSUANT TO ART. 21(2) GDPR).
Right of complaint to the competent supervisory authority
In the event of an infringement of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, their place of work or the place of the alleged infringement. The right to complain shall be without prejudice to any other administrative or judicial remedy.
Right to data portability
You have the right to have data that we process automatically based on your consent or in fulfilment of a contract handed over to you or a third party in a common, machine-readable format. If you request the direct transfer of the data to another controller, this will only be done to the extent that it is technically feasible.
Information, rectification and deletion
Under the applicable legal provisions, you have the right at any time to free access to information about your stored personal data, their origin and recipients, and the purpose of data processing, and, if applicable, a right to rectification or deletion of this data. You can contact us at any time for this purpose, as well as for further questions concerning personal data.
Right to restriction of processing
You have the right to request the restriction of the processing of your personal data. You can contact us at any time for this purpose. The right to restrict processing exists in the following cases:
- If you dispute the accuracy of your personal data stored with us, we will generally require time to verify this. For the duration of the verification, you have the right to request the restriction of the processing of your personal data.
- If the processing of your personal data took place/takes place unlawfully, you can request the restriction of data processing instead of erasure.
- If we no longer need your personal data, but you need it for the establishment, exercise or defence of legal claims, you have the right to request restriction of the processing of your personal data instead of erasure.
- If you have lodged an objection under Article 21(1) of the GDPR, a balancing of your interests and our interests must be carried out. As long as it has not yet been determined whose interests prevail, you have the right to request the restriction of the processing of your personal data.
If you have restricted the processing of your personal data, this data may – apart from its storage – only be processed with your consent, or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person, or for reasons of an important public interest of the Union or of a Member State.
SSL or TLS encryption
This page uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content, such as orders or enquiries that you send to us as the site operator. You can recognise an encrypted connection by the fact that the browser's address bar changes from „http://“ to „https://“ and by the padlock symbol in your browser bar.
When SSL or TLS encryption is enabled, the data you send us cannot be read by third parties.
4. Data collection on this website
Biscuits
Our websites use „cookies“. Cookies are small data packets and do not cause damage to your device. They are stored on your device either temporarily for the duration of a session (session cookies) or permanently (persistent cookies). Session cookies are automatically deleted at the end of your visit. Persistent cookies remain stored on your device until you delete them yourself or they are automatically deleted by your web browser.
Cookies can be set by us (first-party cookies) or by third-party companies (so-called third-party cookies). Third-party cookies enable the integration of certain services from third-party companies within websites (e.g. cookies for processing payment services).
Cookies have various functions. Numerous cookies are technically necessary, as certain website functions would not work without them (e.g., the shopping basket function or video playback). Other cookies can be used to analyse user behaviour or for advertising purposes.
Cookies that are essential for the electronic communication process, for providing certain functionalities you have requested (e.g., for the shopping cart function), or for optimising the website (e.g., cookies for measuring the web audience) (necessary cookies) are stored on the basis of Art. 6(1)(f) GDPR, unless another legal basis is specified. The website operator has a legitimate interest in storing necessary cookies for the technically flawless and optimised provision of its services. If consent has been requested for the storage of cookies and comparable recognition technologies, processing will be carried out exclusively on the basis of this consent (Art. 6(1)(a) GDPR and § 25(1) TDDDG); the consent can be revoked at any time.
You can set your browser to inform you about the setting of cookies and to allow cookies only in individual cases, to exclude the acceptance of cookies for specific cases or in general, and to activate the automatic deletion of cookies when closing the browser. The functionality of this website may be restricted when cookies are deactivated.
You can find out which cookies and services are used on this website in this privacy policy.
Consent with Borlabs Cookie
Our website uses Borlabs Cookie's consent technology to obtain your consent for storing certain cookies in your browser or for using certain technologies, and to document this in a data protection-compliant manner. The provider of this technology is Borlabs GmbH, Rübenkamp 32, 22305 Hamburg (hereinafter referred to as Borlabs).
When you access our website, a Borlabs cookie is stored in your browser, which saves your consents or the revocation of these consents. This data is not passed on to the provider of Borlabs Cookie.
The data collected will be stored until you request its deletion, delete the Borlabs cookie yourself, or the purpose for data storage ceases to apply. Mandatory legal retention periods remain unaffected. Further details on data processing by Borlabs Cookie can be found at https://de.borlabs.io/kb/welche-daten-speichert-borlabs-cookie/.
The use of Borlabs Cookie Consent Technology is to obtain the legally required consents for the use of cookies. The legal basis for this is Art. 6 para. 1 lit. c GDPR.
Contact form
If you send us inquiries via the contact form, your details from the inquiry form, including the contact details provided by you, will be stored by us for the purpose of processing the inquiry and in case of follow-up questions. We will not disclose this data without your consent.
The processing of this data is based on Article 6 (1)(b) GDPR, if your request relates to the fulfilment of a contract or is necessary for the performance of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective handling of your enquiries (Article 6 (1)(f) GDPR) or on your consent (Article 6 (1)(a) GDPR) if this has been requested; consent can be withdrawn at any time.
The data you enter in the contact form will remain with us until you request its deletion, withdraw your consent to storage, or the purpose for data storage ceases to apply (e.g. after your request has been fully processed). Compulsory legal provisions, particularly retention periods, remain unaffected.
Enquiry by email, telephone or fax
If you contact us by email, telephone or fax, your request, including all personal data arising from it (name, enquiry), will be stored and processed by us for the purpose of handling your request. We will not pass on this data without your consent.
The processing of this data is based on Article 6 (1)(b) GDPR, if your request relates to the fulfilment of a contract or is necessary for the performance of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective handling of your enquiries (Article 6 (1)(f) GDPR) or on your consent (Article 6 (1)(a) GDPR) if this has been requested; consent can be withdrawn at any time.
The data you send us via contact requests will remain with us until you request deletion, revoke your consent for storage, or the purpose for data storage ceases to apply (e.g., after your request has been fully processed). Mandatory legal provisions, particularly statutory retention periods, remain unaffected.
5. Analysis Tools and Advertising
Google Tag Manager
We use Google Tag Manager. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Google Tag Manager is a tool that allows us to integrate tracking or statistics tools and other technologies on our website. Google Tag Manager itself does not create user profiles, store cookies, or perform independent analyses. It is solely used for managing and deploying the tools integrated through it. However, Google Tag Manager records your IP address, which may also be transferred to Google's parent company in the United States.
Google Tag Manager is used on the basis of Art. 6(1)(f) GDPR. The website operator has a legitimate interest in the fast and uncomplicated integration and management of various tools on their website. Where appropriate consent has been obtained, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG, insofar as the consent includes the storage of cookies or access to information on the user's terminal device (e.g. device fingerprinting) within the meaning of the TDDDG. Consent can be withdrawn at any time.
The company is certified under the „EU-US Data Privacy Framework“ (DPF). The DPF is an agreement between the European Union and the USA, designed to ensure compliance with European data protection standards for data processing in the USA. Any company certified under the DPF commits to adhering to these data protection standards. Further information on this can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780.
Google Analytics
This website uses functions of the web analytics service Google Analytics. The provider is Google Ireland Limited („Google“), Gordon House, Barrow Street, Dublin 4, Ireland.
Google Analytics enables the website operator to analyse the behaviour of website visitors. In doing so, the website operator receives various usage data, such as page views, duration of stay, operating systems used, and the user's origin. This data is compiled into a user ID and assigned to the respective end device of the website visitor.
Furthermore, with Google Analytics, we can record your mouse and scroll movements and clicks, among other things. Google Analytics also uses various modelling approaches to supplement the collected data sets and employs machine learning technologies for data analysis.
Google Analytics uses technologies that enable user recognition for the purpose of analysing user behaviour (e.g. cookies or device fingerprinting). The information collected by Google about the use of this website is usually transmitted to a Google server in the USA and stored there.
Use of this service is based on your consent according to Art. 6 Para. 1 lit. a GDPR and § 25 Para. 1 TDDDG. Consent can be withdrawn at any time.
Data transfer to the USA is based on the EU Commission's Standard Contractual Clauses. You can find details here: https://business.safety.google/adscontrollerterms/sccs/.
The company is certified under the „EU-US Data Privacy Framework“ (DPF). The DPF is an agreement between the European Union and the USA, designed to ensure compliance with European data protection standards for data processing in the USA. Any company certified under the DPF commits to adhering to these data protection standards. Further information on this can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780.
IP anonymization
Google Analytics IP anonymisation is activated. This means your IP address will be truncated by Google within member states of the European Union or other contracting states to the Agreement on the European Economic Area before being transmitted to the USA. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and truncated there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, to compile reports on website activity, and to provide other services related to website and internet use to the website operator. The IP address transmitted by your browser in the context of Google Analytics will not be merged with other Google data.
Browser Plugin
You can prevent Google from collecting and processing your data by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=de.
For more information on how user data is handled by Google Analytics, please see Google's Privacy Policy: https://support.google.com/analytics/answer/6004245?hl=de.
Order processing
We have concluded a data processing agreement with Google and fully implement the strict requirements of the German data protection authorities when using Google Analytics.
Google Ads
The website operator uses Google Ads. Google Ads is an online advertising programme by Google Ireland Limited („Google“), Gordon House, Barrow Street, Dublin 4, Ireland.
Google Ads allows us to display advertisements in the Google search engine or on third-party websites when users enter specific search terms into Google (keyword targeting). Furthermore, targeted advertisements can be displayed based on user data available at Google (e.g., location data and interests) (audience targeting). We, as website operators, can evaluate this data quantitatively by, for example, analysing which search terms led to the display of our advertisements and how many ads led to corresponding clicks.
Use of this service is based on your consent according to Art. 6 Para. 1 lit. a GDPR and § 25 Para. 1 TDDDG. Consent can be withdrawn at any time.
Data transfer to the USA is based on the EU Commission's Standard Contractual Clauses. You can find details here: https://policies.google.com/privacy/frameworks and https://business.safety.google/controllerterms/.
The company is certified under the „EU-US Data Privacy Framework“ (DPF). The DPF is an agreement between the European Union and the USA, designed to ensure compliance with European data protection standards for data processing in the USA. Any company certified under the DPF commits to adhering to these data protection standards. Further information on this can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780.
6. Plugins and Tools
Adobe Fonts
This website uses Adobe web fonts to ensure consistent display of certain fonts. The provider is Adobe Systems Incorporated, 345 Park Avenue, San Jose, CA 95110-2704, USA (Adobe).
When you access this website, your browser downloads the necessary fonts directly from Adobe to display them correctly on your device. Your browser establishes a connection to Adobe's servers in the USA to do this. This allows Adobe to know that this website has been accessed via your IP address. According to Adobe, no cookies are stored when providing the fonts.
The storage and analysis of data are carried out on the basis of Art. 6 (1) lit. f GDPR. The website operator has a legitimate interest in the uniform display of the font on their website. If appropriate consent has been requested, processing is carried out exclusively on the basis of Art. 6 (1) lit. a GDPR and § 25 (1) TDDDG, insofar as the consent includes the storage of cookies or access to information in the user's terminal device (e.g. device fingerprinting) within the meaning of the TDDDG. Consent can be withdrawn at any time.
Data transfer to the USA is based on the EU Commission's Standard Contractual Clauses. You can find details here: https://www.adobe.com/de/privacy/eudatatransfers.html.
Further information on Adobe Fonts can be found at: https://www.adobe.com/de/privacy/policies/adobe-fonts.html.
Adobe's privacy policy can be found at: https://www.adobe.com/de/privacy/policy.html
The company is certified under the „EU-US Data Privacy Framework“ (DPF). The DPF is an agreement between the European Union and the USA, designed to ensure compliance with European data protection standards for data processing in the USA. Any company certified under the DPF commits to adhering to these data protection standards. Further information on this can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/participant/5660.
Google reCAPTCHA
We use „Google reCAPTCHA“ (hereinafter referred to as „reCAPTCHA“) on this website. The provider is Google Ireland Limited („Google“), Gordon House, Barrow Street, Dublin 4, Ireland.
reCAPTCHA is used to check whether data input on this website (e.g. in a contact form) is being made by a human or an automated program. To do this, reCAPTCHA analyses the website visitor's behaviour based on various characteristics. This analysis begins automatically as soon as the website visitor enters the website. For the analysis, reCAPTCHA evaluates various pieces of information (e.g. IP address, website visitor's time spent on the website, or mouse movements made by the user). The data collected during the analysis is forwarded to Google.
The reCAPTCHA analyses run entirely in the background. Website visitors are not notified that an analysis is taking place.
The storage and analysis of data are carried out on the basis of Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in protecting its web offerings from abusive automated snooping and SPAM. If a corresponding consent has been requested, the processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a GDPR and Section 25 para. 1 TDDDG, insofar as the consent covers the storage of cookies or access to information in the user's end device (e.g. device fingerprinting) within the meaning of the TDDDG. Consent can be revoked at any time.
Further information on Google reCAPTCHA can be found in the Google Privacy Policy and the Google Terms of Service at the following links: https://policies.google.com/privacy?hl=de and https://policies.google.com/terms?hl=de.
The company is certified under the „EU-US Data Privacy Framework“ (DPF). The DPF is an agreement between the European Union and the USA, designed to ensure compliance with European data protection standards for data processing in the USA. Any company certified under the DPF commits to adhering to these data protection standards. Further information on this can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780.
SolidWP
We have integrated SolidWP on this website. The provider is iThemes Media LLC, 1720 South Kelly Avenue Edmond, OK 73013, USA (hereinafter referred to as „SolidWP“).
SolidWP serves to protect our website from unwanted access or malicious cyberattacks. For this purpose, SolidWP collects, among other things, your IP address, the time and source of login attempts, and log data (e.g., the browser used). SolidWP is installed locally on our servers.
SolidWP submits IP addresses of recurring attackers to a central SolidWP database in the USA (Network Brute Force Protection) to prevent such attacks in the future.
The use of SolidWP is based on Art. 6(1)(f) GDPR. The website operator has a legitimate interest in the most effective possible protection of their website against cyberattacks. Where appropriate consent has been obtained, processing shall be carried out exclusively on the basis of Art. 6(1)(a) GDPR and § 25(1) TDDDG, insofar as the consent covers the storage of cookies or access to information on the user's terminal device (e.g. device fingerprinting) within the meaning of the TDDDG. Consent can be withdrawn at any time.